89% of professional services firm report fraud incidents

Image

The financial services sector was the hardest hit by fraud, cyber and security incidents during 2017, while the majority of executives in the professional services industry report their companies had experienced a fraud incident in the past year, according to global research by security consultants Kroll

Its report, based on a survey of 540 senior executives in companies where 84% had annual revenues of $500m (£358m) or more, found that 89% of executives in the professional services industry said their companies had experienced a fraud incident in the past year, up five percentage points from the previous year. A similar number (87%) reported a cyber incident and 65% reported security incidents in the same time period.

Information theft, loss, or attack was the most prevalent type of fraud experienced in the professional services sector, cited by 33% of respondents, followed by internal financial fraud (29%).

Nearly four in 10 (38%) executives surveyed said their companies had been impacted by a virus or worm attack. Physical theft or loss of intellectual property was by far the most prevalent type of security incident (38%), while ex-employees were the main culprits of cyber (33%) and security (36%) incidents experienced by executives in the professional services sector.

In the financial services sector, 91% of respondents reported incidents of fraud this year, the highest percentage reported by any sector, and two percentage point higher than last year’s number (89%) and significantly higher than this year’s global average (84%).

Respondents in the financial services sector said that management conflict of interest (27%) and information theft, loss, or attack (27%) were the main types of fraud experienced. Ex-employees (39%) were cited as the main perpetrators of fraud, followed by junior employees (33%) and vendors/suppliers (33%). Over half of these instances of fraud were detected through an internal audit (53%).

Separately, a freedom of information request to the Financial Conduct Authority (FCA) from RSM has shown that reported data hacking attacks against financial services companies have quadrupled in the last year, up from four in 2016 to 17 in 2017. There were also two separate incidents of ‘data leakage’ reported to the FCA.

The figures also show a rise in the number of incidents of financial loss resulting from malware infection. In total, there were four reported cases in 2017, up from just one in the previous year.

During 2017, the retail banking sector suffered the highest number of reported attacks (17), followed by retail lenders (16) and investment management firms (16). There were a further 11 incidents reported to the FCA by insurance firms.

Steve Snaith, technology risk assurance partner at RSM said: ‘We have previously raised concerns that there is likely to be significant under-reporting of cyber-attacks by regulated financial services firms. Nevertheless, these new numbers do reveal some important trends.

‘The jump in incidents of data loss resulting from hacking attacks should be particularly concerning to the financial services sector, given we are just months away from the new GDPR regime coming into force.’

Report by Pat Sweet

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

0
Be the first to vote

Rate this article

Related Articles
Subscribe