May 29, 2018 By Douglas Bonderud 2 min read

Financial institutions are prime targets for cybercriminals. According to a February 2018 report from management consulting firm Accenture, the number of breaches in the financial services sector tripled in the last five years. Meanwhile, the Journal of Cyber Policy noted recently that 89 percent of survey respondents say their existing information security (InfoSec) tools and policies don’t meet current needs.

During a recent Senate Banking Committee hearing, witnesses addressed both sides of the issue: the increasing scope of cybersecurity threats facing financial institutions and the steps that can be taken to limit the impact. Ideally? Clearer regulations, more accountability and recognition of critical risk.

Risk Is Our Business? Cybersecurity Threats

Cybercriminals are looking for maximum profit with minimum effort. As banks make the switch from storing physical currency to moving and investing money online, attackers have prioritized financial targets. Bob Sydow, a principal at professional services firm Ernst & Young, was straightforward about the state of financial cybersecurity at the Senate hearing, noted Politico.

“Keeping up with known threats and vulnerabilities is difficult enough, but the scope of unknown cyber risks seems much larger than other, more traditional risk domains,” Sydow said.

Financial institutions must also acknowledge the role of employees in securing or exposing networks to risk. According to Financial News, 58 percent of cyber claims stem from employee behavior, with the financial sector facing the highest annual cost per year for cybercrime — intentional or not.

Thirty-five percent of companies say their data protection policies are “ad hoc or nonexistent” and 12 percent have no breach detection solutions in place, according to Ernst & Young’s latest data, Global Information Security Survey.

It’s clear there’s a gap between current financial InfoSec and practices and the impact of cybersecurity threats.

Industry Investment to Protect Personal Data

According to Forbes, Senate Banking Committee Chair Mike Crapo and his democratic counterpart Sherrod Brown both agree the financial sector needs better legislation when it comes to protecting consumers’ personal data. Brown describes a bill with provisions that hold companies accountable for data loss but doesn’t know exactly what form that would take — although he does say record bank profits could be used for more cybersecurity investment.

During the recent hearing, however, Bill Nelson, president and CEO of the Financial Services Information Sharing and Analysis Center (FS-ISAC) argued that “despite a dynamic and ever-changing cyberthreat environment, the financial sector has invested heavily to protect the sector’s assets and consumers’ information from adversaries and cybercrime,” noted Politico. For Nelson, improved financial sector security includes government action to harmonize conflicting regulations, more cybercrime prosecutions and Congress-defined responses to specific types of cybersecurity threats.

To Spend and Secure

The recent Senate hearing makes it clear: Financial institutions are spending on cybersecurity, but the scope and nature of threats make it difficult to keep up. While more monetary investment remains a priority, increased legislative follow-through and government streamlining of existing regulations also play a critical role in reducing cyber risk.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today