Banks lead the fight against cyber risk

Risk management is in banks’ DNA. They have some of the largest cyber-risk management teams and budgets around – and senior management is taking the threat seriously. But are the banks secure? Can they drive cybersecurity down the supply chain?

Most businesses understand the normal risks of competition, and an increasing number have sophisticated financial and operational risk management functions. A few may even be alive to the threat of industrial espionage.

 

IN ADDITION        


Cyber-risk – or information security risk – is different. It arises from the hostile actions of human attackers bent on disabling or defrauding their targets. Few non-financial companies have had much experience of defending themselves against deliberate, intelligent and evolving threats. Banks of course have. 

Unlike almost every other private-sector business, banks are used to being attacked. But, as one bank chief information security officer (CISO) puts it: “Banks have always been in the crosshairs. Yes, today it’s ransomware and digital attacks, but previously it was paper-based cheque and mortgage fraud and even guys with guns. So it’s baked into our DNA that we are a target.” 

However, as the former CISO for corporate functions and trading at a large oil company, shortly to be found at one of the big four UK clearers, points out: “One difference between the cyberworld and the physical world is that the cyberworld evolves 1,000 times faster – so the time in which you have to understand and keep up with the threats is tiny compared to other operational risks. 

“This also means that the past very quickly does not look like the present at all – so systems and processes and solutions built on analyzing the past and extrapolating do not work very well. And then there’s the fact that we spend millions on solutions and they do not work. That’s the other big difference.”

That said, banks are also fundamentally risk-management operations and have long been dependent on complex technology running across large networks of branches and subsidiaries. They understand long-tail, low-volume, high-impact market risks – Nasim Taleb’s ‘black swans’ – and because of regulation they are experienced at managing the intersection of operational risk and compliance. And the fact that they face so many cyberthreats from so many sources also means that banks are at the forefront of the global business response to cyber-risk. 

So, in many ways banks are best placed to lead the charge. But do they?

timeline1

Information flow

The key to an effective response to growing cyber-risks is backing from the very top. Most large organizations have figured out by now that they need to talk a good game in cybersecurity, but to see if they do much more than talk you need to ask: how senior is the CISO and what board access do they have? What is the budget process and how big is the budget? And how much formal information flow is there on cybersecurity to the board?

Outside banking, it is common to be told, as this CISO for a large non-financial company says, that “there is often a communications breakdown between the board and cybersecurity professionals, and this can be a significant problem in implementing security”, and “it’s impossible for the CISO to get board attention. Look how many levels down the CISO is – most of them are below VP level.”

heart2

This is not true of large banks. Cybersecurity is a critical board concern for the big financial institutions, and has been for some time. A typical bank CISO comment is: “Cybersecurity emanates from the board – and it has done so for many years, not just after WannaCry. The board understands the message, as does the risk committee.”

At Barclays, Paul Gillen, interim group chief security officer (CSO), says: “No one in senior management has any doubt whatsoever that cybersecurity is a key priority in the modern financial services industry.” 

Gillen reports to the chief operating officer, who reports directly to the chief executive.

At Morgan Stanley, says Peter Troy, deputy CISO with responsibilty for non-US cyberecurity, “cybersecurity is a regular discussion topic at board level.”

In his most recent letter to shareholders, JPMorgan Chase chief executive Jamie Dimon called cybersecurity: “A critical issue… an arms race, and we need to do whatever we can to protect the United States of America.” 

Assuming that there is a CISO – and at big banks there is – they need C-suite access, and they get it.

To give just a couple of examples. At Barclays, the reporting line goes from the cybersecurity chief to the COO to the CEO. At Deutsche Bank, the chief information officer (CIO) and CSO are peers and have the COO as the escalation point. At Citi, the CISO reports to the head of operations and technology (who reports to the CEO) but also has access to the chief executive as well as the chairman of the board. 

At Morgan Stanley globally,  the head of cybersecurity reports to the head of technology, who in turn reports to the CEO and in EMEA the office of the CISO has dual reports to the CIO operationally and for funding and to the chief executive to ensure that the business and technology points of view are heard. 

timeline2

A number of banks stress the importance of this type of separate reporting arrangement. 

“The CISO is a separate reporting line outside technology,” says one. “The CSO and the CISO both need a path to the board that is not filtered by the CIO. In the past, the CIOs have gone with the business only and they have tended to overrule the security function. That has changed. And there are regulators who demand that the CISO has a separate reporting line outside the key functions. For example, in Germany, BAIT requires that the CISO has that reporting line.” 

Bankaufsichtliche Anforderungen an die IT (BAIT) is Germany’s new Circular 10/2017 – Regulatory requirements for IT-systems – published in November 2017 by the German regulator for the financial sector, the Federal Financial Supervisory Authority. 

At other institutions, the CISO reports to the CIO or COO, who may then report to the CFO rather than the CEO. However, all agree that, regardless of the complexities of reporting lines, cybersecurity is a risk that is taken seriously.

Leadership is all very well, but to drive cybersecurity the board needs to know what is going on and they need to understand an often technical and complicated subject. Again, the global banks have a generally impressive set of monitoring and reporting processes.

For example, group chief risk officer Christian Bluhm describes the approach at UBS. “Every two weeks we have a security committee (a technical committee chaired by the COO) and we explain the threatscape; we look at three, four or five initiatives and go through them in detail, and then we summarize all the programmes we are running, and this reports to the CEO every two weeks. Then there is a quarterly security committee. And there is an annual board-approved cybersecurity plan.”

UBS also produces a cyberthreat intelligence weekly email update, a monthly and quarterly group risk report, a quarterly cyber update to the board of director’s risk committee and an annual cyber update report. In addition, the security function delivers an annual cyber workshop, reinforcing the role of the board in managing cyber risk through crisis simulations. The bank has even produced a cybersecurity handbook for board members.

At Citi, where reporting is similarly thorough, board members have also visited the bank’s Cyber Security Fusion Centres. 

“The CEO and the board directors and senior management are my best supporters, having seen how much we are targeted by attackers,” says Citi’s CISO Tom Harrington. “They’ve learnt this from visiting the fusion centres.”

The other large global banks have an equivalent level of reporting and board engagement.

timeline3

Complexity

Of course, the real measure of management commitment to anything is the money they spend on it. And here again the banks outscore other industries. Most are not keen to reveal cybersecurity spending, arguing that not only is it misleading, since no one can agree what counts as cyber and what counts simply as IT, but also that it is meaningless, since it depends on the size and complexity of the institution and where it is on the cybersecurity journey. A bank that has already spent billions establishing cybersecurity may not need so much to maintain it.

However, one large US institution has been extremely public about its financial commitment and for some time. In 2015, Bank of America Merrill Lynch’s chief executive, Brian Moynihan, told Bloomberg that cybersecurity was the only place in the company that did not have a budget constraint. Talking to Euromoney earlier this year, Cathy Bessant, BAML’s chief operations and technology officer, confirmed the stance and that the bank was now spending around $600 million annually on cyberdefence alone, with 1,200 people dedicated solely to information security.

JPMorgan has, in the past, mentioned a figure of $600 million, while other large banks spoken to by Euromoney for this story mentioned figures between $500 million and $1 billion. But more importantly, all said that the budget process had become straightforward. 

Typical is the statement of one CISO who says his institution spends between $600 million and $800 million a year. 

“I’ve done six budget cycles. The first was a really basic conversation with everyone pushing back and wanting more data. Now we start the conversation with the threat landscape. We go through all the different threats and trends and explain our vulnerabilities to those threats. We review the threats versus compensating controls and where the gaps are and what it will take to fix them. We have not had an issue getting budget.”

Of course none of that matters if business units fight the cyber-risk management function. 

“The tension in cybersecurity is between protecting [a newly developed piece of software] before it goes live and what the business wants, which is just to get products delivered as quickly as possible without the security necessarily having been baked in,” explains one CISO.

Or as Morgan Stanley’s Troy says: “We have to operate at very high speeds – for example on exchanges – and significant damage can be inflicted by over-aggressive security shutting down legitimate business transactions. So your security has to be proportional to the risk.”

And there is also the standard tension between businesses, which take the view that “we make all the money and pay the wages,” and central management functions, which are often seen as imposing unnecessary overheads and friction on the business. 

In general, bank cybersecurity functions deliver half a dozen or so key services: security operations centres responsible for risk management, incident response, group investigations and cyber-threat intelligence; security assurance – security systems deployment, security consultancy to trading entities and other departments; identity and access management systems to authenticate system users; resilience services such as testing; and, in some cases, physical security. They then cost the services and charge them out to the businesses. 

There are then two different approaches to the problem of business unit buy-in.

The first is an extension of normal financial risk management and uses the concept of risk appetite. Businesses are asked what level of financial risk they are prepared to take as a result of a particular cybersecurity posture but are not allowed to take reputational or franchise risk, which no single business unit can take. 

“Risk budgeting and appetite are key. There can be some very heated discussions and we can be accused of being excessively paranoid,” says one CSO.

However, a number of leading institutions take a different approach. First, they effectively disallow the business units from taking cybersecurity risk. 

“The businesses do not have the expertise to make a cybersecurity judgement, and they need to understand that,” says one CISO. “They say: ‘But we own the risk’, but in our view all cybersecurity is a franchise risk because these days all the businesses are so interconnected that any cybersecurity risk they take is effectively a risk to every system to which they are connected. All the businesses now share infrastructure to such an extent that they cannot simply accept cyber-risk on their own behalf without it feeding through to others. If I think they are imposing a franchise risk, I have a pass to debate that at the board.”

timeline4

The best way to avoid these arguments is information flow. Not simply making the costs transparent on each business’s management accounts but giving businesses detailed information about the cybersecurity environment and what the money is being spent on.

“We do not do cybersecurity ‘to’ the business, we do cybersecurity ‘with’ the business,” says a group COO. “I don’t want to provide and impose a service, I want to embed security in the business. We have a CISO and security staff in each business and we try to make the management information we provide really detailed: here’s the attacks; here’s what we did; this is the potential impact to the business; this is an update on all the security projects that will mitigate threats to your business. So every week I report to businesses in a meeting that includes their embedded CISO. They get reports every 48 hours, every week, every month, and they get a trend report every three months.

“That level of reporting to the business, combined with the embedding of the CISO and other security staff in the business, has been transformational,” the COO continues. “The question of whether businesses are allowed to accept cyber-risk does not arise here anymore because that level of information has removed the demand from the business to accept risk. When they understand the risk, they don’t ask to accept it.”

Does all this good work mean that the banks are secure? It is a hard question to answer. Partly because they do not report all breaches and losses and partly because no organization can ever say that they are completely secure. As the UK National Cyber Security Centre’s chief, Ciaran Martin, says, total protection is impossible: “Some attacks will get through. What you need to do [at that point] is cauterize the damage.”

The lack of cybercrime reporting is a vexed question. Without transparency on data breaches and financial losses, law enforcement is hobbled, investors cannot make informed decisions about the material risks run by banks whose shares they hold and customers cannot compare potential providers. On the other hand, talking about successful attacks may encourage further attempts. There is no legal requirement to report all data breaches or cyber-related financial losses. And unless everyone reports everything, those who are open risk looking less secure than those who are not. 

Ciaran_Martin-R-780px
“Some attacks will get through. What you need to do is cauterize the damage.” – Ciaran Martin, National Cyber Security Centre

The UK’s National Crime Agency (NCA) is clear about what it would like. 

“The banks have a great reputation for sharing information and it’s a reputation they work hard to maintain,” says Mike Hulett, head of operations at the NCA’s National Cyber Crime Unit. “But it’s not entirely true. They are pretty good at bilateral sharing with us, but not so good about multilaterally sharing breach data with each other. And it’s a shame because they have so much data and they have the budgets and the technology to crunch it. If they all worked together, they could solve the problem pretty quickly.”

He would like to see much better reporting of real financial losses to enable law enforcement to do a better job of catching the criminals. Right now, cybercrime pays well because the risk of jail time is so low. Only better reporting will break the cycle.

“The banks are attacked massively all the time, but they are very coy about things,” says Hulett. “Under-reporting of losses is a huge issue – they feel they have no incentive to. But it’s like burglary; burglars are not caught on the evidence they leave at a single crime scene; you need to report every crime, even if there is no prospect of anything happening as a result of your one report, to allow law enforcement to build up the big picture that lets us catch the criminals in the end. If we can’t get our own big banks to report losses accurately, then what hope do we have with the foreign banks?”

