More than half of British and foreign banks operating in the UK were found to have insecure SSL instances on the Login page of their Web portals.

Most banks today provide a banking portal where their customers can log in and manage their bank accounts. High security is crucial for such portals, such as the transaction pages, account history, and user settings page.
While all of this is critical, there is another place where bank security must be paramount, which is the page where users validate their identity: the login page.
60% of UK banks have failed to implement SSL. According to research by security expert Mike Kemp:
· Of the 22 UK state-owned banks audited, 50% were found to have insecure SSL
· Of the 25 foreign state-owned banks operating in the UK that were examined, 79% have insecure SSL
· Of the 37 UK banking associations examined, 51% have insecure SSL
The worst part was that 12 of the 84 tested received an F grade, which Kemp described as shockingly bad.
Some of the attacks that banking institutions are susceptible to are POODLE, CRIME, BEAST, and Lucky 13 attacks.
Kemp tried to contact all the banking organizations but couldn't get through to the call centers and decided to inform the National Crime Agency and the Financial Conduct Authority.
