The advent of disruptive tech is exposing financial institutions to vulnerabilities they never had to contend with in the past. PA
The advent of disruptive tech is exposing financial institutions to vulnerabilities they never had to contend with in the past. PA
The advent of disruptive tech is exposing financial institutions to vulnerabilities they never had to contend with in the past. PA
The advent of disruptive tech is exposing financial institutions to vulnerabilities they never had to contend with in the past. PA

Cyber security: The new-age risk bankers are struggling to mitigate


  • English
  • Arabic

It is not boardroom pressure that keeps chief executives of global banks, who manage trillions of dollars in aggregate balance sheets, awake at night; rather, it's the increasing number of cyber security risks.

As the imprint of technology continues to deepen on the financial services sector and the push for digitisation in operations is growing, cyber security has risen to the fore.

Jane Fraser, the chief executive of Citigroup, says cyber security is the risk “you can't really control” despite the fact that the fourth-largest lender in the US is spending “a huge amount” to mitigate it.

“We have a lot of intelligence and other support around it but cyber I think is the risk to major ecosystems. That I think keeps most global bank CEOs up at night,” Ms Fraser told The National in an interview earlier this year.

Ahmed Abdelaal, chief executive of Dubai lender Mashreq, agrees.

“This is the number one threat on any board’s table. Period. Earlier, it used to be credit and compliance, but if it's not the case,” he said.

This is the number one threat on any board’s table
Ahmed Abdelaal,
chief executive, Mashreq Bank

“I can sit here talk to you for the next two hours about what we are doing in terms of innovation and transformation and business expansion, but if I'm not paying equal attention to this important front, then I'm not doing my job.”

The financial services and technology landscape are both evolving at a breakneck speed and the advent of disruptive tech such as the Internet of Things, machine learning and generative artificial intelligence are exposing financial institutions to vulnerabilities they never had to contend with in the past.

Global banks, wealth and asset managers and the insurance industry, as well a host of digital banks and FinTechs that have cropped up in the past decade are pouring in hundreds of billions of dollars a year in cyber security to protect their systems from attacks.

“They say when investigating criminal activity, you should 'follow the money'. When it comes to cyber threats, they also follow the money, making banks and financial institutions a big target,” James Maude, field chief technology officer of US cyber security company BeyondTrust, told The National.

“In general, the financial sector is uniquely exposed to cyber risks, that cannot only impact an individual but an entire economy, given the financial holdings combined with the vast amounts of personal data.”

Cyber security is the second most concerning challenge for banks in 2024, just behind inflation and high interest rates, a 2024 survey from UK research firm GlobalData found.

However, with bank chief security information officers contending with spending cuts, it has led to reduced cyber security budgets as a share of total revenue, Deloitte said in its 2023 cyber security report on financial institutions. Spending for cyber security still grew slightly, relative to total revenue in investment management, with digital transformation the top business driver, the London-based consultancy said.

Banks around the world are expected to spend more than $8.5 billion this year, nearly double the $4.29 billion they doled out in 2019, an April study from the Brazilian Banks Federation and Deloitte revealed.

JPMorgan, the biggest US bank that has been a victim of cyber breaches, had said it spends about $600 million per year for cyber security and claimed to repel about 45 billion attempted attacks per day. Bank of America, the second largest, said it raised its spending on the sector to $1 billion from 2021.

Regulatory scrutiny is also adding pressure. The EU, for instance, encouraged more spending after a landmark stress test for banks in June.

In the UAE, Mohammed Al Kuwaiti, chairman of the UAE Cybersecurity Council, recently announced that the executive regulations for an encryption law, which will establish key standards for data transmission security in line with quantum systems, are expected to be finalised before the end of the year.

On a broader scale, the value of the global banking cyber security market – which includes the tech, protocols and infrastructure to counter attacks – is projected to hit $282 billion by 2032, from an estimated $74.3 billion in 2022, growing at a compound annual rate of 14.4 per cent, data from Allied Market Research shows.

Will quantum computing pose a bigger threat?

