The Essence of Cybersecurity in Financial Sector

The use of technology in the financial sector is an integral part of modern operational strategy. Financial services are central for economic development. Financial institutions store the data of billions of customers as well as financial transactions on an everyday basis. Cyber security is crucial in the financial sector because cyber-attacks are rising across the world which is costing up to 10% of the global GDP. This article aims to discuss various sources of cybercrimes including AI attacks, malwares, DoS and DDoS attacks, misconfiguration, third party risks, social engineering, and insider threats. It highlights the importance of cyber risk management in preventing financial losses, protecting sensitive data, maintaining business reputation, and ensuring customers' trust. Finally, it examines the development of a comprehensive cyber risk framework for the financial sector.

Introduction

Cyber theft is the illicit access and use of digital devices, networks, data, and information. The aim of cyber threats includes financial gains, disruption of networks, harassments, interference with regulatory systems and governments, and terrorist activities. They create multiple vulnerabilities and enable the exploitation of people, organizations, and governments. While digital devices and services provide numerous benefits and ease of doing business, they also introduce new kinds of risks.

Financial systems play a vital role in the development of nations. Globally, banks and financial institutions have digitalized infrastructure to enhance competitiveness and ease of doing business. Digital technologies have reshaped the entire financial industry by automating operations for efficient management and faster financial transactions, providing better customer services via internet banking, mobile applications, BHIM UPI payments, mobile wallets, digital debit and credit cards, chat bots, and AI assistants that interact with customers. The financial digital landscape has become more convenient for the customers to carry out financial transactions and activities.

However, the digital landscape is vulnerable to cyber-attacks that can lead to more concerns about the safety and security of personal, social, and financial affairs. According to the ITU (2024), the Global Cybersecurity Index report 2024 portrays that all countries including developed and emerging economies are hotspots for cybercrimes, with India ranking amongst the top 10 globally. The Indian Cybercrime Coordination Center (I4C) reported an average of 7,000 cyber complaints daily in May 2024. India's National Cybercrime Reporting Portal (NCRP) reported a total of 8,50,034 digital financial fraud complaints, with a total amount of 11,269.38 crore rupees lost due to cyberfraud in the first half of 2024. Steve Morgan (2020) stated that cybercrime costs are growing at a rate of 15 percent yearly, projected to reach 10.5 trillion USD by 2025. Therefore, it is essential to understand various sources of cybercrimes and conduct assessments to ensure the efficient implementation of cybersecurity measures.

Key Sources of Cyber Risk

Cyberattack or threat is a pathway for cyber hackers to get illegitimate access of computers and networks to exploit network vulnerabilities. Attack vector or threat vector enables hackers to obtain sensitive and confidential data of an organization by delivering malicious malware into the system and network. Vector attacks include malware attacks, web attacks, network attacks, physical attacks, password attacks, internal threats, and social engineering attacks.

"Cyberattack or threat is a pathway for cyber hackers to get illegitimate access of computers and networks to exploit network vulnerabilities."

In this section, some important cyber risk vulnerabilities have been presented.

