Payments 20 (P20) has collaborated with some of the largest payment firms and law enforcement organisations to develop a standard approach which will help firms defend themselves against the growing, global cyber threat.
The advocacy group, alongside organisations including American Express, Elavon, Hogan Lovells, J.P. Morgan Chase, the UK National Cyber Security Centre and New York State Department of Financial Services, has created a new report entitled ‘20 Best Practice Recommendations for Improved Cyber Security Protection’.
Aimed at non-cyber professionals, the report emphasises the urgency of implementing more efficient and comprehensive cyber security frameworks in response to the increasing capabilities of cyber criminals, scammers and other nefarious actors since the onset of the COVID-19 pandemic.
The uncertainty and disruption caused by the COVID-19 pandemic has presented cyber criminals with a wealth of opportunities to attack. Since March 2020 cyber crime has rocketed with 74% of banks experiencing a rise in cyber attacks and three out of four financial institutions worrying about the historic rise in criminal activity and what will happen going forward.
The cyber security problem now represents a serious systemic threat to the global financial system, a sentiment echoed by Chairman of the Federal Reserve Jerome Powell, who in April 2021 said he worried that a cyber attack may result in the next great financial crisis. This highlights the need to a collective global, standardised approach towards counteracting the threat.
The best practice actions cover five areas:
- Network security
- Data handling
- Employee awareness
- Actions before a cyber attack occurs
- Actions immediately after a cyber attack occurs
Duncan Sandys, Chief Executive Officer at P20, said: “As businesses across the globe embraced remote working and shifted operations online, the state sponsored and professional criminal gangs exploited the weaknesses of security apparatus and the fears of individuals. At P20, we believe everyone has a part to play in protecting their organisation and its reputation against this threat. This is why we joined forces with leading financial institutions, cyber security experts and government officials to compile standardised, easy to implement actions for non cyber experts which will go a long way in strengthening their organisations’ defences and protecting their customers.”
Michael Papay, EVP, Technology Risk & Information Security at American Express, said: “The greatest vulnerabilities in the payments network are those hidden third-parties or fourth-party suppliers that nobody has identified as a risk. A lot of the big companies involved in payments networks understand the challenges — they understand information security; they know how to approach these problems and how to tackle them. It’s the smaller companies that are providing some critical service that we haven’t fully solved for yet.”
JF Legault, Managing Director, Global Head of Cyber Security Operations at J.P. Morgan Chase, said: “You can have the strongest controls in the world, the best cyber security program but one thing that organisations continuously need to work on is improving their crisis management processes.”
Paul Maddinson, Director for National Resilience & Strategy at the UK National Cyber Security Centre (NCSC), said: “There are several things that we recommend for small organisations to get those basics right. One is about backing up data and making sure you’re doing that properly. The second is using passwords appropriately. The third is keeping your devices updated and making sure that the software is patched. The fourth is putting some protections in place against malware and then trying to avoid phishing attacks through email and how your staff respond.”
The publication of the report comes ahead of P20’s annual Global Payment Conference, taking place on 28-29 September 2021 where cyber security will be a key talking point. The conference will bring together hundreds of industry leaders, politicians, government officials, regulators, thought leaders and others to highlight trends, debate industry priorities and shape the future. Keynote speakers include Andrew Bailey, Governor of Bank of England, Patricia Scotland, Secretary General of The Commonwealth, Christopher Woolard CBE, ex-Interim CEO, UK Financial Conduct Authority, Michael D’Ambrosio, ex-Assistant Director, US Secret Service and former US Ambassador to the United Nations, Andrew Young.