The Pak Banker

Banks and cyber threat

-

An official of Federal Investigat­ion Agency has claimed that the data of major Pakistani banks have been hacked. According to FIA Cyber Crimes Director ( retd) Capt Mohammad Shoaib, the banks chiefs have not shared the details with the authoritie­s, however, our investigat­ions confirmed the incidents of data theft in ' almost all' banks.

The reports of reported cyber attack on a Pakistani banks and financial institutio­n have sent an alarm bell ringing across the financial sector, and the lessons must be learnt quickly. The hackers located abroad have stealth Rs3.6m according to the bank itself - but the figure could have been much larger. More importantl­y, the attack exposed the vulnerabil­ity of Pakistan's financial system to cyber attacks at a time when another similar technology- related breach was reported in the database of the Central Directorat­e of National Savings that holds up to Rs3.65 trillion in deposits from individual and institutio­nal investors. The nature of the breach in the two cases is very different, but both have served to highlight the fact that the country's financial system has powerful vulnerabil­ities that could lead to largescale damage if not plugged properly.

In the wake of the hacking attack, it was discovered that the entire security architectu­re of the banking system is flawed. For example, one would expect that an attack on one institutio­n would trigger an alert for all other institutio­ns so that they can take preventive steps. One would also expect that the alert would be shared with the State Bank and the payment operator in a timely manner so that they can put in place the measures necessary to plug the breach, as well as protect customers. But no such system for generating alerts exists, and individual financial institutio­ns would prefer to bury the news of an attack and cover up its impact in the hope that nobody, save for a few customers who have been affected, will find out, so that they can return to business as usual.

With the emergence of mobile banking and the fast growth of internet banking, it is more important for banks and other financial institutio­ns to focus on cyber security and have industrywi­de protocols on how to react when a breach is known to occur. Biometric verificati­on can play a role in this, as it does in mobile banking, as well as real- time monitoring of the IT systems of all financial institutio­ns. The State Bank needs the cooperatio­n from the banks. But other institutio­ns, like CDNS and the Central Depository Corporatio­n also need to be brought into this effort, along with brokerages.

The State Bank can sit down with the management of the Pakistan Stock Exchange and the Securities and Exchange Commission of Pakistan, along with FIA cybercrime experts and private- sector cyber activists, and lead a process to determine the full scope of protection­s required to safeguard the financial system from future attacks. The cyber threat should not be taken lightly because the next attack could be far bigger.

Newspapers in English

Newspapers from Pakistan