The banks can retort that they have formed a number of different information-sharing forums and have proved that they can come together to create technology that protects the entire industry. 

They point to initiatives like the Financial Systemic Analysis & Resilience Center (FSARC) for eight US global systemically important financial institution (G-Sifi) banks; the Financial Services Information Sharing and Analysis Center (FS-ISAC), the industry’s cyberthreat information-sharing hub; the Financial Services Sector Coordinating Council (FSSCC), a group set up to help the financial services sector prepare for and recover from cyberattacks; as well as the UK’s various groups, the Global Financial Markets Association, the European Cyber Security Organization and others.

In the US, banks highlight the recently launched Sheltered Harbor project. This is a voluntary industry initiative that allows all banks to create industry-standard encrypted backups of all their key account data and enables that data to be retrieved and used to maintain continuity of service at another institution if the original data holder loses the ability to operate for any reason.

timeline5

Good security

In the absence of hard data, leadership, budget and the rest are part of the proxy for good security. The remainder are the compliance, testing and monitoring processes, incident response and risk modelling techniques used by the industry.

It would take a sizeable book to describe these, but it is clear from conversations with the leading institutions that their procedures for understanding the threatscape and testing and evaluating their own vulnerabilities and defences are far more advanced than probably any other industry sector outside national security.

The banks investments in, and sophistication around, the use of red team/blue teams, ‘cyber ranges’, threat intelligence-driven models and cyber-risk modelling are impressive.

But one piece of data serves to show how far the banks are ahead of the average. 

In 2015, the Ponemon Institute reported that the average time it took for financial institutions to discover a threat had penetrated their systems (the so-called dwell time or time to detect) was 98 days. That was at a time when it could be 200 days or more for non-financial companies. 

In 2017, cybersecurity firm Mandiant reported that the average dwell time of a threat in a corporate environment (all sectors averaged) had come down to 99 days, a pretty good trendline. But nothing compared to the progress the banks have made.

Banks talked to by Euromoney for this story operate on the assumption that attackers will get in. So they emphasize dwell time as one of the key cybersecurity performance indicators, along with time to mitigate and time to eradicate. 

The figure for one large bank – and this is typical – is that 96% of threats are detected on day one and: “For us, the 4% are laptops not connected to the system,” says one CISO, “so those guys have just circumvented $800 million of cybersecurity spend!” 

For many banks, their dwell time is one day versus a wider average of 99 days.

They then pull infected machines offline for a forensic review for mitigation and look for lateral movement – has the attacker managed to achieve their aim of moving away from the initial entry site into more interesting areas of the network? The time is takes to do this is in the handful of days, and most banks use the concept of the ‘cyber kill chain’, a military methodology adapted by Lockheed Martin 

“We use that religiously, it’s one of our key performance indicators,” says one CISO. “So, if you were in my office, you would see a map with all these boxes, each event, where in the kill chain we caught the hack and which tools succeeded and which tools were not successful. We then have a process in which we ask: ‘Why did we catch that attack at step six and not step four? How do we do better?’”

No one is completely secure. But the large banks understand that and have a multilayered approach that they hope gives them resilience as well as a strong defence.

timeline6

Digital economy

Unfortunately, resting on your laurels is not an option in cybersecurity. Artificial intelligence was heralded as the solution to the problem of automating the detection of anomalous digital activity in the vast data flows of the digital economy. However, it is already being harnessed by the bad guys to create malware that can evade AI-based defences and learn to mimic the system that it has penetrated. 

Basic ransomware is being replaced with smarter data integrity attacks. Attackers are beginning to target the most senior executives with complex two-stage stings. First, they install illegal pornography or other compromising material on the executive’s machine. Then they charge the first ransom. 

“Often these are reasonably small and they are extorted by specialist ‘customer service’ people who are genuinely nice and professional with the board member, trying to build a relationship with them so that in two years the big one [extortion attack on the company or board member] hits and these executives will say: ‘Pay the transaction,’” explains one CISO. “If the board member being blackmailed does not tell anyone, then [the firm] has a huge problem.”

Finally, the internet of things (IoT) changes everything. In a network of many billions of connected devices, including all of those being explored by banks as potential delivery channels, a digital world has been created that parallels the physical world as a playground for criminals. The difference is that we generally know how to keep ourselves safe in the physical world, where we can take for granted the power and expertise of the police, the legal system, the ambulance service, paramedics and doctors to help us avoid harm, recover from it and obtain recourse.

In cyberspace, none of that really holds. Individuals and businesses are not yet experienced enough to wander safely in the digital domain, but they are largely left to do so. Threats are evolving faster than we can learn to protect ourselves. Governments do not have the resources or expertise yet with which to replicate physical paramedics and police forces with equivalent levels of protection in cyberspace. 

“What frightens me about the threatscape today? All of it” – Chief information security officer

And the private security providers – the solution vendors who sell software products that claim to be able to solve cybersecurity issues – are not up to scratch. If they were, cybersecurity would not be the issue it is.

“The solutions that are available are not fast enough – and most vendor product ecosystems are not interoperable,” says one CISO. “The vendor community needs to create open security products able to interact with each other and this has been a problem for the last seven to eight years. We need visibility, analytics, automated response and we need solutions that work together and are scalable.” 

Many otherwise good solutions cannot be scaled to the enterprise level required by large, global companies.

Worse still, he says, IoT device manufacturers “are building very insecure products. One device or application could be used to expose the whole financial network, and that means we need improvements in manufacturing. But it’s just not happening because the potential for making money in consumer markets beats security every time. Enterprise-class products are OK, but consumer products are behind the curve.”

And there is one final problem. Right now, the banks are keen to emphasize the level of cooperation and information sharing within the sector. Indeed, BAML’s Bessant told Euromoney earlier this year that since “the US financial system is an interdependent ecosystem, which is only as strong as its weakest link… cybersecurity is one of those rare instances where traditional competition detracts from the outcome.”

A peer at a large US investment bank agrees with her. 

“We have to collaborate on cybersecurity, otherwise we risk undermining the whole industry,” he says. “All our goals are around sharing, they are not about acquiring a technology or information advantage in terms of threats or vulnerabilities because we cannot compete on ‘we are hacked less than you.’”

But will the love-in last? After all, as Dimon pointed out in his latest shareholder letter: “Data privacy and security should be a way in which we and other businesses compete to serve customers.” 

Winning that competition requires differentiation – differentiation communicated to retail clients, to the ratings agencies, who have said that cybersecurity is a creditworthiness issue, and to the big institutional investors, such as Robeco and Legal & General, going public with their concerns about the lack of transparency over this issue.

But those are all tomorrow’s problems. It is today’s issues that are keeping CISOs up at night. 

As one tells Euromoney: “What frightens me about the threatscape today? All of it.”

 

Why threat intelligence?

One decent proxy for security is an organization’s level of threat awareness. After all, it is hard to defend yourself against something you don’t know about. Here again the banks can teach the rest of industry a thing or two. 

Threat intelligence is important not just because it helps to know your enemy. It matters because modern organizations cannot be defended using the obvious model of a fortified perimeter. Large global companies are more like a modern city than a medieval citadel, with many gates and roads in and out. So simply building deeper moats and higher walls does not work, and would in any case disrupt the business intolerably. 

This was first realized by counter-terrorism agencies, who understood that the answer was to move away from reactive defences to proactive. This in turn meant that threat intelligence became critical: who are the adversaries and what are they doing? Knowing this allows a defender to assess their own defences and vulnerabilities against that threat and to prepare and adapt accordingly. 

The banks in most cases have adopted the security agency model by hiring experts who understand the adversaries and giving them the money to build the machine.

These agency-minded CISOs have built in their respective banks various platforms for intelligence-driven defence, for example. Citi has created its three cybersecurity fusion centres (CSFCs) in New Jersey, Budapest and Singapore. 

These threat intelligence centres act as ‘detectives’, looking at the who, what, why and how of threat actors and the threatscape, as opposed to its two security operations centres that act as firefighters – first responders to incidents as they occur.

The CSFC bring together experts from 11 teams across Citi’s Information Protection Directorate, Citi Security & Investigative Services, Citi Technology Infrastructure and Global Consumer Business, to form a team of teams. This approach enables effective information sharing and strategic intelligence analysis to support Citi’s security risk decision-making. The CSFCs blend intelligence from a variety of sources to prevent attacks, reduce risk and support executive decision-making.

Citi’s CISO Tom Harrington says: “They live off new intel, from machine learning, from external sources and platforms, from government, from peers, from vendors in order to understand our adversaries, both external and internal. These centres are the heart of the [cybersecurity] operation.”

Threat intelligence at this level allows banks to continuously adapt resourcing to the relevant protection. “Automated scanning of vulnerabilities around the perimeter can be mapped to the current activity in the threatscape and it can allow you to prioritize particular types of programme to mitigate particular vulnerabilities, depending on the trends you see,” says one CISO. “So, the meltdown/spectre [affecting Intel CPUs] vulnerability was serious, but it is a secondary attack vector. We have been watching to see exploits and we have not seen that. 

“That observation determines the speed at which we deal with the vulnerability. If we see an exploit developed then we would re-prioritize. So we look at the threatscape and we ask ourselves: ‘Do we have a compensating control for that particular threat?’ If we don’t and the threat is rising in importance, then we prioritize that compensating control.”

The banks can benchmark threat versus vulnerability very specifically. A CISO might be able to say: ‘We have 757 vulnerabilities disclosed, 391 unpatched. Of those 82 are critical and high impact, and 48 are related to Russian APTs [advanced persistent threats]. We expect an uptick in Russian activity and so we will prioritize those.’

As the CISO at one leading bank points out: “Threat intelligence lets you know that you’re doing the right thing.”

 

The cutting edge of testing

Testing cybersecurity defences is not straightforward. Deliberately infecting your own network with crippling malware is not really an option. Even trying to trick your staff with simulated phishing campaigns can backfire. So global organizations, including banks, have developed a sophisticated suite of procedures designed to test vulnerability, incident response and business continuity.

Typically, using a combination of internal and external testing works best. Internal testers (sometimes known as blue teams) know the landscape of an organization best and are better able to draw connections between systems. External testers are unbiased, may see items insiders no longer notice and can draw from experience with different organizations. External testers are further divided into penetration testers and red teams.

Penetration testers are essentially ethical hackers hired to find as many vulnerabilities as possible in a given time (say, two weeks) and then to exploit those vulnerabilities to determine their risk. This is an extension of the internal vulnerability assessment process.

Red teams are also usually external hackers but hired not to conduct a vulnerability assessment but to simulate real attackers to test the organization’s detection and response capabilities. The red team will try to get in and access sensitive information in any way possible, including a combined physical and cyberattack, as quietly as possible. The trick is to make these realistic enough to be valuable without being totally disruptive. 

Done well, ‘red teaming’ lets banks focus on known threats, based on threat intelligence gathering (threat actors, tactics, techniques, procedures and scenarios) and critical information assets and business processes that it has identified. The tests can be based on pre-agreed goals, with the objective to achieve these without predefined testing techniques and paths of attack. 

Importantly, the tests are conducted against live systems and infrastructure (with careful planning, pre-approvals and strong oversight to minimize the risk of any operational issues). And they are performed without the awareness of those being tested, such as the bank’s own security and operations centres, meaning that detection and response capabilities are tested as well.

So, for example, one of the global banks spoken to by Euromoney for this piece builds its own red-team testing service. 

“Red-team testing subjects the bank’s technology systems, business processes and control frameworks to targeted cybersecurity tests,” it says. “A red team simulates the continuous evolution of tactics, techniques and procedures of real threat actors, based on their motivation, intent and attack capabilities. 

“Through testing, the red team aims to find vulnerabilities in the bank’s cyber protection, detection and response capabilities, which may not be discovered by traditional testing approaches. Red-team testing is executed by partnering internal staff with external vendors, who provide niche services. A dedicated internal coordination team manages the external and internal red teams executing specific testing exercises, with tightly defined scopes and objectives.”

In general, chief information security officers (CISO) and heads of security come up with and run these exercises to test their playbooks – the incident response plans they have developed and which must be constantly updated to reflect the current threat landscape. 

