ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity - Sponsored Content

Why financial firms should pay particular attention to their client-side web assets

June 30, 2022
Reading Time: 4 mins read

SPONSORED CONTENT PRESENTED BY FEROOT SECURITY

By Ivan Tsarynny

The banking industry was dubbed the “most breached sector” by Forbes in 2019. At the time, it accounted for 35 percent of all data breaches. Fast forward to just three years later, it is clear that banks and other financial services firms remain prime targets for malicious actors. They are among the ripest industries for people seeking to take advantage of the fact that customers enter ultra-sensitive (and valuable) data into JavaScript-based online forms and other tools housed in the front end or “client-side.”

Online banking has experienced a tremendous shift in the past two years. Banking websites rely heavily on scripts to gather sensitive information and are held to high standards in regard to online compliance. The need to improve security in the financial sector has never been greater, especially from the client-side.

The Types of Client-Side Attacks Threatening the Financial Services Sector

Online banking has never been more accessible but has a few drawbacks for digital security. The client side is especially susceptible to cyberattacks. Account takeover occurs when threat actors achieve access to user credentials for financial gain. Cross-Site Scripting (XSS) is an attack involving injecting malicious code onto client-facing websites. E-skimming involves stealing credit card information or other sensitive data through exploiting code flaws. Formjacking is a type of e-skimming that collects valuable data through malicious code. JavaScript injection attacks occur by injecting malicious code to control the website.

To properly guard their websites and web applications from client-side attacks, the industry’s cybersecurity professionals have little choice but to give more and more attention to what’s happening on their organization’s “surface” to avoid client-side breaches.

What Other Types of Tools Support Client-Side Security?

There are additional client-side security tools available to organizations, none of which, unfortunately, protect the entire client-side surface. Web Application Firewalls (WAFs) scan and protect against some types of skimming attacks. However, WAFs do not protect the browser-level user interface itself and are not able to detect and protect businesses from sophisticated skimming malware, drive-by skimming, supply chain attacks, or sideloading.

Content Security Policies (CSPs) can detect attacks such as cross-site scripting (XSS), but they are not easy to add to an existing website due to their complexity and the extent to which they can conflict and affect website functionality. Penetration testing, vulnerability assessment and security assessment are uncommon for client-side security threats at this point in time. Pen testing and assessments are also a snapshot in time, which means hackers have the ability to execute attacks between quarterly or annual assessments. And if hackers discover new vulnerabilities, then it is likely that they will target those vulnerabilities before a pen test has been completed. Pen testing and assessments are a key part of the security process, but organizations still remain exposed to threats, even after tests are completed. Unfortunately, threat actors are much more nimble than most companies.

Vulnerability scanning tools are designed to scan back-end code and systems, typically those digital assets that live on the server side. They will not be capable of detecting and calculating all JavaScript scripts and vulnerabilities. Vulnerability scanners can only see the client-side after it’s been assembled together, not in real time. Vulnerability scanning tools see only one site or domain, not all of the links that are part of it.

Code obfuscation (or scrambling) makes it difficult for cybercriminals to interpret code, but free online de-obfuscation tools can enable threat actors to reverse engineer the original code. Code obfuscators can also be problematic in that sometimes it is difficult to unscramble the code when necessary. Implementing an approach that prioritizes client-side attack surface monitoring provides organizations with a strategic advantage to detect and prevent cyber threats.

What Is Client-Side Attack Surface Monitoring?

Client-side attack surface monitoring automates the process of logging an organization’s web assets. It then provides IT personnel with a list of the data each asset is accessing, offering specific remediation advice to security teams in real time.

Client-side security technologies replicate actual user behavior on a webpage, including the ability to execute custom user journey scenarios. By employing “synthetic users,” disguised as honeypot customers, client-side attack surface monitoring solutions autonomously simulate real user behavior. A client-side attack surface monitoring tool automatically maps and monitors the client-side attack surface, detects and outlines abnormal application behaviors then informs security teams of their client-side attack surface and will alert application developers to code issues to fix in real time. This approach provides security against customer data exfiltration.

By revealing previously undetected or net new threats, and delivering mitigation advice, client-side surface monitoring allows companies to close security gaps in their client-side JavaScript web applications.

