literature review

profilebalaji1692
DraftmakechangesperFeedback.docx

CYBERSECURITY IN FINANCIAL INDUSTRIES 1

CYBERSECURITY IN FINANCIAL INDUSTRIES 10

Cybersecurity in Financial Industries

Sai Balaji Yamsani

University of the Cumberland’s

Introduction

Cybersecurity, also known as computer security, refers to IT security in organizations that protect the computer system from attacks and theft of the hardware and software information from untrusted sources. Cybersecurity encompasses the protection of physical access to the system's hardware and security against harms that may arise from network access and data and code injections. Other malpractices that might put the computer system at risk are the intentional or accidental malpractices by the operator mat may bring about the diversion from security procedure rendering the network vulnerable. According to Elnagdy, et al, (2016), through the application of Cybersecurity in an organization, information and services are protected from unauthorized access, which may bring changes or distraction to the system's overall performance. Proper Cybersecurity within an organization will ensure confidentiality, integrity, and in-time availability of credible data. There are several ways in which the organization can improve its Cybersecurity, which involves the use of antivirus software to protect the system against malware, the use of firewalls that can prevent hacking, and using technological solutions that can protect personal data in the organizations, such as using passwords and biometric systems such as fingerprints.

Why is Cybersecurity so critical?

In the modern world, economic, social, and political activities depend on computer networks and information technology to simplify complex problems. This has come with many challenges since cyber-attacks have also increased with hackers coming up with more sophisticated ways of conducting their attacks. Basing on the statistics that were collected by the Symantec cybercrime report published in April 2012, the cybersecurity attacks cost a loss of US$114 billion each year. A lot of time is also lost by organizations in handling cybersecurity issues; his time was quantified to approximately US$385 billion, (Gai, et al, 2017).

Over the years, cybersecurity victims have increased, with the hackers now shifting their attention to financial industries. According to the research conducted by Symantec in 24 countries, out of 20000 people were interviewed, 64% of them were found to be victims of cyber-attack. In every second, based on the survey, an averagely of 14 men are victims of cyber-attacks every second, which amounts to over one million attacks every day. The increased cases of cyber-attacks can be attributed to the fact that it is more convenient and less risky than physical attacks. The anonymity nature of the internet makes it hard for the culprits to be identified or caught. More so, the attacks can take place regardless of the distance or geographical locations. The increased number of cyber-attacks brings about the need to enhance Cybersecurity to enhance data's credibility and integrity and secure critical data from falling into unauthorized hands. There is a need for financial institutions to upgrade their system to prevent massive losses from the attacks.

Key Weapon

Many experts who deal in Cybersecurity believe that malware is the key weapon used by hackers to carry out cyber-attacks and malicious breaches. Malware can be described as a large group of attacks that can be uploaded on the system without the operator's knowledge, which can lead to compromising the design for the benefit of the attacker. According to Gao, et al, (2020), there are several categories of malware, which includes spyware, Trojan horse, viruses, and worms. There are several ways malware can be uploaded onto the computer system, which provides for opening an infected file, infection from other machines, or access to a corrupted website. The virus can also be loaded onto a USB and uploaded into the system corrupting files and data or granting unauthorized person entry into the system.

Premier Defense Strategy against Malware

The best strategy for protecting an organization's data on the computer system is the perimeter defense strategy that covers everything inside the network from access by unauthorized individuals rather than the process that protects individual assets. This strategy involves using firewalls and the installation of antivirus, which serves as a primary defense that ensures that there is no malware penetration. Through that, all the incoming traffics is intercepted and examined to ensure there is no malware penetration into the system, (Huang & Li, 2018)

Cyber-security and Financial Sector

In the recent past, financial sectors have become a center of attention for hackers who conduct malicious acts and leads to massive losses. Due to the advancement of technology, it has become easier for hackers to infiltrate security systems in financial institutions using more sophisticated means that cannot be easily realized. This makes it necessary for financial institutions to upgrade their systems.

In many cases of cyber-attacks on banking and financial sectors, it was realized that the attack required minimum technical skills whereby some of the attacks were carried out by individuals with no or less computer knowledge, there is a need for financial sectors to safeguard their network, which has many users. The persons responsible for data entry into the system are also required to receive adequate technical training to detect Data that is corrupted before it is fed into the system. A lack of acceptable procedures and policies govern the system, making it possible for individuals with malicious intentions to exploit these avenues since most of the designs are not technically complicated. In such a case, individuals with evil intentions exploit non-technical vulnerabilities in the organization's rules and policies. Such attacks are carried out by individuals with little or low technical expertise.

· In all the reported cases of cyber-attacks in the financial sectors, 87% was an inside job where there was an application of a simple comment to carry out the incidence. According to Kosutic & Pigni, (2020), Of all the cases, only 9% of the required technical knowledge of network security to carry out the incident. After the incident, it is always discovered that there wasn't an initial scan of the system to identify the vulnerabilities, making it easy to carry the attack.

