Problem : Although IT security frameworks and solutions are available, banking and financial organizations encounter challenges in accepting security technology to secure the organization and its third-parties. Purpose : The purpose of the study is to explore implementation strategies for banking and financial IT third-party security solutions to determine impediments to full acceptance of available security tools related to access control and data protection. Method : The technique selected for this project is qualitative inquiry. Population : The project question was explored via interviews. The researcher used purposeful and convenience sampling methods to identify participants who work within the banking and financial services industry in the United States. Results : The researcher conducted a thematic analysis using the UTAUT framework applied to access controls, and data protection was completed during the review. The themes identified included the key factors for increasing the acceptance of security solutions for banking and financial services organizations and related third-parties for access controls and data protection: assessments, executive sponsorship, oversight of the implementation, requirements management, sufficient planning, and testing of technical solutions. Implications/Practica l Uses : This project’s recommendations include assessments for third-parties, training, and scoping requirements. The researcher may propose increased communication, assessment methodologies, and tools for protecting data, services, and third-parties.
KeywordsBankingFinancial ServicesInformation SecurityAccess ControlsData ProtectionAPIsApplication Program InterfacesWeb Application SecurityThird-PartySupplierVendor
AbuShanab, E., & Pearson, J. M. (2007). Internet Banking in Jordan: The Unified Theory of Acceptance and Use of Technology (UTAUT) Perspective. Journal of Systems and Information Technology, 9, 78-97. https://doi.org/10.1108/13287260710817700
Akdag, Y. (2017). Cyber Deterrence against Cyberwar between the United States and China: A Power Transition Theory Perspective (Order No. 10640499). ProQuest Central.
Alsowail, R. A., & Al-Shehari, T. (2022). Techniques and Countermeasures for Preventing Insider Threats. PeerJ Computer Science . https://doi.org/10.7717/peerj-cs.938
Anak Agung Bagus, A. W., & Gusti Made, A. S. (2019). IT Risk Management Based on ISO 31000 and OWASP Framework Using OSINT at the Information Gathering Stage (Generic Qualitative Inquiry: X Company). International Journal of Computer Network and Information Security , 11, 17-29. https://doi.org/10.5815/ijcnis.2019.12.03
Ashraf, S. A., Wu, S. L., Fon, S. O., & Deng, R. (2021). The Mediating Influence of the Unified Theory of Acceptance and Use of Technology on the Relationship between Internal Health Locus of Control and Mobile Health Adoption: Cross-Sectional Study. Journal of Medical Internet Research , 23, e28086. https://doi.org/10.2196/28086
Barrett, B., & Newman, L. (2018). The Facebook Security Meltdown Exposes Way More Sites than Facebook . Wired. https://www.wired.com/story/facebook-security-breach-third-party-sites/
Boggavarapu, S. (2021). The Effect of Third-Party Service Providers on Information Security Breaches at Financial Institutions . Master’s Thesis, University of the Cumberlands.
Bronson, H. E. (2022). Five Common Shortcomings of Third-Party Management Programs in Financial Organizations and Recommended Risk Management Strategies . Master’s Thesis, Utica University.
Bryant, L. (2016). Cybersecurity Regulations: Banking and Third-Party Providers (Order No. 10109630). ProQuest Central.
Buker, H. N. (2021). Financial Institutions Adapting to Cybersecurity Regulation Modifications: A Qualitative Multiple-Case Study (Order No. 28722239). ProQuest Central.
Burton, J. (2018). Cyber Deterrence: A Comprehensive Approach? https://ccdcoe.org/uploads/2018/10/BURTON_Cyber_Deterrence_paper_April2018.pdf
Chitreddy, K., Anthony, A., Bandaru, C., & Abiona, O. (2024). Information Security in the Cloud: Emerging Trends and Challenges. International Journal of Communications, Network and System Sciences, 17, 69-80. https://doi.org/10.4236/ijcns.2024.175005
Security Assessments
Cleary, S., & McLarney, C. (2019). Organizational Benefits of an Effective Vendor Management Strategy. IUP Journal of Supply Chain Management, 16, 50-67.
Colnago, J., Devlin, S., Oates, M., Swoopes, C., Bauer, L., Cranor, L., & Christin, N. (2018). It’s Not Actually That Horrible: Exploring Adoption of Two-Factor Authentication at a University. In CHI ’ 18: Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems (pp. 1-11). Association for Computing Machinery. https://doi.org/10.1145/3173574.3174030
Cotton, W. G. (2022). Best Practices to Improve Big Health Care Data Project Success in the US . Master’s Thesis, Capella University.
Crosman, P. (2017). Scottrade Bank ’ s Breach Underlines Third-Party Vendor Risk. American Banker.
DeFleice, M. O. (2022). Prevention and Mitigation against Cyberattacks: Bare Minimum (Order No. 28869362). ProQuest Central.
