Basware logo representing G-Cloud 6 partnership for public sector e-invoicing - Global Banking & Finance Review
This image features the Basware logo, symbolizing its new partnership with G-Cloud 6. This collaboration aims to enhance e-invoicing and procurement for UK public sector entities, promoting efficiency and cost savings.
Top Stories

FINANCIAL CONDUCT AUTHORITY URGED TO ESTABLISH TOUGHER CYBERSECURITY REGULATION TO COMBAT CONTINUING CONSUMER DISTRUST

Published by Gbaf News

Posted on December 2, 2014

3 min read

· Last updated: October 18, 2018

Add as preferred source on Google
  • One in four Brits still don’t trust the security of their banks’ digital systems, according to new research revealed by Intelligent Environments today
  • The financial services software provider urges the Financial Conduct Authority to establish mandatory cybersecurity tests for banks
  • Intelligent Environments believes a new standard could help keep customers safe from “daily” cyber-attacks on banks

Ongoing Consumer Distrust After Bank Cyber-Attacks

A year on from some of the biggest ever cyber-attacks on banks, research from Intelligent Environments shows over a quarter (28%) of Brits still don’t trust the security of their bank’s digital systems.[1]

Call for FCA to Strengthen Cyber Rules

In light of these findings, leading financial services software provider Intelligent Environments is urging the Financial Conduct Authority (FCA) to establish a more robust security regulation framework for the financial services industry, such as the one already in place for the payments industry.

Current Cybersecurity Regulations in Financial Services

While the payment card industry has a mandatory testing process to assess the threat of credit card fraud, known as The Payment Card Industry Security Standard (PCI-DSS), there is currently no similar cybersecurity compliance process for the financial services industry as a whole.  Given the continuing growth in the sector, Intelligent Environments claims a compulsory testing process similar to PCI-DSS is key to protecting the financial services sector from the ever-evolving cybercrime threat.

Clayton Locke, chief technology officer at Intelligent Environments, said: “Bank fraud and cybercrime are industrial-scale problems that present a critical threat to the financial services industry, as has been clearly demonstrated by previous attacks on prominent providers. Many customers feel their banks aren’t secure enough. This lack of consumer confidence in itself represents a major threat to the financial industry. By creating a tougher industry-wide standard for financial services security, banks and financial services providers can improve services, increase customer security and reclaim consumer confidence in their products.”

Bank of England Introduces CBEST Framework

To help combat the threat of cybercrime to banks’ digital services, the Bank of England recently created the CBEST testing framework for banks. This framework gathers intelligence from commercial and government sources to provide a holistic assessment of a financial services provider’s capabilities for dealing with cybercrime, by testing processes and technology. However, unlike PCI-DSS, CBEST’s assessments are not compulsory, meaning banks and financial services providers are under no obligation to comply with the recommended measures.

Industry Reactions and Proposed Solutions

The British Standards Institute (BSI) is now offering a kitemark for secure digital transactions. Intelligent Environments welcomes this new development in cybersecurity standards, but believes the industry should go further to make compliance mandatory.

Locke continued: “It’s clear the cybersecurity arms race favours the criminal. Banks now have to fend off cyber-attacks on a daily basis.  The FS industry therefore must respond more aggressively to these threats. While the CBEST testing framework is a strong step forward, the fact these assessments are still voluntary highlights an inherent weakness. It would be much more effective to make these assessments compulsory as is the case for PCI- DSS. It’s ridiculous card providers are required to adhere to a standard while banks are not. It’s time to develop a similar standard across our industry.”

[1] Online survey of 2,000 UK consumers undertaken by One Poll in September 2014

Key Takeaways

  • 28% of UK consumers still distrust their banks’ digital security.
  • Intelligent Environments urges the FCA to mandate cybersecurity testing similar to PCI‑DSS.
  • Existing frameworks like CBEST are voluntary and less effective without compulsory compliance.
  • Mandatory cybersecurity standards could restore confidence and safeguard against daily cyber‑attacks.

References

Frequently Asked Questions

What percentage of Brits distrust their bank’s digital systems?
28% of UK consumers reportedly don’t trust their bank’s digital systems, per a survey by Intelligent Environments.
What cybersecurity standard is used in the payments industry?
The Payment Card Industry Security Standard (PCI‑DSS) is a mandatory testing framework in the payments sector.
What is the CBEST framework?
CBEST is a Bank of England initiative offering intelligence‑led cybersecurity assessments for banks, but participation is currently voluntary.
What action is being proposed to improve consumer confidence?
Intelligent Environments proposes that the FCA mandate an industry‑wide cybersecurity testing standard similar to PCI‑DSS, making compliance compulsory.

Tags

Related Articles

More from Top Stories

Explore more articles in the Top Stories category