Phone : +91 95 8290 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » Vulnerabilities & Exploits » How an investment bank secured AI adoption without compromising confidential financial data

How an investment bank secured AI adoption without compromising confidential financial data

How an investment bank secured AI adoption without compromising confidential financial data

https://etimg.etb2bimg.com/thumb/msid-134777699,imgsize-62676,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/how-an-investment-bank-secured-ai-adoption-without-compromising-confidential-financial-data.jpg

An investment analyst researching market trends turns to an AI platform to analyse a client portfolio. Another researcher copies a proprietary trading model into an AI tool seeking optimisation suggestions, while a junior analyst uses AI to summarise a confidential deal memo.

Such use cases are becoming part of everyday workflows as financial institutions adopt AI for market research, financial modelling, investment analysis, report writing, portfolio optimisation and risk assessment. Platforms such as ChatGPT, Claude and Gemini can accelerate analysis and improve productivity, but they can also create a new data-security challenge when sensitive financial information is shared with external AI services.

Client portfolios, trading strategies, proprietary models, material non-public information and deal-related confidential information can potentially leave an organisation’s security boundaries. For financial institutions, such exposure can raise regulatory concerns, breach client confidentiality obligations and put competitive advantage at risk.

With hundreds of analysts and thousands of daily interactions with AI platforms, relying solely on employee training or restricting internet access may not be sufficient. The challenge is therefore shifting from whether employees should use AI to how financial institutions can enable legitimate AI use while maintaining control over the data being shared with these platforms.

A regional investment bank addressed this challenge by deploying eScan Enterprise DLP, enabling analysts to continue using AI for approved business activities while automatically preventing the transmission of confidential financial information to public AI platforms.

Controlling data before it reaches AI platforms

The eScan deployment uses an endpoint DLP agent to monitor AI interactions across analyst workstations, trading floors, research departments and mobile devices. The agent operates in the background, allowing users to continue their normal workflows while controls are applied to the data being transmitted.

Before data reaches an AI platform, the DLP agent can inspect content in real time, classify its sensitivity, identify confidential financial information and automatically block unauthorised transmission.

The information identified for protection can include client account details, trading strategies, proprietary models, material non-public information and deal-related confidential information.

This approach allows organisations to control data movement without taking a blanket approach of blocking AI platforms altogether.

The technology combines Neural Intelligence AI/ML, behavioural analysis, content-aware inspection and Optical Character Recognition (OCR) capabilities to identify and protect sensitive information. Its AI Platform Data Protection capability is designed to monitor and control data uploads to AI services including ChatGPT, Claude, Gemini and other AI platforms, helping prevent inadvertent sharing of sensitive documents while allowing legitimate AI-powered tasks.

For an analyst, an attempted transmission of confidential information can be stopped before the data reaches the external AI service, with the user receiving an indication that the request contains information that cannot be transmitted.

AI workflows with security controls

The bank also established approved AI workflows for different business functions.

Market research uses approved Claude instances, general macroeconomic analysis uses Gemini, while public financial data research can use ChatGPT. Each approved workflow is supported by audit logging, enabling analysts to review their AI interaction history while compliance and audit teams gain visibility into how AI systems are being used.

The approach allows the organisation to distinguish between legitimate AI use and potentially risky data transfers instead of treating all AI usage as a security threat.

Data classification and governance

A key part of the implementation was defining what constitutes confidential information.

The bank established classifications covering public data, internal reference data, client-confidential information and trading-sensitive information. The endpoint agent then enforces these classifications automatically.

The implementation was integrated with existing compliance infrastructure, including surveillance systems, audit logging and compliance reporting. The bank also established governance policies covering AI tool approval, security updates as new AI platforms emerge and user training.

Analyst adoption was another important part of the implementation. The bank demonstrated that monitoring could help prevent inadvertent regulatory violations while approved AI workflows could support faster analysis than unrestricted use of public AI platforms. Early adoption by senior analysts helped drive wider acceptance across teams.

Hundreds of confidential data transfers blocked

During implementation, the solution prevented hundreds of attempted transmissions of confidential financial datato public AI platforms.

The blocked attempts included:

  • Client portfolio information that could breach client confidentiality
  • Trading strategies and execution models that could compromise competitive advantage
  • Material non-public information that could create securities-regulation concerns
  • Deal-related information protected under confidentiality agreements

The bank also established comprehensive audit trails covering who used an AI platform, when it was used, what data was being analysed and which system processed the request.

Such visibility can support compliance reviews by providing organisations with a record of AI-related data activity and the controls applied to it.

Enabling AI without losing data control

Financial institutions are increasingly looking at AI to improve research, analysis, decision-making and client servicing. But for organisations handling highly sensitive financial information, AI adoption also introduces a need for stronger data governance and visibility. Recent industry discussions have similarly highlighted security, governance and data protection as prerequisites for scaling enterprise AI.

For financial institutions, the choice does not have to be between banning AI and accepting uncontrolled data exposure. The focus can instead be on controlling what data reaches which AI system, under what circumstances and with what level of oversight.

Govind Rammurthy, CEO & MD, eScan, said:

“Financial services firms face a manufactured choice: restrict AI adoption to protect confidential data, or enable AI and hope analysts don’t accidentally leak trading strategies to ChatGPT. That’s a false choice. Monitor what data flows where. Block the confidential stuff automatically. Allow analysts to use AI for legitimate market research and analysis. It’s straightforward endpoint monitoring—the same principle that prevents data leakage to email or USB drives, just extended to LLM/AI platforms. You don’t need to restrict innovation. You need to control data flow.”

The author is Govind Rammurthy, CEO & MD, eScan.

Disclaimer: The views expressed are solely of the author and ETCISO does not necessarily subscribe to it. ETCISO shall not be responsible for any damage caused to any person/organization directly or indirectly.

  • Published On Oct 8, 2026 at 08:00 AM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETCISO industry right on your smartphone!




Information Security - InfoSec - Cyber Security - Firewall Providers Company in India

 

 

 

 

 

 

 

 

 

 

 

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India

Sales Number : +91 95 8290 7788 | Support Number : +91 94 8585 7788
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket