Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Business
    3. >While holiday hacks lurk, the insider threat mustn’t be ignored
    Business

    While Holiday Hacks Lurk, the Insider Threat Mustn’t Be Ignored

    Published by maria gbaf

    Posted on December 28, 2021

    5 min read

    Last updated: January 28, 2026

    Add as preferred source on Google
    An image depicting a financial advisor explaining green finance products to clients, highlighting the importance of sustainable investments and risk avoidance in the finance sector.
    A financial advisor discussing green finance options with clients - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Quick Summary

    Insider threats in banking are rising, especially during the holiday shopping season. Effective identity access management is crucial to mitigate these risks.

    Addressing Insider Threats in Banking Amid Holiday Cyber Risks

    By Ben Bulpett, EMEA Identity Platform Director, SailPoint

    The holiday shopping season is in full swing. Online sales are forecast to hit over £32 billion from mid-November to the end of December 2021. However, it’s not all glad tidings; more online shopping equals more sharing of online credentials and greater cyber risk. And this risk is prolific – hackers stole £754 million in the first six months of this year alone.

    Where money flows, criminals follow. Methods used by cybercriminals to infiltrate and exploit the swell of online retail are becoming increasingly more sophisticated. For example, almost one-third of UK respondents to a recent survey said they had received emails and messages impersonating retailers over the past year. According to Which?, ‘smishing’ (SMS phishing) increased by 700% in the first six months of 2021.

    With most credit card transactions at some point going across the banking network, and with the potential financial impact of customer fraud, banks need to be more alert than ever to who is accessing their systems and data. This isn’t limited to just outsider threats, despite these often dominating the headlines. Concerningly, the banking industry retains the dubious reputation of having the highest rates of insider data breaches across any sector. Not always criminal in nature, even accidental breaches can end in misery for customers and providers alike. Running through so many of these breaches are issues with identity access and security.

    While external threats and attacks launched on unsuspecting customers will continue to evolve, banks and financial institutions must ensure their lines of defense remain water-tight. Using AI and machine learning, businesses can put in place appropriate identity security measures to detect unusual behaviour and take immediate action to stop a breach occurring.

    Making a list, checking it twice; who has what and why?

    Managing internal threat, the risk posed by employees themselves, is not often top of the holiday list, with much focus on what criminals are doing to dupe holiday shoppers. When shopping online, banks need to ensure that both the device and the shopper’s identity are verified. However, with the genuine risk of internal data leaks, banks also need to ensure that the employees tasked with handling data and those who have access to it are appropriately screened and audited.

    This starts with ensuring that data is only accessible to those who need to use it. Users with incorrect access privileges are one of the most significant areas of identity fraud. This also includes ex-employees who remain able to access systems due to poor identity and access management practices. Where malicious insiders are provided with access to the data they exploit, such seemingly ‘legitimate’ activity is much harder to detect than that of the brute-force hack.

    There are also legacy issues that can lead to innocent leaks, where financial institutions still in the digital transformation process retain pockets of poor practice. Complex organisational structures mean many are still in a hybrid state where spreadsheets and other manual processes continue to sit alongside more sophisticated processes. This provides ample opportunity for unprotected documents that contain sensitive or PII data to be shared incorrectly or misdirected.

    Without a complete view of all data access across an organisation, there is no way to uncover such hidden risk. This has been made harder during the pandemic where remote working, furlough, and unprecedented hiring have rapidly changed the employee mix and provided additional access points. With the government continuing to issue Covid-prevention measures in reaction to new variants, this landscape is ever changing, but systems and processes are not adapting at the same rate.

    Top of the wish list

    Even in the face of such challenges, preventative steps can be taken to mitigate insider threats. For example, IT teams can use automated access and geolocation alerts to spot abnormal behaviours. Made possible through AI and ML-driven security measures, this can be the basis of an agile identity security foundation that learns and adapt as business needs change.

    Gaining a full view of customer data is hard when so much of this data is unstructured. We are not dealing with simple transactional data anymore. Indeed, some challenger banks, in particular, are increasingly using biometric authentication such as voice, fingerprint, or video (notwithstanding the recent wave of concern around deep fake technologies) within multi-factor authentication, giving rise to the need to protect extremely sensitive personal data, beyond the financial.

    Identity security is a cybersecurity tactic that delivers a holistic view of data access in an organisation, with a pure view of all identities, their permissions, and actions. This provides greater visibility over each application, data repository, cloud service, and internal platform, reducing the risk of password duplication, permissions creep, and over-provisioning.

    While much attention is on the risk posed by external holiday hacks and scams, the ongoing risk posed by the insider threat cannot be ignored. Identity security must be top of the wish list for banks seeking to shore up defenses against potential breaches or hacks. Any criminal activity that results in customers losing funds or having sensitive data comprised is clearly of the utmost concern to banks, both given regulatory fines incurred as well as major reputational damage. However, where that criminality results from poor internal controls and identity security, it is almost unforgivable.

    During this holiday season, financial institutions, of course, must be alert and responsive to new scams and sophisticated external attacks. The risk is that this facilitates a blind spot, where they fail to see the threat sitting at their own table.

    Key Takeaways

    • •Insider threats in banking pose significant cybersecurity risks.
    • •Online shopping increases cyber threats during the holiday season.
    • •Identity access management is crucial for preventing data breaches.
    • •Banks must screen and audit employees handling sensitive data.
    • •Remote work has complicated data access and security measures.

    Frequently Asked Questions about While holiday hacks lurk, the insider threat mustn’t be ignored

    1What is the main topic?

    The article discusses insider threats in banking and the importance of identity access management during the holiday season.

    2How can banks mitigate insider threats?

    Banks can mitigate insider threats by implementing strong identity access management and auditing employee access to sensitive data.

    3Why are insider threats a concern during holidays?

    Insider threats are a concern during holidays due to increased online shopping, which raises the risk of data breaches and cyber attacks.

    More from Business

    Explore more articles in the Business category

    Image for Submit Your Entry for Years of Excellence Awards 2026
    Submit Your Entry for Years of Excellence Awards 2026
    Image for Nominations Open for Travel & Hospitality Awards 2026
    Nominations Open for Travel & Hospitality Awards 2026
    Image for Submit Your Entry Today for Telecom Awards 2026
    Submit Your Entry Today for Telecom Awards 2026
    Image for Submit Your Entries for The Next 100 Global Awards 2026
    Submit Your Entries for the Next 100 Global Awards 2026
    Image for Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Image for Nominations Invited for Real Estate Development Awards 2026
    Nominations Invited for Real Estate Development Awards 2026
    Image for Submit Your Entry: Process & Product Awards 2026
    Submit Your Entry: Process & Product Awards 2026
    Image for Call for Entries: HR & Recruitment Awards 2026
    Call for Entries: HR & Recruitment Awards 2026
    Image for Submit Your Nominations Today for Education & Training Awards 2026
    Submit Your Nominations Today for Education & Training Awards 2026
    Image for Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Image for Submit Your Entry Today for Business Awards 2026
    Submit Your Entry Today for Business Awards 2026
    Image for Decentralized Masters’ ‘family culture’ building trust instead of hierarchy
    Decentralized Masters’ ‘family Culture’ Building Trust Instead of Hierarchy
    View All Business Posts
    Previous Business PostCustomer Satisfaction, Data & the Post-Pandemic Recovery
    Next Business PostRetail Technologists Must Brace Themselves for a Holiday Season Like No Other