Rob Demain, CEO at e2e-assure, on why the clock is ticking when it comes to IT/OT convergence for Critical National Infrastructure (CNI) and associated organisations

Many critical national infrastructure (CNI) operators lack the ability to protect their infrastructure despite the UK being subjected to daily sub-threshold cybersecurity attacks, according to the Strategic Defence Review 2025. It’s a situation that the Network and Information Systems (NIS) regulations, introduced back in 2018, sought to prevent. But since its inception, just over half of the operators of essential services have updated or strengthened their existing policies and processes, leaving many woefully unprotected. 

In desperate need of reform, NIS is set to be superseded by the Cyber Security and Resilience Bill (CSRB), which is expected become law later this year, at which point a consultation on implementation proposals will commence followed by secondary legislation and an adjustment period for stakeholders. The bill will broaden the scope to include other organisations deemed critical to the national economy i.e. data centres, Managed Service Providers (MSPs) and critical suppliers. Plus, the government reserves the right to extend those categories still further as part of its ‘future proofing’, which will enable changes to be made to the act to accommodate emerging threats and potential targets. 

New Demands 

All of these new entities will need to comply with the Cyber Assessment Framework (CAF), which lays out expected cybersecurity and resilience outcomes. First published in 2018 to support NIS, it has undergone a number of revisions since, with v4.0 released in August 2025. This version places a far greater emphasis on proactive security and decision making based on real threat intelligence. As well as adding new contributing outcomes on understanding threats and secure software development and support, it also expands the sections on security monitoring and response and recovery, while an entirely new category has been added on threat hunting.   

All of this points to a far greater emphasis on being able to demonstrate assurance and proactively monitor all aspects of CNI infrastructure and that means more scrutiny of both IT and Operational Technology (OT). Until recently, securing OT wasn’t seen as a priority. These systems were chiefly concerned with maintaining system availability and minimising downtime. But their increased integration with IT systems to connect with the industrial Internet of Things (IIoT) and deliver real-time monitoring, for example, are exposing these systems to attack, with threat actors able to move laterally from one environment to the other.  

The threat posed by IT/OT convergence is well known, but it continues to be the Achilles heel of CNI, as revealed by the Volt Typhoon attack. This saw Chinese nation state actors maintain persistence across CNI in the USA since at least 2021 through the use of Living off the Land techniques, illustrating just how insidious and sustained these cybersecurity attacks can be. 

Securing IT/OT Systems 

It’s these types of threat the CAF addresses through its risk and asset management requirements. Organisations must risk assess systems with respect to their dependencies and interactions with other systems such as IT/OT, and document and understand those dependencies. But other complementary frameworks can also be used to map IT/OT system security, such as the ISMS within ISO27001 from an IT perspective and IEC 62443 from the OT side, in addition to ISO/IEC 27019 for process control systems. 

Being able to follow these frameworks will require organisations to increase their security monitoring of both IT and OT and the transparency of their processes. They will need to transition from being reactive to proactive, and become resilient and risk informed, which will mean many will have to change their approach. These are really the only options available to them in this respect if they are to move the resilience needle. 

The first is to decentralise and harden OT systems while keeping them segregated from IT. However, hardening alone can’t keep pace with digital transformation. Many OT assets cannot support multi-factor authentication (MFA) or accommodate rapid patching because they are downtime sensitive. So, surface hardening alone won’t confer the resilience needed long term.  

The second option is to manage IT and OT together by giving everything an identity in a converged environment, but to do that you need to move the monitoring of OT into the Security Operations Centre (SOC). Centralised monitoring allows threats to be detected across both IT and OT networks, for teams to monitor east-west traffic, and to correlate alerts that might otherwise appear unrelated. And it’s this centralised management that will provide the visibility and control needed to improve IT/OT resilience.  

Converged Cybersecurity 

Such a converged SOC doesn’t just offer continuous visibility over IT, industrial control systems (ICS), OT and cloud environs, but also the real-time triage of critical alerts. These might include unauthorised PLC logic changes, unsafe set-point writes, abnormal OT protocol behaviour, lateral movement in ICS DMZs, OT malware,or unauthorised remote access into OT environments. These alerts are then grouped by operational impact, such as whether they present a safety critical risk or could lead to service degradation, so that they can be prioritised. Weekly threat hunts and detection surface validation over distributed environments provide the threat hunting capabilities needed to meet the CAF requirements and the SOC evidences and provides that all important audit-ready compliance mapping to meet the demands of other frameworks too such as IEC 62443, and ISO/IEC 27019. 

Whether standing up a converged SOC internally or outsourcing, this capability is the most efficient way to adapt to the tightening regulations, particularly as we can expect ‘future proofing’ to lead to yet more demands. The emphasis is now firmly focused on the proactive monitoring of both IT and OT systems together, given their growing dependencies, so it makes sense for those organisations in scope – as well as those who could soon be – to begin to move their OT monitoring from the plant and into the all-seeing all-knowing enclave of the SOC.  

Learn more at e2e-assure.com

  • Cybersecurity
  • Cybersecurity in FinTech
  • Digital Strategy
  • Fintech & Insurtech

Karen Allan, Head of FinTech at HaysMac, on why building a company that can scale and stay ahead of regulation needs an auditor

In August 2025, the FCA launched a considerable overhaul of the safeguarding regime for payments and e-money firms. The result? PS12/25, a policy statement that makes clear the significant new expectations under CASS 15.

CASS 15 covers any firms which hold relevant funds above the qualifying threshold of more than £100,000, within a 53-week period, or expect to. As the May 7th deadline nears, firms can no longer ‘wait and see’. The requirement for a first CASS 15 audit is on its way, and for a firm to put its best foot forward, the preparation needs to start now.

Be Prepared for CASS 15

The new regulation is a big shift from the existing regime, and the requirement for a regulatory audit by a statutory auditor will make a considerable impact. The FCA has outlined extensive rules, and firms must comply with these ahead of the 7 May.

These changes include the need for daily reconciliations, as well as monthly reporting requirements on safeguarding funds. Planning for firm failures will also be a requirement, via a CASS 15 resolution pack. Similarly, there is the clear provision for the first CASS 15 audit to be completed within 6 months.

Many FinTech firms are run with as few employees as possible, as a way to stay agile. Under CASS 15, this won’t be as simple. Firms need to make sure they are structured correctly, with the right people in the right positions. Management also needs to lead by example, by supporting on regulatory oversight and compliance. The right tone and messaging from the top is particularly important.

Making the Right Partnerships

The new changes make a significant difference, and firms should start working with both a compliance advisor, to support with preparedness reviews, and a statutory auditor, to deliver CASS 15 audits. Finding a team of advisors who understand the rules and requirements in the new world of CASS 15 is key. By establishing strong partnerships now, firms can have a valuable outsourced ‘head of compliance’ to support further down the line. These can be crucial through rule mapping, for example, to identify problems, propose solutions, and deal with structural concerns a firm may have.

The best time to bring in an auditor before CASS 15 would’ve been when the policy was first launched, but the second-best time is now. Management should be engaging with auditors now who provide CASS 15 audits, to ensure they perform the right due diligence in identifying and bringing in the right partners for the job.

Compliance teams and directors should also be asking the right questions. Resources are an important concern, and when choosing an auditor, working out whether they can perform regular audits well, at all stages of a business scaling up, is vitally important. It may seem obvious, but is still foundational. Whether an auditor has the know-how to perform in the new CASS 15 world is key to consider.

Communication is the Key

These conversations should be starting now. Multiple advisors should be in the conversation to find the right match. Each firm is unique, and the audit and financial challenges they face will be different. Setting up a foundation of collaboration now makes sure that this will continue going forward.

The first year of a CASS 15 audit will not be easy. There will likely be a learning curve for the sector as a whole. Most likely, there will be breaches across the industry, and these will be reportable to the FCA. There are therefore likely to be difficult conversations needed with auditors.

Setting up advice and compliance partnerships now is important to avoid disappointment once we reach the 7 May. Starting the groundwork early, and allowing auditors to understand the firm’s entity, means they will more easily be able to recognise risk areas. This helps in developing a CASS 15 audit strategy, which in itself can be an advantage. All stakeholders can ensure that audit work is completed well within the deadline.

CASS 15 is not just an exercise for compliance. It’s an opportunity to use robust governance as an advantage ahead of the rest of the market. The new rules will be an unknown to both firms and investors, and getting your house in order first shows reliability and discipline to investors. In an industry where actions are louder than words, this is very important.

Many firms are now looking to strengthen their compliance at the cutting edge of fintech. If you want to stay ahead of the curve on regulation, and build a company that scales with confidence, approaching an auditor is an obvious next step.

Learn more at haysmac.com

  • Digital Payments

Dimitrios Bougioukas, VP – IT Security Training Services at Hack The Box, on how simulations can support security teams to detect, respond, contain and mitigate in real time

Financial institutions are operating in one of the most heavily targeted and scrutinised cyber environments in the world. They handle vast numbers of transactions, flows of sensitive personal data and have high-value digital infrastructures. Therefore, it is no surprise that the sector has invested heavily in technology. The aim is to ensure visibility of threats, including monitoring platforms, telemetry, alerting systems and threat intelligence. Yet, despite these investments, the visibility is not always translating into effective containment.

The Hack The Box Global Cyber Skills Benchmark 2025 analysed performance from 795+ teams and over 4,500 players. Carried out across 40 real-world Capture The Flag challenges, highlights this imbalance. 

According to the report, in simulated attacks, finance teams had a strong 37.6% average solve rate. Outperforming sectors like healthcare, education and government. They demonstrated great investigation skills, scoring 71% in OSINT, 54.6% in forensics and 51.4% in coding. These figures are all good indications that financial sector cybersecurity teams are able to effectively identify and analyse suspicious activity.

However, the report also shows there is significant underperformance in the skills required to stop attackers once they are inside. This means the gap is not in detection skills; it is in depth of capability.

Cyber Attackers Get Further Than They Should

The weakest scores are being recorded in the areas where adversaries could inflict the most damage.

According to the report, persistence scored just 21.1%, privilege escalation 20.3% and collection just 10.8% across financial cybersecurity teams. These are the tactics that determine how attackers entrench themselves, escalate access and gather sensitive data before exfiltrating it. They are central to adversarial movement inside financial networks.

Emerging threat vectors showed even more vulnerability. Blockchain security challenges, DeFi (Decentralized Finance) and smart contract–related vulnerabilities were only solved by the teams 10.1% of the time. And in exploit development, the teams averaged just 3.9%. This exposes weaknesses in exploit awareness, with the attackers increasingly using zero-day and near-zero-day vulnerabilities.

The combination of strong investigative skills and weaker adversarial resilience suggests that current capabilities are more focused on post-incident analysis than on preventing or containing attacks in real time.

Visibility Doesn’t Equal Control

Financial institutions have one of the most mature cybersecurity monitoring ecosystems across any industry. They deal with enormous volumes of logs, run highly tuned detection pipelines and leverage advanced SIEM and SOAR tooling. But this visibility on its own clearly does not equal security.

The benchmark report found that reconnaissance and initial access had solve rates between 23.8% and 28.4%, which indicates that many attacks will not be effectively blocked. From there, attackers are often able to succeed with their persistence, privilege escalation and lateral movement tactics because defenders do not have the technical depth to disrupt the attack chain at critical points.

In practice, this means teams may be able to see an attack unfold, but they will struggle to break it apart before data is collected for exfiltration. Even though exfiltration itself scored a relatively high at 53.4%, a low collection score suggests most teams are not catching malicious activity upstream, when intervention matters most.

A Depth Problem, Not A Monitoring Problem

This skills imbalance stems from how training and capability development have historically been structured. Much of the financial sector’s cybersecurity readiness has been shaped by compliance, audit frameworks and classroom-style instruction. While these approaches fulfil important governance functions, they do not by themselves produce the hands-on adversarial fluency that simulation-based training supports.

Financial teams must move beyond compliance checklists and legacy training models because they do not provide the attacker-aligned, hands-on experience required to strengthen deeper-layer defensive capabilities.

Attackers do not operate in silos and neither should defenders. A phishing foothold becomes privilege escalation, which becomes persistence, which becomes lateral movement – all in a matter of minutes. Without having continuous practice in this full attack flow, teams will continue to be strong in analysis and weak in action.

Continuous, scenario-based upskilling is the clearest path to addressing this imbalance. The benchmark data in the report demonstrates the need for a cyber readiness model that is based on realistic adversarial simulation. These simulations don’t just replicate individual techniques; they replicate entire attack chains. This forces security teams to detect, respond, contain and mitigate in real time.

Learn more at hackthebox.com

  • Blockchain & Crypto
  • Cybersecurity in FinTech

Michele Centemero, EVP Services, Mastercard Europe on why promoting awareness, stronger collaboration and data-sharing, and continued innovation of payments ecosystems, will be critical in reducing the impact of scams and protecting trust in the digital economy

As our world becomes faster, smarter and more interconnected, scammers are evolving in parallel, developing increasingly sophisticated ways to exploit people’s trust. By harnessing new technologies and behavioural insights, they are refining their methods to appear ever more credible and convincing.

While attacks on systems continue, today’s fraudsters are increasingly targeting people, often relying on psychological manipulation to achieve their goals.

Understanding Social Engineering

Many modern scams fall under the umbrella of social engineering,which isthe use of deception and emotional manipulation to influence a person’s behaviour.

In the digital world, cybercriminals use these tactics to build false trust, create urgency or fear, and ultimately trick people into sharing confidential information or taking actions that can cause financial harm to themselves or their employer.

Recent European industry data indicates that social engineering-related fraud and authorised push payments (APPs) – where victims are tricked into sending money to fraudsters posing as legitimate payees – now account for a growing share of overall scam losses[1].

This is directly impacting a growing number of consumers, with the majority of people saying they’ve experienced some form of scam or fraudulent attempt to capture their personal information highlighting why awareness and vigilance are critical for people of all ages.

Education is the First Line of Defence

Protecting consumers and businesses from malicious activity is a priority, and it starts with awareness. When people understand how scams work, they’re more likely to spot the warning signs before it’s too late and be empowered to protect themselves against fraudsters.

Three of the most common social engineering scams to watch out for are:

  • Imposter fraud – Criminals pose as trusted organisations (such as banks, retailers, or government bodies) to pressure victims into sharing personal or financial details. Research indicates over half (53%) of European consumers have been targeted via phone or voice call scams, with social media scams affecting around two in five people, and tech support impersonation tricking roughly one in three.*
  • Phishing – Fraudulent emails, texts, or messages that are designed to look legitimate, often urging immediate action like clicking a link or resetting a password, leading victims to disclose sensitive information or install malicious software. Nearly three in five (58%) have received phishing emails or fraudulent text messages (63%) and QR code scams are on the rise, impacting nearly a quarter of Europeans.*
  • Romance or honeypot scams – Scammers build emotional relationships over time, gaining trust before exploiting it for financial gain. These types of attacks are also widespread, with one in four people (24%) encountering fake profiles, requests for money, or online relationships that lead to financial exploitation. These scams hit younger generations hardest, with 40% of Gen Z and 35% of Millennials affected, compared with 21% of Gen X and 11% of Boomers.*

How Businesses Can Protect Consumers from Scams

With fraudsters increasingly using AI to commit more sophisticated, larger scale attacks, businesses and banks should also consider how they deploy technology to protect customers from bad actors.

The combination of AI, robust identity controls and open banking can help protect consumers from scams, whether across card and account‑to‑account payments or in fraudulent account openings.

Looking at identity controls specifically – take the example of continuous identity verification, a fraud prevention measure that verifies the user is who they claim to be throughout the entire lifecycle journey. This helps to prevent scammers from opening or taking over accounts to apply for credit, create ‘mule’ accounts or impersonate others.

Behavioural biometric data is often used as part of this and can be used to analyse how a user interacts with their device – from typing patterns to on‑screen movements – to flag unusual behaviour.

More in depth, AI powered transaction analysis can also help banks and financial institutions to stay ahead of payment threats. It provides banks with the intelligence needed to detect and stop payments to scammers, using AI and a network-level view of account‑to‑account transactions to enable intervention before funds leave an account.

Staying Ahead of an Ever-Evolving Threat

As social engineering tactics continue to evolve, staying ahead requires a combination of intelligent technology, consumer education, and proactive action from businesses and financial institutions.

While no single measure can eliminate risk entirely, greater awareness, stronger collaboration and data-sharing, and continued innovation of payments ecosystems will be critical in reducing the impact of scams and protecting trust in the digital economy.

*Source: This study was conducted by The Harris Poll on behalf of Mastercard from September 8 to September 25, 2025, among 5000+ consumers in the following European markets: EUR: France (n=1,005), Germany (n=1,002), Italy (n=1,016), Spain (n=1,005), UK (n=1,004)

Mastercard: Transforming the Fight Against Scams

Innovation – Our advanced AI-powered Identity insights examine digital footprints and assess unique patterns to detect risk and flag suspicious activity indicative of scams.

Collaboration – We collaborate across industries, partners and organizations worldwide to secure the digital ecosystem, ensuring payments are safe for all. Combating the growing threat of scams demands a collective effort.

Education – We work with and through our collaborators to provide knowledge and tools that help people protect themselves and their loved ones from scams, while also working to destigmatise the experience of being a victim.

  • $12.5bn in losses from U.S. consumer reported online scams in 2023
  • $486bn in global losses from scams and bank fraud schemes in 2023
  • 22% YoY growth in U.S. consumer scam losses suffered in 2023

From sender to recipient, we vigilantly monitor accounts and transactions for any elevated scam risk

Identity insights – Provides actionable identity insights and risk scores for businesses to improve identifying their good customers from the scammers creating “mule” accounts or impersonating someone else with a false identity.

Transaction patterns – Flags suspicious activity across the money movement flow to prevent payments to scammers before it is sent through the real-time analysis of transaction elements.

Account confirmation – Enables account validation to confirm account ownership and validate identity details in real-time through our open banking capability, which draws on the safe exchange of consumer-permissioned data to facilitate frictionless and secure payments.

Learn more at mastercard.com


[1] Joint EBA-ECB report on payment fraud: strong authentication remains effective, but fraudsters are adapting

  • Artificial Intelligence in FinTech
  • Cybersecurity
  • Cybersecurity in FinTech
  • Digital Strategy
  • InsurTech

Richard Ford, Chief Technology Officer at Integrity360, on why cybersecurity must move beyond control and embrace trust

Cybersecurity has long been focused on building walls, but the biggest threat is already inside. Today, insider risk accounts for nearly half of all data breaches. This isn’t just about malicious actors, it’s about regular employees and trusted contractors who make simple, costly mistakes.

Remote and hybrid working has only intensified the problem. With teams distributed and work happening across cloud platforms and collaboration tools, it’s harder than ever to track what’s happening, let alone why. Although AI tools promise efficiency, they also introduce new vulnerabilities. Employees pasting code into chatbots or bypassing corporate tools to meet deadlines. All seemingly innocent, but highly risky.

Insider Risk

Ransomware gangs know this and are now skipping the technical breach altogether and going straight to the source – a company’s insiders. Whether through bribery or social engineering, attackers are finding that humans can be the weakest link in even the most well-defended environments. Despite this, most security budgets still focus outward.

Traditional tools like data loss prevention (DLP) struggle to keep up with today’s dynamic and unpredictable user behaviour. Meanwhile, simulated phishing tests and punitive training schemes often breed resentment, not resilience. It’s time to rethink the model.

Human Error, Human Fix

We need to stop treating employees as the problem and start making them part of the solution. Enter Human Risk Management (HRM), a behavioural approach to cybersecurity that recognises the complexity of modern work. HRM tools monitor real-world user behaviour, detect anomalies in context, and deliver just-in-time nudges to prevent risky actions before they happen. Instead of punishing mistakes, they help users avoid them in the first place.

Of course, technology alone won’t fix the issue, culture is key. Leadership must champion security as a shared responsibility, not an IT rulebook. Success should be measured by how quickly employees improve, not how often they slip up. Awareness campaigns need to be practical and rooted in real-world behaviour.

Organisations also need to understand how digital transformation has changed the risk landscape. Shadow IT is no longer a fringe issue, it’s how work gets done. Whether it’s a developer using an AI plugin or a marketer sharing files via a personal drive, employees will always find the fastest path to productivity. Security must meet them there, not block the way.

Cybersecurity Built on Trust

The smartest businesses are those that treat identity like infrastructure, and behaviour like a vital data stream. They invest in tools that adapt to people, not the other way around. This means a move away from a surveillance approach and embracing the nuance of human error and design systems that support.

In a world where threats are increasingly internal and AI is both a risk and a tool, cybersecurity can no longer be about control. It must be about trust, and that starts with understanding the humans behind the keyboards.

Learn more at integrity360.com

  • Cybersecurity
  • Cybersecurity in FinTech
  • Digital Strategy
  • Infrastructure & Cloud

Pierre Noel, Field Chief Information Security Officer at Expel, on why security with community-based governance is a key business pillar that better positions organisations to become more resilient and target growth

It’s been a particularly rocky start to 2026 for the global cybersecurity landscape. From the Substack data breach to PayPal credential-stuffing attacks in February, we are not looking at IT failures alone. These attacks are balance-sheet events: direct assaults on business value, triggering remediation costs and long-term impacts on financial health. Compounded with the conflict with Iran, leading to potential ramifications in the cyber realm, it’s more important than ever for the C-suite to be aligned on cybersecurity priorities.

Despite this, a glaring disconnect remains in planning and execution. Expel’s research found that while 85% of finance leaders view cybersecurity as a key component of business planning, only 40% express full confidence in security’s ability to align with business strategy. To bridge this gap, CISOs must move from reporting on activity and start reporting on resilience and unit cost.

Translating Alert Volume Into Unit Cost

CISOs must change how they present the value of their operations. CFOs are largely indifferent to technical metrics like the ‘millions of blocks pings’ or ‘SOC alert volume’ – to a finance leader, an alert is simply another form of disruption to daily operations.

To fix this, CISOs should introduce the ‘unit of cost protection’. By breaking down security spend into the cost required for a single transaction or business unit, CFOs can understand and manage it from experience. A tiered approach works best here: high-risk business units justify higher protection costs than low-risk ones. This allows CFOs to treat security as a scalable operational expense rather than a black hole of additional tooling – the kind of framing that also resonates in a boardroom.

Mapping Investment to Business Risk Exposure

Expel’s research shows that while 43% of finance decision-makers are confident that security can prioritise investments based on risk, only 46% are confident that security can deliver cost-efficient solutions. To move in the right direction, CISOs should shift from ‘vulnerability management’ to thinking about ‘business risk exposure’, requiring a different view of how threats unfold over time.

It’s all about asking the right questions. Instead of requesting more firewalls to protect a specific timeframe, start asking for the cost of securing diverse digital ecosystems across an extended risk window. The 2026 Winter Olympics is a good example: Russian-led cyber campaigns began raising concerns months before a single athlete arrived in Italy, proving that risk isn’t a one-day event but an ongoing operational cost.

For European organisations, this framing is increasingly non-negotiable. While NIS2 and DORA help make the cost of under-investment concrete and quantifiable, the upcoming Cyber Resilience Act (CRA), with key reporting requirements starting in September 2026, extends this pressure to anyone manufacturing or selling digital products in the EU. Even for purely domestic UK entities, the new UK Cyber Security and Resilience Bill is moving the goalposts toward these same high standards. Ultimately, CFOs must understand that cybersecurity isn’t just about preventing loss; it’s a prerequisite for safe and secure growth.

The Reputational Multiplier

So those are the questions to ask, but how do CISOs deal with the ‘unknown unknowns’, specifically long-term brand damage? While compliance fines under NIS2 or DORA may be straightforward (and important) to model, they rarely represent the full scope of the potential damage. In such scenarios, CISOs should propose a reputation multiplier: a framework for quantifying the financial fallout of brand damage in a language CFOs know and trust, looking past immediate recovery costs to factor in the long-term implications of re-establishing market trust.

The 2026 CarGurus breach illustrates this well. Impacting 12 million users, the cost wasn’t purely technical; it also came from the stock price dip and marketing spend required to repair the brand. For UK companies, where regulatory scrutiny is heightened, that multiplier effect is even more pronounced. This is the language of a CFO, and it helps CISOs better translate the urgency and relevance of a strong cybersecurity posture.

