Finance watchdog found gaps in security strategies
Published: 25 April 2008 12:45 GMT
The Financial Services Authority (FSA) has warned the banking industry to shape up their attitudes to securing sensitive data and customer information.
Following an audit of 39 banks, building societies, insurance companies and financial advisors, the regulatory watchdog called on financial services firms to adopt a more transparent stance towards customers, rather than fearing adverse media coverage when data breaches occur.
As a result of the audit, one firm has been referred to enforcement.
Full Disclosure campaign
silicon.com is aiming to make businesses and government take data security more seriously. Read more here.
Instances of bad security practice found in the audit included a lack of due diligence in checking third-party suppliers vet their employees or have adequate security arrangements, too much emphasis on IT controls at the expense of staff awareness and training; and in some areas, an over reliance on compliance consultants who did not understand the importance of data security.
One of the recommendations the FSA made as a result of the audit was that finance firms should appoint a senior manager with overall responsibility for data security.
Speaking at the FSA annual conference on financial crime, FSA director, financial crime and intelligence division Philip Robinson said: "It is worrying that despite increased public awareness of the impact that identity theft can have on customers, many firms are still not taking this risk seriously. Some firms have made progress by adopting good practice, while others need to do more in the area… we expect the industry to raise its standards. We will follow up on this [audit] with firms and will not hesitate to take action if future breaches are found."
The FSA audit is in conflict with another survey conducted by BT and YouGov on staff awareness about what to do when things go wrong. This report found staff in financial sector companies were 27 percentage points more likely to have a high awareness of their company's business continuity strategy than the cross-industry average.
BT Global Services finance industry sector MD Andy Nicholson said in a statement: "With an ever increasing regulatory environment, operational risk and business continuity planning must extend to every employee, business process and ICT asset."
Are rogue traders an inevitable evil?
HSBC loses 370,000 customers' details
Sepa fraud risk warning for businesses
Banks under attack: Phishing on the rise
Laptop theft breaks data protection law
HMRC data breach prompts password and PIN changes
Would you spot £1,000 missing from your account?
Disaster Recovery Specialist / Business Continuity Manager urgently sought by a major organisation based in their prestigious offices in South ...
In addition to this you will also be expected to provide expertise and support in operational risk, governance, business continuity, data leakage and ...
Business Continuity Manager and Quality Assurance AnalystHarrogate,30,000 - 35,000 + excellent benefitsMy Client, a leading financial organisation ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Tim Ferguson
On a new Voyager, tackling fraud and the intellectual challenge
Interview: Nationwide IT director, Peter Stafford
Nick Heath
David Lister on smart grids and why he left RBS
Interview: National Grid CIO
Andy Jones
Why banks will push ahead with offshoring
Comment: Even if they don't want to
Catherine Stagg-Macey
Legacy IT holding back insurers
Comment: Economic crisis means finance giants must step lively
Julian Goldsmith
The City fund manager with no IT department
Q&A: How asset management is embracing the cloud...
Peter Cochrane
Peter Cochrane's Blog: How tech can solve the banking crisis
Bring on a machine-based economy