By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Prague ExaminerPrague Examiner
  • Europe Today
    Europe Today
    Show More
    Top News
    Could AI-powered drones be the solution to Europe's wildfire problems? thumbnail
    Could AI-powered drones be the solution to Europe’s wildfire problems?
    September 19, 2023
    Live “in der tram”: Franco-German band Zweierpasch making a difference for European Mobility Week thumbnail
    Live “in der tram”: Franco-German band Zweierpasch making a difference for European Mobility Week
    September 19, 2023
    Four in five people with high blood pressure aren’t adequately treated, WHO says thumbnail
    Four in five people with high blood pressure aren’t adequately treated, WHO says
    September 20, 2023
    Latest News
    EU fines Intel €376.36 million for breaching antitrust rules in computer chip market
    September 22, 2023
    German housing prices at record low
    September 22, 2023
    Facial injury may end French skipper Antoine Dupont’s Rugby World Cup
    September 22, 2023
    Tony Blair faces fresh scrutiny over Azerbaijan PR work amid Nagorno-Karabakh offensive
    September 22, 2023
  • World
    World
    Show More
    Top News
    Anger as some Barcelona restaurants ban solo diners thumbnail
    Anger as some Barcelona restaurants ban solo diners
    August 8, 2023
    Why Tuesday August 15th is a public holiday in Spain thumbnail
    Why Tuesday August 15th is a public holiday in Spain
    August 15, 2023
    Are Spain’s wildfires a risk to people's health? thumbnail
    Are Spain’s wildfires a risk to people’s health?
    August 21, 2023
    Latest News
    Els Castells: What you need to know about Catalonia’s human towers
    September 22, 2023
    The cheapest new cars to buy in Spain in 2023
    September 22, 2023
    Padrón: How to register at your town hall in Spain
    September 22, 2023
    Why you shouldn’t answer the phone with ‘sí’ in Spain anymore
    September 22, 2023
  • Business
    BusinessShow More
    Promote Your Business with Logo Golf Balls thumbnail
    Promote Your Business with Logo Golf Balls
    September 22, 2023
    Play to Win: Tips for Choosing the Best Betting Platform for Your Needs thumbnail
    Play to Win: Tips for Choosing the Best Betting Platform for Your Needs
    September 22, 2023
    Democratizing Data: How Synthetic Data Generation is Changing the Game thumbnail
    Democratizing Data: How Synthetic Data Generation is Changing the Game
    September 22, 2023
    Why Is My Google Organic Traffic Dropping and How to Improve it? thumbnail
    Why Is My Google Organic Traffic Dropping and How to Improve it?
    September 22, 2023
    Locating and Evaluating Cannabis Dispensaries Near Me thumbnail
    Locating and Evaluating Cannabis Dispensaries Near Me
    September 22, 2023
  • Technology
    TechnologyShow More
    Real-World AI Triumphs: Transforming Revenue Models for the Future thumbnail
    Real-World AI Triumphs: Transforming Revenue Models for the Future
    September 13, 2023
    From ideas to results thumbnail
    From ideas to results
    September 4, 2023
    Join the gardening revolution thumbnail
    Join the gardening revolution
    September 2, 2023
    Time to bridge the skills gap thumbnail
    Time to bridge the skills gap
    August 31, 2023
    Awareness is critical to tackling tech skills shortage thumbnail
    Awareness is critical to tackling tech skills shortage
    August 29, 2023
  • Celebrity
    CelebrityShow More
    Family Accuses Google Maps Of Instructing North Carolina Father To Drive Across Collapsed Bridge In New Lawsuit thumbnail
    Family Accuses Google Maps Of Instructing North Carolina Father To Drive Across Collapsed Bridge In New Lawsuit
    September 21, 2023
    Lizzo’s Team Reportedly Responds After Fashion Designer Files New Sexual Harassment & Discrimination Lawsuit Against Singer thumbnail
    Lizzo’s Team Reportedly Responds After Fashion Designer Files New Sexual Harassment & Discrimination Lawsuit Against Singer
    September 21, 2023
    POLICE: 2 Alleged Ex-Lovers Dead Following Suspected Murder-Suicide At Georgia Walmart thumbnail
    POLICE: 2 Alleged Ex-Lovers Dead Following Suspected Murder-Suicide At Georgia Walmart
    September 21, 2023
    Quavo Advocates Against Gun Violence At White House & During Congressional Black Caucus Panel thumbnail
    Quavo Advocates Against Gun Violence At White House & During Congressional Black Caucus Panel
    September 21, 2023
    Blast From The Past! Social Media Reacts To Jada Pinkett Smith Sharing Throwback Video Of Her & Tupac (WATCH) thumbnail
    Blast From The Past! Social Media Reacts To Jada Pinkett Smith Sharing Throwback Video Of Her & Tupac (WATCH)
    September 21, 2023
  • Lifestyle
    LifestyleShow More
    15 Dresses With Pockets, From Casual Minis To Glam Gowns thumbnail
    15 Dresses With Pockets, From Casual Minis To Glam Gowns
    September 21, 2023
    It Took A Layoff, A Canceled Move & Turning 30 To Figure Out My True Calling thumbnail
    It Took A Layoff, A Canceled Move & Turning 30 To Figure Out My True Calling
    September 21, 2023
    14 Free People Pieces R29 Editors Are Carting This Fall thumbnail
    14 Free People Pieces R29 Editors Are Carting This Fall
    September 21, 2023
    I Found The Polished Theory Staples To Build An Elevated Capsule Wardrobe thumbnail
    I Found The Polished Theory Staples To Build An Elevated Capsule Wardrobe
    September 20, 2023
    8 Biggest London Fashion Week Trends To Shop Now thumbnail
    8 Biggest London Fashion Week Trends To Shop Now
    September 20, 2023
  • Foodies
    FoodiesShow More
    Healthy Tuna Salad thumbnail
    Healthy Tuna Salad
    August 10, 2023
    Favorite Vegan Cheese Sauce thumbnail
    Favorite Vegan Cheese Sauce
    August 10, 2023
    Juicy Grilled Pork Chops thumbnail
    Juicy Grilled Pork Chops
    August 10, 2023
    Quinoa Tabouli Recipe thumbnail
    Quinoa Tabouli Recipe
    August 10, 2023
    Spicy Mezcal Margaritas thumbnail
    Spicy Mezcal Margaritas
    August 10, 2023
  • More
    • Featured
Reading: Why the financial sector needs to address every aspect of their attack surface
Share
Notification Show More
Aa
Aa
Prague ExaminerPrague Examiner
  • Bookmarks
  • Customize Interests
  • Submit News
  • Contact Us
  • Categories
    • Europe Today
    • World
    • Business
    • Technology
    • Celebrity
    • Lifestyle
    • Foodies
    • Featured
Have an existing account? Sign In
Follow US
Copyright 2023 Prague Examiner - All Rights Reserved.
Prague Examiner > News > Technology > Why the financial sector needs to address every aspect of their attack surface
Technology

