Security Risk Assessments: Why Your Company Needs One

Every organization knows it is at risk of a cyberattack, yet too many don’t know where their vulnerabilities are. However, these vulnerabilities can help you identify the likelihood and impact of a cyber incident.

Knowing how to identify the areas of risk in your systems is essential for overall cybersecurity maturity. Moreover, most governmental and industry compliance regulations require you to conduct regular risk assessments. Since nearly every company must meet at least one regulatory compliance requirement, knowing the basics will help you build a successful security risk assessment framework.

 

What Is a Security Risk Assessment?

A security risk assessment is a comprehensive evaluation of your IT system’s security posture. Moreover, a security risk assessment helps you determine the level of risk in your IT infrastructure by identifying, evaluating, and prioritizing issues. It then recommends security tools, controls, and actions to mitigate the risks it finds.

Digging deeper, you can also opt for a vulnerability assessment to complement your security risk assessment. Vulnerability assessments are a more focused and technical examination that specifically searches for vulnerabilities within your organization’s systems, applications, and network infrastructure.

The purpose of a security risk assessment is to see your entire network architecture through the eyes of a threat actor and anticipate where potential attacks are most likely to be launched. Knowing where and how a cybercriminal can enter your network will enable you to accurately allocate cybersecurity resources and maintain vigilance.

There are different types of security risk assessments that a company can conduct. They include:

  • Information security that will look for vulnerabilities within the network.
  • Data security that will assess the security controls around sensitive corporate data.
  • Application security that will examine risks coming from source code and the supply chain.
  • Physical security that offers a deep examination into how well your building and property are protected from intrusion, including the use of security cameras and entry access procedures.
  • Insider threats to better understand how human behavior is impacting your cybersecurity posture.

 

A risk assessment is not the same as risk management; risk assessments are conducted periodically and evaluate your systems to find weaknesses. Recommendations for how often to conduct a risk assessment fall between six months and two years depending on regulation requirements. However, significant changes in your environment, such as the introduction of new technologies or major business process changes, may require a more urgent or immediate reassessment to ensure that your security posture remains up-to-date and effective.

On the other hand, risk management is the ongoing process of identifying and mitigating issues. It involves the continuous monitoring of risks, implementing controls, and making adjustments to your security posture as needed to address evolving threats and changes in your organization’s environment.

 

Who Needs a Security Risk Assessment?

The simple answer is every company, especially those who handle any type of personally identifiable information (PII). Conducting regular audits of your infrastructure should be part of an organization’s regular best security practices.

Depending on the types of compliance your organization is required to follow, risk assessments are required and will guard against large fines and penalties should you face a data breach or other cyber incident.  Because guidelines are always evolving, it is crucial for organizations to stay current. Below is a short list of links for compliances that require a security risk assessment:

 

Along with regulatory compliance standards, organizations wishing to purchase cyber insurance may be required to conduct an assessment before approval. As the cyber insurance loss ratio climbs, insurers are stepping up their efforts to measure your risk to determine your insurability and premiums.

 

What to Expect During Your Assessment?

The risk assessment will usually be conducted by a third-party security assessor. In some cases, however, you may have an in-house team with the skill set and system knowledge to perform the assessment. No matter who handles the evaluation, organizational transparency is necessary to ensure nothing is missed and that the assessment meets all required policy standards.

Because the overall goal is to gain insight into anything that could create risk, the security assessor will do a deep dive into one or more of the following areas:

  • Servers and networking systems, including backup processes, update processes, and identity and authentication systems.
  • Data and information security, including data classification systems, data encryption reviews, and access controls.
  • Application scanning, including internal and external web applications and vulnerability assessments.
  • Security policies, including log monitoring, employee onboarding and offboarding processes, disaster recovery and incident responses, and device controls.
  • Physical infrastructure, including power backup systems, disaster response systems, and facility security systems.

 

Although you will have input into the type of assessment you’d like, such as a data security assessment or insider threat evaluation, the assessor is the one who takes the lead. They will determine the assessment scope—which could look at your organization as a whole or, more likely, a single business department or process.

Once that is determined, the assessor will begin the identification process to uncover your most sensitive and valuable corporate assets. After that, they can identify potential threats to these assets and discover how a threat actor could launch an attack against them. Knowing this, the assessor will analyze the different threat scenarios and the impact of an attack. Consequently, they are able to then prioritize risk levels coordinating with the type of threat factor.

With a determined risk outlook, the risk assessor will then put together a mitigation strategy to meet your agreed-upon risk tolerance level. Tools and processes needed to meet this strategy will be recommended for you to implement within a pre-determined time frame.

