Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Banking
    3. >THE IMPORTANCE OF ONLINE BANKING SECURITY
    Banking

    The Importance of Online Banking Security

    Published by Gbaf News

    Posted on February 3, 2018

    10 min read

    Last updated: January 21, 2026

    Add as preferred source on Google
    Image depicting investors assessing the impact of drought on companies and exploring water management solutions. This relates to the article's discussion on the financial implications of water scarcity.
    Investors analyzing water scarcity impacts on companies - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    By Jacob Ghanty, Head of Financial Regulation at Kemp Little LLP

    Jacob Ghanty, Head of Financial Regulation at Kemp Little LLP

    Jacob Ghanty, Head of Financial Regulation at Kemp Little LLP

    Banks and businesses are under increasing scrutiny to ensure they have the right security measures in place, especially in wake of the numerous high-profile data breaches that took place in 2017. In recent news, NatWest came under fire for failing to use an encrypted https (Hypertext Transfer Protocol Secure) connection for a customer-facing section of their website.

    Internet banking has grown in popularity in the UK for its convenience and timesaving benefits.For many consumers it has overtaken the use of physical branches. However, security is still a main concern for consumers when it comes to moving from ‘offline’ to online banking and banks must ensure they are meeting both customer expectation in terms of convenience but also tough regulation restrictions in order to keep their customers safe online.

    Not an isolated case

    In the case of NatWest, the absence of an encrypted https was spotted by an external security expert and made public knowledge through Twitter. This security flaw meant hackers had the potential to redirect customers to a falseNatWest site which looked identical to the legitimate site. Although this issue was resolved within 48 hours by the team, this vulnerability could have left NatWest liable to numerous security and legal consequences.

    Clearly, banks and financial institutions are legally obliged to protect customer data in order to maintain the security, integrity and confidentiality of information. Yet, since 2007, 11 banks to date have been named and shamed by the Information Commissioner’s Office (ICO) for unacceptable data security practice.

    According to the Data Protection Act 1998 (DPA), organisations must have appropriate organisational and technical measures in place to protect data against unauthorised or unlawful processing, and accidental loss or destruction of or damage to personal data (data security breach). This is known as the seventh data protection principle.While the DPA does not specify how “appropriate organisational and technical measures” should be developed according to this principle, data controllers must ensure they prevent the possibility of data being compromised in any way.

    Financial and legal obligations

    From a financial perspective, banks must ensure they have reliable security mechanisms in place to protect the transfer of sensitive information, prevent the possibility of data corruption and leakagewhilemaintaining data confidentiality at all times. These requirements fall under the Prudential Regulation Authority Rulebook, and failure to meet the conditions leaves banks liable to disciplinary action.

    From a data privacy law perspective, data controllers are at risk of huge fines should crucial customer information be compromised. For example, the ICO could impose penalties of up to £500,000, particularly in the case of a serious breach. In October 2016, TalkTalk was fined £400,000 for a breach which compromised the seventh data protection principle, in failing to have appropriate organisational nor technical measures in place.

    Banks and financial institutions must also keep in mind the upcoming EU General Data Protection Regulation (GDPR), taking effect from 25 May 2018. This regulation will impose stricter obligations on data controllers than ever before and increase maximum fines under a two-tier system if they suffer a breach. Such fines, under GDPR, could look like the following:

    • Up to 2% of a bank’s annual worldwide turnover of the preceding financial year or 10 million euros (whichever is the greater) for violations relating to internal record keeping, data processor contracts, data security and breach notification, data protection officers, and data protection by design and default
    • Up to 4% of annual worldwide turnover of the preceding financial year or 20 million euros (whichever is the greater) for violations relating to breaches of the data protection principles, conditions for consent, data subjects’ rights and international data transfers

    The importance of comprehensive security measures

    The above fines highlight the scale of the initial financial impact that the lack of HTTPS connection could have had on NatWest from their customer website.However, what cannot be calculated is the financial loss following the depreciation of trust and reputation from current and prospect customers. In order for financial institutions to safeguard such losses they must use a HTTPS connection to ensure that any data sent between a customer’s device and a website is encrypted and therefore, rendered inaccessible to anyone trying to intercept their data.

