UK’s top financial services organisations still collecting PII insecurely in the run up to GDPR, discovers RiskIQ
By FF Newsroom · 22 May 2018

With the EU General Data Protection Regulation (GDPR) coming into effect on May 25, RiskIQ, the digital threat leader, has discovered that one in nine PII capturing websites belonging to the top 10 UK financial services organisations are doing so without adequate security measures, potentially breaching GDPR guidelines.
Across 28,991 active websites, RiskIQ research found that out of 1,245 sites capturing PII through data entry points accessible by site visitors, 27 percent of these sites (342 sites) are capturing PII insecurely. This equates to an average of 34 sites per organisation.
A PII capturing website is one which accepts user input that can identify an individual. Examples of PII include input data such as name, address, date of birth, and email address. This also extends to pages with iframes and pop-up windows that populate during a browser session and accept data. RiskIQ identifies these by referencing the Document Object Model (DOM) of each page of a website. This method is language agnostic and identifies PII capture regardless of site language.
RiskIQ research found:
- Out of 3,101 public websites with a login page, 294 of these sites (9.4 percent) capture login information insecurely
- Out of 320 sites capturing PII through data entry fields accessible by site visitors, 124 (39 percent) are capturing PII insecurely