Blog

Building Societies are at risk

BY eSentire

May 22, 2018 | 3 MINS READ

Regulatory Compliance

Cybersecurity Strategy

Want to learn more on how to achieve Cyber Resilience?

TALK TO AN EXPERT

Building societies offer banking, savings and mortgage lending, and other financial services, all of which makes them privy to their clients’ financial accounts and personal information. As a result, cybercriminals are targeting building societies for this data, as well as trade secrets and other information that could be used to their advantage.

Unfortunately—as it stands—many building societies have limited resources and so are resorting to using automated defences to catch threats, which is leaving them exposed. The risk of cyber-attacks has put operational resilience (including cyber resilience) on the priority list of regulators.

“It is no longer just about cybersecurity and building those security walls around your business even higher. It is also about considering different aspects of how the risk actually manifests today…Some of the biggest challenges come from old legacy systems and the integration of acquisitions.”

The potential effects of a breach include:

“Traditional cyber security strategies, such as firewalls and intrusion detection systems, are no longer enough to prevent determined threat actors.”- PRA Cyber Resilience Questionnaire

Threats targeting Building Societies

According to eSentire Threat Intelligence, common attack methods used against the finance industry include:

These methods can cause serious business disruptions and extensive costs if not detected and responded to quickly.

Cybersecurity compliance requirements

Cyber-attacks aren’t the only thing building societies need to be thinking about. Your organisation will be required to comply with the Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) cybersecurity guidance and/or requirements. In fact, the PRA recently created a cybersecurity questionnaire that will be used to assess a firm’s cyber resilience and their ability to detect, respond and recover from cyber-attacks.

Furthermore, with the General Data Protection Regulation (GDPR) coming into affect in May 2018, there will be greater accountability surrounding security policies and specific data breach notification obligations.

In other words, compliance regulations matter more than they ever have, and businesses needs to be prepared to meet increasing requirements.

The faster the firm catches the threat, the lower the impact

Breaches can have a significant impact on your business and customers. Recent attacks on building societies have resulted in clients’ personal information being compromised[1] and confidential emails being leaked.[2]

Fortunately, the next victim doesn’t have to be you. According to Aberdeen’s Monte Carlo analysis, being twice as fast at threat detection and incident response lowers the business impact of a cyber-attack by approximately 70%. The only way to avoid an incident and react quickly is to have a certified Security Operations Centre (SOC) with human analysts hunting and responding to threats on your network 24x7x365.

We defend against the threats facing building societies

eSentire Managed Detection and Response™ (MDR) keeps building societies safe from cyber-attacks that other technologies miss. Our 24x7 Security Operations Centres (SOC) are staffed by elite security analysts who hunt, investigate and respond to known and unknown threats in real time. With MDR, you’ll experience:

We prepare building societies for complex compliance and regulatory requirements

Beyond MDR, our dedicated security experts help firms assess risks, address known gaps and build a comprehensive cybersecurity program that meets stringent regulatory requirements. With eSentire Advisory Services, you’ll have access to:

Security Program Maturity Assessments

About eSentire

eSentire is the largest pure-play Managed Detection and Response (MDR) service provider, keeping organisations safe from constantly evolving cyber-attacks that technology alone cannot prevent. Its 24x7 Security Operations Centre (SOC), staffed by elite security analysts, hunts, investigates, and responds in real-time to known and unknown threats before they become business-disrupting events. Protecting more than £4 trillion in corporate assets, eSentire absorbs the complexity of cybersecurity, delivering enterprise grade protection and the ability to comply with growing regulatory requirements. For more information, visit www.eSentire.com and follow @eSentire.


 

[1] https://www.expressandstar.com/news/2017/04/05/identity-theft-warning-as-stafford-building-society-hit-by-hackers/

[2]https://www.hrbs.co.uk/14350-statement-on-cyber-incident/

eSentire
eSentire

eSentire, Inc., the Authority in Managed Detection and Response (MDR), protects the critical data and applications of 2000+ organizations in 80+ countries, across 35 industries from known and unknown cyber threats by providing Exposure Management, Managed Detection and Response and Incident Response services designed to build an organization’s cyber resilience & prevent business disruption. Founded in 2001, eSentire protects the world’s most targeted organizations with 65% of its global base recognized as critical infrastructure, vital to economic health and stability. By combining open XDR platform technology, 24/7 threat hunting, and proven security operations leadership, eSentire's award-winning MDR services and team of experts help organizations anticipate, withstand and recover from cyberattacks. For more information, visit: www.esentire.com and follow @eSentire.

Read the Latest from eSentire