?

Bank of England’s Systemic Risk Survey shows risk of cyber attack increasing for third time running

The proportion of firms citing cyber attack as a key risk has increased for the third consecutive time in the Bank of England’s Systemic Risk Survey. The survey highlights perceived risks to the UK financial system.

Posted by Global Banking & Finance Review on June 28, 2018:

The proportion of firms citing cyber attack as a key risk has increased for the third consecutive time in the Bank of England’s Systemic Risk Survey, released today. The survey highlights perceived risks to the UK financial system. Although overall confidence in the UK’s system has increased, the number of firms who perceive cyber attack as a risk has increased to 62 percent.

Finding new ways to mitigate this risk is a growing area of focus for financial services firms. The Bank of England is developing new guidelines to help firms demonstrate resilience against technology threats. The tech industry is coming up with lots of product recommendations to help firms address cyber risk.

But financial services firms are increasingly moving away from a product-centric approach to cyber-security. Instead, they are focusing on compartmentalising and individually securing their critical applications, such as online banking or interbank payments, in order to prevent a domino effect if one area comes under attack.

But due to legacy infrastructure, it can be difficult for financial institutions to gauge how applications are built into the network and communicating with each other in real-time. This is a crucial first step when it comes to writing security policies for individual applications, says Nick Hammond, Lead Advisor for Financial Services at World Wide Technology. It’s important that firms can work out what effects each policy could have on the way the entire system functions.

Nick Hammond, from World Wide Technology, comments: “With financial services firms facing high-levels of regulatory interest in their cyber defences, they are working towards ensuring a high level of application assurance. Whilst older rules required yearly tick-box compliance exercises, new regulations necessitate continued assurance of critical applications.

“But due to the complex nature of existing systems which have been built with different and sometimes conflicting metrics over the years, legacy infrastructures are typically built from a complex patchwork of applications, which communicate with each other in complicated ways.

View the full article here.

Additional Coverage

Read full article here