The Benefits of Client-Side Attack Surface Monitoring for Financial Firms

The benefits of client-side attack surface monitoring for financial firms are numerous—it’s not just limited to evaluating web applications. It also has the capability of providing financial institutions with synthesized intelligence through post-scanning. Additionally, IT personnel can analyze the data gathered by synthetic users and gain important threat intelligence that security teams can respond to rapidly, if needed. These synthetic users are adaptable and have the ability to learn as they go, identifying and classifying information to discover client-side issues that would be left undetected otherwise.

Client-side attack surface monitoring solutions are simple to implement and maintain on active websites with no major modifications needed and are more effective than the other approaches mentioned. This approach does involve interaction between the financial institution’s development and cybersecurity teams. Both teams need to be well versed on client-side application structures in order to ensure the website is properly secured. But by working together, security and development teams can ensure client-side security with ease.

The best defense for web applications and websites is awareness. By employing some or all of the aforementioned approaches, IT personnel will always know the web assets they own and the data that is stored. And more importantly, they’ll be more confident of how those assets function and how users interact with them. It’s security from the outside-in, giving web assets the attention they deserve so that they don’t transform from a business enabler into a formidable threat.

Ivan Tsarynny is CEO and co-founder of Feroot Security.

ShareTweetPin

Related Posts

How top agricultural lenders are approaching AI, automation and innovation in 2026

How top agricultural lenders are approaching AI, automation and innovation in 2026

Ag Banking
March 2, 2026

SPONSORED CONTENT PRESENTED BY MOODY'S The agricultural market faces unique challenges, from volatile markets and cyclical production to complex operations. In a rapidly changing landscape, time-pressed producers can benefit from lenders who act as strategic partners, offering financial...

Top 7 FP&A Trends in Banking for 2026

Top 7 FP&A Trends in Banking for 2026

Compliance and Risk
March 1, 2026

SPONSORED CONTENT PRESENTED BY EMPYREAN SOLUTIONS In the banking world, financial planning and analysis (FP&A) is no longer a budgeting task to be completed. It has evolved into a key part of strategic planning, utilized heavily to help...

How Instant Payments Can Accelerate B2B Payments Modernization

How Instant Payments Can Accelerate B2B Payments Modernization

Payments
February 3, 2026

SPONSORED CONTENT PRESENTED BY FEDERAL RESERVE FINANCIAL SERVICES The business-to-business (B2B) payments market is a very large segment of the U.S. payments industry, with transactions reaching an estimated $35.8 trillion in 2024, according to eMarketer estimates. As the...

Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

Community Banking - Sponsored Content Live
February 1, 2026

SPONSORED CONTENT PRESENTED BY JACK HENRY™ “Digital banking” is banking. The transformation of financial services is accelerating, driven by competitive pressure, profitability demands, and rapid technological advancement. Your customers no longer distinguish between “digital” and “traditional” banking. They...

Planning Your 2026 Budget? Allocate Resources to Support Growth and Retention Goals

Why Every Digital Interaction Defines Your Brand Experience

Retail and Marketing
February 1, 2026

SPONSORED CONTENT PRESENTED BY ALKAMI TECHNOLOGY   What most influences trust, primacy and growth among financial institution account holders? The digital banking experience. According to The 2025 Generational Trends in Digital Banking study, 70% of digital banking consumers...

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Compliance – Sponsored Content
November 1, 2025

SPONSORED CONTENT PRESENTED BY THE FEDERAL RESERVE Payments fraud continues to grow and impact individuals and organizations alike. According to the Federal Trade Commission, consumers reported losing more than $12.5 billion to fraud and scams in 2024, up 25% from...

NEWSBYTES

ABA DataBank: Stable credit risk in corporate bond markets

March 13, 2026

Trump proposes regulatory overhaul to promote housing finance, construction

March 13, 2026

Court tosses subpoenas against Fed’s Powell

March 13, 2026

SPONSORED CONTENT

How top agricultural lenders are approaching AI, automation and innovation in 2026

How top agricultural lenders are approaching AI, automation and innovation in 2026

March 2, 2026
Top 7 FP&A Trends in Banking for 2026

Top 7 FP&A Trends in Banking for 2026

March 1, 2026
How Instant Payments Can Accelerate B2B Payments Modernization

How Instant Payments Can Accelerate B2B Payments Modernization

February 3, 2026
Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

February 1, 2026

PODCASTS

Podcast: From stablecoin to fraud, top takeaways from the 2026 ABA Summit

March 13, 2026

Podcast: How the SCAM Act would encourage platforms to go after scammers

February 4, 2026

A new kind of ‘community bank’ for small businesses

January 22, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.