Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Top Stories > AS BANKS FACE TOUGHER REGULATIONS, SECURITY NEEDS TO PREEMPT THREATS
    Top Stories

    AS BANKS FACE TOUGHER REGULATIONS, SECURITY NEEDS TO PREEMPT THREATS

    AS BANKS FACE TOUGHER REGULATIONS, SECURITY NEEDS TO PREEMPT THREATS

    Published by Gbaf News

    Posted on February 21, 2017

    Featured image for article about Top Stories

    Guy Guzner, CEO, Fireglass

    Several months ago, a new cybersecurity regulation was introduced aimed specifically at the finance industry. Some may say it’s about time. The regulation proposed by the state of New York requires every bank and insurance company doing business in the state to establish a cybersecurity program, appoint a Chief Information Security Officer (CISO) and screen the cybersecurity policies of its business partners.Shortly after New York’s announcement,the Federal Reserve weighed in, unveiling a national plan to toughen the country’s largest banks against major cyberattacks.

    Why all the new regulations? Recent attacks on the banking sector may be the primary motivation behind this surge. While there have been a number of attacks over recent years, several stand out. The JP Morgan Chase breach of July 2014 saw attackers gain the highest level of administrative privileges to the banks computer servers. In 2013, investigators unearthed a scheme where hackers had conducted a seven-year onslaught on organizations across the U.S., including banks, which targeted over 800,000 bank accounts. At the start of 2016, Bangladesh Bank saw over $81 million siphoned from its accounts in just hours. The hackers targeted the bank’s SWIFT accounts, the international money transfer system that banks have used since the 1970s to make daily transactions between themselves. We are seeing how technologies that have been in place for decades are no longer effective and become the weak points that hackers are leveraging to their advantage.

    The rise of the financial tech industry is opening up additional opportunities for cyber attackers. The number of companies in this space is increasing rapidly. The demand from younger generations for digital alternatives to banks and financial institutions has spurred billions in investments in fintech ventures. Some of these companies certainly will commit to making cybersecurity an integral part of their organizational mandate. Still, it’s also inevitable that some will fall short when it comes to security. With more and more people having access to financial services and more interfaces to do so, this is creating more vulnerable scenarios for hackers to take advantage of.

    While regulations in the U.S. will enforce the development of crises and risk plans that will help banks prepare for the worst, there is a lot at stake relying on archaic systems. The Bangladesh heist may have scared institutions into action, but the damage resulting from a cyberattack can do much more than leave organizations without cash. Imagine if cyber criminals were able to shut down stock exchanges for long periods of time, blocking trades and access to markets. Not only would this impact day-to-day activity, it could shake the faith of investors to the core. On a large scale,this can destabilize an economy overnight. Most concerning is that breaches can be accomplished using common malicious tactics and tools such as phishing and malware.

    Taking a cue from Israel

    Regulations like the ones being proposed here in the U.S. may have taken inspiration from similar guidelines effected in other countries. Take, for instance,the way Israel is approaching regulations in the financial world. Israeli banks have had to comply with even tougher regulations than those imposed by the state of New York. For example, they are required to physically separate their internal and external networks. This means the same computer cannot be used to access both networks unless there are two separate network cards and two separate virtual machines running on the computer. By enforcing these types of strict guidelines, Israel prevents malware from entering banks’ principal systems from the risky public internet.

    What banks could expect

    The New York regulationcould impact financial institutions in several ways.

    * Organizational structure changes. The responsibility for security in some organizations have been splintering across multiple departments and business units, and overlapping between IT-focused organizations, Risk or security organizations, and operational organizations. In smaller organizations the security role has often been shared with IT responsibilities. As mentioned above, the regulation directs that the organization must appoint board-level responsibility for cybersecurity as well as a CISO.

    * New security measurements. Until recently the security program was measured according to the subjective judgment of security professionals. But now that a prescriptive regulation is in place, there is danger that focus will be to satisfy the regulation and not maintain an effective program. This is always a risk with prescriptive regulation.

    • More breaches disclosed. Given the impact breaches inflict on bank reputations and the public trust, there is a powerful incentive to keep breaches quiet. This regulation makes it much harder to hide data breaches, which, in turn, would increase the perceived risk of breaches.
    • Increase in oversight over third parties. The regulation mandates that financial institutions take responsibility for the security posture of vendors providing services to them. This is not surprising as many breaches were caused by compromising vendors rather than the organizations themselves However, there are no standard methods today to ensure the security of third party, and this regulation will probably encourage that field. In the short term this may slow down the adoption of cloud technologies and outsourcing, especially for the smaller financial institutions that cannot audit their vendors themselves.
    • Industry mergers. The regulation clearly favors the larger financial institutions that already have programs like this in place. This will significantly increase the IT cost of smaller financial institutions and make it more difficult for them to be competitive against their larger counterparts. As such, this may drive mergers and/or consortiums to leverage economy of scale.

