Threat Intelligence

Report: Financial sector suppliers severely lacking in cybersecurity

Cybersecurity Dive reports that organizations providing tools and services to the financial sector had worse scores on 16 of 22 cybersecurity risk vectors, compared with financial services organizations.

Among the risk vectors where vendors most severely lagged behind their customers were in web application security, TLS, and HTTP headers, according to a BitSight analysis. However, financial services suppliers performed better in leveraging the DMARC and DKIM email security protocol, as well as the DNSSEC protocol. Additional findings revealed that while supplier security is being better monitored by the finance industry than other sectors, suppliers tracked by more entities had reduced security performance.

"Given the growing number of supply chain incidents involving technology providers, perhaps financial sector organizations should be monitoring more of their providers. On the other hand, it is possible that financial sector organizations have undertaken a criticality determination and concluded that the vast majority of technology vendors within their supply chain do not need to be continuously monitored," said BitSight.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds