{"id":17717,"date":"2017-06-13T08:08:25","date_gmt":"2017-06-13T04:08:25","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=17717"},"modified":"2017-06-13T08:08:25","modified_gmt":"2017-06-13T04:08:25","slug":"30-days-after-wannacry-what-can-the-financial-services-sector-learn","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2017\/06\/13\/30-days-after-wannacry-what-can-the-financial-services-sector-learn\/","title":{"rendered":"30 Days after WannaCry \u2013 what can the financial services sector learn?"},"content":{"rendered":"<p><em>By Charles Habak, Vice President at Booz Allen Hamilton MENA, and Wayne Loveless, Principal at Booz Allen Hamilton MENA <\/em><\/p>\n<p>WannaCry or Wcry represents the latest version of a growing threat called Ransomware \u2013 a tailored piece of malware designed to exploit specific vulnerabilities in the operating systems of its victims\u2019 computers.<\/p>\n<p>Malware outbreaks are not infrequent, but Wcry spread so rapidly that it revealed vulnerabilities in the business planning, employee preparation and internal procedures of organisations all over the world. A majority of affected systems were running outdated versions of software, with no access to updates because the vendor had phased out support to these legacy systems. <\/p>\n<p>The financial services industry sector is no stranger to the phenomenon of outdated software. Many of today\u2019s financial systems still run on UNIX based platforms developed in the 1980s and 1990s, which often are no longer supported by vendors. <\/p>\n<p>What the financial sector can learn from the Wcry fallout is the importance of investing in a sound risk management framework that involves technology change management as well as updated software \u2013 all of which could have prevented Wcry. <\/p>\n<div id='gallery-1' class='gallery galleryid-17717 gallery-columns-3 gallery-size-thumbnail'><figure class='gallery-item'>\n\t\t\t<div class='gallery-icon portrait'>\n\t\t\t\t<a href='https:\/\/www.intelligentcio.com\/me\/2017\/06\/13\/30-days-after-wannacry-what-can-the-financial-services-sector-learn\/booz-allen-hamilton-wayne-loveless-senior-cyber-technology-chief-strategist-1000\/'><img loading=\"lazy\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2017\/06\/Booz-Allen-Hamilton-Wayne-Loveless-Senior-Cyber-Technology-Chief-Strategist-1000-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail\" alt=\"\" aria-describedby=\"gallery-1-17729\" \/><\/a>\n\t\t\t<\/div>\n\t\t\t\t<figcaption class='wp-caption-text gallery-caption' id='gallery-1-17729'>\n\t\t\t\tWayne Loveless of Booz Allen Hamilton\n\t\t\t\t<\/figcaption><\/figure><figure class='gallery-item'>\n\t\t\t<div class='gallery-icon landscape'>\n\t\t\t\t<a href='https:\/\/www.intelligentcio.com\/me\/2017\/06\/13\/30-days-after-wannacry-what-can-the-financial-services-sector-learn\/boozallenhamilton-charles_habak_1000-2\/'><img loading=\"lazy\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2017\/06\/BoozAllenHamilton-Charles_Habak_1000-1-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail\" alt=\"\" aria-describedby=\"gallery-1-17728\" \/><\/a>\n\t\t\t<\/div>\n\t\t\t\t<figcaption class='wp-caption-text gallery-caption' id='gallery-1-17728'>\n\t\t\t\tCharles Habak of Booz Allen Hamilton\n\t\t\t\t<\/figcaption><\/figure>\n\t\t<\/div>\n\n<p>Investing in a sound backup and continuity plan can also enable organisations to quickly rebuild and recover systems in the event of a cyber-attack or ransomware impact and eliminate any need to pay ransom. Most law enforcement agencies and cyber experts would caution against paying the ransom as it may open the victims up to further exploitation and potential identity theft.<\/p>\n<p>Financial services organisations and their leadership have a duty to protect their customers\u2019 financial interests as well as their own institutions. This begins with a dedicated cyber agenda at the board level along with the formation of a cybersecurity action committee reporting directly to the CEO. <\/p>\n<p>Bank-wide vulnerability assessments across all of the business units that are C-level driven and business-aligned should be prioritised. Additionally, a dedicated cyber security business unit should be formulated with the goal of assessing and implementing new types of capabilities, processes and functions to combat growing threats.<br \/>\nFinally, encouraging bilateral and multilateral communication mechanisms with other banks in the marketplace, and interfacing with regulators to inform of threats and share information of potential breaches as well as threat intelligence from local, regional, and international partners can provide the contextual understanding needed to proactively defend institutions from future threats.<\/p>\n<p><em>About Booz Allen Hamilton<\/p>\n<p>Booz Allen Hamilton has been at the forefront of strategy and technology for more than 100 years. Today, the firm provides management and technology consulting and engineering services to leading Fortune 500 corporations, governments, and not-for-profits across the globe. <\/p>\n<p>In the Middle East and North Africa (MENA) region, Booz Allen builds on six decades of experience partnering with public and private sector clients to solve their most difficult challenges through a combination of business strategy, digital innovation, data analytics, cybersecurity and resilience, operations, supply chain, organisation and culture, engineering and life-cycle project management expertise. <\/p>\n<p>With regional MENA offices in Abu Dhabi, Beirut, Cairo, Doha, Dubai and Riyadh, and international headquarters in McLean, Virginia, the firm employs more than 23,300. <\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Charles Habak, Vice President at Booz Allen Hamilton MENA, and Wayne Loveless, Principal at Booz Allen Hamilton MENA WannaCry or Wcry represents the latest version of a growing threat called Ransomware \u2013 a tailored piece of malware designed to exploit specific vulnerabilities in the operating systems of its victims\u2019 computers. Malware outbreaks are not [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":17719,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1741,139,809,16],"tags":[598,292,138,562],"class_list":["post-17717","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking-finance","category-industry-expert","category-more-news","category-regional-news","tag-banking-finance","tag-cyber-attacks","tag-cyber-security","tag-middle-east"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/17717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=17717"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/17717\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/17719"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=17717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=17717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=17717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}