FS firms’ sites still insecure a year after GDPR

Almost a year after the General Data Protection Regulation (GDPR) came into effect, RiskIQ has discovered that 1 in 10 personally identifiable information (PII) capturing websites belonging to the large UK financial services firms are running without adequate security measures.

While this is down from the 27 per cent of sites identified a year ago, it is still in breach of the regulations.

Across 48,949 active websites, RiskIQ research found that out of 4,512 sites capturing PII through data entry points accessible by site visitors, with 11.5 per cent of these sites (522 sites) capturing PII insecurely.

A PII capturing website is one which accepts user input that can identify an individual. Examples of input data are name, address, date of birth, email address and login credentials. In addition to web pages with data entry fields, the research also extended to pages with pop-up windows that populate during a browser session and accept data.

The analysis found that out of 3,940 public websites with a login page, 442 of these sites - 11 per cent - capture login information insecurely. Out of 572 sites capturing PII through data entry fields accessible by site visitors, 80 of these sites - 14 per cent - are capturing personal information insecurely.

Insecure sites are defined as those websites that capture data in clear text using the HTTP protocol or sites with certificate issues, such as expired certificates, misconfigured certificates or using old and untrusted certificates.

The findings highlight one of the key challenges businesses face in the protection of PII, as required by GDPR.

“This research shows that organisations are continuing to make progress in ensuring that personal data entered online is collected in a secure manner,” said Fabian Libeau, EMEA vice president at RiskIQ.

“However, that we still see instances serves to highlight that there is more to be done – most organisations are continuing to expand their web presence and it's vitally important that they maintain a complete inventory of those sites and the PII collecting pages they contain.”

    Share Story:

Recent Stories


FREE E-NEWS SIGN UP

Subscribe to our newsletter to receive breaking news and other industry announcements by email.

  Please tick here to confirm you are happy to receive third party promotions from carefully selected partners.


The new episode of The Mortgage Insider podcast, out now
Regional housing markets now matter more than ever. While London and the Southeast still tend to dominate the headlines from a house price and affordability perspective, much of the growth in rental yields and buyer demand is coming from other parts of the UK.

In this episode of the Barclays Mortgage Insider Podcast, host Phil Spencer is joined by Lucian Cook, Head of Research at Savills, and Ross Jones, founder of Home Financial and Evolve Commercial Finance.

Air and the role of later-life lending
Content editor at MoneyAge, Dan McGrath, spoke to the chief executive officer at Air, Will Hale, about the later-life lending industry, the importance of tailored advice and how technology and obligations have shaped the sector.


Helping the credit challenged get mortgage ready
A rising number of borrowers are finding it harder to access mortgages due to being credit challenged - whether that’s from historic debts, a county court judgment, or having little to no credit history.

In the latest episode of the Mortgage Insider podcast, Phil Spencer is joined by Eloise Hall, Head of National Accounts at Kensington Mortgages, and Alastair Douglas, CEO of TotallyMoney.

The future of the bridging industry and the Autumn Budget
MoneyAge content editor, Dan McGrath, is joined by head of marketing at Black & White Bridging, Matt Horton, to discuss the bridging industry, the impact of the Autumn Budget and what the future holds for the sector.