# Winning the security race: how financial services can keep pace with cybercriminals
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-02-04
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Protecting Financial Services: Cybersecurity Strategies
Meta Description: Learn how the financial services industry can stay ahead of cybercriminals by implementing key security measures to safeguard valuable data and maintain
URL: https://financedigest.com/winning-the-security-race-how-financial-services-can-keep-pace-with-cybercriminalshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-693643766-1736816259290-compressed.jpg)

_By_ **_Craig Wellman,_** _Director, Financial Services, Microsoft_

As our lives were turned upside-down by the pandemic, cybercriminals acted quickly to exploit the chaos and confusion. Equipped with an emboldened cybercrime economy, attackers have been relentless in their pursuit of personal gain and distribution, demonstrating a willingness to take advantage of a global crisis and use the vulnerability of others to their advantage.

This saw attackers focus on [critical infrastructure](https://www.financedigest.com/hiding-in-plain-sight-finance-as-critical-national-infrastructure.html "Hiding in plain sight – Finance as Critical National Infrastructure") in attempts to cause maximum disruption, and in turn, access lucrative rewards. In fact, [recent research](https://www.computerweekly.com/news/252506646/Cost-of-ransomware-attack-in-financial-sector-exceeds-2m) placed the average cost of a ransomware attack at £1.44mn to financial services organisations, despite the industry being one of the most resilient to attacks. With attackers taking this as their approach and ambition, it’s of no surprise that the [financial services industry was a top target of cybercriminals](https://www.financedigest.com/financial-firms-can-use-technology-combat-todays-cybercriminals.html "How financial firms can use technology to combat today’s cybercriminals") through this period, alongside healthcare and the energy sector.

In fact, the latest [Microsoft Digital Defence Report](https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report) showed that the financial services industry was the second most targeted sector by ransomware through the pandemic, ahead of government, healthcare and education – coming second only to the broad consumer and retail industries.

**The security [landscape for financial services:</b](https://www.financedigest.com/trends-in-the-financial-service-landscape-and-the-impact-on-fraud.html "Trends in the financial service landscape and the impact on fraud") >**

As cybercriminals expanded their arsenal through the pandemic, so too did the organisations defending against their attacks. Alongside accelerating the use of technology to enable [remote working](https://www.financedigest.com/digital-insurance-and-the-remote-working-and-studying-boom.html "Digital insurance and the remote working and studying boom"), came the use of associated security tools and heightened awareness of the security risks associated with remote working. However, as we emerged from periods of near-universal [home working](https://www.financedigest.com/working-from-home-heres-how-you-can-save-money-on-your-auto-insurance.html "Working From Home? Here’s How You Can Save Money on Your Auto Insurance"), new challenges and demands emerged.

A shift from [working at the kitchen table five days a week](https://www.financedigest.com/productivity-and-the-four-day-working-week-in-financial-services.html "Productivity and the four-day working week in financial services"), the new hybrid workplace sees every employee working to their own rhythms – with each individual switching day to day from working in the office, from home, from coffee shops or taking calls on the go.

While supporting newfound freedoms and flexibility for employees, this does create a much more complex environment for security professionals in the industry. Much of these new [challenges come from the conflicts that emerge from balancing the safety of valuable data](https://www.financedigest.com/meeting-the-data-challenge-in-financial-services.html "Meeting the data challenge in financial services") and supporting employees to access the information they need in an efficient way from wherever they may be, critical to ensuring success in the modern financial services industry.

Working in this complex environment, and fending off an increasingly sophisticated opponent, how can the industry stay ahead and keep their [data safe](https://www.financedigest.com/your-money-is-safe-but-your-data-might-not-be.html "YOUR MONEY IS SAFE, BUT YOUR DATA MIGHT NOT BE")? From our [work with customers spanning the financial services industry](https://www.financedigest.com/hybrid-working-a-risk-or-opportunity-for-the-financial-services-industry-2.html "Hybrid working: a risk or opportunity for the financial services industry?") and others, we’ve found that organisations who stick to the following four steps stand the best chance of ensuring the protection of their data.

**1 – Get the fundamentals right**

While it is certainly true that cybercrime has become more sophisticated over time, when it [comes to gaining](https://www.financedigest.com/stocks-shed-gains-treasury-yields-jump-as-fed-signals-rate-hikes-could-come-soon.html "Stocks shed gains, Treasury yields jump as Fed signals rate hikes could come ‘soon’") initial access to your environment attackers are still using tried and tested methods to gain access. For example, over [70% of ransomware attacks](https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report) started with phishing or password sprays, serving as a reminder that maintain high security awareness in your organisation, persisting with phishing training and building rigorous authentication policies is as critical as ever.

In fact, [organisations that maintain the fundamentals of security hygiene are protected](https://www.financedigest.com/protect-your-organisation-from-fraud.html "Protect your organisation from fraud") from 98% of attacks, with much of this work requiring little other than consistency and persistence. Security hygiene, as the name implies, is the hand gel and facemasks of [information security](https://www.financedigest.com/privacy-vs-security-is-the-cybersecurity-information-sharing-act-beneficial.html "PRIVACY VS SECURITY: IS THE CYBERSECURITY INFORMATION SHARING ACT BENEFICIAL?") – constituting multifactor authentication, keeping on top of software updates and applying least privileged access within a network along with a few other routine requirements.