A depiction of the interior of a quantum computer laboratory. Quantum computing uses highly-specialised technology to solve complex problems that traditional computers or even supercomputers cannot, or reduce the time it takes to solve them. Getty Images
A depiction of the interior of a quantum computer laboratory. Quantum computing uses highly-specialised technology to solve complex problems that traditional computers or even supercomputers cannot, or reduce the time it takes to solve them. Getty Images

While quantum computing is still about a decade or two away, depending on various estimates, it is a clear danger that requires investments in protection today.

Quantum computing uses highly-specialised technology to solve complex problems that traditional computers or even supercomputers cannot, or reduce the time it takes to solve them. A qubit – short for quantum bit – is the basic unit of quantum computing that is more versatile than binary bits in classical computers.

Quantum computers are exponentially faster than their counterparts. In 2019, Google claimed that its Sycamore chip was able to solve a mathematics problem – that would take 10,000 years – in just 200 seconds. However, the secure keys and firewalls that banks have in place to protect their systems can also be dismantled with quantum computing, experts say.

“The major concern is a very real possibility of current encryption methods being rendered almost instantly redundant by powerful quantum computers,” David Boast, managing director for the Middle East and North Africa at UK tech consultancy Endava, told The National.

“These encryption techniques are what currently underpin the secure storage and handling of data related to customer details, account balances, transaction histories, financial records, official communications and more.”

Vishal Pala, a senior solutions engineer at California-based Barracuda Networks, agrees: “A quantum computer will be able to crack almost any current cryptographic encryption – the foundation for almost all current security technology – in a matter of seconds.

“Highly-sensitive communications could be read or financial transactions could be hacked. This is a major concern for companies, banks, intelligence agencies and other organisations that rely on encryption to secure their data, but ultimately also for citizens,” he told The National.

It’s a never-ending race which top executives in financial services industry have to win, especially since criminals can go to any lengths to get into banking coffers. “I tend to agree as quantum computing journey is going to actually increase significantly the capacity and attributes of bad actors and people on the other side and less so for banks or financial institutions,” Mr Abdelaal said.

“Regardless of how much you invest in new technology, we are at disadvantage because we also have the vulnerability of our clients.”

Banks, he said, can protect their own shores and build super-smart firewalls with multiple layers of protection. However, a client clicking on a wrong link will dismantle everything. “This is also a key disadvantage that financial institutions have vis-a-vis bad actors,” he said, adding that Mashreq's annual spending is “an ever-evolving number”.

Costly price to pay

The financial sector is the second highest when it comes to monetary consequences, of cyber attacks with the average breach of data cost pegged at more than $6 million in 2024, IBM said in its latest industry report.

That's as much as 138 per cent higher than other industries except for healthcare, which tops the list. The industrial, technology and energy sectors rounded out the top five in IBM's Cost of Data Report – a list that proves cyber attackers are primarily targeting key industries vital to economies and societies.

What is needed is a balancing act for enterprises: keeping down financial damages and their fallout, while also ensuring cost-effectivity for the measures they take.

Companies can take advantage of AI, particularly behavioural analytics, which can be especially helpful in keeping bad actors out, Mr Boast said. “Spotting unusual patterns and detecting anomalies is a strong weapon in the chief security officer's arsenal.”

He argues that this is especially important in the Middle East, due to the heavy reliance on internet banking and e-interactions with customers. “The more data these protective systems have, the more useful they become … if this is not something you have considered, you should invest now,” he added.

When specifically dealing with the potential threats posed by quantum technology, post-quantum cryptography algorithms – one that cannot be easily cracked by quantum computers – is a viable option, Mr Pala said. “It remains essential to educate employees on cyber security best practices to reduce the risk of phishing and other social engineering attacks.”

In short, “get the biggest bang for your buck”, Mr Boast added.

The use of AI indeed helps: cost savings from the extensive use of the technology in cyber attack prevention showed that enterprises averaged $2.2 million less in breach costs compared to those with no AI use in prevention workflows, according to the IBM report.

“We have now entered the age of identity security where attackers find it easier to log in than hack in. This means we need to rethink our security approach to be more identity centric,” Mr Maude said.

Measures are already being taken by the banking sector globally as well. Last month, HSBC joined the Monetary Authority of Singapore for a collaboration on quantum security.