· In the studied cases, it was discovered that 70% 0f the, the insiders exploited or tried to use the vulnerabilities present in the system applications, procedures, or processes. To carry out the attack. In cases, 61 % of them showed that the insiders exploited the vulnerability characteristics present in designing the software, hardware, and network.

· 78% of the cases studied showed that insiders carried out the incident with authorization and active computer accounts in the financial sector by the attack time. Out of the 78%, 43 percent of the incidents had the insiders using their usernames and passwords to carry out the experience.

Recent Trends in Finance Industry

In financial sectors, cybercrime’s is the most reported threat. Other money-related industries and the supply of the national foundations that deal with money also report the same cases. Financial departments in earning institutions like colleges and universities also experience the same sort of attacks. The way these economic sectors react to cyber-attacks to a larger extend determines the magnitude of a country’s security and strengths. The digitation of the financial and banking industries has rendered them more vulnerable to attacks since the hackers are able to conduct their acts from any given location, (McSweeney, 2018). 

    The financial sectors, especially those with multiple branches in different regions, are at more risk of attacks since they operate their transactions through the internet, which can be intercepted and altered if not well secured. There are new advancements in payment methods such as the use of PayPal, apple wallet, the service of m-pesa, among others, online banking, and critical database, making it an easy target for hackers to conduct their activities and obtain maximum benefits from them.

In recent years, the largest 50 banking websites have been accessed illegally by unauthorized users, leading to a loss of over than $1 billion. The financial sectors need to address the broad range of cyber threats, which include the use of malware o render the system vulnerable, phishing that uses electronic communication to trick people into revealing corrupted data, and the use of DOS- denial of service attack that makes the procedure inaccessible to unauthorized individuals.

Due to the large number of individuals who access the system and the large volume of data stored in the financial sectors, it makes it easy to conduct an attack since the avenues that an individual can exploit to carry out the attack are broadened. In 2015, it was reported that there was an increase in cyber-attacks in the financial sectors by 40%, with 21 million cases of cyber-attacks reported in the same year on the financial sectors across the globe. Forty-five million BOT attack was also reported in the same year. From the third quarter to the fourth quarter of the year, the BOT attacks were reported to have multiplied ten times, (Ossamah, 2020)

Why is the financial sector vulnerable to cyber-security breaches?

Due to the complex nature of financial institutions, there is a need to employ different security techniques and structures in each sector and sub-sector. The use of various organization techniques tends to be useful since it caters to all kinds of potential attacks. However, multiple approaches can also render the system security vulnerable since some methods might be conflicting, creating loopholes to be exploited. The use of mobile banking and online lending together with other modernized techniques of banking that have been brought about due to the advancement of technology are the main targets of attacks since they have weak security infrastructure that can easily be hacked, the high speed of transaction cycle that is brought by online lending to give out loans as compared the traditional money lending methods gave made it more comfortable for attacks since to facilitate the high number of transactions with the high speed it requires less security infrastructure. The vulnerability created by a single lender can diversify to the individuals taking the loans since the system is inter-connected. The exposure can also expose other larger institutions that are linked in terms of transactions, (Lau, et al, 2018)

Other financial; institutions that are involved in e-commerce makes it easy for them to be hacked between the year 2016 and 2017; the volume of mobile transactions was estimated to have increased by 20%, and it is estimated to increase due to the advancement and adoption of mobile phone devices as well as the increase in online many lending sectors. Due to the adoption of technology in many institutions and collaboration to enable e-commerce, businesses need to develop multiple-layer firewalls that can allow the company to detect malware and prevent access into the system. Device spoofing and a mobile bot can be used to enhance security.

New Trends in Cyber-Security breaching

In the modern world, cybercrime is the second most reported crime in the world in PWC's Global Economic Crime Survey. Financial institutions were discovered to be the main targets of the attack. Cybercriminals have devised new ways of attack, breach, threat patterns such as phishing, spear-phishing, and social engineering due to technological advancement. Credential theft attack is another avenue that is exploited by cybercriminals in the financial sectors. Since the beginning of COVID-19 and its spread worldwide, there is a need for economic sectors to change their modes of transactions from paper to digital transactions. According to Lewallen, (2020), there was a rapid change in their operations; simultaneously, a cybercriminal moved swiftly to take advantage of the enormous scope to conduct their attack. Due to the rapid growth in financial institutions' operations, there were no adequate security measures to make their systems vulnerable. The aggression has further moved to smaller businesses.

Ruinous and problematic malware assaults prod multiparty and cross-area was focusing on. Danger bunches utilizing ransomware are focusing on numerous connected gatherings without a moment's delay worldwide. On August 16, 2019, above 20 elements in Texas, United States, detailed ransomware assaults, provoking a planned state and government reaction to a multi-jurisdictional network protection occasion that was the first of its kind.37 Testing the versatility of the influenced elements, this multiparty assault is a bellwether demonstrating the probability of extra simultaneous, troublesome assaults. A proactive cyber defense plan that joins multiparty assault reenactments with industry and cross-industry companions could enable monetary organizations to be more ready to confront this danger, (Moorer, 2018).

