# Three areas of focus for Financial Service CISOs in 2022
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-03-04
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: How Financial Institutions Can Combat Ransomware Attacks in
Meta Description: Learn why ransomware attacks on financial institutions have increased by 1,300%, costing an average of $2.1 million. Discover cyber threat mitigation strategies for 2022.
URL: https://financedigest.com/three-areas-of-focus-for-financial-service-cisos-in-2022html

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-1304484797-1736816003476-compressed.jpg)

_By_ **_James Mingard,_** _Head of Retail & Finance at Maintel_

Research suggests there has been a [1,300% increase in ransomware attacks on financial institutions](http://www.scmagazine.com/analysis/managed-security/cyber-struggles-for-finance-sector-may-get-worse-in-2022), with the National Cyber Security Centre (NSCS) reporting that [over a third of financial services firms were hit by ransomware](https://www.ncsc.gov.uk/report/weekly-threat-report-17th-september-2021) in the last year – with attacks costing an average of $2.1 million.

Such weaponry is easily accessible to even the most junior of cybercriminals who can engage underground ransomware-as-a-service almost as easily as any everyday SaaS solution. As such there are thousands of computers scanning every internet-connected machine for [vulnerabilities](https://www.maintel.co.uk/vulnerability-management-understanding-the-benefit-of-regular-application-and-infrastructure-testing/), and too often, they are easily found. For example, in March 2021, Microsoft revealed the exploitation of ‘zero-day’ vulnerabilities in its popular Exchange software, which was being could be used as a cypher for ransomware. The [bottom line](https://www.financedigest.com/why-investing-in-wellbeing-can-boost-your-bottom-line.html "Why investing in wellbeing can boost your bottom line") is that no organisation is safe.

With the pandemic only [increasing the number of attacks levelled at financial services](https://www.institutionalassetmanager.co.uk/2021/03/02/296548/data-extortion-ransomware-attacks-financial-sector-350-cent-during-covid-19), this year must see cyber threat mitigation rise to the top of board priorities – not just in terms of the potential for financial loss. In the event of an attack, the [Chief Information Security Officer](https://www.financedigest.com/tips-for-choosing-the-right-chief-finance-officer-for-your-business.html "Tips for Choosing the Right Chief Finance Officer for Your Business") (CISO) will have to answer for the loss of productivity, reputation and growing consumer concern around data privacy and the raft of laws that now govern this. There are three focus points CISO’s will [need to consider](https://www.financedigest.com/7-finance-career-options-to-consider-and-what-you-need-to-know-about-each.html "7 Finance Career Options to Consider and What You Need to Know About Each") to ensure minimal risk and maximum preparedness in 2022.

**1 – Zero compromise on Zero Trust**

If they haven’t already CISOs must adopt a [Zero Trust](https://www.ncsc.gov.uk/collection/zero-trust-architecture) mantra and instil this across the organisation.  AsPwCputs it, ‘Start by assuming that your users are already compromised’. Least-privilege access combined with behaviour monitoring must become ubiquitous, with NCSC urging companies to [choose services designed for zero trust](https://www.ncsc.gov.uk/collection/zero-trust-architecture). New services such as PAM – Privilege Access Management – will be increasingly integrated into Zero [Trust solutions](https://www.financedigest.com/exact-launches-practice-management-solution-to-help-transform-accountants-into-trusted-business-advisors.html "Exact launches Practice Management solution to help transform accountants into trusted business advisors"), where user credentials and privileges are finely honed, controlled, and audited.

**2 – [Meet ‘Anywhere working’](https://www.financedigest.com/meetings-in-the-metaverse-how-likely-is-this-the-future-of-work.html "Meetings in the metaverse – how likely is this the future of work?") with xDR**

With the new ‘office anywhere’ working model, Endpoint Detect and Respond, which brings enormous value, must now [evolve to support](https://www.financedigest.com/how-banks-will-evolve-to-support-small-business-owners.html "How banks will evolve to support small business owners") and secure the hybrid workforce. The evolution of the wider [network fabric means that next-level eXtended](https://www.financedigest.com/hermes-extends-parcelshop-network-with-doddle-locations.html "HERMES EXTENDS PARCELSHOP NETWORK WITH DODDLE LOCATIONS") Detect and Respond (XDR) solutions are really the only option. XDR is no longer a buzzword. As [Forrester Analyst, Allie Mellen](https://www.forrester.com/blogs/xdr-defined-giving-meaning-to-extended-detection-and-response/?utm_source=zdnet&utm_medium=pr&utm_campaign=sr) explains:

_‘The evolution of EDR, optimises threat detection, investigation, response, and hunting in real-time. XDR unifies security-relevant endpoint detections with telemetry from security and business tools such as network analysis and visibility (NAV), email security, identity and access management, [cloud security](https://www.financedigest.com/cloud-security-and-the-department-of-go.html "Cloud security and the ‘department of go’"), and more. It is a cloud-native platform built on [big data](https://www.financedigest.com/how-big-data-is-sending-shockwaves-through-the-financial-services-sector.html "How big data is sending shockwaves through the financial services sector") infrastructure to provide security teams with flexibility, scalability, and opportunities for automation.’_

The XDR multi-layered (but, crucially, avoiding siloing) approach has the potential to match the multi-faceted, ever-more [creative attacks launched](https://www.financedigest.com/automated-creative-launches-in-the-us-and-canada.html "Automated Creative launches in the US and Canada") by bad actors. It is a way to uncover the unknown [gaps waiting to be exploited, and new gaps brought about by new working](https://www.financedigest.com/how-has-hybrid-working-impacted-the-gender-gap.html "How has hybrid working impacted the gender gap?") cultures. As highlighted by the [Enterprise Strategy Group](https://www.darkreading.com/vulnerabilities-threats/the-realities-of-extended-detection-and-response-xdr-technology), 70% of organisations reported to them that an XDR budget would be set aside within the next 12 months. Nearly one-fifth reported an existing XDR project — for example, integrating EDR and network [detection and response](https://www.financedigest.com/endpoint-detection-and-response-market-is-projected-to-expand-at-a-cagr-of-21-from-2020-to-2030-tmr.html "Endpoint Detection and Response Market Is Projected To Expand At A CAGR of 21% from 2020 To 2030 | TMR") tools. It’s clear. XDR isn’t a passing fad, it’s not even the future. It’s the solution needed here and now.

**3 – The rise of the ‘R’**

Of course, approaches like XDR will continue to use novel applications of AI and ML to [improve detection](https://www.financedigest.com/fico-machine-learning-algorithms-improve-card-not-present-fraud-detection-by-30.html "FICO Machine Learning Algorithms Improve Card-Not-Present Fraud Detection by 30%") accuracy and provide a faster, more efficient incident response.  The rise of the ‘R’ or Respond will be a [key differentiator and as the liabilities grow](https://www.financedigest.com/determination-and-innovation-the-key-for-fast-growing-uc-firm.html "Determination and Innovation the Key for Fast Growing UC Firm"), being able to react to IOC’s – Indicators of Compromise – could mean success or failure. As research published in the [Journal of Cybersecurity and Privacy](https://www.mdpi.com/2624-800X/1/1/8?type=check_update&version=2) explored, ‘traditional indicators of compromise may not always capture the breath or essence of a cyber security threat or attack campaign, possibly leading to false alert fatigue and missed detections with security analysts’.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

