Venafi Study: 69 Percent of Financial Services Organizations Do Not Rotate SSH Keys After Employees Leave

Eva Hanscom from Venafi
07 Dec 2017

SALT LAKE CITY, UT – December 7, 2017: Venafi®, the leading provider of machine identity protection, today announced the results of a study of how financial services organizations manage and implement Secure Shell (SSH). One hundred IT security professionals from the financial services industry participated in the study, which reveals a widespread lack of SSH security controls.

According to Venafi’s research, even though SSH keys provide the highest levels of administrative access, they are routinely untracked, unmanaged and poorly secured. For example, sixty-nine percent of respondents from the financial services industry admit they do not actively rotate keys, even when an administrator leaves their organization. This allows the former employee to have ongoing privileged access to critical and sensitive systems.

“Cyber criminals can leverage compromised SSH keys to gain elevated access to servers and perform nefarious activities, all while remaining undetected,” said Nick Hunter, senior technical manager for Venafi. “In addition, they know that a single SSH key will often be copied across hundreds or thousands of systems. Cybercriminals can use compromised keys to move throughout a financial services organization, creating additional backdoors and setting up beachheads for their operations.”

Key findings of the study include:

• Eighty-five percent of respondents say they do not have a complete and accurate inventory of all SSH keys. Without a comprehensive inventory, organizations in the financial services industry cannot determine if keys have been stolen, misused or should not be trusted.

• Sixty-one percent of respondents do not restrict the number of SSH administrators, which allows an unlimited number of users the ability to generate SSH keys across large numbers of systems. These administrators tend to use inconsistent security controls that leave organizations without any inventory or regular review of SSH trust relationships.

• Just twenty-nine percent of respondents rotate keys on a quarterly or more frequent basis. Thirty-six percent say they don’t rotate keys at all or only do so occasionally. Attackers who gain access to SSH keys will have ongoing privileged access until keys are rotated.

• Thirty-nine percent of respondents say they do not enforce “no port forwarding” for SSH. Because port forwarding allows users to effectively bypass the firewalls between systems, a cybercriminal with SSH access can rapidly pivot across network segments.

• Nearly a third (thirty-one percent) of respondents say SSH entitlements are not featured in their Privileged Access Management (PAM) policies and are rarely audited. Without proper auditing and effective SSH security policies, SSH key weaknesses can go undetected, leaving financial services organizations vulnerable to a wide range of cybersecurity attacks.

The study was conducted by Dimensional Research earlier this year. It analyzed responses from one hundred IT and security professionals in the financial services sector. Respondents have in-depth knowledge of SSH and are located in the U.S., U.K. and Germany.

About Venafi

Venafi is the cybersecurity market leader in machine identity protection, securing all connections and communications between machines. Venafi protects machine identity types by orchestrating cryptographic keys and digital certificates for SSL/TLS, IoT, mobile and SSH. Venafi provides global visibility of machine identities and the risks associated with them for the extended enterprise —on premises, mobile, virtual, cloud and IoT — at machine speed and scale. Venafi puts this intelligence into action with automated remediation that reduces the security and availability risks connected with weak or compromised machine identities while safeguarding the flow of information to trusted machines and preventing communication with machines that are not trusted.

With over 30 patents, Venafi delivers innovative solutions for the world's most demanding, security-conscious Global 5000 organizations, including the top five U.S. health insurers, the top five U.S. airlines, four of the top five U.S., U.K. and South African banks, and four of the top five U.S. retailers. For more information, visit

For more information, please contact:
Eva Hanscom
175 E 400 S
84111 Salt Lake City

Category: Cyber Security/Anti-Fraud
Back To All Press Releases

Powered by

How EBICS should have been built - A modern API for bank accounts. Fully automatized processing of incoming and outgoing money transactions.

Railslove - Ruby on Rails, JavaScript, and HTML5 web development. We're a team developing products for the web. Web apps are more than our daily business. We closely accompany our clients throughout the process of turning an initial idea into a product ready to launch - and beyond.

Subscribe to FinTechWeekly

* indicates required
How did you hear about FinTech Weekly & FinTech Press Releases?
Please tell us your age:
Do you work in the fields of banking, finance, etc