Welcome!

Cloud Security Authors: Zakia Bouachraoui, Pat Romanski, Elizabeth White, Yeshim Deniz, Liz McMillan

Related Topics: @CloudExpo, Cloud Security

@CloudExpo: Blog Post

Financial Institutions Are Vulnerable to Cyber Attacks | @CloudExpo #Cloud #Cybersecurity

The introduction of nascent technologies to improve financial access is also accompanied by increased vulnerability

Financial Institutions are Vulnerable to Cyber Attack as the Increase in Technologies Improves

It is impossible to go outside and not notice banks offering consumers new ways to save, send, spend, and access their money at a bank. This trend-to ease access to funds – extends well beyond the retail banking sector and is equally prevalent among investment banks, private banks, hedge funds, mutual funds, ETFs and just about any financial institution, large or small. It is arguably the single most compelling commercial driver in the financial services sector. Financial institutions compete aggressively and continuously for dominance in this regard and technology is, in all cases, the single most important differentiator across institution, customer, and geography.

Unfortunately the introduction of nascent technologies to improve financial access is also accompanied by increased vulnerability to the very currency and associated details at the heart of the financial services industry. This is the cost of an increasingly open marketplace for financial services and a dynamic that is only further complicated by the growing array of devices and techniques customized for each device to engage in financial transactions. Fortunately there are technologies and strategies available that can be embedded within the security infrastructure of financial institutions to defensively and prospectively detect and eliminate threats, which vary in scope and nature.

General Scope of Threat
Financial institutions are ripe for cyber attacks because of the breadth of personal and business data embedded within their networks as well as financial information. An approximately 35-40% increase in cyber crime targeting the financial sector was recorded in 2015 and a staggering record 21 million fraud attacks and 45 million BOT attacks were detected in Q4 of 2015 alone. Q3 to Q4 BOT attacks increased tenfold and there is little reason to see this trend reversing course. The threat is neither one dimensional or lacking in sophistication – attacks are highly organized and are multi-channel in nature. BOTs and other complex attacks (e.g., malware) are structured to behave as authentic customers to circumvent traditional security defenses. The consequences and costs are severe: data loss and its wide-reaching proximate impact as well as direct financial losses that can easily reach billions of dollars for a single firm.

At Risk Sub-Sectors
The complex nature of financial institutions demands different technological approaches and structures for each sub-sector. This is also the inherent challenge in devising dynamic strategies to protect against cyber attacks across all vulnerability points of a firm or specific categories of firms. Mobile usage as well as online lending and alternative payment techniques are primary target areas with perceived weak security infrastructure. Part of this vulnerability comes from the speed of the transaction cycle, compared to traditional lending, but also due to the less traditional and smaller lenders that are enabled by online lending to issue loans and are less likely to have powerful security infrastructure on par with traditional lenders. Vulnerability from a single lender can create systemic vulnerabilities reaching beyond the lender itself. A weakness in a small lender can create a vulnerability that exposes a larger institution on the other side of the transaction.

Financial institutions involved in e-commerce are also soft targets for cyber attacks. Mobile transaction volume increased more than 200% between 2014 and 2015 and is estimated to maintain that growth trajectory as more mobile devices, with greater sophistication and applications tied to financial institutions, enter the e-commerce system. With multiple technologies and institutions collaborating to enable e-commerce, the complexion of any approach to cyber security must be multi-layered to enable businesses to detect and prevent various attacks such as malware, device spoofing, and mobile bot attacks.

Methods and Strategies
In an environment where the challenges are not static or one-dimensional, neither should the solution. Speed and comprehensiveness of a defense and response system is critical to effectiveness in minimizing risks and mitigating damages in the event of an attack. Unified risk assessment and threat prevention techniques must be core to a financial institution's cyber attack strategy. Financial institutions must recognize their central role in core financial services activity as well as e-commerce and mobile payment products. But how should financial institutions with disparate sizes, services, and, most importantly, balance sheets make decisions about cyber security? How can varied budget sizes be accounted for in maintaining consistently effective approaches to similar threats?

For large institutions the risks are too considerable and far-reaching to implement anything short of the most comprehensive systems available in the market. Speed, synchronization and uniformity should be paramount considerations and, fortunately, there are technologies available that accomplish these objectives while retaining a degree of malleability to adjust with evolving threats and risk points.

For smaller firms the solutions that are being implemented tend to be more patchwork (though even larger financial institutions have similar ‘band-aid' approaches). "Cyber-as-a-service" firms are increasingly common service providers for smaller and medium sized companies as well as concentrated on key risk areas through the utilization of dedicated computers for sensitive transactions, which can be monitored for unusual activity. These methods, while often effective defensively, lack the key elements of speed and comprehensiveness; they are reactionary in nature, but lack the embedded and dynamic technical characteristics to be prospective in their approach to risk.

In devising a cyber attack strategy financial institutions should be mindful of four dynamics:

  • The role that the interconnected nature of the financial services industry, regardless of firm size and scope of services offered, plays in widening the scope of vulnerabilities outside the immediate ambit of a firm
  • The value of an integrated and uniform solution to ensuring responsiveness across platforms and vulnerability points
  • The importance of speed in detection and responsiveness to preventing attacks and mitigating damages
  • The crucial role that comprehensive internal and external monitoring will play in anticipating unforeseen attacks that exploit vulnerabilities in newly introduced technologies

More Stories By Yuri Frayman

Yuri Frayman is the Chief Executive of ZENEDGE. He recently sold his last company to Google.

IoT & Smart Cities Stories
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
Dynatrace is an application performance management software company with products for the information technology departments and digital business owners of medium and large businesses. Building the Future of Monitoring with Artificial Intelligence. Today we can collect lots and lots of performance data. We build beautiful dashboards and even have fancy query languages to access and transform the data. Still performance data is a secret language only a couple of people understand. The more busine...
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science," is responsible for setting the strategy and defining the Big Data service offerings and capabilities for EMC Global Services Big Data Practice. As the CTO for the Big Data Practice, he is responsible for working with organizations to help them identify where and how to start their big data journeys. He's written several white papers, is an avid blogge...
Nicolas Fierro is CEO of MIMIR Blockchain Solutions. He is a programmer, technologist, and operations dev who has worked with Ethereum and blockchain since 2014. His knowledge in blockchain dates to when he performed dev ops services to the Ethereum Foundation as one the privileged few developers to work with the original core team in Switzerland.
René Bostic is the Technical VP of the IBM Cloud Unit in North America. Enjoying her career with IBM during the modern millennial technological era, she is an expert in cloud computing, DevOps and emerging cloud technologies such as Blockchain. Her strengths and core competencies include a proven record of accomplishments in consensus building at all levels to assess, plan, and implement enterprise and cloud computing solutions. René is a member of the Society of Women Engineers (SWE) and a m...
Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereal. Andrew's role at ConsenSys Enterprise is a mul...
Whenever a new technology hits the high points of hype, everyone starts talking about it like it will solve all their business problems. Blockchain is one of those technologies. According to Gartner's latest report on the hype cycle of emerging technologies, blockchain has just passed the peak of their hype cycle curve. If you read the news articles about it, one would think it has taken over the technology world. No disruptive technology is without its challenges and potential impediments t...
If a machine can invent, does this mean the end of the patent system as we know it? The patent system, both in the US and Europe, allows companies to protect their inventions and helps foster innovation. However, Artificial Intelligence (AI) could be set to disrupt the patent system as we know it. This talk will examine how AI may change the patent landscape in the years to come. Furthermore, ways in which companies can best protect their AI related inventions will be examined from both a US and...
Bill Schmarzo, Tech Chair of "Big Data | Analytics" of upcoming CloudEXPO | DXWorldEXPO New York (November 12-13, 2018, New York City) today announced the outline and schedule of the track. "The track has been designed in experience/degree order," said Schmarzo. "So, that folks who attend the entire track can leave the conference with some of the skills necessary to get their work done when they get back to their offices. It actually ties back to some work that I'm doing at the University of San...
When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things'). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing. IoT is not about the devices, its about the data consumed and generated. The devices are tools, mechanisms, conduits. This paper discusses the considerations when dealing with the...