# Steps Toward Fostering a Security-First Culture
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-09-15
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Stay Ahead of Cyber Threats: How to Protect Your Financial
Meta Description: Learn how to stay ahead of cyber criminals by educating employees on best practices and leveraging managed services to augment your security teams.
URL: https://financedigest.com/steps-toward-fostering-a-security-first-culturehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/security-sbi-300195529-1736837874647-compressed.jpg)

_By_ **_Josh Davies_** _, Product Manager,_ [_Alert Logic_](https://www.alertlogic.com/)

![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/josh-davies-product-manager-at-alert-logic-1736837874512-compressed.jpg)

Josh Davies, Product Manager, Alert Logic

Financial institutions have always been highly targeted by cyber criminals and the professionals responsible for security posture must continue to try and stay ahead. We’re now seeing more sophisticated threat actors reinvesting profits from campaigns, such as cryptolocker ransoms, into their endeavours. The increasing tempo and audacity of attacks has gained mainstream media exposure, raising the general awareness of the [need for cyber security](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") among businesses and individuals.

Organisations should capitalise on the increased exposure of cybercrime to educate employees on best practices, and foster discussions about issues such as [social engineering](https://www.financedigest.com/united-bulgarian-bank-selects-onespan-to-help-fight-social-engineering-and-mobile-malware-attacks.html "United Bulgarian Bank Selects OneSpan to Help Fight Social Engineering and Mobile Malware Attacks"). Build upon these experiences with interactive training so users can better protect themselves, and in turn prevent the compromise of credentials or endpoints.

The increased awareness of security only serves to add to the [cybersecurity](https://www.financedigest.com/privacy-vs-security-is-the-cybersecurity-information-sharing-act-beneficial.html "PRIVACY VS SECURITY: IS THE CYBERSECURITY INFORMATION SHARING ACT BENEFICIAL?") skills shortage as security mature organisations with limitless budget ramp up their hiring policies to improve their programs. Smaller enterprises and SMBs can address the shortage by augmenting their [security teams with managed services](https://www.financedigest.com/managing-the-hidden-security-gap-in-financial-services-the-office-printer.html "MANAGING THE HIDDEN SECURITY GAP IN FINANCIAL SERVICES: THE OFFICE PRINTER") such as MDR. Utilising managed [services does not relinquish control or responsibility but are opportunities to hand off trivial or specialist tasks that your organisation](https://www.financedigest.com/cloud-migration-for-financial-services-organisations-whats-the-best-approach.html "Cloud Migration for Financial Services Organisations – What’s the best approach?") does not have the people, processes or time for. The augmentation of your team with [managed services should allow your staff](https://www.financedigest.com/edf-staff-shareholders-file-complaint-over-management.html "EDF staff, shareholders file complaint over management") to focus on daily operations of dev/sec/ops, knowing someone is watching over your shoulder to alert and direct you, when it really matters.

**Cloud**

User error persists as one of the top patterns in cloud-based breaches. Despite the presence of public [cloud for over 10 years, user errors’ prevalence has been on a steady incline and Gartner predicts that 99% of cloud security](https://www.financedigest.com/cloud-security-and-the-department-of-go.html "Cloud security and the ‘department of go’") failures will be the user’s fault by 2025. \* Although the 99% figure is likely hyperbole, the sentiment rings true. Public Cloud providers operate on a shared responsibility principle, where the cloud provider is responsible for the [security](https://www.financedigest.com/assurance-v-security-reassessing-responsibility-for-data-assurance.html "Assurance v Security: Reassessing Responsibility for Data Assurance") **of** the cloud but users must take responsibility for what they deploy **in** the cloud. Public cloud providers have made consistent improvements to the [security](https://www.financedigest.com/how-cloud-is-driving-forward-implementation-of-zero-trust-security.html "How Cloud is Driving Forward Implementation of Zero Trust Security") of the cloud but the same is not true for the average user, in the cloud.

The transition towards facilitating [remote and hybrid working](https://www.financedigest.com/7-tips-for-building-a-positive-remote-work-culture.html "7 tips for building a positive remote work culture") models has added fuel to this fire. Some [organisations have prioritised speed and agility](https://www.financedigest.com/how-the-cfo-can-embrace-organisational-agility.html "How the CFO can embrace organisational agility"), including undertaking cloud migrations of certain workloads, often at the expense of implementing appropriate security controls. Consider an example where an IT admin is tasked with getting on premise workloads into the [public cloud](https://www.financedigest.com/the-new-fangled-normal-of-working-from-home-to-push-the-public-cloud-service-market.html "The “New-Fangled” Normal of “Working from Home” to Push the Public Cloud Service Market") space. The quickest way to achieve this is by undertaking a lift and shift exercise and copying the on-premise app onto IaaS. Not only is this a sub-optimal use of the advantages of [cloud computing](https://www.financedigest.com/the-value-of-cloud-computing.html "The Value of Cloud Computing") but it is also the least secure. Suddenly the application which used to sit behind [layers of firewalls and other security](https://www.financedigest.com/password-layering-security-modern-banking.html "More Than a Password: Layering Security in Modern Banking") controls is exposed publicly. Any default passwords or unpatched vulnerabilities which may not have been accessible in the layers of the datacentre are can now be exploited.

This scenario is all too common. Verizon performed a scan of public [facing assets](https://www.financedigest.com/analysis-investors-face-expensive-quest-for-year-end-cash-and-safe-assets.html "Analysis-Investors face expensive quest for year-end cash and safe assets") and found that ~40% had unpatched vulnerabilities disclosed between 2017 to 2006.\*\*   Without a clear migration and modernization strategy, the admin falls back on all that they know – processes and policy built for data centre deployments. Cloud native security tools or managed [services](https://www.financedigest.com/wrapping-financial-services-in-a-security-blanket.html "Wrapping Financial Services in a Security Blanket") exist to address some or all of your cloud security responsibilities. While cloud providers implement some controls greenfield, like AWS preventing public S3 buckets by default, the majority must be configured and maintained by the user. It is important that decision makers [know what security](https://www.financedigest.com/safe-and-secure-payments-for-customers-what-businesses-need-to-know.html "Safe and secure payments for customers – what businesses need to know") controls are suited to their threat model.

**Strategy**

[Organisations must take a forward-thinking approach to public cloud](https://www.financedigest.com/embracing-cloud-computing-how-and-why-organisations-are-set-to-invest-more-in-cloud-computing-in-2023.html "Embracing Cloud Computing: How and why organisations are set to invest more in cloud computing in 2023") and hybrid environments. First identify the reason(s) for moving to the cloud. Common drivers are efficiency, agility, accessibility and moving to OpEx. Then build an adoption policy around the three principles of migration, modernisation and optimisation. [Security needs](https://www.financedigest.com/the-financial-services-industry-needs-to-get-serious-about-cyber-security-in-the-covid-19-era.html "The financial services industry needs to get serious about cyber security in the Covid-19 era") to be addressed at each stage, and a phased approach makes this manageable. For example, Google’s Zero-trust should be an end goal, but identify areas where you can crawl, walk and then run. Multicloud is becoming increasingly popular as certain provider’s services are optimal for different outcomes, so while multicloud makes best use of the benefits of Cloud, it adds complexity because it requires [expertise to secure](https://www.financedigest.com/emvco-and-pci-ssc-combine-expertise-on-3-d-secure-2-0.html "EMVCo and PCI SSC Combine Expertise on 3-D Secure 2.0") and manage multiple IaaS platforms. If possible, consider a staged [migration into each and ensure that you have adequate visibility across all clouds](https://www.financedigest.com/cloud-migration-key-considerations-for-financial-services.html "Cloud migration: Key considerations for financial services") in a centralised tool.

**[Financial Organisations](https://www.financedigest.com/tackling-the-complexity-of-data-within-financial-organisations.html "Tackling the complexity of data within financial organisations") will continue to be the most targeted.**

With the primary motivation of breaches being financial, it is no surprise that the majority of attacks are made against [financial organisations](https://www.financedigest.com/double-and-triple-extortion-tactics-cornering-financial-services-organisations.html "Double and triple extortion tactics cornering financial services organisations "). Out of the customers that Alert Logic secures, it is the Fin-Techs that generate the highest proportion of incidents, and this trend has been echoed across the Threat [Detection and Response](https://www.financedigest.com/endpoint-detection-and-response-market-is-projected-to-expand-at-a-cagr-of-21-from-2020-to-2030-tmr.html "Endpoint Detection and Response Market Is Projected To Expand At A CAGR of 21% from 2020 To 2030 | TMR") (TDR) industry. [Financial organisations need](https://www.financedigest.com/cfos-need-a-focus-on-forex-in-financial-planning-tools-accountagility-reveals.html "CFOs need a focus on forex in financial planning tools, Accountagility reveals") to be aware of the target on their back and act proportionately.

Finally, whatever controls are implemented, each silo must be monitored continuously and IT/Security personnel should be equipped to respond to all threats. EUBA should be used to identify when users behave abnormally, preventive controls should be monitored and endpoint/log/network traffic should be inspected daily.

Compromise must be treated as inevitable, so 24/7 visibility into the actions/configurations/topology of devices and [networks is essential to maintain business](https://www.financedigest.com/the-new-wifi-how-private-5g-networks-could-revolutionise-business.html "The New WiFi? How Private 5G Networks Could Revolutionise Business") continuity. Organisations should evaluate tools such as XDR and SIEM to facilitate holistic visibility and understand what approach is needed. Do you have adequate and capable staff to monitor 24/7/365?  Do you have the staff that can consistently tune security tool set to extract value/actionable insights? Can you utilise threat intelligence to stay ahead of 0-day and emerging threats?

If your answer is “no” to any of the above points, then a managed detection and response approach may be best for you.

\*Is the Cloud Secure?” _Smarter with Gartner_, October 10, 2019

\\*\\* Verizon DBIR 21, Figure 31

**About the Author**

Josh Davies is a Product [Manager at Alert](https://www.financedigest.com/asset-managers-on-alert-after-whatsapp-crackdown-on-banks.html "Asset managers on alert after ‘WhatsApp’ crackdown on banks") Logic. Formerly a Security Analyst and Solutions Architect, Josh has extensive experience working with mid-market and enterprise organisations; conducting incident response and [threat hunting activities as an analyst before working with organisations](https://www.financedigest.com/cyber-threats-for-finance-organisations-to-watch-in-2023.html "Cyber threats for finance organisations to watch in 2023") to identify appropriate security solutions for challenges across cloud, on-premises and hybrid environments.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

