Ask most people to picture a banking cyber threat and they imagine a remote attacker breaching a firewall from the other side of the world. It’s a fair image, and financial institutions spend heavily to prevent exactly that. But some of the most damaging incidents in banking cyber security begin with something far more mundane: a USB drive carried through the front door and plugged into a workstation.
Why finance is such a target
Financial institutions operate in one of the most targeted environments anywhere. They hold vast quantities of sensitive customer data, move enormous sums, and run payment infrastructure that criminals probe relentlessly. Industry figures suggest UK financial services face hundreds of cyberattacks every day, and the cost of a single breach in the sector now runs to millions of pounds.
Much of the defensive effort, quite rightly, goes into network security, fraud detection, and staff phishing awareness. Yet a significant share of successful breaches involves external or removable media the physical devices that bypass network defences entirely because they are plugged straight into a trusted machine.
The removable media blind spot

Banks and financial firms constantly handle external devices, but each one introduces a potential banking cyber threat. Auditors arrive with data on USB drives, third-party vendors bring devices to service equipment, and regulators share files on portable media. Across trading floors, branch offices, and back-office operations, handling removable media has become routine yet unvetted devices remain an overlooked risk.
Each of these is a legitimate, necessary activity. Each is also an uncontrolled entry point unless there is a formal process to check the device first. A USB drive that has passed through several other organisations may carry malware that standard antivirus does not recognise, firmware-level attacks that file scanning cannot see, or data-stealing tools designed to sit quietly and exfiltrate customer records over months.
The uncomfortable truth is that software running on the target machine is not always enough. If a device arrives already compromised, endpoint antivirus may only catch the threat once it’s already on the system which can be too late.
What the regulators expect
This is not merely good practice; it’s increasingly a compliance expectation. Financial firms operate under stringent requirements including PCI DSS for card data, FCA rules on operational resilience, and PRA supervisory statements. These frameworks expect firms to manage the risks posed by removable media and to maintain detailed audit trails demonstrating they have done so.
Being able to show, device by device, that removable media is checked before it touches a sensitive system is exactly the kind of evidence auditors look for.
A practical line of defence

The most reliable way to close this gap is to inspect every removable device in isolation before it connects to anything important. Dedicated decontamination stations do this by scanning each device in a hardened, separate environment, using multiple detection engines to catch both known and unknown threats, and neutralising anything malicious before the device is cleared for use. Because the process happens away from the bank’s network, malware never gets the chance to spread, and every scan produces a log for compliance purposes.
The bottom line
Scotland’s financial firms are right to invest in defending against remote attackers, but the humble USB drive remains an overlooked banking cyber threat. Treating removable media as a deliberate, checked, and auditable process rather than an afterthought closes a gap that determined attackers are still happy to exploit.

















