{"id":5535,"date":"2022-03-28T15:34:23","date_gmt":"2022-03-28T12:34:23","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=5535"},"modified":"2022-04-21T12:23:04","modified_gmt":"2022-04-21T09:23:04","slug":"3-data-security-tips-for-lending-and-brokerage-firms","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/3-data-security-tips-for-lending-and-brokerage-firms\/","title":{"rendered":"3 Data Security Tips for Lending and Brokerage Firms"},"content":{"rendered":"<p>Any company wishing to accept card payments over the phone, in person, or online from the world\u2019s biggest card schemes must comply with the\u00a0Payment Card Industry Data Security Standard\u00a0(PCI DSS).\u00a0<a href=\"https:\/\/www.endpointprotector.com\/solutions\/finance\" target=\"_blank\" rel=\"noopener\">Lending and brokerage firms<\/a>\u00a0whose collection of sensitive credit card and personal information is a core part of their business operations are no exception.<\/p>\n<h2>Compliance requirements for lending and brokerage firms<\/h2>\n<p><a href=\"https:\/\/www.endpointprotector.com\/blog\/all-you-need-to-know-about-pci-dss-compliance\/\" target=\"_blank\" rel=\"noopener\">PCI DSS<\/a> is an international proprietary information security standard developed by the PCI Security Standards Council for organizations that handle cardholder information for the world\u2019s biggest card schemes: American Express, Discover, JCB, MasterCard, and Visa. It was adopted by financial institutions worldwide as a general standard to help protect payment systems from breaches, fraud, and theft of cardholder data.<\/p>\n<p>Noncompliance with PCI DSS comes with hefty fines of up to $100,000\/month and increased transaction fees. But the biggest danger is the possibility of a company\u2019s relationship with its bank being permanently terminated. Organizations can also be added to the Merchant Alert to Control High-Risk (<a href=\"http:\/\/www.mastercard.com\/elearning\/match\/story.html\" target=\"_blank\" rel=\"noopener\">MATCH<\/a>) list, which means they would never be allowed to process card payments again.<\/p>\n<p>Besides PCI DSS compliance, lending and brokerage firms need to be mindful of data protection laws such as the EU\u2019s\u00a0<a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener\">General Data Protection Regulation<\/a>\u00a0(GDPR), the\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/glba-the-gramm-leach-bliley-act\/\" target=\"_blank\" rel=\"noopener\">Gramm-Leach-Bliley Act\u00a0<\/a>(GLBA), and the\u00a0<a href=\"https:\/\/www.endpointprotector.com\/epp\/ccpa-compliance-the-most-in-depth-guide\" target=\"_blank\" rel=\"noopener\">California Consumer Privacy Act<\/a>\u00a0(CCPA). These regulate the collection, processing, and storage of\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/how-to-protect-pii-with-data-loss-prevention\/\" target=\"_blank\" rel=\"noopener\">personally identifiable information<\/a>\u00a0(PII) such as names, addresses, and phone numbers and grant several rights to data subjects.<\/p>\n<p>To meet compliance requirements and protect both credit card and personal information, lending and brokerage firms can turn to cybersecurity solutions. Companies can implement basic security measures such as firewalls and antimalware solutions to prevent malicious attacks. They can also turn to more advanced strategies such as the use of <a href=\"https:\/\/www.endpointprotector.com\/blog\/tpm-the-new-windows-11-requirement-everybody-is-talking-about\/\" target=\"_blank\" rel=\"noopener\">Trusted Platform Module<\/a>\u00a0(TPM) capabilities and the adoption of\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/the-first-steps-towards-zero-trust-security\/\" target=\"_blank\" rel=\"noopener\">Zero Trust<\/a>\u00a0architecture.<\/p>\n<p>However, that may not be enough to prevent a data breach. Traditional security strategies tend to address only external threats while ignoring security risks associated with <a href=\"https:\/\/www.endpointprotector.com\/blog\/top-5-internal-data-security-threats-and-how-to-deal-with-them\/\" target=\"_blank\" rel=\"noopener\">insiders<\/a>.<\/p>\n<p>Here are our tips on how lending and brokerage companies can improve their cybersecurity strategies and address these often overlooked threats.<\/p>\n<h2>1. Monitor sensitive data<\/h2>\n<p>To better understand vulnerabilities in their data flow and check whether their security policies are being applied effectively, lending and brokerage firms can use data monitoring tools such as <a href=\"https:\/\/www.endpointprotector.com\/blog\/what-is-data-loss-prevention-dlp\/\" target=\"_blank\" rel=\"noopener\">Data Loss Prevention<\/a> (DLP) solutions.