Standardising the Language of ROI

Closing the gap between CFOs and CISOs needs more than just better data; it needs a shared vocabulary. By standardising the language of ROI, CISOs transform cybersecurity from a vague insurance policy into a transparent value driver fully trusted by finance teams. Move away from complicated defensive jargon toward a unified framework of unit costs, and the gap between the CISO and CFO starts to close.

Security has become a key pillar of business operations, and in the current threat environment, it’s genuinely a community-based governance issue. The organisations that get this right aren’t just more resilient. They’re better positioned to grow.

Learn more at expel.com

  • Cybersecurity
  • Cybersecurity in FinTech
  • Digital Strategy
  • Infrastructure & Cloud

New research from Aqua Global shows banks are struggling to keep up with compliance, as legacy tech drags them down

Aqua Global, the financial messaging hub built for payments, treasury and securities processing, today revealed research showing European banks are prioritising compliance over customer experience as legacy infrastructure struggles to keep pace.

The survey of 150 European IT banking leaders, with half based in the UK, showed that:

  • Regulation is putting a drag on innovation:
    • 77% of respondents say regulatory demands outweigh customer demands when it comes to payment modernisation.
    • 67% spend more effort adapting systems to new standards than improving customer experience.
  • Banks fear missing milestones – but can’t keep up:
    • 77% say missing a key regulatory milestone would cause significant operational and reputational damage.
    • But 60% admit their existing infrastructure struggles to keep pace with evolving standards.
  • Richer data requirements expose structural weaknesses:
    • 72% admit richer data requirements (e.g. AML, sanctions, fraud) have exposed gaps in their current infrastructure.
    • Structured addresses, AML/sanctions-related data and counterparty identifiers (BIC/LEI) are the most difficult piece of data to capture.

“The challenge with richer payment data isn’t availability, it’s fragmentation. Information sits across multiple systems and formats, making it hard to build a complete, trusted view of a transaction. The ability to manage, govern and validate data at scale is quickly becoming a defining factor in payments resilience. This is why 81% of respondents believe a unified messaging hub across multiple channels will be essential to remain compliant and competitive in the future.” Elliot Wood, Chief Technology Officer at Aqua Global.

ISO 20022 and T+1: Regulatory Compression Exposes Legacy Fragility

One in five respondents experienced downtime and/or payment disruption during migration to the new ISO 20022 standard. Almost all respondents (97%) experienced challenges, with the top three cited as:

  1. Legacy systems unable to handle structured ISO 20022 data.
  2. Poor underlying data quality for enriched ISO 20022 fields.
  3. Integrating challenges with other third-party systems, such as AML, sanctions and fraud systems.

As a result, 65% still rely, at least in part, on translation tools to remain compliant, even though 83% believe such short-term fixes will prove more costly in the long run.

The same structural weaknesses are now surfacing in preparation for T+1 settlement. While 21% of banks have taken action to prepare, almost a quarter (23%) have no plans in place. Legacy systems incapable of supporting compressed settlement windows without significant investment remain the most cited barrier.

Together, ISO 20022 and T+1 highlight a broader issue: regulatory timelines are accelerating faster than banks’ infrastructure can adapt.

“The migration challenges we’re seeing aren’t isolated incidents – they expose the structural limits of legacy payment architecture,” says Cian Fernando, CEO of Aqua Global. “Treating regulatory change as a tick-box exercise encourages short-term fixes that increase complexity. Banks that modernise natively reduce cost, operational risk and friction over time. As regulatory deadlines tighten and data requirements grow richer, banks relying on fragmented systems face rising operational risk and mounting cost pressures, with less capacity left to compete on customer experience.”

To learn more download the full From Compliance Burden to Competitive Advantage report

About Aqua Global

For over 43 years, Aqua Global has delivered a robust suite of financial messaging and transaction automation solutions for payments, treasury, and securities processing that integrate internal systems to external services. Trusted by leading banks across 22+ countries, our Aquila orchestration and integration framework offers exceptional performance, control, and scalability.

Learn more at aquaglobal.co.uk

  • Cybersecurity in FinTech
  • Neobanking

Chris Gunner, vCSO at Thrive – a leading NextGen MSP/MSSP, delivering global AI, cybersecurity, cloud, compliance, and digital transformation managed services – on how CISOs can position their cyber strategy to to become part of how a business navigates uncertainty

Quantification of cyber risk is a growing trend. While this can be genuinely useful, in practice it is often misunderstood or over-applied by security leaders. It can range from an arbitrary figure to attempting to model every possible risk on the register in a Monte Carlo simulation. The focus can fall on the mechanics of quantification, rather than how financial decision-makers actually use the information.

Think of the CFO – they don’t walk through every penny in the budget. Instead, they usually focus on the board-level levers that can materially affect the business. These often include three key areas: strategic optionality, removing friction from capital events and avoiding shocks and smoothing operating costs. Security conversations should be anchored the same way.

The Importance of Strategic Optionality

If faced with a credible one-year growth plan, CFOs may recommend a one-year office lease despite a 20% premium. This is because it maintains the option later of moving or re-contracting once the growth trajectory becomes more visible. Like most strategic decisions, it is about preserving flexibility in the face of uncertainty, even if that flexibility comes at a short-term cost.

If we apply this to a cyber context, there are often businesses that have taken a calculated gamble with their existing business strategies. While the plan is sound, there is a chance it might not land as expected. When they require security services, the choice between a ‘standard’ and ‘premium’ SOC frames the decision as one of optionality rather than security spend. Paying more now to preserve the ability to adapt later down the line. A simple illustration is incident response. An on-call retainer with defined response times can look more expensive than ad hoc support. Until an incident occurs and procurement becomes the bottleneck. In those moments, flexibility is often far more valuable than marginal savings achieved earlier.

Removing Friction from Capital Events

For CFOs, especially those operating in the alternative investment space, the focus is on structuring capital events. As opposed to managing day-to-day operational costs. One of the most painful points in that process is due diligence. The careful exchange between acquirer and target that aims to provide enough information for each to price risk, without giving the entire game away.

CISOs can materially influence how smooth or painful that process becomes. The most effective support often comes from understanding upfront what the diligence process will look like and preparing accordingly.

For example, they might develop executive-level ‘Security at ACME’ overviews to sit alongside more detailed trust centre or technical reports. Being available to diligence teams for interviews, and for example clearly articulating which services are outsourced to an MSSP, and why, builds credibility between those executive teams.

Decision-makers often don’t look at penetration test reports at a deal level. They are assessing whether the organisation understands its own control environment. A well-prepared CISO who can clearly explain why certain controls exist acts as a trust amplifier during transactions.

It is often the difference between a diligence process that closes cleanly and one that drifts. Two organisations can have similar maturity. Yet the one that can respond within a day with clear, consistent evidence reduces follow-up questions, avoids uncertainty premiums in pricing discussions and prevents security from becoming a late-stage negotiation point.

Avoiding Shocks and Smoothing Operating Costs

For any individual who has worked with a finance partner to define a departmental budget will know that predictability often takes precedence over absolute cost. Contract value can be secondary to payment terms, renewal timing or the ability to forecast spend with confidence.

CISOs can align with this by looking to reduce unplanned operating expenditure. In addition to understanding the cost structure of their controls by communicating with the technical pre-sales engineer, procurement and account teams.

A good example is cyber insurance. While often purchased directly by finance teams, many policies are relatively off-the-shelf and provide access to services the security team already operates or has under contract. Other policies include notable exclusions for the events most likely to occur. Such as a ransomware incident without business interruption cover. In many cases, these gaps can be addressed in-policy with a flat fee or a more predictable cost model.

The value here extends beyond risk transfer and into more predictable costs: replacing reactive spend with planned expenditure.

Aligning Cyber Conversations to Board Priorities

Across all of the above examples, the common thread is that the board is rarely asking security to prove its value in isolation, and is surprisingly comfortable with uncertainty. But they are asking whether the cyber papers support better decisions, fewer constraints and more predictable outcomes for the business as a whole.

CISOs who frame their priorities in those terms will find their conversations move away from justifying individual controls and towards understanding how security choices shape the organisation’s ability to respond to change. In that context, cyber becomes part of how the business navigates uncertainty, rather than a specialist function defending its budget. Speaking the board’s language, ultimately, is less about converting cyber risk into pounds and pence. It is more about understanding which levers matter at that level and showing how security choices influence them.

Learn more at thrivenextgen.com

  • Cybersecurity
  • Cybersecurity in FinTech
  • Digital Strategy

Obrela’s Dr. George Papamargaritis (EVP MSS) and Dr. Konstantia Barmpatsalou,  (Blue Team Support Manager) on why embracing a risk-led cybersecurity model will leave financial organisations better positioned not just to meet regulatory requirements but to strengthen resilience, protect customers and uphold the trust that is so essential to the future of financial systems

Cybersecurity in the financial sector was once viewed as a compliance-driven discipline. But as attackers have increasingly targeted institutions with sophisticated, persistent and often internally driven campaigns, it has become a strategic priority.

According to the Digital Universe Report H1 2025, financial services were the second most targeted industry globally, accounting for 19% of all observed cyberattacks. This reflects both the sector’s value to adversaries and the complexity of the digital ecosystems it now operates within.

Regulatory frameworks such as the FCA and PRA’s operational resilience rules, the EU’s Digital Operational Resilience Act (DORA) and NIS2 have strengthened baseline protections. However, the report’s findings demonstrate that regulation alone cannot deliver true cyber resilience. Institutions must adopt a strategic, risk-led approach that looks beyond compliance to understand real threats, behaviours and operational dependencies.

Tailored, Internal and Stealthier Threats

One of the most striking insights from the report is how targeted financial sector attacks have become. Industry-specific security risks now represent 32% of all incidents in the sector. This is an indication that adversaries are designing attacks using detailed knowledge of financial operations, from trading workflows to payment systems.

Internal activity is also a major concern. Suspicious internal activity accounts for 26% of detections across financial services, reflecting the frequency of compromised accounts, misused privileges and lateral movement. For a sector historically focused on defending the perimeter, this shift highlights the need for deeper visibility into user behaviour and identity-driven risks.

The wider threat landscape reveals adversaries are moving away from overt, signature-based attacks. In H1 2025, brute force activity made up 27% of global alerts, while vulnerability scanning accounted for 22% and known malicious indicators for 20%. Notably, direct malware payloads dropped to 0% of trending alerts, replaced by fileless techniques and living-off-the-land methods that bypass traditional defences.

For financial institutions, this is a challenge. Many compliance requirements still centre on endpoint protection, patching and malware controls. These will of course, remain important, but they cannot address threats that are increasingly behavioural, stealth-driven and identity-focused.

Operational Complexity

The financial sector’s cyber risk is intensified by its expanding operational footprint. Cloud adoption, open banking, digital identity models and extensive third-party ecosystems have all created new points of exposure. Financial services operate within a global digital infrastructure that is both vast and increasingly interconnected. This level of complexity cannot be effectively protected through compliance checklists alone.

Regulators are recognising these realities. DORA’s emphasis on ICT third-party risk, operational resilience testing and continuous oversight reflects the need for more proactive, intelligence-driven approaches. But DORA still only sets a minimum standard. True resilience requires institutions to move beyond regulatory expectations and embed cybersecurity into broader business strategy.

Strategic, Risk-Led Cybersecurity

A risk-led approach begins with understanding the threats that pose the greatest risk to operations and customers. Financial institutions remain priority targets for groups such as FIN7, TA505, Cobalt Group and various state-backed actors. Their tactics, such as credential harvesting, remote access tools, web-injection frameworks and lateral movement, are specifically designed to exploit the digital fabric of financial services.

This evolving threat profile puts identity and behaviour at the heart of cyber defence. With credential-driven and internal threats so prevalent, institutions must prioritise behavioural analytics, continuous authentication and zero-trust models that verify users and devices contextually rather than relying on static controls.

Strategic cyber resilience also needs to have continuous assurance. Traditional audits, annual testing and scheduled penetration exercises cannot keep pace with rapidly evolving threats. Leading institutions are shifting toward continuous control monitoring, automated attack simulation and persistent adversarial testing. These practices align with the Bank of England’s CBEST framework and demonstrate a sector-wide move toward ongoing, intelligence-led assurance.

Crucially, cyber risk must be treated as an operational issue, not just a technical one. Embedding cybersecurity into enterprise risk management, financial planning, product development and board oversight is essential. This integrated approach also mirrors the direction of FCA and PRA regulation, which increasingly emphasises governance, accountability, and resilience across the entire organisation.

Beyond Compliance

Financial services underpin national economies and public confidence. As digital ecosystems grow and adversaries become more sophisticated, the sector faces a dual challenge: meeting rising regulatory expectations while defending against complex, targeted attacks. It is clear that cybersecurity must evolve from compliance-driven activity to a strategic capability built on intelligence, continuous assurance and behavioural insight.

Institutions that embrace this risk-led model will be better positioned not just to meet regulatory requirements but to strengthen resilience, protect customers and uphold the trust that is so essential to the future of financial systems.

Learn more at obrela.com

  • Cybersecurity
  • Cybersecurity in FinTech
  • Digital Strategy
  • Fintech & Insurtech
  • InsurTech

Jack Bingham, Regional Director of Digital Native UK, Ireland & South Africa, Confluent on how data, treated properly, compounds in value to drive digital disruption

When I talk to founders and tech leaders, one question seems to consistently come up: what separates today’s disruptors from the last decade’s? In 2010, being cloud-first was what made investors sit up and take note. In 2026, it will be streaming-first.

I’ve spent the last year or so working closely with companies that are, quite literally, building their businesses in real time. For them, real-time capability isn’t a department or a layer that supports the business. It is the business. The acid test is simple: how quickly can you capture a critical event – a payment, a login, a failed delivery – and respond with the next best action? That focus shapes how they build products, structure teams, and think about innovation.

Here’s what I’ve learned from them:

Lesson 1: Data is a Product, Not a By-Product

Many traditional companies still treat data as something to collect, store, and analyse later. The new generation of businesses, on the other hand, treats it as a reusable, governed product that everyone can access. When it’s built and shared this way, teams stop rebuilding the same foundations for every new use case. They move faster because they’re working from a single, trusted view of the truth, shortening product cycles, speeding up iteration, and spending more time solving problems that matter.

That mindset, rather than the size of the tech stack or the number of engineers, is what sets disruptive businesses apart. In these organisations, technology, data, and business strategy move in lockstep. Decisions aren’t passed up and down hierarchies, they’re made by teams who understand both the data and the customer problem in front of them.

When you can trust your data and respond in real time, innovation stops being a department. It becomes a reflex.

Lesson 2: Real-Time isn’t a Feature, it’s a Foundation

A few years ago, one of the world’s largest supermarket chains realised it didn’t have a single real-time view of its inventory. Without that visibility, omnichannel experiences were impossible. Once it shifted to a streaming architecture, every transaction became a live event that updated stock, triggered supply chains, and even made it possible to get your groceries delivered straight to your kitchen fridge – coordinated through live inventory data, smart home devices, and real-time security feeds.

That’s the practical power of streaming: it connects what happens in your business to what should happen next so you can provide products and services that take customer satisfaction to a whole other level. Real-time data stops being a reporting tool and becomes the foundation of every decision, interaction, and innovation.

I often ask businesses what they would do differently, if they knew the state of every event in their organisation. The most forward-thinking companies already have the answer. They’re using streaming to turn business events into reusable building blocks, creating new experiences by connecting the data they already have in smarter ways.

Lesson 3: Culture is the Multiplier

Being streaming-first is only half about architecture. The other half is attitude. The best digital enterprises don’t wait for permission to experiment. They map their most important business events, align teams around them, and empower people at every level to react fast and learn faster.

And the difference is visible. Feedback loops are shorter. Structures are flatter. Failure is treated as information. This culture of continuous experimentation is why these companies can move at the pace they do.

We often run ‘Event Storming’ workshops with teams to map their critical business events. The idea is to create alignment – getting people from engineering, product, and operations to agree on what really matters and how those moments connect. That process reveals a lot. 

Digital disruptors go beyond simply deploying streaming architectures. They build streaming mindsets. Leadership plays a crucial role here: data must be treated as a strategic asset. If it isn’t up top, it won’t be anywhere else in the organisation either.

Lesson 4: Streaming and AI will Converge

AI is only as good as the data you feed it. Unfortunately, most enterprises are still feeding it yesterday’s data. Streaming-first companies already know this. They’re building intelligent data pipelines that give AI the context it needs to make decisions in real time.

That’s how the next generation of innovators will pull ahead: not by having bigger models, but by having cleaner, faster, more connected data. Streaming is what will let AI move from reactive to predictive… and from predictive to autonomous.

Too many organisations are cutting investment in data while pouring money into AI projects. But AI without quality data is just expensive guesswork. The companies doing this well understand that data has to be a product in its own right. And when business and technology teams design around that shared understanding, innovation follows naturally.

Lesson 5: The Mindset of the Next Disruptors

If I were starting a company tomorrow, I’d look closely at the critical events that run my business. I’d then make sure I had a way to capture those in the stream, make them reusable, and build every product and process around them. 

When your business can see and act on what’s happening in the moment, you gain something no traditional architecture can give you: time. And in the next wave of disruption, that’s the only advantage that really matters.

If we look to who we can learn from in the coming months, it’s financial services and healthcare that are moving the fastest. Real-time fraud detection, patient monitoring, and risk management are becoming operational necessities – and these industries will set the benchmark for real-time data excellence. 

Looking Ahead to 2026

By 2026, I don’t think we’ll talk about ‘real-time’ as a differentiator. It will simply be how modern businesses operate. Batch systems won’t disappear, but they’ll coexist within a single, streaming-first platform that delivers data whenever it’s needed.

Once every process can react instantly, the question then becomes: can it anticipate? Can it learn? That’s where AI and streaming meet and where we move from reactive to autonomous enterprises that not only respond to the present but adapt to what’s coming next.

Data, treated properly, compounds in value. The decisions you make with it become faster, sharper, and more confident. The companies that understand this will be the ones still leading when today’s titans look like yesterday’s news.

Learn more at confluent.io

  • Artificial Intelligence in FinTech
  • Data & AI
  • Digital Payments
  • Digital Strategy
  • Embedded Finance

Dan Nichols, Chief Technology Officer at virtualDCS, on why cloud resilience in the financial services sector hinges on shared accountability and an assume-breach philosophy

A powerful catalyst for transformation, the cloud is reshaping how organisations compete in the financial services sector. Beyond significant cost savings and flexibility, leaders are eager to unlock the potential of AI-driven insights, intelligent automation, and real-time business modelling. And, in a space governed so strictly by data sovereignty and privacy policies, the cloud’s ability to localise, encrypt, and control data has made it a key enabler of compliance and customer confidence.

But as threats become more frequent and sophisticated – with attackers now targeting shared platforms and partner supply chains – organisations can no longer rely on their own defences alone. For true digital resilience, shared accountability, collective readiness, and clear governance across every cloud touchpoint are equally non-negotiable.

All Eyes on the Money

The industry sits at a valuable intersection of data, technology, and finance. A combination that makes it uniquely attractive to attackers. It holds some of the world’s most sensitive data, directly underpins the flow of global capital, and operates through deeply complex and interconnected systems. With every integration increasing the risk of exposure. Ultimately, the attack motivation is as simple and relentless as it is in most sectors: monetary gain. Cybercriminals target institutions precisely because of the value at stake and the speed at which disruption translates to loss.

How the Threat Landscape is Evolving

Ransomware groups may see insurers and payment providers as high-yield targets. They understand even seconds of downtime can induce multi-million pound losses. Under pressure to protect customer trust and avoid regulatory penalties, some firms may choose to pay in order to restore their service quickly. This dangerous perception only encourages repeat targeting and paves the way for damage to spread even further. Yet it remains a common response tactic among many.

At the same time, the rise of supply chain and third-party attacks has made it possible for criminals to bypass even the most well-defended cloud environments. By exploiting shared platforms, managed service providers, and cloud-hosted applications, perpetrators can move laterally across multiple organisations at once, amplifying both the reach and impact of their attacks. In other words, infiltrating one vendor’s weakness can cripple an entire network in one carefully coordinated strike. And, since some firms may overlook the cloud’s shared responsibility model – presuming end-to-end security sits solely with their cloud provider – multiple blind spots can inevitably emerge, creating easy openings to exploit.

In an environment where boundaries blur and dependencies multiply, traditional perimeter-based defences are no longer enough. Hybrid and multi-cloud infrastructures demand continuous visibility, faster detection, and coordinated response across every partner and provider. The goal is not simply to prevent breaches, but to withstand and recover from them collectively. It’s about recognising that in today’s ecosystem, no financial institution is secure in isolation.

Inside the Ransomware Economy

Evolving beyond the scattergun attacks of the past, ransomware now operates as a professionalised, profit-driven ecosystem, where malicious actors collaborate, trade intelligence, and lease attack tools much like legitimate software vendors. The rise of ransomware-as-a-service (RaaS) has even lowered the barrier to entry, giving less skilled affiliates access to ready-made payloads and automated encryption kits in exchange for a percentage of the ransom.

What makes it especially destructive is the precision and psychology behind the attacks. Rather than randomly striking, attackers conduct weeks of reconnaissance – learning behaviours, studying employee hierarchies, and identifying systems most critical to operations. They often infiltrate through phishing emails or compromised credentials, quietly moving laterally through the network to gain elevated access. Once embedded, they disable defences, exfiltrate sensitive data, and target backup repositories before finally encrypting production systems.

At that point, the goal shifts from technical control to financial coercion. Victims are locked out of their systems and presented with a ransom note demanding payment, sometimes in cryptocurrency, in exchange for a decryption key. Increasingly, the threat includes public exposure of stolen data – a tactic designed to pressure leadership into paying to protect their reputation and customer trust. Even when ransoms are paid, recovery is rarely clean: data may be incomplete, corrupted, or resold on the dark web, and repeat targeting is common once an organisation is identified as a payer.

It’s this blend of stealth, strategy, and human manipulation that makes ransomware so difficult to defend against. By the time the encryption begins, attackers have already spent weeks ensuring recovery options are limited. This background isn’t designed to scaremonger, but to highlight why resilience must start long before an attack ever reaches the endpoint.

The Foundations of Ransomware Resilience

Ransomware resilience isn’t achieved through a single product or policy – it’s the outcome of strategic, technical, and cultural alignment. Financial institutions, in particular, must approach it as a continuous process of readiness: Anticipating compromise, containing impact, and restoring normality quickly and transparently:

Assume-Breach Philosophy

The first step is shifting from a defensive mindset to an assume-breach philosophy. In practice, this means recognising that even the most sophisticated systems can and will be breached – and building architectures and response strategies designed to limit damage when this happens. It’s a pragmatic approach, grounded in the reality that attackers are increasingly sector agnostic. No organisation is too small or too secure to be targeted, but the financial sector remains a favourite because it offers both high disruption value and potentially significant monetary reward.

Building meaningful resilience, therefore, demands layered defence and disciplined execution. The goal is to slow attackers down at every stage – detecting them early, limiting lateral movement, and ensuring business continuity when systems are disrupted. Behavioural analytics and continuous monitoring can surface and neutralise subtle anomalies that would otherwise go unnoticed – such as phishing, spear phishing, and malware, with email still the number one entry point for ransomware.

Zero Trust & MFA

Meanwhile, zero trust policies and multi-factor authentication methods add a second layer of protection, blocking unauthorised access even if credentials are compromised.

When incidents do occur, a well-practised response framework ensures action is fast and coordinated, minimising disruption across critical systems, with the ability to switch to secure replica environments to keep operations running while remediation takes place. Secure, immutable, air-gapped backups underpin it all, providing a safety net that guarantees recovery can begin from a clean and uncompromised state.

Human readiness is equally critical. Technology can contain an attack, but only people can recover from one effectively. Regular simulation exercises, incident rehearsals, and cybersecurity awareness training help teams respond calmly and cohesively, transforming response from reactive to instinctive. This operational maturity is reinforced by strong governance. Frameworks such as DORA, NIST, and ISO 27001 provide the structure to align technical teams, compliance leads, and executive decision-makers around shared resilience goals. When combined with skilled practitioners and clear accountability, they embed security into ‘business as usual’ – moving resilience from a strategy to a sustained organisational capability.

Why Multi-Layered Backup is Critical

When ransomware strikes, the speed and integrity of data recovery determine whether disruption lasts minutes or days – and whether the impact cascades through wider global markets. As the last and most decisive line of defence when every other control fails, it’s also fundamental to customer trust and compliance. Yet too often, backup is treated as a static safeguard rather than a dynamic resilience layer.

Since modern ransomware often seeks out and encrypts traditional backups first, a single backup copy or centralised repository is no longer sufficient. True resilience today depends on a multi-layered approach – combining offsite or cloud-diverse storage, immutable data copies that cannot be altered or deleted, and isolated environments to protect against lateral movement.

How frequently these backups are tested is equally important. Too often, financial institutions only discover weaknesses when recovery is already underway, at which point strategies can’t be magically strengthened, and it becomes a race against the clock to minimise downtime and reputational fallout. Regular, automated recovery testing changes that dynamic. It not only confirms that files can be restored, but provides verifiable assurance that systems come back online in the correct order, data dependencies remain intact, and teams have the muscle memory to act quickly and confidently when the worst happens.

The Power of Shared Accountability

In a digital economy so deeply interconnected, no organisation operates in isolation. This is especially true in financial services, where supply chains and service providers form the backbone of day-to-day operations. While this interdependence is a strength in many ways, it also means resilience is no longer defined by how well a single institution can defend itself, but by how effectively every partner in its ecosystem upholds their part of the security chain.

This is where shared accountability becomes critical. It recognises that cloud providers, managed service partners, and financial institutions each have distinct but complementary roles to play in securing data, systems, and infrastructure. When accountability is clearly defined – and when partners collaborate rather than operate in silos – visibility improves, incident response accelerates, and the risk of systemic failure decreases.

Shared accountability also extends beyond contractual obligation. It’s about building a culture of collective readiness: sharing intelligence, rehearsing joint incident scenarios, and supporting smaller or less-resourced partners to raise their security baseline. The result is a unified entity capable of anticipating, absorbing, and recovering from disruption together.

Looking Ahead

To view cyberattacks as inevitable might seem pessimistic to some, but it’s an unfortunate truth that no amount of investment can eliminate risk entirely. In an era where threats are growing in both scale and sophistication, readiness becomes the true differentiator – particularly in such a high-stakes sector. For financial institutions, that means embedding security into culture, strengthening connections across supply chains, and continually testing their ability to withstand and recover as a united ecosystem. Only then can resilience become a strategic advantage rather than a defensive necessity, and unlock the cloud’s transformative potential with absolute confidence.

Learn more at virtualcds.co.uk

  • Artificial Intelligence in FinTech
  • Cybersecurity
  • Cybersecurity in FinTech
  • Data & AI
  • InsurTech

Ben Francis, Insurance Lead at Risk Ledger, on navigating cyber threats by reinforcing security from the inside out

Cyber insurance has evolved from a straightforward risk transfer mechanism into an integral component of enterprise risk strategy. As a result, the conversation has shifted beyond simply securing coverage to embracing three foundational elements: transparency in risk exposure, accountability for security measures, and active collaboration throughout the digital ecosystem.

Rather than asking ‘are you covered?’, the more pertinent question has become ‘can you demonstrate measurable risk reduction?’. Insurers and insureds alike are recognising that what matters now is how well an organisation understands and manages its digital exposure, especially across its extended supply chain. Recent data reveals that 46% of organisations experienced at least two separate supply chain-related cyber incidents in the past year, a clear sign that exposure often lies beyond direct control. 

From Risk Transfer to Risk Visibility 

In recent years, the cyber insurance market has matured significantly. Once viewed as a reactive safety net to cushion the financial impact of attacks, it is now becoming a proactive tool for managing and mitigating risk. This shift is partly driven by insurers, who increasingly expect and work with organisations to demonstrate strong security practices and a nuanced understanding of their threat landscape, including risks deep within their digital supply chains; an area where many businesses still fall short.

At the same time, the industry faces a growing challenge from systemic cyber risk within their portfolios, as many businesses rely on the same cloud providers, payment systems and digital platforms, increasing the chance of a single point of failure. Insurers must gain visibility into how policyholders are connected, not only to suppliers but to each other. Tools and frameworks that map and monitor these interconnections will be essential to avoid underestimating the wider impact of seemingly isolated cyber events.

Mapping Beyond Third Parties

It is no secret that cyber attackers often target the weakest link in a supply chain. These are not always direct suppliers, but fourth, fifth or even sixth-tier vendors that have indirect but critical access to systems and data. Unfortunately, many organisations lack visibility beyond their first tier, creating blind spots that attackers can easily exploit. From an insurance perspective, this presents a clear challenge. If an organisation cannot account for who it is connected to, it cannot adequately quantify its risk and neither can its insurer. Mapping these extended connections is more than just a technical exercise; it means actively practiced risk governance and responsibility. Insurers increasingly want to know how their policyholders are identifying and managing indirect dependencies, particularly in sectors like financial services and retail where disruption can ripple across entire markets.

Collaboration as a Risk Strategy 

One of the more underappreciated aspects of cyber resilience is the role of peer collaboration. Unlike physical incidents, cyber threats rarely exist in isolation. A single compromised vendor can impact multiple organisations simultaneously, a fact that has been highlighted by high-profile supply chain attacks such as SolarWinds and MOVEit

As a result, businesses need to think beyond their own perimeters and adopt a more collective mindset. This includes building relationships with industry peers, sharing threat intelligence and participating in sector-wide initiatives aimed at improving visibility and preparedness. 

In highly regulated sectors, such as insurance, this collaboration is increasingly being encouraged by oversight bodies. Frameworks like the Digital Operational Resilience Act (DORA) in the EU and initiatives from the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA) in the UK are pushing for more transparency around third-party risk. In this context, openness is no longer optional; it will be a regulatory expectation. 

For insurance providers, greater collaboration between policyholders also means better data on emerging threats and more accurate portfolio management. For businesses, it offers a chance to anticipate vulnerabilities that may not yet have hit their own networks but are affecting others in their industry. 

Proactive Transparency Builds Trust 

Organisations that take a proactive, transparent approach to cyber risk management are more likely to secure cover and potentially favourable terms, not just in terms of premiums, but also in access to additional services such as forensic support, incident response sources and legal counsel. 

Demonstrating a mature cyber posture is not about claiming perfection. No organisation is immune to breaches. What insurers are looking for is evidence of a structured approach: the existence of incident response plans, robust governance, effective supply chain risk management, and above all, an honest view of risk. 

A Shift in Mindset 

Ultimately, our understanding of cyber insurance must keep evolving. It should not be treated as a simple checkbox exercise, but as a collaborative relationship between insurers and the organisations they support – one built on shared insight, clear communication, and a drive for continuous improvement.

The organisations best equipped to navigate today’s threats will be those that prioritise transparency. Not only does it lead to stronger protection, but it also builds a culture of accountability that reinforces security from the inside out.

Learn more at riskledger.com

  • Cybersecurity
  • Cybersecurity in FinTech
  • Digital Strategy
  • Fintech & Insurtech
  • InsurTech

Neven Matas, Cybersecurity Team Director EU from Infinum, explores how FinTech companies can turn resilience into a source of innovation and business growth

FinTech companies are under constant pressure to innovate rapidly while maintaining deep and ongoing trust in their platforms. And as AI becomes embedded into everything from credit decisions to customer support, these pressures are intensifying. The future of digital finance will not just be defined by who deploys the most advanced technology first but by who implements systems that can withstand attack, scale efficiently, and evolve without compromising compliance or customer confidence.

Resilience cannot be a technical afterthought; it is a strategic requirement for FinTech. Modular platform architectures, responsible AI operations, and proactive security testing are becoming the foundations of sustainable FinTech growth. Together, they define an operating model where compliance supports innovation instead of obstructing it and where trust becomes a true competitive differentiator.

FinTech Resilience Begins with Architecture

Many FinTech platforms have evolved as tightly integrated but ultimately separate systems. While these can move quickly at first, they will often struggle under regulatory change, evolving security threats or simply the pressure of scale.

Modular, API-driven architectures will enable organisations to compartmentalise risk. They also make it easier to upgrade specific services without disrupting the others and adapt to new regulatory obligations without impacting the whole business. Shared platform capabilities, such as identity management, encryption, logging and access control, will give every new product or feature an inherited baseline of good security practice and governance.

This approach is especially important as operational resilience regulations tighten across global financial services. Requirements around third-party management, continuity planning, and incident reporting demand systems that are secure, observable, and controllable. When resilience is engineered into the platform rather than bolted on, organisations can adapt far more confidently.

Crucially, modularity accelerates innovation rather than slowing it down. Teams can experiment at the edge without placing core systems at risk. New fraud detection models, customer features or AI-driven services can be deployed, tested and refined in isolation. Resilience, therefore, is not simply about withstanding disruption, it is what allows organisations to safely embrace continuous change.

Scaling Digital Products Without Tripping Over Compliance

Digital FinTech products are no longer judged just on usability. They are also evaluated on how transparently they handle data, how well they communicate risk, and whether they meet regulatory expectations across markets. Compliance, which was once seen as a barrier to innovation, is increasingly becoming a fundamental product design input.

The most resilient organisations will embed regulatory thinking directly into product development from the outset. Rather than treating compliance as a late-stage sign-off, they feed regulatory principles into experience design and system behaviours. Consent flows, audit trails, authentication rules, and data retention logic become part of the product’s core architecture rather than something that has been retrofitted.

This approach significantly reduces the operational burden of growth. As FinTech companies enter new regions or launch new services, they avoid the potential of costly remediation triggered by regulatory scrutiny. Instead, they operate from consolidated, well-governed platforms that limit the attack surface and simplify oversight, while also limiting duplication. The outcome is a stronger security posture and faster expansion into new markets with clearer trust signals for customers and partners.

AI as a Trusted Partner Not a Black Box

AI has rapidly become central to the FinTech value proposition. Real-time fraud detection and automated operational processes, for example, depend on increasingly sophisticated models. However, AI also introduces new risks, including opaque decision-making, potential bias, and heightened regulatory exposure when automated systems influence financial outcomes.

The strategic shift now is from experimental AI adoption to accountable AI operations. This begins with defining precisely where AI adds value and where human oversight remains essential. High-impact use cases, such as lending decisions, transaction monitoring and identity verification, all need explainability as well as accuracy. Organisations must be able to demonstrate how decisions were reached, what data was used and how bias is monitored over time.

Clear ownership, review processes, escalation paths, model validation and human-in-the-loop controls will help make large-scale AI deployment viable in a regulated environment.

AI also has a strong defensive capability. Behavioural anomaly detection, predictive threat monitoring and intelligent authentication systems allow fintech platforms to detect and respond to risk faster than traditional rule-based approaches.

When used responsibly, AI can strengthen both customer experience and operational resilience.

Proactive Security Testing as a Continuous Discipline

Modern FinTech infrastructure assumes exposure. APIs are public, ecosystems are interconnected and supply chains are large and complex. Under these conditions, security based solely on perimeter defences or annual audits is not enough. This means continuous, adversarial testing has become essential for resilient fintech organisations.

Mature players are moving beyond compliance-driven testing into ongoing penetration assessments, red-team exercises and social-engineering simulations. These practices uncover technical vulnerabilities, as well as weaknesses in response coordination, escalation decision-making and recovery planning. They test the organisation as a living system rather than a collection of isolated applications.

Integrating security into everyday development is equally critical. Secure coding standards, continuous testing pipelines and regular threat modelling will enable earlier detection of vulnerabilities, when issues are cheaper and easier to resolve. The goal is not to eliminate risk entirely, which is impossible, it is to reduce the time between exposure, detection and response.

Security as a Growth Enabler

The reframing of security from cost centre to growth driver is the most significant strategic transformation in FinTech. Having a strong security posture is not just about ticking compliance checkboxes, it is increasingly a prerequisite for partnerships, institutional trust and international expansion.

Organisations that demonstrate operational resilience, responsible AI governance and proactive security assurance move through due diligence faster. They onboard enterprise clients more easily, integrate with partners with fewer barriers and launch advanced digital services with greater confidence.

In crowded markets, trust is a commercial advantage.

From the customer perspective, security and transparency are inseparable from experience. Clear communication around data usage, visible protections and consistent reliability directly impact adoption, retention and loyalty. Resilience becomes part of brand equity.

Looking ahead, FinTech leaders will not be defined by who adopts new technology first but by who builds systems capable of absorbing disruption, scaling responsibly and evolving continuously. Modular platforms, trustworthy AI and continuous security assurance form the backbone of this.

Learn more at infinum.com

  • Artificial Intelligence in FinTech
  • Cybersecurity in FinTech

Anthony Yeung, CCO at CoinCover, believes Crypto in 2026 will be defined by consolidation, institutional behaviour and long-overdue usability fixes

CoinCover Crypto Predictions for 2026

Prediction 1:

Crypto is rapidly maturing, driven to a great extent by institutional adoption and regulatory oversight. For that reason, I do not expect the next 12 months to produce the sort of hype cycle we’ve seen in previous years.

The real story will be consolidation. 2026 will be defined by the industry finally addressing long-standing usability problems. The biggest change will come from how people interact with their wallets. Seed phrases, which have caused years of confusion and unnecessary risk for everyday users, may begin to disappear as MPC wallet architecture moves into the mainstream. This change lowers the likelihood of irreversible mistakes, reduces friction during the user journey and creates a level of reassurance that the industry has struggled to provide until now.

Retail-facing products will also evolve towards a neobanking style of experience. Kraken’s recent product direction is an early sign of this transition, with cleaner onboarding, more structured recovery paths and interfaces that feel much more like modern banking apps. These improvements support a rise in consumer confidence. However, 2026 is unlikely to deliver a major retail surge. Instead it presents a valuable window for firms to build behind the scenes, improving security, compliance, infrastructure and user experience in preparation for the next growth phase.

Alongside this, institutions will increase their adoption of privacy networks. These networks allow regulated entities to transact on the blockchain without exposing commercially sensitive information. For banks, asset managers and corporates, this becomes an essential step in using blockchain technology while maintaining confidentiality.

Overall, 2026 is shaped by practical progress rather than new hype, and by improving the safety and usability of the tools that already exist.

Prediction 2:

Retail activity may not surge in 2026, but two areas are set for meaningful growth. The first is stablecoins. The landscape is changing quickly as major consumer technology companies start issuing their own stable-value assets. Klarna is already signalling this shift. This trend marks the beginning of a future where stablecoins sit inside the ecosystems of brands that consumers already trust. Stablecoins begin to operate less like crypto-native assets and more like everyday payment infrastructure.

The second area of growth is yield. Simplified and regulated yield products are gearing up to become a powerful on-ramp for first-time retail users. With traditional savings accounts offering returns that remain below the rate of inflation, yield products stand out as an attractive alternative. These products are becoming easier to understand and easier to access. For many new users, they may serve as the first practical interaction with digital assets.

Taken together, these developments shift the behaviour of everyday users. Retail adoption no longer depends on speculative cycles. Instead it is driven by stablecoins embedded in familiar platforms and by yield products that offer a clear financial benefit. Even without a headline retail boom, these trends quietly expand participation and increase confidence in the broader ecosystem.

Prediction 3 (Market Orientated):

The market outlook for 2026 will be shaped primarily by institutional behaviour and macroeconomic conditions. As long as the current Trump’s US administration remains broadly supportive of the sector, sentiment across the industry will remain constructive. However, this does not translate into a calm market environment. With institutions now driving the majority of market activity, reactions to geopolitical events, economic data and regulatory signals will be rapid and pronounced. This creates a jittery atmosphere even in periods where the underlying fundamentals remain stable.

Institutional investors move quickly and often algorithmically. Their responses no longer wait for retail cycles to form. As a result, price movements can feel sharp and frequent even when the long-term outlook remains positive. For crypto companies this creates an unusual opportunity. The year may feel noisy at the surface, but it offers stable political conditions, increasing institutional engagement, growing use of privacy networks and a market that is steadily moving from experimentation towards operational scale.

In simple terms, 2026 is a year where the strongest companies can make significant progress even if the headlines feel unsettled.

Find out more at coincover.com

  • Blockchain & Crypto
  • Neobanking

After a turbulent few years, the crypto sector looks on the cusp of another period of boom. Yet, according to Anthony Yeung, Chief Commercial Officer at CoinCover, the success of this next phase will hinge on embedding responsibility and accountability at its core.

A few years ago, the crypto sector found itself grappling with a profound image crisis. A series of high-profile scandals, widespread misconceptions about its place within the broader financial system, and a glaring absence of regulatory oversight led many to dismiss the space as a haven for tech-savvy opportunists peddling dubious tokens in a never-ending cycle of ‘get-rich-quick’ schemes.

Fast forward to 2025, and while some of that baggage lingers, public understanding of crypto and its underlying value has matured considerably. Endorsements from major governments, coupled with rising levels of institutional investment, have helped to temper concerns about crypto’s legitimacy and long-term role in the financial ecosystem. Nevertheless, questions around trust and transparency continue to cast a shadow over its progress.

A Collective Effort

It’s clear that crypto remains a hotbed of innovation, much of it focused on attracting more individuals and businesses into the ecosystem. However, alongside the development of cutting-edge solutions, the sector must also dedicate time and effort to rebuilding and strengthening its public image. As we enter this next phase of growth, reinforcing trust and public confidence is just as vital as technological progress.

At CoinCover, we believe that tackling this trust deficit could be the key to unlocking the next billion users of cryptocurrency. Driving such a shift will require more than just our efforts. As an industry, crypto must urgently find more effective ways to tell its story showcasing not only its value but also its security. A collective, coordinated effort from stakeholders across the ecosystem is essential to reshape public perception and build lasting confidence.

The Path to the Next Billion Crypto Users

That sentiment is unlikely to raise eyebrows. From my experience, there’s broad agreement that crypto must do more to manage how it’s perceived by those outside the space. Yet, when it comes to charting a path forward, consensus becomes far more elusive. Chief among the contentious issues is the role of external regulation; a topic that continues to divide opinion across the sector and spark lively debate.

Unlike just a few years ago, when regulation in the crypto space was minimal, businesses today face a growing list of compliance demands. Moreover, expectations are mounting that regulatory oversight will only become more stringent in the months and years ahead. For many within the sector, this external scrutiny sits uneasily alongside the original ethos and mission of cryptocurrencies.

Evolution, Not Revolution

Many crypto OGs acknowledge that the space was born out of a desire for decentralisation, autonomy, and freedom from traditional financial systems. Yet, as with many movements, that founding mission has evolved over time. Today, crypto no longer exists as a siloed alternative but is increasingly integrated into the broader financial ecosystem that supports the modern global economy.

While for some the merits of this evolution remain up for debate, its reality is undeniable. For those of us committed to broadening access to the benefits of cryptocurrency, this moment presents more opportunity than challenge. In terms of user access, the crypto space has reached heights few could have expected. The ideology that shaped the sector’s early days need not be discarded, but elements of it must evolve to reflect the times we live in.

Responsible Regulation

At present, regulation represents the key tension point between these two opposing worldviews. For some, external oversight undermines the very essence of crypto. For others, the wave of incoming compliance offers much-needed validation, a chance for the sector to shed its chequered reputation and re-emerge as a more trusted, credible, and accessible solution for the next billion global users.

As a long-time crypto enthusiast, I appreciate the merits of both sides of the debate. At the same time, I’m realistic enough to acknowledge that the genie is well and truly out of the bottle. There’s no turning back the clock on regulation – and perhaps nor should there be. While few within the sector would advocate for overly stringent measures, there is a clear and pressing need for measures to be introduced and upheld that incentivise good behaviour across the board.

Unlocking the Next Wave of Users

Embracing responsible compliance, and viewing its introduction as an opportunity rather than a threat would mark a positive step forward for the sector. Additionally, it would help initiate the much-needed process of reshaping crypto’s public image: one that reflects a commitment to accountability, long-term growth, and sustainable progress. It could prove crucial as the sector looks to unlock the next billion global users.

At CoinCover, we’re committed to helping shape the conversation around this issue. In the months ahead, we aim to engage openly with all sides of the debate; from regulators to crypto companies. By fostering dialogue across the ecosystem, we believe we can play a constructive role in helping the sector reach a more balanced, sustainable equilibrium — one that serves the interests of all stakeholders, and most importantly, its users.

Find out more at coincover.com

  • Blockchain & Crypto

Paul Clarke, Chief Growth Officer at Cashdflows, on how payments infrastructure can support both trust and scale

The UK’s game of skill, competition and raffle sector is undergoing rapid transformation. While data on the sector is limited, UK Government analysis indicates that 14% of UK adults collectively spend a total of £1.3 billion per year. For comparison, 44% of adults spend an estimated £8.2 billion annually on the National Lottery.

The same report shows an upward market trajectory with 60% of operators anticipating an increase in ticket sales over the next three years, while only 5% expect a decline. When it comes to the players themselves, 22% have increased their spending in the past year, outpacing the 17% who have reduced theirs.

Against this backdrop of sustained engagement, fair access to effective payment solutions is essential to support competition among merchants.

The Payments Layer of Trust and Scale

As operators mature, they must balance commercial growth with strong operational integrity. Unlike purely entertainment-driven apps, these platforms are rooted in real-money participation, whether through entry fees, prize payouts, or both. This heightens expectations for merchants and consumers around security, compliance, and player protection.

Payments infrastructure therefore becomes a fundamental line of defence. Tools such as Strong Customer Authentication (SCA) and two-factor authentication (2FA) provide robust safeguards against fraud, account compromise, and unauthorised transactions, reinforcing trust with both consumers and regulators.

Enhanced checkout features also play a significant role. Pre-populated payment details and secure card-on-file capabilities streamline repeat purchases, reducing manual errors and checkout abandonment. Click to Pay and network tokenisation support secure one-click transactions, improving conversion performance while ensuring PCI compliance.

Real-time fraud analytics, velocity checks, and dynamic transaction routing help maintain strong approval rates and minimise friction, ensuring legitimate users enjoy a smooth and reliable payment experience.

From Back-Office Burden to Brand Advantage

Payments were once viewed purely as a back-end process, a necessary function behind the scenes. Today, they are a frontline driver of user experience and commercial differentiation. Deposits and withdrawals bookend the player journey, so speed, transparency, and seamless execution boost satisfaction, reduce churn, and can become pivotal to brand advocacy.

In a high-volume environment where microtransactions dominate, even brief delays or failed payments can quickly damage trust. Conversely, efficient transactions turn reliable payments into a competitive advantage – one that encourages repeat play and referrals.

Powering the Platform Economy of the Future

The broader creator and competition economy is still in its infancy, with new formats emerging at pace but what unites them is a reliance on secure, scalable, and accessible payment systems. What those that succeed will have in common is whether those payment systems can support growth while maintaining compliance and safeguarding trust. As investment continues to flow into the sector, the platforms that thrive will be those that view payments not just as operational plumbing but as a strategic asset.

Paul Clarke, Chief Growth Officer at Cashflows, has a wealth of experience successfully leading product, business strategy, and innovation functions in the payments, eCommerce, and digital sectors. He was previously Executive Vice President for Product and Innovation at international payments solutions provider: Network International. Prior to this, Paul held leadership positions at key payment organisations, such as Barclaycard, Elavon, and Worldpay. Having joined Cashflows in 2021, Paul is responsible for leading the product proposition, strategy, go to market and delivery functions of the business. 

About Cashflows 

Cashflows is a new breed of FinTech payments company that makes it easy for small corporates and SMEs to accept card and digital payments – online, in store and on the move. 

Through its own acquiring platform and gateway, Cashflows provides a safe, secure ecosystem for processing payments right across Europe. Cashflows products and services are built with the latest technology and the future in mind, always to meet the specific needs of partners and customers. 

Learn more at www.cashflows.com  

  • Digital Payments
  • Neobanking

The Card & Payments Awards Middle East will be taking place on Thursday 5th April 2026 at Atlantis – The Palm in Dubai. Entries are open now and close in December.. Book your table for the Awards now!

The Card & Payments Awards is among the leading networking events of the year for the Middle East card and payments industry. With over 1,100 guests attending on the night, from over 300 different companies, and with a compelling list of blue-chip sponsors. Enter here and book your tables now.

Recognising Excellence and Innovation in Payments

For two decades, The Card & Payments Awards has stood as the premier networking event for the UK and Irish card and payments industry. The event was founded 20 years ago by Michael Harty.

Building on this legacy of success, 2025 marked an exciting expansion with the inaugural Card & Payments Awards Middle East. Hosted in Dubai on April 17th, 2025, at the prestigious Ritz-Carlton, DIFC, this highly successful event celebrated best practice, innovation, and excellence within the region’s dynamic card and payments sector. It provided an invaluable networking platform, connecting key players and fostering new partnerships and collaborations to drive continued innovation across diverse verticals.

The Card & Payments Awards Middle East welcomes entries from credit, debit, prepaid, and charge card issuers, co-brands, merchant acquirers, payment processors, retailers, and other payments companies worldwide offering programs or initiatives within the Middle East. With a range of categories covering essential disciplines, the awards offer organizations a significant opportunity to showcase their achievements and contribute to a vital industry platform that recognizes and rewards the best in the Middle East.

Why Enter

Entering your company for an Awards Programme is a fantastic opportunity to showcase your achievements to the industry, while benchmarking against your competitors. Ultimately success at the Awards can be leveraged on consumer facing communications.

Some of the many reasons to consider an entry are listed below.

  • A mark of quality assurance from the leading & longest-standing Awards in the industry
  • Increase your brand exposure through media & PR coverage
  • Increase your profile with top industry blue chip companies
  • Increase your credibility and gain trust from consumers
  • Differentiate your brand
  • Gain a competitive edge
  • Benchmark against others in the industry
  • Drive best practice
  • Receive recognition, network & celebrate with others in the industry.

Putting together an entry can seem a daunting task, so if you aren’t sure where to begin, get in touch with us and we will be able to advise.

Enter here and book your tables now to celebrate the industry’s biggest achievements, whilst meeting the key players from across the sector in the Middle East.

  • Event Newsroom
  • Events

Osama Bari, Chief Technology Officer at D24 Fintech on the need for cybersecurity advancement to support the rise of crypto adoption

Cryptocurrency adoption has accelerated dramatically, rising in popularity in recent years. Yet the sector remains a prime target for cyberattacks. As digital assets grow in value and popularity, the stakes for both exchanges and users have never been higher. High-profile incidents, such as the CoinDCX breach in July, which saw hackers steal $44 million without touching user wallets, Phemex losing $69 million in a crypto heist, and WazirX losing $230 million, demonstrate the sophisticated tactics cybercriminals now employ.

Similarly, the Bybit hack exposed vulnerabilities in multi-signature authorisation and user interface (UI) spoofing. This highlights how even experienced professionals can be caught off guard.

These events underscore the urgent need for exchanges and financial institutions to prioritise security. They must implement robust protocols, and adopt comprehensive risk-management strategies. There are several core areas where crypto platforms can significantly reduce the risk of security breaches.

Strengthening Cybersecurity Protocols

It is vital for exchanges to implement multi-party approval systems for all transactions. By using threshold-based authorisation, combined with real-time monitoring of deposits and withdrawals, platforms can identify unusual activity and flag it for manual verification. Each withdrawal should undergo a transaction audit score assessment before processing. Such measures are critical for preventing attacks that exploit UI vulnerabilities or other operational oversights. This ensures that no single point of failure can compromise user assets.

Another essential safeguard is two-factor authentication (2FA). While a long-established security measure, its importance in protecting accounts and verifying users cannot be overstated. By requiring a second form of identification, exchanges can ensure only authorised personnel access accounts and manage balances. In practice, this simple but effective layer of protection increases the difficulty for hackers. It demonstrates an exchange’s commitment to protecting its customers’ funds. All financial providers should offer 2FA as a baseline security measure.

Custodians also play a vital role in mitigating risks. For many exchanges, especially those handling large volumes of assets, partnering with a trusted custodian provides additional security and oversight. Custodians safeguard digital assets on behalf of clients, reducing exposure to theft, loss, or mismanagement. In the aftermath of this year’s prominent hacks, the value of external support becomes clear. Custodians enable exchanges to focus on customer experience and platform innovation while ensuring that user funds remain secure.

A further innovation gaining traction is liveness verification, which confirms user identity through biometric measures such as facial recognition or fingerprints. With roughly 40% of banks having implemented this measure to counter fraud – up from 26% five years ago – crypto platforms have an opportunity to follow suit. Liveness checks provide an additional barrier to attackers who might otherwise exploit compromised passwords, keys, or devices. The uniqueness of biometric identifiers ensures that users’ accounts are better protected against increasingly sophisticated fraud attempts.

Centralised cryptocurrency exchanges (CEXs) continue to demonstrate resilience in the face of attacks. Security must be embedded into operational design. The recent incidents highlight the effectiveness of CEXs’ ability to freeze or recover stolen assets quickly. By collaborating with other platforms and utilising centralised oversight, these exchanges can mitigate the impact of breaches. As crypto continues to gain mainstream traction, balancing decentralisation with strong security infrastructure is essential to maintaining investor trust and market stability.

A Holistic Approach to Crypto Security

Beyond these specific measures, exchanges must also adopt holistic cybersecurity strategies. Key steps include thorough risk assessments to identify vulnerabilities. Rigorous protection of private keys through encryption and secure storage. Robust wallet security with multi-factor authentication. And secure transaction protocols including encryption and transaction signing. Regular updates to software and firmware, coupled with continuous network monitoring using intrusion detection systems and threat intelligence feeds, further strengthen a platform’s defence.

Data encryption and access control are critical to prevent unauthorised access. Furthermore, periodic security audits and assessments ensure protocols remain effective as threats evolve. Smart contract and token security, secure coding practices, and rigorous testing must also be prioritised to safeguard DeFi applications and other blockchain-based services. Importantly, exchanges should implement backup and recovery protocols to safeguard against potential data loss. And maintain clear incident response plans to mitigate the impact of any breach.

Educating users remains an underappreciated but crucial aspect of crypto security. Platforms should guide strong password practices, phishing awareness, software updates, and overall security hygiene. Well-informed users are an integral layer of defence, reducing the likelihood of successful social engineering attacks or credential theft.

Finally, regulatory compliance is indispensable. Exchanges operating within clear legal frameworks and adhering to anti-money laundering (AML), counter-terrorism financing (CTF), and data protection regulations significantly reduce risk exposure. Partnering with reputable security vendors and maintaining open lines of communication with regulators can enhance both operational security and market credibility.

Learning from Previous Incidents

The CoinDCX incident serves as a cautionary tale. By exploiting vulnerabilities without ever accessing individual wallets, attackers demonstrated high-value, sophisticated hacks can occur even in the absence of traditional breaches. This reinforces the point that centralised oversight, real-time monitoring, and rapid response protocols are crucial in mitigating damage and protecting customer assets. Exchanges that fail to implement these measures risk not only financial loss but also erosion of trust, which is arguably a more severe long-term consequence.

As cryptocurrencies increasingly integrate into institutional portfolios and mainstream finance, robust security is no longer optional; it is fundamental. Investors, funds, and enterprise clients require assurance that digital assets are safeguarded. And that exchanges and custodians adhere to industry-leading security standards. Platforms that prioritise security will not only protect their customers but also foster broader adoption and confidence in the market.

The Path Forward

The evolution of crypto security is a continuous process. While decentralised networks inherently resist certain forms of attack due to their distributed structure, the human, operational, and software layers of the ecosystem remain vulnerable. The combination of multi-party approval systems, 2FA, custodian partnerships, biometric verification, continuous monitoring, and regulatory compliance provides a robust framework for mitigating these risks.

The message is clear: security must be embedded into the DNA of every crypto platform. Only through a proactive, multi-layered approach can the industry protect its users, maintain trust, and continue to grow sustainably. As high-profile breaches like CoinDCX, WazirX, Phemex, and Bybit demonstrate, the cost of complacency is far too great. By prioritising security today, exchanges not only defend against current threats but also lay the foundation for the future of a resilient, trustworthy crypto ecosystem.

About D24 Fintech

D24 Fintech focuses on developing innovative technological solutions for the evolving digital and fintech landscape.

By leveraging innovation and emerging technologies, D24 Fintech engineers integrated solutions designed to enhance transactional security, streamline digital payments, and improve operational efficiency. With a global perspective and a customer-first approach, D24 Fintech aims to redefine industry standards and drive innovation into fintech ecosystems.

D24 Fintech’s digital solutions include developing advanced technological platforms and management tools, and more.

  • Blockchain & Crypto
  • Cybersecurity in FinTech

ClearBank research finds half of large firms say embedded finance will drive new revenue, but concerns over outdated systems, implementation challenges, integration and customer trust loom

New research from ClearBank reveals that large UK businesses now view embedded financial services as a strategic boardroom decision and business growth driver.

The research, The embedded economy: Why brands are embracing financial services as a driver for innovation and growth’ explores the attitudes of 200 senior business leaders at large UK-based corporates towards embedded finance and the potential for payments, accounts, and lending to enable new services, new revenue streams, and enhanced customer loyalty.

It found that despite growing enthusiasm for embedded finance’s potential to deliver these services, many companies are still held back by fears of regulatory requirements, technical complexity, and ongoing concerns around finding the right partner to deliver at scale.

A Boardroom Priority: Nearly Half of Corporates see Embedded Finance as a Revenue Driver

Implementing embedded finance has rapidly moved from a niche innovation to a strategic boardroom decision. Survey results found that 38% of C-suite leaders cite embedded finance as important for their company’s growth, reflecting the shift in mindset from viewing it as a back-office payments tool to a driver of competitive advantage.

Crucially, nearly half (48%) of corporates surveyed see embedded finance as a way to improve payments and launch new revenue-generating services. These services range from offering own brand accounts to saving tools and lending services. For many, the potential increase in revenue is compelling, with more than a quarter (28%) of the view that embedded finance could help drive double-digit revenue growth for their business. 67% believed growth would be at least 5% and just over a third (39%) suggest between 5-10% of revenue growth.

“Embedded banking allows businesses to integrate payments, lending and account services directly into their customer propositions. For corporates, this is a real opportunity to create stronger relationships with customers while also building new and potentially significant revenue streams for the business. We believe we’re on the cusp of the embedded economy.

“For any business looking to remain competitive in the digital age, these services can no longer be seen as ‘add-ons’. They are becoming essential infrastructure to deepen customer loyalty and open new revenue streams.

“We see this shift first-hand through the financial services clients already embedding our infrastructure. That experience gives us a clear view of how the same approach can be applied to corporates more widely and why embedded finance is such a significant opportunity across industries.”

Emma Hagan, ClearBank UK CEO

Cross-Sector Growth:  Companies Across Consumer Products & Services, Retail and Healthcare Have Biggest Appetite for Embedding Financial Services

Although embedded finance has often been associated with the retail sector, interest is broadening across other sectors. Research found that appetite was highest in consumer products and services (23%), retail (20%) and healthcare (18%), with the likes of the payroll and travel industries increasingly seeing the potential to integrate financial services into their customer journeys.

Of those companies surveyed that said they are actively considering offering embedded financial services within their own platforms, payment services were most considered (16%), followed by insurance (13%) and lending (13%). This signals a structural change in non-financial companies as they look to add layers of value and deepen engagement and loyalty with customers.

Untapped Potential: Only 19% Have launched Embedded Finance Services – Challenges Slowing progress

While appetite for embedded finance is growing rapidly, adoption is still maturing. Three-quarters (75%) said they would offer embedded finance today if it were easy to implement. This gap between ambition and reality underlines the perception that embedded finance is still typically difficult to employ and highlights the need for a new type of partner to tackle practical obstacles before broader uptake can occur.

