Story image

Why financial services firms shouldn't fear cloud security

21 Aug 17

Data security concerns may be delaying financial services providers’ move to the cloud, but it’s a fear that is leading to missed opportunities in efficiency gains and cost savings, according to advice from Palo Alto Networks.

If organisations take the right security precautions, there is no reason to avoid the benefits that cloud brings, the company states.

Palo Alto Networks Asia Pacific vice president and regional CISO Sean Duca says that in the recent State of Cybersecurity in Asia Pacific report, 31% of Asia Pacific organisations name cloud migration as one of the biggest issues that financial services organisations face.

“Interestingly, this trend remains roughly similar for companies regardless of market, industry or number of employees. This indicates that, in a world of increased interconnectedness, all businesses worry about the impact their internal shortcomings may have on their external vulnerabilities, and vice versa,” the report says.

Duca explains that the State of Cybersecurity in Asia Pacific report interviewed 500 participants across Australia, China, Hong Kong, India and Singapore.

“The study included over 100 respondents from Australia. While some Australian banks are starting to experiment with moving to the cloud, there are still many who remain apprehensive due to concerns their customers’ data might be compromised,” he says.

The report found that financial organisations across Asia Pacific are also seeing increased budgets for cybersecurity. 72% of surveyed financial organisations reported increased budgets; with India, China, Singapore and Hong Kong leading the way.

Duca believes that data security is important. If it is done right, it won’t be the major fear some organisations believe it could be.

“As cloud adoption grows across the industry, financial services organisations need to put the data being passed to the cloud through the same scrutiny as all other data. Visibility into that data needs to be maintained, and security policies and management must be applied consistently regardless of the location of that data. If they do this effectively, financial services organisations don’t need to fear the cloud,” he explains.

He also says that financial services organisations operate in a highly-regulated environment.

“Any loss of organisational or customer data could have reputational implications and lead to financial penalties. While it’s impossible to prevent every breach, the most important thing is to stop the attacker from achieving their objective and thus prevent material impact on the business.”

In order to properly secure data security, IT teams should keep abreast of the most likely targeted threats, prioritise them in terms of their potential business impact, and then form mitigation strategies to reduce risk and effects of a successful attack.

“Most organizations in the Asia-Pacific region (58%) believe that the “detect and respond” approach to cybersecurity is more important than prevention,” the report says.

The company says that regardless of how data is accessed and shared, it must be secured to protect organisations and customers. Financial services organisations should control network access, segment traffic, and invest in solutions that can help them manage the complex nature of today’s cybersecurity landscape.

Disruption in the supply chain: Why IT resilience is a collective responsibility
"A truly resilient organisation will invest in building strong relationships while the sun shines so they can draw on goodwill when it rains."
Verifi takes spot in Deloitte Asia Pacific Fast 500
"An increasing amount of companies captured by New Zealand’s Anti-Money laundering legislation are realising that an electronic identity verification solution can streamline their customer onboarding."
Businesses too slow on attack detection – CrowdStrike
The 2018 CrowdStrike Services Cyber Intrusion Casebook reveals IR strategies, lessons learned, and trends derived from more than 200 cases.
What disaster recovery will look like in 2019
“With nearly half of all businesses experiencing an unrecoverable data event in the last three years, current backup solutions are no longer fit for purpose."
Proofpoint launches feature to identify most targeted users
“One of the largest security industry misconceptions is that most cyberattacks target top executives and management.”
McAfee named Leader in Magic Quadrant an eighth time
The company has been once again named as a Leader in the Gartner Magic Quadrant for Security Information and Event Management.
Symantec and Fortinet partner for integration
The partnership will deliver essential security controls across endpoint, network, and cloud environments.
Is Supermicro innocent? 3rd party test finds no malicious hardware
One of the larger scandals within IT circles took place this year with Bloomberg firing shots at Supermicro - now Supermicro is firing back.