Implications of the LSE's IT nightmare
The "suspicious circumstances" that ultimately led to the London Stock Exchange postponing the launch of its ultra-fast new tech platform means there's likely to be an increased focus on IT security in the financial sector.
As has been widely reported, the two-hour crash of the LSE's Turquoise trading error was caused by human error, possibly "suspicious circumstances" that have forced it delay the migration of its new Millennium IT system - designed to replace the comparatively clunky TradeElect technology - until the new year.
More details are sketchy, but FT has already raised the prospect that the culprit could have been disgruntled employee "in the departure lounge" as a result of the changes at the exchange.
Within the financial sector more broadly, as we've highlighted before, the threat of such tech sabotage from rogue employees has been a concern for some time now.
The new Ernst & Young Global Information Security Survey suggests that most businesses still aren't addressing the risks posed by new technologies. The need to implement stronger identity and access controls was highlighted by 28% of respondents and 29% are implementing better encryption techniques.
More IT security expertise, but a harder time recruiting it
The implications of this, and other threats of cyber-terrorism towards banks, is that IT security professionals are becoming "increasingly valuable", suggests Paul Winchester, managing director at technology recruiters Greythorn, but conversely it will become a more difficult sector to break into.
"One surprising result of the growing importance of IT security will be that it makes the process of getting a position in this sector increasingly difficult," he says. "While there is a strong demand for trusted security professionals, growing interest in security means that procedures for obtaining clearance will be lengthened and this will have a significant impact on mobility in the sector. IT security personnel will be closely monitored to minimise risk and we believe that the recruitment processes will come under review and will be hardened."
Increased focus on offshore security?
While the crème de la crème of the Sri Lanka-based Millennium IT's team will have been drafted into the LSE's Paternoster Square office since it acquired the firm last year, it's likely a lot of the development work will have been carried out offshore.
Could questions be raised about the security of such offshore ventures? Probably not, surmises Nigel Roxburgh, founding partner of the National Outsourcing Association.
"Most offshore service providers are almost overly paranoid about the threat of IT security breaches and are arguably more vigilant than firms in the UK," he says. "That said, if an individual was determined enough to infiltrate the system they'd probably be able to do so."
The pressure to get the new system spot on
Some of the more scurrilous rumours have suggested this is all a smokescreen to cover up the fact that new system isn't yet up to scratch.
This seems doubtful, as the whole point of rolling out a new IT system was to compete with the LSE's more tech-savvy competitors - like BATS and Chi-X - to which it has been losing market share.
The new Millennium IT platform boosts being the fastest in the world - with trade speeds cut to 126 microseconds - but the longer the delay in implementing it, the more potential there is to fall further behind.
The timing does seem convenient, however, as December is an "agreed freeze period", giving the LSE enough time to sort out any issues. And, as Tabb Group's Miranda Mizen points out: "It will all - technology, implementation and communications policy - have to work flawlessly next time."