Why the financial sector needs to address every aspect of their attack surface

Prague Examiner
Last updated: 2023/09/04 at 2:40 PM
By Prague Examiner 8 Min Read
Share
Why the financial sector needs to address every aspect of their attack surface thumbnail
SHARE

Banking on cybersecurity: a comprehensive approach to attack surface management in financial institutions

(By Sylvain Cortes, VP Strategy at Hackuity)

The European Investment Bank (EIB) experienced a calamitous system breakdown in June of this year, disrupting a staggering €550 billion in their balance sheet. 

It’s just the latest in a long line of attacks targeting the banking sector, driving home the need for investment in robust, proactive security measures. The top priority? Regain control of the attack surface – the total points an unauthorised user can breach. With the accelerating adoption of cloud services and hybrid work models, organisations grapple with ever-expanding, increasingly challenging attack surfaces. 

Attack Surface Management (ASM) is key here. The term is not merely about securing a superficial ‘surface’ but a complex web of every digital asset exposed to cyber exploitation. As demonstrated by the EIB breach, the fallout from an attack on the financial sector has far-reaching consequences, with further disruption to all businesses dependent on their services. As such, organisations must ensure they fully understand and deploy security capabilities to secure their entire attack surface. 

Demystifying ASM 

Falling under the more extensive term of Exposure Management (EM), Attack Surface Management (ASM) exists alongside Vulnerability Management and Validation Management. Unsurprisingly, with so many different terms and acronyms, navigating them is far from obvious. 

Let’s get this out of the way: ASM is not a specific solution or process, nor is it not tied to any singular tool; instead, it’s an overarching approach enveloping various solutions and activities. 

An effective ASM strategy embodies three critical components: 

Firstly, External Attack Surface Management (EASM) is often mistaken for the entirety of ASM. EASM concentrates exclusively on public-facing assets, such as public clouds. 

Secondly, Digital Risk Protection Services (DRPS) focus on achieving visibility into threat intelligence sourced from places like the deep web, social networks, and open data containers. Implementing this advanced capability necessitates high cyber maturity. 

Lastly, the keystone of ASM practice, Cyber Asset Attack Surface Management (CAASM), is centred on gathering and efficiently managing data concerning the organisation’s vulnerabilities. 

An integrated approach to ASM 

Adopting an integrated ASM strategy means comprehensively understanding potential threats and effectively prioritising remedial actions. Without this overarching perspective, security responses tend to be reactionary and tactical rather than strategic.  

CISOs then face the challenge of linking their technical efforts to non-technical staff – notably board members who aren’t interested in the minute details of a vulnerability. They want to understand its potential ramifications on business and the urgency to address it. 

Some firms’ approach to ASM is still embryonic, focusing on individual vulnerabilities rather than appreciating the broader business risk. This narrow view significantly hampers their ability to comprehend and prioritise their security efforts in a business context. 

On the other hand, some companies are trying to bring in ASM strategies but lack efficient tools and processes. Many are still using outdated practices to manage internal and external risks (we’re looking at you, Excel spreadsheets). These are labour-intensive, inefficient, and lead to risks going overlooked. 

