Protecting banks from cyberattacks
Sunday, 15 October 2023
With digitisation progressing at a fast pace in most sectors of national life, the need for ensuring cybersecurity cannot be overemphasized. The banking sector in particular needs to take the issue of protecting itself from onslaught by cyber criminals more seriously than others for understandable reasons. Any ad-hoc approach to cybersecurity is a foolhardy exercise, observed in a keynote paper presented at an event organized by the Bangladesh Institute of Bank Management (BIBM) late last week in Dhaka. The paper suggested sustained investments in the latest technology and development of human resources to help build firewalled networks.
The country experienced history's worst cyber-heist when in February 2016 hackers breached Bangladesh Bank BB)'s security system and robbed it of valuable forex reserves from its account maintained with the New York Fed. Notably, the hackers used the SWIFT messaging network to transfer the money from BB's account. In recent times, also, several government websites that are the repositories of sensitive citizens' information, most notably, the leaking of the personal information of 55 million Bangladeshis. Cybersecurity breaches of such magnitude are both unheard of and alarming. The availability of personal information of NID cardholders in a Telegram channel is the latest incident that highlights the woefully inadequate digital safeguards that authorities had supposedly put to keep the information confidential. Such a lacklustre approach to safeguarding information is part of the lack of awareness of how this information may be manipulated by enemies of the State and criminals who deal in the sale of personal data. That said, the BIBM paper further stressed that the country's banking sector needs to evolve and modernise its operation to take cognizance of threats posed by digital criminals. There needs to be recognition by bank management that cybersecurity is the next battleground for illegal intrusion and that trading of personal financial records is part of a lucrative multi-billion-dollar international black market. Hence, it has become imperative that the financial sector of the country takes proactive measures to build its technical capacity in both manpower and software to safeguard the information of clients against cyber criminals.
The banks are more than institutions that safeguard financial assets. They also play a major role in maintaining financial stability in the country. Speakers at the discussion emphasized the need for enhancing the quality and continual evolution of strategies to tackle cyber threats as they too evolve. These are issues that require support from the top management of financial institutions that need to arm themselves with the requisite technology - hardware, software and technical expertise to keep abreast of the latest threats and act accordingly. It is also imperative that there is effective collaboration among banks, stakeholders and government agencies to strengthen the incident response ecosystem.
The series of cyber attacks on Bangladesh institutions, such as the NID server and the earlier ones bring up the question of our response. Steps should have been taken to strengthen the security of all servers in both the public and private sectors to safeguard sensitive information. The repeated security breaches speak volumes for the laid-back attitude of the custodians of information. It is to say the least that a country that has made digitisation the cornerstone of its policymaking, is not making the effort needed to produce its digital warriors to push back against illicit operations to rob the nation of its sensitive information.