“We spend a lot of time on red teaming and we really focus on what they find,” says one CISO. “If they don’t find anything, then either they are lying or you have the wrong red team. Cyber-risk management is no longer about a set piece battle – we are literally red teaming all the time.”

The banks are also among the organizations that can afford to use start-of-the-art external testing facilities known as cyber ranges. 

Just as much of the internal cybersecurity infrastructure of banks is derived from military and intelligence models, so these facilities are based on more sophisticated military versions and are developed by military contractors or in conjunction with the military. 

They can be in-house or hosted by third-party vendors like Raytheon, Cyberbit, Lockheed and Cisco, which provide a customizable cyber environment able to create accurate emulations of any size and kind of networked environment. The cyber range operators create an accurate replica of a system and then clients can develop sophisticated testing protocols, expose their systems and networks to realistic threats and evaluate the latest cyberdefence technologies.

In April this year, Cisco announced the opening of a new Cisco Cyber Range Lab in India able to deploy between: “200 and 500 different types of malware, ransomware and 100 attack cases to deliver realistic cyber-attack experiences. The facility can be accessed virtually from any part of the world and will be a living lab of technical knowledge for network security and how to mitigate cyber attacks.”

And the banks themselves have collaborated through the Financial Sector Information Sharing and Analysis Council (FS-ISAC), which has recently built out their first range and staged the first exercise on it at the end of November at the Federal Reserve Bank of Boston. Eventually, FS-ISAC wants to stage two regional exercises a month on the range, each based at one of the 12 regional Federal Reserves.

Rich Baich, Wells Fargo’s CISO and chairman of the Financial Services Sector Coordinating Council, believes cyber ranges are a crucial next step in the fight against increasingly sophisticated attackers. 

In January, he predicted that there will be “greater use of cyber ranges to evaluate new technologies and improve cyber defense operations. Organizations will enhance their cyber effectiveness through the various lessons learned that will be a result from moving from paper exercises to reality of virtualized attacks, which require the actual deployment of defence technologies and tradecraft.” 

Wells Fargo has installed cyber ranges in a number of its cyber threat fusion centres.

The heavy use of red teaming and cyber ranges is another demonstration of how far up the curve the large banks are in cybersecurity. It also highlights how difficult it is for smaller and less well-resourced firms to ensure security. The FS-ISAC’s initial range, simulating a banking IT network, cost around $500,000 to set up; exercise participants then pay between $50,000 and $100,000 to use the environment to test their tools.

But there is hope for those with smaller wallets. In 2016, IBM spent $200 million on a series of cybersecurity initiatives whose centrepiece is a new global security headquarters in Cambridge, Massachusetts, in which its first cyber range for the commercial, rather than the government, sector is located. 

Use of IBM Security’s so-called X-Force Command Cyber Range, developed with help from the US Air Force, is free. In its first three months it hosted more than 600 visitors, representing organizations from a dozen industries, in war-game training for cyberattacks using live malware.

 

The big questions every bank will have to answer on cybersecurity

These are the big questions to which investors, lenders, raters, regulators and customers will demand answers – and not just from banks. To do this, companies will end up having to answer many more detailed queries so they might as well get used to the idea of transparency now.

1. Who has overall responsibility and accountability for the management, implementation and compliance of the bank’s data privacy and cybersecurity programmes?

2. Can you demonstrate that your cyber-risk management framework and the resources you allocate to it are appropriate to the risks you face? 

3. Can you demonstrate that your cyber-risk management framework, culture and preparedness is at least as good as the average for your peer group?

4. How do you manage general third-party supply chain risk?

5. How do you manage cloud and security-solution vendor risk?

6. Can you demonstrate that you have realistically quantified the potential financial impact of a big cyber event and have a response plan that is sufficient to meet that impact? 

7. How do you test or measure the effectiveness of your cybersecurity, and can you demonstrate that the results of those tests are acceptable?

8. Do you provide stakeholders with sufficient information on your critical assets, your cybersecurity effectiveness in terms of standard metrics (mean time to detect etc.), on losses/breaches for them to be able to evaluate your cyber competence sufficiently for their risk management processes?

9. Can you demonstrate that you engage appropriately in data-sharing and systemic testing with peers, regulators and law enforcement?