Modern Application Development in Financial Services
The banking and financial services sector has experienced a lot of change over the last decade. The digital revolution has had a significant impact by driving the move to online services and smartphone apps at the expense of many high street branches. The digital native generation that has entered the workforce of the last decade expect that digital tools will deliver their financial service needs. The pandemic shutdowns since early 2020 have accelerated the adoption of digital banking and other financial services, but the trend has been shifting that way for longer than that.
The shift has driven a rapid expansion in the number of FinTech players in the market. These entrants have driven the established financial organisations to adapt and has galvanised the mergers & acquisitions activity as players strive for market share and dominance.
The Threat Landscape
Financial information and people's personal information associated with their banking and other financial accounts are tempting targets for cybercriminals. Both the funds associated with peoples accounts and their personal information have value to attackers if they can bypass security. Between February and April 2020 cyberattacks against financial institutions rose by 238%, according to data published by the VMware Security Business Unit. The same research also reported that 80% of all financial institutions surveyed had reported an increase in cyberattacks over the previous year.
With the increase in FinTech companies in the sector and the move to online and app-based services across the board, the threat landscape that criminals can target has expanded. To deliver the increased service footprint the number of individual applications has increased, and this means that the amount of code written by developers has also increased. All code has bugs and security vulnerabilities. So when more code gets written, there will be more ways for attackers to try to circumvent protections and gain malicious access.
Adopting a Security Focused Development Mindset
Security needs to be front and centre at all stages of the development lifecycle when developing FinTech based apps for the Web and smartphones. Actually, that's true across all sectors, but we're focusing on FinTech here. In addition to the valuable information that FinTech apps contain, the sector is also subject to stringent regulations from governments (e.g., GDPR and the proposed EU Digital Finance Strategy legislation) and via industry regulations (e.g., PCI DSS).
To ensure that development teams in the FinTech sector build robust security into their apps from conception to deployment, they need to adopt auditable AppSec policies and procedures that encourage a security-first design and development process.
A multi-layered approach that can bring automated checking and expert systems to bear on new code and any third-party libraries in use is required. In modern software development, this means:
- Static Application Security Testing (SAST) - incremental scans that look for vulnerabilities in newly written code.
- Software Composition Analysis (SCA) - check open-source libraries and code for known issues.
- Interactive Application Security Testing (IAST) - optimised testing of running applications and code by Test/QA teams as part of a broader DevSecOps process.
Checkmarx Delivers What You Need
Fortunately, application security specialist organisations like Checkmarx have the solutions to deliver this expertise to FinTech development teams. With tools backed by decades of development experience and extension ongoing research into FinTech cybersecurity, the Checkmarx solutions will raise the security posture of any development team.
The free to read Checkmarx White Paper titled Modern Application Development in Financial Services: Ensuring Your AppSec Program Adds Value provides a good overview of the FinTech landscape and what development security needs to deliver to enable organisations to deliver secure applications to their customers.
The paper outlines what AppSec development security solutions should deliver, but it does not go into a hard sell for Checkmarx solutions. But we will. The Checkmarx Application Security Platform with SAST, SCA, IAST, training and consultancy services is ideal for any FinTech organisation or MSPs selling security services into that market. Adopting the tools will reduce time to market for FinTech apps and at the same time deliver more secure apps that guard both the FinTech organisation and their customers.
Conclusion
If you would like to chat with an expert on how Checkmarx solutions can make your FinTech development projects more secure and risk-free, then contact Renaissance. We partner with Checkmarx to make their solutions available in the Irish marketplace.

