# How Bank CISOs Can Respond to a Digital Hostage Scenario
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-06-22
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Protecting Customer Trust: The New Role of CISOs in Banking
Meta Description: Discover how CISOs are safeguarding customer assets from cybercriminals in the digital age. Learn about the latest attack techniques and investment priorities.
URL: https://financedigest.com/how-bank-cisos-can-respond-to-a-digital-hostage-scenariohtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/graphicstock-man-holding-smart-phone-making-online-shopping-and-banking-payment-blurred-backgroundrvljk3dlig-1736838270675-compressed.jpg)

_By **Tom Kellermann,** Head of Cybersecurity Strategy, VMware_

Trust has always been the cornerstone of the banking industry. Without customer confidence that their assets are secure, banks cannot function. A reputation for having the strongest vaults with the thickest walls and unpickable locks is fundamental. But, as the means of protecting financial [assets has moved from the physical to the digital](https://www.financedigest.com/3-top-digital-asset-threats-facing-your-brand-in-2017.html "3 top digital asset threats facing your brand in 2017") realm, the role of custodian of customer trust has shifted inexorably onto the shoulders of CISOs. Now, cybersecurity is not just essential to preventing criminals from theft, it has become a brand protection imperative.

VMware’s annual [Modern Bank Heist report](https://www.carbonblack.com/resources/modern-bank-heists-2021/) has identified critical escalations in the sophistication and co-ordination of attacks against the financial services sector. Cybercriminals and nation-state actors are capitalising on the dual disruptions of the global pandemic and [banks’ ongoing digital transformation](https://www.financedigest.com/transforming-the-banking-experience-to-be-mobile-first-and-people-centric.html "Transforming the banking experience to be mobile-first and people-centric") programmes to broaden and deepen their attack techniques. They are no longer focused simply on direct monetary gain through wire transfer fraud, but on hijacking the [digital transformation](https://www.financedigest.com/3-reasons-why-businesses-get-stuck-at-the-starting-gate-of-digital-transformation.html "3 Reasons Why Businesses Get Stuck At The Starting Gate Of Digital Transformation") of a financial institution through island hopping, and holding them hostage to the threat of destructive attacks.

**Island hopping escalates as** [attackers hijack banks](https://www.financedigest.com/attacking-banking-and-fintech-fraud-head-on-through-ai-infused-strategies.html "Attacking Banking and Fintech Fraud Head-On Through AI-Infused Strategies ")

38 percent of the [financial institutions](https://www.financedigest.com/what-financial-institutions-will-be-like-in-10-years.html "What Financial Institutions Will Be Like In 10 Years") surveyed in the study said they had encountered island hopping, representing a 13 percent increase over 2020 (respondents were asked to exclude the SolarWinds campaign from their response).

Island hopping has become the attack vector of choice because, as [banks have digitised and their supplier ecosystem](https://www.financedigest.com/what-does-2022-hold-for-open-banking-some-predictions-from-the-ecosystem.html "What does 2022 hold for open banking? Some predictions from the ecosystem") has grown, the attack surface has expanded correspondingly; there is quite simply more opportunity now than ever before. And to capitalise on it, cybercrime cartels have taken the guesswork out of the game by studying the interdependencies of [financial institutions](https://www.financedigest.com/securing-financial-institutions-with-the-help-of-pam-solutions.html "Securing financial institutions with the help of PAM solutions"). They have identified entities such as the [Managed Service](https://www.financedigest.com/sacyr-shortlists-four-bidders-for-its-service-waste-management-unit-expansion.html "Sacyr shortlists four bidders for its service, waste management unit – Expansion") Providers and outside Counsels used by their target companies. These [businesses have become the prime target for infiltration as a stepping stone into the target network](https://www.financedigest.com/the-new-wifi-how-private-5g-networks-could-revolutionise-business.html "The New WiFi? How Private 5G Networks Could Revolutionise Business"). What might previously have constituted a “lucky hit” for a cybercriminal campaign is now a well-researched route to a valuable payoff.

Another commonly [reported form of island hopping is watering](https://www.financedigest.com/listen-care-share-ofwats-latest-report-on-the-water-industrys-handling-of-customers-during-the-pandemic.html "Listen, Care, Share: Ofwat’s latest report on the water industry’s handling of customers during the pandemic") hole attacks. Here, adversaries hijack websites or mobile apps used by [customers for digital banking](https://www.financedigest.com/how-will-the-introduction-of-digital-banking-impact-customer-perception-and-overall-loyalty.html "HOW WILL THE INTRODUCTION OF DIGITAL BANKING IMPACT CUSTOMER PERCEPTION AND OVERALL LOYALTY?"). This has a direct brand impact where customer’s trust in the visual assets they associate with the [bank is hijacked to steal credentials or money](https://www.financedigest.com/marketmind-banks-are-leaking-money.html "Marketmind: Banks are leaking money"). The reputational damage caused by these attacks is immense.

**CISOs’ respond to increased attacks**

Faced with these escalating and stealth-focused tactics, what should CISOs be doing in response? The [financial institutions we surveyed are committing budget](https://www.financedigest.com/how-financial-planning-starts-with-a-new-approach-to-budgeting-and-forecasting.html "How financial planning starts with a new approach to budgeting and forecasting") to the battle, with eight in ten planning to ramp up spending by between 10-20%.

