Talk With an Expert

Penetration Testing in the Financial Services Industry

Penetration Testing in the Financial Services Industry (PDF, 1.87MB)Published: 09 Mar, 2010
Created by
Christopher Olson

The financial services industry has unique information security requirements. Frequently the target of attacks, banks have to perform a higher level of due diligence to ensure the confidentiality, integrity and availability of customer transactions. Penetration testing is one way to stress the attack surface that an organization presents to the outside world. The paper will propose a method by which senior management of financial organizations can prioritize a penetration test. By starting with a comprehensive vulnerability assessment it is possible to identify possible targets that may appeal to an attacker. Given that most financial institutions engage in some form of outsourcing we will also address whether it is better to source the test internally or to outsource.