Published

  • 01:00 am

While 82 percent of respondents believe the IT security industry is making progress against cyber attacks, those gains are undercut by egregious security practices in critical areas such as privileged account security, third-party vendor access and cloud, according to results from a new global survey commissioned and released by CyberArk .

The 10th annual CyberArk Global Advanced Threat Landscape Survey 2016, themed “Cyber Security: Past, Present & Future,” examines whether global enterprises are learning and applying lessons from high-profile cyber attacks, and how security priorities and business decision-making are being influenced.

Cyber Lip Service? Bad Security Habits Persist, Despite Rising Awareness
Headline-making cyber attacks have driven significant increases in cyber security awareness. However, the failure to turn increased awareness into the enforcement of security best practices undermines progress for organizations’ cyber security efforts.

  • Seventy-nine (79) percent state their organization has learned lessons from major cyber attacks and has taken appropriate action to improve security.
    • Sixty-seven (67) percent now believe their CEO/board of directors provide sound cyber security leadership (up from 57 percent in 2015).
    • The top actions taken because of this awareness are deployment of malware detection (25 percent), endpoint security (24 percent) and security analytics (16 percent).
  • Fifty-five (55) percent of respondents state their organization has changed or evolved processes for managing privileged accounts.
    • Despite this, 40 percent of organizations still store privileged and admin passwords in a Word document or spreadsheet, while 28 percent use a shared server or USB stick.
  • Nearly half of organizations (49 percent) allow third-party vendors (such as supply chain and IT management firms) remote access to their internal networks.
    • While the majority of respondents secure and monitor that access, the public sector has the least third-party vendor access controls in place compared to other industries, with 21 percent not securing and 33 percent not monitoring that activity.

A Cyber State-of-Mind: Striking a Balance Between Fear and Overconfidence
Organizations are increasingly adopting a post-breach mindset, preparing to deal with ongoing cyber attacks and activity in the case of a breach. This preparedness is leading to positive steps in post-breach planning, but concerns exist about how overconfidence may affect the ability to protect against cyber attacks.

  • Three out of four IT decision makers now believe they can prevent attackers from breaking into their internal network – up from 44 percent in 2015.
    • Despite this, 36 percent believe a cyber attacker is currently on their network, or has been in the last 12 months.
    • Forty-six (46) percent believe their organization was a victim of a ransomware attack in the past two years.
  • Eighty-two (82) percent of respondents believe the security industry in general is making progress against cyber attacks.
    • Seventeen (17) percent believe the industry is falling further behind.
  • Nearly every organization (95 percent) has a cybersecurity emergency response plan.
    • This preparedness is undermined by a lack of communication and testing – only 45 percent communicate and regularly test their plan with all IT staff.
  • Sixty-eight (68) percent of organizations cite losing customer data as one of their biggest concerns following a cyber attack.
    • Sixty (60) percent of those who use the cloud store customer data in it.
    • Fifty-seven (57) percent who store information in the cloud are not completely confident in their cloud provider’s ability to protect their data.
  • When identifying the most difficult stage of a cyber attack to mitigate, malware installation ranked first (41 percent), followed by privileged account takeover (25 percent).

On the Radar: Future Risks Emerge
As cyber attacks continue on trusted institutions such as government, utilities and financial systems, respondents identify what types of cyber attacks or tactics are most concerning. Respondents also share which cyber attack scenarios they think represent the most immediate and potentially catastrophic threat in general.

  • Respondents list the following types of cyber attacks or tactics as the top-ranked concern in the next 12 months: Distributed denial-of-service (DDoS) attacks (19 percent), phishing (14 percent), ransomware (13 percent), privileged account exploitation (12 percent) and perimeter breaches (12 percent).
  • Attacks on financial systems, including disruption of global markets (58 percent) is the most potentially catastrophic threat perceived by respondents, followed by attacks causing massive utilities damage (55 percent) and those impacting civil services such as healthcare and hospital services (51 percent).

The Impact of a Breach on Customer Data and Corporate Accountability
The survey found a varied global picture in terms of preparedness for increased regulatory oversight and the impact on cyber security programs and accountability.

  • While 70 percent of global respondents agree that the threat of legal action and fines influence the level of executive/board involvement in security-related decisions, 22 percent of the respondents do not incorporate compliance fines or legal fees (19 percent) into the cost of a breach.
  • Nearly seven in ten (69 percent) respondents state that, in response to a breach or cyber attack, stopping the breach/removing the attackers is among their top priorities, followed by detecting the source of the breach (53 percent).
    • Far fewer respondents prioritize notifying the CEO/board (26 percent), entire staff/workforce (25 percent) or customers (18 percent).

