90 Percent of IT Security in Financial Services Feel Vulnerable to a Data Breach
By FF Newsroom · 26 October 2015

44 Percent already Experienced One
Spending to protect data increasing, but concentrated in least effective security controls
2016 Vormetric Data Threat Report -- Financial Services Edition
Vormetric, a Thales company, and a leader in enterprise data protection for physical, virtual, big data, and cloud environments, today announced the results of the Financial Services Edition of the 2016 Vormetric Data Threat Report (DTR). The report is issued in conjunction with analyst firm 451 Research, reporting responses from 1,100 senior IT security executives at large enterprises worldwide, including over 100 in U.S. financial services organizations. This edition of the fourth annual report extends earlier findings of the global report, focusing on responses from IT security leaders in financial services, which details IT security spending plans, perceptions of threats to data, rates of data breach failures and data security stances.
"Something doesn't add up in the plans of financial services organizations for protecting data," saidGarrett Bekker, senior analyst, information security, at 451 Research and the author of the 2016 Vormetric Data Threat Report. "Spending to protect data is increasing fastest in areas that have been shown to be ineffective at protecting against multi-stage attacks - Network defenses (65 percent) and end point and mobile device defenses (58 percent) - still see the highest increase in spending, while approaches like data-at-rest defenses that have been proven to be effective at protecting data after perimeter defenses have been bypassed, are at the bottom (48 percent)."
Other key findings:
- 90 percent feel vulnerable to data threats
- 44 percent have already experienced a data breach, with nearly one in five (19 percent) indicating a breach in the last year
- At 56 percent, meeting compliance requirements was the top IT security spending priority, but preventing data breaches at 50 percent and best practices, also at 50 percent, were close followers
- Complexity at 68 percent, and lack of staff at 35 percent, are identified as top barriers to adoption of better data security
- Bright spots include 70 percent increasing spending to offset threats to data and 48 percent increasing spending on data-at-rest defenses this year
- Compliance (56 percent)
- Data breaches (50 percent)
- Implementing security best practices (50 percent)
- Security breaches at the cloud provider level (75 percent)
- Increased vulnerabilities from shared infrastructure (72 percent)
- Lack of a data privacy policy or privacy service level agreements (71 percent)
- 70 percent are increasing spending to protect sensitive data
- 48 percent, plan to invest in data-at-rest defenses this year
- 62 percent are looking to implement data security for brand and reputation protection
- Many are planning to implement 'newer' security tools that are more effective at protecting data even when other defenses have been compromised. These include tokenization (42 percent), application encryption (33 percent), Security Event and Information Management (SIEM) systems (29 percent) and privileged user access management (29 percent)