May 29, 2018 By Douglas Bonderud 2 min read

Financial institutions are prime targets for cybercriminals. According to a February 2018 report from management consulting firm Accenture, the number of breaches in the financial services sector tripled in the last five years. Meanwhile, the Journal of Cyber Policy noted recently that 89 percent of survey respondents say their existing information security (InfoSec) tools and policies don’t meet current needs.

During a recent Senate Banking Committee hearing, witnesses addressed both sides of the issue: the increasing scope of cybersecurity threats facing financial institutions and the steps that can be taken to limit the impact. Ideally? Clearer regulations, more accountability and recognition of critical risk.

Risk Is Our Business? Cybersecurity Threats

Cybercriminals are looking for maximum profit with minimum effort. As banks make the switch from storing physical currency to moving and investing money online, attackers have prioritized financial targets. Bob Sydow, a principal at professional services firm Ernst & Young, was straightforward about the state of financial cybersecurity at the Senate hearing, noted Politico.

“Keeping up with known threats and vulnerabilities is difficult enough, but the scope of unknown cyber risks seems much larger than other, more traditional risk domains,” Sydow said.

Financial institutions must also acknowledge the role of employees in securing or exposing networks to risk. According to Financial News, 58 percent of cyber claims stem from employee behavior, with the financial sector facing the highest annual cost per year for cybercrime — intentional or not.

Thirty-five percent of companies say their data protection policies are “ad hoc or nonexistent” and 12 percent have no breach detection solutions in place, according to Ernst & Young’s latest data, Global Information Security Survey.

It’s clear there’s a gap between current financial InfoSec and practices and the impact of cybersecurity threats.

Industry Investment to Protect Personal Data

According to Forbes, Senate Banking Committee Chair Mike Crapo and his democratic counterpart Sherrod Brown both agree the financial sector needs better legislation when it comes to protecting consumers’ personal data. Brown describes a bill with provisions that hold companies accountable for data loss but doesn’t know exactly what form that would take — although he does say record bank profits could be used for more cybersecurity investment.

During the recent hearing, however, Bill Nelson, president and CEO of the Financial Services Information Sharing and Analysis Center (FS-ISAC) argued that “despite a dynamic and ever-changing cyberthreat environment, the financial sector has invested heavily to protect the sector’s assets and consumers’ information from adversaries and cybercrime,” noted Politico. For Nelson, improved financial sector security includes government action to harmonize conflicting regulations, more cybercrime prosecutions and Congress-defined responses to specific types of cybersecurity threats.

To Spend and Secure

The recent Senate hearing makes it clear: Financial institutions are spending on cybersecurity, but the scope and nature of threats make it difficult to keep up. While more monetary investment remains a priority, increased legislative follow-through and government streamlining of existing regulations also play a critical role in reducing cyber risk.

More from

Black Friday Chaos: The Return of Gozi Malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America.The Black Friday connectionBlack Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity and often…

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Testing the limits of generative AI: How red teaming exposes vulnerabilities in AI models

4 min read - With generative artificial intelligence (gen AI) on the frontlines of information security, red teams play an essential role in identifying vulnerabilities that others can overlook.With the average cost of a data breach reaching an all-time high of $4.88 million in 2024, businesses need to know exactly where their vulnerabilities lie. Given the remarkable pace at which they’re adopting gen AI, there’s a good chance that some of those vulnerabilities lie in AI models themselves — or the data used to…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today