“The findings of this year’s Global Advanced Threat Landscape Survey demonstrate that cyber security awareness doesn’t always equate to being secure. Organizations undermine their own efforts by failing to enforce well-known security best practices around potential vulnerabilities associated with privileged accounts, third-party vendor access and data stored in the cloud,” said John Worrall, CMO, CyberArk. “There’s a fine line between preparedness and overconfidence. The majority of cyber attacks are a result of poor security hygiene – organizations can’t lose sight of the broader security picture while trying to secure against the threat du jour.”

Related News

  • White Papers
  • 22.09.2016 08:19 am

Banks and financial institutions are seized with newer forms of threats to the safety and security of their data, a critical asset for any organization. In the age of Internet of Things, criminal activities and data theft have also gotten smarter and savvier, with criminals increasingly using technology to break technological barriers within the banking system. In light of the low entry barriers to cybersecurity attacks in banks, it is incumbent upon them to invest in systems and technologies that go beyond merely pre-empting an attack.

This White Paper explores:

  • The genesis of cybercrime in India.
  •  How it’s only grown over the recent years, especially 2011 onwards.
  • How increasing reliance on technology makes it harder to detect and monitor financial crime taking place online.
  • Recommends a few solutions that banks can and should invest in if they want their financial assets to stay safe and secure.

Other White Papers

  • 03:00 am

 smartTrade Technologies, a multi-asset electronic trading solutions pioneer, announces today the launch of smartAnalytics, a cross-asset big data analytics solution.

With smartAnalytics, financial firms will achieve a greater control and transparency by leveraging our cutting edge solution to store, analyse and visualise all the data flowing through their trading infrastructure.  Data is stored in a secure high performance, fully hosted and managed environment. smartAnalytics enables users to easily generate graphical reports and analysis on demand. The solution gives a 360 degrees view of their data and covers multiple reporting requirements including regulation and compliance such as Mifid II, risk, Transaction Cost Analysis (TCA), performance analysis and much more.

The smartAnalytics open architecture allows to easily export and share information with other teams - traders, sales and quants - or departments - compliance and risk. Users can leverage pre-defined reports or simply create their own by using powerful modelling tools. smartAnalytics fully integrates and complements the reporting capabilities of LiquidityFX and smartFI, smartTrade’s FX and Fixed Income trading platforms.

“We have invested heavily in our infrastructure to allow our clients to enter in the big data, analytics and machine learning space which we believe will become prevalent in the industry.” says David Vincent, CEO of smartTrade Technologies. “Having the tools to analyse the massive amounts of data produced in the financial markets can help our clients spot patterns and correlations in their trading and improve their execution efficiency” he added.

Related News

  • 04:00 am

Exaxe has been shortlisted for the DC Technology Provider of the Year award at the 2016 Defined Contribution (DC) Awards, organised by Pensions Insight, which is due to take place in London on October 26th. Exaxe has also been shortlisted for the Pensions Technology Provider of the Year at the 2016 Irish Pensions Awards, which is due to take place in Dublin on November 24th.

Since winning the Pensions Technology Provider of the Year at the 2015 Irish Pension Awards, Exaxe has continued to innovate its products and grow its Irish and international client base. 2015 / 2016 has been a major growth period for the company with record levels of new sales and doubling its workforce in Sandyford.

Norman Carroll, CEO at Exaxe said: “We are delighted to announce that we have been shortlisted for the DC Technology Provider of the Year award. This is a new category to the awards so we are thrilled to be able to take part in these prestigious awards for the first time this year.  Combining that with the announcement that we have also been shortlisted again for the Irish Pensions Technology Provider of the Year award is a cause for double celebration. These two selections acknowledge the hard work we have completed for our UK and Irish clients as we strive to constantly innovate to improve service and reduce costs for pension providers via our SaaS based solutions.”

As the only awards event in the sector to focus solely on DC – and taking place immediately after DC Insight, the sector’s leading DC conference – the Pensions Insight’s Defined Contribution Awards celebrate all that is best in the world of DC. As more and more workers come to depend on DC arrangements for their retirement income, these awards recognise providers that go that extra mile for schemes, and schemes that go that extra mile for members.

This year’s awards ceremony will take place at 155 Bishopsgate, Liverpool Street, London on Wednesday 26 October, after the DC Insight Conference.

The full list of DC Awards finalists is available at: http://events.nqsm.com/e/dc-awards-2016/shortlist/

Now in their 5th successful year the Irish Pensions Awards give recognition to those pension funds and providers who have proved their excellence, professionalism and dedication to maintaining high standards of Irish pension provision.

The Irish Pensions Awards winners, determined by an independent judging panel, will be announced at the highly anticipated gala dinner and ceremony on 24thNovember 2016 at the 5 star Shelbourne Dublin. Over 300 guests attended the event in 2015 and this year is set to be even bigger and better than ever.

The full list of Irish Pensions Awards finalists is available at: http://www.europeanpensions.net/irishawards/

Related News

  • 01:00 am

 

Profile Software, an international financial solutions provider, announced today its participation in Sibos 2016 the world’s premier financial event organised by SWIFT, taking place on 26-29 September in Palexpo Geneva, Switzerland, to showcase its pioneering product developments and international implementations.

Profile is exhibiting at stand no G07, demonstrating its innovative FinTech solutions for the industry including 'challenger banks' and 'crowdfunding alternatives', while presenting new products and enhancements to its solutions’ portfolio. The company and its team will present cases on:
> Banking
> Wealth Management
> Alternative Finance

By investing in new technologies such as mobile, web and cloud, Profile has implemented its solutions in leading financial services institutions to help them experience business agility and cost efficiencies, thus becoming an established vendor in the industry. During Sibos, professional delegates will have the opportunity to attend Profile’s happenings.

On the 27th of September at 16:00, Profile will host at its stand G07 a relaxing cocktail reception to allow professional delegates to find out more on its latest products’ developments while networking.

On the 29th of September at 14:45, Open Theater 1, Profile’s team, capitalising on its recent international implementations and industry expertise of the financial services sector, will present cases and intriguing trends through a short presentation on “A FinTech approach for Alternative Finance”.

Furthermore, a number of meetings with industry experts will be held at the stand, so interesting parties can request a meeting through the online form here.

Sibos is an annual conference, exhibition and networking event organised by SWIFT - the global provider of secure financial messaging services - for the financial industry with more than 8,000 delegates, from the world’s largest banks and financial institutions. The exhibition brings together business leaders, decision makers and topic experts focusing on the latest trends for the financial services industry. This year, apart from the Banking and Securities stream, a FinTech approach is greatly supported to further elaborate in this growing trend.

More information about the events around Sibos 2016 and the registration process are available on the event's website.

Related News

  • 09:00 am

BNL, BNP Paribas Group, announces the availability of a fully electronic PIN code distribution for their cards. The service, called cl SecurPin, is provided by TAS Group – a company specialized in software solutions for e-money and cashless payments – and manages a “dematerialized” PIN code, both at issuance and in case of replacement for lost, with unrivalled benefits in regards to security and convenience.
 
BNL adopted this new service on Hello Mat! debit card from Hello Bank!, the BNP Paribas Group's digital bank active in Italy.
 
The customer gets the PIN for his card in the restricted area of the Hello Bank! site using the security codes generated from the Hello! app, which is downloadable for free on smartphones from all major app stores. In this way cl SecurPin allows quick delivery of the PIN and is much more secure than a code issued on paper, which is generally  subject to the risk of theft or loss.
 
“BNL continues investing in innovation and technology to make its service and offering model more and more competitive,” stated Marco Tarantola, Deputy General Manager in charge of the Retail & Private Division of the BNL. “We believe that innovation, especially in an evolving industry such as banking, primarily means knowing how to propose solutions that bring concrete benefits for the customers in terms of simplicity, speed and safety for their daily professional and personal needs”.
 
Roberto Carlucci, Director of TAS Group’s E-Money Business Unit, said, “In depth knowledge of the architectures and core processes of banks on physical, virtual and mobile channels is one of the differentiators of TAS Group. We are very attentive to implement technological innovation in a sustainable way for our customers, taking into account the banks’ daily challenges in recovering profitability while meeting risk management and regulatory compliance.”
 
In addition to electronic PIN management, TAS Group’s cl SecurPin solution allows for wider scope of applications related to the use of tokens. Besides payment cards, the dematerialisation services are key in all areas affecting the digital transformation of the FinTech industry. cl SecurPin integrates with the existing BNL core systems and is fully compliant to the rigorous standards set by PCI (Payment Card Industry sector regulations) and is applied to all methodologies and technologies employed by TAS Group for the implementation of solutions for the digital payments of the future as part of their cashless 3.0™ platform.

Related News

  • 04:00 am

INDATA, a leading industry provider of software, technology and services for buy-side firms, today announced that Renaissance Investment Management, an institutional and high net worth investment manager with approximately $4.4 Billion in AUM, based in  the Greater Cincinnati Area  has expanded their use of INDATA’s Intelligent Portfolio Management® software suite.  The firm has implemented iPM Cloud, INDATA’s private cloud solution and upgraded to the latest version of the software, iPM Epic.

