Report warns of FS data leak risk

Every employee in financial services is able to access nearly 11 million files, according to the 2021 Financial Data Risk Report from data security firm Varonis, leaving a huge data leak landscape for the industry to contend with.

The new report delves into the state of data security across on-premise, cloud and hybrid environments in the banking, insurance and investment sectors.

“Financial services organisations must safeguard tons of highly sensitive information, but data is often left exposed to far too many people,” said Varonis.

Varonis analysed a random sample of data risk assessments for 56 companies to uncover how exposed companies really are.The company's analysts crunched the numbers and examined 4 billion files for the report.

Amongst the key findings, the research found that on average, every financial services employee has access to nearly 11 million files, but for larger companies the number doubles to 20 million files.

In addition, 20 per cent of all folders are open to every employee, while 39 per cent of companies have over 10,000 stale - but enabled - user accounts.

The data security risk is raised further by the fact that nearly two-thirds of companies have 1,000-plus sensitive files open to every employee, and about 60 per cent of companies have 500-plus passwords that never expire, leaving systems vulnerable to hacking attempts and data breach.

Rachel Hunt, Varonis content and media relations manager, said of the threat: “If just one employee clicks on a phishing email, attackers will move into action fast, and they’ll be able to copy, change, encrypt or delete any files the victim can touch – which is pretty scary.”

    Share Story:

Recent Stories


The human firewall: Activating employees to safeguard financial data
As financial services increasingly embrace SaaS and cloud-based technologies, they face emerging threats to safeguard sensitive customer data. While comprehensive IT security measures are essential, the active involvement of employees across organisations is pivotal in ensuring the protection of sensitive data.

Building a secure financial future for instant payments: The convergence of ISO 20022 and fraud detection
The financial landscape is rapidly evolving its approach to real-time transactions under the ISO 20022 standard, and financial institutions must take note. With examples such as the accelerated adoption of SEPA Instant Credit Transfers in Europe and proposed New Payment Architecture (NPA) programme in the UK, the need for swift and effective fraud detection is more crucial than ever.

Data Streaming and Consumer Duty: Transforming customer experience in banking
Introduced at the end of July, the Consumer Duty is a game-changing new set of rules and guidance for financial services institutions in the UK, and companies must look to modernise their systems in adherence with it in mind to create the best customer experience possible.

From insight to action: Empowering financial institutions through advanced technology and collaborative information sharing
The use of Information sharing in enhancing financial crime prevention has been universally agreed as being beneficial. However no-one has been able to agree on how information can be shared safely without breaching data protection laws or having the right systems to facilitate this, Information sharing has re-emerged as a major consideration for financial institutions (FIs) ahead of the Economic Crime and Corporate Transparency Bill being made into law in the UK.