Cyber Security is one of the most pressing matters facing financial institutions around the world following the widespread implementation of Information Technology (IT) in the banking sector. Banks and financial entities within the Asia Pacific (APAC) region are not exempted from the trouble. Even more so, APAC banks could face higher risks due to the region’s favourable economic growth that comes with complex and large-volume IT arrangement.
In the S&P Global Ratings’ 2024 Financial Institutions Virtual Conference, such IT threats and counter solutions were amply covered by panelist Sandro Bucchianeri, Group Chief Security Officer (CSO) of the National Australia Bank (NAB).
When asked about his most pressing concerns amid emerging cyber threats, the CSO replied that his major worries are cyber breach on the supply chain and private data collection aided by Artificial Intelligence (AI). He said some lower-tier supply chain vendors do not have a large security budget. The attackers target those that compromise more easily so they can get into the organisation. As for the consumers, they receive better AI-crafted scam emails that appear genuine. “You cannot tell the difference whether it comes from your bank or the scam artist,” he added.
In the fight against cyber threats, business organisations should focus on the ‘basics’ including patch management, identity access and security provision that should be implemented well on a daily basis. In other words, good security management should start from the onset, making sure that anything going into the organisation is secured by design.
The CSO noted, ” NAB is a major bank that is subject to stringent regulatory standards. We have supported several proposals in the Australian Cyber Security Strategy roadmap.” Notably, owing to such initiative, new laws have been enacted to protect critical infrastructure of Australia including cyber assets.
“Legislation is exceptionally important in supporting our intention to improve legal construct and policy framework to make sure that everybody is singing from the same hymm sheet.” He continued, “Clear and consistent rules will effect faster building of public trust and confidence on proposed regulatory changes.”
On external vendors who are not regulated to the same extent, he said the Australian Prudential Regulatory Authority (APRA) requires the bank to be CPS234-compliant and at the same time to uphold high security standards among the third and fourth party vendors associated with the bank. “The vendors must ensure that they can give you the confidence that they are taking care of the data that you have handed over to them,” he noted. Ultimately, the customers are concerned about dealing with the bank rather than the outsource vendor.
“Due to the interconnection of the modern business, we have thousands of vendors within a multi-tier supply chain. Having visibility of the security processes of these vendors makes it easy for me, the security officer, to manage cyber risks,” he added. However, uniform security processes are absent further down the tiers as the budget for security becomes smaller and smaller.
“That’s why I keep reiteracting the basics of security related to badge management and identity access. The Australian Cyber Security Centre endorses these essential measures as great security mechanism. If followed, an organisation is relatively protected. Obviously there are other things that the organisation needs to do but it’s a great starting point,” said the CSO.
One important thing about any third party contract is the inclusion of sound terms and conditions that cover the relevant security provisions. If something should go wrong, the business can seek accountability from the vendors.
On the size of the monitoring team, the CSO said it could involve hundreds of people. However, it’s not restricted to a team that focuses on monitoring the vendors. Rather, it’s a collective effort across the security, procurement and various other departments.
The CSO also recommended the use of financial reports to monitor the level of security of a business as the reports contain commentaries about security risks. He added that NAB uses Nist which is a maturity level model. Generally, the higher the Nist score, the more matured the security function, and the higher the cost. With regards to third party monitoring, he said Bitsight and Black kite are useful as they award security score cards related to security management: Are the businesses patching up their system? Are they making sure that their certificates are not expired?
According to the CSO, collaboration is the ticket to the cyber game. “If we don’t collaborate, we will all be sitting in a silo saying our walls are safe.” To him, it is exceptionally important that government and industries work together along with their vendors as they may all use Microsoft and Crowdstrike. He noted that NAB is a member of the Strategic Banking Alliance working with banks from the UK and Canada on broader threats that involve cross-border jurisdiction.
He also warned against casual attitude when using cyber tools in the absence of physical threats. “When you are at home browsing the internet with your laptop, clicking on all sorts of links doesn’t seem to matter because your physical safety need is removed from the equation. That’s why people end up clicking dangerous links leading to fraud and scam.”
Talking about the impact of a cyber attack, he said the bank is a customer-oriented organisation where the customers experience the loss of access to their bank account and also the loss the trust. The bank’s reputation is tarnished as the wider financial system struggles to cope with the attack. For example, electronic terminals could be shut down causing patrons of a local supermarket unable to pay for their purchased goods.