 

The Business Case for Conducting a Security Risk Assessment

Compliance requirements are a reason for any company to evaluate their risk levels. But considering the damage a cyber incident can do to an organization, through reputational impact, financial losses, and customer defection, conducting a risk analysis is simply a smart policy. Determining risk levels and identifying vulnerabilities and security threats before they cause harm will save you a lot of headaches in the long run.

An understated benefit of conducting a risk assessment is the emphasis on your policies and processes. Many organizations will devise an incident response plan, but once it is written, it is never looked at again until it is needed.

By focusing an audit on policies, you will be able to see how effective—or how out of date your processes are, what’s missing, and how to set up regular test runs to ensure your incident response is seamless when it is put into action. The assessment will also determine how effective workforce policies, like offboarding and security awareness training, actually are for your company.

Regular assessments will make sure that your most sensitive data is well protected, encrypted, and stored in a secure manner across all devices and systems.

And finally, regular assessments will help your organization create a budget that works best for your actual needs, by providing directions on where you need to build up your security systems and what tools are no longer useful.

Compliance regulations and insurability are the biggest push for security risk assessments, but every organization should consider regular risk evaluations. Threats and vulnerabilities are always out there. Attackers know where you will be most vulnerable. The best way to stop their attack is to have better insight into your vulnerabilities than the threat actors do.

 

Taking the Next Step – Secure the Future of Your Organization

We understand that effective cybersecurity is more than just a checklist; it’s a comprehensive and ongoing commitment to safeguarding your organization. As your trusted partner, we offer a unique approach to cybersecurity strategy—one that begins at the foundation of your IT infrastructure.

Whether you’d like to discuss your current IT setup or pursue cybersecurity strategy and support, we’re here to help you every step of the way—let’s talk.

Combatting the Growing Frequency of Ransomware Attacks on Financial Services Organizations

Understanding and Mitigating Finance-Specific Cybersecurity Risks

Cybersecurity in the financial industry is of the utmost importance as financial institutions handle sensitive and valuable personal information daily, including Social Security numbers, banking information, and confidential business knowledge. Hence, the financial industry is a prime target for cyberattacks due to the possession of this data and the potential for financial gain through fraud or theft.

Phishing emails, the unauthorized use of Remote Desktop Protocols (RDP) credentials, and brute force have become the top three ways nefarious actors penetrate financial servic­es networks to launch ransomware demands. As ransomware’s financial demands escalate, the payoffs become addictive and nefarious groups opt to “hit the financial jackpot” more often.

First recognized as a severe threat in 2020, ransomware proliferated during the pandemic-associated work-from-home (WFH) phenomenon. As multitudes of barely protected endpoints multiplied, leading financial services providers found themselves transferring significant amounts of money to nefarious actors who held their confidential data hostage. Post-COVID, as the financial services industry’s blanket implementation of digital transformation gained speed, meeting customer demand for a comprehensive online experience created exponential growth in cybersecurity risk and vulnerabilities.

Ransomware attacks targeting financial institutions have advanced since 2020 and are significantly impacting organizations and their stakeholders. In June of 2021, the Central Pacific bank announced that it had been the target of a ransomware attack that resulted in the disruption of its online banking and other digital services (indicating inadequate cyber resilience). The threat actors used a type of malware called Ryuk ransomware to encrypt the bank’s files and demanded a ransom to be paid to restore access to the data. Despite taking immediate action to contain the attack and prevent the spread of the malware, some of Central Pacific’s systems remained offline for several days while the incident was being investigated. The incident resulted in inconvenience for the bank’s stakeholders, significant financial loss due to the ransom payment and cyberattack resolution, and extensive reputation damage & negative customer sentiment.

A disturbing new trend is also emerging: Banking’s operational response often allows additional threats to be created in real-time as cyber attackers exploit lateral vulnerabilities within the organization. This trend is particularly worrisome because, while responding, the organization often struggles to pinpoint and understand the nature of the attack and the depth of its own vulnerabilities.

Today, cyber thieves have tapped the power of artificial intelligence (AI) and self-learning malware to boost the effectiveness and velocity of cyberattacks. Current reports from cybersecurity experts across the United States, Australia, and the United Kingdom state that ransomware, the most lucrative type of cyberattack, will continue to be a significant, expensive threat to financial services organizations through the end of 2023.

