Skip to content
Open access

NIST-Based Cybersecurity Risk Management for Mitigating Customer Data Breaches and Cyber Threats in Banking

Aug 2026 · International Journal of Innovative Science and Research Technology · 0 citations · 20 references

TL;DR

The results indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks, strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring.

Abstract

The rapid digitalization of business processes has heightened organizational vulnerability to cybersecurity threats, particularly customer data breaches, unauthorized access, malware, phishing, and cyberattacks. These threats can compromise sensitive information, disrupt operations, cause financial losses, and erode customer trust. This study aims to examine the implementation of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) for mitigating customer data breaches and cybersecurity threats. A qualitative research approach is employed to analyze cybersecurity risks, vulnerabilities, security controls, and risk mitigation practices in accordance with the NIST RMF. The framework encompasses a systematic process for categorizing information systems, selecting and implementing security controls, assessing control effectiveness, authorizing systems, and continuously monitoring risks. The results indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks, strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring. The findings suggest that strengthening customer data protection requires a holistic approach integrating technological safeguards, organizational governance, employee awareness, risk assessment, and effective incident response mechanisms. This study contributes to the cybersecurity risk management literature by proposing a structured approach to strengthening organizational resilience against customer data breaches and evolving cyber threats.

Read PDF

Similar papers

Open access Jul 2026

Identifying Critical Cybersecurity Threats Impacting Financial Stability in Investment Firms: A Qualitative Risk Management Perspective

Investment organizations now face greater cybersecurity risks as financial services become increasingly digitalized. Wherein the high-value transactions, sensitive client data, third-party platforms, and real-time operational systems are closely interconnected. The opinions of investment firm specialists on which specific risks pose the greatest threat to financial stability have not received as much attention as cyber risk, even though cyber risk has been thoroughly investigated using technological and quantitative approaches. This study used a qualitative case study to address the following research question: Which cybersecurity threats have the greatest impact on the financial stability of investment businesses? Semi-structured interviews with seven professionals in investment company settings were analyzed using thematic analysis informed by the Technology Acceptance Model, Risk Management Theory, and Contingency Theory. The findings demonstrate that the most serious threats are phishing, social engineering, third-party vendor risks, and the development of external threat vectors, as they have the potential to interfere with business operations, jeopardize data integrity, impair regulatory compliance, and erode investor confidence. The report argues that investment firms should view cybersecurity as a fundamental financial stability concern rather than a strictly technical function, and offers qualitative, theory-driven insights into cybersecurity threat prioritization.

Qamarsultana Alad, James C. Hyatt, Rahul Azmeera · 0 citations
Review Open access Sep 2026

Cyber Security in Accounting: Increasing Threat of Cyber-Attacks and Data Breaches in Accounting

The increasing reliance on digital platforms in accounting has heightened the vulnerability of financial information to cyber threats, including hacking, phishing, ransomware, and insider attacks. This study explores the intersection of cybersecurity and accounting, emphasizing the risks posed to the integrity, reliability, and transparency of accounting information systems. Anchored in Systems Theory, the study provides a theoretical lens to understand accounting systems as interconnected, adaptive structures that are susceptible to external and internal disruptions. By synthesizing existing literature, the study identifies how cyber threats compromise the stability of financial reporting and examines the role of security controls in mitigating these risks. The thematic review highlights the critical interplay between technological safeguards, human actors, organizational governance, and regulatory frameworks in maintaining system resilience. Empirical evidence from prior studies indicates that breaches not only affect data integrity but also influence stakeholder confidence, corporate reputation, and compliance with reporting standards. Furthermore, the study reveals the importance of professional competence and continuous training in enhancing accountants’ ability to navigate cybersecurity challenges. Based on these insights, the study recommends the adoption of robust security architectures, integration of cybersecurity education into professional development, and the strengthening of governance and regulatory mechanisms.

Ogiriki Tonye · 0 citations
Open access Sep 2026

Cyber Security Awareness and Employee Compliance Behavior at Wipro Limited

Cybersecurity has become a critical concern for organizations as the increasing use of digital technologies, cloud computing, remote work, and interconnected information systems has led to a rise in cyber threats and data breaches. While organizations invest heavily in advanced security technologies, employee awareness and compliance with cybersecurity policies remain essential for protecting organizational information assets. This study examines cybersecurity awareness and employee compliance behavior at Wipro Limited by evaluating employees knowledge of cybersecurity practices, adherence to security policies, and the factors influencing secure workplace behavior. The research focuses on key aspects such as password management, phishing awareness, secure internet usage, data protection, incident reporting, cybersecurity training, and organizational support. A descriptive research design was adopted using both primary and secondary data. Primary data were collected through structured questionnaires administered to employees, while secondary data were obtained from company reports, academic journals, books, industry publications, and credible online sources related to cybersecurity and information security management. The collected data were analyzed using percentage analysis, mean analysis, and graphical representations to assess the level of cybersecurity awareness and compliance behavior among employees. The findings indicate that regular cybersecurity training, continuous awareness programs, management support, and clearly defined security policies significantly improve employees compliance with organizational security practices and reduce the likelihood of cyber incidents. However, challenges such as evolving cyber threats, human error, social engineering attacks, insufficient awareness, and varying levels of digital literacy continue to affect organizational cybersecurity. The study concludes that fostering a strong cybersecurity culture through continuous education, policy enforcement, employee engagement, and proactive risk management is essential for enhancing cybersecurity awareness, strengthening compliance behavior, and improving the overall security posture of Wipro Limited.

