Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

12/8/2020
02:00 PM
Ed Bellis
Ed Bellis
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

Why Compliance Is No Longer King for Financial Services Cybersecurity

Financial services companies' experience in risk management serves them well when it comes to minimizing their cyber-risk.

Financial services has long been a compliance-driven industry. Nearly everything a bank or an investment adviser does is governed by some regulation. Usually, these rules are in place for consumer protection, but the rules the industry must follow extend to cybersecurity as well.

Unfortunately, auditors and other professionals tasked with compliance have historically developed their cybersecurity procedures in the dark. They don't always have a great view of what truly reduces risk to the organization. There's a box-checking mentality meant to assure regulators that cybersecurity procedures are in place, even when there's little guarantee that the procedures being audited add up to a secure environment.

Related Content:

A Call for Change in Physical Security

The Changing Face of Threat Intelligence

ISP Security: Do We Expect Too Much?

In the field of patching vulnerabilities, for example, compliance rules tend to force companies into closing security holes that pose little risk. And that's a problem, because there is no company on the planet with the resources to fix every vulnerability on its systems.

Fortunately, the finance sector has broad experience in risk management, and more and more of these companies are adopting risk-based vulnerability management approaches that rely on objective data rather than aged "best practices."

These two countervailing observations raise important questions. Are financial services companies investing their cybersecurity resources in the right areas? Are they truly reducing cybersecurity risk while still maintaining compliance?

How Financial Services Stacks Up
New research conducted by the Cyentia Institute and Kenna Security is providing important answers to these questions.

At first glance, Cyentia's research shows that financial services companies have big challenges. On average, financial institutions have four times more security vulnerabilities than companies in other industries. But thinking this through, it's not too surprising. The footprint of assets for these firms is not only large but made up of many general-purpose computing devices, which make them ripe for a wide array of vulnerabilities.

But as we have seen in previous research, not every vulnerability poses a significant risk. In fact, we see exploitation activity for only about 5% of these vulnerabilities "in the wild." This is good news because, on average, a typical company can fix just one out of 10 vulnerabilities.

In aggregate, the financial services sector does particularly well in focusing on high-risk vulnerabilities, patching nearly 85% of them. And some companies do better than others. That's impressive given their large digital footprint, especially noting that financial services outperformed most industries in our research.

Risk management is in the DNA of most financial services companies, and that accounts for much of their success in this area. We know that attackers tend to follow well-worn paths, reusing tools and abusing the same security gaps over and over. They often focus on certain operating systems and certain software publishers because they have higher market penetration. Likewise, they also tend to focus their efforts on a select group of vulnerabilities that can be leveraged for profit. 

Using tools and data science, companies can identify which vulnerabilities are more likely than not to be exploited by hackers. Risk-based vulnerability management programs are tailored to tackling these vulnerabilities first. 

This is all to say that tides are changing in financial services' security practices, and this is reason for optimism. What was once a pure focus on compliance is now shifting. More and more organizations are adopting better practices to improve security and lower risk, as Cyentia's data reflects. 

On the whole, the financial services industry does an impressive job of managing vulnerability risk. If they are as good at other cybersecurity disciplines as they are at vulnerability management, there's reason to be optimistic. Cybersecurity is often regarded as an expense rather than an investment, but done right, chaotic practices that never seem adequate can evolve into well-managed programs that provide real value for organizations.

Ed Bellis is a security industry veteran and expert and was once named Information Security Executive of the Year. He founded Kenna Security to deliver a data-driven, risk-based approach to remediation and help IT teams prioritize and thwart would-be security threats. Ed is ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31755
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31756
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitrary code on the system via a crafted post request. This occurs when input vector controlled by malicious attack get copie...
CVE-2021-31757
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31758
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31458
PUBLISHED: 2021-05-07
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handlin...