# The financial services industry needs to get serious about cyber security in the Covid-19 era
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2020-12-30
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Financial Services Cybersecurity Risks in the Covid-19 Era
Meta Description: Learn about the increasing cyber risks faced by financial services organisations during the Covid-19 era, as analysed by Anurag Kahol, CTO at Bitglass.
URL: https://financedigest.com/the-financial-services-industry-needs-to-get-serious-about-cyber-security-in-the-covid-19-erahtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/business-man-engineer-in-data-center-server-roomzjpfjksd-scaled-1736838659480-compressed.jpg)

_By **Anurag Kahol,** CTO at_ [_Bitglass_](https://www.bitglass.com/)

In the Covid-19 era, cyber risks are ever-increasing. Not only has there been a massive acceleration of business and digital transformation, but the attack surface has also expanded rapidly due to the vast number of people working from home. Put simply, the pressure is on businesses to get a better handle on cybersecurity – and this is especially true of the financial services industry.

Cybercriminals go where the money is. And, whilst [financial institutions may vary wildly in terms of the services](https://www.financedigest.com/can-financial-services-brands-ever-be-credible-on-social.html "Can financial services brands ever be credible on social? ") they offer, one thing they all have in common is the high volume of personally identifiable information (PII) that they collect from customers. High [value data](https://www.financedigest.com/three-ways-data-unlocks-business-value-for-financial-organisations.html "Three Ways Data Unlocks Business Value for Financial Organisations ") such as home addresses, financial histories and bank details are an extremely attractive target for cybercriminals. which is why financial [services organisations must](https://www.financedigest.com/financial-services-must-lead-the-charge-in-the-re-skilling-revolution.html "Financial Services must lead the charge in the re-skilling revolution") take significant steps to ensure it remains protected at all times. However, this begs the question, does the [industry take its security responsibilities](https://www.financedigest.com/corporate-social-responsibility-within-the-festival-industry.html "Corporate Social Responsibility Within The Festival Industry") seriously enough?

In a recent pre-Covid study, Bitglass set out to uncover the state of cybersecurity within the financial services industry, compiling data from the [Identity Theft Resource Center (ITRC)](https://www.idtheftcenter.org/) and the [Ponemon Institute](https://www.ponemon.org/). They drew a wide range of insights about the financial breaches that have occurred in the twelve months leading up to the pandemic – enabling us to reflect on the need to bolster [cybersecurity in the Covid-19](https://www.financedigest.com/the-aftermath-of-covid-19-cybersecurity-crisis-have-the-attacks-benefitted-the-industry-more-than-they-hurt-it.html "The Aftermath of COVID-19 Cybersecurity Crisis: Have The Attacks Benefitted the Industry More Than They Hurt It?") era.

**Growing concerns**

In total, only 6.5 percent of all [data breaches](https://www.financedigest.com/when-not-if-why-a-data-breach-response-plan-is-more-important-now-than-ever.html "When not if: why a data breach response plan is more important now than ever") that occurred in the 12 months leading up to the pandemic were suffered by financial services organisations – but that doesn’t tell the whole story. That 6.5 percent of breaches accounted for a massive 61.7 percent of all leaked records. This shows that while financial [services](https://www.financedigest.com/integrated-finance-the-advantages-of-using-financial-infrastructure-as-a-service.html "Integrated Finance: the advantages of using financial-infrastructure-as-a-service") organisations don’t suffer breaches particularly often, when breaches do occur, they tend to be much larger and more detrimental than those experienced by companies in other industries.

However, the number of breaches has rapidly increased during Covid-19. Indeed, between February and April 2020, [cyber attacks](https://www.carbonblack.com/resources/modern-bank-heists-2020/) against financial institutions rose by 238 percent, meaning the threat level has heightened considerably.

**The [biggest threats](https://www.financedigest.com/credit-squeeze-biggest-threat-to-economic-outlook-fidelity-international-says.html "Credit squeeze ‘biggest threat’ to economic outlook, Fidelity International says")**

![Anurag Kahol](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/anurag-kahol-bitglass-1-450x675-1736838658972-compressed.jpg)

Anurag Kahol

As malware continues to evolve, it’s becoming increasingly difficult to detect and block. Consequently, the financial services industry [must learn to defend against this ever-growing threat by deploying the right security](https://www.financedigest.com/why-the-finance-sector-must-prioritise-mobile-security-over-innovation.html "Why the finance sector must prioritise mobile security over innovation") tools.

Hacking and malware remained the biggest causes of data breaches in the financial [services sector](https://www.financedigest.com/how-communication-technology-can-help-relieve-pressure-on-staff-in-the-financial-services-sector.html "How communication technology can help relieve pressure on staff in the financial services sector ") by far, in the lead up to the pandemic. They were responsible for 75 percent of all incidents (up slightly from 73.5 percent in 2018). Additionally, insider threats grew from 2.9 percent in 2018 to 5.5 percent in 2020 and accidental disclosures increased from 14.7 percent to 18.2 percent.

Furthermore, the Covid-19 coronavirus pandemic has prompted [an acceleration](https://www.snowsoftware.com/company/news/cloud-use-surges-even-businesses-plan-return-workplace-finds-new-snow-software-survey) in the adoption of cloud technologies by IT leaders worldwide, which looks set to continue for the foreseeable future. Unfortunately, for organisations that struggle with implementing proper security measures, [rising cloud](https://www.financedigest.com/european-banks-cash-in-on-rising-rates-as-clouds-gather.html "European banks cash in on rising rates as clouds gather") adoption will likely only exacerbate these threats. When proper security is not in place, cloud and mobile represent new attack vectors to threat actors.

**[Learn your lesson](https://www.financedigest.com/tripling-the-size-of-my-business-in-the-pandemic-the-mistakes-made-and-lessons-learned.html "Tripling the Size of my Business in the Pandemic — The Mistakes Made and Lessons Learned"), before it’s too late**

Maintaining proper visibility and control over data can be challenging – particularly when the appropriate [cloud and mobile security](https://www.financedigest.com/cloud-security-and-the-department-of-go.html "Cloud security and the ‘department of go’") solutions are not put in place. Global [cloud adoption](https://pages.bitglass.com/CD-FY19Q4theCloudAdoptionReportof2019_LP.html) has reached 86 percent and [bring your own device (BYOD)](https://pages.bitglass.com/MissionImpossibleSecuringBYOD_LP.html) policies have found their way into 85 percent of organisations. Regardless, financial services organisations [need to be more cognizant of how their data](https://www.financedigest.com/the-four-pillars-of-data-integrity-what-finance-businesses-need-to-know.html "The four pillars of data integrity: what finance businesses need to know") is being used. Unfortunately, some organisations are still not [learning their lessons](https://www.financedigest.com/aml-and-identity-checks-lessons-learned-from-the-natwest-case.html "AML and identity checks: Lessons learned from the NatWest case ."). Consequently, they are suffering from a worryingly high number of recurring breaches. Even highly-reputable banks can be found at the centre of unenviable, record-breaking breach statistics, like Capital One, which suffered four in the last seven years.

**A greater cost**

The bad news for financial services organisations is that the cost per compromised record has been steadily increasing over the last few [years](https://www.financedigest.com/is-2022-the-year-green-finance-incorporates-climate-risk.html "Is 2022 the year green finance incorporates climate risk?"), both for regular breaches as well as mega breaches (i.e. those affecting 100 million individuals or more). The 2019 cost per breached record for mega breaches is now much greater than that of average breaches, with figures standing at $388 and $210, respectively. Additionally, Ponemon notes that the cost per compromised record within financial services now exceeds that of all other [industries](https://www.financedigest.com/how-to-drive-a-data-culture-in-the-finance-industry.html "How to drive a data culture in the finance industry") with the exception of healthcare (which was $429). Technology came in third place at $183, while the public sector came in last at $78.

Whether it’s careless users, malicious insiders, evolving malware, advanced phishing schemes, or something else yet to be discovered, modern financial [services organisations face](https://www.financedigest.com/how-advanced-self-service-technologies-are-changing-the-face-of-finance.html "How Advanced Self-Service Technologies are Changing the Face of Finance") an intimidatingly large number of threats- only accelerated by Covid-19. As guardians of some of the most sensitive customer data in any business world, it’s critical that they adopt a proactive approach to data protection and are properly equipped with the latest [security technologies](https://www.financedigest.com/how-open-source-technology-is-securing-the-future-of-financial-services.html "How open-source technology is securing the future of financial services"). Only then can they defend against the [threat agents in the cyber](https://www.financedigest.com/is-the-next-big-cyber-threat-mis-placed-security-spending.html "Is the next big cyber threat mis-placed security spending?") world.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

