Find White Papers
Home
About Us
List Your Papers
    
> Quocirca > Banks and Data Leak Prevention

Banks and Data Leak Prevention

White Paper Published By: Quocirca

The financial services industry deals with a commodity that is primarily electronic — money. Consequently it spends more per employee on IT than any other industry.  Despite this, there is a worrying tendency for information that should be confidential to end up in the public domain. Why is this and what can be done?



Tags : 
quocirca, bank, banks, financial services, finserve, finserv, network security, customer data

Quocirca
Published:  Feb 05, 2008
Type:  White Paper
Length:  4 pages



QUOCIRCA BRIEFING January 2008 Banks and data leak prevention Contacts: Banks are an obvious target for data thieves-how can they be stopped? Bob Tarzey Quocirca Ltd Tel +44 1753 855794 The financial services industry deals with a commodity that is primarily electronic-bob.tarzey@quocirca.com money. Consequently it spends more per employee on IT than any other industry. Clive Longbottom Despite this, there is a worrying tendency for information that should be confidential Quocirca Ltd to end up in the public domain. Why is this and what can be done? Tel +44 118 948 3360 clive.longbottom@quocirca.com The financial consequences of data theft for banks are direct and indirect When a customer?s money is stolen electronically, the onus is on the bank to compensate. The bank can also face fines if the loss is caused by careless data management on its part and publicity can lead to brand damage. Banks have to share data and it is often not a bank itself that is responsible for data leaks Consumers get caught unawares by email scams, businesses are careless with BRIEFING NOTE: customer information and public sector bodies, with which banks are obliged to This briefing has been share information, have proved to be reckless in the way they handle data. written by Quocirca to address issues faced by Banks need to review their IT infrastructure financial services Ultimately, for thieves to achieve their goals they need access to financial organisations with regard to data loss. services and products that the banks have ultimate control over. Strict management and auditing of all IT assets is essential. The report draws on Quocirca's knowledge of The software development process needs rigorous quality control the technology and business issues faced by Examples are on record of backdoors being built into banking systems by rogue banks and other financial developers. Testing and auditing must be exhaustive and carried out using services companies and dummy, not real, customer data. provides advice on the approaches that can be taken to prevent data Processes need to be well defined and audited leakage. The way in which data and transactions are handled internally needs to be governed by strong processes. Those responsible for weak processes or those During the preparation of this report, Quocirca has who ignore strong ones must face the consequences. spoken to a number of end users, service providers Education and awareness needs to be driven by banks and vendors and is grateful Banks need to keep up awareness campaigns for consumers and encourage best for their time and insights. practice amongst their business customers to prevent data leakage. Quocirca would like to thank Symantec for its The level of potential risk is not going to decrease sponsorship of this report. New financial products, such as e-wallets and the continuing growth of internet shopping and other online services, will mean more and more opportunity for would-be thieves. In order for this growth to continue, people need to have more confidence in the way their financial data is being managed.
An independent briefing by Quocirca Ltd. www.quocirca.com Banks and data leak prevention Page 2
Financial services, IT and data security which a persistent hacker could probably work around. Financial services organisations (including banks, insurance companies, building societies and so The obvious downside for banks is money lost on, but referred to from here on as just "banks?) through theft, but it goes beyond this. There is spend more on information technology (IT) per compensation to be paid to customers who may employee than those in any other industry. Some become victims through no fault of their own and estimates suggest it is fines may be incurred for regulatory breach. Then more than double that there are indirect costs-such exposure can cause spent in the utility, customers to desert and share prices to drop, telecoms and public leading to further financial loss and brand sectors. damage: a real worry, especially for a trusted high street bank. Customers may lose confidence in There are a number of transacting electro... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search