Demetriou, S., Zhou, X. Y., Naveed, M., Lee, Y., Yuan, K., Wang, X., & Gunter, C. A. (2015). What ’ s in Your Dongle and Bank Account? Mandatory and Discretionary Protection of Android External Resources. NDSS. https://doi.org/10.14722/ndss.2015.23098
Dhillon, G., Syed, R., & de Sá-Soares, F. (2017). Information Security Concerns in IT Outsourcing: Identifying (in) Congruence between Clients and Vendors. Information & Management, 54, 452-464. https://doi.org/10.1016/j.im.2016.10.002
Elzamly, A., Hussin, B., Abu-Naser, S. S., Shibutani, T., & Doheir, M. (2017). Predicting Critical Cloud Computing Security Issues Using Artificial Neural Network (ANNs) Algorithms in Banking Organizations.
Fielding, J. (2020). The People Problem: How Cyber Security’s Weakest Link Can Become a Formidable Asset. Computer Fraud & Security , 2020, 6-9. https://doi.org/10.1016/S1361-3723(20)30006-3
Fujimori, R., Liu, K., Soeno, S., Naraba, H., Ogura, K., Hara, K., Sonoo, T., Ogura, T., Nakamura, K., & Goto, T. (2022). Acceptance, Barriers, and Facilitators to Implementing Artificial Intelligence-Based Decision Support Systems in Emergency Departments: Quantitative and Qualitative Evaluation. JMIR Formative Research, 6 , e36501. https://doi.org/10.2196/36501
Ghelani, D., Hua, T. K., & Koduru, S. K. R. (2022). A Model-Driven Approach for Online Banking Application Using AngularJS Framework. American Journal of Information Science and Technology, 6, 52-63.
Harrison, S., & Jürjens, J. (2017). Information Security Management and the Human Aspect in Organizations. Information and Computer Security, 25, 494-534. https://doi.org/10.1108/ICS-07-2016-0054
Kellezi, D., Boegelund, C., & Meng, W. (2021). Securing Open Banking with Model-View-Controller Architecture and OWASP. Wireless Communications & Mobile Computing (Online), 2021, Article ID 8028073. https://doi.org/10.1155/2021/8028073
Knudson, J. (2021). Top Bank Risks for 2021. American Bankers Association.
Kolpakova, G., & Evdokimova, I. (2017). The Financial Mechanism of Management as a Way of Organizing Financial Services and Financial Values. Varazdin Development and Entrepreneurship Agency (VADEA).
Krell, E. (2022). Payments Trends: Faster, Larger, and More Secure. Treasury & Risk.
Legowo, M. B., Subanidja, S., & Sorongan, F. A. (2020). A Conceptual Framework of Technological Innovation for the Financial and Banking Industry in Indonesia. International Journal of Information, Business and Management, 12, 100-114.
Leung, R. (2018). Cybersecurity Regulation in the Banking Sector: Global Emerging Themes . Master’s Thesis, The London School of Economics and Political Science.
Levtsov, V. (2017). Cyberattacks Cost Financial Institutions US$1M Per Attack. SMB World Asia (Online).
Li, Y. (2022). A Framework for Secure Online Bank System and Cloud Architecture. Journal of Internet Banking and Commerce, 27, 1-3.
Lusher, T. (2018). Present and Future Solutions for the Lack of Cybersecurity Professionals (Order No. 10791221). ProQuest Dissertations & Theses Global.
Ly, L. T., Maggi, F. M., Montali, M., Rinderle-Ma, S., & van der Aalst, M. P. (2015). Compliance Monitoring in Business Processes: Functionalities, Application, and Toolsupport. Information Systems, 54, 209-234. https://doi.org/10.1016/j.is.2015.02.007
Malik, M. (2020). Elements Influencing the Adoption of Electronic Banking in Pakistan an Investigation Carried Out by Using Unified Theory of Acceptance and Use Technology (UTAUT) Theory. Journal of Internet Banking and Commerce, 25, 1-18.
Mayur, S. (2018). Govt to Banks: Speed Up Cards with NFC Tech [Times Business]: Secur ity Concerns Delay Pay Channel ’ s Adoption. The Times of India.
McGinnis, J. O. (2020). Bitcoin’s Nature and Its Future. Harvard Journal of Law and Public Policy, 43, 59-66.
Mest, E. (2019). Financing Marriott Ends 2018 Ahead despite Data Breach, Strikes . http://hdl.handle.net/10919/89076
Mohsen, F. (2016). Exploring Varied Approaches for Countering the Privacy and Security Risks of Third-Party Mobile Applications. ProQuest Dissertations Publishing.
Naylor, L. (2016). Trading Fraud Liability for National Security: A Proposal to Amend the False Claims Act for Cybersecurity Contractors. Public Contract Law Journal, 45, 677-693.
News Bites (2020). BearingPoint Generic Qualitative Inquiry: Hero Prepares for the Future with Digitally Harmonized Supply Chain. News Bites—Private Companies.
Noble, S. M., Saville, J. D., & Foster, L. L. (2022). VR as a Choice: What Drives Learners’ Technology Acceptance? International Journal of Educational Technology in Higher Education, 19 , Article No. 6. https://doi.org/10.1186/s41239-021-00310-w
Nunes, N., Adamo, G., Ribeiro, M., Gouveia, B. R., Elvio, R. G., Teixeira, P., & Nisi, V. (2022). Modeling Adoption, Security, and Privacy of COVID-19 Apps: Findings and Recommendations from an Empirical Study Using the Unified Theory of Acceptance and Use of Technology. JMIR Human Factors, 9 , e35434. https://doi.org/10.2196/35434
O’Rourke, K. (2022). Banks Must Respond to Digital Threats after Pandora’s Box Moment. FT.Com.