<\/p>\n<p>DLP technology allows companies to track sensitive data through policies based on predefined profiles for specific data protection legislation and standards such as PCI DSS, GLBA, and GDPR or customized definitions based on company needs. Through them, organizations can easily identify any files containing sensitive data and their movements across the company network. They can also discover data exit points or employees who may bypass security policies to steal data or simplify their tasks.<\/p>\n<p>By identifying bad data security practices among employees through data monitoring, organizations can better educate them in future training sessions by focusing on known risks. Monitoring can also help companies discover which employees require further training and which do not. In this way, they can prioritize education for those who need it and save money.<\/p>\n<h2>2. Protect sensitive data from internal threats<\/h2>\n<p>Monitoring and training do not eliminate the risks posed by\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/what-are-insider-threats-and-how-can-you-tackle-them\/\" target=\"_blank\" rel=\"noopener\">internal threats<\/a>. Insiders can also turn malicious and try to steal data for personal gain or because outsiders have compromised them. There is also no guarantee that even the most diligent employee will not have a moment of carelessness in which they send an email to the wrong person or hit reply all. While these kinds of incidents cannot be eliminated, sensitive data can be protected from them.<\/p>\n<p>Lending and brokerage firms can apply DLP policies to not only monitor sensitive data but also prevent it from being shared via popular messaging apps such as Skype or Slack, via personal emails or cloud applications, or from being printed or copy-pasted in the body of an email. They can also search locally stored data and apply remediation actions such as encryption or deletion when sensitive data is found in unauthorized locations.<\/p>\n<p>Some solutions, like\u00a0<a href=\"https:\/\/www.endpointprotector.com\/solutions\/data-loss-prevention\" target=\"_blank\" rel=\"noopener\">Endpoint Protector DLP software<\/a>, ensure minimal disruption to a company\u2019s workforce through a flexible implementation of DLP policies. This means that it allows companies to set different rules based on groups, departments, individuals, or devices. In this way, employees working directly with sensitive data on a daily basis can be more strictly controlled without affecting overall employee productivity.<\/p>\n<h2>3. Control the use of removable devices<\/h2>\n<p>Removable devices are another common data exit point. In the past decade, USBs have been the root cause of massive data breaches. In recent years they have also become a popular malware infection tool. However, removable devices can also be useful tools for employees to easily transfer large amounts of data or take data with them when they attend off-site meetings.<\/p>\n<p>Lending and brokerage firms can use DLP solutions to\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/6-standout-endpoint-protector-device-control-features\/\" target=\"_blank\" rel=\"noopener\">control the use<\/a>\u00a0of peripheral and USB ports as well as Bluetooth connections. Companies can choose to block removable devices altogether or limit their use to secure pre-approved devices. In this way, companies do not only ensure data security but can also monitor the use of removable devices and easily identify which sensitive data transfers were attempted by which employee at what time and using which device.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Any company wishing to accept card payments over the phone, in person, or online from the world\u2019s biggest card schemes must comply with the\u00a0Payment Card Industry Data Security Standard\u00a0(PCI DSS).\u00a0Lending and brokerage firms\u00a0whose collection of sensitive credit card and personal information is a core part of their business operations are no exception. Compliance requirements for &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/3-data-security-tips-for-lending-and-brokerage-firms\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;3 Data Security Tips for Lending and Brokerage Firms&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":5546,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[162],"tags":[],"class_list":["post-5535","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking-financial-institutions","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/5535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=5535"}],"version-history":[{"count":9,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/5535\/revisions"}],"predecessor-version":[{"id":5636,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/5535\/revisions\/5636"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/5546"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=5535"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=5535"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=5535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}