  • Artificial Intelligence (AI) is the most sophisticated technology which uses machine learning and complex algorithms to mimic human intelligence. No doubt, AI is greatly advantageous for the organization and customers due to its ability to process large amount of data and provide solutions, but it also enables advanced cyber-attacks. Cyber attackers use AI capabilities to wreak havoc on sensitive data belonging to organizations and individuals. AI algorithms are proficient in identifying and exploiting the network vulnerabilities, making cyber attackers more efficient to recognizing patterns in security system and enabling them to excute perfect attack on networks. There are multiple AI cyber-attacks including AI-powered social engineering, AI-powered fishing attacks, deepfakes, and malicious GPT. For instance, AI-powered chatbots are intelligent agents that can inject malicious malwares into the network while going undetected. AI-generated malwares are capable of designing personalized fishing attacks that are not easy to detect. The use of social medial and online platforms is inevitable today. Cyber attackers adopt AI algorithms to propagate false information and spread rumors, manipulating public behavior towards the credibility of financial firms. The National Cyber Security Centre (NCSC) of the UK reported that AI will certainly increase the volume of attacks and heighten the impact of cyber risk. They also stated that AI makes it easier to attack networks.
  • Malware is a malicious software intentionally developed by cyber criminals to harm and exploit computer devices, networks, and servers to obtain personal, financial, and business data. Malware spreads via email attachments and links, advertisements on websites, virus, apps, infected drives, and text massages (McAfee). Malicious software has numerous forms including viruses, ransomware, spyware, adware, trojan horses, scareware, and worms. Cyber criminals use malicious software to steal, encrypt, decrypt, delete and alter sensitive data belonging to individuals, organizations, and the government.
  • Denial of Service (DoS) is a malicious cyber-attack designed to disrupt the normal functioning of devices, servers, and networks with the aim of crashing or repudiating access to the user. Cyber criminals target specific devices, websites, networks, and servers by flooding them with illegitimate requests to crash normal functions, resulting in slowdowns, crippled websites, disrupted networks, ad preventing access for legitimate users. DoS can be carried out either through a buffer overflow attack or a flood attack. A buffer overflow attack involves consuming disk memory and CPU time to slowdown or crash a device or network. The flood attack involves sending an excessive amount of traffic to crash or slow down the system, preventing access for legitimate users.
  • Distributed Denial of Service (DDoS) works similar to DoS but is launched from different systems in different locations. It is a more complex attack, executed from different systems simultaneously to flood the network with traffic, making it difficult for legitimate user to trace or mitigate.
  • Misconfiguration means the settings of a system, network, and security being erroneously configured. Misconfigurations weaken the systems and networks that result in vulnerability or damage to the whole business data. Misconfiguration happens due to numerous reasons, including coding, weak passwords, erroneous firewalls, outdated software, and unsecured cloud storage. Erroneous configuration is the root cause of data breaches and is easy to exploit and block networks and applications.
  • Social Engineering is the psychological manipulation of people to obtain sensitive information and access to personal devices. Social engineering attacks are very common in the financial sector. Cybercriminals use these tactics to obtain financial information like bank account numbers, passwords, debit card and credit card numbers, and OTP. Cybercriminals use these tactics through emails, text messages, and phone calls, claiming that your account will be blocked if you don't deposit a certain amount, or that you have won lottery money but need to deposit a specific amount in a specific account. They may also claim that an incorrect amount was credited to your account and demand repayment, threatening legal action. Sometimes, cybercriminals threaten people by sharing personal information, photos, and videos to obtain personal and financial benefits. Social engineering is an attack on people's behavior rather that an attack on systems.
  • Insider Threats arise from a person who has legitimate access to an organizations resources, including networks, systems, and databases. Insider threats are a main concern for all organizations globally because they are more dangerous than external cybercriminals. These threats are either intentional or unintentional, but they exploit the organization. Ponemon Institute (2022) published the 2022 Cost of Insider Threats Global Report, stating interesting facts about a total of 6,803 insider threats within 278 organizations. 56% of these threats happened due to negligence which costed $6.6 million per incident; 26% were from malicious insider, costing $4.1 million per incident and 18% were from credential theft, costing $4.6 million per incident. Financial services firms are paying the highest average cost of $21.25 million per incident.
  • Third Party Risk arises from external firms that supply IT services. Third party services place a vital role in supply chain management to provide an enhanced customer experience. Globally, 60% of firms are working with over 1,000 third parties. Either directly or indirectly, firms have been experiencing increasing breaches of sensitive and confidential data shared with third parties. Ponemon Institute (2017) reported that the 56% of firms experienced data breaches by their vendors with an average growth of 7% over the previous year. Financial and insurance firms operating with vendors are experiencing high level of data breaches (RiskRecon, 2018).

"Social Engineering is the psychological manipulation of people to obtain sensitive information and access to personal devices. Social engineering attacks are very common in the financial sector."

Importance of Cyber Risk Management

The financial sector landscape has transformed from bricks to digital. Customers are also experiencing digital services with the penetration of smartphones, which provide easy and convenient access for fulfilling their needs and wants. Therefore, cybersecurity is very important in todays' digital era, particularly in the financial industry.

  • Protection of Data: Banks and other financial services providers handle billions of financial transactions and customers every day through digital means. Digital finance makes it easy to carry out any value of transactions. As technology grows, new kinds of cybercrimes are also growing across the world. The financial industry is experiencing a flood of cyber-financial frauds and complaints that worry the customers as well as financial firms about protecting the sensitive data of their businesses and customers. Cybercriminals are using new tactics to attack the digital landscape to obtain sensitive and important data for financial and psychological advantage. Data is vital for any business's sustainability, especially financial firms, which are the key players in the economy. India witnessed a total of 593 data breach cases in the first six months of 2024, including 388 cases of data breaches, 107 cases of data leaks, 39 cases of malwares, and 59 cases of access sales. Therefore, data protection is a major concern for every financial firm.
  • Protection of financial losses: IMF (2024) reported that globally, cybercrimes have doubled after the COVID-19 period. Cyber incidents are directly costing around $28 billion for financial firms, which is expected to rise up to 10% of the global GDP. In India, a total of 177 crore was lost in cyberattack for the FY 2023-24, which is twice the loss in the previous FY 2022-23. Cyber-related financial losses have been substantially increasing year after year in India. For instance, 44.22 crore in FY 2019-20, 50.10 crore in FY 2020-21, and 80.33 crore in FY 2021-22. These statistics portray the importance of ensuring financial security from cyberattacks.
  • Protection of Business Reputation: Data breaches highly impact the reputation of a business, especially small businesses. Cybercriminals target an organization to disrupt its entire business operations, which puts it at a greater risk of losing money, customers' trust, competitive advantage, and growth opportunities, ultimately impacting the reputation of the business. Building a reputation takes many years, but destruction can happen in minutes. Therefore, protecting sensitive data and ensuring comprehensive cybersecurity enhances business reputation, which is very important for financial firms because they act as agents of economic development.
  • Ensuring customers' trust: Cybersecurity is vital for ensuring customers' trust. Cyberint (2024) found that 60% of customers stop shopping online after a data breach, 83% of customers stop using financial apps due to data breach, and 81% of customers expressed the need for a stringent security system for further use of digital services. This shows the importance of cybersecurity in building customer trust. Cybercrime and data breaches have a significant impact on reputation and customers' loyalty. The financial sector is highly vulnerable to cybercrimes. Therefore, customers' data protection and cyber risk mitigation are vital to ensure customers' sustainable use of digital finance.

Comprehensive Cyber Security Framework

Information technology is an integral part of the modern financial system that helps to gain a competitive advantage and enrich customer experience. Financial stability is paramount for any economy. In the digital epoch, data breaches and cyber-attacks on banks and other financial institutions are growing across the world's economies. Especially after COVID, the financial landscape has been substantially digitalized. The digital landscape is posing new kinds of risks and challenges. To protect sensitive data, reputation, and ensure customers' trust, the financial sector needs to strengthen its cybersecurity framework.

"A cybersecurity framework is a set of rules and regulations that aim to protect against illegitimate attacks through continuous assessment of attacks and resolution with an immediate responsive system."

Cybersecurity management in the financial sector must be comprehensive and dynamic depending on the evolution of technology and challenges. A cybersecurity framework is a set of rules and regulations that aim to protect against illegitimate attacks through continuous assessment of attacks and resolution with an immediate responsive system. To keep the entire digital landscape safe, a cybersecurity policy should be broader than mere IT security. The technological landscape varies from firm to firm. Hence, it is essential to understand the inherent risks and implement appropriate security measures in compliance with the governing mechanism, such as a centralized security management system, data access control, encryption of sensitive data, implementing security protocols in web and mobile apps, regular security updates, training employees, and educating customers.

  • Robust control system: A cyber control system aims to focus on reliable and stable control algorithms that are not easily tampered with by illegitimate users. Every firm has a unique digital infrastructure, so the control mechanism should be designed based on their risk profile, like implementing strong firewalls for web and mobile applications, continuously updating the software and networks, and encrypting important and sensitive data. Implementation of a multilayer protocol to prevent malware and DDoS attacks is crucial. The adoption of AI and machine learning algorithms enables continuous assessment, including identifying, assessing, and auto-responsive systems. Blockchain technology is a shared immutable ledger that enhances integrity and transparency among the stakeholders.
  • Regulatory compliance: From time to time, the government and regulatory authorities enact laws and amendments to protect all stakeholders, based on the type of challenges and risks arising in the digital environment. In India, the Information Technology Act 2000, Information Technology Rules 2021, and National Cyber Security Rules 2023 address all cyber-based issues and matters. In addition, the RBI is the regulatory body for banks and issued cybersecurity guidelines in 2016 that were amended and new master guidelines were implemented from 1 April 2024. Further, SEBI also issues and implements guidelines to protect investors from cyber-attacks.
  • Third-party risk controls: Third parties play a vital role in supply chain management. Financial firms should concentrate on third party vendors related to data breaches who provide IT services and have legitimate access to sensitive financial data and systems. Financial institutions should draft stringent guidelines for third-party vendors to protect sensitive data and business reputation.
  • Training employees: Creating awareness and educating staff about cyber-attacks and their consequences is very crucial. Hence, banks, financial institutions, the RBI, and the government should provide training for staff. This helps to mitigate cyber risk and financial losses.
  • Educating customers: Most financial losses occur due to customers' lack of knowledge about safeguarding the credentials of debit cards, credit cards, internet banking, and BHIM UPI. Banks and financial institution should educate customers about various cyber-attacks and security measures for safeguarding sensitive financial data such as login credentials, OTP, debit and credit card details, and tracking financial transactions.

Conclusion

Cybersecurity is pivotal for the financial sector, which handles a large quantum of financial transactions and stores financial information about customers. While digital infrastructure facilitates enhanced customer service, cyber-attacks are also evolving with new tactics like infiltrating malware and DDoS attacks into the digital landscape to damage networks and businesses. Therefore, financial institutions should adopt comprehensive cybersecurity measures to prevent and mitigate cyber-attacks. A multilayer security approach and advanced technologies like AI, machine learning, and blockchain are essential for efficient cybersecurity management.

Reference

  • Cyberint. (2024). SECURITY MATTERS Consumer Views On Cybersecurity Retail Finance 2024.
  • Deloitte. (2023). The rising importance of third party risk management (TPRM).
  • IMF. (2024). GLOBAL FINANCIAL STABILITY REPORT.
  • ITU. (2024). Global Cybersecurity Index 2024.
  • KPMG. (2015). Small Business Reputation & The Cyber Risk.
  • Ponemon Institute. (2017). Data Risk in the Third-Party Ecosystem Second Annual Study. https://insidecybersecurity.com/sites/insidecybersecurity.com/files/documents/sep2017/cs2017_0340.pdf
  • Ponemon Institute. (2022). 2022 COST OF INSIDER THREATS GLOBAL REPORT
  • Riskrecon. (2018). THIRD-PARTY SECURITY RISK MANAGEMENT PLAYBOOK.
Author may be reached at eboard@icai.in