Financial sector firms failing to combat cyber security threats

The majority of financial companies have experienced a cyber security incident in the past year, highlighting the serious threat that both data breaches and malicious attacks pose to the UK financial sector. Research by data security company Clearswift found that 70% of financial companies have experienced an incident in the past 12 months.

The survey of senior business decision makers within financial sector organisations in the UK, found that almost half of the incidents reported over the past year originated from employees failing to follow security protocol or data protection policies. This threat was biggest in mid-sized financial companies (3,000 – 4,999 employees) with 52% of respondents citing employee failure to follow corporate data protection policies as their biggest issue.

Further causes of cyber security incidents within the financial sector included the introduction of malware and viruses via third-party devices, including USBs and BYOD (32%), file and image downloads (25%) and employees sharing data with unintended recipients (24%).

“The financial sector is the lynchpin of the UK’s economy and a vital part of our nation’s Critical National Infrastructure, so it is alarming to see such high numbers of security incidents within financial organisations,” said Dr. Guy Bunker, CTO, Clearswift. “Unfortunately, it is a case of ‘when’ not ‘if’ a firm is breached so the financial sector needs to shift gears and speed up the innovation and deployment of effective data protection and threat mitigation strategies.”

The numbers associated with security incidents are in stark contrast with further findings from the survey which revealed less than a quarter (23%) of respondents had an adequate level of budget allocated to cyber security within the firm. 73% of respondents would like to see some, if not significant, increase in their organisation’s cyber security spending.

Bunker added: “Whether it’s an inadvertent mistake, a malicious insider, or an external threat actor that causes a security incident, the ramifications of data loss are extremely serious for any organisation. For those organisations who hold citizen data and their financial information, there is a need for extra vigilance to protect that data no matter where it is stored, how it’s processed or what digital collaboration channels it flows through. Understanding the latest threats and the potential consequences from next generation attacks will help drive the business case for investment in new technology to mitigate the risks.”

He added: “Cyber security needs to rapidly evolve and the budgeting process should take this into account – the threat which can bring down a company may not have existed three months ago. Financial organisations need to be able to respond immediately in order to protect their reputation.”

    Share Story:

Recent Stories


Financial institutions were early adopters of cyber security and insurance. Are they still on top of the game?
Managing huge amounts of sensitive data online makes financial institutions a prime target for hackers. As such, the sector was an early cohort for insurers in creating cyber cover. Since then, the market has evolved almost beyond recognition. It continues to challenge itself to this day, complying with rigorous regulatory demands and implementing avant-garde enhancements to keep abreast of the ever-changing risks. Published June 2021

Manufacturing: An industry at risk amid great technological change
Of the many sectors of business, manufacturing companies are among the most at risk from cyber threats. How has the sector evolved to make it so vulnerable and what does the task of managing cyber exposure in a manufacturing company look like? CIR’s latest podcast with Tokio Marine HCC sought to answer all these questions and more. Published April 2021