Over Confidence In Cyber Security Training Reduces Financial Security

New research by Threat Detection and Response provider, e2e-assure, reveals an alarming disconnect between cyber risk owners and employees within Financial Services, when it comes to cyber security training. 

Despite most (82%) cyber risk owners in this sector being confident employees are engaged in the training they offer, the majority (69%) of workers said they are either only ‘somewhat engaged’ (55%) or ‘not engaged’ (14%) in the training provided by their organisation.

As the sector undergoes digital transformation, and operational efficiencies are increasingly pushed for, staff are experimenting with new tooling to increase their productivity. As a result, most cyber risk owners (76%) are feeling either “very concerned” (25%) or “somewhat concerned” (51%) about the use of AI within their organisation. 
Over one in four cyber risk owners (43%) said their biggest frustration with employees was the use of unauthorised software

The research also found that although most cyber risk owners (80%) are confident in the AI polices they have introduced, there is a clear disconnect between the confidence in these policies and employee understanding. 

  • One in five (20%) of employees stated their company has policies, but admitted they don’t know what they are, and 17% have no idea whether their company has them. 
  • Comparing this year’s findings to e2e-assure’s 2023 research, although 49% of cyber risk owners in Financial Services say resilience is at the top of their agenda this year, up from 34%, speed is now the top priority for the majority (57%).  

This focus on speed over resilience, could suggest that the sector has a closer eye on external threats, jeopardising previous resilience gains if left unchecked.  

  • The research showed that when cyber attacks happen, 43% of Financial Services employees receive a disciplinary and training if they cause a breach, the highest out of all the sectors surveyed. In addition, while 37% have witnessed cyber security incidents happen, only 14% have reported them to IT.
  • But despite cyber risk owners’ confidence in training and AI policies being rolled out, employees revealed the training they are receiving isn’t cutting through, with the vast majority (69%) either only ‘somewhat engaged’ (55%) or ‘not engaged’ (14%) in the training provided by their company.  

In a sector for which speed is of utmost importance, this approach could ironically be slowing companies down, with breaches being framed as individual failures, and employees afraid to report cyber malpractice due to a reactive focus on disciplinaries.   

The data also highlights how cyber risk owners’ confidence in training programmes may be causing them to overlook gaps in the process. The research revealed employees are not receiving the style of training that resonates with them.

Employees in this sector are less likely to receive real-life scenario training (39%), despite a huge majority (82%) of workers stating they would be more engaged if they did. Rob Demain, Founder and CEO at e2e-assure, said: 
“Our research paints a picture of a sector that is overly focused on external threats, rather than fully understanding the risks from within such as employees being unaware of AI policies and therefore using unauthorised software that could jeopardise a company’s security... This sector’s reactive approach to cyber defence and employee training, perhaps understandable in an industry which prioritises speed due to high stakes, is having the unintended consequence of increasing cyber risk...   

“Data attacks such as phishing are becoming more frequent in the Financial Services sector. To ensure future resilience, cyber risk owners must turn their attention to how to mitigate this risk through effective, tailored employee training.” 

The findings show it’s vital for cyber risk owners to start looking at their resilience picture from the ground up, with four key recommendations emerging: 

  1. Tailor training to engage employees 
  2. Create a security awareness culture 
  3. Use automation to reduce human error 
  4. Have the right provider in place 

To read the full report, click HERE:- 

Image: Ideogram

You Might Also Read:

Boards Need To Step Up Or Risk Cybersecurity Fines:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« Turning The Weakest Link Into Cybersecurity’s Strongest Line Of Defence 
British Spy Agency Opens A New Cyber Centre »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Nullcon

Nullcon

Nullcon provides an integrated platform for exchanging information on the latest attack vectors, zero-day vulnerabilities and unknown threats.

Omada

Omada

Omada is a leading provider of IT security solutions and services for identity management and access governance.

Advens

Advens

Advens is a company specializing in information security management. We provide Consultancy, Security Audits and Technology Solutions.

Farsight Security

Farsight Security

Farsight Security provides the world’s largest real-time actionable threat intelligence on how the Internet is changing.

NeuroChain

NeuroChain

NeuroChain is an intelligent ecosystem that is more secure, more reliable and much faster than blockchain.

Cloudsine

Cloudsine

Cloudsine (formerly Banff Cyber Technologies) is a cloud technology company specializing in cloud adoption, security and innovation.

oneclick

oneclick

oneclick is a central access and distribution platform in the cloud, enabling the management of the entire technology stack for application provisioning.

Spin Technology

Spin Technology

SpinOne is a SaaS data protection platform designed to monitor, secure, and back up your G Suite and O365 data, improve compliance, and reduce IT costs.

CentricalCyber

CentricalCyber

CentricalCyber is a cyber risk consultancy and NIST CSF specialist set up to help business leaders better understand and manage cyber risk.

Realsec

Realsec

RealSec is an international company and is a developer of encryption and digital signature systems and Blockchain for the Banking and Methods of Payment sectors, Government and Defense and Multisector

Siege Technologies

Siege Technologies

Siege Technologies is a pioneer of multi-purpose cybersecurity products and services that enable customers to leverage both offensive and defensive technologies.

Sevco Security

Sevco Security

Sevco Delivers Real-time Asset Intelligence to Identify and Close Unknown Security Gaps.

Picnic

Picnic

Picnic is a gritty, pioneering team of intelligence and cybersecurity specialists focused on solving the security challenge of our time - social engineering.

Ballistic Ventures

Ballistic Ventures

Ballistic Ventures is a new kind of venture capital firm, built by and for cybersecurity entrepreneurs and investors.

InfoTrust

InfoTrust

InfoTrust is a leading specialised cybersecurity practice that combines a customer-first consulting approach with next-generation security solutions.

Amtivo Ireland

Amtivo Ireland

Amtivo Ireland (formerly Certification Europe and EQA) offers a range of certifications and related services.