About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

FCA Urges Greater Cyber Resilience

Subscribe to our newsletter

The number of cyber incidents financial services firms reported to the Financial Conduct Authority (FCA) soared in 2018, and the watchdog is now calling on regulated firms to develop greater cyber resilience to prevent attacks and operational resilience to recover from them.

According to data recently acquired by accountancy firm RSM under the Freedom of Information Act, cyber attacks on financial services firms increased 12-fold in 2018, with 819 incidents reported in 2018 compared to just 69 in 2017. Banks are the most vulnerable, accounting for over 50% of reports, while whole financial markets reported 115 incidents and retail investment firms accounted for 53.

Firms also reported a 187% increase in technology outages to the FCA, with 18% cyber-related and 20% specifically related to change management.

The FCA is now calling for greater IT security awareness across the financial industry, following a survey last year which found that nearly half of regulated financial services firms do not upgrade or retire old IT systems in time, while only 56% say they can measure the effectiveness of their information asset controls. Only the largest firms have automated their detection systems to spot potential cyber attacks, with smaller firms generally relying on old school, manual processes – or no processes at all. The regulator also suspects that under-reporting is still an issue, suggesting that the problem could be even more widespread.

“The current threat level is remarkable,” warns Megan Butler, Executive Director of Supervision – Investment, Wholesale and Specialists at the FCA. “Keeping this in mind, it is a major concern that a lot of firms still seem to be trying to get the basics right on cyber. A third of firms do not perform regular cyber assessments. Most know where their data is. But describe it as a challenge to maintain that picture.”

The financial services industry is currently one of the slowest to address security flaws. According to cyber security firm Veracode it takes an average 163 days to fix security defects in a financial institution, compared to (for example) just 43 days in Healthcare.

“Global financial institutions are consistently a favourite target of attackers and will continue to be until they speed up vulnerability remediation. Leaving holes in a bank’s security posture is like leaving the keys to the castle under the mat, putting highly valuable information and critical assets at risk,” warns Paul Farrington, Veracode’s EMEA Chief Technology Officer.

“Whilst our data shows the sector is in fact scanning a huge volume of applications and finding flaws that need fixing, the next frontier is achieving greater speed in fixing those flaws, because speed matters. The velocity at which organisations fix flaws they discover in their code directly mirrors the level of risk incurred by applications. The financial sector should consider all dimensions of risk to prioritise which flaws to fix first.”

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Effective due diligence, screening and monitoring to mitigate financial crime risk

Managing financial crime risk requires a comprehensive approach to due diligence, screening, and continuous monitoring. Financial institutions face increasing regulatory scrutiny and staying compliant in today’s dynamic environment requires advanced technologies. Failure to comply is resulting in severe enforcement penalties. This webinar will explore practical strategies and tools for mitigating financial crime risk, focusing on...

BLOG

LBBW Selects Fenergo for Onboarding and Client Lifecycle Management (CLM)

Landesbank Baden-Württemberg (LBBW), Germany’s largest state bank, is implementing a cloud-based client onboarding system aimed at improving its compliance processes, based on Fenergo’s client lifecycle management platform (CLM). LBBW, with total assets of €324 billion, hopes the initiative will enhance its automation capabilities and increase operational efficiency. As part of the project, LBBW will deploy...

EVENT

AI in Capital Markets Summit London

The AI in Capital Markets Summit will explore current and emerging trends in AI, the potential of Generative AI and LLMs and how AI can be applied for efficiencies and business value across a number of use cases, in the front and back office of financial institutions. The agenda will explore the risks and challenges of adopting AI and the foundational technologies and data management capabilities that underpin successful deployment.

GUIDE

Regulatory Data Handbook 2024 – Twelfth Edition

Welcome to the twelfth edition of A-Team Group’s Regulatory Data Handbook, a unique and useful guide to capital markets regulation, regulatory change and the data and data management requirements of compliance. The handbook covers regulation in Europe, the UK, US and Asia-Pacific. This edition of the handbook includes a detailed review of acts, plans and...