In 2023, the US National Institute of Standards and Technology teamed up with MasterCard and other industry players to develop and test post-quantum cryptography standards that can be used to secure financial data when the time comes.

Cryptography refers to the method of coding or hiding information so a message can only be read by the person it was intended for. “Defending against these attacks will call for financial institutions to fight fire with fire, deploying quantum computing and AI in defence,” Mr Boast said.

Race card

6.30pm: Emirates Holidays Maiden (TB), Dh82,500 (Dirt), 1,900m
7.05pm: Arabian Adventures Maiden (TB), Dh82,500 (D), 1,200m
7.40pm: Emirates Skywards Handicap (TB), Dh82,500 (D), 1,200m
8.15pm: Emirates Airline Conditions (TB), Dh120,000 (D), 1,400m
8.50pm: Emirates Sky Cargo (TB), Dh92,500 (D)1,400m
9.15pm: Emirates.com (TB), Dh95,000 (D), 2,000m

JOKE'S%20ON%20YOU
%3Cp%3EGoogle%20wasn't%20new%20to%20busting%20out%20April%20Fool's%20jokes%3A%20before%20the%20Gmail%20%22prank%22%2C%20it%20tricked%20users%20with%20%3Ca%20href%3D%22https%3A%2F%2Farchive.google%2Fmentalplex%2F%22%20target%3D%22_blank%22%3Emind-reading%20MentalPlex%20responses%3C%2Fa%3E%20and%20said%3Ca%20href%3D%22https%3A%2F%2Farchive.google%2Fpigeonrank%2F%22%20target%3D%22_blank%22%3E%20well-fed%20pigeons%20were%20running%20its%20search%20engine%20operations%3C%2Fa%3E%20.%3C%2Fp%3E%0A%3Cp%3EIn%20subsequent%20years%2C%20they%20announced%20home%20internet%20services%20through%20your%20toilet%20with%20its%20%22%3Ca%20href%3D%22https%3A%2F%2Farchive.google%2Ftisp%2Finstall.html%22%20target%3D%22_blank%22%3Epatented%20GFlush%20system%3C%2Fa%3E%22%2C%20made%20us%20believe%20the%20Moon's%20surface%20was%20made%20of%20cheese%20and%20unveiled%20a%20dating%20service%20in%20which%20they%20called%20founders%20Sergey%20Brin%20and%20Larry%20Page%20%22%3Ca%20href%3D%22https%3A%2F%2Farchive.google%2Fromance%2Fpress.html%22%20target%3D%22_blank%22%3EStanford%20PhD%20wannabes%3C%2Fa%3E%20%22.%3C%2Fp%3E%0A%3Cp%3EBut%20Gmail%20was%20all%20too%20real%2C%20purportedly%20inspired%20by%20one%20%E2%80%93%20a%20single%20%E2%80%93%20Google%20user%20complaining%20about%20the%20%22poor%20quality%20of%20existing%20email%20services%22%20and%20born%20%22%3Ca%20href%3D%22https%3A%2F%2Fgooglepress.blogspot.com%2F2004%2F04%2Fgoogle-gets-message-launches-gmail.html%22%20target%3D%22_blank%22%3Emillions%20of%20M%26amp%3BMs%20later%3C%2Fa%3E%22.%3C%2Fp%3E%0A
Five healthy carbs and how to eat them

Brown rice: consume an amount that fits in the palm of your hand

Non-starchy vegetables, such as broccoli: consume raw or at low temperatures, and don’t reheat  

Oatmeal: look out for pure whole oat grains or kernels, which are locally grown and packaged; avoid those that have travelled from afar

Fruit: a medium bowl a day and no more, and never fruit juices

Lentils and lentil pasta: soak these well and cook them at a low temperature; refrain from eating highly processed pasta variants

Courtesy Roma Megchiani, functional nutritionist at Dubai’s 77 Veggie Boutique

The specs

Engine: 2.0-litre 4-cyl turbo

Power: 247hp at 6,500rpm

Torque: 370Nm from 1,500-3,500rpm

Transmission: 10-speed auto

Fuel consumption: 7.8L/100km

Price: from Dh94,900

On sale: now

Moon Music

Artist: Coldplay

Label: Parlophone/Atlantic

Number of tracks: 10

Rating: 3/5

What can victims do?

