09 Jan 2009
Over half of global financial firms have no accurate record of where customer and employee data is collected, transmitted or stored, according to new research from consultancy PricewaterhouseCoopers (PwC).
In addition, 51 per cent of financial services providers said that they do not mandate third parties to adhere to their own privacy policies.
Although 81 per cent of respondents to the PwC survey said they are 'somewhat' or 'very' confident in their own or their partners' information security procedures, only 45 per cent carry out due diligence on third parties that handle sensitive customer and employee data.
"Financial services firms have been leaders in privacy and security, but their policies and capabilities are being outstripped by changes in technology and business practices," said Sergio Pedro, managing director of PwC.
"Firms must address customer demand, competitive pressure and stringent, ever-changing regulatory requirements by developing comprehensive, integrated privacy and data protection programmes."
The research also found that many financial firms focus too much on protecting customer data, neglecting to adequately secure employee records.
Encryption has also been neglected by many of the companies. Some 41 per cent do not encrypt data stored in databases, 52 per cent do not encrypt file shares, 43 per cent do not encrypt backup tapes, and 33 per cent do not deploy laptop encryption.
PwC urged firms to implement a written plan to monitor, respond to and remediate incidents where there is a potential risk of a data breach, and to contractually oblige third parties to protect sensitive data.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Java / Oracle Coherence Technical / Solution Architect...
ASP.Net/C#/Web Development/Desktop Development/Winforms...
My Major client urgently requires an experienced contract...
Decision Systems Analyst West Midlands £19-24,000 Are...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?