Mismatched cybersecurity components, a lack of customizable solutions, and a shortage of quality and/or affordable cybersecurity talent can make it hard for financial institutions to defend their internal systems against attacks.
The European Payments Council’s 2018 Payment Threats and Fraud Trends Report concluded that the organization and sophistication of recent cyber attacks have shown “a greater degree of professionalism” of cybercriminals.
“Multi-vector attacks are becoming commonplace and have been targeting a number of financial institutions,” the report said. “Recent examples of multi-vector attacks include cyber attacks using the SWIFT-related banking infrastructure, ATM infections, adapting card risk parameters, remote banking systems, and POS terminal networks.”
In addition to these “classic” threats, the report identified new risks are arising from the use of innovative (mobile) technologies.
“The number and types of IoT devices are continuously increasing, posing the risk of new types of attack,” the report said.
Bloomberg reported today that U.S. banks and other financial firms are projecting higher spending, bigger threats and more attacks, with the largest firms spending up to $1 billion annually on cybersecurity. In a survey of 100 senior security officers, 84% said their firms are planning to spend more this year on cybersecurity, up from 78% a year ago, according to a report to be released this week by data-security provider Thales eSecurity. About 36% of companies said they experienced an intrusion in 2018, up from 24% last year.
An all-in-one platform
Financial technology provider Fiserv and cybersecurity firm BlueVoyant have partnered up to deliver a comprehensive managed security platform for FIs that can detect threats, respond, remediate, do regulatory compliance, and report. The long-term strategic alliance is fortified by an investment from Fiserv in BlueVoyant, a company led by cybersecurity experts formerly with the National Security Agency, FBI, and British and Israeli intelligence services.
The companies said the platform orchestrates an organization’s internal cybersecurity modules and provides a clear, customizable portal with actionable, plain-English alerts, along with cybersecurity experts who work to remediate threats. Financial institutions using the platform receive consolidated reports to greatly simplify regulatory compliance, and professional threat remediation that allows IT staff to focus attention on building business value.
Nayan Patel, VP of Strategic Alliances for Fiserv, told Bank Innovation they’re trying to collect and analyze as much data as possible at the various entry points on financial transactions, particularly on digital banking platforms, so security decisions can be made based on facts.
“What we’re trying to do is enable financial institutions to understand what the emerging threats are so that they can establish a multi-layered defense that’s going to help them minimize risk, prevent fraud, and maintain compliance in a heavily regulated world where there is a lot of malicious activity occurring,” he said.
Nayan Patel said the partnership with BlueVoyant is not replacing anything Fiserv is already doing on cybersecurity, but complementing existing services.
“We’re wrapping sort of a security blanket around the network and the data from within the financial institution because, often times, that’s where malicious activity can originate,” he said.
Milan Patel, Chief Client Officer for BlueVoyant, told Bank Innovation the company operates exclusively from the cloud, allowing it to be “extremely flexible” and to adopt or absorb the best tools on the market as they become available.
One of their guiding questions: How do you tackle complex software and complex, malicious activity that has the backing of an organized criminal element, akin to how organized crime operated in the United States and elsewhere in the 50s, 60s, 70s, and 80s?
“What we’re finding is a real commercialization and sophistication of hacking operations that we did not see years back,” Milan Patel said.
The companies said banks and other FIs are telling them they can’t attain, much less retain, quality cybersecurity talent in-house. It’s simply too cost prohibitive for startups all the way up to mid-size institutions to fund around-the-clock protection against attacks that are coming 24-7, plus deal with mitigation, compliance, and reporting.
The platform, which launched earlier this year already has several clients, the companies said. They said they have “a substantial number of commitments” and expect to have upwards of 100 clients, from small banks to mid-size FIs (and larger), on the platform by the end of 1Q19.






