picture of padlock
Banks must do better to protect customer data, says the FSA

Banks still oblivious to fraud risks, says FSA

Watchdog unveils slack conduct of financial services industry towards data security

Written by Angelica Mari

The Financial Services Authority (FSA) urged financial institutions to improve security systems after a review exposed the fact that many companies underestimate the value of their customer’s information.

The FSA assessed the systems and controls at 39 UK firms including banks and building societies, as well as insurance companies and financial advisers, many of which still do not realise the dangers surrounding the exposure of client data.

Businesses are not checking if third-party suppliers vet their employees or have adequate security arrangements in place to prevent unnecessary access to customer data, it said.

Training was also an issue, with businesses placing more emphasis on IT control procedures for data protection than on security awareness and education for their workforce, said the FSA review.

"It is worrying that despite increased public awareness of the impact that identity theft can have on customers, many firms are still not taking this risk seriously,” said FSA’s director of financial crime and intelligence division Philip Robinson.

“Customers have a right to be confident that firms are doing everything reasonably possible to keep their personal and financial details safe,” said Robinson.

"Some firms have made progress by adopting good practice while others need to do more in this area to ensure that they are treating their customers fairly,” he said.

Understanding areas of data exposure is a practical challenge for many financial services organisations, said Deloitte’s head of UK security and privacy services Mike Maddison.

“A common challenge for companies is having a complete view of their exposure to the risk of data compromise,” said Maddison.

“Many firms struggle to define what their sensitive data actually is and where that data resides or who it is provided to. They also struggle to co-ordinate management of these risks, which are owned by different parts of the business,” he said.

“The FSA recommendation to appoint a senior manager with overall responsibility for data security, in conjunction with the publication of more information to help management understand their responsibilities, will go some way towards addressing this.”

reader comments

related articles

Picture of a credit card

Online card fraud more extensive than reported

Original APACS figures for 2007 did not include failed attempts, says the BBC 23 Apr 2008

 

Privacy watchdog to get new powers

Office will be given ability to spot check central government 22 Apr 2008

PayPal to block old browsers

Payment service will warn and block old browsers as part of attempts to stop phishing attacks 21 Apr 2008

eBay welcomes alleged cyber criminal's arrest

Romanian stands accused of defrauding eBay users by accessing administrative accounts 18 Apr 2008

FSA slams banks' data security

New report recommends firms appoint a senior manager in charge of data security 24 Apr 2008

UK finance firms urged to tighten up on data security

FSA presses financial firms to take greater precautions to stop data leaks 24 Apr 2008

Police attempt to assuage e-crime fears

Law enforcers promise more joined-up effort to combat e-crime 11 Jun 2008

related whitepapers

today's top stories

IT's stock is soaring at the LSE

London Stock Exchange IT chief David Lester explains to Angelica Mari how the integration of Borsa Italiana is keeping his team busy, despite the worsening economy 20 Nov 2008

Keeping IT in fashion

John Bovill has been hooked on retail since his early years as a fashion market trader. His industry knowledge is now helping him build a slick IT operation, reports Charlotte Moore 20 Nov 2008

Cutting-edge IT delivers the goods

Chief technology officer Jay Bregman explains how constant innovation is part and parcel of his strategy for delivering competitive advantage at eCourier 20 Nov 2008

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Keeping IT on track

Catherine Doran, winner of Computing’s IT Leader of the Year award, tells Angelica Mari of her determination to drive on with technology-led transformation at Network Rail despite uncertainty over funding 19 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will attempts to rebrand IT as a "cool" choice of profession increase the number of IT graduates?

Will attempts to rebrand IT as a "cool" choice of profession increase the number of IT graduates?

Can brand building reverse a decline in IT graduate numbers?

Previous poll results

Latest audio and video articles

Video

The definitive guide to converged communications

Five key trends and five best practice tips to help you improve your corporate communications 20 Nov 2008

PodcastAudio

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Latest in-depth articles

StarFeatures

Retaining the stars of IT

Jim Mortleman investigates the innovative techniques IT leaders are using to hang on to their star performers 20 Nov 2008

Dave BaileyComment

Clouds darken outlook for Vista's successor

Windows 7 looks like being an improvement on Vista, but economic and environmental concerns may mean few enterprises will rush to adopt it 20 Nov 2008

Advertisement

Primary Navigation