Regulatory action is biggest data protection fear for financial firms
The threat of regulatory action is the top concern for UK financial services firms should they lose data, according to research from Ernst & Young.
The threat of regulatory action is the top concern for UK financial services firms should they lose data, according to research from Ernst & Young.



From forensic cyber to encryption: InfoSec17
Security technologist Bruce Schneier’s insights and warnings around the regulation of IoT security and forensic cyber psychologist Mary Aiken’s comments around the tensions between encryption and state security were the top highlights of the keynote presentations at Infosecurity Europe 2017 in London.
Ernst & Young's report said 72% of the 29 UK financial services firms polled saw regulatory action or sanctions as the biggest danger from data loss, ahead of damage to reputation and brand (66%).
Ken Allan, partner in Ernst & Young's technology and security risk services department, said, "The sizeable penalties imposed by the Financial Services Authority on a number of financial institutions have clearly hit home. Financial institutions are acutely aware of the impact that sanctions and regulatory action can have on their business and in turn their reputation."
Regulatory compliance has caused almost 25% of the UK financial institutions polled to report a significant increase in information security costs this year. More than 33% reported a significant rise in costs over the past three years.
The survey shows that 38% have spent between 20% and 50% of their annual information security budget in the last financial year complying with regulation. Most UK financial institutions are set to maintain or increase their investment in the next financial year.
Data loss: how to minimise risk, liability and reputational damage >>
Read more on IT risk management
-
Why businesses must think like criminals to protect their data
-
Security Think Tank: Use awareness, education and controls to halt cryptojacking
-
Security Think Tank: Awareness is a good starting point to counter fileless malware
-
Security Think Tank: Human, procedural and technical response to fileless malware
Start the conversation
0 comments