Bosses’ lack of cyber security knowledge putting clients at risk, FCA warns

The regulator’s multi-firm review has exposed serious shortcomings at the most senior level for many UK firms

CEO looking isolated and disappointed in a board room

Senior management and board-level executives' limited knowledge of cyber security threats are putting clients and their markets at risk of "serious harm".

That's according to a new Financial Conduct Authority review of asset management and financial firms, which found that businesses are also over-reliant on third-party providers for advice, which can potentially have an adverse effect on a firm's long-term development of in-house cyber capabilities.

"All the firms acknowledged the importance of strong cyber security. But there were different degrees of understanding of the many potential ways that weak cybersecurity could affect business activities and lead to harm to clients and the wider markets," the FCA said.

"This was particularly the case at the Board or Management Committee levels."

The FCA added that awareness is lower in firms that don't have a cyber-specific strategy, and where response plans take little account of non-technical consequences such as the impact to their reputation, clients and markets.

Reviewing a representative sample of 20 UK firms, the FCA said organisations' senior leadership must do better to understand the cyber risks tied with the business' activities, particularly where the management structure is centralised.

Firms should also take steps to create a culture that shifts cyber security from just an IT priority to an organisational-wide issue.

Moreover, the UK's financial regulator published a list of questions board-level staff and senior management can ask themselves as they better-familiarise themselves with the threats they face on a regular basis.

These queries include: 'Which aspects of our approach to conduct risk management could we apply to the way we manage our cyber risk. Does this offer value?' and 'How confident are we that our incident management plans would be effective in dealing with the aftermath of a cyber incident?'

The FCA's findings reflect the view of the UK's National Cyber Security Centre's (NCSC) chief executive Ciaran Martin, who said board-level members must do more to grasp the basics or risk their firms falling behind.

Martin, speaking at the Confederation of British Industry's (CBI's) fourth annual Cyber Security Conference in September, warned executives that cyber is now a mainstream business risk.

"People at board level need to understand the basics and I stress, basics of cyber attacks, cyber risks and cyber defences," Martin said in his keynote address.

"That's daunting, but it is doable. It's essential. And today is a significant moment in our efforts to equip the UK's major companies to do it."

The FCA's view also mirrors Department for Digital, Culture, Media and Sport (DCMS) findings released earlier this year that show UK businesses are failing the most basic cyber security measures. Just 50% of businesses surveyed, according to DCMS, are adhering to the very basics of cyber security, while the figure was even lower for charities.

It's a reality that can be partially explained by a widely-publicised cyber skills shortage, with a report published in October exposing a wide global IT skills shortage that currently stands at almost three million.

ITC Secure's director of cyber security Malcolm Taylor said the FCA's findings confirm what many in the industry have known for some time that the cyber threat is widely misunderstood and underestimated by some.

"I don't think this is limited to these sectors, either it's every sector and at every level," he said. "None of this is a criticism; the cyber threat is a new threat, it is in places deeply complex, and it is presented as almost existentially dangerous.

"I also think the cyber security industry has to take some responsibility for this state of affairs. Cyber security products and services have been sold by some through over-emphasising the fear and the complexity of the issue, but whilst that might work for a one-off sale it doesn't build the essential, trusted partnerships that we need, to more expertly and successfully repel attacks."

Featured Resources

Security analytics for your multi-cloud deployments

IBM Security QRadar SIEM solution brief

Download now

Five reasons to move to the cloud

Join the enterprises moving their workloads to the cloud

Download now

Architecting hybrid IT and edge for digital advantage

Why business leaders should consider a hybrid IT strategy

Download now

Six reasons to accelerate remote asset monitoring with AI

How to optimise resources, increase productivity, and grow profit margins with AI

Download now

Recommended

Cyber security firm saw attacks rise by 20% during 2020
cyber security

Cyber security firm saw attacks rise by 20% during 2020

23 Feb 2021
What to look for in a secure cloud system
cloud security

What to look for in a secure cloud system

23 Feb 2021
Hackers turn to 'silent stealing' in bid to exploit home workers
scams

Hackers turn to 'silent stealing' in bid to exploit home workers

22 Feb 2021
Kia Motors allegedly suffers a ransomware attack
data breaches

Kia Motors allegedly suffers a ransomware attack

18 Feb 2021

Most Popular

Mysterious Silver Sparrow malware hits 30,000 macOS devices
malware

Mysterious Silver Sparrow malware hits 30,000 macOS devices

22 Feb 2021
IBM reportedly mulls sale of Watson Health business
mergers and acquisitions

IBM reportedly mulls sale of Watson Health business

22 Feb 2021
Microsoft to launch standalone Office 2021 suite
Microsoft Office

Microsoft to launch standalone Office 2021 suite

19 Feb 2021