About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

OFR’s Ref Data Could be a Cyber Attack Target, Warns Sans Institute’s Paller

Subscribe to our newsletter

As well as coming under attack for its central theory of collecting data for systemic risk analysis during a government organised roundtable last week (see more on which here), the US Office of Financial Research (OFR) also came under fire for the potential information security threat it could pose. Alan Paller, founder and research director of the global security focused Sans Institute, indicated that federal agencies currently prove to be easy targets for cyber attacks and unless much more rigorous IT security measures are taken for the OFR, it will end up putting the data it collects at risk.

“As long as security remains so lax inside government, there is great risk that any data gathered by government would be easy prey for financial criminals and nation states bent on cyber mischief,” said Paller. “This concern applies particularly to small agencies that may lack the scale to implement first class cyber security protections. For example, if the OFR moves data from well protected financial sites to less well protected government or contractor sites, they will put that data at risk.”

Given that Swift and the Depository Trust and Clearing Corporation (DTCC) have been backed by the industry to take on the mantle of establishing and maintaining the new legal entity identification (LEI) standards that are required by the OFR, both will no doubt refute that their data repositories could pose such a threat. After all, Swift sells itself on the basis of the security and resilience of its financial messaging network and the DTCC is already a data repository and clearer trusted by the government authorities.

However, it is by no means a done deal that these two will act as the technology and standards partners for the whole of the OFR, this mandate only covers the LEI. What of the other systemic risk monitoring data items listed by Berner and Liechty last week? Surely sensitive transaction reporting and internal risk data are potentially at threat in Paller’s eyes?

To guard against the dangers of a cyber attack, Paller therefore listed a number of suggested defences that should be introduced against these dark forces:

  • Continuous (daily) monitoring of the 20 key controls in the Consensus Audit Guidelines (CAG) and the exclusive use of tools that strictly adhere to the automation and interoperability requirements of the security configuration automation protocols developed by the National Institute of Standards and Technology (NIST) and the National Security Agency (NSA).
  • Implacable adherence to operating system and software configurations defined in the Universal Gold Master configurations approved by the Department of Defence’s Joint Consensus Working Group.
  • Rigorous multi-factor identity validation of every user without exceptions.
  • A team of at least eight “hunters and tool builders” who use constantly updated scripts to monitor OFR system logs and network information continuously to find evidence of penetrations and then reverse engineer, and eliminate malicious programmes that make it through the perimeter.
  • Software code analysis and penetration testing for all software that accesses sensitive information and any that allows access to the systems, such as websites.
  • Auditors who verify these defences are in place and substantial consequences for auditors if they miss well known problems.

If the risk to the nation’s financial system is great enough, determine whether the collected data should be treated as, and protected as classified data.

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: The Role of Data Fabric and Data Mesh in Modern Trading Infrastructures

23 September 2025 10:00am ET | 3:00pm London | 4:00pm CET Duration: 50 Minutes The demands on trading infrastructure are intensifying. Increasing data volumes, the necessity for real-time processing, and stringent regulatory requirements are exposing the limitations of legacy data architectures. In response, firms are re-evaluating their data strategies to improve agility, scalability, and governance....

BLOG

Data’s Evolution Continues From Cost to Core Asset: DMS New York City 2025 Preview

Modern Chief Data Officers are not only the guardians of financial institutions’ data estates, they are also the caretakers of their single-biggest asset. With every part of an organisation’s business now dependent on data, the custody of its digital information is every bit as critical to operations as the management of trading teams or even...

EVENT

TradingTech Briefing New York

Our TradingTech Briefing in New York is aimed at senior-level decision makers in trading technology, electronic execution, trading architecture and offers a day packed with insight from practitioners and from innovative suppliers happy to share their experiences in dealing with the enterprise challenges facing our marketplace.

GUIDE

The DORA Implementation Playbook: A Practitioner’s Guide to Demonstrating Resilience Beyond the Deadline

The Digital Operational Resilience Act (DORA) has fundamentally reshaped the European Union’s financial regulatory landscape, with its full application beginning on January 17, 2025. This regulation goes beyond traditional risk management, explicitly acknowledging that digital incidents can threaten the stability of the entire financial system. As the deadline has passed, the focus is now shifting...