Executive Summary
Financial institutions are increasingly incorporating emerging technologies into their operations, recognizing the potential benefits these technologies offer. However, this shift comes with heightened cyber risks that necessitate proactive management. To navigate this landscape effectively, financial institutions must prioritize certain technologies and cybersecurity capabilities, invest wisely, and ensure robust risk measurement and talent management.
Key Points:
-
Technology Prioritization: The majority of surveyed financial institutions are focusing on four key emerging technologies - cloud and edge computing, applied AI, next-gen software development, and digital identity and trust architecture. These technologies are favored due to their widespread applicability, maturity, and demonstrated value in the financial sector.
-
Risk Mitigation: Companies acknowledge the need to strengthen critical cybersecurity capabilities, particularly in third-party management and privileged access management, to manage the risks associated with these new technologies effectively.
-
Alignment of Technology and Security Capabilities: There is a recognition that technology priorities must align with existing security capabilities. Companies should reassess their ability to manage risks associated with emerging technologies and ensure that their cybersecurity measures are adequate.
-
Investment Considerations: Investment in the right technologies and cybersecurity capabilities is crucial. Financial institutions must ensure they can accurately measure their risk appetite, provide transparency to regulators and executives, and identify areas needing improvement.
-
Talent Management: Adequate talent is essential to closing capability gaps and supporting future technological expansions. Institutions must ensure they have the right skills to maintain and enhance cybersecurity capabilities.
Action Plan:
To future-proof the environment, financial institutions should:
- Reassess technology priorities in light of existing cybersecurity capabilities.
- Strengthen critical cybersecurity capabilities, especially in third-party management and privileged access management.
- Ensure alignment between technology investments and risk management strategies.
- Develop comprehensive metrics and reporting systems for risk assessment and mitigation.
- Invest in talent development to support current and future technological needs.