Le Lézard
Classified in: Science and technology
Subjects: Photo/Multimedia, Survey

SecurityScorecard Research Reveals 78% of Europe's Largest Financial Institutions Experienced a Third-party Breach in the Past Year


SecurityScorecard today announced the release of a new report on the Digital Operational Resilience Act (DORA). The report analyzes 240 of the largest financial institutions in the European Union that must comply with the Digital Operational Resilience Act (DORA) by January 2025.

Key takeaways include:

"If nearly 20% of the most well-resourced financial entities in the EU have grades of C or worse, then it's likely that the overall cyber resilience for other financial entities is actually much lower," said Matthew McKenna, Chief Sales Officer, SecurityScorecard. "Financial entities need a trusted view of security risk. SecurityScorecard dynamically discovers risk across a customer's attack surface, including their third- and fourth-party ecosystem, to dramatically reduce the risk of a compromise."

Cyber risk by financial vertical:

DORA implications for third-party risk management

Managing third-party risk is a core theme of DORA and the EU approach to digital cyber risk more broadly. DORA requires financial entities to identify and assess all third-party risks. This includes threats to the confidentiality, integrity, and availability of data and systems, as well as risks to the financial entity's ability to continue operating in the event of a third-party incident.

"Who financial entities choose to trust and how they sustain that trust are essential factors for the resilience of the EU's financial services sector," said Dan Morgan, Senior Government Affairs Director, Europe & APAC, SecurityScorecard. "Financial institutions must adopt an objective, standard measurement for third-party cyber risk to inform regulatory decisions, reduce cyber incidents, and comply with regulations, such as DORA in the EU."

Research Methodology

SecurityScorecard examined the cybersecurity profiles of the largest 240 financial institutions, including their third- and fourth-party vendor operations in Europe in 2023. This aggregates into an ecosystem of 26,142 domains. The top 240 were determined by current revenue, assets under management, or gross written premium. The 240 financial institutions included private equity, asset management, retail banks, Insurance, and pension funds.

This financial institution ecosystem was scored and analyzed against reported data breaches to demonstrate the cybersecurity posture of the financial market in the lead-up to the full implantation of DORA in January 2024.

SecurityScorecard ratings offer easy-to-read A-F ratings across ten risk factors (network security, DNS health, patching cadence, cubit score, endpoint security, IP reputation, web application security, hacker chatter, leaked credentials, and social engineering). Each factor has a numerical weight, which reflects the severity or risk that the factor contributes to an organization's overall cybersecurity posture.

SecurityScorecard utilizes machine learning to optimize the weights of its risk factors. This data-driven approach maximizes the correlation between SecurityScorecard scores and the relative likelihood of a breach. Organizations with an ?A' rating are 7x7 times less likely to experience a cybersecurity breach. SecurityScorecard continuously monitors the threat landscape and evaluates new data sources and new analytics to better reflect cybersecurity risk.

Resources

About SecurityScorecard

Funded by world-class investors, including Evolution Equity Partners, Silver Lake Partners, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings, response, and resilience, with more than 12 million companies continuously rated.

Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 25,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight.

SecurityScorecard makes the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees, and vendors. SecurityScorecard is listed as a free cyber tool and service by the U.S. Cybersecurity & Infrastructure Security Agency (CISA). Every organization has the universal right to its trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.


These press releases may also interest you

at 20:07
Ascentage Pharma (6855.HK), a global biopharmaceutical company engaged in discovering, developing and commercializing both first-in-class and best-in-class therapies for hematological malignancies, announced today that on July 2, 2024, in relation to...

at 20:05
Enterprises in Asia Pacific are moving toward software-defined networking (SDN) to make communication more secure and resilient and speed up business decision-making, according to a new research report published today by Information Services Group...

at 20:00
Atara Biotherapeutics, Inc. , a leader in T-cell immunotherapy, leveraging its novel allogeneic Epstein-Barr virus (EBV) T-cell platform to develop transformative therapies for patients with cancer and autoimmune diseases, today announced that Pascal...

at 18:46
BOXABL, the innovative housing startup known for its foldable Casita homes and building technology, has announced this week that investors have indicated they want to invest over $10MM in the current stock offering. BOXABL previously SOLD OUT the Reg...

at 18:40
Today, a federal court ruled for Ryan (a leading global tax services and software provider) and against the U.S. Federal Trade Commission (FTC), halting the FTC's ban on non-compete agreements set to take effect this fall. U.S. District Court Judge...

at 17:45
The global automotive battery testers market  size is estimated to grow by USD 78.9 million from 2024-2028, according to Technavio. The market is estimated to grow at a CAGR of almost 3.73%  during the forecast period.  Increasing lifespan of...



News published on and distributed by: