What We Do
How we do it
Resources
SECURITY ADVISORIES
May 11, 2022
CVE-2022-26923 - Active Directory Domain Services Elevation of Privilege Vulnerability
THE THREAT Microsoft has disclosed a new vulnerability impacting Active Directory Certificate Services (ADCS) tracked as CVE-2022-26923 (Active Directory Domain Services Elevation of Privilege Vulnerability). If exploited successfully, an authenticated attacker can escalate privileges in environments where ADCS is running on the domain. eSentire is aware of technical details and tooling [2] for…
Read More
View all Advisories →
Company
ABOUT ESENTIRE
About Us
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 1200+ organizations in 75+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
Read about how we got here
Leadership Work at eSentire
LATEST PRESS RELEASE
May 17, 2022
Cybersecurity Leader eSentire Continues Its Commitment to Rigorous Security Standards Earning PCI DSS Certification
Waterloo, ON, May 17, 2022 — eSentire, the Authority in Managed Detection and Response (MDR), maintains one of the most secure and robust IT environments of any MDR provider in the industry. To that end, eSentire today announced that it has received the Payment Card Industry Data Security Standard (PCI DSS) certification, considered one of the most stringent and comprehensive payment card…
Read More
Partners
PARTNER PROGRAM
e3 Ecosystem
We provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
Learn more
ECOSYSTEM PARTNER RESOURCES
Apply to become an e3 ecosystem partner with eSentire, the Authority in Managed Detection and Response.
Login to the Partner Portal for resources and content for current partners.
Search
Resources
Blog — May 22, 2018

Building Societies are at risk

Speak With A Security Expert Now

Building societies offer banking, savings and mortgage lending, and other financial services, all of which makes them privy to their clients’ financial accounts and personal information. As a result, cybercriminals are targeting building societies for this data, as well as trade secrets and other information that could be used to their advantage.

Unfortunately—as it stands—many building societies have limited resources and so are resorting to using automated defences to catch threats, which is leaving them exposed. The risk of cyber-attacks has put operational resilience (including cyber resilience) on the priority list of regulators.

“It is no longer just about cybersecurity and building those security walls around your business even higher. It is also about considering different aspects of how the risk actually manifests today…Some of the biggest challenges come from old legacy systems and the integration of acquisitions.”[1]

The potential effects of a breach include:

“Traditional cyber security strategies, such as firewalls and intrusion detection systems, are no longer enough to prevent determined threat actors.”- PRA Cyber Resilience Questionnaire

Threats targeting Building Societies

According to eSentire Threat Intelligence, common attack methods used against the finance industry include:

These methods can cause serious business disruptions and extensive costs if not detected and responded to quickly.

Cybersecurity compliance requirements

Cyber-attacks aren’t the only thing building societies need to be thinking about. Your organisation will be required to comply with the Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) cybersecurity guidance and/or requirements. In fact, the PRA recently created a cybersecurity questionnaire that will be used to assess a firm’s cyber resilience and their ability to detect, respond and recover from cyber-attacks.

Furthermore, with the General Data Protection Regulation (GDPR) coming into affect in May 2018, there will be greater accountability surrounding security policies and specific data breach notification obligations.

In other words, compliance regulations matter more than they ever have, and businesses needs to be prepared to meet increasing requirements.

The faster the firm catches the threat, the lower the impact

Breaches can have a significant impact on your business and customers. Recent attacks on building societies have resulted in clients’ personal information being compromised[2] and confidential emails being leaked.[3]

Fortunately, the next victim doesn’t have to be you. According to Aberdeen’s Monte Carlo analysis, being twice as fast at threat detection and incident response lowers the business impact of a cyber-attack by approximately 70%.[4]. The only way to avoid an incident and react quickly is to have a certified Security Operations Centre (SOC) with human analysts hunting and responding to threats on your network 24x7x365.

We defend against the threats facing building societies

eSentire Managed Detection and Response™ (MDR) keeps building societies safe from cyber-attacks that other technologies miss. Our 24x7 Security Operations Centres (SOC) are staffed by elite security analysts who hunt, investigate and respond to known and unknown threats in real time. With MDR, you’ll experience:

We prepare building societies for complex compliance and regulatory requirements

Beyond MDR, our dedicated security experts help firms assess risks, address known gaps and build a comprehensive cybersecurity program that meets stringent regulatory requirements. With eSentire Advisory Services, you’ll have access to:

Security Program Maturity Assessments

About eSentire

eSentire is the largest pure-play Managed Detection and Response (MDR) service provider, keeping organisations safe from constantly evolving cyber-attacks that technology alone cannot prevent. Its 24x7 Security Operations Centre (SOC), staffed by elite security analysts, hunts, investigates, and responds in real-time to known and unknown threats before they become business-disrupting events. Protecting more than £4 trillion in corporate assets, eSentire absorbs the complexity of cybersecurity, delivering enterprise grade protection and the ability to comply with growing regulatory requirements. For more information, visit www.eSentire.com and follow @eSentire.



View Most Recent Blogs
eSentire
eSentire

eSentire is the Authority in Managed Detection and Response, protecting the critical data and applications of 1200+ organizations in 75+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events. Combining cutting-edge machine learning XDR technology, 24/7 Threat Hunting, and proven security operations leadership, eSentire mitigates business risk, and enables security at scale. The Team eSentire difference means enterprises are protected by the best in the business with a named Cyber Risk Advisor, 24/7 access to SOC Cyber Analysts & Elite Threat Hunters, and industry-leading threat intelligence research from eSentire’s Threat Response Unit (TRU). eSentire provides Managed Risk, Managed Detection and Response and Incident Response services. For more information, visit www.esentire.com and follow @eSentire.