APAC Banks Will Stop Doing Business with Suppliers that Fail Cybersecurity Audits

Banks across the Asia Pacific region will stop doing business with suppliers that fail cybersecurity audits, according to a recent poll by FICO.

Three in four senior fraud managers surveyed said that they would be concerned enough to stop working with a partner, while another 16 percent said they weren’t sure if they would continue working with them. Only 8 percent of fraud managers said they would definitely continue doing business.

While the auditing of business partners and their security capabilities is a relatively new practice, four in ten respondents confirmed they were already actively engaged in the process.

Cybersecurity audits commonplace in 2017

“We expect cybersecurity audits to become commonplace in 2017,” said Dan McConaghy, president for FICO Asia-Pacific. “High profile fraud cases, such as the Bangladesh Bank heist where USD$81 million was stolen, illustrate the importance of banks running audits on their own networks as well as those of their partners. However, due to the complex ecosystem of relationships with other businesses that banks have we are seeing the audit tools evolve.

“While formal audits remain important, they can be lengthy, intrusive, and expensive. They also only offer a snapshot of the cybersecurity picture for a moment in time. We are seeing a need for monitoring tools that allow for ongoing assessment between these audits to strengthen the IT ecosystem and make a substantial impact on the cyber breach problem.”

In October 2016, FICO announced the launch of its FICO Enterprise Security Score, a cybersecurity risk rating that subscribers can use to evaluate the risk of their own network and their business partners’.

“The score was created by analyzing networks that have been victimized by a cyber-attack,” explained McConaghy. “This allows FICO to understand the conditions and behaviors that are precursors to impactful security events. Company networks can then be measured against the indicators that are most predictive of an increase to the likelihood of a material data breach.”

FICO’s poll revealed that bankers nominated large retailers as the greatest data breach risk (84%) in 2017, with telecommunications companies ranking second (70%). These numbers were up significantly on last year’s poll, showing some consensus on which industries remain the largest targets for cybercriminals.

“E-commerce has created low hanging fruit in the form of vast stores of unprotected sensitive personal data that can be used to steal identities,” explained McConaghy. “In Asia Pacific the problem is compounded by the huge growth in sales, poorly protected companies and a lack of disclosure.”

Respondents to the survey were anxious to prevent cybercrime at their banking institutions, with 65 percent saying that it will be their key focus in 2017.

The biggest obstacle identified by the fraud executives in fighting cybercrime was that siloed operations prevented the flow of information and worked against a coordinated response.

Nearly half of respondents identified cybercrime as having the largest potential financial impact on their organizations, and said they had already increased their cybersecurity budget at least 10 to 25 percent over the last 12 months.

“APAC banks want to ensure that the digital economy will continue to thrive,” said McConaghy. “In addition to protecting themselves, we’ll see more banks initiate cybersecurity audits, and as they become more selective avoiding to do business with vendors and suppliers that return ‘fail scores’ on cybersecurity.”

Suggested Articles

Some of you might have already been aware of the news that Questex—with the aim to focus on event business—will shut down permanently all media brands in Asia…

Some advice for transitioning into an advisory role

Global risks are intensifying but the collective will to tackle them appears to be lacking. Check out this report for areas of concern