As widespread remote work has expanded the attack surface, we’ve seen the threat landscape become increasingly sophisticated, with cybercriminals continuing — even escalating — their activity amid crisis. Ransomware attacks are increasingly successful, crippling governments and businesses, and the profits from these attacks are soaring. As the global cybercrime supply chain continues to mature, anyone can now buy the services needed to conduct malicious activity for financial gain. Sophisticated cybercriminals are also still working for governments conducting espionage and training on the new battlefield.

Few industries face greater security challenges than the financial services industry (FSI), as the frequency, sophistication and rewards of financial crimes increase. According to Microsoft Security data in the “Microsoft Digital Defense Report,” FSI remains one of the top three sectors targeted by ransomware actors.
Along with industry sectors such as health care, information technology and energy, FSI is a key component of critical infrastructure. Last summer’s oil pipeline incident showed us how easily cybercriminals can launch a ransomware attack that shuts down businesses, impacts the economy and disrupts everyday life for millions of people. With a well-financed global cybercrime supply chain in operation, bad actors will continue to have access to the tools and technologies needed to execute such attacks.
Persistent, evolving attacks are powerful reminders that we must act decisively on all fronts in new ways to reinforce cybersecurity measures for industries and individuals. That’s why FSI organizations and their governing bodies mandate the establishment of robust and often complex safeguards to protect assets as well as the entities and people they belong to.
As FSI companies stand up those safeguards, they must address two competing needs. Delivering low-friction customer experiences is a major priority, with much innovation and attention dedicated to meeting customers where they are. At the same time, they need to create high-friction experiences for cybercriminals, fraudsters and money launderers by implementing strong cybersecurity and data protection policies and practices.
FSI organizations that use an integrated cloud platform to manage data and their overall security posture will find themselves in a stronger position to address both priorities. Further, cloud migration is imperative to scaling up operations safely and sustainably. FSI leaders appear to agree, citing the cloud among their top emerging tech priorities, according to a recent Deloitte Center for Financial Services analysis.
Start with the fundamentals
As FSI organizations pursue digital transformation in the cloud, there are several essential steps to implement right away that can protect them from attacks.
Enable multifactor authentication: Require that anyone accessing any endpoint — including devices and servers, among others — use a combination of two to three unique identifiers such as username, password, token, email address, fingerprint or PIN.
Apply least privilege access: Limit user access with just-in-time and just-enough-access, risk-based adaptive policies and data protection to help secure both data and productivity.
Keep up to date: Ensure that systems and endpoints are protected by the latest available security patches and software updates.
Use anti-malware: Stop malware attacks by installing and enabling anti-malware solutions on endpoints and devices.
While some of these precautions may seem obvious, the rising number of successful cyberattacks suggests they are often ignored. In fact, it is shocking that less than 20% of our customers use strong security methods such as multifactor authentication, which is free to them and can be activated by default.
With the essentials covered, FSI decision-makers can turn their attention to more specific areas of concern.
Take control of your data
As data spreads across increasingly more tools, platforms, devices and clouds, the risks to security and compliance grow. Understanding your data and protecting it across its entire lifecycle is imperative.
Data governance plays a critical role in FSI since it is imperative to data security and data privacy. A recent Morgan Stanley report found that 17% of Chief Security Officers (CSOs) identified data governance as one of their top three security priorities for 2021, an increase of five points year over year. More than 52% of those CSOs cite the rising compliance and regulatory requirements as a top-three concern in 2021.
With a system that helps properly manage and govern data, organizations can better support all business functions, including data privacy management. Safeguarding sensitive personal data builds trust with customers and employees. Plus, it helps organizations maintain compliance with regulations, laws and their own policies.
Ensure compliance
A complex regulatory environment designed to protect consumers, financial institutions and markets means that everyone in the sector must demonstrate compliance through a wide range of monitoring, reporting and record-keeping activities and processes. And failure to do so can be very costly. Industry reports show penalties on FSI institutions for noncompliance with anti-money laundering, know your customer, data privacy and markets in financial instruments directive regulations totaled more than $10 billion worldwide in 2020.
At the same time, compliance itself is an expensive proposition. According to the “Global Regulatory Outlook” by Duff & Phelps, almost one-third, or 32%, of senior financial services decision-makers surveyed in 2021 predict that the total cost of compliance will be greater than 5% of their revenues. Only 12% expected to see compliance costs lower than 1% of revenues.
Factors such as how and how long an organization stores its data straddle regulatory compliance and security. To mitigate risk on both fronts, a “zero trust” philosophy should lie at the core of all FSI organizations’ operations. The phrase refers to a proactive mindset that assumes all activity, even by known users, could be an attempt to breach systems. Given business risks today, inside and out, zero trust is not just an option — it’s a business imperative.
Set the stage for sustainable innovation
To successfully scale and grow, financial services companies must accelerate the journey toward digital transformation — and realize cybersecurity’s role in it. Those that use the latest technologies to manage their security and compliance posture will find themselves in a stronger position to address risk management and compliance challenges.
The principles of zero trust — verify explicitly, provide least privileged access and always assume breach — lay the foundation for comprehensive security and data privacy essential for innovation. They also help organizations develop a critical component of success: resilience.
Today’s best FSI systems help secure data from the endpoint to the cloud, addressing security, compliance, identity device management and privacy management. Artificial intelligence (AI) and automation capabilities can catch and track threats from outside or inside the organization. As FSI organizations pursue digital transformation, it’s important to remember that there are inherent risks in all the new technologies and business practices we adopt, and those risks must factor into any decisions about technology, policy or business practices.
Adopt a security-first focus
An integrated, end-to-end approach, paired with AI and automation capabilities, empowers FSI organizations to tackle security from all angles at scale. After all, risk comes in many forms, and a siloed approach is a vulnerability that cybercriminals are adept at exploiting. Plus, a strategy that’s extensible to a broad ecosystem of clouds, platforms and devices gives customers the flexibility of choice they expect.
Security, compliance, innovation, privacy, choice, trust — they’re all interconnected and integral to stronger collaboration, productivity and user experience.
Vasu Jakkal serves as corporate vice president of security, compliance and identity at Microsoft, where she is responsible for security strategy, go-to-market activities and security marketing.






