How Financial Institutions Can Address Their Top Cybersecurity Challenges

Financial institutions are a top focus for cybercriminals for obvious reasons, including the value of the information they hold, and the opportunities bad actors see for large payouts.

According to Verizon’s Data Breach Investigations Report, the financial sector is consistently among the most targeted industries, and the rate of attacks is growing. Banks saw a 238% increase in attacks for 2022 alone. The average data breach in the financial sector costs $5.9 million, which trails only the healthcare sector in average cost, according to IBM’s Cost of a Data Breach Report 2023.

While the industry has made significant strides with cybersecurity, there are countless factors that still make banks and financial institutions attractive targets.

The Challenges Of Protecting Financial Data

Several issues contribute to the difficulties financial institutions face in protecting their assets. One of the most significant is the complexity of the business environment, especially for larger institutions that have undergone mergers and acquisitions. Connecting legacy networks and applications can result in misconfigurations introducing vulnerabilities that provide hackers easy entry.

Financial institutions, like many businesses, also have a more distributed workforce in the wake of the pandemic. As a result, they have had to integrate greater uses of cloud and mobile computing which increases the attack surface. And, despite the implementation of modern, outward-facing applications, it’s not uncommon for banks to have 50-year-old applications  - written in COBOL - running on the back end that are long past the point of being supported. These applications can become risky from a security perspective, but often do not make financial or operational sense to update.

Despite all these risks, most attacks hinge on the human element in the form of identities on the network. Active Directory and the Importance of Identities. User identities play a big part in many cyberattacks, whether breaches result from insider actions, external attacks, or the involvement of third-party partners.

When it comes to identity threats, a malicious insider can cause extensive damage. The most notable example being the 2019 Capital One hack. Almost four years later this particular hack is still widely recognised as one of the greatest insider threats to date. A single insider was responsible for the theft of 100 million customer records, 140,000 Social Security numbers and 80,000 bank details of customers. And a credential compromise from outside an organisation is really just another type of insider threat. Once external attackers gain access by stealing credentials, they operate like a trusted insider.

Third-party risk can also cause severe damage. Most financial institutions have dozens to hundreds of vendors, service providers, and other partners connected to their network. For savvy hackers, a breach in a third-party system can create the perfect jumping off point to enter financial environments.

What's the one similarity these attacks share? The most common avenue for these breaches is Active Directory (AD).

When someone asked Willie Sutton why he robbed banks, he replied, “Because that’s where the money is.” So, why do cybercriminals attack Active Directory? Because that’s where the privileged access is. AD is so tightly woven into most organisations that it’s involved in 9 out of 10 cyberattacks. Microsoft estimates threat actors attack 95 million AD accounts each day, and that’s on the conservative side.

Whether an attacker gains access through phishing or other means, moving to an identity-rich area like Active Directory can allow them to elevate privileges, move across networks, and steal data or launch ransomware attacks. These types of attacks can bring banks and other financial service operations to a halt, preventing access to funds, leaking customer data and causing brand damage.

Breach Preparedness & Other Best Practices

To better protect their data, banks and financial institutions should start with prioritising their risk. They need to accept that breaches will happen, so they must identify their highest-priority assets - those that would cause the most damage if compromised - and the vulnerabilities of those assets.

Breach preparedness begins with an assessment of AD security, along with reviews of an organisation’s security architecture, operational procedures and security configurations. This allows security teams to identify attack paths and develop plans for response and remediation. With thorough assessments of the environment, organisations can develop threat mitigation plans to reduce the attack surface, optimise security configurations and create a thoughtful plan for recovering from an attack that reduces downtime and disruption.

Continually monitoring user identities is also very important. If a lower-level employee suddenly has elevated privileges, is accessing sensitive data they shouldn’t be reviewing, or is operating at odd hours and not performing regular business tasks, there’s a chance their identity is compromised.

Finally, planning should have a human element, in the form of recruiting and retaining security personnel and educating users. Banks and financial institutions must attract and retain knowledgeable security practitioners, which is easier for large institutions to afford. But in organisations of any size, security is a small part of the business. Financial institutions still have hordes of people with limited knowledge of security who are accessing systems and handling sensitive data. As such, employee training and security awareness is essential, especially with an increasing number of remote workers.

The Future Of Financial Sector Security

With the pace and sophistication of attacks on the rise, institutions need to gain visibility into their environments, get control of user identities and develop clear plans for breach preparedness, response and recovery.

Looking forward, financial institutions will also have to confront the risks associated with new threats and challenges with cryptocurrency. As with all forms of security, it comes down to mastering the fundamentals of gaining visibility into and control over the enterprise. 

 Igor Baikalov is Chief Scientist at Semperis

Image: Simon Kadula

You Might Also Read: 

Operational Resilience: More Than Disaster Recovery:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« Five Tips for Securing Your CI/CD Pipeline
Britain Removes Chinese Components From The National Grid »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Spambrella

Spambrella

Spambrella provides email security with real-time threat protection. 100% SaaS (nothing to install)

Ground Labs

Ground Labs

Ground Labs is a security software company dedicated to making sensitive data discovery products that help organisations prevent sensitive data loss.

Global Forum on Cyber Expertise (GFCE)

Global Forum on Cyber Expertise (GFCE)

GFCE is a global platform for countries, international organizations and private companies to exchange best practices and expertise on cyber capacity building.

Identillect Technologies

Identillect Technologies

Identillect Technologies provide a user-friendly secure email solution to protect critical information, with an emphasis on simplicity.

Purple Security

Purple Security

Purple Security arises from the association of specialists in offensive security (ethical hackers, white hats) and experts in insurance, compliance and implementation of industry standards.

Infodas

Infodas

Infodas provides Cybersecurity and IT consulting / system integration services as well as a range of innovative Cybersecurity products to public sector and commercial clients.

SafeCipher

SafeCipher

At SafeCipher, we pride ourselves on being your single vendor-neutral resource for navigating the complexities of cryptographic data encryption.

FCI

FCI

FCI is a NIST-Based Managed Security Service Provider (MSSP) offering Cybersecurity Compliance Enablement Technologies & Services to Financial Services organizations.

Filigran

Filigran

Filigran provides threat intelligence, adversary simulation and crisis response open solutions to thousands of cybersecurity and crisis management teams across the world.

AuthMind

AuthMind

Prevent your next identity-related cyberattack with the AuthMind Identity SecOps Platform. It works anywhere and deploys in minutes.

Yarix

Yarix

Yarix is the leading company in Var Group’s Digital Security division and one of the most recognised, innovative and authoritative Italian companies in the IT security sector.

AI or Not

AI or Not

AI or Not - Leverage AI to combat misinformation and elevate the landscape of compliance solutions.

Aztek

Aztek

Aztek is one of the UK’s leading Managed Service Providers, providing customer-focused IT, Communication and Cyber Security solutions to help transform and grow your business.

Etalon Cyber

Etalon Cyber

Etalon Cyber provides a range of advanced features to ensure the highest level of security for your website.

Office of Cyber Security and Information Assurance (OCSIA) - Isle of Man

Office of Cyber Security and Information Assurance (OCSIA) - Isle of Man

OCSIA acts as the focal point in developing the Isle of Man’s cyber resilience, working in partnership with private and third sector organisations across the Island alongside the wider population.

Blue Networks & Infrastructure (BNI)

Blue Networks & Infrastructure (BNI)

Blue Networks and Infrastructure (BNI) is an innovative systems integrator and managed services provider.