Financial firms 'prone to lax cyber security practices'

A third of financial organisations discovered sensitive or regulated customer data outside of designated secure locations in the past 12 months, according to new research finding that financial services firms are prone to a range of insufficient cyber security controls that make them vulnerable to escalating cyber threats.

Netwrix surveyed 102 financial organisations, revealing that 40 per cent of respondents admitted that in the last year, while their IT teams granted direct access to sensitive data based solely on a user’s request.

On top of that, IT teams are overloaded with addressing data subject access requests (SARs) as a part of General Data Protection Regulation (GDPR) compliance, since 73 per cent of respondents report that DSARs put significant or moderate pressure on IT staff.

The research also showed that 70 per cent of unauthorised data sharing incidents led to data compromise, while 32 per cent of financial organisations have experienced a surge in SARs.

Meanwhile, 44 per cent of chief information security officers or chief information officers did not have or did not know whether they had key performance indicators to report on IT security and cyber risk.

“As the COVID-19 pandemic accelerates the rise of digital payments, financial organisations are generating more and more data, which makes the sector a tempting target for cyber criminals," said Ilia Sotnikov, vice president of product management at Netwrix.

"Poor access management practices and lack of control over sensitive data make the sector vulnerable to these increasing threats - organisations need to mitigate security risks by deploying technologies that enable them to regularly review and correct access permissions as well as to automatically discover their sensitive data enterprise-wide regardless of where it is located, and to move it to a secured storage."

    Share Story:

Recent Stories


Safeguarding economies: DNFBPs' role in AML and CTF compliance explained
Join FStech editor Jonathan Easton, NICE Actimize's Adam McLaughlin and Graham Mackenzie of the Law Society of Scotland as they look at the role Designated Non-Financial Businesses and Professions (DNFBPs) play in the financial sector, and the challenges they face in complying with anti-money laundering and counter-terrorist financing regulations.

Ransomware and beyond: Enhancing cyber threat awareness in the financial sector
Join FStech editor Jonathan Easton and Proofpoint cybersecurity strategist Matt Cooke as they discuss the findings of the State of the Phish 2023 report, diving into key topics such as awareness of cyber threats, the sophisticated techniques being used by criminals to target the financial sector, and how financial institutions can take a proactive approach to educating both their employees and their customers.

Click here to read the 2023 State of the Phish report from Proofpoint.

Cracking down on fraud
In this webinar a panel of expert speakers explored the ways in which high-volume PSPs and FinTechs are preventing fraud while providing a seamless customer experience.

Future of Planning, Budgeting, Forecasting, and Reporting
Sage Intacct is excited to present FSN The Modern Finance Forum’s “Future of Planning, Budgeting, Forecasting, and Reporting Global Survey 2022” results. With participation from 450 companies around the globe, the survey results highlight how organisations are developing their core financial processes by 2030.