Factoring Security Into Data Governance

During this week's European Financial Information Summit (EFIS), answers to one of the questions posed in last week's column previewing the conference emerged in discussions ostensibly about other concerns.
I had asked whether centralization or outsourcing to implement data governance strategies would be better or more advantageous for firms. Panelists discussing the current regulatory landscape arrived at some answers concerning data governance as part of their discourse—as did an EFIS keynote speaker focused on cyber security and protecting data.
Jacob Gertel, senior project manager for legal and compliance data at SIX Financial Information, observed that to comply with US Fatca tax withholding and reporting law, and work with the Common Reporting Standard (CRS) used for Fatca reporting, the data that financial intermediaries must deliver is based on data files from their customers. As a result, this data, with its relevance for regulatory compliance, has greater value than it might otherwise. And, Gertel says, SIX seeks ways to make the data available to users without having to set up all new structures for management and distribution.
Fatca or CRS-relevant data is increasing in volume, and resembles the type of "big data" that Dan Crisp, managing director, EMEA, information risk management at BNY Mellon, says needs protection from cyber invasion. "We have gone to a super-abundant world of data," he says. "Conceptualizing data, unless you are a deep subject matter expert, is quite challenging. We have data growing exponentially, bigger and bigger challenges with metadata and visualization-and getting that across to people who may not be familiar with the details."
The European Union's Cybersecurity Strategy and the European Commission's Directive on Network and Information Security, now in place, was a long-shot for passage a year ago, Crisp notes. There is a social element to data, namely the possibility that hackers can use social engineering to gather information on data users and deceive them through social familiarity to gain access, Crisp says. Along with the EU directive, regulators in European nations want firms to demonstrate what systems and organization they have in place, for data protection.
It may seem contradictory to the goal of making data more available for distribution, as Gertel discussed, but the cyber security directive is requiring firms to know what their IT partners or vendors are doing about data security. "We all understand that there's speed to market challenges, and speed of compliance challenges, from regulators; and global regulations are becoming increasingly strict requirements," says Crisp.
So, if your firm is in the middle of deciding whether to centralize or outsource data management, and is considering how to write data governance plans accordingly, the data security issues Crisp raises are also something that has to be figured into that process. That's an unexpected answer to the data governance question, but a valid one.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Data Management
Growing pains: Why good data and fortitude are crucial for banks’ tech projects
The IMD Wrap: Max examines recent WatersTechnology deep dives into long-term technology projects at several firms and the role data plays in those efforts.
Investing in the invisible, ING plots a tech renaissance
Voice of the CTO: Less than a year in the job, Daniele Tonella delves into ING’s global data platform, gives his thoughts on the future of Agile development, and talks about the importance of “invisible controls” for tech development.
Optiver relies on BMLL market data for quant strategy
The market-maker has built its trading business on top of BMLL’s Level 3 data. But the collaboration is young, and the pair have grand plans to make options the next quant frontier.
Bloomberg expands IBVAL; the SIPs and 24/5 trading; Broadridge’s agentic play, and more
The Waters Cooler: State Street embraces interop, Citi’s CIO outlines the XiNG risk platform, power companies explore alternative nuclear supply options to datacenters, and more.
As costs rise, buy-side CIOs urge caution on AI
Conference attendees encouraged asset managers to tread carefully when looking to deploy AI-driven solutions, citing high cost pressures.
XiNG: Inside Citi’s all-encompassing risk platform
Voice of the CTO: Citi’s chief information officer, Jon Lofthouse, explains how and why the bank has extended its enterprise-wide risk platform so that every trade in any asset class goes through it.
Demand for private markets data turns users into providers
Buy-side firms seeking standardized, user-friendly datasets are turning toward a new section of the alternatives market to get their fix—each other.
LSEG-AWS extend partnership, Deutsche Bank’s AI plans, GenAI (and regular AI) concerns, and more
The Waters Cooler: Nasdaq and MTFs bicker about data fees, Craig Donohue to take the reins at Cboe, and Clearwater closes its Beacon deal, in this week’s news roundup.