    Hackers often create phishing sites which look similar to users to a bank’s website, in order to lure customers to share their personal data. They can look more similar than perhaps users realise – even using fake log-in mechanisms to simulate the real website. This underlines why banks and financial institutions must be thorough with their security processes: the sheer scale of customers processing data and transactions through online services entail undeniable security and financial risks to both the customer and the banks.

    Important next steps for banks

    An effective way to spot and resolve any vulnerabilities in online systems is through carrying out a cyber-security audit. Financial services and banks can maintain a high level of protection by using appropriate detection capabilities, and putting in place fast-acting recovery and response systems. This will provide websites and online banking systems with the right tools to react to any issues quickly, and to prevent service outages in the case of unexpected interruptions.

    There are number of useful sources of information in this area including: the FCA’s speech in September 2016 on its supervisory approach to cyber security in financial services firms; various ICO guides on information security; the FCA’s Financial Crime Guide; and the FSA’s Thematic Review Report on data security in the financial services sector of April 2008.

    By Jacob Ghanty, Head of Financial Regulation at Kemp Little LLP

    Jacob Ghanty, Head of Financial Regulation at Kemp Little LLP

    Jacob Ghanty, Head of Financial Regulation at Kemp Little LLP

    Banks and businesses are under increasing scrutiny to ensure they have the right security measures in place, especially in wake of the numerous high-profile data breaches that took place in 2017. In recent news, NatWest came under fire for failing to use an encrypted https (Hypertext Transfer Protocol Secure) connection for a customer-facing section of their website.

    Internet banking has grown in popularity in the UK for its convenience and timesaving benefits.For many consumers it has overtaken the use of physical branches. However, security is still a main concern for consumers when it comes to moving from ‘offline’ to online banking and banks must ensure they are meeting both customer expectation in terms of convenience but also tough regulation restrictions in order to keep their customers safe online.

    Not an isolated case

    In the case of NatWest, the absence of an encrypted https was spotted by an external security expert and made public knowledge through Twitter. This security flaw meant hackers had the potential to redirect customers to a falseNatWest site which looked identical to the legitimate site. Although this issue was resolved within 48 hours by the team, this vulnerability could have left NatWest liable to numerous security and legal consequences.

    Clearly, banks and financial institutions are legally obliged to protect customer data in order to maintain the security, integrity and confidentiality of information. Yet, since 2007, 11 banks to date have been named and shamed by the Information Commissioner’s Office (ICO) for unacceptable data security practice.

    According to the Data Protection Act 1998 (DPA), organisations must have appropriate organisational and technical measures in place to protect data against unauthorised or unlawful processing, and accidental loss or destruction of or damage to personal data (data security breach). This is known as the seventh data protection principle.While the DPA does not specify how “appropriate organisational and technical measures” should be developed according to this principle, data controllers must ensure they prevent the possibility of data being compromised in any way.

    Financial and legal obligations

    From a financial perspective, banks must ensure they have reliable security mechanisms in place to protect the transfer of sensitive information, prevent the possibility of data corruption and leakagewhilemaintaining data confidentiality at all times. These requirements fall under the Prudential Regulation Authority Rulebook, and failure to meet the conditions leaves banks liable to disciplinary action.

    From a data privacy law perspective, data controllers are at risk of huge fines should crucial customer information be compromised. For example, the ICO could impose penalties of up to £500,000, particularly in the case of a serious breach. In October 2016, TalkTalk was fined £400,000 for a breach which compromised the seventh data protection principle, in failing to have appropriate organisational nor technical measures in place.

