Thread regarding Wells Fargo & Co. layoffs

Risk associated with outsourcing/offshoring sensitive financial data to India

Happened to meet a friend of a friend today who is a lawyer and a data security and privacy officer for a large investment company. I asked him a lot of questions. He talked about part of his job being to limit access to data only to employees who can demonstrate the need for access to such information in order to perform their job duties etc

I asked him if his company offshores to India, and if so, would he allow access to sensitive financial data to employees in India? He laughed and said NO. “We want to keep that data in-house in order to maintain proper controls.” He said “We would never allow the elevated risk inherent in sharing financial data and intellectual property with an outside partner. That would substantially increase the risk of security breaches and data loss.”

I wonder how Wells Fargo rationalizes it??

by
| 3472 views | | 33 replies (last July 31, 2023) | Reply
Post ID: @OP+1nQkerFD

33 replies (most recent on top)

WF has been allowing India to access US customer data for many years via WF systems. This is old news.

One of the problems now is that WF allows India to WFH for various reasons and THAT is a new risk that WF doesn’t seem concerned about any longer. India sites encouraged their employees to WFH several days in the last month due to heavy rain and traffic in India. When an Indian is WFH they can easily photograph that data on their cell camera where as when in the office environment some areas are not permitted to have cell phones for that very reason.

Unfortunately WF no longer considers India as our back up site but instead as US equals and with no greater risk concerns than if the work is done is Charlotte.

Sad times for American employees!

by
| | Reply
Post ID: @2snk+1nQkerFD

Use turbotax desktop, not online
Data will reside on your own PC

by
| | Reply
Post ID: @2nhe+1nQkerFD

OP- it’s where the data resides. So while work is offshored it does not mean the data was offshored . They are accessing it , yes , by logging into US based systems.

by
| | Reply
Post ID: @2dne+1nQkerFD

Japan has struck rules on maintaining their information outside of their borders. There are other countries that do this as well.

by
| | Reply
Post ID: @2ptp+1nQkerFD

Most of the executives won’t be held accountable either way, and even if they are they’ll still receive a golden parachute..

by
| | Reply
Post ID: @1rky+1nQkerFD

@pcf+1nQkerFD

Yeah, well, at least the boomers aren't running around believing that communism is a great idea that we should give a try.

by
| | Reply
Post ID: @1ajp+1nQkerFD

Oh actually, I didn't see that you went out of your way to point out that the "friend" actually works at an "Investment company", and with "a stock price much higher than Wells" I'm sure the transparent appeal to authority lends all the credibility to the OP that anyone could ever want. I retract my criticism in the face of such a master logician.

by
| | Reply
Post ID: @oih+1nQkerFD

@uyf+1nQkerFD If I told you it was indeed magic, I'm sure you'd take me at face value given how readily you think anyone would believe the OP 😉 But nice try trying to paint anyone calling you out as the actual trolls, once again.

by
| | Reply
Post ID: @pxd+1nQkerFD

Post ID: @zdd+1nQkerFD

Do you have magical vote spyware? How do you determine which votes are legitimate and which are not? Are you down ticking your own posts because you want to be seen as some mega-troll?

by
| | Reply
Post ID: @uyf+1nQkerFD

@dpz
You said "I won't go into all the reasons here but basically I found doing it myself was the best solution." Does this mean you had trouble working with your counterparts in India? Were they qualified? Did they understand relational databases and how to create data for them?

by
| | Reply
Post ID: @zym+1nQkerFD

@cuw+1nQkerFD I’m sorry that being exposed hurt your ego so much. Hopefully those upvotes you just gave yourself again will make it all better.

by
| | Reply
Post ID: @zdd+1nQkerFD

Post ID: @zky+1nQkerFD

Calm down. You undermine your defense of Wells Fargo’s position with your frantic multiple posts, name-calling, finger-pointing and false accusations. You are not acting in Wells Fargo’s (or anyone’s) best interests.

by
| | Reply
Post ID: @cuw+1nQkerFD

@dpz Is such a computer wiz you can watch him upvoting his own comment over and over right now lol

by
| | Reply
Post ID: @zky+1nQkerFD

@tkt Conservative boomers can only accept something as fact if it's presented as part of a folksy anecdote by some anonymous "expert" online

by
| | Reply
Post ID: @pcf+1nQkerFD

Before I was laid off, I worked on an application that was quickly sent to India. I was impressed with how quickly it reached the team there. However, I noticed that the data they worked with in India was not anonymized or synthetic; it was real data with actual names, contracts, and other sensitive information.
Later, I and a couple of Indian developers were asked to create routines to scramble the data for the test and development environments. It felt like another rushed decision made after the fact. Maintaining data integrity while obfuscating it proved to be much more challenging than expected, and the risks associated with handling real sensitive data were concerning. Creating and testing these "data load" routines was tedious and took time. I won't go into all the reasons here but basically I found doing it myself was the best solution.
Unfortunately, in typical Wells fashion, we were not allowed to use tools that would aid in this process, adding further complications to the task.
Charlie aided with his JPM buds seemed to focus on the advantages of offshoring without fully considering the costs and complexities involved. The practical implementation of offshoring faces significant hurdles and risks -- something I suppose the expensive McKinsey consults have missed telling him.

by
| | Reply
Post ID: @dpz+1nQkerFD

@lwr+1nQkerFD Exactly, some people here have no idea what happens in the world around them. This has been going on for decades and FI's are perfectly aware of any risks. This is such a weird angle to take and is the clear obsession with one specific troll here.

