Digital transformation ‘increases security risk’

Digital transformation is driving turmoil among financial services organisations and leaving sensitive data at risk, according to the 2018 Thales Data Threat Report.

The security firm’s analysis suggested that the industry has hastily entered the digital transformation era, but this is not balanced with appropriate security measures. Almost two thirds (65 per cent) of financial services firms have now suffered a data breach, with 28 per cent having suffered a breach in the past year.

While new technologies - including cloud, mobile payments, blockchain, the Internet of Things (IoT), machine learning and artificial intelligence - help meet increased consumer and business demands for improved services and experience, Thales argued that the industry opens itself up to new avenues for attacks and breaches.

Cloud usage with sensitive data is especially high in the financial services industry at 76 per cent, with multiple cloud usage is also high with 60 per cent of organisations using more than 25 software as a service applications.

But security spending is up but not aligning with the new risks, according to Thales. While 78 per cent of firms reported a spending increase on IT security, they are not spending in the right areas. The majority (72 per cent) of IT security professionals acknowledge data-at-rest defences are most effective at protecting data, but only 38 per cent registered a spending increase for those specific tools.

Garrett Bekker, principal analyst for information security at 451 Research, said there is a “Groundhog Day phenomenon” where the times have changed, but security strategies have not.

“Organisations need to change how they protect their data. With increasingly porous networks and expanding use of external resources (SaaS, PaaS and IaaS most especially), traditional endpoint and network security are no longer sufficient safeguards,” he added.

Peter Galvin, chief strategy officer at Thales eSecurity, concluded that encryption is proven to be the most effective technology to protect data, wherever it resides, as well as help meet compliance mandates.

“As new technologies such as cloud IoT and mobile payments are increasingly adopted by financial organisations looking for a competitive edge, the security risks they bring must be addressed.”

    Share Story:

Recent Stories


Sanctions evasion in an era of conflict: Optimising KYC and monitoring to tackle crime
The ongoing war in Ukraine and resulting sanctions on Russia, and the continuing geopolitical tensions have resulted in an unprecedented increase in parties added to sanctions lists.

Achieving operational resilience in the financial sector: Navigating DORA with confidence
Operational resilience has become crucial for financial institutions navigating today's digital landscape riddled with cyber risks and challenges. The EU's Digital Operational Resilience Act (DORA) provides a harmonised framework to address these complexities, but there are key factors that financial institutions must ensure they consider.

Legacy isn’t the enemy: what FSIs can do to keep their systems up and running
In this webinar we will examine some of the steps FSIs have already taken to rigorously monitor and test systems – both manually and with AI-powered automation – while satisfying the concerns of regulators and customers.

Optimising digital banking: Unifying communications for seamless CX
In the digital age, financial institutions risk falling behind their rivals if they fail to unite fragmented communications ecosystems to deliver seamless, personalised customer experiences.

This FStech webinar sponsored by Precisely explores vital strategies to optimise cross-channel messaging through omnichannel orchestration and real-time customer data access.