High Time for Cybercrime

For me, 2013 has pretty much been the year of the cybercriminal, in that every month I've written about, or had discussions on, something to do with cybercrime. It's a big phrase, and it's not entirely fleshed out yet, but recently it seems as if the financial services industry, or more accurately, the financial-markets side, is doing something about it.
You'd be forgiven for thinking otherwise, though. From my experiences as a reporter trying to cover the story, nobody wants to talk about it. Most major exchanges reply with "I don't think we want to be discussing that, James", and most banks say "We don't want to draw attention to ourselves." Presumably because they're comfortable with a bank's natural under-the-radar profile. But the discussions are going on, as are the attacks, and the penetrations, and the activity we don't hear about in the mainstream press.
But, the sense of forward motion is building. The World Federation of Exchanges (WFE) announced the formation of a cybersecurity committee last week, featuring most of the big names of the global exchange landscape, and headed up by Nasdaq's CISO─or chief information security officer. Further simulations akin to Global Dawn II, held by the Securities Industry and Financial Markets Association earlier this year, have been employed with success.
Public Image
The theft of money through cyberattack is one thing, but at the end of the day, money can be replaced. Reputation is something much harder to quantify in dollars and cents, and in the new era of online, the security and integrity of an institution (therefore an individual's money) is probably the overriding contributor to that reputation. Confidence is king, and damaging confidence damages the institution, and in a wider sense, the real economy and political world as well.
So, therefore, cybercrime will naturally become a matter for regulation, probably in the not-too-distant future. Those regulations, I'm told, will be minimum standards though, and firms will be expected to go above and beyond that, and essentially do whatever it takes to keep their systems secure.
The World Federation of Exchanges (WFE) announced the formation of a cybersecurity committee last week, featuring most of the big names of the global exchange landscape, and headed up by Nasdaq's CISO.
It's a good thing, then, that the industry is getting together and collaborating on best practice. But no defense, particularly in the cyber arena, can be fool proof. As one ex-FBI cyber agent told me a few months ago (in a more dramatic metaphor than this): if somebody wants to do something, they'll do it. There will always be a ladder tall enough to get over the wall, or an insider disgruntled enough to leave the drawbridge down and the portcullis up.
Taking this in mind, mitigation becomes crucially important, if total prevention is impossible. But it's such an overwhelmingly complex topic area that it's hard for many institutions to adequately put protections in place. Cybercrime can be taught from a legal perspective, but from a practical perspective, it's impossible to keep up to speed with the latest threat vectors, delivery mechanisms, and assault methodology in a classroom. For the financial services industry, tough times are ahead.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Data Management
Stocks are sinking again. Are traders better prepared this time?
The IMD Wrap: The economic indicators aren’t good. But almost two decades after the credit crunch and financial crisis, the data and tools that will allow us to spot potential catastrophes are more accurate and widely available.
In data expansion plans, TMX Datalinx eyes AI for private data
After buying Wall Street Horizon in 2022, the Canadian exchange group’s data arm is looking to apply a similar playbook to other niche data areas, starting with private assets.
Saugata Saha pilots S&P’s way through data interoperability, AI
Saha, who was named president of S&P Global Market Intelligence last year, details how the company is looking at enterprise data and the success of its early investments in AI.
Data partnerships, outsourced trading, developer wins, Studio Ghibli, and more
The Waters Cooler: CME and Google Cloud reach second base, Visible Alpha settles in at S&P, and another overnight trading venue is approved in this week’s news round-up.
A new data analytics studio born from a large asset manager hits the market
Amundi Asset Management’s tech arm is commercializing a tool that has 500 users at the buy-side firm.
One year on, S&P makes Visible Alpha more visible
The data giant says its acquisition of Visible Alpha last May is enabling it to bring the smaller vendor’s data to a range of new audiences.
Accelerated clearing and settlement, private markets, the future of LSEG’s AIM market, and more
The Waters Cooler: Fitch touts AWS AI for developer productivity, Nasdaq expands tech deal with South American exchanges, National Australia Bank enlists TransFicc, and more in this week’s news roundup.
‘Barcodes’ for market data and how they’ll revolutionize contract compliance
The IMD Wrap: Several recent initiatives could ease arduous data audit and reporting processes. But they need buy-in from all parties if all parties are to benefit.