Bank of England: Financial sector failing to implement basic cybersecurity controls
ID: 4826d073-d9f8-53a7-b68a-a533f7d49c0e
STIX ID: report--4826d073-d9f8-53a7-b68a-a533f7d49c0e
Feed Name: The Register (Security)
The UK’s 2025 CBEST review of financial institutions highlights recurring weaknesses—misconfigured and inconsistently patched systems, weak access controls, inadequate detection/monitoring, and staff prone to social engineering (phishing, helpdesk impersonation); NCSC notes these tactics align with groups like Scattered Spider. While CTI foundations exist and MFA adoption has improved, integration across the business and security culture remain gaps, and regulators urge firms and FMIs to strengthen resilience against sophisticated/state-backed, third-party/supply-chain, and insider threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
