News

Beyond the Firewall: Why Tech, Trust, and Training are the New Financial Security Currency

Author:  Julia Streets, MBE, CEO, Streets Consulting  

What a timely, important and rich conversation we had on the MainStage at Sibos in Frankfurt this week. Rightly billed as a ‘Big Issue Debate’, security is of huge concern, and it’s only becoming yet more complex and urgent. 

I was honoured to interview five leading experts, including Mashrur Arefin, City Bank; Lisa Lee, Microsoft; Ole Matthiessen, Deutsche Bank; Sudhir Pai, Capgemini; and Leigh-Ann Russell, BNY, as we discussed “Navigating the intersection of technology and financial security”.
 

We covered everything from the latest tech disruptions to the harsh reality of legacy systems, the crucial importance of humans in the mix and the necessary conversation of legacy. 

The Exponential Threat: AI, Quantum, and the Pace of Change

The velocity of innovation right now is extreme. It is a pivotal time, where the very tools we rely on for efficiency and growth are also opening new doors to risk.

Artificial Intelligence is the perfect example of this duality. On one hand, AI is proving invaluable for defence, used for real-time fraud detection, security vulnerability scanning, anomaly detection, and augmenting our cyber defence teams at a huge scale. It helps reduce the time required to detect and resolve issues.

On the flip side, AI is fueling the threat landscape. We heard about the staggering 3,000% increase in deep fake scams in 2023, a surge that coincided with the release of GPT. AI enables the creation of sophisticated phishing attacks and deep fakes, exposing existing vulnerabilities we might have “kicked down the road,” particularly issues surrounding identity.

Meanwhile, Quantum Computing threatens today’s existing security models. The panellists agreed that while not every machine will become a quantum computer, it will necessitate industry-wide protection via quantum-safe cryptography. Quantum is expected to be hugely disruptive as it will affect every device and every piece of software we use.

Resilience is Commercial: Making Smart Investments

In this hyper-connected world, a single point of failure can instantly ripple across markets. Our discussion quickly shifted from merely preventing technology from breaking to focusing on how fast we can recover and get back to normal – agility is paramount.

Here are some of the positive steps the industry is taking:

  • Investing in Resilience: We must fundamentally change the mindset that views cyber defences as a cost centre. It is, in fact, an investment, and as one panellist keenly put it, “resilience is commercial”. This requires spending on technology (like self-healing automation that can rebuild data centres in hours), people (training), and scenario planning.
  • Adopting Innovation Equilibrium: Organisations are adopting “innovation equilibrium,” also referred to as “steel threads”. This philosophy dictates that every new idea must be built with resiliency and security baked in from the beginning to ensure safe deployment.
  • Shifting to End-to-End Thinking: Operational resilience can no longer be achieved by optimising individual institutional ecosystems. It demands looking at the end-to-end flow from the client’s perspective.
  • Embracing AI Adoption: Companies cannot afford to be “fast followers”. At least one institution is already embracing the mantra: “AI in the hands of everyone, for everything, everywhere,” completely reimagining business processes. This pace is illustrated by one institution creating 100 non-human ‘digital employees’ this year.

Culture, Collaboration, and the Smarter Path

We also tackled the tough questions of legacy and regulation. Legacy is increasingly viewed as a mindset issue. It is challenging because replacing one end-of-life system might require replacing five or more interdependent applications. Dealing with legacy means managing all dimensions, from monolithic mainframes to modern AI, requiring significant investment in training.

Regulators are essential to keeping the industry safe, particularly given AI-driven risks like ‘disinformation, deep fakes, and discrimination’. Institutions are responding by building strong governance frameworks, such as BNY Mellon’s platform “Eliza,” to work lockstep with regulators, ensuring that innovation remains safe and ethical.

When it comes to the human element, the panel agreed: the strongest firewall for an enterprise is a well-trained employee. Culture must shift from being merely compliance-driven to a model of dynamic, continuous learning and adoption.

Key steps for the industry going forward:

  • Learn from Attackers: Organisations are taking bold steps by employing ethical hackers to breach and test their systems. This allows them to learn from and match the agility of malicious actors.
  • Find a Smarter Path: Instead of just trying to run faster than fraudsters, the industry needs a smarter path. This means strengthening inter-industry collaboration – which is often lacking – to share intelligence. It also involves creating centralised utilities and ledgers utilising harmonised data standards (like ISO) to quickly detect wrongdoing across the entire ecosystem.

The key takeaway from our rich discussion is clear: we are likely underestimating how fast the change is coming. My thanks to all the panellists for such a comprehensive and open discussion.