Domakonda Vamshi Krishna, K.Shashidhar, Srilekha Rageru · 0 citations
Review Open access Aug 2026

Design and Validation Framework for Multi-Level Cybersecurity and Privacy Protection in Modern Digital Infrastructures

A multi-level cybersecurity and privacy framework that integrates complementary controls across physical, network, endpoint, application, data, identity and access management, monitoring and incident response, and human and policy domains is developed.

Kennedy Owino Jaramba, Samwel Oonge · 0 citations
Review Open access Sep 2026

Cyber Security Awareness and Employee Compliance Behavior

Cybersecurity has become one of the most critical concerns for organizations as digital transformation, cloud computing, remote work, and internet-based business operations continue to expand globally. Despite significant investments in advanced security technologies, human error remains one of the leading causes of cybersecurity incidents, making employee awareness and compliance with organizational security policies essential for protecting information assets. Cybersecurity awareness refers to the knowledge and understanding employees possess regarding cyber threats, safe online practices, organizational security policies, and responsible digital behavior. Employee compliance behavior involves the extent to which employees follow established cybersecurity guidelines such as creating strong passwords, enabling multi-factor authentication, identifying phishing emails, handling sensitive information securely, updating software regularly, and reporting suspicious activities promptly. Organizations increasingly implement cybersecurity awareness training, simulated phishing exercises, security awareness campaigns, and policy enforcement programs to reduce cyber risks and strengthen organizational resilience. The primary objective of this study is to examine the relationship between cybersecurity awareness and employee compliance behavior by evaluating how awareness programs influence employees adherence to cybersecurity policies and best practices. The research also investigates the effectiveness of cybersecurity training, password management practices, phishing awareness, and organizational security culture in improving compliance behavior. A descriptive research design was adopted for the study. Primary information was obtained through structured responses collected from employees, while secondary information was gathered from peer-reviewed journals, books, industry reports, government publications, and authentic cybersecurity databases. Percentage analysis and graphical techniques were employed to analyze and interpret the collected information. The findings indicate that higher cybersecurity awareness significantly improves employee compliance with organizational security policies, reduces risky online behavior, enhances phishing detection capabilities, and minimizes the likelihood of cyber incidents. However, challenges such as insufficient training, employee negligence, lack of continuous awareness programs, and evolving cyber threats continue to affect organizational cybersecurity. The study concludes that continuous cybersecurity education, regular policy updates, practical security training, and a strong security culture are essential for improving employee compliance behavior and strengthening organizational cybersecurity resilience. Keywords: Cybersecurity Awareness, Employee Compliance, Information Security, Cyber Threats, Phishing, Password Security, Multi-Factor Authentication.

Gade Venumadhav, A. Shaik, Pavani Mudem · 0 citations
Review Open access Sep 2026

Cybersecurity In Fintech Ecosystems: A Systematic Review of Threats and Security Strategies

FinTech's tremendous expansion has revolutionized the financial industry by making services like online lending, mobile banking and digital payments possible. Financial systems are becoming more vulnerable to cybersecurity risks, data breaches and financial fraud as a result of this digital transition. Strong cybersecurity has become a significant concern as financial institutions depend more and more on digital infrastructures. The research paper analyses the key vulnerabilities in digital banking systems and addresses the changing cybersecurity issues in FinTech ecosystems. In order to assess current academic research, industry reports and cybersecurity frameworks, the study uses a systematic literature review (SLR) methodology together with exploratory and descriptive research approaches. Important security algorithms utilized in financial transactions, such as AES, RSA, ECC, SHA-25 and SSL/TLS protocols, are also covered. The research found that existing solutions frequently address specific risks or separate security tasks, leading in inadequate protection across interconnected FinTech environments. Key research gaps include a lack of integration of various threat indicators, difficulties in explaining and detecting fraud in real time, interoperability concerns and insufficient integration of technological, organizational and governance-level security measures. Based on these findings, the study demonstrates the importance of an integrated and versatile cybersecurity architecture that includes multi-vector threat monitoring, behavioural analytics, intelligent fraud detection and risk management. Such hybrid method can improve detection capabilities, minimize false positives, boost data protection and increase the cyber resilience, consistency and trustworthiness of FinTech payment and financial service ecosystems.

Vedankita Mohod, R. Jugele · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.