However, more enterprises are recognising the importance of structured ASM practices and are gearing up to invest in suitable tools and processes. So, what are the challenges that financial businesses specifically face when implementing ASM protocols? 

Challenges implementing ASM 

The initial hurdle is comprehending the organisation’s specific security requirements related to ASM and how it plugs into related practices like EM. Following this, it’s important to explain these distinctions to the board and secure their approval for the necessary investments. The key lies in simplicity, emphasising that the primary role of ASM is to identify and counter business risks while enhancing the overall security posture of the enterprise. 

Next on the agenda is dismantling the siloed IT structures within the organisation. Larger and older organisations will need to do more de-compartmentalisation to align departments that have independently grown and evolved over the years. This is particularly common in the financial sector, where institutions likely have decades of technical and structural growth to account for. In contrast, smaller firms such as new challenger banks and digital-native financial services with only a handful of individuals in IT and security will find this task significantly more manageable. 

Further complicating matters, internal and external security and IT teams don’t often operate under the same strategy and are therefore rarely on the same page. This disparity is even more profound when considering IT-security adjacent departments such as DevOps, cloud, and web teams. 

Each unit operates with its unique agenda, deploying distinct tools and processes. There are often multiple, disconnected solutions even within the same team – from scanning vulnerabilities to coding configurations. 

To formulate a unified ASM strategy, it’s essential to establish a harmonised view across all business divisions. Risk data should converge to a single focal point, visible concurrently and in a consistent format, providing the CISO with complete visibility. 

Significance of a proactive ASM approach in cybersecurity resilience 

The correct set of tools can significantly help consolidate diverse threat and vulnerability data streams, creating a unified and clear-cut view of cyber risk. 

The first critical step includes establishing a shared understanding between key decision makers, from the board to department heads. While it’s easier said than done, a shared vision of risk and universal KPIs for vulnerability mitigation is imperative. This unified perspective will facilitate the prioritisation of risks across the entire organisation from a singular reference point. 

Once the silos have been dismantled, it’s possible to identify where processes, tools, and tasks are being unnecessarily replicated so that redundancies can be eliminated. Automation can also be further integrated to enhance team productivity. As the internal ASM strategy evolves, the company can expand its scope to start implementing CAASM and integrating more threat intelligence. 

A comprehensive and proactive approach to Attack Surface Management is crucial in today’s digitally driven financial sector. To prevent adversaries from disrupting these critical services, companies must break down silos, leveraging appropriate tools and fostering a unified view of threats. They can then effectively mitigate vulnerabilities, streamline processes, and bolster their overall cybersecurity resilience. 

Drilling past surface-level ASM enables organisations to go beyond simple operational “enhancements” to proactively pinpoint potential threats from any source and act swiftly to neutralise them. This is a fundamental rethink that can transform your cybersecurity program and, with it, establish an irreplicable competitive advantage in the financial marketplace. 

Further information – Hackuity

You Might Also Like

France and Germany give new push to joint next-generation battle tank 

Ukraine’s forces say NATO trained them for wrong fight

Poland turns toward bets on offshore wind

Secrets of Success: Marcus Brew, MD at UNTHA UK

UK Chancellor Jeremy Hunt defends China’s invitation to AI summit

TAGGED: Technology, Uncategorized
Prague Examiner September 4, 2023 September 4, 2023
Share this Article
Facebook Twitter Email Print
Previous Article From ideas to results thumbnail From ideas to results
Next Article Venice 2023 review: 'The Killer' - David Fincher's nihilistic thriller hits its mark thumbnail Venice 2023 review: ‘The Killer’ – David Fincher’s nihilistic thriller hits its mark
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

Facebook Like
Twitter Follow
Youtube Subscribe
Telegram Follow
- Advertisement -

Latest News

Promote Your Business with Logo Golf Balls thumbnail
Promote Your Business with Logo Golf Balls
Business
Play to Win: Tips for Choosing the Best Betting Platform for Your Needs thumbnail
Play to Win: Tips for Choosing the Best Betting Platform for Your Needs
Business
Democratizing Data: How Synthetic Data Generation is Changing the Game thumbnail
Democratizing Data: How Synthetic Data Generation is Changing the Game
Business
Why Is My Google Organic Traffic Dropping and How to Improve it? thumbnail
Why Is My Google Organic Traffic Dropping and How to Improve it?
Business
Locating and Evaluating Cannabis Dispensaries Near Me thumbnail
Locating and Evaluating Cannabis Dispensaries Near Me
Business
Office Address
16192 Coastal Highway Lewes,
Delaware City,
DE,
United States
Call Information
Phone: +1-619-780-8035
Email:   info@pragueexaminer.com

Quick Link

  • My Bookmarks
  • Customize Interests
  • Privacy Policy
  • Contact Us
  • About Us

Support

  • SUBMIT NEWS
  • ADVERTISE
  • Become a Publicist
  • PROMOTION PACKAGES
  • BECOME A MEDIA OWNER

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

Prague ExaminerPrague Examiner
Follow US

Copyright 2023 Prague Examiner - All Rights Reserved.

  • Advertise
Welcome Back!

Sign in to your account

Lost your password?