**2 – Act as if you’ve been attacked**

With attackers deploying increasingly sophisticated tools once they gain access to a network, less and less can organisations depend on their reactive response to a breach. Instead, organisations who take a pro-active, zero trust [approach are best positioned to contain and reduce](https://www.financedigest.com/the-importance-of-a-proactive-and-collaborative-approach-to-reducing-contactless-fraud.html "THE IMPORTANCE OF A PROACTIVE AND COLLABORATIVE APPROACH TO REDUCING CONTACTLESS FRAUD") the cost of a breach or malware attack. In practice, this approach is all about taking a lean approach to information access, providing [access to only those employees](https://www.financedigest.com/700000-employees-across-the-uk-have-access-to-fair-finance-will-reach-one-million-employees-in-2017.html "700,000 Employees Across The UK Have Access to Fair Finance, Will Reach One Million Employees in 2017") who absolutely need it, and at only the times that they need access.

As [well as containing more sophisticated attacks](https://www.financedigest.com/tennis-panic-attack-ends-tsurenkos-indian-wells-as-raducanu-marches-on.html "Tennis-Panic attack ends Tsurenko’s Indian wells, as Raducanu marches on"), this approach is critical to reducing another threat we have seen spike through the pandemic – insider risk. Knowingly or not, employees are posing an increased [security risk](https://www.financedigest.com/tesla-to-warn-of-data-privacy-risk-from-car-security-cameras-in-germany.html "Tesla to warn of data privacy risk from car security cameras in Germany") to organisations, particularly as they are now accessing sensitive data away from the office and in a range of environments. Restricting their [access to the information they need](https://www.financedigest.com/what-needs-to-happen-to-improve-the-landscape-for-smes-trying-to-access-finance-options-in-the-uk.html "What needs to happen to improve the landscape for SMEs trying to access finance options in the UK") minimises the risk should an employee accidentally, or purposefully, leak information or data.

**3 – [Utilise the latest tools and technologies](https://www.financedigest.com/how-financial-services-companies-can-successfully-utilise-low-code-and-no-code-technologies.html "How financial services companies can successfully utilise low-code and no-code technologies") to stay ahead**

Thankfully, as cybercriminals have become more sophisticated so to have the tools and technologies we can use to [defend against their attacks](https://www.financedigest.com/banks-can-provide-a-protective-shield-to-defend-customers-from-cyber-attack.html "Banks can provide a protective shield to defend customers from cyber attack"). Machine learning based tools can be used to automatically pinpoint anomalous activity and speed up a response to issues, while analytics tools can help security professionals more effectively identify which of the many alerts they receive should responded to. These tools are most effective when packaged alongside the layered security and multi-factor authentication capabilities supported by the cloud, which come alongside solutions such as Microsoft’s [Cloud for Financial Services](https://cloudblogs.microsoft.com/industry-blog/financial-services/2021/02/24/announcing-microsoft-cloud-for-financial-services/).Such technologies can deliver on the promises of just-in-time and just [enough approaches to security](https://www.financedigest.com/the-challenge-of-keeping-data-secure-why-in-house-security-isnt-enough.html "The challenge of keeping data secure: why in-house security isn’t enough"), while using the power of the cloud to support the industry to make use of the vast data sets it has available and enable employees to access the information they need wherever and whenever they wish.

**4 – Collaborate inside and outside of the industry**

A disparate, loose [network of malicious actors has rapidly become an organised](https://www.financedigest.com/6-steps-to-organising-an-introvert-friendly-networking-event.html "6 Steps to organising an introvert-friendly networking event ") cybercrime economy over the pandemic. It would be unreasonable to expect an individual organisation to combat this threat alone, thankfully there a range of organisations spanning government and the private [sector that a ready and able to support the industry protect its data](https://www.financedigest.com/the-financial-sector-must-act-to-tackle-internal-data-security.html "THE FINANCIAL SECTOR MUST ACT TO TACKLE INTERNAL DATA SECURITY") and respond to live threats. No longer exclusive to major [financial institutions](https://www.financedigest.com/the-future-of-financial-institutions-in-2023.html "The Future of Financial Institutions in 2023"), these partnerships and the tools they provide are available to organisations of any size. For example, UK-based start-up, [Allica Bank](https://customers.microsoft.com/en-us/story/823100-allica-bank), used the Microsoft Cloud to establish its bank within a year. These technologies helped it establish “best-in-class” levels of security as soon as it opened, and as they are based in the cloud, these solutions will scale with Allica [bank as it grows](https://www.financedigest.com/bank-finance-for-cleaner-energy-grows-but-still-lags-fossil-fuels-report.html "Bank finance for cleaner energy grows, but still lags fossil fuels – report").

It’s also critical to use the external support available if something does go wrong. Alongside your technology providers, UK organisations can receive support and guidance from the [National Cyber Security Centre](https://www.ncsc.gov.uk/), who can deliver critical, external guidance if your organisation does fall victim to an attack.

As the industry progresses into 2022, the risk posed by cybercrime is only set to increase, as are the demands on the industry to [innovate at pace](https://www.financedigest.com/2021-predictions-less-fraud-shifting-consumer-behaviour-and-accelerating-pace-of-innovation.html "2021 predictions: less fraud, shifting consumer behaviour and accelerating pace of innovation") and scale, utilising data and information to do so. It is critical that the industry puts strong [security hygiene measures and rigorous data](https://www.financedigest.com/2023-fintech-prediction-secure-and-private-data-usage-is-key.html "2023 FinTech Prediction: Secure and Private Data Usage is Key") governance front of mind, while also understanding which technologies and partnerships can help them fend off the organised and sophisticated threats that are set to emerge in the years ahead.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

