Digital Interaction: Geeks to Criminals
- Yenni Leighton
- Jun 3
- 7 min read
Updated: Jun 4
Editor's Note: This article was originally published in November 2015. Ten years later, the Digital Operational Resilience Act (DORA) came into force across European financial services — mandating precisely the integrated, board-level approach to cyber risk governance that this piece argued for. We have republished it unchanged as a marker of where the signals were pointing, long before the regulation followed.

Digital interaction: geeks to criminals
Author: Yenni Leighton, Founder, The Impetus Global | The Signal Before the Headline
November 25, 2015
Trust and accountability are watch words in financial services; information security and information governance play a major part in the digital landscape. In effect, they are intrinsically linked.
The last five years have seen an upsurge in digital attacks of some form on individuals, businesses, corporations, governments and organisations. Global security breaches grew by an astonishing 48% in 2014, according to PricewaterhouseCoopers (PWC).
What is this telling us? Is it really true, as the evidence suggests, that digital security is failing wholesale, that methods of attacks are becoming more sophisticated and that our defences are simply inadequate?
We knew the culprits, or at least we were pretty sure we knew the culprits in the past – they featured in Hollywood blockbusters! Broadly speaking, they were anti-establishment, anarchistic, tech-savvy geeks. They nurtured a reassuringly high profile in certain areas of the national psyche, based on showing us they could infiltrate databases. Any database.
The evidence today is that a different group has joined the game: serious, secret and malevolent. When the new cyber-criminals find a way into your network, they are not chasing fame; they are after information they can use either for financial or possibly some other, more lethal, gain. If this is the case and what we are seeing is the emergence of a new systemic disease, then what is the actual damage to our organisation, our investors and stakeholders?
In this article, I want to try and get a fix on the nature of the threats and the real impact for the infrastructure of data networks.
The threat is real
Millions of us are using mobile devices to communicate and to receive and share information. Sensing the potential in this new world order, organisations have built systems to interact with the new digitally-connected market place.
But if the rewards are high, the cost of maintaining state of the art systems is high too. So high, that organisations are clearly struggling to protect their data. PWC estimated that organisations haemorrhaged a massive $20 billion in 2014. That is an increase of 92% on the previous year.
The scale of the loss suggests that high-profile, private and public organisations, with so-called sophisticated infrastructure, are being routinely compromised.
These are examples chosen at random:

2011 - the US and the UK stock exchanges were victims of a cyber plot to spread panic in global markets 99 million PlayStation Network accounts had their personal data stolen over 2-year period
2012 - Red October randomly transmitted diplomatic secrets and personal data from mobile device
2012 - Parastoo leaked email data of experts working with the International Atomic Energy Agency after breaking into one of the agency's servers
2013 - news outlets hit with cyber warfare in response to new regulations on internet censoring
2013 - 200 million Twitter accounts and 2 million Vodafone accounts were accessed
2014 - data held for 25,000 employees of US Department of Homeland Security compromised
2014 - cyber criminals secured credit cards details and financial data from JP Morgan; 76 million households and 7 million businesses affected
2015 - three US healthcare payer organisations attacked, 91 million people affected
2015 - TalkTalk, the most recent, high profile corporate espionage so far
Cyber criminals infiltrate databases. Any database.
This infographic represents the level of indiscriminate targeting of databases, where no one is exempt. Governments know that cyber criminals will go to any length to steal data and they are now making concerted efforts to find solutions. For example, the Anti-Phishing Working Group, the global industry, law enforcement and government coalition focused on unifying the global response to cybercrime, tracks more than 9,000 phishing domains and almost 50,000 phishing URLS monthly. That is just to try and keep some control. The question has to be, is that sustainable?
Relationship with intellectual assets
So how did we get here?
Well, the investment management community has to comply with stringent data rules and follow rigorous risk management policies emerging from AIFMD, FATCA, EMIR, UCITS, PRIIPs regulations.
Operating expense has spiralled, physical storage means cost. A paperless environment seems to offer a way to cut cost. Another option is an increase in granular data, offering a way to cater for the needs of clients and investors now and into the future.
Today’s organisation demands exponential growth in the quality of information requested, processed and transmitted, digitally. Granular data can give you the advantage depending on how you use it. Criminals know this and if they can they will infiltrate your systems, record patterns and copy data.
They scan:
· Strategic investment decisions
· User profiles, passwords and privileges
· Account entries, know your customer (KYC) data
· Portfolio positions and trading history
· Assets held and valuations P&L as well as the cash-flow
· Fees and expenses
A systemic problem
The year 2014 saw more vulnerabilities, faster attacks, more files held ransom and more malicious coding than ever before. Perpetrators now want anything you have, that they can use.
An organisation’s data spans the value chain. Without it there is no business. We use data to determine new products, assess new markets, qualify leads, review risk profile, determine pricing structure and formulate investment strategies – and more. In the wrong hands data will hide the criminal while they steal your data. Gartner estimated that cyber security spending will hit $76.9 billion in 2015.
Dr. Sally Livesey, former UK Home Office scientific adviser is on record saying “…hackers pose more of a threat to world security than nuclear weapons...”.
So if we accept that this is at least partially true isn’t it time for some radical thinking? Should we, for example, introduce performance metrics to tell our clients and investors there are controls in place and they measure up? Because it is not enough to have processes that monitor suspicious activity.
Vigilance has to be intelligence-led and equipped with robust risk systems that can detect, report and monitor. Organisations have to know which assets the hackers want and how they are going to hit their defences.
Mind the gap
Digital attackers operate by exploiting weaknesses quicker than companies can defend them. Attackers are organised, sophisticated, plus they have time. They will spend months in the shadows, tracking, monitoring, and recording information flow. In 2014, Symantec reported that software companies take an average of 59 days to create and roll-out patches for zero-days. That’s up from four days in 12 months. We need to find the threat. We need employees who are wise to the newest tactics immediately the threat hits the radar.
Digital threat = business risk
Here is my list of seven essential steps:
Build intelligence-based cyber defence system that can find what is targeted and why. Understand the nature of the threat, across the value chain, to find the weakest link; look outward at third-party suppliers and inward at your own systems
Focus on surveillance and detection triggers; seek out any suspicious or unauthorised activity
Ensure prevention and risk governance that enables you to respond fast
Digital threat equals business risk: make it part of investment strategy
Invest in best: technology that repels persistent threats and protects data assets
Train staff: don’t trust finding security breaches to luck
Use independent auditors: audit, test and scrutinise policies systematically
For smaller firms, a private equity, an asset owner, a fund, this can all cost a lot of money and take time. They have to be aware of credential management, email and internet use, access protocol, documentation and storage and more. Using forensic cyber security analysts is an option. It’s unsustainable without infrastructure and investment.
Outsourcing to a firm with scope, embedded processes, a data centre and agile infrastructure with rapid mobile safeguards deployment capability, is a way to assure ‘business as usual’ during an outage. Advocating a particular provider is a company’s choice, it’s not the issue here.
An integrated approach
Regulators and government bodies have redoubled efforts in response to multiple attacks and the threat to investors. Businesses have traditionally seen this as chief information officer or the chief data officer territory. I have attended conferences where cyber security, information governance and data protection were on the agenda. I have been astonished that business executives, client teams and marketers and product managers simply walk away from these events. The message seems to be ‘we deal with customers, this is techie stuff’.
Perhaps, traditionally, these sessions were not a hunting ground for clients. But having awareness of how you prevent your target client’s data becoming a hostage in a front-page cyber kidnap? That really is part of today’s marketer skills set and a fiduciary responsibility on the organisation.
But why wait till you make headlines? It is worth stressing that in this digital age the roles and responsibilities at C-level are converging. C-level leaders need a joint digital strategy to run an agile profitable business and survive. It is a collaborative effort. Surely, you must recognise that without data and forensic scientists, information and data gatekeepers to protect data, your business may not flourish.
Make cyber security a business strategy priority, close revenue leakages and invest in protecting your investors, shareholders, clients and staff interest, it is good business practice.
Where do you stand?
The frameworks have changed. The urgency has not. If your board is still treating cyber resilience as an IT line item rather than a strategic and fiduciary priority, the conversation is already overdue.
The Capital Markets Playbook: Europe & Africa addresses concentration risk, operational fragility and regulatory intelligence as interconnected systemic challenges — not separate functions.
——————————————————————————————————————————
© 2026 Yenni Leighton / The Impetus Global. All rights reserved.
KENSAM™ market framework coined by Yenni Leighton, The Impetus Global, 2024.
——————————————————————————————————————————

Comments