All that being said, the little anecdote in the OP is very obviously a tall tale so this nutcase can launder his opinions as those of an expert he made up 😂

by
| | Reply
Post ID: @tkt+1nQkerFD

H1b visa workers too

by
| | Reply
Post ID: @ouw+1nQkerFD

Indians aren't a homogeneous group. The biggest scammers in the world are in Indian. Some of the absolute most honest and honorable people I have ever met are Indians.

by
| | Reply
Post ID: @gwk+1nQkerFD

External audit firms are considering increasing the frequency and volume of testing over Financially-relevant activities overseas. So there is a direct cost associated with this risk from a Financial Statement compliance perspective.

by
| | Reply
Post ID: @ccn+1nQkerFD

The rationalization is easy. The data resides in the US on-prem and in the cloud. Indian employees are mandated to use VDI.

The files they access stay in the US. The VDI session they access is running in the US and what they see on their screens is an image of it transmitted to the device they are on.

So they can claim the data never actually leaves the US.

by
| | Reply
Post ID: @tzl+1nQkerFD

I would be embarrassed to use the “But everyone else is doing it” defense, an immature plea to rationalize our failures and transgressions.

by
| | Reply
Post ID: @azf+1nQkerFD

@qvi+1nQkerFD You don’t think Fidelity, Schwab, Goldman Sach, Morgan Stanley… do the same thing? Nothing new here.

by
| | Reply
Post ID: @lwr+1nQkerFD

I guess this is a situation where we need to get congressional action. We've had even just recently times when both houses of congress plus the president were all Democrat. We then had both houses of congress plus the president were Republican. It's happened repeatedly and yet there's virtually nothing being done to stop our data from being sent outside the country.

We as individuals need to make our 70, 80, 90+ year old congressional leaders understand that it's wrong for it to be legal to send personal data of US citizens outside of the USA.

by
| | Reply
Post ID: @iwb+1nQkerFD

Post ID: @nod+1nQkerFD

OP here: I didn’t say bank, I said Investment company. This man works for a publicly held company with a stock price much higher than Wells.

Additionally, just because other companies do it doesn’t mean they are right. These executives all follow each other like puppy dogs with FOMO. See the subprime mortgage crisis 2008.

by
| | Reply
Post ID: @qvi+1nQkerFD

Just checked, per a Glassdoor review H&R Block is also displacing HQ employees due to outsourcing in India. That’s another 21.6 million Americans filing taxes (with sensitive information) through this service.

by
| | Reply
Post ID: @jrx+1nQkerFD

Obviously he doesn’t work for Intuit -Turbo Tax. They have been outsourcing to India for over 15 years. And, 46% of American taxpayers use this online service. That’s the holy grail of sensitive information.

by
| | Reply
Post ID: @orn+1nQkerFD

Every bank with a presence in India already does the same. So either OP is stirring up junk or their “friend” is either lying or works at a much smaller company with limited presence.

by
| | Reply
Post ID: @nod+1nQkerFD

India is a third world dirt poor country. That is the last place we should be sending confidential information such as everyone’s paystubs and tax returns too! Wells Fargo should be buying theft protection to every single customer!

by
| | Reply
Post ID: @gtd+1nQkerFD

Well Chase already has all Credit Card Operations executed from India. So definitely there is confidence 😀

by
| | Reply
Post ID: @wtc+1nQkerFD

Nobody but @OP cares. Must be a worthless ORC.

by
| | Reply
Post ID: @ihj+1nQkerFD

Charlie has been actively trying to burn this place to the ground since he got here. He’s more determined than ever now since he’s yet to be called out publicly on his actions. I don’t know why people aren’t paying attention. It’s so egregious.

by
| | Reply
Post ID: @dps+1nQkerFD

I thought Wells would at least wait until after the consent orders were all lifted before doing anything to put the company data at risk, but no. None of this makes sense anymore. Do your banking with a credit union. They're one of the only ways to ensure the employees are actually local and that the overall financial institution isn't big enough to have economy of scale to outsource jobs to a foreign country.

by
| | Reply
Post ID: @onc+1nQkerFD

They don't....

by
| | Reply
Post ID: @mel+1nQkerFD

Post a reply

: