Story image

Why financial services firms shouldn't fear cloud security

21 Aug 17

Data security concerns may be delaying financial services providers’ move to the cloud, but it’s a fear that is leading to missed opportunities in efficiency gains and cost savings, according to advice from Palo Alto Networks.

If organisations take the right security precautions, there is no reason to avoid the benefits that cloud brings, the company states.

Palo Alto Networks Asia Pacific vice president and regional CISO Sean Duca says that in the recent State of Cybersecurity in Asia Pacific report, 31% of Asia Pacific organisations name cloud migration as one of the biggest issues that financial services organisations face.

“Interestingly, this trend remains roughly similar for companies regardless of market, industry or number of employees. This indicates that, in a world of increased interconnectedness, all businesses worry about the impact their internal shortcomings may have on their external vulnerabilities, and vice versa,” the report says.

Duca explains that the State of Cybersecurity in Asia Pacific report interviewed 500 participants across Australia, China, Hong Kong, India and Singapore.

“The study included over 100 respondents from Australia. While some Australian banks are starting to experiment with moving to the cloud, there are still many who remain apprehensive due to concerns their customers’ data might be compromised,” he says.

The report found that financial organisations across Asia Pacific are also seeing increased budgets for cybersecurity. 72% of surveyed financial organisations reported increased budgets; with India, China, Singapore and Hong Kong leading the way.

Duca believes that data security is important. If it is done right, it won’t be the major fear some organisations believe it could be.

“As cloud adoption grows across the industry, financial services organisations need to put the data being passed to the cloud through the same scrutiny as all other data. Visibility into that data needs to be maintained, and security policies and management must be applied consistently regardless of the location of that data. If they do this effectively, financial services organisations don’t need to fear the cloud,” he explains.

He also says that financial services organisations operate in a highly-regulated environment.

“Any loss of organisational or customer data could have reputational implications and lead to financial penalties. While it’s impossible to prevent every breach, the most important thing is to stop the attacker from achieving their objective and thus prevent material impact on the business.”

In order to properly secure data security, IT teams should keep abreast of the most likely targeted threats, prioritise them in terms of their potential business impact, and then form mitigation strategies to reduce risk and effects of a successful attack.

“Most organizations in the Asia-Pacific region (58%) believe that the “detect and respond” approach to cybersecurity is more important than prevention,” the report says.

The company says that regardless of how data is accessed and shared, it must be secured to protect organisations and customers. Financial services organisations should control network access, segment traffic, and invest in solutions that can help them manage the complex nature of today’s cybersecurity landscape.

Cisco expands security capabilities of SD­-WAN portfolio
Until now, SD-­WAN solutions have forced IT to choose between application experience or security.
AlgoSec delivers native security management for Azure Firewall
AlgoSec’s new solution will allow a central management capability for Azure Firewall, Microsoft's new cloud-native firewall-as-a-service.
How to configure your firewall for maximum effectiveness
ManageEngine offers some firewall best practices that can help security admins handle the conundrum of speed vs security.
Exclusive: Why botnets will swarm IoT devices
“What if these nodes were able to make autonomous decisions with minimal supervision, use their collective intelligence to solve problems?”
Why you should leverage a next-gen firewall platform
Through full lifecycle-based threat detection and prevention, organisations are able to manage the entire threat lifecycle without adding additional solutions.
The quid pro quo in the IoT age
Consumer consciousness around data privacy, security and stewardship has increased tenfold in recent years, forcing businesses to make customer privacy a business imperative.
ForeScout acquires OT security company SecurityMatters for US$113mil
Recent cyberattacks, such as WannaCry, NotPetya and Triton, demonstrated how vulnerable OT networks can result in significant business disruption and financial loss.
Exclusive: Fileless malware driving uptake of behavioural analytics
Fileless malware often finds its way into organisations via web browsers (or in combination with other vectors such as infected USB drives).