Aug 2026· International Conference on Cyber Security And Protection Of Digital Services· Vol 10, pp. 97· 0 citations
TL;DR
The paper concludes that a disciplined focus on validation enables financial institutions to reduce exposure, improve returns on existing investments, and provide more meaningful, evidence-based reporting to senior stakeholders.
Abstract
Financial services institutions face increasing pressure from regulators, boards, and customers to demonstrate the effectiveness of their cyber security controls. Many organisations, however, operate extensive portfolios of security tools without clear evidence that these investments deliver measurable risk reduction. This paper examines the operational and governance challenges associated with tool sprawl and introduces the concept of ‘security debt’ as the accumulation of unvalidated exposures and misconfigurations. Drawing on practitioner experience and industry research, it argues that the core issue is not the absence of technology but the lack of systematic validation of control effectiveness. The paper proposes a structured four-phase model to streamline cyber security programme performance: baseline, integrate, remediate what matters, and automate and scale. The model emphasises alignment with recognised frameworks, including MITRE ATT&CK, the National Institute of Standards and Technology Cybersecurity Framework, the Center for Internet Security Critical Security Controls, and the Digital Operational Resilience Act, alongside continuous measurement of control performance. By shifting from activity-based to effectiveness-based metrics, organisations can improve visibility, prioritise remediation, and strengthen governance. The paper concludes that a disciplined focus on validation enables financial institutions to reduce exposure, improve returns on existing investments, and provide more meaningful, evidence-based reporting to senior stakeholders. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The study demonstrates the importance of an integrated and versatile cybersecurity architecture that includes multi-vector threat monitoring, behavioural analytics, intelligent fraud detection and risk management that can improve detection capabilities, minimize false positives, boost data protection and increase the c...
Vedankita Mohod, R. Jugele· International Research Journ...· 0 citations
In emerging markets, the strategic conundrum is similar, with financial institutions investing big in cybersecurity and lacking a clear path to measurement of impact on outcomes of digital transformation at the firm level. With the theory and insights provided by Resource Based View and the economics-of-information-sec...
Afeniforo Ayodele Augustine· Journal of Business Practice...· 0 citations
The digital transformation of the Tunisian banking sector has profoundly altered the ways in which financial services are accessed, transactions are processed and data is managed. This development simultaneously increases the attack surface of banking institutions and the importance of cybersecurity for financial stabi...
Houda Jendoubi· International Journal of Sci...· 0 citations
The NERC CIP standards have been mandatory for more than fifteen years and are widely regarded as a baseline for securing the bulk power system, yet little is known about how the people who implement, audit, and write them experience the regulatory lifecycle in practice. Drawing on interviews with twenty two auditors,...
Sena Şahin, Burak Sahin, Robin Berthier et al.· IEEE Power and Energy Magazi...· 0 citations
In the 20th century, the increasing reliance on technology by organizations has led to a significant rise in cyber threats, including malware, ransom ware, and phishing attacks. These threats pose serious challenges to business success, jeopardizing the availability, integrity, and confidentiality of organizational ass...
Mohamed Abdirisak Burale, Aedah Binti Abd Rahman, Prof, Dr. Syed Sajjad Hussain Rizvi· International Journal of Sci...· 0 citations
Despite growing regulation and mature security tooling, cyberattacks continue to rise. This study examines how information security professionals perceive the challenges of securing modern systems. More specifically, we consider increasing technological complexity, the human factor, organizational change, and resilienc...
Emmanouil Mavrofidis, Aikaterini Tsatsaroni, A. Kameas· Journal of Cybersecurity and...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.