# The foundation of security compliance for financial services businesses

DevFeed: [The foundation of security compliance for financial services businesses](<https://devfeed.tech/articles/the-foundation-of-security-compliance-for-financial-services-businesses-1918.md>)

Original publisher: [Read original article](<https://1password.com/blog/foundation-of-security-compliance-for-financial-services>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-06-16T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [business](<https://devfeed.tech/tags/business.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This article explains why small and medium-sized financial services businesses need a strong security and compliance foundation. It highlights rising cyberattack and ransomware risks, limited security resources, credential management challenges, and the way AI adoption can increase SaaS sprawl, shadow IT, policy violations, and attack sophistication.

## Source excerpt

One of the less surprising findings of the 2026 Verizon Data Breach Incident Report (DBIR) is the fact that incidents targeting the Financial and Insurance sector are on the rise. As they put it, "This sector continues to be a favorite among attackers, which isn't surprising given that its core business is handling money." For small-to-medium businesses (SMBs) in the financial services sector, the DBIR paints an even more dire picture. The report notes that SMBs face the same threats and breach patterns of larger organizations, but are also disproportionately impacted by attacks; 96% of ransomware victims were SMBs. In short: businesses in the financial services industry who are still building their foundation, or who possess limited security resources, are caught between a rock and a hard place. They operate within one of the most heavily targeted sectors for cyberattack, and are held to enterprise-level security standards by regulators and clients alike, but they're operating with startup-level security resources. For lean security and IT teams to make the most of those limited resources, they need to focus on what they can afford. That means getting the fundamentals right for a strong and impactful security foundation. The highest-leverage fundamental is, of course, credential management. Top security challenges for financial services organizations Small IT and security teams in the financial services industry are faced with high expectations when it comes to security. Unfortunately, they also experience significant challenges when it comes to securing credentials. AI is accelerating SaaS and credential sprawl JP Morgan Chase's recent research report, Understanding the use of AI among small businesses, finds that not only are a growing number of small businesses adopting AI, when they do, they also tend to implement a greater number and variety of AI tools. It's not hard to understand why this is the case; AI's ability to automate processes and improve productivi