# Securing a new era of collaboration in financial services
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2020-12-30
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Risks of Remote Collaboration in Financial Services
Meta Description: Learn how financial services firms are adapting to remote working models and addressing IT security challenges amidst collaboration sprawl.
URL: https://financedigest.com/securing-a-new-era-of-collaboration-in-financial-serviceshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/img8570-514-scaled-1736838661112-compressed.jpg)

_By **Dave Henderson,** Co-founder at BlueFort Security_

Kitchen table trading is a notion that would have seemed laughable to many financial services firms at the end of 2019.  But while mobile phones are generally banned on trading floors globally and conversations often tracked and recorded, the rapid deployment of remote working models has meant that many of these safeguards were no longer practical.  Indeed, early on in the pandemic, the Financial Conduct Authority (FCA) relaxed its rules for those [working at home](https://www.financedigest.com/how-to-maintain-physical-and-mental-health-while-working-from-home.html "How to maintain physical and mental health while working from home").  However, while the regulator accepted that – in some instances – organisations would be unable to comply with their obligations, [firms would still be expected](https://www.financedigest.com/german-engineering-firms-expect-hit-from-supply-chain-bottlenecks-next-year.html "German engineering firms expect hit from supply chain bottlenecks next year") to come up with ways to address the issue.

Like most organisations and indeed most industries, [digital collaboration tools acted as a lifeline for financial services](https://www.financedigest.com/the-future-for-financial-services-is-digital-engagement.html "The future for financial services is digital engagement") during periods of widespread workplace disruption in 2020.  But while many of these changes were initially seen as a temporary way of ensuring business continuity, it has become all too clear that remote working – or at least [hybrid working](https://www.financedigest.com/how-to-make-hybrid-working-successful.html "How to make hybrid working successful") – is here to stay.  For IT [security and compliance](https://www.financedigest.com/maintaining-security-and-compliance-amid-digital-transformation-in-financial-services.html "Maintaining Security and Compliance amid Digital Transformation in Financial Services") professionals, this leaves plenty of challenges to consider.  Those within financial services, in particular, operate under a set of rigorous rules and regulations around privacy, [data security](https://www.financedigest.com/how-financial-services-can-secure-data-and-build-trust-in-todays-modern-environment.html "How financial services can secure data and build trust in today’s modern environment") and insider trading.  Regulated firms must demonstrate they are working within the boundaries set out by the [FCA](https://www.fca.org.uk/) and [PRA](https://www.bankofengland.co.uk/prudential-regulation).

**The daunting challenge of collaboration sprawl**

The challenge of delivering on these requirements with a geographically dispersed workforce – with hundreds of computers and [devices all operating outside the protection](https://www.financedigest.com/the-hearing-protection-devices-market.html "The Hearing Protection Devices Market") afforded inside the corporate network – is a daunting one.  Particularly while working remotely – which many security teams will still be doing long into 2021 – being able to prove the appropriate controls over inside information and effective information [barriers remain](https://www.financedigest.com/high-barrier-packaging-films-for-pharmaceuticals-market-set-for-5-cagr-through-2029-blisters-remain-top-application-area-says-a-new-fmi-report.html "High Barrier Packaging Films for Pharmaceuticals Market Set for 5% CAGR Through 2029; Blisters Remain Top Application Area, Says a New FMI Report") in place, regardless of where their teams are working from, is complex.

Collaboration application sprawl, which a recent [report from Aternity](https://www.aternity.com/resources/?resource_type%5b%5d=white-paper) revealed has increased dramatically since March 2020, significantly extends an organisation’s threat surface and has the potential to impact data governance in new ways.  With employees adopting numerous collaboration tools for internal, external and ad hoc communications, simply gaining visibility is tough enough – effectively monitoring, managing and [securing these platforms can be far more challenging](https://www.financedigest.com/hybrid-working-and-the-continued-security-challenges-for-financial-organisations.html "Hybrid working and the continued security challenges for financial organisations").

For the most part, remote workers have simply been trying to find a quick and easy communication workaround to being [physically separated](https://www.financedigest.com/why-it-pays-for-companies-to-hold-physical-assets-in-separate-limited-companies.html "Why it pays for companies to hold physical assets in separate limited companies") from their colleagues.  But as the oft-quoted proverb goes, the road to hell is paved with good intentions.  The challenging task now facing [security and compliance teams with these collaboration platforms – from Slack, to Microsoft Teams and Zoom – is enforcing stringent data and security policies](https://www.financedigest.com/uk-finance-regulators-should-pay-heed-to-energy-security-policy-says-sunak.html "UK finance regulators should pay heed to energy security policy, says Sunak") over a range of new applications.  The sudden and widespread nature of their adoption also [poses a number of security](https://www.financedigest.com/london-police-say-queens-funeral-poses-biggest-ever-security-test.html "London police say queen’s funeral poses biggest ever security test") risks, with platforms often left wide open for exploitation by cyber criminals.  Indeed, shortly after the first lockdown started, Standard Chartered [banned the use of the Zoom video conferencing app and Google Hangouts](https://uk.reuters.com/article/us-health-coronavirus-zoom-exclusive/exclusive-stay-off-zoom-and-google-hangouts-standard-chartered-chief-tells-staff-idUKKCN21W2PX), specifically because of the security risks it suddenly faced.

**Defining the collaboration threat**

If a malicious actor is able to compromise a user account on one of these collaboration tools, there is a strong probability that they’ll gain access to the corporate network.  Once inside, a threat actor can cause significant damage.  For example, they could pose as a trusted employee to share malicious documents or [files to move](https://www.financedigest.com/resilience-how-a-glory-file-helps-traveltech-founder-julie-grieve-move-onwards-and-upwards.html "Resilience: How a ‘glory file’ helps traveltech founder Julie Grieve move onwards and upwards") laterally into other devices.  Or, they might move into file-sharing [apps such as G-suite or Sharepoint to gain access to and exfiltrate sensitive data](https://www.financedigest.com/data-privacy-and-navigation-how-our-personal-data-is-used-in-navigation-apps.html "Data Privacy and Navigation: How our personal data is used in Navigation Apps.").

Another significant security loophole with collaboration tools is that legacy security and data loss prevention (DLP) tools that have been in place for years to handle on-site collaboration and [work environments](https://www.financedigest.com/the-benefits-of-creating-a-great-working-environment.html "The Benefits of Creating a Great Working Environment") are simply ineffective now that Google, Slack and Dropbox are so commonplace.  Collaboration apps lack granular controls and there is only so much an organisation can do to restrict how their use.

The informal nature of the chat function in these platforms also means the lines between what’s appropriate to discuss – and what is not – can become blurred.  Conversations can easily stray into sensitive territory, with the fallout being just as damaging as a successful cyber attack.  With chats easily created – and not often deleted – there are far more [potential exit points for sensitive or regulated data](https://www.financedigest.com/spotting-the-signs-of-potential-financial-vulnerability-through-policy-history-data.html "Spotting the signs of potential financial vulnerability through policy history data").  Ensuring confidential files are not accidentally [shared with external guests or other unauthorised users](https://www.financedigest.com/power-generation-sector-to-remain-largest-end-user-of-industrial-engines-persistence-market-research.html "Double Acting Hydraulic Cylinders to Hold Close to 50% Market Share: Persistence Market Research"), or posted in the wrong place, is extremely difficult – and yet it must be done.  Financial services organisations have a duty to ensure confidential insider information is not disclosed to unauthorised [third parties](https://www.financedigest.com/why-a-replacement-to-third-party-cookies-is-key-to-post-pandemic-recovery.html "Why a replacement to third party cookies is key to post-pandemic recovery"), even under challenging circumstances.

Indeed, in a [speech at a recent City Financial Global event](https://www.fca.org.uk/news/speeches/market-abuse-coronavirus), Director of Market Oversight, Julia Hoggett, explained: “New challenges, including controlling inside information moving within a firm and leaving a firm may also manifest at times like these… We expect firms to have updated their policies, refreshed their training and put in place rigorous oversight reflecting the new environment – particularly regarding the risk of use of privately-owned devices.”

**Ensuring [data oversight in a changing](https://www.financedigest.com/sterling-little-changed-after-mixed-labour-market-data.html "Sterling little changed after mixed labour market data") environment**

[Information lies at the heart of everything financial](https://www.financedigest.com/overcoming-information-overload-in-the-financial-sector.html "OVERCOMING INFORMATION OVERLOAD IN THE FINANCIAL SECTOR") services firms do.  Now, more than ever, this needs to focus on [protecting the data](https://www.financedigest.com/how-financial-organisations-can-stay-protected-from-financial-data-breaches.html "How Financial Organisations can Stay Protected from Financial Data Breaches ") itself.  With sensitive information now moving out of the confines of the corporate network and into new collaboration platforms, IT security teams must ensure employees are using and [securing data](https://www.financedigest.com/cyber-security-data-re-assurance.html "Cyber Security: Data ‘Re’-Assurance") properly.

[Strong data](https://www.financedigest.com/global-shares-slide-dollar-gains-as-rates-rise-on-strong-data.html "Global shares slide, dollar gains as rates rise on strong data") loss prevention (DLP) policies combined with a Cloud Access Security Broker (CASB) and Secure Web Gateway (SWG) will be ‘must have’ tools of the trade for any financial services organisations that are embracing digital technologies.  [Security teams must prioritise](https://www.financedigest.com/why-the-finance-sector-must-prioritise-mobile-security-over-innovation.html "Why the finance sector must prioritise mobile security over innovation") both visibility into collaboration tool usage across the organisation, as well as the ability to enforce granular security policies.

While the [pandemic has fundamentally changed](https://www.financedigest.com/the-future-of-retail-and-the-ways-that-retail-has-changed-for-consumers-during-the-pandemic.html "The future of retail and the ways that retail has changed for consumers during the pandemic") how many organisations will operate in the long-term, 2021 undoubtedly holds further challenges.  As Julia Hoggett highlighted in her speech, when it comes to new [technologies and communication](https://www.financedigest.com/how-communication-technology-can-help-relieve-pressure-on-staff-in-the-financial-services-sector.html "How communication technology can help relieve pressure on staff in the financial services sector ") tools, there remains an expectation that organisations will update their policies, renew their emphasis on training and ensure oversight is just as rigorous oversight in a changing environment.

Ultimately, there is no such thing as risk-free.  However, with comprehensive, robust, and well-considered data security policies and tools in place, security teams can recreate the closely [monitored environment of the past in a new and exciting era for the industry](https://www.financedigest.com/condition-monitoring-service-market-buoyant-with-flourishing-power-generation-industry-adoption-exhibits-a-notable-decline-amid-covid-19-pandemic-fmi.html "Condition Monitoring Service Market Buoyant with Flourishing Power Generation Industry; Adoption Exhibits a Notable Decline Amid COVID-19 Pandemic: FMI").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