Always use only regulated platforms

Stop all transactions and communication on suspicion

Save all evidence (screenshots, chat logs, transaction IDs)

Report to local authorities

Warn others to prevent further harm

Courtesy: Crystal Intelligence

Specs

Engine: 51.5kW electric motor

Range: 400km

Power: 134bhp

Torque: 175Nm

Price: From Dh98,800

Available: Now

COMPANY PROFILE
Name: Kumulus Water
 
Started: 2021
 
Founders: Iheb Triki and Mohamed Ali Abid
 
Based: Tunisia 
 
Sector: Water technology 
 
Number of staff: 22 
 
Investment raised: $4 million 
How to apply for a drone permit
  • Individuals must register on UAE Drone app or website using their UAE Pass
  • Add all their personal details, including name, nationality, passport number, Emiratis ID, email and phone number
  • Upload the training certificate from a centre accredited by the GCAA
  • Submit their request
What are the regulations?
  • Fly it within visual line of sight
  • Never over populated areas
  • Ensure maximum flying height of 400 feet (122 metres) above ground level is not crossed
  • Users must avoid flying over restricted areas listed on the UAE Drone app
  • Only fly the drone during the day, and never at night
  • Should have a live feed of the drone flight
  • Drones must weigh 5 kg or less
If you go

 

  • The nearest international airport to the start of the Chuysky Trakt is in Novosibirsk. Emirates (www.emirates.com) offer codeshare flights with S7 Airlines (www.s7.ru) via Moscow for US$5,300 (Dh19,467) return including taxes. Cheaper flights are available on Flydubai and Air Astana or Aeroflot combination, flying via Astana in Kazakhstan or Moscow. Economy class tickets are available for US$650 (Dh2,400).
  • The Double Tree by Hilton in Novosibirsk ( 7 383 2230100,) has double rooms from US$60 (Dh220). You can rent cabins at camp grounds or rooms in guesthouses in the towns for around US$25 (Dh90).
  • The transport Minibuses run along the Chuysky Trakt but if you want to stop for sightseeing, hire a taxi from Gorno-Altaisk for about US$100 (Dh360) a day. Take a Russian phrasebook or download a translation app. Tour companies such as  Altair-Tour ( 7 383 2125115 ) offer hiking and adventure packages.
Labour dispute

The insured employee may still file an ILOE claim even if a labour dispute is ongoing post termination, but the insurer may suspend or reject payment, until the courts resolve the dispute, especially if the reason for termination is contested. The outcome of the labour court proceedings can directly affect eligibility.


- Abdullah Ishnaneh, Partner, BSA Law 

Profile of Foodics

Founders: Ahmad AlZaini and Mosab AlOthmani

Based: Riyadh

Sector: Software

Employees: 150

Amount raised: $8m through seed and Series A - Series B raise ongoing

Funders: Raed Advanced Investment Co, Al-Riyadh Al Walid Investment Co, 500 Falcons, SWM Investment, AlShoaibah SPV, Faith Capital, Technology Investments Co, Savour Holding, Future Resources, Derayah Custody Co.

Five%20calorie-packed%20Ramadan%20drinks
%3Cp%3E%3Cstrong%3ERooh%20Afza%3C%2Fstrong%3E%0D%3Cbr%3E100ml%20contains%20414%20calories%0D%3Cbr%3E%3Cstrong%3ETang%20orange%20drink%3C%2Fstrong%3E%0D%3Cbr%3E100ml%20serving%20contains%20300%20calories%0D%3Cbr%3E%3Cstrong%3ECarob%20beverage%20mix%3C%2Fstrong%3E%0D%3Cbr%3E100ml%20serving%20contains%20about%20300%20calories%0D%3Cbr%3E%3Cstrong%3EQamar%20Al%20Din%20apricot%20drink%3C%2Fstrong%3E%0D%3Cbr%3E100ml%20saving%20contains%2061%20calories%0D%3Cbr%3E%3Cstrong%3EVimto%20fruit%20squash%3C%2Fstrong%3E%0D%3Cbr%3E100ml%20serving%20contains%2030%20calories%3C%2Fp%3E%0A
In numbers: China in Dubai

