Insider Threats in Banking Sector: Detection, Prevention, and Mitigation

1Citations
Citations of this article
41Readers
Mendeley users who have this article in their library.

Abstract

The banking sector, as a custodian of sensitive financial data, has increasingly become a prime target for insider threats. Unlike external cyberattacks, insider threats originate from within the organization, making their detection, prevention, and mitigation more complex. This study provides a comprehensive review of scholarly and industry literature published between 2015 and 2024, with a particular focus on insider threats in financial institutions. The article categorizes insider attacks into four key vectors: data exfiltration, misuse of privileged access, social engineering, and cloud exploitation. It further examines modern detection mechanisms, including user and entity behavior analytics (UEBA), anomaly detection, and deception technologies, as well as preventive frameworks such as Zero Trust Architecture, multi-factor authentication (MFA), and employee awareness training. Mitigation strategies—such as continuous monitoring, blockchain-based audit trails, and incident response automation—are also discussed. The findings highlight that while technical solutions have become increasingly mature, human-centric and behavioral models remain underutilized. The study concludes with a call to integrate technical tools and human factors through predictive analytics and cross-disciplinary collaboration in order to effectively manage insider threats in the banking sector.

Cite

CITATION STYLE

APA

Huy, S., Ang, S., Ho, M., & Balasubramaniam, V. (2025). Insider Threats in Banking Sector: Detection, Prevention, and Mitigation. Journal of Cyber Security and Risk Auditing, 2025(4), 257–265. https://doi.org/10.63180/jcsra.thestap.2025.4.5

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free