What Financial Organizations need to do?

There is a need for financial organizations to develop solutions that can detect its systems and vendors' vulnerabilities. There are several ways that financial institutions can improve their security. First, there is a need to secure data that is coming in and out of their system. Due to the increase in mobile banking, there is also an increase in the volume of data handled by the organization. There is a need to classify each data to mitigate the risks. Data can be classified based on type, sensitivity, or value. A financial institution's other measure needs to take is monitoring third party risk by conducting assessment on the vendor. The organization will be able to identify the gaps that would otherwise lead to losses. This will enable the organization to take the necessary measures to mitigate the risks. The third measure a financial organization can take is to leverage cybersecurity data. The organization can use this data to understand the past events of cyber-attacks and predict the future by taking all the necessary measures to prevent the attacks. By having insight into the security data, it will be easier to identify vulnerabilities in the network, facilitating the institution to stay ahead of the threat, (Szabó, 2018)

For financial institutions to effectively ensure against dangers, they should have the option to ceaselessly survey and screen their security act just as the cybersecurity of their sellers. With Security Scorecard's money related administrations arrangements, associations can adopt a proactive strategy to network safety. Our extensive network safety arrangements assist you with increasing an outside considering your IT framework so you can without much of a stretch distinguish digital dangers and organize danger alleviation. To improve danger recognition, offer online protection information abilities that can be utilized to remediate weaknesses before they are abused, (Zhang, et al, 2020).

Conclusion

As I have discussed above, it is possible that one can say that there is a lot to be done in financial needs to be sure that there are essential cleanliness and hygiene. A perfect example is security for SSL. And this is important in enhancing the general system as well as practices security as well as consistency in patching. There may be an increased cyber-attack hazard when all these issues have not been made so that they can be able to hold security measures. However, there is still a future for companies' financial increment. For example, Swift is in the mission of enhancing digital security and instructing banks and their management on proficient methods at keeping a very safe system. OCC about the security measures has set up third-party merchants. The SEC's chairperson has declared cybercrime as the most dangerous danger squeezing into a financial company worldwide, enduring the summit held up in Reuters Financial Regulation Summit in May. The security pose should be investigated to focus on cybercrimes and security of data to boost the organization's financial aspect. Comment by DeAnna: No pronouns in scholarly writing

References

Elnagdy, S. A., Qiu, M., & Gai, K. (2016, June). Cyber incident classifications using ontology-based knowledge representation for cybersecurity insurance in financial industry. In 2016 IEEE 3rd International Conference on Cyber Security and Cloud Computing (CSCloud) (pp. 301-306). IEEE.

Gai, K., Qiu, M., & Hassan, H. (2017). Secure cyber incident analytics framework using Monte Carlo simulations for financial cybersecurity insurance in cloud computing. Concurrency and Computation: Practice and Experience29(7), e3856.

Gao, L., Calderon, T. G., & Tang, F. (2020). Public companies' cybersecurity risk disclosures. International Journal of Accounting Information Systems38, 100468.

Huang, H., & Li, T. S. (2018). A centralised cybersecurity strategy for Taiwan. Journal of Cyber Policy3(3), 344-362.

Kosutic, D., & Pigni, F. (2020). Cybersecurity: investing for competitive outcomes. Journal of Business Strategy.

McSweeney, K. (2018). Motivating Cybersecurity Compliance in Critical Infrastructure Industries: A Grounded Theory Study (Doctoral dissertation, Capella University).

Ossamah, A. (2020, June). Blockchain as a solution to Drone Cybersecurity. In 2020 IEEE 6th World Forum on Internet of Things (WF-IoT) (pp. 1-9). IEEE.

Lau, N., Pastel, R., Chapman, M. R., Minarik, J., Petit, J., & Hale, D. (2018, September). Human Factors in Cybersecurity–Perspectives from Industries. In Proceedings of the Human Factors and Ergonomics Society Annual Meeting (Vol. 62, No. 1, pp. 139-143). Sage CA: Los Angeles, CA: SAGE Publications.

Lewallen, J. (2020). Emerging technologies and problem definition uncertainty: The case of cybersecurity. Regulation & Governance.

Moorer, W. L. (2018). WYNN AND OTHERS CAN LEARN FROM WYNDHAM: EFFECTS OF FTC v. WYNDHAM WORLDWIDE CORP. ON CASINO OPERATORS'CYBERSECURITY POLICIES AND LOYALTY PROGRAMS. Gaming Law Review22(1), 3-11.

Szabó, Z. (2018, September). Cybersecurity issues in industrial control systems. In 2018 IEEE 16th International Symposium on Intelligent Systems and Informatics (SISY) (pp. 000231-000234). IEEE.

Zhang, L., Xie, Y., Zheng, Y., Xue, W., Zheng, X., & Xu, X. (2020). The challenges and countermeasures of blockchain in finance and economics. Systems Research and Behavioral Science37(4), 691-698.