Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Technology > The top three threats to post-Covid FSI security
    Technology

    The top three threats to post-Covid FSI security

    The top three threats to post-Covid FSI security

    Published by Jessica Weisman-Pitts

    Posted on March 1, 2022

    Featured image for article about Technology

    By Sarah Armstrong-Smith, Chief Security Advisor, Microsoft UK

    How tech can guard against the most modern forms of cybercrime

    Throughout the global pandemic, FSI organisations have been under increased pressure to continue to deliver an array of services – they have had to adjust to remote and hybrid working, as well as supporting consumers with loans and Government-backed payment schemes. The key to the pandemic response was adaptability, availability, and speed – and FSIs rose to the challenge with gusto. But now, security and compliance are back on top as one of the most important factors for FSI organisations to focus on, and technology will be crucial in the fight back against a growing number of cybercriminals.

    Cybercrime is now as profitable as the drugs trade

    Cybercrime has evolved during the pandemic too, and cybercriminals are advancing their tactics, at scale, to capitalise on how profitable it has become. In fact, cybercrime is now comparable to the global drugs trade with regards to the level of profit and syndication involved in cyber criminal’s operations, where groups are created, and each member is paid for a particular expertise. Attackers evade detection with high levels of sophistication and move money extremely quickly. They also operate cross jurisdictions, taking advantage of a lack of law enforcement collaboration between some nations.

    Of course, not only are FSI organisations high-value targets for cybercrime, but they are also potentially liable for additional costs when protecting their consumers from being the victims of increasingly sophisticated scams and fraud. Insurers are having to pay out large sums when victims of ransomware and email compromise claims, with additional pressure coming from consumers and regulators. FSIs must be cognisant that the risk is evolving rapidly, and they themselves are huge targets for attack – particularly when nation state actors are taken into consideration.

    The top three threats

    When it comes to cybercrime, research from Microsoft revealed the three key areas FSI organisations need to protect against when it comes to the changing threat landscape, with each being operationally, reputationally and financially damaging. Each is growing in prevalence and complexity.

    Phishing continues to be the most common cyber threat, with 70% of all attacks starting with phishing or credential compromise. Phishing emails are designed to trick an individual into sharing sensitive information, such as usernames and passwords with an attacker, most commonly using malicious domains which masquerade as well known, legitimate login pages. Attachments may also contain malware, designed to be released on to endpoints and into the target network. Meanwhile, credentials and other types of information are obtained by the attacker for later abuse or sale.

    Secondly, ransomware is one of the most operationally impacting cybercrimes, as we see criminal actors performing reconnaissance on a target victim to infiltrate their critical infrastructure and potentially gaining access to financial documents and insurance policies to identify an optimal ransom demand. Ransomware has grown to include a variety of extortion techniques enabled by human intelligence and research. A common attack involves a threat actor deploying malware and scripting that encrypts and exfiltrates data and then holds that data for a ransom, often demanding payment in cryptocurrency.

    Thirdly, while not the most prolific type of malicious email in terms of quantity, business email compromise (BEC) is becoming a growing concern and could be considered the most financially impacting cybercrime of all, equating to 40% of all financial crime on the internet. Email compromise is one of the growth areas of cyberattacks, particularly when we consider the abuse and resilience of the supply chain. BEC attacks occur when an attacker pretends to be a legitimate businessperson often in a position of authority, most often by using a compromised email address, or spoofing a company domain. It benefits from the complexity of financial accounting, by monitoring financial or business-related messages to intercept. One party to a financial transaction is impersonated to authorise transactions or divert payments to an unauthorised recipient. In this case, it is particularly insidious as the person whose credentials and email account were compromised would unknowingly cause another person or company to become a victim.

    Technology plays a crucial role in the defence against cybercrime

    Technologies such as cloud, AI, data analytics and multi-factor authentication can all play a crucial role in protecting FSI’s critical infrastructure against cyberattacks, especially considering external stimuli including nation state actors, the continued proliferation of hybrid working and the rapid spread of disinformation.

    Many FSI organisations are reconsidering their business models and are looking to the Cloud, to seek innovation and increased security capacity, as well as cost optimisation. We have seen a shift in emphasis over the last few years, as boardrooms learn that cybersecurity is fundamental to every aspect of their business operations, but more education is critical to this. FSIs must make it an organisational priority to increase that understanding and awareness of the threats involved from cybercrime across their businesses, as well as being cognisant of it as an evolving and sophisticated risk.

    As well as the agility and flexibility the cloud can provide, one of the biggest benefits of a cloud-first strategy from a cybersecurity perspective is having access to threat intelligence and trend reports. Cloud service providers are actively monitoring a variety of different threat actors globally, whether they are ransomware operators or nation states, and disseminate intelligence about the evolving tactics and techniques, which enables organisations to evolve their response.

    FSI organisations stand the best chance of defending against cyberattacks by being empowered with knowledge and supported in their security and compliance objectives. Cloud service providers have a huge role to play in the future of cybersecurity. Not just in terms of protecting companies, but also protecting nations as well.

    Related Posts
    Treasury transformation must be built on accountability and trust
    Treasury transformation must be built on accountability and trust
    Financial services: a human-centric approach to managing risk
    Financial services: a human-centric approach to managing risk
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    How Integral’s CTO Chidambaram Bhat is helping to solve  transfer pricing problems through cutting edge AI.
    How Integral’s CTO Chidambaram Bhat is helping to solve transfer pricing problems through cutting edge AI.

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Technology PostFintech apps are an advisor’s ally, not a foe
    Next Technology PostPACE Anti-Piracy Raises the Bar in White-Box Encryption Protection for Bank, PSP, and Payment Scheme Applications

    More from Technology

    Explore more articles in the Technology category

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Compliance Has Become an Engineering Problem

    Why Compliance Has Become an Engineering Problem

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    How Nclude.ai   turned broken portals into completed applications

    How Nclude.ai turned broken portals into completed applications

    The Silent Shift: Rethinking Services for a Digital World?

    The Silent Shift: Rethinking Services for a Digital World?

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    View All Technology Posts