Ogudebe, O. I. (2022). Challenges of Digital Privacy in Banking Organizations (Order No. 29258011). ProQuest Central, ProQuest Central, ProQuest Dissertations & Theses Global.
PCI (2022). Payment Card Industry (PCI) Data Security Standard Requirements and Security Assessment Procedures Version 3.2.1 https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf?agreement=true&time=1612157094225
Pennic, F. (2022). Most Healthcare Facilities Lack Holistic Digital Identity Strategy, Report Finds. Newstex.
Peters, A. (2015). Faulty Access Controls Led to Morgan Stanley Data Breach: FTC. Financial Planning (Online).
Plachkinova, M. (2018). Teaching Case: Security Breach at Target. Journal of Information Systems Education, 29 , 11-20.
Pomerleau, P. (2019). Countering the Cyber Threats Against Financial Institutions in Canada: A Qualitative Study of a Private and Public Partnership Approach to Critical Infrastructure Protection (Order No. 27540959). ProQuest Central (2320957957).
Qazi, F. A. (2022). Insecure Application Programming Interfaces (APIs) in Zero-Trust Networks (Order No. 28966153). ProQuest Central (2638299306).
Savage, B. A. (2017). A Qualitative Exploration of the Security Practices of Registered Nurses . Master’s Thesis, Walden University.
Scott, C. R. (2022). Comparing Cybercrime in Banking and Healthcare Sectors (Order No. 29206127). ProQuest Dissertations & Theses Global.
Sfoglia, P. (2019). N.Y. Cyber Reg: A Third-Party Service Provider Compliance Framework. ProQuest Dissertations Publishing.
Sloboda, L. Y., & Demianyk, O. M. (2020). Prospects and Risks of the Fintech Initiatives in a Global Banking Industry. Problemy Ekonomiky , 1, 275-282. https://doi.org/10.32983/2222-0712-2020-1-275-282
Stoppok, P., Teufel, M., Jahre, L., Rometsch, C., Müßgens, D., Bingel, U., Skoda, E., & Bäuerle, A. (2022). Determining the Influencing Factors on Acceptance of eHealth Pain Management Interventions among Patients with Chronic Pain Using the Unified Theory of Acceptance and Use of Technology: Cross-Sectional Study. JMIR Formative Research, 6 , e37682. https://doi.org/10.2196/37682
Tanoh, C. N. (2022). Effectiveness of Information Security Governance in the U.S. Banking Industry: Towards a Resilient Business Perspective (Order No. 29160858). Dissertations & Theses @ Capella University; ProQuest Dissertations & Theses Global.
Tarlow, P. (2019). The Human Side of Cyber Security Breaches. International Journal of Safety and Security in Tourism and Hospitality, No. 20, 1-4.
Thomson, L. (2018). Third-Party Vendors Can Be a Weak Link: ABA Vendor Contracting Cybersecurity Checklist Focuses on the Procurement Process to Strengthen Security Protections. Sci T ech Lawyer, 14, 36-37.
Tissera, M., Thelijjagoda, S., & Goonathilake, J. (2017). User-Centric Privacy Preservation Solution to Control Third-Party Access in Digital Databases. International Journal of Advances in Engineering & Technology, 10, 30-45.
Turunen, M., & Kari, M. J. (2020). Cyber Deterrence and Russia ’ s Active Cyber Defense. Academic Conferences International Limited.
Ula, M., Ismail, Z., & Sidek, Z. M. (2011). A Framework for the Governance of Information Security in Banking System. Journal of Information Assurance & Cybersecurity , 2011 , Article ID: 726196. http://www.ibimapublishing.com/journals/JIACS/jiacs.html https://doi.org/10.5171/2011.726196
Unigwe, O. P. (2021). Exploring Risk Management Strategies for Transitioning to Cloud within Financial Services Industry: A Grounded Theory Study (Order No. 29395857). ProQuest Central.
Varma, P., Nijjer, S., Sood, K., Grima, S., & Rupeika-Apoga, R. (2022). Thematic Analysis of Financial Technology (Fintech) Influence on the Banking Industry. Risks, 10, Article 186. https://doi.org/10.3390/risks10100186
Weinstock, D. (2014). Is Your Practice at Risk for Medical Identity Theft? The Journal of Medical Practice Management: MPM, 30, 168-170.
Wewege, L., Lee, J., & Thomsett, M. C. (2020). Disruptions and Digital Banking Trends. Journal of Applied Finance and Banking, 10, 15-56.
Williams, R. T. (2021). Banking and Cybersecurity Governance . Master’s Thesis, Utica College.
Yee Yen, Y. (2011). User Acceptance of Internet Banking Services: A Comparative Study (Order No. 3498184). ProQuest Central.