As financial institutions transition employees to working remotely during the coronavirus pandemic, cybersecurity threats have made them more vulnerable, according to information and cybersecurity experts.
“The hackers are going to have a field day with this, I believe they’re going to redouble their efforts on banks because that’s where the money is,” said Steve Hunt, senior analyst of Aite Group’s cybersecurity team. “Banks often operate on a very highly secure operational paradigm. This is the first time banks have revealed a chink in their armor, and hackers are going to focus on it.”
As financial institutions have prioritized employees working off-site, they are trying to figure out how to do so securely, said Aaron Warner, CEO of ProCircular, an information security advisory firm. As such, banks must supply secure connectivity, ramp up authentication processes and mandate new policies to protect employees from malware and phishing attacks.
In fact, there’s been an uptick in phishing attacks targeted specifically at finance and health care, Warner said, and ProCircular’s call centers have seen a 20% jump in call volume in those industries.
Ensuring secure connectivity via VPNs is the first workaround, Aite’s Hunt said, but accommodating a sizable workforce to connect remotely requires additional licenses, costs and infrastructure. “Banks will have to suddenly transform their infrastructure to support workers,” he said.
Identifying employees who work remotely is another. Typically, banks have strong authentication measures to simply enter the building, and two-factor authentication is crucial for remote employees. When employees present something they have, such as a physical token, and something they know to get access to information, companies can cut down external threats by 70%, according to Warner.
Also read: Banks boost VPNs to accomodate remote work
Financial institutions need to be aware, more than ever, of business email compromise and phishing campaigns playing on coronavirus, recession and stock market fears, Hunt said. Hackers will likely take advantage of employees and their bosses operating outside their regular patterns, which makes them much more susceptible to business email compromise and malicious attacks.
There are internal email security threats, too. According to fresh data from Egress, a company specializing in email security, 35% of respondents in the financial industry admit to sharing data via email to the wrong recipient, putting their institution’s security at risk. Additionally, 25% of IT leaders attribute accidental insider threats to a lack of secure systems, and 24% to lack of employee awareness and training. The survey collected responses from 500 IT leaders and 5,000 employees.
Organizations dealing with valuable and sensitive information will need to introduce new internal policies to protect against cybercriminals. Any requests for aid or business information should be met with a call-back number, so that employees call back with the number in their company directory to avoid phishing attempts, Hunt said.
Additionally, businesses should mandate that employees allow software updates as soon as possible, as most computer software updates are security related, ProCircular’s Warner said.
However, the biggest change will be the operational paradigm shift.
“Whereas before, you had this huge investment in firewalls, border protection and so forth, now employees are in their extra bedroom with a laptop, without any of those protections in place,” Warner said. “The threat actors — the bad guys — see opportunity through the path of least resistance. Well, the path of least resistance is that much easier than it used to be.”






