article thumbnail

Financial Services and the Zero Trust Journey

Data Breach Today

Menlo Security's Mark Guntrip on How to Learn to 'Defend Differently' On one hand, rapid cloud migration has been a boon to financial services organization. But it's also exposed some security weaknesses.

article thumbnail

Three use cases for cloud fax in financial services

OpenText Information Management

Fax is so secure that faxed documents and signatures are recognized in the courts as being legally binding. It stands to reason, then, that fax would be the bedrock of financial communications, but are there ways to make it even better?

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Record-Setting DDoS Attack Hits Financial Service Firm

Data Breach Today

Million Request-Per-Second Attack Launched by 20,000 Bots, Cloudflare Says Security firm Cloudflare says it detected and mitigated a 17.2 million request-per-second (rps) distributed denial of service attack, almost three times larger than any previously reported HTTP DDoS attack

article thumbnail

New York Department of Financial Services Released New Guidance Addressing COVID-19 Related Cybersecurity Risks

HL Chronicle of Data Protection

Continuing its focus on COVID-19’s impact on its regulated entities, on April 13, the New York Department of Financial Services (NYDFS) released new cybersecurity guidance in response to the COVID-19 pandemic.

article thumbnail

NYDFS Amends Cybersecurity Rules for Financial Services Companies

Hunton Privacy

On November 9, 2022, the New York Department of Financial Services (NYDFS) released its second, proposed amendments to the Part 500 Cybersecurity Rule. Any cybersecurity event that affects a third-party service provider that also affects the covered entity.

article thumbnail

Summary – “Industry in One: Financial Services”

ARMA International

The scope of a records and information management (RIM) program in financial services can seem overwhelming. Compared to other industries, the complexities of managing records and information in financial services are arguably some of the toughest to solve, primarily because of the intense regulatory scrutiny. The program must evolve with the industry as new challenges and opportunities emerge, and it requires constant attention and program adjustments.

article thumbnail

The Financial Service and Insurance Industries Need Intelligent Document Processing; Here’s Why

Rocket Software

Analyst firm IDC recently published a Vendor Spotlight report featuring ASG Mobius Content Services (Mobius) and its applications in the financial service and insurance industries. IDP Trends in the Financial and Insurance Industries.

article thumbnail

The importance of data quality in Financial Services

Collibra

Financial services are highly regulated and maintain a strong focus on compliance and risk management. Constantly monitoring data and also reporting it to the regulatory authority is their top priority. What is data quality in financial services?

article thumbnail

OpenText STP Financial Hub revolutionizes workflows in the Financial Services sector

OpenText Information Management

It’s been a busy 2018 here on our OpenText™ Straight Through Processing (STP) for Securities (STP Financial Hub) platform, with many new clients discovering the benefits of our powerful workflow engine and flexible connectivity methods, along with our constant improvement and enhancement process for our existing clients.

article thumbnail

Financial Services Data – More at risk than you’d believe

Thales Cloud Protection & Licensing

One of the top findings from the 2018 Thales Data Threat Report, Financial Services Edition was that data breaches in U.S. financial services organizations are increasing at an alarming rate. IT security pros in financial services organizations reporting that their organization already had a data breach – but breaches are increasing at alarming rates. Check out our data security solutions , and follow us on Twitter , LinkedIn and Facebook.

article thumbnail

NY Department of Financial Services Issues Cyber Fraud Alert to Regulated Entities Using Instant Quote Websites

Hunton Privacy

Lastly, the Alert provides recommendations to secure data, noting that (1) regulated entities should review whether it is necessary to display any NPI (even redacted NPI) and (2) NPI should not be displayed on public-facing sites unless there is a compelling reason to do so.

article thumbnail

First American Financial Pays Farcical $500K Fine

Krebs on Security

In May 2019, KrebsOnSecurity broke the news that the website of mortgage settlement giant First American Financial Corp. NYSE:FAF ] was leaking more than 800 million documents — many containing sensitive financial data — related to real estate transactions dating back 16 years.

article thumbnail

Boosting Security Resilience and Defending the IT Ecosystem

Data Breach Today

Jeetu Patel of Cisco Discusses the Critical Ability to 'Bounce Back' From Incidents With rising threats facing critical infrastructure sectors, such as healthcare and financial services, "society as a whole, and the safety of society is completely dependent on cyber risk" - and being security resilient, says Jeetu Patel of Cisco.

article thumbnail

New York Department of Financial Services Issues First Guidance by a U.S. Regulator Concerning Cyber Insurance

Data Matters

On February 4, 2021, the New York Department of Financial Services (NYDFS) issued Circular Letter No. Issuance of the Framework is notable as it represents the first official guidance by a U.S. It also calls for insurers to “take steps to mitigate existing silent risk, such as by purchasing reinsurance.”. The post New York Department of Financial Services Issues First Guidance by a U.S. Cybersecurity Information Security Insurance Policy

article thumbnail

Financial Services Organizations Need to Adapt their Security Practices to the Shifting Environment

Thales Cloud Protection & Licensing

Financial Services Organizations Need to Adapt their Security Practices to the Shifting Environment. Even “traditional banks” seek to drive more revenue from digital products, personalized services and experiences. Weak security practices lead to data breaches.

Cloud 62
article thumbnail

NY Charges First American Financial for Massive Data Leak

Krebs on Security

In May 2019, KrebsOnSecurity broke the news that the website of mortgage title insurance giant First American Financial Corp. First American Financial Corp. It employs some 18,000 people and brought in $6.2 First American released its first quarter 2020 earnings today.

article thumbnail

Scary Fraud Ensues When ID Theft & Usury Collide

Krebs on Security

Or how about not learning of the fraudulent loan until it gets handed off to collection agents? The reader who shared this story (and copious documentation to go with it) asked to have his real name omitted to avoid encouraging further attacks against his identity.

article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

On July 29, 2022, the New York Department of Financial Services (“NYDFS”) posted proposed amendments (“Proposed Amendments”) to its Cybersecurity Requirements for Financial Services Companies (“Cybersecurity Regulations”).

article thumbnail

Historic Charges: First Enforcement Action Filed by New York Department of Financial Services Under Cybersecurity Regulation

Data Matters

On July 21, 2020, the New York State Department of Financial Services (NYDFS or the Department) issued a statement of charges and notice of hearing (the Statement) against First American Title Insurance Company (First American) for violations of the Department’s Cybersecurity Requirements for Financial Services Companies, 23 N.Y.C.R.R. First American failed to classify its applications properly as actively transmitting confidential, nonpublic information.

article thumbnail

NY Payroll Company Vanishes With $35 Million

Krebs on Security

Unlike many stories here about cloud service providers being extorted by hackers for ransomware payouts , this snafu appears to have been something of an inside job. Nevertheless, it is a story worth telling, in part because much of the media coverage of this incident so far has been somewhat disjointed, but also because it should serve as a warning to other payroll providers about how quickly and massively things can go wrong when a trusted partner unexpectedly turns rogue.

article thumbnail

NY Investigates Exposure of 885 Million Mortgage Documents

Krebs on Security

New York regulators are investigating a weakness that exposed 885 million mortgage records at First American Financial Corp. That measure, which went into effect in March 2019 and is considered among the toughest in the nation, requires financial companies to regularly audit and report on how they protect sensitive data, and provides for fines in cases where violations were reckless or willful. ” A Little Sunshine Data Breaches First American Financial Corp.

article thumbnail

NY Department of Financial Services Issues Reminder for Cybersecurity Filing Deadline

Hunton Privacy

On January 22, 2018, the New York Department of Financial Services (“NYDFS”) issued a press release reminding entities covered by its cybersecurity regulation that the first certification of compliance with the regulation is due on or prior to February 15, 2018. As DFS continues to implement its landmark cybersecurity regulation, we will take proactive steps to protect our financial services industry from cyber criminals.”.

article thumbnail

Oracle Tackles a Massive 405 Bugs for Its April Quarterly Patch Update

Threatpost

Oracle will detail 405 new security vulnerabilities Tuesday, part of its quarterly Critical Patch Update Advisory.

article thumbnail

Disneyland Malware Team: It’s a Puny World After All

Krebs on Security

A financial cybercrime group calling itself the Disneyland Team has been making liberal use of visually confusing phishing domains that spoof popular bank brands using Punycode , an Internet standard that allows web browsers to render domain names with non-Latin alphabets like Cyrillic.

