Reliable Brokers
Online Investing
Alerts & Analysis
Easy Trading

OP-ED

Cyber digital transformation – a must for the future of banking

Digital Transformation is not only the technology development but transforming the business

Update : 20 Jun 2022, 06:49 PM

Banks are taking multiple digital transformation initiatives for the benefit of business and customer demands.

Digital Transformation is not only the technology development but transforming the business.

It happens through redesigning the processes, products, or services; banks are utilizing artificial intelligence and transforming through robotic process automation, the internet of things, big data analytics, etc. 

While banks are doing digital transformation, it also increases the risk of cyber-attacks.

Cybersecurity is now mandatory to be an integrated part of digital transformation. It should work together with product design from the beginning.

However, cybersecurity alone is insufficient, and banks need cyber-resilience as a critical component of digital transformation.

Cyber-resilience is significant to data and system availability.

Without a proper cyber digital transformation resiliency, the bank will find themselves more vulnerable to cyber-attack, which can destroy the whole business. 

Calculating the cost of a cyber-incident is not straightforward.

The cost of direct business can be identified easily.

Still, while calculating the overall cost of business, it is equally important to consider employee productivity loss, business operation, damage to the organization's reputation, cost of business opportunity, etc.

A ransomware attack can destroy the whole business.

Even paying a hefty ransom doesn't ensure the company is restored.

Neither the cyber digital transformation resilience journey itself is straightforward. It requires a corporate cultural shift.

Banks need to build specific capabilities for identifying and properly treating cyber risks to the organization.

Technology, processes, and people are the critical element of this journey.

Proper engagement and effective coordination are vital for any digital transformation to any crisis management situation.

Why it is needed

Though most digital-focused banks are going through some digital transformation, cyber digital transformation resiliency has yet to be developed for most of the banks.

Still, some of them are primarily compliance-focused.

However, other elements are also essential, like protecting data assets, maintaining customer and consumer trust, and third-party relationships.

Adaptable digital security is considered the main element for successful cyber digital transformation.

Others like addressing the persistent threat, risk and trust, compliance, data analytics, technology proliferation, and talent shortage.

It is good that banks are considering cybersecurity, but they sometimes face challenges while communicating about cybersecurity.

Both for cyber digital transformation and resiliency, effective communication is most vital.

Cross-functional departments need to communicate effectively on cyber reliance.

Internal and external stakeholders need to be adequately aware of cybersecurity.

Since cybersecurity is a top-down approach, it requires appropriate directives and escalations.

Focus from the board is necessary, which is possible through effective communication.

Businesses must understand the value; only a common language can bridge cybersecurity and IT/business. 

Cyber digital transformation resiliency strategy starts in mind that an attack may happen.

So, a crisis management plan and practical readiness for the response are essential. Risk culture is primarily influential.

Effective communication, continuous management, and board culture support can help build it.

Understandable for all

Security issues and requirements need to be converted into business language, so that management, the board, and everybody must understand.

Data is most important in this digital world.

In this challenging environment, effective communication means data for the suitable receiver at the right moment.

The only approach is not enough to get the best outcome, and it is vital if the receivers understand the message. 

A bank should consider reputation as the top to establish a risk culture.

Risk management strategy (e.g., Risk appetite, Crisis management plan, etc.) should be developed and effectively communicated with the stakeholders.

As the likelihood of falling victim to a cyber-attack has increased over time, so too, the need to understand precisely what is effective corporate communication after an attack and how best to engage the concerns of customers, partners, and other stakeholders.

Cybersecurity is a shared responsibility, and all departments should own it.

Frequent cross-functional meetings and activities may help to overcome the isolation attitude.

In addition, it is essential to take cybersecurity awareness initiatives for external stakeholders.

They are also responsible for their part. 

Cyber-attacks are changing their pattern every day. So, situation awareness communication should be regular.

Case study-based communication may help to understand better by all stakeholders.

In case of any regulatory change or new regulatory guidelines in cybersecurity, it is vital to communicate it effectively with all stakeholders.

Regular meeting with the stakeholders is an excellent approach to ensure compliance.

A spokesperson should be defined before communicating with external stakeholders.

Frequent collaboration with external bodies should be provided.

Stakeholders’ trust is critical, so making any communication should be in a proper way.

People are the essential part of cyber digital transformation resilience.

During a business meeting, the security team should be invited and appropriately privileged to provide their input.

In addition, cyber education should be ensured for both technical and non-technical stakeholders.

Particular cyber-attacks or vulnerabilities may miss the attention of the media; through a common forum, learning or understanding can be shared with other organizations for proactive measures.

A recent comment I found on LinkedIn made me think. 

It was in response to a post on zero-day vulnerabilities and software patching, and roughly translated from the French, it read as follows:

 “One day, I was standing in front of the Ex Co having to explain how the millions spent on cyber over the years have improved their level of protection; then while go back to my desk discovered that three new vulnerabilities have just turned up, which need patching across the entire estate; Welcome to my world !!!"

Cybersecurity is not a one-time exercise; digital-focused banks must continuously monitor assets for the likelihood and potential severity of cyber-attacks.

An integrated defence with digital transformation is the only defence for a digital-focused bank.

A business to be resilient should combine a proper risk management plan to manage any disruptive changes better and protect stakeholders’ values.

To accelerate business resilience planning, an organization must consider cybersecurity as an integrated part of their business continuity and risk management strategy.

There should be no more cybersecurity as a separate topic but rather a shift to digital security for business transformation.

 

The author is an information security and cyber digital transformation specialist

Top Brokers