The financial services sector is one of the highest performing in terms of cybersecurity. One factor that contributes to this performance is regulation. Laws such as FFIEC IT, the Gramm-Leach-Bliley Act, NYDFS, GDPR, and SOC2 have placed pressure on financial services companies to build and enforce some of the strongest cyber risk management programs across any industry.
You should consider another factor, which is money. Because of the extremely sensitive personal and financial information they handle, firms in this sector typically have higher security budgets than other organizations.
But as threats continue to evolve, there is always work to do. Indeed, a recent Bitsight study found that finance companies have much to do to improve their security postures.
Given this sobering discovery, here are four best practices that can bolster cybersecurity in the financial sector.
- Reduce Ransomware Risk
- Focus on third-party risk management
- Share information on cyber risk
- Gain buy-in from executives
1. Reduce Ransomware Risk
According to the Verizon 2021 Data Breach Investigations Report, ransomware incidents have doubled in the past year and are now the most common form of cyberattack. Yet despite their sophisticated risk management programs, when we analyzed the security posture of financial institutions, we found that 54% are at heightened risk of ransomware attacks.
This conclusion is drawn based on two key security program performance indicators – patching cadence (the elapsed time between software patches becoming available and when they are implemented) and configuration management (weak TLS/SSL configurations create vulnerabilities in infrastructure that could expose companies to attacks). Both indicators correlate with the risk of ransomware threats.
When this analysis is applied to the financial services sector, we found that 30% of institutions are slow to apply patches. This makes them seven times more likely to experience ransomware than those that maintain a regular patching cadence.
Perhaps more worrying, misconfigured systems expose 70% of these companies to ransomware risk.
What can financial services sector security professionals do? Our findings stress that continuously monitoring security performance so that vulnerabilities are discovered and remediated before they are exploited is key to defending against ransomware, and indeed any cyberattack.