Get All Access for $5/mo

Changing Role of CTOs and CISOs In Banking and Financial Cybersecurity Despite the efforts and developments in cyberthreat management, banks are the most prone to cyberattacks across the world

By Paromita Gupta

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

Freepik

In today's digital world, banks are more prone to cyber threats. Once in a while, banks get attacked by malicious actors or groups. The common cyber attacks include phishing attacks (deceptive emails trick), trojans (dangerous tricks used by attackers to sneak into secure data), ransomware (malicious software), and spoofing (Imitate legitimate entities to deceive customers). However, banks have simultaneously started deploying cybersecurity measures to prevent inside and outside cyber-attacks. This can be seen in practices such as do not share your OTP and do not click on unknown links. Despite the efforts and developments in cyberthreat management, banks are the most prone to cyberattacks across the world. Also, emerging cyberthreats are transforming the role of CTOs and CISOs in the banking sector.

Strategic Leadership

While addressing the changing role of the CTOs and CISOs, Kiran Belsekar, executive vice president, CISO & IT Governance, at Bandhan Life said "The role of Chief Information Security Officers is evolving significantly in the context of digital transformation". He emphasized that CISOs are now integral in shaping overall business strategy, ensuring security considerations are embedded from the outset by following "security by design principles."

Further, he mentioned that the regulatory mandates now require CISOs to "directly report to the board," bringing critical risk issues to the forefront of decision-making processes. This change underscores the importance of "data-driven governance and risk management" in modern enterprises for outside and inside threat prevention.

Robust Vision and Hands-On Expertise

According to Venkata Ramana Ratnakaram, Chief Information Security Officer Leading MFI, CTOs and CISOs are increasingly becoming integral to the Information Technology Strategy Committee (ITSC) under the Reserve Bank of India (RBI) framework. This involvement demands a higher level of strategic and technical acumen. "They need to be a lot savvier in dealing with risk, compliance, and cyber security," he said. Also, he mentioned that the dual need for strategic vision and hands-on expertise is becoming more pronounced, "CTOs and CISOs must be both strategic and hands-on without data at the micro level, they can't make macro-level decisions."

Further, direct interaction with regulators has become indispensable. "Today, a CTO can't afford not to have an interaction with the regulator. These conversations are intense and in-depth." Regulators now demand detailed data and insights, particularly concerning disaster recovery (DR) and cyber threats. "For example, if there's a cyber threat incident, they want the CTO and the team to know exactly what's happening," said Ratnakaram.

Policy and Guardrails

Gaurav Mehrotra, chief technology officer at Northern Arc Capital explained, "What we have agreed within CSO and myself is that we will put the guardrails in place," referring to the policies defined to ensure security and compliance.The CISO's role involves staying updated with frameworks like ISO and SOC 2, while the CTO focuses on implementing these policies. "The role of CTO is to ensure that we implement those expectations whatever is laid out in these various policies," he stated.

He outlined the three-phase approach of policy implementation: policy definition, execution, and audit. "We have a very good understanding that CSO understands business, and we in the engineering team understand the relevance of all these security measures," said Mehrotra. He emphasized the importance of both internal and external audits to ensure compliance.

He mentioned the impact of the digital lending guidelines rolled out by the RBI in September 2022. These guidelines pushed the agenda of security across their partners, making it a regulatory requirement. "This becomes a regulatory requirement, and as a regulatory entity, we have to enforce that our partners really comply with all the regulations," he further added.

Adapting to New Threats And Coordination Against Cyber Threats

While addressing the emerging cyber threats, Belsekar emphasized that CISO should be ahead of time when it comes to cyber risk management. Changing modes of working such as hybrid work, work from home, and work from anywhere added more layers to security threats. That is why the modern CISOs are expected to get advanced with Artificial Intelligence and Machine Learning which can provide proactive threat detection and response capabilities.

"So overall the role of CISO is becoming more dynamic and integrated with the business processes requiring a balance of technical expertise, strategic thinking and collaborative skills," said Belsekar.

"The kind of coordination and collaboration hackers and syndicates have is remarkable. We need to match that level of coordination in our security efforts," Ratnakaram also added.

The experts shared their views during a webinar on cybersecurity and risk management in the banking & financial sector: changing role of CTO & CISO conducted by The Digital Fifth.

Paromita Gupta

Entrepreneur Staff

Features Writer with Entrepreneur India

Covering news and trends in AI and Metaverse segments. An avid book reader running her personal blog on the side. You may reach me at paromita@entrepreneurindia.com. 
News and Trends

"45% of All Ongoing Hydropower Projects in India are Ours": Patel Engineering

Patel Engineering reported a turnover of INR 4,400 crore in the last fiscal year, with a projected 10 per cent growth for the current year.

Side Hustle

'Hustling Every Day': These Friends Started a Side Hustle With $2,500 Each — It 'Snowballed' to Over $500,000 and Became a Multimillion-Dollar Brand

Paris Emily Nicholson and Saskia Teje Jenkins had a 2020 brainstorm session that led to a lucrative business.

Leadership

Should I Stay or Should I Go? 8 Key Points to Navigate the Founder's Dilemma

Here are eight key signs that help founders determine whether to persevere or let go.

Marketing

5 Critical Mistakes to Avoid When Giving a Presentation

Are you tired of enduring dull presentations? Over the years, I have compiled a list of common presentation mistakes and how to avoid them. Here are my top five tips.

News and Trends

RBI's Next Chapter: Can India Embrace Crypto Innovation?

With the appointment of under-the-radar Sanjay Malhotra to replace Das as India's new and 26th central bank governor, crypto players are optimistic about the future

Leadership

Visionaries or Vague Promises? Why Companies Fail Without Leaders Who See Beyond the Bottom Line

Visionary leaders turn bold ideas into lasting impact by building resilience, clarity and future-ready teams.