Cybersecurity: A different kind of banker

The cybersecurity challenge has forced banks to hire a new breed of professional, often from national security services. But cultural issues can make staffing a cyber team difficult

The big banks’ cybersecurity chiefs are not the average techies, traders or salespeople you generally meet in finance. 

The chief risk officers to whom they sometimes report often come from a quantitative background, because their role, driven to seniority by the financial crisis, has been to ensure the complex financial risks banks run are managed in a way the regulators are happy with. But the security guys do not need to understand derivatives calculus, they need to understand how criminals and hostile states think and act.

heart4

“We hire people from the security services and from law enforcement because they can give you a realistic, granular view,” says one bank’s C-suite member. “These are real hands-dirty people – they may have killed someone – and we combine them with commercial people, who know what can be done and what cannot be done.”

The trend is particularly pronounced at the large US banks, most of whom have picked super-senior ex-National Security Agency, Federal Bureau of Investigation, Department of Homeland Security, White House and Central Intelligence Agency operatives to fill the key cybersecurity jobs. 

Tom Harrington was hired in 2012 and is a managing director and the chief information security officer (CISO) for Citi. Before that he was with the FBI for 28 years, starting as a street agent and rising to chief operating officer after stints in counter-terrorism and other national security-related areas. 

After 9/11, he was tasked by then FBI director Robert Mueller (now head of the Special Counsel investigation of Russian interference in the 2016 US elections) to drive a more intelligence-lead and threat-focused risk management approach.

“Unless you came from a national security background you just weren’t ready for this level of threat” – Ex-agency chief security officer

In January 2017, Goldman Sachs hired Andy Ozment as a managing director and CISO. Ozment spent the previous nine years in cybersecurity at various US government departments, including the White House, the Department of Defense and latterly the US department of Homeland Security.

Rich Baich came to the CISO role at Wells Fargo in 2012 after 20 years with the US navy, the Information Operations Directorate at Norad/Northern Command headquarters, the Information Operations Technology Center in the NSA and the National Infrastructure Protection Center at the FBI.

UK and European institutions have also looked to US agencies. For example, Al Tarasiuk joined Deutsche Bank in 2015 as a managing director and the global head of IT security. He previously served as the United States Intelligence Community chief information officer, a position he was appointed to by president Barack Obama. He also served as the CIO of the CIA.

Firms have also pillaged European police forces, especially the UK National Crime Agency and Europol. “Talent is an issue,” says another bank’s CRO. “We have hired people on the basis of their contacts in law enforcement and intelligence. My head of cyber threat intelligence is ex-Europol.”

Wanted: spooks

The perception of information security as a war against a guerrilla-style adversary partly explains why so many banks have chosen to hire their digital security chiefs from the worlds of national security, intelligence, the military and law enforcement. But the other driver is the rise in the importance of nation-state actors and the trickle-down of their hacking R&D. Banks need people who understand state-to-state conflict and have already experienced the adversaries you meet in cyberspace.

“We [organizations like the CIA and NSA] were dealing with nation-state actors in the Cold War long before anybody else was,” says one ex-agency chief security officer. “They were breaking into communication systems way before the internet and the widespread adoption of computers, and so we come from a culture of that. That is very helpful in this new environment.”

Another says: “A big problem over the last decade has been that we just weren’t ready. Unless you came from a national security background you just weren’t ready for this level of threat. We’re only just catching up with the more agile threat actors.”

Paul Gillen is now interim group information security officer at Barclays and formerly head of the operations department in Europol’s European Cybercrime Centre (EC3) and worked alongside Troels Oerting (previously head of Europol’s Counter Terrorist and Financial Intelligence Centre and head of EC3 and later Barclay’s group CSO and CISO). 

“Before this,” says Gillen, “I ran the operations department in EC3 and took part in the infrastructure take-downs against organised criminal gangs. That included botnets such as Gameover Zeus (a botnet that successfully stole millions of dollars from banks by obtaining customer banking credentials) and Shylock (another piece of botnet-spread malware designed to target banks and their customers). That kind of operation opens your eyes to the capabilities of these criminal groups. 

“We are threat-aware at Barclays and keep ourselves abreast of how adversaries operate.”

However, a pure security background without additional experience, can cause problems. One potential issue has been the culture clash between people who have spent a lifetime in the public sector and who are likely used to giving orders and being obeyed, and commercial organizations, in which at least some degree of consensus is desirable. Some hires have not worked out.

In 2015, Andy Archibald, the head of the UK NCA’s cyber-crime unit moved to Credit Suisse as director of cyber security, intelligence and threat management. After a difficult year and 10 months, he moved on, saying in private that he had been unable to operate as he had wanted.

Put another way, as a former agency chief, now a bank CSO, explains: “If you just have a security background, then you emphasize protection above all else, but you don’t necessarily look at risk management or the commercial impact of security. You don’t look at the need to get new products out the door quickly.”

“A threat actor could plan something on the physical side that could have implications on the cybersecurity side” – Chief security officer

But in general, it is not true that former law enforcement and public-sector officials do not understand commercial imperatives. 

“Even MI5 and MI6 do not have unlimited budgets,” says a bank board member who was hired from the services. “In fact, their budgets are way smaller than ours, so they are used to make-do-and-mend. In that sense, they do understand the idea of ‘commercial’ and have had to negotiate and achieve consensus. 

“However, friction can still arise from the presumption that we are an extension of the state and have a civic duty over and above our commercial activities. We have to make it clear that it is not our role to snoop, so that can be an issue.”

The best hires seem to combine the agency or law enforcement background with senior operational management, ideally in a CIO or COO capacity. As one explains: “It’s very beneficial that I have been a CIO because I understand the struggle of getting new software on the floor quickly, as well as understanding the need to protect those new systems.”

It also helps if hires can combine physical security skills with cybersecurity. This may seem a less obvious amalgamation and it has not been adopted by all the banks – and it is rare outside them. But there are good reasons for putting the two together.

For a start, many cybersecurity threats include a physical security component. The Bangladesh Bank attack seems to have involved a number of physical breaches, including the disabling of security cameras, access to terminals that should have been in restricted areas and the possible use of a USB stick to introduce the key-logging software that made the attack possible.

A source at the Bank of England confirms that central banks are concerned about the physical security issues raised by the heist. And Swift itself, in its Customer Security Controls Framework 1.0, published in March 2017 after the series of attacks via its network, dedicates its section three to the physical security of systems able to access Swift infrastructure. 

One bank spoken to by Euromoney argues that this need for hybrid security is a fundamental weakness of Swift itself that will be overcome with the use of blockchain or other new technology. But in the meantime the reliance of cybersecurity on physical security seems obvious.

Less obviously, as one CSO explains, combining physical and cyber security “is also useful when looking at intelligence and threat intelligence. Combined threat intelligence that combines physical and digital information security measures makes sense. A threat actor could plan something on the physical side that could have implications on the cybersecurity side and vice versa. If you can see both, then you have a better chance of stopping them.”

Weaponised world

In fact, the deeper you look at cybersecurity, the plainer it is that it is a hybrid risk. The internet of things creates networks of physical devices that can be hacked to create botnets, which can then be used as digital weapons. 

Analogue physical devices of all sorts are being digitized and so made hackable. Biometric access control tools can be hacked; turnstiles, doors and elevators are now digitally controlled and so a cybersecurity hack can lead to a physical breach and vice versa – the solution is better identity- and access-management software, while physical devices can be used as multi-factor authentication to mitigate cyber-risk.

So for example, if you swipe in at a particular location – which can be a building or even a particular door or turnstile – then that can activate access to your desktop computer at that same location and if you do not swipe in, you do not have access. If you are swiped in at one location and then someone attempts to access the network as you in another location, the system can detect the anomaly and raise an alert. The boundaries between physical and cybersecurity are disappearing.

Organizations that run cybersecurity and physical security together generally join them under a CSO. So what makes a good one? 

“A good CSO comes from the cybersecurity side,” says one, “but has had experience of physical security. Information security is a very complicated topic to manage and understand. It is much easier to learn the physical side – buildings, executive protection, guns and so on – if you don’t have it, than it is to learn the cyber side.”

Understanding the complex interdependencies of the physical world and cyberspace is the cutting edge of cybersecurity. This last bank only brought the security and physical security functions together at the beginning of 2017. But others are following and other global industries will need to too.