IT 267
article thumbnail

Episode 247: Into the AppSec Trenches with Robinhood CSO Caleb Sima

The Security Ledger

Paul speaks with Caleb Sima, the CSO of the online trading platform Robinhood, about his journey from teenage cybersecurity phenom and web security pioneer, to successful entrepreneur to an executive in the trenches of protecting high value financial services firms from cyberattacks.

article thumbnail

Spearphishing Attack Spoofs Microsoft.com to Target 200M Office 365 Users

Threatpost

It remains unknown as to why Microsoft is allowing a spoof of their very own domain against their own email infrastructure. Web Security exact domain spoofing financial services Healthcare Ironscales manufacturing Microsoft Office 365 spearphishing Spoofing telecom utilities vertical markets

article thumbnail

Oracle Kills 402 Bugs in Massive October Patch Update

Threatpost

Over half of Oracle's flaws in its quarterly patch update can be remotely exploitable without authentication; two have CVSS scores of 10 out of 10.

article thumbnail

Mobile Security Vendor Approov Hires New CEO to Expand in US

Data Breach Today

Ted Miracco Plans to Grow Approov's Footprint in Healthcare and Financial Services Approov has landed a new CEO to help the mobile security upstart expand in the United States and capture more healthcare and financial services customers.

article thumbnail

Work from Everywhere, Securely

Data Breach Today

CyberEdBoard Executive Member, Charmaine Valmonte, guest speaks at ISMG Virtual Cybersecurity Summit Asia: Financial Services Volmonte is VP, IT security and IT infrastructure, Aboitiz Group of Companies.

Military 173
article thumbnail

New York State Expected to Increase Enforcement of Cybersecurity Practices

HL Chronicle of Data Protection

It applies to any “Covered Entity,” which is defined broadly to include “any Person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law.”

article thumbnail

The ‘Zelle Fraud’ Scam: How it Works, How to Fight Back

Krebs on Security

One of the more common ways cybercriminals cash out access to bank accounts involves draining the victim’s funds via Zelle , a “peer-to-peer” (P2P) payment service used by many financial institutions that allows customers to quickly send cash to friends and family.

IT 358
article thumbnail

The G7 expresses its concern over ransomware attacks

Security Affairs

Experts are observing a significant increase in the number of Ransomware attacks against hospitals, financial institutions, schools, and other critical infrastructure in G7 countries. “The G7 is committed to working with our financial sectors to combat ransomware.

IT 141
article thumbnail

Financial Execs Say Security a Top Cryptocurrency Barrier

Data Breach Today

article thumbnail

Security Compliance & Data Privacy Regulations

eSecurity Planet

Regulatory compliance and data privacy issues have long been an IT security nightmare. And since the EU’s General Data Protection Regulation (GDPR) took effect May 25, 2018, IT compliance issues have been at the forefront of corporate concerns. Financial Data Protection Laws.

article thumbnail

Keeping Up with New Data Protection Regulations

erwin

Facebook was in the news again last week for another major problem around the transparency of its user data, and the tech-giant also is reportedly facing 10 GDPR investigations in Ireland – along with Apple, LinkedIn and Twitter. When it comes to new data protection regulations in the face of constant data-driven change, it’s a matter of when, not if. Less than four months before GDPR came into effect, only 6 percent of enterprises claimed they were prepared for it.

article thumbnail

7.5M Banking Customers Affected in Dave Security Breach

Dark Reading

The financial services app confirms user data was compromised in a data breach at its former third-party provider, WayDev

article thumbnail

Morgan Stanley's Hard Drive Destruction Investment Failure

Data Breach Today

$35 Million Fine From Securities and Exchange Commission Covers 5 Years of Mishaps Financial services giant Morgan Stanley will pay a $35 million fine to settle U.S.

article thumbnail

Ransomware at IT Services Provider Synoptek

Krebs on Security

Synoptek , a California business that provides cloud hosting and IT management services to more than a thousand customer nationwide, suffered a ransomware attack this week that has disrupted operations for many of its clients, according to sources.

article thumbnail

Takeaways From Viasat Outage

Data Breach Today

It also examines the invasion's impact on financial services and how to modernize security operations

article thumbnail

Business Process Modeling Use Cases and Definition

erwin

A visual representation of what your business does and how it does it. According to Gartner , BPM links business strategy to IT systems development to ensure business value. It also combines process/ workflow, functional, organizational and data/resource views with underlying metrics such as costs, cycle times and responsibilities to provide a foundation for analyzing value chains, activity-based costs, bottlenecks, critical paths and inefficiencies.