In terms of where spending will be focused, investment priorities include: Extended detection and response (XDR); threat intelligence; workload security and container security. These priorities [paint a picture](https://www.financedigest.com/trade-finance-the-small-brush-to-paint-the-big-picture.html "Trade Finance: The Small Brush to Paint the Big Picture") both of how attacks have evolved and the new cloud-based infrastructure that has become the target.

Particularly encouraging is the frequency and impact of threat hunting. 48% of surveyed institutions conduct weekly threat hunts and, as programmes become more [mature and hunters gain more understanding](https://www.financedigest.com/understanding-the-different-levels-of-maturity-in-travel-and-expense-management.html "Understanding the different levels of maturity in travel and expense management") of their environment, they are driving change at a process and technology level. We are seeing more use of data science, [machine learning and artificial intelligence](https://www.financedigest.com/machine-learning-in-artificial-intelligence.html "Machine learning in artificial intelligence") to determine what normal looks like and spot anomalies. This is [driving a true partnership between human-led hunting and automation](https://www.financedigest.com/top-3-reasons-2021-will-drive-automation-acceleration.html "Top 3 Reasons 2021 Will Drive Automation Acceleration").

**Best practices to defend against modern** [bank heists](https://www.financedigest.com/learning-the-lessons-of-the-bangladesh-bank-heist.html "LEARNING THE LESSONS OF THE BANGLADESH BANK HEIST")

Adversaries are [focusing on gaining](https://www.financedigest.com/powder-dispenser-market-market-2019-2029-where-should-participant-focus-to-gain-maximum-roi.html "Powder Dispenser Market Market (2019 – 2029) | Where Should Participant Focus To Gain Maximum ROI ") undetected access to networks and this means that incident response must be conducted under the assumption that the network has been compromised. The following best practices are advised for defence teams:

1. Deploy honey tokens or deception grids, especially on attack paths that cannot be hardened.
2. Apply just-in-time administration.
3. Integrate your network detection and [response with your endpoint](https://www.financedigest.com/endpoint-detection-and-response-market-is-projected-to-expand-at-a-cagr-of-21-from-2020-to-2030-tmr.html "Endpoint Detection and Response Market Is Projected To Expand At A CAGR of 21% from 2020 To 2030 | TMR") detection platform.
4. Deploy workload security.
5. Conduct weekly threat hunting.
6. Stand up a secondary line of secure [communications to discuss](https://www.financedigest.com/optical-satellite-communication-market-emerging-trends-to-boost-the-global-revenue-growth-discussed-in-a-new-market-research-report-by-tmr.html "Optical Satellite Communication Market – Emerging Trends to Boost the Global Revenue Growth Discussed in a New Market Research Report by TMR") ongoing incidents without risk of interception and compromise. This channel should allow for talk, text and file transfer.
7. When responding to an incident- Assume the adversary has multiple means of gaining access to the environment and avoid alerting them that you know they’re there. Watch and wait before taking action – don’t start [blocking malware or terminating](https://www.financedigest.com/climate-activists-plan-daily-protests-after-blocking-10-uk-oil-terminals.html "Climate activists plan daily protests after blocking 10 UK oil terminals") C2 systems until you are sure you understand all possible avenues of re-entry.
8. Deploy agents in monitor-only mode. If you begin blocking or impeding their activities, they will change tactics, potentially leaving you blind to their additional means of re-entry. Rename agents to something innocuous.

On top of these tactical activities, we [need to see](https://www.financedigest.com/boes-pill-sees-need-for-further-interest-rate-rises.html "BoE’s Pill sees need for further interest rate rises") a strategic shift. Three quarters of CISOs at financial institutions still report to CIOs, [yet the landscape has changed dramatically over the past year](https://www.financedigest.com/four-years-of-open-banking-2022-may-be-the-best-year-yet.html "Four years of Open Banking: 2022 may be the best year yet "). The switch to work from anywhere has [put cybersecurity and CISOs at the centre](https://www.financedigest.com/new-research-from-impact-com-shows-shifting-power-dynamic-that-puts-influencers-at-the-centre-of-the-brand-consumer-relationship.html "New Research from impact.com Shows Shifting Power Dynamic that Puts Influencers at the Centre of the Brand-Consumer Relationship") of business continuity and resilience. CISOs should be promoted to a true C-level to [ensure they have the strategic](https://www.financedigest.com/strategic-budgeting-ensures-success-of-community-support-programs.html "Strategic Budgeting Ensures Success of Community Support Programs") influence they need to discharge their role effectively. As custodians of a financial institution’s greatest asset – [customer trust](https://www.financedigest.com/how-to-maintain-customer-loyalty-and-trust-in-the-face-of-a-pandemic-and-digital-competition.html "How to maintain customer loyalty and trust in the face of a pandemic and digital competition") – their position should be elevated accordingly.

[Financial institutions are unquestionably facing](https://www.financedigest.com/the-changing-face-of-financial-advice.html "The changing face of financial advice ") new and more pernicious threats but, by leveraging advanced tools and intelligence, they can successfully hunt out and suppress cyber cartels preying on the extended ecosystem. Trust and confidence will depend on vigilant [digital transformation](https://www.financedigest.com/redefining-the-human-touch-with-data-driven-digital-transformation.html "Redefining the human touch with data-driven digital transformation").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

