* [Topics](/en/topics "Topics")
* [Security](/en/topics/security "Security")
* What is financial services security (and compliance)?
What is financial services security (and compliance)?
=====================================================
Published  January 8, 2019•*5*-minute read
Copy URL
Jump to section
---------------
OverviewHistoryChallengesSecure data and maintain complianceWhy Red Hat?
Overview
--------
Financial services security and compliance refers to the responsibility financial service companies have to hold, manage, and protect customers’ money and financial information. It involves adhering to federal, state, and local regulations that determine standard levels of security surrounding customer data.
[Consider automating your security compliance](/en/resources/security-automation-ebook "Simplify your security operations center")
A brief history of financial service security (and compliance)
--------------------------------------------------------------
Protecting financial customers' assets and information has historically evolved with access.
When assets and information were stored in vaults and transfers were made in physical environments, physical barriers were sufficient. Now that lenders (such as banks and credit unions) and insurance companies provide financial products to customers through financial technology (FinTech), they need to also add security systems that comply with regulations.
Governments around the world have different laws, regulations, and technology standards—and regulatory changes happen every year to accommodate new threats to the world's financial systems.
Why does security and compliance matter?
----------------------------------------
Because nothing lives in a silo anymore. Everything is connected digitally. So a threat at one point could impact a handful of other financial service providers. Consider the increase in high-profile financial crimes and data breaches. A breach at 1 financial services business regularly impacts other financial service providers.
Large-scale regulatory requirements, corporate governance, [data management](/en/topics/data-services/what-is-data-management) strategies, and compliance programs strengthen endpoints (and transfer avenues) of customer data. When all financial service providers meet or exceed regulators' or compliance officers' compliance requirements, there are less entry points for security threats.
Cybersecurity measures, risk assessments, and continued due diligence protect sensitive information—but no system is foolproof. Continued investments in security technology that keep up with new regulations can keep financial services organizations ahead of security threats.
This video can't play due to privacy settings
To change your settings, select the "Cookie Preferences" link in the footer and opt in to "Advertising Cookies or try disabling adblockers."
Red Hat resources
-----------------
[Keep reading](/en/resources "Keep reading")
What are the challenges for financial services?
-----------------------------------------------
### Convenience and customer expectations
The banking industry has made strides moving from a traditional brick-and-mortar model to align with today’s convenience and functional expectations. However, technology and customer sentiment are moving faster than government regulatory oversight of the expanding set of digital features, so banks face a challenge to adapt to customer demand while still adhering to regulations that are slow to change. Additionally, new players in financial services are moving quickly to fill any void, challenging established firms to remain competitive.
### Data protection
Data fraud and breaches are always risks when digital information becomes more convenient to access. Data is transmitted over many points before it reaches its final destination—and each point presents a potential security risk. Mobile applications are especially easy targets. The app itself and the server it sits on may have vulnerabilities that can be exploited. User behavior can also contribute to the risk.
Government regulations, such as the [General Data Protection Regulation](https://ec.europa.eu/commission/priorities/justice-and-fundamental-rights/data-protection/2018-reform-eu-data-protection-rules/eu-data-protection-rules_en) (GDPR) in the European Union (EU) attempt to address many of these points of vulnerability, even as data is transmitted across international borders.
### Institutional mindset
Changing the mindset of the financial services industry presents additional challenges. The financial sector is cautious about changing from a business model that works reliably to one that, in its point of view, poses risks. The rush to offer consumers more convenience without addressing security risks can have disastrous consequences, but if security processes make the user experience more difficult, customers will look for easier ways to accomplish their tasks. Maintaining this delicate balance is a daunting challenge for even the most innovative and forward-thinking companies.
### Public trust
Addressing consumer perception is just as important as the adoption of technology. High-profile data breaches over the years have cultivated an atmosphere of public mistrust toward any company that handles personal data. Trust is easy to lose, and difficult to repair. Customers want assurance that their information is in safe hands. Financial services firms should be as transparent as possible on how they’re keeping information safe from cybercrime and data breaches to cultivate trust.
### Consumer awareness and education
Educating customers on how to protect themselves is probably the most important element in a productive and safe banking experience. Keeping consumers updated on what to look for to protect their information, and what to do in case of a breach can improve the relationship between bank and customer. This information changes as new technologies and threats are introduced, and keeping consumers informed will go a long way toward attracting and retaining customers.
How should financial services secure data and maintain compliance?
------------------------------------------------------------------
How the financial services industry addresses risk and compliance varies. Government institutions (like the U.S. Federal Reserve), companies, and organizations worldwide invest heavily in anti-money laundering, risk management, and compliance processes.