    Implementing pre-emptive approaches

    Like other large businesses and institutions, the banking and finance industries rely on archaic systems prone to modern day attacks. But implementing modern and innovative solutions that don’t require complete overhaul can help bring these systems into the 21st century.

    . Additionally, banks can implement pre-emptive approaches to security to strengthen systems and thwart cyberattacks. Taking pre-emptive approaches to security can benefit not only the largest global banks, but also the smallest local banks. While larger banks may have the resources to continually reevaluate their security posture and invest in post breach solutions, smaller banks would need to be prioritize security controls which dramatically reduce risk.

    Some modern security strategies financial institutions are starting to deploy have taken inspiration from the separation of internal and external networks.One such technology is based on the concept of “isolation”. It focuses on strengthening the most vulnerable targets — the users, by preventing malicious web content from reaching them. This allows users to click with confidence from any device by minimizing exposure to malware and phishing from web and email.

    Unlike traditional security solutions that need to distinguish good from bad, isolation assumes all content is malicious and should not be allowed into the corporate network. Isolation creates a secure execution environment placed between users and the web where all browsing sessions are executed remotely and only a safe visual stream is sent users’ devices. Because all content is executed away from endpoints, users are completely protected from malicious websites,emails and documents. Gartner recently published a research recognizing isolation as one of the single most significant ways to reduce attacks.

    Conclusion

    With ever increasing opportunities for attackers to compromise sensitive networks, financial organizations must do their part to not only prepare for compliance with tightening regulations, but also adopt advanced technologies to secure their networks. Relying on traditional methods will only get them so far. Instead they need to implement solutions that can help strengthen an infrastructure relying on seemingly stalwart technology.

    Guy Guzner, CEO, Fireglass

    Several months ago, a new cybersecurity regulation was introduced aimed specifically at the finance industry. Some may say it’s about time. The regulation proposed by the state of New York requires every bank and insurance company doing business in the state to establish a cybersecurity program, appoint a Chief Information Security Officer (CISO) and screen the cybersecurity policies of its business partners.Shortly after New York’s announcement,the Federal Reserve weighed in, unveiling a national plan to toughen the country’s largest banks against major cyberattacks.

    Why all the new regulations? Recent attacks on the banking sector may be the primary motivation behind this surge. While there have been a number of attacks over recent years, several stand out. The JP Morgan Chase breach of July 2014 saw attackers gain the highest level of administrative privileges to the banks computer servers. In 2013, investigators unearthed a scheme where hackers had conducted a seven-year onslaught on organizations across the U.S., including banks, which targeted over 800,000 bank accounts. At the start of 2016, Bangladesh Bank saw over $81 million siphoned from its accounts in just hours. The hackers targeted the bank’s SWIFT accounts, the international money transfer system that banks have used since the 1970s to make daily transactions between themselves. We are seeing how technologies that have been in place for decades are no longer effective and become the weak points that hackers are leveraging to their advantage.

    The rise of the financial tech industry is opening up additional opportunities for cyber attackers. The number of companies in this space is increasing rapidly. The demand from younger generations for digital alternatives to banks and financial institutions has spurred billions in investments in fintech ventures. Some of these companies certainly will commit to making cybersecurity an integral part of their organizational mandate. Still, it’s also inevitable that some will fall short when it comes to security. With more and more people having access to financial services and more interfaces to do so, this is creating more vulnerable scenarios for hackers to take advantage of.

    While regulations in the U.S. will enforce the development of crises and risk plans that will help banks prepare for the worst, there is a lot at stake relying on archaic systems. The Bangladesh heist may have scared institutions into action, but the damage resulting from a cyberattack can do much more than leave organizations without cash. Imagine if cyber criminals were able to shut down stock exchanges for long periods of time, blocking trades and access to markets. Not only would this impact day-to-day activity, it could shake the faith of investors to the core. On a large scale,this can destabilize an economy overnight. Most concerning is that breaches can be accomplished using common malicious tactics and tools such as phishing and malware.

    Taking a cue from Israel

    Regulations like the ones being proposed here in the U.S. may have taken inspiration from similar guidelines effected in other countries. Take, for instance,the way Israel is approaching regulations in the financial world. Israeli banks have had to comply with even tougher regulations than those imposed by the state of New York. For example, they are required to physically separate their internal and external networks. This means the same computer cannot be used to access both networks unless there are two separate network cards and two separate virtual machines running on the computer. By enforcing these types of strict guidelines, Israel prevents malware from entering banks’ principal systems from the risky public internet.

    What banks could expect

    The New York regulationcould impact financial institutions in several ways.

    * Organizational structure changes. The responsibility for security in some organizations have been splintering across multiple departments and business units, and overlapping between IT-focused organizations, Risk or security organizations, and operational organizations. In smaller organizations the security role has often been shared with IT responsibilities. As mentioned above, the regulation directs that the organization must appoint board-level responsibility for cybersecurity as well as a CISO.

    * New security measurements. Until recently the security program was measured according to the subjective judgment of security professionals. But now that a prescriptive regulation is in place, there is danger that focus will be to satisfy the regulation and not maintain an effective program. This is always a risk with prescriptive regulation.

    • More breaches disclosed. Given the impact breaches inflict on bank reputations and the public trust, there is a powerful incentive to keep breaches quiet. This regulation makes it much harder to hide data breaches, which, in turn, would increase the perceived risk of breaches.
    • Increase in oversight over third parties. The regulation mandates that financial institutions take responsibility for the security posture of vendors providing services to them. This is not surprising as many breaches were caused by compromising vendors rather than the organizations themselves However, there are no standard methods today to ensure the security of third party, and this regulation will probably encourage that field. In the short term this may slow down the adoption of cloud technologies and outsourcing, especially for the smaller financial institutions that cannot audit their vendors themselves.
    • Industry mergers. The regulation clearly favors the larger financial institutions that already have programs like this in place. This will significantly increase the IT cost of smaller financial institutions and make it more difficult for them to be competitive against their larger counterparts. As such, this may drive mergers and/or consortiums to leverage economy of scale.

    Implementing pre-emptive approaches

    Like other large businesses and institutions, the banking and finance industries rely on archaic systems prone to modern day attacks. But implementing modern and innovative solutions that don’t require complete overhaul can help bring these systems into the 21st century.

    . Additionally, banks can implement pre-emptive approaches to security to strengthen systems and thwart cyberattacks. Taking pre-emptive approaches to security can benefit not only the largest global banks, but also the smallest local banks. While larger banks may have the resources to continually reevaluate their security posture and invest in post breach solutions, smaller banks would need to be prioritize security controls which dramatically reduce risk.

    Some modern security strategies financial institutions are starting to deploy have taken inspiration from the separation of internal and external networks.One such technology is based on the concept of “isolation”. It focuses on strengthening the most vulnerable targets — the users, by preventing malicious web content from reaching them. This allows users to click with confidence from any device by minimizing exposure to malware and phishing from web and email.

    Unlike traditional security solutions that need to distinguish good from bad, isolation assumes all content is malicious and should not be allowed into the corporate network. Isolation creates a secure execution environment placed between users and the web where all browsing sessions are executed remotely and only a safe visual stream is sent users’ devices. Because all content is executed away from endpoints, users are completely protected from malicious websites,emails and documents. Gartner recently published a research recognizing isolation as one of the single most significant ways to reduce attacks.

    Conclusion

    With ever increasing opportunities for attackers to compromise sensitive networks, financial organizations must do their part to not only prepare for compliance with tightening regulations, but also adopt advanced technologies to secure their networks. Relying on traditional methods will only get them so far. Instead they need to implement solutions that can help strengthen an infrastructure relying on seemingly stalwart technology.

    Related Posts
    Chase Buchanan Private Wealth Management Highlights Key Autumn 2025 Budget Takeaways for Expats
    Chase Buchanan Private Wealth Management Highlights Key Autumn 2025 Budget Takeaways for Expats
    PayLaju Strengthens Its Position as Malaysia’s Trusted Interest-Free Sharia-Compliant Loan Provider
    PayLaju Strengthens Its Position as Malaysia’s Trusted Interest-Free Sharia-Compliant Loan Provider
    A Notable Update for Employee Health Benefits:
    A Notable Update for Employee Health Benefits:
    Creating Equity Between Walls: How Mohak Chauhan is Using Engineering, Finance, and Community Vision to Reengineer Affordable Housing
    Creating Equity Between Walls: How Mohak Chauhan is Using Engineering, Finance, and Community Vision to Reengineer Affordable Housing
    Upcoming Book on Real Estate Investing: Harvard Grace Capital Founder Stewart Heath’s Puts Lessons in Print
    Upcoming Book on Real Estate Investing: Harvard Grace Capital Founder Stewart Heath’s Puts Lessons in Print
    ELECTIVA MARKS A LANDMARK FIRST YEAR WITH MAJOR SENIOR APPOINTMENTS AND EXPANSION MILESTONES
    ELECTIVA MARKS A LANDMARK FIRST YEAR WITH MAJOR SENIOR APPOINTMENTS AND EXPANSION MILESTONES
    Hebbia Processes One Billion Pages as Financial Institutions Deploy AI Infrastructure at Unprecedented Scale
    Hebbia Processes One Billion Pages as Financial Institutions Deploy AI Infrastructure at Unprecedented Scale
    Beyond Governance Fatigue: Making ESG Integration Work in Financial Markets
    Beyond Governance Fatigue: Making ESG Integration Work in Financial Markets
    Why I-9 Verification Matters for Financial Institutions: Building a Culture of Compliance and Trust
    Why I-9 Verification Matters for Financial Institutions: Building a Culture of Compliance and Trust
    Curvestone AI partners with The White Rose Finance Group to enhance compliance file reviews
    Curvestone AI partners with The White Rose Finance Group to enhance compliance file reviews
    LinkedIn Influence in 2025: Insights from Stevo Jokic on Building Authority and Trust
    LinkedIn Influence in 2025: Insights from Stevo Jokic on Building Authority and Trust
    Should You Take the Dealer’s Bike Insurance or Buy Online Yourself? Here’s the Real Difference
    Should You Take the Dealer’s Bike Insurance or Buy Online Yourself? Here’s the Real Difference

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Top Stories

    Explore more articles in the Top Stories category

    ID-Pal Unveils ID-Detect Enhancements to Counter Surge in Digital Manipulation and Deepfakes

    ID-Pal Unveils ID-Detect Enhancements to Counter Surge in Digital Manipulation and Deepfakes

    TRUST TAKES THE LEAD: HALF OF UK SHOPPERS HAVE ABANDONED ONLINE PURCHASES OVER SECURITY CONCERNS

    TRUST TAKES THE LEAD: HALF OF UK SHOPPERS HAVE ABANDONED ONLINE PURCHASES OVER SECURITY CONCERNS

    Why Choose Premium Driver Service in Miami Over Rideshare Apps for Business Travel and Special Events?

    Why Choose Premium Driver Service in Miami Over Rideshare Apps for Business Travel and Special Events?

    Over 30 Million Users Benefit From Ant International’s Bettr Credit Tech Solutions

    Over 30 Million Users Benefit From Ant International’s Bettr Credit Tech Solutions

    Side-Hustle Economics: How Part-Time Service Work Can Strengthen Your Financial Plan

    Side-Hustle Economics: How Part-Time Service Work Can Strengthen Your Financial Plan

    London to Host Major Summit on “New Horizons” for Islamic Economy in the UK

    London to Host Major Summit on “New Horizons” for Islamic Economy in the UK

    BLOXX Launches World’s First Home Equity Subscription, Creating a New Residential Asset Class

    BLOXX Launches World’s First Home Equity Subscription, Creating a New Residential Asset Class

    LiaFi Addresses Gap Between Business Transaction and Savings Accounts

    LiaFi Addresses Gap Between Business Transaction and Savings Accounts

    Ant Group Chairman Eric Jing Outlines Strategy for Inclusive AI, Collaboration on Tokenised Settlement

    Ant Group Chairman Eric Jing Outlines Strategy for Inclusive AI, Collaboration on Tokenised Settlement

    Deeply Cultivating the Syndicated Loan and Cross-Border Financing Fields: Empowering Chinese Banks’ Global Expansion with Professional Excellence

    Deeply Cultivating the Syndicated Loan and Cross-Border Financing Fields: Empowering Chinese Banks’ Global Expansion with Professional Excellence

    Ant International’s Antom Launches AI‑Powered MSME App for Finance and Business Operations

    Ant International’s Antom Launches AI‑Powered MSME App for Finance and Business Operations

    A Gateway for U.S. Capital: Inside Kazakhstan’s Expanding Financial Hub

    A Gateway for U.S. Capital: Inside Kazakhstan’s Expanding Financial Hub

    View All Top Stories Posts
    Previous Top Stories PostGlobal Banking & Finance Review Names Desjardins Private Wealth Management “Best Private Wealth Management Company Canada 2017”
    Next Top Stories PostIBM AND VISA TURN AUTOMOBILES, APPLIANCES AND ALL OTHER CONNECTED DEVICES INTO POTENTIAL POINTS OF SALE WITH WATSON INTERNET OF THINGS