enterprisesecuritymag

OCTOBER 2024ENTERPRISE SECURITY| | 19requires banks to adapt strategies to comply with evolving regulations while maintaining business agility. For instance, we need to implement thorough and ethical simulations to comprehensively understand the tools and methods used by attackers. This requires significant investment as we need to understand the current tactics employed by them.What innovative developments in cyber risk management do you anticipate will ensure user safety?Cyber risk management involves four key dimensions, which include people, processes, technology and governance. The focus is fixed on raising awareness and fostering a security-focused culture among customers, emphasizing secure practices like protecting PINs and being vigilant against fraudsters by contacting via various channels like phone calls, messages, WhatsApp or emails. On the process side, measures like zero-trust steps are implemented in mobile banking applications to minimize risks. For example, it is essential to verify the authenticity of the recipient when initiating a top-up or transfer. Payments should only proceed if the recipient's details are confirmed. Users can further authenticate transactions by receiving OTPs on their registered phone numbers and inputting them into the application. This process helps mitigate risks associated with mobile banking.Technologically, the deployment of detection systems helps in identifying unauthorized devices or malware and prevents risky transactions. Proper governance ensures compliance with regulatory standards, integrating cyber risk into overall business risk management strategies.Can you discuss the key aspects of a recent project you have been involved in?We highlight the importance of initiatives like enhancing incident response capabilities. This offers mutual benefits for IT and risk management and also enables effective communication on the business side. It allows us to promptly identify and address any digital impersonations of our products or services in the public domain. Detecting these instances early on minimizes the risk of attackers exploiting them to harm our customers. Through proactive monitoring, we can respond to potential threats, akin to a cat catching a mouse. We also collaborate with global third parties to remove unauthorized applications and report them to regulators. Strengthening incident response capabilities involves conducting tabletop exercises and optimizing communication protocols to ensure swift responses. Employee security awareness training is crucial to establish a baseline for safeguarding both our employees and customers against fraudulent activities.What is your sage advice for professionals in similar roles across companies?It is crucial to foster a culture of cybersecurity risk awareness across all levels of the organization. This involves ensuring everyone understands that cybersecurity is part of business risk and not solely a technological concern. Regular self-assessment and simulation exercises are essential to gauge our readiness and identify vulnerabilities. Staying updated on the latest threats and collaborating with industry peers and regulators are key strategies to effectively mitigate cyber risks. ESDEPLOYMENT OF DETECTION SYSTEMS HELPS IN IDENTIFYING UNAUTHORIZED DEVICES OR MALWARE AND PREVENTS RISKY TRANSACTIONS
< Page 9 | Page 11 >