Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Financial Institutions and E-Commerce – Are Their Minds on the Security of Your Money?
News & Analysis

Financial Institutions and E-Commerce – Are Their Minds on the Security of Your Money?

ISBuzz TeamBy ISBuzz TeamNovember 6, 20146 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Most people would imagine that protecting payment data would be the top priority for any business that deals primarily in online financial transactions. But according to a Kaspersky Lab survey of more than 3,900 IT professionals worldwide, financial organisations (banks and service providers) and e-commerce providers (online retailers) don’t see the protection of financial information as more important than any other business, and in some cases, they believe it’s much less important than average.

IT Department Security Concerns: Financial Institutions Step Up, E-Commerce Falls Down

According to the survey, the e-commerce industry pays significantly less attention to guarding sensitive payment information and protecting systems from IT security breaches. This seems highly counter-intuitive from what might be expected of a company that exists solely to process online transactions, but the responses regarding almost all aspects of e-commerce security were notably lower than the average responses of traditional businesses.

For example, the survey asked each business about the top concerns of the IT department

·         The highest overall response was “protecting highly-sensitive data (including financial information) from targeted attacks,” an answer given by an average of 34 percent of businesses. The responses from the e-commerce segment were lower than this average, at 28 percent.
·         The second-highest overall priority of the IT department was “preventing IT security breaches,” given by 29 percent of all businesses. Again, the responses from the e-commerce section were lower than average, at 22 percent.
·         Another high-ranking concern for the IT department was “ensuring continuity of service for business-critical systems,” cited as a top concern by 23 percent of businesses overall. E-commerce again came in lower than the average at 19 percent, which is shocking since an online retailer’s entire revenue stream could be cut off by a DDoS attack.

It should be noted that the e-commerce segment wasn’t just “lower than average” for these questions. Responses from this industry were the lowest of all business segments. So if the IT departments of e-commerce businesses aren’t focused on preventing targeted attacks, data breaches, or network outages, then what are they focused on? “Client management” was the one response that e-commerce businesses ranked far higher than any other business (34 percent, compared to an average of 17 percent).

But Kaspersky Lab’s survey found that while the IT departments of e-commerce businesses didn’t have security top-of-mind, financial institutions told a different story when responding to the same question.

·         “Protecting highly-sensitive data (including financial information) from targeted attacks,” was the top IT security concern, cited by 34 percent of businesses. 38 percent of financial institutions rated this as a top concern, the second-highest response rate.
·         “Preventing IT security breaches,” rated as a top concern by 29 percent of all businesses was rated at 30 percent by financial institutions, again the second-highest response rate for this task.
·         “Ensuring continuity of service for business-critical systems,” cited as a top concern by 23 percent of businesses overall, was cited by 26 percent of financial institutions, again the second-highest response rate for this task.

Other Differences (And Occasional Similarities) in Attitudes

The differences in attitudes towards the security of financial information was evident in other questions as well. When asked “What type of data loss would be most potentially damaging,” unsurprisingly, financial institutions ranked “financial information” the second-highest rating of any business segment at 24 percent, while e-commerce gave this response only a seven percent response rate. When the all the responses were added up, the survey found that 37 percent of financial institutions rated any sort of internal or customer financial data as the most damaging type of data they could possibly lose, the highest response rate of all business segments. Once again, e-commerce lagged behind at 21 percent, the second-lowest.

An interesting convergence of opinions occurred around responses less focused on financial information and more focused on customer information in general. Losing “customer/client information” was ranked as highly-damaging by 29 percent of financial institutions, and this time, e-commerce wasn’t as far behind at 21 percent. But by far, the biggest divergence on this question involved the importance of intellectual property. E-commerce businesses rated “intellectual property” and “market intelligence/competitive intelligence” as the two types of data they fear losing the most, and rated these higher than any other segment at 21 percent and 18 percent, respectively. In comparison, “intellectual property” was rated as data they “most feared” losing by only seven percent of financial services businesses, with “market intelligence/competitive intelligence” at nine percent.

Featured Download: Social media access at work. Do your employees know the rules?

When tasked with managing service outages caused by DDoS attacks, financial institutions and e-commerce have more in common than their attitudes may suggest. As noted previously, financial institutions rate DDoS attacks as a much higher source of concern than e-commerce businesses. But according to Kaspersky Lab’s survey, both e-commerce and financial institutions are two sectors that are most highly-targeted by DDoS attacks – 44 percent of e-commerce businesses reported a DDoS attack in the previous 12 months, along with 39 percent of financial institutions. When it comes to suffering negative consequences from DDoS attacks, these two sectors have more in common than they think.

Comprehensive Protection for Specialised Industries

While businesses in the financial institution segment clearly show a more firm commitment to data security their e-commerce counterparts, both segments can benefit from a renewed focus on service continuation planning. E-commerce businesses should take the opportunity to bolster their overall security posture as well.

The Kaspersky Fraud Prevention platform, introduced by Kaspersky Lab earlier in 2014, is designed specifically for banks, payment systems and e-commerce companies. It allows for specialised monitoring and advanced protection on the servers of the business, as well as coordinated security agents operating on the desktops of the business’ customers, combined to ensure a secure transaction and protection of financial data once stored.

To prevent service disruption caused by DDoS attacks, Kaspersky DDoS Protection is now being introduced in selected global markets. To learn more about Kaspersky Lab’s anti-DDoS technologies, please visit our solution homepage.

Kaspersky Endpoint Security for Business leverages the real-time data and analysis obtained by the company’s security experts, who designed this suite specifically to thwart targeted attacks and software exploits. To learn more about how Kaspersky Lab blocks previously-unknown “zero day” software exploits, phishing attacks, and sophisticated polymorphic malware, visit the company’s Internet Security Center for information about targeted attacks.

About Kaspersky Lab

Kaspersky LabKaspersky Lab is the world’s largest privately held vendor of endpoint protection solutions. The company is ranked among the world’s top four vendors of security solutions for endpoint users*. Throughout its more than 17-year history Kaspersky Lab has remained an innovator in IT security and provides effective digital security solutions for large enterprises, SMBs and consumers. Kaspersky Lab, with its holding company registered in the United Kingdom, currently operates in almost 200 countries and territories across the globe, providing protection for over 300 million users worldwide. Learn more at www.kaspersky.com.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}