Ransomware: Beachhead of Sophisticated Operations

As more financial services organizations pay ransomware demands to recover access to their systems and sensitive data, payment merely solidifies this renegade business model. The growing complexity and interconnectedness of players across the global ransomware continuum make it ever more difficult to identify who is beyond the demands and who is receiving the payments.

The significant and ongoing financial gains associated with ransomware have prompted an army of unaffiliated hackers operating around the globe to formalize their operations, becoming an “attack for hire” marketplace with notoriously effective attackers offering Ransomware as a Service (RaaS). These sophisticated operations routinely use a “triple extortion” strategy to force victimized financial services organizations to pay a ransom. The three-pronged threat includes the public release of the company’s sensitive data, disruption of the organization’s Internet access, and the distribution of an attack to the victim’s shareholders, partners, and suppliers.

Ransomware attacks are rarely a “one-and-done” effort. In Eurasia, for example, ransomware groups have been known to share victimology with their peers. The Conti ransomware gang, which claims to have extorted $180 million in a single year, granted access to its victim network on the open market, enabling other ransomware groups to launch follow-up attacks of their own.

An Evolving Threat Landscape

Navigating this complex threat landscape requires that financial services operations of all sizes focus on ever-changing attack origins and approaches. Today, the most encountered threats are coming from:

  • Ransomware – This form of malware encrypts files, rendering them and the systems that rely on them unusable. Malicious actors then demand financial payment in exchange for decryption. These attacks often target financial institutions because they possess valuable data and have a strong incentive to pay the ransom to restore access to their files. To say that ransomware attacks are on the rise is an understatement. A year-to-year comparison of these attacks for the first six months of 2021 showed a growth rate of 1,318%.
  • Government-sponsored attacks – Financial services companies have more to worry about than packs of international hackers; governments are getting into the attack act as well. NATO, citing the increasing frequency of digital misconduct, named cyberspace as an official warfare domain in 2016. Given ongoing geopolitical events, CISA has issued alerts addressing risks from Russian State-Sponsored cyber threats and highlighted recent malicious cyber incidents suffered by public and private entities in Ukraine.
  • Third-Party Software – No financial services organization’s IT infrastructure operates independently; it includes a myriad of third-party solutions needed to support business-critical initiatives, such as digital transformation and internal and external workflows. This reliance on third-party applications creates known and unknown vulnerabilities that malicious hacking groups can leverage and exploit.
  • Phishing – A common tactic used by cybercriminals to gain access to sensitive information, such as login credentials and financial data. In the financial industry, phishing attacks are often directed at employees of financial institutions, as well as customers. These attacks typically involve the use of fraudulent emails, text messages, or websites that appear to be from a legitimate source, such as a bank or other financial institution, to trick individuals into providing sensitive information.
  • Unencrypted Data – Smaller financial institutions, many of which face limited financial resources, may bypass encryption, which greatly complicates cybersecurity protection. Data breaches in these organizations create additional risk for clients and partners whose data can be used as soon as it is captured by cyber thieves. Cyber thieves have figured out that while the financial assets at smaller financial services operations may be of less monetary value, smaller, less protected financial services organizations can be easier to penetrate and offer a gateway to clients’ and partners’ assets.
  • Bypassing MFA – Once thought to be the “Holy Grail” of data protection, multi-factor authentication (MFA) has recently taken significant hits from fraud-related attacks. Cybercriminals are using auto-dialers to intercept one-time passwords, creating “MFA fatigue” for customers and opening the way for bots to penetrate targeted accounts.

While external threats to the financial services industry take top billing in the cyber war, human error and individuals with malice toward the organization can also launch cyberattacks. Employees, especially former staff who have an axe to grind or those who have been recruited by third parties, can exploit known vulnerabilities or creating new ones.

This list is not intended to be comprehensive. Cyber thieves morph their strategies and tactics frequently, making it extremely challenging for financial services organizations to keep ahead of the threats.

Financial Systems Require the Constant Diligence of a Dedicated Security Team

Cyber attackers aim AI and self-learning malware onto a larger attack surface, reaching beyond the corporation to its customers and partners to find and exploit vulnerabilities in financial services’ technology infrastructures. This larger attack surface especially comes into play during the consolidation of financial services operations such as mergers and acquisitions.

To improve their cyber resillience, financial services organizations need to broaden and expand their efforts in three key areas: data privacy, identity protection, and vulnerability management. In most financial services organizations, internal IT teams have their hands full executing business-critical digital transformation initiatives and managing the existing technology infrastructure. Most financial services simply don’t have the specially trained staff or massive budget needed to keep nefarious actors at bay.

