/

Research Uncovers Thousands of Vulnerable Cyber Assets In Southeast Asia’s Financial Sector

1 min read

Singapore, 5 September 2024 – New research by Tenable®, Inc., a leader in exposure management, has identified over 26,500 potential internet-facing assets among the largest banking, financial services, and insurance (BFSI) companies in Southeast Asia by market capitalization. The study spanned Indonesia, Malaysia, the Philippines, Singapore, Thailand, and Vietnam.

On July 15, 2024, Tenable analyzed the external attack surfaces of more than 90 BFSI organizations with the highest market capitalizations in the region. The findings revealed that, on average, each organization possesses nearly 300 internet-facing assets vulnerable to potential exploitation, totaling over 26,500 assets across the surveyed companies.

Singapore topped the list, with more than 11,000 internet-facing assets identified across its 16 leading BFSI companies, of which over 6,000 are hosted in the United States. Thailand followed with over 5,000 assets. The distribution of internet-accessible assets highlights the pressing need for adaptive cybersecurity strategies in today’s rapidly evolving digital landscape.

CountryNo. of internet-facing assets among top 90 BFSI companies by market capitalisation
Singapore11,000
Thailand5,000
Indonesia4,600
Malaysia4,200
Vietnam3,600
Philippines2,600

“The results of our study reveal that many financial institutions are struggling to close the priority security gaps that put them at risk. Effective exposure management is key to closing these gaps,” said Nigel Ng, Senior Vice President, Tenable APJ. “By identifying and securing vulnerable assets before they can be exploited, organisations can better protect themselves against the growing tide of cyberattacks.”

Cyber Hygiene Gaps

Tenable’s study uncovered several vulnerabilities and cyber hygiene issues among the BFSI companies analyzed, including outdated software, weak encryption, and system misconfigurations. These weaknesses create exploitable entry points, posing serious risks to the security and integrity of financial data.

Weak SSL/TLS Encryption

One significant finding was that nearly 2,500 assets across organizations still support TLS 1.0—a security protocol introduced in 1999 and disabled by Microsoft in 2022. The continued use of this outdated encryption highlights the challenges organizations with large internet footprints face in identifying and upgrading legacy technologies.

Misconfigurations Increasing Exposure

Over 4,000 assets, originally meant for internal use, were unintentionally exposed and made externally accessible. These misconfigurations create a heightened risk by offering malicious actors opportunities to access sensitive information and critical systems.

Lack of Encryption

The study also revealed more than 900 assets with unencrypted final URLs, which poses a significant security risk. Unencrypted URLs leave data exchanged between the user’s browser and the server unprotected, making it vulnerable to interception, eavesdropping, and manipulation. This gap could expose sensitive information like login credentials, personal data, and payment details.

API Vulnerabilities Amplify Risk

Additionally, over 2,000 API v3 assets were identified across organizations’ digital infrastructures, representing a major security risk. APIs, which connect software applications for data exchange, are critical components but can become vulnerable due to weak access controls, inadequate authentication, and improper input validation. These weaknesses provide a potential attack surface that can be exploited by malicious actors to gain unauthorized access, compromise data, and launch cyber attacks.

Discover more from DigitalCFO Asia

Subscribe now to keep reading and get access to the full archive.

Continue reading