Over the last several years, cybersecurity regulations (like NYDFS and GDPR) have placed pressure on the financial services industry to build and enforce some of the strongest risk management programs across any industry. These programs focus not only on internal security performance, but also on managing third party risk. Financial service organizations are both highly regulated and handle extremely sensitive personally identifiable information (PII), and as a result typically have higher security budgets when compared to other industries.
Financial services companies also tend to perform towards the higher end of the scale from a cybersecurity perspective. Leveraging data from Bitsight Sovereign Security Ratings which look at security performance at a national and industry level, we examined the security performance of the finance sector in the United Kingdom. Our researchers analyzed UK Financial Services security performance for the month of May 2018 to determine whether the security posture of this industry falls where expected. 
Figure 1
Bitsight’s research shows that the average security rating for the United Kingdom — when compared to the average security rating for other European countries — is highest in Insurance, Credit Unions, and Real Estate, with Finance coming in 4th place. This is positive, given that each of these industries deal with very sensitive client information that could be extremely harmful if compromised.
This image also shows that some of the overall lowest average security ratings in the UK are in Retail, which is concerning given that retail companies work many third parties who handle customer data. There have been several instances of some very public retail breaches in the last few years. Working with third parties has a big impact on retailers’ business bottom line, so they should be proactively working to improve the cybersecurity of their supply chains.