The number of Chinese people living in Dubai: An estimated 200,000

Number of Chinese people in International City: Almost 50,000

Daily visitors to Dragon Mart in 2018/19: 120,000

Daily visitors to Dragon Mart in 2010: 20,000

Percentage increase in visitors in eight years: 500 per cent

Avatar%3A%20The%20Way%20of%20Water
%3Cp%3E%3Cstrong%3EDirector%3A%20%3C%2Fstrong%3EJames%20Cameron%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStars%3A%20%3C%2Fstrong%3ESam%20Worthington%2C%20Zoe%20Saldana%2C%20Sigourney%20Weaver%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%20%3C%2Fstrong%3E3.5%2F5%3C%2Fp%3E%0A
Wenger's Arsenal reign in numbers

1,228 - games at the helm, ahead of Sunday's Premier League fixture against West Ham United.
704 - wins to date as Arsenal manager.
3 - Premier League title wins, the last during an unbeaten Invincibles campaign of 2003/04.
1,549 - goals scored in Premier League matches by Wenger's teams.
10 - major trophies won.
473 - Premier League victories.
7 - FA Cup triumphs, with three of those having come the last four seasons.
151 - Premier League losses.
21 - full seasons in charge.
49 - games unbeaten in the Premier League from May 2003 to October 2004.

The President's Cake

Director: Hasan Hadi

Starring: Baneen Ahmad Nayyef, Waheed Thabet Khreibat, Sajad Mohamad Qasem 

Rating: 4/5

Rajasthan Royals 153-5 (17.5 ov)
Delhi Daredevils 60-4 (6 ov)

Rajasthan won by 10 runs (D/L method)

TECH%20SPECS%3A%20APPLE%20WATCH%20SERIES%208
%3Cp%3E%3Cstrong%3EDisplay%3A%3C%2Fstrong%3E%2041mm%2C%20352%20x%20430%3B%2045mm%2C%20396%20x%20484%3B%20Retina%20LTPO%20OLED%2C%20up%20to%201000%20nits%2C%20always-on%3B%20Ion-X%20glass%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EProcessor%3A%3C%2Fstrong%3E%20Apple%20S8%2C%20W3%20wireless%2C%20U1%20ultra-wideband%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ECapacity%3A%3C%2Fstrong%3E%2032GB%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EMemory%3A%3C%2Fstrong%3E%201GB%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EPlatform%3A%3C%2Fstrong%3E%20watchOS%209%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EHealth%20metrics%3A%3C%2Fstrong%3E%203rd-gen%20heart%20rate%20sensor%2C%20temperature%20sensing%2C%20ECG%2C%20blood%20oxygen%2C%20workouts%2C%20fall%2Fcrash%20detection%3B%20emergency%20SOS%2C%20international%20emergency%20calling%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EConnectivity%3A%3C%2Fstrong%3E%20GPS%2FGPS%20%2B%20cellular%3B%20Wi-Fi%2C%20LTE%2C%20Bluetooth%205.3%2C%20NFC%20(Apple%20Pay)%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EDurability%3A%3C%2Fstrong%3E%20IP6X%2C%20water%20resistant%20up%20to%2050m%2C%20dust%20resistant%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EBattery%3A%3C%2Fstrong%3E%20308mAh%20Li-ion%2C%20up%20to%2018h%2C%20wireless%20charging%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ECards%3A%3C%2Fstrong%3E%20eSIM%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EFinishes%3A%3C%2Fstrong%3E%20Aluminium%20%E2%80%93%20midnight%2C%20Product%20Red%2C%20silver%2C%20starlight%3B%20stainless%20steel%20%E2%80%93%20gold%2C%20graphite%2C%20silver%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EIn%20the%20box%3A%3C%2Fstrong%3E%20Watch%20Series%208%2C%20magnetic-to-USB-C%20charging%20cable%2C%20band%2Floop%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EPrice%3A%3C%2Fstrong%3E%20Starts%20at%20Dh1%2C599%20(41mm)%20%2F%20Dh1%2C999%20(45mm)%3C%2Fp%3E%0A

Small Victories: The True Story of Faith No More by Adrian Harte
Jawbone Press

Updated: September 15, 2024, 5:14 AM