
This six page White Paper, which I wrote for financial sector secure communication specialist Salt Communications, explores the increasingly critical realm of secure communication within the financial sector, laying out both the challenges and necessities that modern financial institutions face against the backdrop of a digital-first world. This is a highly specific niche, and I’ve written the paper in a way that assumes a high degree of familiarity with the issues on the part of the reader. Specialist White Paper for financial sector secure communication specialist Salt Communications.

*Thumbnails of some older projects were uploaded at resolutions which may now appear out of focus.
DANGEROUS TALK
Non-secure and non-compliant internal communications in financial institution management.
A White Paper from Salt Communications
Executive Summary
This paper explores the increasingly critical realm of secure communication within the financial sector, laying out both the challenges and necessities that modern financial institutions face against the backdrop of a digital-first world.
At its core, the paper seeks to illuminate the key objective: an imperative need for robust, secure communication solutions that can safeguard sensitive discussions and information against the threat or actuality of breaches, ensuring operational continuity and regulatory compliance.
The financial landscape is fraught with potential vulnerabilities, from cyber threats to regulatory penalties, heightening the critical need for institutions to have in place a communication solution that is not only resilient in the face of attacks but also adaptable to the evolving regulatory environment. This necessity is underscored by recent high-profile breaches, regulatory changes, and the global push towards digital transformation, all of which compound the risks associated with non-secure communication.
Within this context, the paper touches on an innovative ‘safe haven network’ solution designed to meet the unique needs of the financial sector. This solution addresses the identified gaps in existing communication platforms, offering end-to-end encrypted messaging, voice calls, and file transfers, all within a framework that prioritises security, compliance, and operational efficiency.
While avoiding specifics or engaging in sales presentation, the paper sets the stage for discussions on how such a solution can serve as a linchpin in the strategy of financial institutions to protect their data, maintain their reputation, and comply with stringent regulatory standards.
-
Communications security in financial institutions.
In the financial sector, secure communication at management level is not just a matter of confidentiality; it’s a cornerstone of good governance and integrity, critical to the smooth operation of global markets. Recent years have seen a surge in cyber threats, ranging from sophisticated phishing scams to advanced persistent threats, all aiming to exploit vulnerabilities within modern enterprise networks. These challenges are not confined by geography but are global in nature, reflecting the interconnectedness of the financial system. Compounded by the shift towards remote work, the security of digital communications has never been more paramount.
Regulatory bodies across different territories have responded by tightening the requirements for communication security. For instance, the European Union’s GDPR and the United States’ SEC regulations mandate strict data protection and privacy measures, including how financial institutions communicate internally and with clients. These regulations require encryption, data handling, and user authentication to prevent unauthorised access. This necessitates financial institutions adopting secure messaging solutions that not only comply with these regulations but also provide a robust defence against the evolving landscape of cyber threats. As financial institutions navigate this complex regulatory environment, the importance of implementing a secure, compliant platform for internal communication amongst management cannot be overstated. It is essential not only for safeguarding sensitive information, but also for maintaining the trust of clients, and the integrity of the financial system at large, should a security crisis arise.
-
The risk constituted by the use of consumer-grade messaging apps for internal communications.
In crisis situations in particular, the use of consumer grade messaging applications, such as WhatsApp, for internal discussion by management teams in financial institutions introduces unacceptable vulnerabilities, and leaves sensitive communications exposed to potential interception and misuse. Such platforms are simply not intended to provide the security required for intercommunication between the members of a management team and other key stakeholders operating under such a threat.
In addition to the potential consequences of any such security vulnerability in being able to deal with, or fend off, an attack, the potential legal and financial implications surrounding the misuse of consumer messaging platforms in this way are significant, including as they do the possibility of regulatory fines and legal actions, as well as reputational damage.
JPMorgan, for example, was hit with $200 million in fines in December 2021 by the SEC and CFTC for letting employees use personal devices to send texts, WhatsApp messages and emails about company business. (Even the managers and senior personnel responsible for compliance had used personal devices to communicate sensitive business information.)
Since 2021, the SEC has hit dozens of firms, including big banks such as JPMorgan Chase and Wells Fargo, with fines of $1.7 billion over such compliance failures.
“The SEC’s investigations uncovered pervasive and longstanding uses of unapproved communication methods, known as off-channel communications,” the SEC said in a statement.
How an organisation reacts to a security breach, or the threat of such a breach, is critical. Being able to speak to senior executives, advisors and cyber experts using a pre-prepared, robust and regulatory compliant comms system is critical to effective incident response.
/contd
On mobile? Use the Category links below to return to the thumbnails page you were browsing.