Cybersecurity requires specialized expertise that is up-to-the-minute current and a preventive eye to accurately forecast where international hackers will go next. That’s simply too much responsibility to heap on the already full agendas of internal IT staff.

However, faced with an IT cybersecurity talent shortage and an ever-changing threat landscape, financial services organizations have discovered that partnering with a Managed Services Provider (MSP) can offer the expert assistance and full-time attention to data protection they need without onboarding and managing additional staff.

What should financial services providers look for in an MSP partner?

A proven track record of cyber expertise in this preventive, high-risk game of “technology cat and mouse” is just the beginning. Even with deep cyber expertise, an all-industry MSP won’t understand the highly regulated aspects of financial services. When selecting a managed services provider, they should have a deep understanding of and the ability to meet the regulatory requirements that apply to financial institutions, such as the Payment Card Industry Data Security Standards (PCI DSS) and the General Data Protection Regulation (GDPR).

Few financial services providers have the time to educate an all-purpose MSP. Instead, look for one that already understands the language of financial services, appreciates the intricate challenge of cybersecurity in global and local financial services, and has done what your organization needs many times before.

Having a cyber partner who understands the constantly changing customer-facing dynamics of financial services, especially from a digital transformative perspective, will make your ideal MSP partner stand out from the rest. With that partner, a financial services organization can cultivate strategic risk management conversations, set cybersecurity proprieties and benefit from the cybersecurity expertise gained by working with all the other financial services who have gone before.

IT Solutions, an MSP partner offering a robust array of managed IT services, has trained staff with years of experience focusing on cyber reliance for companies and organizations specializing in financial services. This focus means staying up to date on regulatory requirements and emerging challenges unique to the financial industry. To learn more, visit our dedicated resources and information page on supporting financial services organizations.

Protecting Mobile Devices and Application Data with Microsoft 365

Microsoft 365 includes two options for mobile device management, a strategy designed to help protect devices and control application data. One is “Basic Mobility and Security,” the provided option in the core versions of Microsoft 365—Business Basic, Apps for Business, Business Standard, Business Premium, Microsoft 365 E3, and Microsoft 365 E5.

The second is Microsoft Intune, which offers more security features and is recommended for business scenarios where security is paramount. It is the included security option in Microsoft 365 Enterprise Mobility + Security E3 and Microsoft 365 Enterprise Mobility + Security E5.

Security Best Practices Tip: It is possible to use both offerings simultaneously, provided Basic Mobility and Security is set up first. However, we recommend an evaluation of your firm’s overall security needs in advance to ensure business assets will be sufficiently protected.

Seeking Just the Basics?

Basic Mobility and Security enables authorized personnel to manage a variety of mobile devices, including those running Android or Mac OS (e.g., iPhone and iPad). Users and any individuals who manage the devices must have an applicable Microsoft 365 license, and their devices must be enrolled in Basic Mobility and Security. Authorized personnel can manage devices by blocking access to them or wiping them, as well as using device security policies to limit email, view device reports, and more.

Why Your Business Might Need the Intune Upgrade

For companies seeking more stringent security—perhaps to meet compliance mandates or secure corporate data traveling outside the firm’s network (e.g., work-from-home personnel)—we recommend Microsoft Intune. Intune includes most of the features technology leaders consider critical for security in the current threat-laden landscape. Following are key highlights:

  • Multiple OS versions: Send custom notifications remotely that format correctly for each system (Android, iOS, etc.).
  • Remove devices from the Intune portal: Intended to prevent unauthorized use after a termination or resignation, this option deletes company data from the device and removes the device from the console at the next device check-in.
  • Compliance-based conditional access: Prevent devices that do not meet corporate security standards from accessing company email and data from Exchange Online, SharePoint Online, and Outlook (not supported on Windows 10).
  • Provision profiles: Set up a native profile (WiFi or VPN) on the device so personnel can use the organization’s wireless or virtual private networks.
  • Mobile application management: Deploy (to users) internal line-of-business applications and applications from app stores.
  • Mobile application protection: Enable users to securely access corporate data using their mobile and line-of-business applications while restricting specific actions (copy, save as, etc.) to ensure data security.

In addition to these features, there are many more possibilities with Intune, including preventing corporate data from leaving the firm’s control. At IT Solutions, we focus on security, mobility, and productivity to help our clients in all industries achieve their goals. To discuss the solutions mentioned here or explore what we can do to help your firm, contact your Strategic Advisor or call 866.PICK.ITS (866.742.5487).