Compliance Challenges in Cyber Security for Banks
Compliance with cyber security directives/rules/laws/guidelines/procedures put forth by regulatory institutions/government bodies and banks themselves holds an important position as important as compliance of other domains/areas in a bank. Information technology is a business enabler and support provider for banks. The IT infrastructure binds the organization together and brings in cohesion, and delivers/creates value for the banks and its customers. Cyber security compliance caters to the requirement for securing the bank’s IT infrastructure to be compliant with best industry practices, laws of the land, and regulations put forth by the regulators. Infiltrations into the bank's IT systems can cause serious damage to the banks in terms of compromised data and systems and financial fraud. Recently one of the banks in India encountered financial fraud which happened due to a breach of its systems where hackers siphoned off more than ₹94 crore through a malware attack over a period of two days in 2018. The customer data is of pinnacle importance and banks leverage it for marketing their products and services. Such PII (Personally Identifiable Information) data if fell into the wrong hands can create a liability scenario for banks and risk of financial and non-financial damage to the bank and its customers.
The following are the enumerated cyber security compliance challenges for banks -
1. DATA COLLECTION
The collection of data from different sources within the organization and collating them poses a great challenge and is a daunting task due to the involvement of many departments and the manual process being in place for some operations in the bank. Provisioning of the same to the regulators presents a challenge as there is a requirement for presenting the data to the regulator in a specified format. There is a limit to the amount of automation that can be done concerning the gathering of data, verification, and submission of data to the regulator. Human intervention is inevitable and of utmost importance since data cannot be submitted to a regulator without proper inspection.
2. ACCURATE AND TIMELY SUBMISSION OF DATA TO REGULATORS
The data about compliance status should be accurate and there should be no errors of omission or commission. Incorrect data submission to the regulator without proper checks and balances can invite penal action from the regulator. Such data is used by regulators for analytical purposes and to improvise further policy-making and carries importance to improve the cyber security environment of the banking industry. Delay and untimely submission of data pose a challenge due to system factors (extraction of proper and correct data from IT systems) and human factors (delay in forwarding the compliance data to the appropriate authority, Inspection.etc.).
3. LACK OF CLARITY IN POLICIES/DIRECTIVES BY REGULATORY BODIES - Regulatory guidelines for compliance are not specific and require many deliberations with different stakeholders within and outside the bank to understand the requirement correctly and suitably implement the same in the bank's IT environment. Wrong implementation of the same adds to reworking the problem statement for compliance and this includes additional efforts in terms of time and money.
4. COMPLEX LEGAL AND REGULATORY FRAMEWORKS - Concerning the cyber security landscape for banks, there is a compliance requirement with the different risk frameworks/directives put forth by regulatory institutions and authorized technical bodies. The followings are some laws/regulations/standards for which banks need to maintain compliance (list not exhaustive) - Information Technology Act, 2000; PCI DSS (Payment Card Industry Data Security Standard), RBI Circulars on cyber security and information technology management and ISO 270001 (standard for information security management systems). etc
5. EVOLVING CYBER SECURITY LANDSCAPE
Cyber security is ever evolving field due to the introduction of new technologies/software products/solutions which come with undiscovered/discovered security issues. The issues must be addressed and remediated to ensure the safety of the IT infrastructure of the bank and the smooth functioning of business operations. The cyber security framework of the bank needs to be robust enough to address these challenges with the continual improvement of its systems through patches/updates. Compliance and reporting become easier when the bank’s cyber security strategy is robust.
6. COMPLIANCE CHALLENGES CONCERNING OFF-SHORE OPERATIONS - Banks having offshore operations are mandatorily required to follow the laws and directives of the country in which they operate. There is a requirement for adhering to compliance requirements set forth by the country regulators in which the bank is operating. For example, banks operating in the European Union are mandatorily required to follow GDPR (General Data Protection Regulation). The banks face the risk of heavy financial penalties for non-compliance with GDPR. There is also a scenario where compliance with the laws of the country where foreign offices are located can often conflict with the local laws where the bank has primary operations.
7. COST ISSUES INVOLVED IN SECURING COMPLIANCE WITH RULES - Changes to IT infrastructure entail cost and whenever there is a requirement for conforming to cyber security directives expenditure is imminent. Big banks with large scale of operations can afford and perform heavy investments to ensure and comply with compliance requirements for cyber security but small banks don’t often have large headroom for IT expenditure to address the compliance points.
8. SKILLSET OFTHE ORGANIZATION STAFF: Compliance requires implementation/modification of the IT solutions to match the compliance requirements put forth by the regulator and policies of the bank. Implementation of these requires having a specific set of expertise and a strong pool of talent, without which compliance can be difficult. Lack of specialized manpower can often result in bad implementation of the solution or delay in the implementation of solutions.
Compliance should not be seen as a redundant effort to comply with the directives of regulators or banks’ policies. An Organization should strive to achieve a certain benchmark and establish a baseline in the industry concerning cybersecurity compliance to ensure a smooth and secure operating environment that other players in the banking industry can emulate.
The golden statement - “Doing things right the very first time” is central to compliance.