Happened to meet a friend of a friend today who is a lawyer and a data security and privacy officer for a large investment company. I asked him a lot of questions. He talked about part of his job being to limit access to data only to employees who can demonstrate the need for access to such information in order to perform their job duties etc
I asked him if his company offshores to India, and if so, would he allow access to sensitive financial data to employees in India? He laughed and said NO. “We want to keep that data in-house in order to maintain proper controls.” He said “We would never allow the elevated risk inherent in sharing financial data and intellectual property with an outside partner. That would substantially increase the risk of security breaches and data loss.”
I wonder how Wells Fargo rationalizes it??