Online banks servicing UK's SMBs found to have 'serious' security flaws
TSB and Virgin Money were both ranked bottom of a study examining security practices at leading UK banks


Some of the largest online banks in the UK have been found to have "worrying" security vulnerabilities in their products, leaving the UK businesses they service, and their customers, at risk of cyber attacks.
TSB and Virgin Money, both of which offer business current accounts for SMBs across the country, were found to have serious security issues that could put customers at risk, researchers said.
Researchers at Red Maple Technologies, working on behalf of Which?, raised “several concerns” over TSB security practices in particular, revealing that the bank still asks “basic security questions” to recover login details.
In addition, Red Maple said it found a potentially vulnerable subdomain and two outdated web applications. which could place customers at risk. However, the bank confirmed that the vulnerable subdomain will be removed.
“[TSB] also lost points for using SMS-based security, not sending alerts when sensitive account changes were made and including phone numbers in new-payee notifications,” researchers said.
A spokesperson for TSB told the consumer group that it is continuing to invest in online and mobile banking services and work with “globally-leading tech firms to deliver both security and accessibility” to customers.
“TSB also tracks well across the industry on fraud prevention,” the spokesperson added.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The researchers examined the cyber defences of 13 current account providers to rate their online and mobile banking security.
Virgin Money received the lowest score for online and app banking, according to Red Maple's analysis.
The security firm found six outdated web applications, an exposed IP address, and a subdomain using an outdated version of TLS.
Of the six outdated web apps, three contained minor security vulnerabilities, researchers revealed.
Small business security concerns
Red Maple’s research on banking security comes amidst a period rife with escalating security risks for small businesses across the UK.
Research from Close Brothers last year found that around half of UK-based SMBs have suffered a cyber attack, with 54% suffering a financial loss.
Ransomware attacks were highlighted as the most common attack method among SMBs, followed by phishing attacks.
Among those that suffered a cyber attack, the study found that two-thirds have been subjected to increased incidents in the weeks and months following.
Jasson Casey, CTO at Beyond Identity, said the research from Red Maple is concerning, and highlights vulnerabilities which are frequently targeted by threat actors.
RELATED RESOURCE
Storage's role in addressing the challenges of ensuring cyber resilience
Understanding the role of data storage in cyber resiliency
“It’s worrying to see this latest report from Which? which has marked banks down on multiple security measures, including failing to block weak passwords, sending one-time passcodes and sensitive data via SMS,” he said.
“It’s about time these organisations woke up and fixed their major vulnerabilities. Threat actors are constantly taking advantage of outdated security measures that make it easy, and inexpensive to breach systems.”
More broadly, the financial services sector has also been subjected to growing threats in recent years. Recent research from Imperva found that the volume of cyber threats directed towards the financial services and insurance industry (FSI) has grown rapidly over the course of 2022.
Imperva’s research found that across 2022, more than a quarter of all cyber attacks (28%) hit FSI businesses, double that of the next most-targeted sector.
Top-rated banks for security
Red Maple research noted that a number of leading UK banks boast robust security measures and safety for users.
Starling, which provides one of the UK’s most popular business current accounts, was ranked top for security.
The rapidly-growing challenger bank was followed closely by HSBC, NatWest, and Lloyds – all of which had strong security measures to protect customers.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
How the channel can simplify cybersecurity to build trust and agility for SMBs
Industry Insights There's an opportunity for the channel to move from tech resellers to trusted advisors on security and help alleviate the security burden on SMBs
By Ben Aung Published
-
Why ransomware attacks happen to small businesses – and how to stop them
In-depth With a surge in small business ransomware attacks, it's critical to know what makes your organization a target and what defensive measures you can take
By Kate O'Flaherty Published
-
Four measures SMBs can take to avoid common security pitfalls
In-depth Security can be challenging for SMBs, but it’s possible to make yourself more resilient to reduce the impact of cyber attacks
By Kate O'Flaherty Published
-
NCSC launches free in-browser security threat checks for SMBs
News The new cyber toolkits will help SMBs assess their cyber readiness in a matter of minutes
By Ross Kelly Published
-
Microsoft 365 security checklist
Whitepaper A practical guide for the time-strapped admin
By ITPro Published
-
Datto SMB cyber security for MSPs report
Whitepaper A world of opportunity for MSPs
By ITPro Published
-
State-sponsored hackers are diversifying tactics, targeting small businesses
News Research has warned that state-sponsored threat actors will increasingly target smaller enterprises in 2023
By Ross Kelly Published
-
How MSPs can capitalise on SMBs' security spending spree
Sponsored A single cyber attack can easily provide a death blow to SMBs and they’re now ready to spend their way to safety
By IT Pro Published