X
  • About
  • Advertise
  • Contact
  • Expert Resources
Get the latest news! Subscribe to the Money Management bulletin
  • News
    • Accounting
    • Financial Planning
    • Funds Management
    • Life/Risk
    • People & Products
    • Policy & Regulation
    • Property
    • SMSF
    • Superannuation
    • Tech
  • Investment
    • Australian Equities
    • Global Equities
    • Managed Accounts
    • Fixed Income
    • ETFs
  • Features
    • Editorial
    • Expert Analysis
    • Guides
    • Outsider
    • Rate The Raters
    • Top 100
  • Media
    • Events
    • Podcast
    • Webcasts
  • Promoted Content
  • Investment Centre
No Results
View All Results
  • News
    • Accounting
    • Financial Planning
    • Funds Management
    • Life/Risk
    • People & Products
    • Policy & Regulation
    • Property
    • SMSF
    • Superannuation
    • Tech
  • Investment
    • Australian Equities
    • Global Equities
    • Managed Accounts
    • Fixed Income
    • ETFs
  • Features
    • Editorial
    • Expert Analysis
    • Guides
    • Outsider
    • Rate The Raters
    • Top 100
  • Media
    • Events
    • Podcast
    • Webcasts
  • Promoted Content
  • Investment Centre
No Results
View All Results
No Results
View All Results
Home Expert Analysis

Protecting data in a remote working environment

Institutional investors need to be on high alert as COVID-19 has triggered a wave of significant cyber attacks and data breaches, writes George Takesian.

by Industry Expert
October 16, 2020
in Expert Analysis
Reading Time: 5 mins read
Share on FacebookShare on Twitter

By October 2020, Australia has already tirelessly battled not only horrific bushfires but a global pandemic too. While these events have drastically impacted the everyday life of Australians and businesses, at the same time, we have seen a spike in cyber attacks which can affect anyone, particularly the vulnerable and distracted. 

The Australian Department of Foreign Affairs and Trade and the Australian Cyber Security Centre have come together to denounce these cyber attackers who are “seeking to exploit the pandemic for their own gain”. In particular, the recent attacks have highlighted data vulnerabilities for investors. It goes to show that the saying ‘never let your guard down’ remains relevant – especially in a crisis. 

X

RISKS FOR INVESTMENT MANAGERS AND SUPER FUNDS

According to NTT’s 2020 ‘Global Threat Intelligence Report’, in Australia, financial services was the third-most targeted industry with 13% of cyber attacks. Since the COVID-19 pandemic began, we have seen a further increase in cyber attacks in the industry; resulting in attempted, and actualised, incidents of fraud and data breaches. Scammers are targeting not only the large players in the market (i.e. the big four banks) as they have in the past, but are now targeting smaller organisations, including boutique investment management firms and small superannuation funds. Some of the most worrying trends for the investment management and super fund industry include:

Spear phishing 

Spear phishing attacks are fraudulent emails targeted at a specific individual, organisation or business. GreatHorn’s ‘2020 Phishing Attack Survey’ found that US organisations are remediating on average nearly 2,000 phishing attacks every month, with more than half of all respondents saying their enterprise has seen an increase in phishing attacks through email since the start of the pandemic. While most of these have been, and remain, laughable due to the spelling inaccuracies and the ludicrousness of the requests, spear phishing attempts have become significantly more sophisticated in the last year.

Recently we have seen multiple instances of scammers, who clearly have knowledge of how the industry works, targeting organisations through their third parties. They often pose as a member of the finance or accounting team at an investment manager or super fund, and target the appointed fund administrator or custodian to gain information regarding the organisation’s bank accounts. 

The scammers often know details about these third-party relationships. This can happen when a corporate email account has been compromised (which is also increasing in frequency) but generally, it should be noted that information regarding third-party fund administrators and custodians can usually be found publicly online.

Manipulation of instructions sent via email

The most troubling trend we are seeing is the interception and manipulation of emailed instructions. As with spear phishing, the most-successful attempts have been between investment managers and super funds and their third parties. 

Recent incidents include manipulated cash payment instructions (such as for settlements of collateral movements), application and redemption requests, and capital call and distribution notices. This has involved scammers intercepting emails between organisations, changing just the bank account details, and then sending on the email with a near-identical email address and with the original recipient’s name displaying. 

This has been observed across multiple asset classes, for instance, attempted fraudulent $100+ million capital calls for direct infrastructure assets, and in relation to lesser settlement and redemption request for equities and fixed income funds and mandates. 

WHAT CAN BE DONE TO MITIGATE THE RISK?

No organisation, regardless of size, has unlimited resources – and the increasing sophistication of cyber attacks means that no organisation can be 100% secure. Unfortunately, data breaches present enormous financial and reputational risk for businesses. A few of the baseline steps that organisations should take to help protect themselves include: 

Conduct an IT security risk assessment – Performing an IT risk assessment helps to identify key assets and corresponding vulnerabilities and threats. There are a number of external IT security consultants in Australia who can assist, and there are also great resources online (such as NIST-based risk assessment templates).

Use secure transfer protocols – Secure web portals or SFTP are recommended, but if sending confidential data via email attachments, then attachments should be encrypted. While not nearly as secure, it will at least create an extra hurdle for scammers.

Employ multi-factor authentication (MFA) – Not only for remote access to the network but also to key applications hosted externally and mobile email. Many of the instances we have seen where email accounts have been compromised are where MFA is not employed for email accessible on mobile phones.

Conduct penetration testing – Penetration testing can help to identify exploitable vulnerabilities, including for online web portals, applications and networks which may contain proprietary and confidential client data.  

Deliver comprehensive staff cyber security training – Employees are an organisation’s greatest line of defence, but can also be their greatest weakness. All the controls in the world will not prevent data breaches if employees are not aware of threats. Research from KnowBe4 found that when organisations implemented phishing testing and subsequent training, within 90 days employees that clicked a simulated phishing email link or opened an infected attachment during a testing campaign was cut in half from 37% to 14%. 

Perform adequate due diligence on third parties – While onsite due diligence is difficult in the current environment, in-depth due diligence should be performed on key third parties annually and should include a review of data security measures.

The recent increase in attempted cyber attacks have highlighted security vulnerabilities for the financial services industry, heightened by the ongoing remote working environment. Particularly, with the greater sophistication of these attempted cyber attacks and our growing dependence on digital tools, the likelihood of serious data breaches occurring has never been greater – or the consequences never more costly. 

No organisation can be 100% secure from a cyber attack; however, implementing proactive and robust practices such as these may help minimise the potential risk of cyber attacks. 

George Takesian is principal at Mercer.

Tags: Covid-19Cyber Security

Related Posts

Shifting views on portfolio construction

by Industry Expert
October 28, 2025

As the industry shifts from client-centric to consumer-centric portfolios, this personalisation is likely to align portfolios with investors’ goals, increasingly...

Foreign currency board

Share-class hedging may not offer best-in-class hedging

by Industry Expert
September 24, 2025

Managing currency risk in an international portfolio can both reduce the volatility, as well as improve overall returns, but needs...

How ETF model portfolios are reshaping practice efficiency

by Industry Expert
September 9, 2025

In today’s evolving financial landscape, advisers are under increasing pressure to deliver more value to clients, to be faster, smarter,...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Consistency is the most underrated investment strategy.

In financial markets, excitement drives headlines. Equity markets rise, fall, and recover — creating stories that capture attention. Yet sustainable...

by Industry Expert
November 5, 2025
Promoted Content

Jonathan Belz – Redefining APAC Access to US Private Assets

Winner of Executive of the Year – Funds Management 2025After years at Goldman Sachs and Credit Suisse, Jonathan Belz founded...

by Staff Writer
September 11, 2025
Promoted Content

Real-Time Settlement Efficiency in Modern Crypto Wealth Management

Cryptocurrency liquidity has become a cornerstone of sophisticated wealth management strategies, with real-time settlement capabilities revolutionizing traditional investment approaches. The...

by PartnerArticle
September 4, 2025
Editorial

Relative Return: How fixed income got its defensiveness back

In this episode of Relative Return, host Laura Dew chats with Roy Keenan, co-head of fixed income at Yarra Capital...

by Laura Dew
September 4, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Podcasts

Relative Return Insider: RBA holds, Fed cuts and Santa’s set to rally

December 11, 2025

Relative Return Insider: GDP rebounds and housing squeeze getting worse

December 5, 2025

Relative Return Insider: US shares rebound, CPI spikes and super investment

November 28, 2025

Relative Return Insider: Economic shifts, political crossroads, and the digital future

November 14, 2025

Relative Return: Helping Australians retire with confidence

November 11, 2025

Relative Return Insider: RBA holds rates steady amid inflation concerns

November 6, 2025

Top Performing Funds

FIXED INT - AUSTRALIA/GLOBAL BOND
Fund name
3 y p.a(%)
1
DomaCom DFS Mortgage
211.38
2
Loftus Peak Global Disruption Fund Hedged
110.90
3
SGH Income Trust Dis AUD
80.01
4
Global X 21Shares Bitcoin ETF
76.11
5
Smarter Money Long-Short Credit Investor USD
67.63
Money Management provides accurate, informative and insightful editorial coverage of the Australian financial services market, with topics including taxation, managed funds, property investments, shares, risk insurance, master trusts, superannuation, margin lending, financial planning, portfolio construction, and investment strategies.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • Financial Planning
  • Funds Management
  • Investment Insights
  • ETFs
  • People & Products
  • Policy & Regulation
  • Superannuation

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
    • All News
    • Accounting
    • Financial Planning
    • Funds Management
    • Life/Risk
    • People & Products
    • Policy & Regulation
    • Property
    • SMSF
    • Superannuation
    • Tech
  • Investment
    • All Investment
    • Australian Equities
    • ETFs
    • Fixed Income
    • Global Equities
    • Managed Accounts
  • Features
    • All Features
    • Editorial
    • Expert Analysis
    • Guides
    • Outsider
    • Rate The Raters
    • Top 100
  • Media
    • Events
    • Podcast
    • Webcasts
  • Promoted Content
  • Investment Centre
  • Expert Resources
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited