• Non ci sono risultati.

CybeRisk Management in Banks: An Italian Case Study

N/A
N/A
Protected

Academic year: 2021

Condividi "CybeRisk Management in Banks: An Italian Case Study"

Copied!
1
0
0

Testo completo

(1)

CybeRisk Management in Banks: An Italian Case Study

Authors : E. Cenderelli, E. Bruno, G. Iacoviello, A. Lazzini

Abstract : The financial sector is exposed to the risk of cyber-attacks like any other industrial sector. Furthermore, the topic of CybeRisk (cyber risk) has become particularly relevant given that Information Technology (IT) attacks have increased drastically in recent years, and cannot be stopped by single organizations requiring a response at international and national level. IT risk is never a matter purely for the IT manager, although he clearly plays a key role. A bank9s risk management function requires a thorough understanding of the evolving risks as well as the tools and practical techniques available to address them. Upon the request of European and national legislation regarding CybeRisk in the financial system, banks are therefore called upon to strengthen the operational model for CybeRisk management. This will require an important change with a more intense collaboration with the structures that deal with information security for the development of an ad hoc system for the evaluation and control of this type of risk. The aim of the work is to propose a framework for the management and control of CybeRisk that will bridge the gap in the literature regarding the understanding and consideration of CybeRisk as an integral part of business management. The IT function has a strong relevance in the management of CybeRisk, which is perceived mainly as operational risk, but with a positive tendency on the part of risk management to the identification of CybeRisk assessment methods that are increasingly complete, quantitative and able to better describe the possible impacts on the business. The paper provides answers to the research questions: Is it possible to define a CybeRisk governance structure able to support the comparison between risk and security? How can the relationships between IT assets be integrated into a cyberisk assessment framework to guarantee a system of protection and risks control? From a methodological point of view, this research uses a case study approach. The choice of “Monte dei Paschi di Siena” was determined by the specific features of one of Italy’s biggest lenders. It is chosen to use an intensive research strategy: an in-depth study of reality. The case study methodology is an empirical approach to explore a complex and current phenomenon that develops over time. The use of cases has also the advantage of allowing the deepening of aspects concerning the "how" and "why" of contemporary events, on which the scholar has little control. The research bases on quantitative data and qualitative information obtained through semi-structured interviews of an open-ended nature and questionnaires to directors, members of the audit committee, risk, IT and compliance managers, and those responsible for internal audit function and anti-money laundering. The added value of the paper can be seen in the development of a framework based on a mapping of IT assets from which it is possible to identify their relationships for purposes of a more effective management and control of cyber risk.

Keywords : bank, CybeRisk, information technology, risk management

Conference Title : ICRFSB 2019 : International Conference on Risk, Financial Stability and Banking Conference Location : Zurich, Switzerland

Conference Dates : January 14-15, 2019

World Academy of Science, Engineering and Technology International Journal of Economics and Management Engineering

Vol:13, No:1, 2019

Open Science Index, Economics and Management Engineering Vol:13, No:1, 2019

waset.org/abstracts/93956

ISNI:0000000091950263

Riferimenti

Documenti correlati

As part of the above undertaking, auxiliary systems have also been developed to manage all municipal waste streams generated in the central part of the Region of Warmia

Since the over- expression of aqua1 in transgenic Villafranca clones induced a general increase of plants growth rate (i.e., RGR), in comparison to wt plants,

The aim of the present study is that of a preliminary assessment of the lifestyle, in terms of physical activity and nutrition, and the resulting body composition of the employees

In keeping with this idea CAFs within the primary tumors elicit achievement of stem-like traits (see above,.. Of note, the role of CAFs embraces also the preparation of

the development of novel bioremediation systems of waters polluted by the EDCs of interest AREA DI STUDIO Site 1 Site 2 Sample characterization (Mullus barbatus)

:XGT.cML&cMX N LZ[c:SUXGTkGe.X S4SMTQl‡L J=kGLSMT cESUKMTIGe e.KMN Z S L LWVSUc4SUN Z[IGe G\[NVWL NfSDTIG\ NnoL e.KMN 'Z SYNfSMZ[T.I Nf\ KUNJGZ^Z noKMT.] SMXGL L LWI SHXGT.KgZ

The problem of this work, is that of increasing the effectiveness of Petri net structures for system representational purposes. Petri net structures have several

L’autore, già docente dell’Università di Genova e per un cinquantennio ai vertici della Società Ligure di Storia Patria, illustra sinteticamente la consistenza del fondo