September 11, 2024โฏโโฏTrustwave, a leading cybersecurity and managed security services provider, has released aโฏseries of reportsโฏdetailing the threats facing the financial services sector, marking the second year of its ongoing research into these critical security issues.
In its annual research, Trustwave SpiderLabs highlights the unique factors at play in financial services, significant trends currently affecting the industry, including cryptocurrency and ransomware, and provides an overview of threat actor techniques by attack stage.
Additionally, Trustwave SpiderLabs has produced two complementary in-depth write-ups on pressing threats in the sector: phishing-as-a-service and insider threats. Recent research by theโฏPonemon Instituteโฏidentifies malicious insiders as the costliest type of data breach, with phishing being the second most expensive and the most prevalent. Trustwave SpiderLabsโ analysis delves into why these threats are particularly pervasive in the financial services vertical.
Kory Daniels, chief information and security officer, Trustwave, said โDigital trust is paramount for financial services to effectively operate in a hyper-competitive market, and the attack surface has never been more challenging with the size, and the diversity, of the data.,โ
โOur latest series of threat briefings highlight the urgent risks of insider threats and phishing-as-a-service attacks, offering vital insights and actionable strategies to help organisations defend their most sensitive data and assets. This resource is essential for business leaders and cyber defenders striving to stay ahead in an evolving threat landscape.โ
Financial services organisations are a goldmine for cybercriminals due to their wealth of sensitive financial data and substantial funds. The sector also faces a unique cybersecurity landscape influenced by expanded regulatory requirements, heightened risk aversion, and consumer protection considerations.
Trustwave SpiderLabsโ 2024 research series on the financial services vertical includes:
- 2024 Trustwave Risk Radar Report: Financial Services
- 2024 Financial Services Deep Dive: Phishing-as-a-Service
- 2024 Financial Services Deep Dive: Insider Threat
Key findings from Trustwave SpiderLabsโ financial services research series include:
- 24 per cent of ransomware attacks against the financial sector were by ALPHV
- 49 per cent of attacks against financial institutions originated from phishing
- 20 per cent of ransomware attacks in the sector were against banking institutions
- 65 per cent of ransomware attacks targeting financial services were in the US
- 37 per cent of phishing emails in the industry contained HTML attachments
- 73 per cent of credential access techniques were brute-force attempts
In 2023, Trustwave released its firstโฏFinancial Services Threat Intelligence Briefingโฏthat analysed the attack flow specific to the financial services sector, offering insight on specific threat actors, actionable intelligence, and recommended mitigations for each stage.
To access this yearโs research, please clickโฏhere for the full financial services threat research series.
About Trustwave
Trustwave is a globally recognised cybersecurity leader that reduces cyber risk and fortifies organisations against disruptive and damaging cyber threats.
Trustwaveโs comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimises its clientโs cyber investment, and improves security resilience. Trusted by thousands of organisations worldwide, Trustwave leverages its world-class team of security consultants, threat hunters, and researchers, and its market-leading security operations platform to decrease the likelihood of attacks and minimise potential impact.
Trustwave is an analyst-recognised leader inโฏmanaged detection and response (MDR),โฏmanaged security services (MSS),โฏcyber advisory,โฏpenetration testing,โฏdatabase security, andโฏemail security. The elite Trustwave SpiderLabs team provides industry-defining threat research, intelligence, and threat hunting, all of which are infused into Trustwave services and products to fortify cyber resilience in the age of inevitable cyber-attacks.
For more information about Trustwave, please visit:โฏhttps://www.trustwave.com/en-us/.