Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


02:00 PM
Ed Bellis
Ed Bellis
Connect Directly
E-Mail vvv

Why Compliance Is No Longer King for Financial Services Cybersecurity

Financial services companies' experience in risk management serves them well when it comes to minimizing their cyber-risk.

Financial services has long been a compliance-driven industry. Nearly everything a bank or an investment adviser does is governed by some regulation. Usually, these rules are in place for consumer protection, but the rules the industry must follow extend to cybersecurity as well.

Unfortunately, auditors and other professionals tasked with compliance have historically developed their cybersecurity procedures in the dark. They don't always have a great view of what truly reduces risk to the organization. There's a box-checking mentality meant to assure regulators that cybersecurity procedures are in place, even when there's little guarantee that the procedures being audited add up to a secure environment.

Related Content:

A Call for Change in Physical Security

The Changing Face of Threat Intelligence

ISP Security: Do We Expect Too Much?

In the field of patching vulnerabilities, for example, compliance rules tend to force companies into closing security holes that pose little risk. And that's a problem, because there is no company on the planet with the resources to fix every vulnerability on its systems.

Fortunately, the finance sector has broad experience in risk management, and more and more of these companies are adopting risk-based vulnerability management approaches that rely on objective data rather than aged "best practices."

These two countervailing observations raise important questions. Are financial services companies investing their cybersecurity resources in the right areas? Are they truly reducing cybersecurity risk while still maintaining compliance?

How Financial Services Stacks Up
New research conducted by the Cyentia Institute and Kenna Security is providing important answers to these questions.

At first glance, Cyentia's research shows that financial services companies have big challenges. On average, financial institutions have four times more security vulnerabilities than companies in other industries. But thinking this through, it's not too surprising. The footprint of assets for these firms is not only large but made up of many general-purpose computing devices, which make them ripe for a wide array of vulnerabilities.

But as we have seen in previous research, not every vulnerability poses a significant risk. In fact, we see exploitation activity for only about 5% of these vulnerabilities "in the wild." This is good news because, on average, a typical company can fix just one out of 10 vulnerabilities.

In aggregate, the financial services sector does particularly well in focusing on high-risk vulnerabilities, patching nearly 85% of them. And some companies do better than others. That's impressive given their large digital footprint, especially noting that financial services outperformed most industries in our research.

Risk management is in the DNA of most financial services companies, and that accounts for much of their success in this area. We know that attackers tend to follow well-worn paths, reusing tools and abusing the same security gaps over and over. They often focus on certain operating systems and certain software publishers because they have higher market penetration. Likewise, they also tend to focus their efforts on a select group of vulnerabilities that can be leveraged for profit. 

Using tools and data science, companies can identify which vulnerabilities are more likely than not to be exploited by hackers. Risk-based vulnerability management programs are tailored to tackling these vulnerabilities first. 

This is all to say that tides are changing in financial services' security practices, and this is reason for optimism. What was once a pure focus on compliance is now shifting. More and more organizations are adopting better practices to improve security and lower risk, as Cyentia's data reflects. 

On the whole, the financial services industry does an impressive job of managing vulnerability risk. If they are as good at other cybersecurity disciplines as they are at vulnerability management, there's reason to be optimistic. Cybersecurity is often regarded as an expense rather than an investment, but done right, chaotic practices that never seem adequate can evolve into well-managed programs that provide real value for organizations.

Ed Bellis is a security industry veteran and expert and was once named Information Security Executive of the Year. He founded Kenna Security to deliver a data-driven, risk-based approach to remediation and help IT teams prioritize and thwart would-be security threats. Ed is ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Cyberattacks Are Tailored to Employees ... Why Isn't Security Training?
Tim Sadler, CEO and co-founder of Tessian,  6/17/2021
7 Powerful Cybersecurity Skills the Energy Sector Needs Most
Pam Baker, Contributing Writer,  6/22/2021
Microsoft Disrupts Large-Scale BEC Campaign Across Web Services
Kelly Sheridan, Staff Editor, Dark Reading,  6/15/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-06-23
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.
PUBLISHED: 2021-06-23
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
PUBLISHED: 2021-06-23
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.
PUBLISHED: 2021-06-23
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.
PUBLISHED: 2021-06-23
Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive information via unspecified vectors.