Here are some security options used to meet financial services compliance requirements.
### Encryption
Sensitive data goes through an encryption process—converting it into code that can only be deciphered by using the correct decryption key. However, encrypting, verifying, and decrypting data takes extra time and processing power. To speed up ever-increasing amounts of data processing, banks are upgrading and expanding their existing IT infrastructures or implementing new systems that are more flexible and robust to accommodate faster data encryption that easily scales. The [Payment Card Industry Data Security Standard](https://www.pcisecuritystandards.org/) (PCI DSS) plays a large part in how data is encrypted.
### Multi-factor authentication
Logging in using multiple forms of authentication is becoming a popular option for more than just financial services websites. The user enters a password or PIN, triggering a request to send a code via text message to a previously registered device. The code contains a set of randomly-generated characters that the user enters to complete the log-in process. While this creates an extra step in the login process, it becomes much more difficult for criminals to break in. Banks in the EU are required by the [second Payment Services Directive](https://www.ecb.europa.eu/paym/intro/mip-online/2018/html/1803_revisedpsd.en.html) (PSD2) to implement multi-factor authentication for all transactions, even those extending beyond international borders.
### Data storage and distribution
The influence of GDPR extends to countries beyond the EU and drives the policies of financial institutions around the world on how they store, access, and distribute data. Storing data in one place is no longer a safe option for businesses, even those that rely on cloud services to store digital information. Reliance on a single provider creates a concentration risk—making the data vulnerable to breaches. Distributing storage and functions in separate pieces over several providers dilutes the risk, making it more difficult for criminals to access.
### Artificial Intelligence (AI)
Predefined algorithms can flag transactions that do not fit a normal pattern, for example, a transaction made in London by a customer who lives in the United States. However, if that customer makes visits to London several times a year, the algorithm will continue to flag every transaction made there, even when it’s legitimate. AI can be applied to learn and adapt to customer behavior and update the algorithms so future transactions that match this pattern are less likely to be flagged. AI also drives biometrics—a method of identifying customers using their unique features to get access to account information. Fingerprint, "eyeprint", and facial recognition are features in many smart devices, and a growing number of banks are now offering these options in their mobile apps. This adds an extra layer of security, making it harder for criminals to defeat.
#### Improve AI/ML application management
Get expert perspectives on how to simplify the deployment and lifecycle management of Artificial Intelligence/Machine Learning (AI/ML) applications so you can build, collaborate, and share ML models and AI apps faster with this webinar series.
[Watch the webinar series on demand](https://www.brighttalk.com/summit/4763-ai-ml-smart-apps-easy-delivery-fast-platform/?utm_source=Red%20Hat&amp%3Butm_medium=web&amp%3Butm_campaign=RH-ISV-AI-ML-2020)
Why Red Hat?
------------
We want you to have confidence as you adopt a continuous security strategy. We do that by making open source ready for the enterprise. Our goal is to help your business remain competitive, flexible, and adaptable while maintaining security and regulatory compliance.
[Learn how Red Hat can help](/en/contact "about | contact")
The official Red Hat blog
-------------------------
Get the latest information about our ecosystem of customers, partners, and communities.
[Keep reading](/en/blog "The official Red Hat blog")
All Red Hat product trials
--------------------------
Our no-cost product trials help you gain hands-on experience, prepare for a certification, or assess if a product is right for your organization.
[Keep reading](/en/products/trials "All Red Hat product trials")
Keep reading
------------
### What is security automation?
Security automation uses technology to perform tasks with reduced human assistance to integrate security processes, applications, and infrastructure.
[Read the article](/en/topics/automation/what-is-security-automation "article | what is security automation")
### What is SOAR?
SOAR refers to 3 key software capabilities that security teams use: case and workflow management, task automation, and a centralized means of accessing, querying, and sharing threat intelligence.
[Read the article](/en/topics/security/what-is-soar "article | what is soar")
### What's an insider threat?
An insider threat is leaked or misused data that—whether released accidentally or purposefully—could be used in malicious ways or viewed by individuals who shouldn’t have legitimate access.