    Banks and financial institutions must also keep in mind the upcoming EU General Data Protection Regulation (GDPR), taking effect from 25 May 2018. This regulation will impose stricter obligations on data controllers than ever before and increase maximum fines under a two-tier system if they suffer a breach. Such fines, under GDPR, could look like the following:

    • Up to 2% of a bank’s annual worldwide turnover of the preceding financial year or 10 million euros (whichever is the greater) for violations relating to internal record keeping, data processor contracts, data security and breach notification, data protection officers, and data protection by design and default
    • Up to 4% of annual worldwide turnover of the preceding financial year or 20 million euros (whichever is the greater) for violations relating to breaches of the data protection principles, conditions for consent, data subjects’ rights and international data transfers

    The importance of comprehensive security measures

    The above fines highlight the scale of the initial financial impact that the lack of HTTPS connection could have had on NatWest from their customer website.However, what cannot be calculated is the financial loss following the depreciation of trust and reputation from current and prospect customers. In order for financial institutions to safeguard such losses they must use a HTTPS connection to ensure that any data sent between a customer’s device and a website is encrypted and therefore, rendered inaccessible to anyone trying to intercept their data.

    Hackers often create phishing sites which look similar to users to a bank’s website, in order to lure customers to share their personal data. They can look more similar than perhaps users realise – even using fake log-in mechanisms to simulate the real website. This underlines why banks and financial institutions must be thorough with their security processes: the sheer scale of customers processing data and transactions through online services entail undeniable security and financial risks to both the customer and the banks.

    Important next steps for banks

    An effective way to spot and resolve any vulnerabilities in online systems is through carrying out a cyber-security audit. Financial services and banks can maintain a high level of protection by using appropriate detection capabilities, and putting in place fast-acting recovery and response systems. This will provide websites and online banking systems with the right tools to react to any issues quickly, and to prevent service outages in the case of unexpected interruptions.

    There are number of useful sources of information in this area including: the FCA’s speech in September 2016 on its supervisory approach to cyber security in financial services firms; various ICO guides on information security; the FCA’s Financial Crime Guide; and the FSA’s Thematic Review Report on data security in the financial services sector of April 2008.

    More from Banking

    Explore more articles in the Banking category

    Image for How Risk Management Is Strengthening Stability in Modern Banking
    How Risk Management Is Strengthening Stability in Modern Banking
    Image for Apply Now for Best Bank for HR & Recruitment 2026
    Apply Now for Best Bank for HR & Recruitment 2026
    Image for The Role of Liquidity Management in Strengthening Banking Stability
    The Role of Liquidity Management in Strengthening Banking Stability
    Image for Apply Now for Best New Bank for Sustainable Development 2026
    Apply Now for Best New Bank for Sustainable Development 2026
    Image for Submit Your Nominations Today for Best ESG Bank / Best Green Bank 2026
    Submit Your Nominations Today for Best ESG Bank / Best Green Bank 2026
    Image for Entries Open: Best Bank for Sustainable Development/Best Sustainable Development Bank 2026
    Entries Open: Best Bank for Sustainable Development/Best Sustainable Development Bank 2026
    Image for Entries Open: Most Innovative Private Bank for Intergenerational Wealth Management 2026
    Entries Open: Most Innovative Private Bank for Intergenerational Wealth Management 2026
    Image for Submit Nominations for Most Innovative Private Bank for Digital Client Solutions 2026
    Submit Nominations for Most Innovative Private Bank for Digital Client Solutions 2026
    Image for Submit Your Nominations Today for Fastest Growing Private Bank 2026
    Submit Your Nominations Today for Fastest Growing Private Bank 2026
    Image for Nominations Open for Fastest Growing SME Bank 2026
    Nominations Open for Fastest Growing Sme Bank 2026
    Image for Call for Entries: Fastest Growing Investment Bank 2026
    Call for Entries: Fastest Growing Investment Bank 2026
    Image for Submit Your Nominations for Fastest Growing Islamic SME Bank 2026
    Submit Your Nominations for Fastest Growing Islamic Sme Bank 2026
    View All Banking Posts
    Previous Banking PostHow Banks Can Make the Most of Technology in 2018
    Next Banking PostHow UK Banks Can Combat Low Productivity Rates