MetrosPress is available in multiple languages. Use the language switcher at the top to reach a wider audience.
Finance

Cybersecurity: an Evolving Battleground in the Finance Sector

Banks, fintechs, and other service providers are investing heavily in cybersecurity. But is the complex network of third-party providers, technology partners, and outsourced services they depend on as well protected as their internal operations?

By Reklame

Banks, fintechs, and other service providers are investing heavily in cybersecurity. But is the complex network of third-party providers, technology partners, and outsourced services they depend on as well protected as their internal operations?

“In the field, we sometimes see a relaxing of critical checks and balances, especially as the relationship between the organisation and its providers matures,” says David Loxton, CEO at Loxton Forensics.

Left unchecked, such complacency could spell a cybersecurity disaster with severe legal consequences and reputational damage.

A growing threat
With the introduction of AI and AI agents, new and dangerous forms of attack have become available to cybercriminals, state-sponsored groups, hacktivists, and anyone else wishing to breach corporate systems. That’s in addition to existing methods.

Cybersecurity is no longer a set of tried-and-true principles, but an evolving battleground on which organisations must continually adapt.

This new reality was illustrated in July when autonomous AI agents broke free of their sandboxed testing environment at OpenAI, accessed the internet, and launched an unauthorized cyberattack on the Hugging Face AI platform. Their reason: to obtain information needed to complete a task assigned by their trainers.

Imagine how much worse it could be in the hands of a determined cyberattacker.

“Organisations are rushing to keep up, but they need to assure themselves that their vendors are moving at the same pace and all routes in their service supply chain are locked down,” says Loxton.

Trust no one
Adhering to the principle of Zero Trust, companies should treat service providers and their systems as untrusted and vulnerable to attack, even if cybersecurity audits suggest otherwise.

This stance demands strict and continuous verification of every attempt by an external party to access, transfer, or process their data.

“However, once the data is outside the organisation, providers must guarantee the appropriate level of system security required to protect it—one that cascades down to their own vendors,” says Loxton.

Most companies ensure they have ironclad contracts in place that bind their providers to strict SLAs, timely intrusion alerts, prompt patching, regular audits, and other good practices.

Trouble arises when human relationships interfere with and compromise these commitments. Loxton says the worst sin is leniency.

Relationship woes
He has come across poorly drafted contracts—even at some of the largest financial institutions in the country—that give too much leeway to vendors on how well they implement essential standards, simply because of their industry reputation or previous dealings.

Yet, even an ironclad contract can unravel over time. Renewals may be awarded without applying the same strict reviews performed at the initial signing.

“Unfortunately, the trust developed between the parties can lead to an almost automatic renewal that assumes, without question, that the vendor has maintained its original standard,” says Loxton.

One-time deviations or lapses in compliance might be overlooked initially, but they become more pronounced with each contract extension or renewal.

“This can result in a fairly unregulated relationship with the vendor, leading to unacceptable operational and legal risks that go unnoticed until catastrophe strikes,” says Loxton.

Assured impartiality
Carrying out due diligence checks when onboarding a vendor is not enough. Non-compliance typically surfaces through ongoing monitoring, auditing of access rights, and reviewing incident notification obligations.

That works best when a department independent of the service users is tasked with regularly monitoring the vendor, ensuring they are delivering what they are paid for, and reviewing contractual obligations for practical inconsistencies.

“Most importantly, this independent body should monitor and review the relationship between the approver and the vendor to ensure contracts are based on demonstrable value rather than industry reputation or personal trust,” says Loxton.

ENDS

#cybercrime#loxtonforensics#fraud#corruption#thirdpartyserviceproviders#cybersecurity

Contact the Author

Want to reach out to the author?

Login to contact author