04 Feb 2009
Financial institutions are facing an increased risk of security breaches this year owing to budgetary constraints and an increased threat of insider misconduct, according to the latest annual Global Security Survey from Deloitte.
The research found that internal and external security breaches at financial institutions worldwide actually fell over the past year, but that employee misconduct is a growing concern.
Some 36 per cent of respondents expressed a greater level of concern about insiders, compared to only 13 per cent who were more concerned about external misconduct. In addition, 58 per cent said that they felt 'not very' or only 'somewhat' confident in their ability to protect their organisation from internal cyber attacks.
The threat to organisations from their own employees was confirmed by the fact that 86 per cent of respondents indicated that human error is the leading cause of information systems failure.
Although 60 per cent of respondents said that information security budgets have increased, more than half identified budgetary constraints and lack of resources as the main barriers to effective information security. Lack of resources was cited by a third as the main cause of information security project failure.
Mike Maddison, head of Deloitte's security and privacy practice, warned that financial organisations face a battle on two fronts to protect customer data.
"On one side is the growing sophistication of hackers that exploit new technologies such as social networks, and on the other side is the challenging economic environment and potential redundancies that have created a distracted workforce and a growing number of disgruntled former employees," he said.
"In this economic climate it is vital that firms become extra vigilant in protecting their data, and implement checks and measures to reduce the potential impact of human error."
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Key skills for this role include a comprehensive understanding...
Fantastic opportunity for an Information Security Professional...
VB.NET Developer / SQL / VB6 / ASP / XML / Cheshire...
Fantastic opportunity for a high calibre Security Architect...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Top Audit Finding Excessive Access Rights
It is very interesting to read about how the effects of the economic crisis is heightening security risks at the world's largest financial institutions. It comes as no surprise that identity and access management (IAM) and security regulatory compliance were the top security initiative of financial institutions for the past 2 years. Increasing regulation and industry guidelines, as well as the need to provide secure access to systems for suppliers, business partners and others is driving the need for identity and access management and compliance solutions. In spite of this, many of these organizations have a growing concern about insider threats - according to the survey 36 per cent of respondents expressed a greater level of concern about insiders. 'Excessive access rights' was the top internal/external audit finding over the past 12 months and 'unauthorized access to personal information' was the number one privacy concern stated by respondents. As financial institutions face an increased risk of security breaches this year due to budgetary constraints and an increased threat of insider misconduct, an access assurance strategy can help them to strengthen security and improve compliance by assuring users' access rights and activities are compliant with policy while aligning security and business objectives. Stuart Hodkinson, General Manager UK, Courion
Posted by: Stuart Hodkinson, General Manager UK, Courion 06 Feb 2009