When it comes to cybersecurity, the financial services sector needs to implement strong cyber risk management programs. One factor that contributes to this performance is regulations and standards. Laws such as FFIEC IT and GDPR, coupled with standards such as SOC2 have spurred financial services companies to create some of the most stringent programs in the world.
Another factor is money. Financial services firms have a higher security budget than others due to the very sensitive personal and financial information they handle. And, should a cyberattack occur, the costs are high. According to the Ponemon Institute and IBM, the average cost of a data breach in the financial sector is $5.97 million per incident.
But as threats and regulations continue to evolve, there’s always work to be done, particularly when it comes to supply chain cyber risk:
- 62% of network intrusions originate with a third-party
- 73% of organizations have experienced at least one significant disruption from a third-party in the last three years
In this blog, we explore the risks that an increased reliance on vendors brings and the critical elements of an effective vendor risk management (VRM) program for financial institutions.
Understanding the third-party landscape
Financial services firms are part of a vast, interconnected, third-party ecosystem of partners and suppliers. Many of these vendors support essential operations and have access to sensitive systems and data.
Skilled hackers target these vendors who may not have stringent security controls in place. Once a vendor’s network is breached, hackers can insert malicious software that is then propagated across the supply chain, as happened with the SolarWinds hack in 2020, which impacted 18,000 downstream customers.
This and more recent third-party data breaches demonstrate the importance of managing third-party risks.
5 risks that VRM must address
Breaches that occur as a result of poor vendor security practices can have significant impacts. Here are some of the risks that may arise from a financial institution’s use of third parties:
1. Compliance risk: Regulators, such as the SEC, are increasingly requiring that financial institutions step up their third-party risk management programs. Specifically, firms must conduct vendor cybersecurity assessments and include security requirements and standards in third-party contracts. Furthermore, if a vendor is breached, firms are obligated to report the incident to impacted clients. Finally, security and VRM leaders must keep the board of directors apprised of the security posture of companies in their vendor portfolios.
2. Reputation risk: Data breaches can severely damage an institution's reputation and negatively affect customer retention and acquisition.
3. Financial risk: Regulatory violations or data breaches can result in millions of dollars in fines and remediation and digital forensic investigation costs.
4. Operational risk: Cyberattacks cause significant disruption to business operations, productivity, and continuity as they try to contain the breach and restore systems and data.
5. Strategic risk: Cyber incidents can drastically limit a firm’s ability to meet its strategic goals, such as digital transformation, building market integrity, attracting talent, M&A, new product development, and delivering customer value.