Financial institutions gamble with information security

1 July 2013 Information Security, Financial (Industry)

A financial institution not investing in a long-term information security strategy is gambling with the protection of corporate and client data, according to information security experts at 4Di Privaca.

The executive mindset of viewing information security as a grudge purchase or ‘best left to the CIO’ needs to change, in order for financial institutions to keep pace with the ever-changing technology needs that impact business operations and defends against sophisticated cyber threats.

The growing importance of protecting sensitive data, bring new security challenges to the CIO, who is already facing ROI pressures, complex regulatory requirements and lack of access to skilled security specialists. As a result, CIOs are left reliant on deploying ‘band-aid’ type tactical approaches to quickly resolve IT security threats, leaving sensitive information and networks open to risk.

Drew van Vuuren, CEO of 4Di Privaca.
Drew van Vuuren, CEO of 4Di Privaca.

Drew van Vuuren, CEO of 4Di Privaca, commented, “IT has become a major cost for businesses, with the incorporation of information security as a reluctant purchase in the broader business cost model, it is becoming increasingly difficult to secure executive approval for ‘all things IT’, and by extension security.”

For a sector like finance, every time a new regulation or standard is released, there is a need to re-evaluate the IT systems in order to be compliant and without impacting productivity, profit or critical data security. Van Vuuren believes the issue begins with companies tending to leave information security to the last minute and not having regular access to qualified security specialists.

“Executives need to be more aware of the fundamental risks a data breach can have on the business and its reputation. The regular security testing of systems responsible for managing critical data, is the most appropriate way of defending against the Tsunami of cyber attacks that regularly happen across the financial sector,“ added van Vuuren.

Although there are not many independent information security practices and specialists in South Africa, it is important that businesses engage with a practice that takes a vendor agnostic approach. “Work with firms that understand your requirement from a business perspective, who know what the requirement is and will architect and articulate a solution based on the business need and not on their relationships with technology vendors,” says van Vuuren.

For more information contact 4Di Privaca, +27 (0)21 659 2043, [email protected], www.4diprivaca.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...
Cybersecurity in South Africa
Information Security
According to the Allianz Risk Barometer 2025, cyber incidents, including ransomware attacks, data breaches and IT outages, are now the top global business risk, marking their fourth year at the top.

Read more...
Are AI agents a game-changer?
Information Security
While AI-powered chatbots have been around for a while, AI agents go beyond simple assistants, functioning as self-learning digital operatives that plan, execute, and adapt in real time. These advancements do not just enhance cybercriminal tactics, they may fundamentally change the battlefield.

Read more...
Disaster recovery vs cyber recovery
Information Security
Disaster recovery centres on restoring IT operations following events like natural disasters, hardware failures or accidents, while cyber recovery is specifically tailored to address intentional cyberthreats such as ransomware and data breaches.

Read more...
Continuous AML risk monitoring
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
AU10TIX, launched continuous risk monitoring as part of its advanced anti-money laundering (AML) solution, empowering businesses to detect behavioural anomalies and emerging threats as they arise.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
The deepfake crisis is here and now
Information Security Training & Education
Deepfakes are a growing cybersecurity threat that blur the line between reality and fiction. These AI-generated synthetic media have evolved from technological curiosities to sophisticated weapons of digital deception, costing companies upwards of $600 000 each.

Read more...
What does Agentic AI mean for cybersecurity?
Information Security AI & Data Analytics
AI agents will change how we work by scheduling meetings on our behalf and even managing supply chain items. However, without adequate protection, they become soft targets for criminals.

Read more...