Threat landscape
Customer trust
Cost optimization
Regulation
Digital security
Third party
Key questions to consider:
What am I trying to protect my business and critical assets from?
How do I continuously monitor exposure to cyber threats?
Financial services organizations which proactively navigate the evolving threat landscape can position their proactivity for growth. Key themes in the threat landscape conversation include:
Key questions to consider:
How do I manage my customers’ expectations on cyber security?
If my competitors are ahead of me, does this give them an advantage?
Organizations must consider trust and safety when analyzing their business security functions and protecting the needs of their customers. Building a trust agenda that is integrated throughout the customer journey is critical in every organization and can be achieved through:
Key questions to consider:
How much should I spend annually on cyber security?
What is the balance between capability maintenance and capability investment?
How does our cyber spend compare with competitors?
The number of security tools available to organizations has grown significantly. They are tasked with implementing the right tools and connecting them flawlessly and consistently through every layer of the business. Organizations are able to navigate this complex process by investing in intelligent and agile high-end solutions to produce process excellence across all control functions, thereby increasing cost efficiencies and driving business value and market agility.
Key questions to consider:
Who on the board owns cyber risk?
What are the key metrics of focus for cyber security within financial organizations?
How do I ensure compliance with complex regulatory requirements?
What should be the key business processes and information assets critical to maintaining the core business operation?
Globally, regulators are focused on two areas with cyber security relevance:
Key questions to consider:
What are the right cyber security considerations when developing our digital strategy?
How well integrated are our digital security tools? Do they link into our fraud monitoring tools and anti-money laundering tools?
Organizations are becoming increasingly digitized – as they compete with new technology enabled entrants (including Virtual Banks). This significantly increases the pace of digital transformation, requiring an acceleration in digital risk management. Within the digital bank, organizations are experimenting with self-learning and self-defending solutions to maintain pace with the evolving technological landscape. There is also a focus on enabling seamless security experiences across multiple customer channels (e.g. mobile, web, ATM, branch).
Key questions to consider:
How do I build a comfort level with third party risk?
How can I identify which of our supply chain partners could put us at risk?
Third party concerns remain a perennial concern in the organization with boards acknowledging that third parties represent a key vulnerability in any system. There is increased awareness and interest in exploring real-time supply chain monitoring tools and more organizations recognize that third party risk cannot adequately be mitigated by annual third party reviews. Developing and implementing a third party risk management approach including: governance and operating models, role of three lines of defense and technology tools is important for protection and innovation within banks.