[Read the article](/en/topics/security/what-are-insider-threats "article | What's an insider threat")
Security resources
------------------
### Related content
* Blog post
  [Beyond automation: Why the surge in AI-driven security vulnerabilities demands human technical advocacy](/en/blog/beyond-automation-why-surge-ai-driven-security-vulnerabilities-demands-human-technical-advocacy)
* Blog post
  [Fragnesia and friends: When page cache vulnerabilities keep coming back](/en/blog/fragnesia-and-friends-when-page-cache-vulnerabilities-keep-coming-back)
* Blog post
  [10 essential reads to optimize performance, security, and ROI in the AI era](/en/blog/10-essential-reads-optimize-performance-security-and-roi-ai-era)
* Blog post
  [Advancing post-quantum capabilities of SSH in Red Hat Enterprise Linux](/en/blog/advancing-post-quantum-capabilities-ssh-red-hat-enterprise-linux)
### Related articles
* [What is microsegmentation?](/en/topics/virtualization/microsegmentation)
* [What is AI security?](/en/topics/ai/what-is-ai-security)
* [What is patch management?](/en/topics/management/what-patch-management-and-automation)
* [What is security automation?](/en/topics/automation/what-is-security-automation)
* [What's an insider threat?](/en/topics/security/what-are-insider-threats)
* [What is SOAR?](/en/topics/security/what-is-soar)
* [What is post-quantum cryptography?](/en/topics/security/post-quantum-cryptography)
* [What is lightweight directory access protocol (LDAP) authentication?](/en/topics/security/what-is-ldap-authentication)
* [What is software supply chain security?](/en/topics/security/what-is-software-supply-chain-security)
* [What is secrets management?](/en/topics/devops/what-is-secrets-management)
* [What is confidential computing?](/en/topics/security/what-is-confidential-computing)
* [What are SPIFFE and SPIRE?](/en/topics/security/spiffe-and-spire)
* [Red Hat Enterprise Linux security](/en/technologies/linux-platforms/enterprise-linux/security)
* [What is zero trust?](/en/topics/security/what-is-zero-trust)
* [Functional safety and continuous certification on Linux](/en/topics/open-source/functional-safety-and-continuous-certification-on-linux)
* [What is access control?](/en/topics/security/what-is-access-control)
* [What is a CVE?](/en/topics/security/what-is-cve)
* [What is role-based access control (RBAC)?](/en/topics/security/what-is-role-based-access-control)
* [What is kubernetes security?](/en/topics/containers/kubernetes-security)
* [Shift left vs. shift right](/en/topics/devops/shift-left-vs-shift-right)
* [Red Hat Lightspeed data and application security](/en/topics/management/data-application-security)
* [What is CI/CD security?](/en/topics/security/what-is-cicd-security)
* [What is an intrusion detection and prevention system (IDPS)?](/en/topics/security/what-is-an-IDPS)
* [What is security information and event management (SIEM)?](/en/topics/security/what-is-SIEM)
* [The increasing importance of cybersecurity in banking](/en/topics/financial-services/increasing-importance-cybersecurity-banking)
* [Gain security with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/gain-security-with-red-hat-ansible-automation-platform)
* [What is edge security?](/en/topics/security/what-is-edge-security)
* [What is the importance of operational resilience?](/en/topics/financial-services/what-is-operational-resilience)
* [What is vulnerability management?](/en/topics/security/what-is-vulnerability-management)
* [What is backup and recovery?](/en/topics/security/backup-and-recovery)
* [What is container security?](/en/topics/security/container-security)
* [What is DevSecOps?](/en/topics/devops/what-is-devsecops)
* [What is compliance management?](/en/topics/management/what-is-compliance-management)
* [Why choose Red Hat for DevSecOps](/en/topics/devops/why-choose-red-hat-for-devsecops)
* [What is cloud governance?](/en/topics/automation/what-is-cloud-governance)
* [Security in the software development lifecycle](/en/topics/security/software-development-lifecycle-security)
* [Kubernetes security best practices](/en/topics/containers/kubernetes-security-best-practices)
* [Security for IoT devices](/en/topics/security/security-for-iot-devices)
* [What is identity and access management (IAM)?](/en/topics/security/what-identity-and-access-management-iam)
* [Advantages of Kubernetes-native security](/en/topics/containers/advantages-of-kubernetes-native-security)
* [Intro to Kubernetes security](/en/topics/containers/intro-kubernetes-security)
* [Container and Kubernetes compliance considerations](/en/topics/containers/compliance)
* [What is risk management?](/en/topics/management/what-is-risk-management)
* [What is SELinux?](/en/topics/linux/what-is-selinux)
* [Hybrid cloud security](/en/topics/security/what-is-hybrid-cloud-security)
* [What is API security?](/en/topics/security/api-security)
* [What is malware?](/en/topics/security/what-is-malware)
* [What is cloud security](/en/topics/security/cloud-security)
[More about this topic](/en/topics/security "More about this topic")