CYBER SECURITY: Banks and other institutions struggle to stay ahead of the cyber threat
New York’s State Department of Financial Services says that although banks are working hard to combat cyber crime, they are struggling to keep up with the pace of change. Rapid changes being forced on them from the competitive pressure to adopt new technologies into their product offerings puts pressure on managements to respond and this pressure is transferred through to staff who are already fully committed defending the current estate. The speed of technological change is testing institutions ability to protect themselves in the face of increasingly sophisticated attacks. The report notes that frequency and sophistication of attacks are growing and that smaller banks, credit unions and vendors are increasingly being targeted. Perps range from foreign nations through to organised criminals and hacktavists. A black market for stolen data means that hackers are not only interested in stealing money from the banks.
Regulators are pressuring banks and other financial firms by upping their oversight. Virtually all regulators are now embarking on a rolling regime intended to test cyber security defences. The regulators are looking particularly at network security, access controls, incident response and third-party vendor management. Crisis management/disaster recovery planning is slowly moving toward the top of the priority list for most institutions as C officers are increasingly held personally responsible for breaches. This will force banks to concentrate on their security systems and, hopefully, start looking at the problems in a more efficient and effective way.
Cyber Security at the banks tends to be heavily IT focused. That is not good. Changes are occurring slowly. This is because, like virtually all corporations, bank managements and boards tend to be full of conservative characters. All this technical stuff sounds fascinating and sexy, but what does it all mean!? They want to use new systems to improve their bottom line, but they don’t really want to change the way they are doing things. They see new IT systems as enhancements to what they do, rather than changing the way that things are done. They usually have limited knowledge of the systems upon which they rely to drive their businesses. To further complicate their problems, the ever more complex array of offerings created by technological advancement creates the need to use outside suppliers and providers. This creates further weaknesses as those thire-party systems are plugged in, thereby creating vulnerabilities. Because third-party vendor systems are seldom controlled by the prime user, any vulnerability at the third-party becomes an unknown and unmeasured vulnerability at the corporation employing that vendor (think Target = $500m loss and 33% drop in stock price).
Most corporations, whether large or small, use a mix of organic and outsourced IT management (only just over 10% rely on entirely outsourced support for their cyber security). Interestingly, whilst all of the institutions covered by the report conduct Penetration Testing (PenTest), almost 80% only do so annually (oh dear!). The rest conduct their tests more frequently but only 4% conduct monthly PenTests. PenTesting is a spot check so it looks like the banks are just using these tests as a ‘check in the box’ activity. Many will restrict PenTest frequency for cost reasons – for these, you might say that paying bonuses are more important than ensuring security!
We question whether the regulators have the ability or capability to conduct all this checking and to understand the data it will garner in the process. Given that there aren’t enough cyber practitioners around just to feed commerce’s need to run and protect their own systems, we wonder whether there will be enough left for the regulators to use. Then there is the ability of commerce and industry (and in particular the banks) to pay more than the regulators for the skills they need. Surely we will end up with regulators which have inferior skills to their charges. That would mean that we have banks which could hide bad things. Given their previous behaviour, can we trust them not to do that? That is very much a suboptimal situation – but that’s another story.
Bronzeye Group has a comprehensive set of programs to help our clients identify, fix and mitigate their cyber vulnerabilities to get ahead of cyber criminals and stay there. Please contact us for advice and assistance.
In the meantime, mind your eye………..











