Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

7/5/2018
11:45 AM
50%
50%

UK Banks Must Produce Backup Plans for Cyberattacks

Financial services firms in Britain have three months to explain how they would stay up and running in the event of an attack or service disruption.

The Bank of England and Financial Conduct Authority have given UK financial services firms three months to produce backup plans explaining how they would respond to cyberattacks and avoid technical shutdowns, Reuters reports.

Financial services organizations are particularly vulnerable to cybercrime, as recently indicated by issues with Visa and UK bank TSB, where an April outage prevented customers from accessing online accounts. Regulators say the risk reflects a failure among banks and insurers to upgrade their systems, and demand they have strategies in place if systems are disrupted.

Businesses have until October 5, 2018 to produce their backup plans. If they fail to do so, or if their plans fall short of regulators' standards, they may be required to increase their capital levels or invest in their systems' resilience to cyberattacks.

Read more details here.  

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
7/5/2018 | 2:26:12 PM
NIST analog?
On the surface, this sounds like pretty basic stuff already covered under the NIST Cybersecurity Framework in the US -- which effectively acts as "pseudo-law" for financial institutions in the US. Seems like the only financial institutions in the UK that might have issue are those that have not crossed the pond -- and, even then, given the dramatic increase in collaboration on security matters throughout the finance sector over the past few years, this should not be too terribly burdensome, I suspect.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
7/9/2018 | 2:39:31 PM
Re: NIST analog?
Of more significance is that backup and restoration plans ARE PART of normal IT functionality and business purpose.  The data centers do not operate in a run-only vacuum.  There have to be plans to reconstruct and rebuild in any event, whether ransomware or hurricane, flood, loss of power, etc.  That it must be mandated by law is insane!  Good yes, but OMG this is It 101 basics folks!!!  
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
7/9/2018 | 8:05:59 PM
Re: NIST analog?
@REISEN: Conversely, the NIST Cybersecurity Framework -- like any framework -- is not exactly perfect, and has its own weaknesses. At least it's something to get started with, however.
Manchester United Suffers Cyberattack
Dark Reading Staff 11/23/2020
As 'Anywhere Work' Evolves, Security Will Be Key Challenge
Robert Lemos, Contributing Writer,  11/23/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25738
PUBLISHED: 2020-11-27
CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.
CVE-2020-29144
PUBLISHED: 2020-11-27
In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via an Alert Dashboard comment. In most test cases, session hijacking was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover, or e...
CVE-2020-29145
PUBLISHED: 2020-11-27
In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS via the name or description field to a solutionUnitServlet?SuName=UserReferenceDataSU Access Rights Group. In most test cases, session hijacking was also possible by utilizing t...
CVE-2020-29136
PUBLISHED: 2020-11-27
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
CVE-2020-29137
PUBLISHED: 2020-11-27
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).