Renaissance, a long term INDATA client, had been looking at ways to streamline their IT infrastructure and also increase the efficiency of its investment operations. After a detailed review of available options open to the firm, Renaissance decided to expand and upgrade its use of INDATA’s solutions, choosing iPM Cloud for their technology infrastructure needs and iPM Epic for their front-to-back office investment software suite.

Among the key advantages of iPM Cloud for Renaissance was the ability for INDATA to host other applications including desktops for end users and other specialized proprietary applications in one outsourced private cloud environment provided by INDATA. 

“Having all of our key software applications in one place creates many efficiencies in terms of interoperability between systems, so expanding our partnership with INDATA was the logical decision. What impressed us most was the willingness of INDATA personnel to go out of their way to make our transition to iPM Cloud smooth and trouble free,” commented Sudhir Warrier, Senior Partner & Chief Operating Officer, Renaissance Investment Management. “With INDATA as our front-to-back office investment software provider, outsourcing our technology infrastructure via iPM Cloud streamlines how our end users are able to operate, allowing our firm to better focus on the business of investing and also satisfying industry best practices for disaster recovery and business continuity planning.” 

“We are delighted that Renaissance has decided to expand their usage of our products and services and we look forward to continuing to serve them as a trusted partner for their investment technology needs now and in the future,” commented David J. Csiki, President of INDATA.

Related News

An Analyst’s Perspective on the Future of Robo-Advisors

Christopher Monaco
Content Marketing Manager, Financial Services at Seismic Software

With robo-advisors receiving so much press as of late see more

  • 02:00 am

Paxos, a financial technology company delivering revolutionary blockchain solutions for global financial institutions, today unveiled its new brand. The name Paxos is inspired by a technical term that represents a process for reaching consensus. The name underscores the company’s goal to leverage consensus-driven blockchain technology in transforming the way global financial institutions work together. The company’s flagship service, Bankchain, is a cloud-based platform-as-a-service (PaaS) solution transforming post-trade market infrastructures and back office processes for its global clients. Bankchain was previously recognized under the itBit umbrella, but has become established as an offering under the Paxos brand.

Bankchain delivers instantaneous settlement, offering market participants reduced risk exposure and increased operational efficiencies. Paxos’ strategic relationships with leading market participants and infrastructure providers such as Euroclear allows Bankchain to seamlessly connect to today’s existing settlement systems.

“Increasingly, the financial services industry is embracing the transformative potential of blockchain technology. Paxos is making that potential a practical reality,” said Paxos CEO Charles Cascarilla. “Our collaboration with Euroclear to create a trusted blockchain settlement infrastructure for gold is just the beginning, and an important first for the industry.”

The Paxos team—whose leadership launched itBit, the innovative crypto-currency trading platform—consists of experienced financial services professionals with post-trade and market infrastructure expertise, leading technologists and engineers. The company has offices in New York, London and Singapore, providing a strong presence in key global financial centers as it continues to grow its staff and services across capital markets.

Related News

  • 08:00 am

FIME is pleased to announce that its Japanese laboratory has achieved AMEX Enabled accreditation* for functional testing on contactless payment terminal kernels, in line with American Express’ Expresspay specifications. FIME has also been accredited by EMVCo for EMVCo’s Book C-4 specification, which defines the mandatory and optional functionality required when implementing terminal kernel 4. These latest accreditations enable contactless payment terminal and mobile point of sale (mPOS) manufacturers, as well as kernel developers, to validate their products in any of FIME’s French, Japanese and Taiwanese laboratories.

The separate accreditations from AMEX and EMVCo ensure the effective operation and market interoperability of contactless payment terminals by outlining the minimum software functionality required to operate effectively.

“Ongoing EMV migration and the upcoming 2020 Olympics in Tokyo are driving an increase in EMV chip deployments and the adoption of contactless payment technology across Japan,” comments Arnaud Peninon, VP Global Laboratories at FIME. “These latest accreditations are part of FIME’s ongoing strategy to support local terminal manufacturers and kernel developers with the widest test and consultancy portfolio available on the market. These certification processes foster stability and security across the region’s expanding contactless infrastructure.”

The Japanese laboratory will use FIME’s qualified test tool, EVAL, to perform formal certification testing. The tool is available to purchase for in-house pre-certification testing to help identify issues that can lead to delays later in the process.

Related News

Pages