When asked about the challenges corporates faced, some firms pointed to the technicalities of setting up such an offering in terms of integration challenges (61%), regulatory compliance (49%) and lack of technical expertise (44%)

Beyond the technical barriers, businesses also flagged reputational and regulatory risks such as greater regulatory scrutiny (57%), a loss of customer trust (52%) with reputational damage if the service fails (65%).

Taken together, these figures highlight that while embedded finance is seen as a major growth opportunity, corporates remain cautious. Success will depend not only on demonstrating the revenue potential but also on reducing risks during implementation through providing trusted infrastructure, regulatory clarity, and a smooth integration path that allows businesses to move from intent to action with confidence.

The Benefits & Motivations: Convenience & Customer Loyalty

For many corporates, embedded finance is first and foremost about strengthening customer relationships. Over half of firms 63% highlighted the opportunity to deliver a more seamless and convenient experience, positioning embedded finance as a customer service differentiator as much as a commercial driver. A further (57%) saw offering embedded services as a way of improving customer loyalty through creating more frequent and valuable touch points.

“Traditional banks we have found, give you a good brand halo and risk expertise but the cycles are killing us. They are slow, the integrations are not really bespoke and the slower cycle of development and keeping up to track with regulation has been the problem consistently.” (spokesperson from consumer industries)

About the Report

Ronin conducted interviews with  30 Senior Business Leaders at UK-based organisations across technology, healthcare, consumer, retail, travel, energy, and utilities sectors, along with surveying 200 Senior Business Leaders on the evolving nature of payment strategies, with a particular focus on the role of embedded finance in enabling new services and revenue streams. The interviews took place over August and September 2025.

  • Embedded Finance
  • Neobanking

Richard May, director of product development at virtualDCS, on navigating cyber regulation, assessing risk, and building digital resilience in a cloud-first financial landscape

In 2025, financial services are deeply reliant on digital infrastructures. Cloud services, especially, are reshaping how the sector operates.

The cloud offers both established and challenger companies the ability to improve flexibility, efficiency, and analytics capabilities. When deployed properly, it can deliver integrated security across an organisation, but also introduces new vulnerabilities.

Due to the sensitive nature of financial data, the sector remains a target for cyberattacks. This, combined with strict regulatory oversight, means firms must continuously align with evolving legislation while enhancing service functionality.


Which regulations do financial services need to be aware of?

There are several specific regulatory requirements that financial institutions must follow. These pieces of legislation are designed to ensure customer data is protected from attackers:

Payment card information and PCI-DSS

For businesses that handle payment card information, PCI DSS requirements dictate security and operational requirements for protecting cardholder information during storage, processing, and transmission. In practice, these requirements are 12 mandatory security controls that cover network security, data protection, vulnerability management, access control, monitoring and logging, physical security, testing, and policy enforcement. Failure to comply with the 12 security controls can lead to severe financial penalties and even liability for compensation costs.

GDPR implications

GDPR regulations categorise financial data as sensitive personal data. This refers to bank details, transaction histories, assets, credit scores, and anything else that might concern the overall financial health of an individual. Firms must take measures to prevent unauthorised access or risk facing fines.

Basel III considerations

The third Basel Accord, Basel III, sets the international standards for capital requirements, stress tests, liquidity regulations, and leverage. It is designed to reduce the risks of phenomena such as bank runs and bank failures, as we saw in the 2008 financial crash. Due to this, most of Basel III focuses on financial requirements such as liquidity to ensure banks are more resilient to changes in the international financial markets. However, it still communicates standards in relation to information and communication technology (ICT),‍ cyber incident response and reporting, and‍ third-party risk management (TPRM).

Digital Operational Resilience Act (DORA)

Introduced in January 2025 by the European Union (EU), DORA addresses rising digital dependency in finance. It covers ICT risk management, third-party oversight, operational resilience, incident reporting, and information sharing.

Compliance with these regulations is essential. Beyond avoiding penalties or criminal charges, it strengthens protection against growing cyber threats.

Assessing Vulnerability and Risk in the Financial Services Industry

Risk assessments are critical to business continuity and reducing the impact of cybersecurity breaches. A task of identifying threats and vulnerabilities, and quantifying the consequences of threats if they were to materialise, enables firms to rank services and ensure the most critical systems are protected first.

The Financial Services Information Sharing and Analysis Center (FS-ISAC) identified several key threats to the global financial sector in its latest report, including: 

Supply Chain Incidents

Businesses should remain alert to the competencies and overall security of service providers they utilise. As reliance on external providers is increasingly integral to many core business strategies, firms cannot afford to overlook the cyber maturity of their partners. To mitigate potential security risks, organisations should ensure and verify that all service providers meet robust cyber-security standards.

Fraud

The universality of real-time payments has led to a surge in fraud action in all sectors for which financial channels and services are used. The immediacy of payment has also created a scenario where it is almost impossible to retrieve stolen funds. Online scammers are building complex operations to take advantage of this. Fraud prevention and detection are becoming more and more important to companies in the sector. Increasing friction for payments through two-factor authorisation, along with other strategic obstacles, reduces fraud risks. Without cross-border partnerships tackling this global issue, however, this is set to remain a growing threat for businesses.

Ransomware

Ransomware has long been a cybersecurity threat. Many victims are often opportunistically targeted by hackers, rather than chosen specifically. Incidents of spear phishing are also on the rise – attackers research individuals or organisations to create personalised messages to convince them to click on infected links. Creating barriers to stop or delay ransomware attacks is therefore essential to reduce the threat. Ransomware’s targeting of customer data also means detection and recovery protocols are critical for firms that want to reduce the threat from malicious actors.

Distributed Denial-of-Service

The FS-ISAC revealed that financial services accounted for a third of all distributed denial-of-service (DDoS) attacks in 2023. DDoS attackers bring down an area of a network or application and extort the affected organisation for financial gain. Motivations may also include political statement-making, competitor sabotage, and cyber vandalism, simply to cause chaos and disruption. The increasing use of application programming interfaces (APIs) in the sector means that denial of service can have a devastating effect on financial service businesses. Firms should implement mitigation strategies to protect customer trust and service availability. 

When, Not If: Building Cyber Resilience Through Disaster Recovery

While cybersecurity defences are essential, effective disaster recovery is vital to reduce the impact of incidents and maintain operations.

Speed of recovery has become the main point of difference for organisations attempting to recover from cyber incidents. Prolonged downtime can lead to reputational damage, regulatory penalties, and lost customers. Without effective disaster recovery, continuity efforts are undermined.

Firms should develop a ‘when’, not ‘if’, mindset when it comes to disaster recovery. A comprehensive disaster playbook provides a manual in the event of a cyber incident. This plan must incorporate tools to allow for early detection of malicious action. Your plan for disaster recovery should be printed as a hard copy or saved on an external device (to ensure it remains accessible if your primary system is compromised). It must consider the first steps of: documenting evidence for cyber insurance and law enforcement, identifying and isolating infected systems, and informing relevant stakeholders an attack has taken place. Furthermore, the plan should contain information around communication and key contacts, an agreed chain of command and designated person to lead the ransomware response, and assurance the plan comes under regular review with ‘fire drill’ rehearsals.

Financial institutions face some of the most severe cyber risks in the world. Abiding by regulatory requirements goes some way to protect against threats, but organisations must go further – by proactively assessing threats, incorporating security measures, and preparing for disruptions. Resilience isn’t just about avoiding breaches. It is about ensuring trust, safeguarding sensitive data, and maintaining the ability to deliver reliable services in a digital-first landscape.

Learn more at virtualDCS

  • Cybersecurity in FinTech
  • Risk & Resilience

The Card & Payments Awards will be taking place on Thursday 5th February 2026 at the famous JW Marriott Grosvenor House Hotel in Mayfair, London. Entries are open now and close in October… Book your table for the Awards now!

The Card & Payments Awards remains the longest-standing and leading networking event of the year for the UK and Irish card and payments industry. With over 1100 guests attending on the night, from over 300 different companies, and with a compelling list of blue-chip sponsors. Enter here and book your tables now.

Recognising Excellence and Innovation in Payments

The Card & Payments Awards has been instrumental in recognising excellence and innovation across the industry from a diverse range of corporations for the past two decades. Each year many eligible organisations compete for one of the prestigious awards which are judged by an independent panel of industry experts. The Awards concludes with its infamous Industry Achievement Award each year. 

The Card & Payments Awards are open across the different categories to credit, debit, prepaid and charge card issuers, co-brands, merchant acquirers, payment processors, retailers and other payments companies worldwide who are offering programmes or initiatives within the UK and Irish market. There are a range of categories covering key disciplines and offering organisations the opportunity to showcase all of their achievements. 

Why Enter

For over 20 years, The Card & Payments Awards have been recognising excellence across the industry.

Widely regarded as the Oscars of the card and payments world, this is your opportunity to stand out and celebrate your achievements.

An entry gives you the chance to:

  • Gain recognition from respected industry leaders
  • Build brand credibility and consumer trust
  • Increase visibility through press and media coverage
  • Extensive networking opportunities with senior industry leaders
  • Demonstrate your commitment to excellence
  • Assessment by an independent panel of experienced industry judges

Entries are judged on the strength of the submission and how well it meets the category criteria. Categories include: Best Industry Innovation, Best Payment Facility, Best App User Experience (CX Initiative), Best Product Design and the Financial Inclusion Award. Last year’s winners include moneyhub for Open Banking, Dojo for Innovating Customer Service with AI, and Nationwide for Product Design.

Enter here and book your tables now to celebrate the industry’s biggest achievements, whilst meeting the key players from across the sector.

  • Digital Payments
  • Event Newsroom
  • Events

FinTech Strategy meets with Citigroup’s Head of ESG Credit Management, Mauricio Masondo, to discover the future for ESG and sustainable finance

Financial Transformation Summit 2025 EXCLUSIVE

At Financial Transformation Summit, Mauricio Masondo, Head of ESG Credit Management at Citigroup, featured on a sustainability panel – ‘The Future of ESG and Sustainable Finance: Balancing Profit and Purpose’. Alongside peers fromGenerali AM, Gallagher Re and Arma Karma, Masondo considered: What key metrics should FIs use to track ESG progress, and how can they ensure authenticity in their sustainability efforts? Developing a holistic ESG strategy amid evolving regulations – key challenges and solutions. How can FIs leverage technology to meet sustainability goals and drive long-term profitability? How can FIs move beyond offering ESG products to embedding sustainability into their core business models?

Following the panel, we spoke with Mauricio to find out more…

Hi Mauricio, tell us about your role at Citigroup?

“In my 32 years with Citi my career has primarily focused on wholesale credit, and in recent years I built out our portfolio management function. For the past year specifically, I’ve been leading the integration of ESG and climate considerations into our credit processes. As Head of ESG Credit Management, my role is to embed ESG requirements into our credit processes in a way that’s consistently and efficiently applied through technology, policies, training, and governance frameworks. Our strategic approach was not to create an ESG silo that replicates existing processes, but rather to integrate ESG considerations seamlessly into our current workflows. This means any credit analyst can now underwrite ESG credits, sustainable loans, or green loans, rather than requiring dedicated specialists. We’ve equipped our entire team with the knowledge and tools they need to handle these transactions effectively.”

You were part of a panel at this Summit focused on the future for ESG and sustainable finance. Can you give us an overview of your thoughts?

“Data standardisation is absolutely critical, especially as we advance into the AI era. I often reference Moody’s as an excellent example of strategic foresight. Moody’s operates two key businesses – credit ratings and data analytics – and early in their AI journey, they made the strategic decision to structure and normalise all their credit research data. This proved to be transformational because it enabled them to deploy AI solutions much more rapidly with clean, structured datasets. We’re working to apply this same principle at Citi. We’re developing processes to structure climate-related data in a way that will be usable across multiple applications. For example, we’re working on integrating emissions data and climate risk assessments into our credit risk rating models. We’re also exploring how this structured approach could support underwriting processes and securitisations, where comprehensive data packages could facilitate risk transfer transactions with institutional investors. The goal is to build normalised, structured data as the foundation for various applications, from portfolio management to AI-driven solutions. While we’re still in the early stages of many of these initiatives, the potential is significant.”

Why is this an exciting time for the business?

“We’re witnessing the convergence of several transformative trends. However, one of our biggest challenges is policy divergence across jurisdictions. Countries are taking vastly different approaches to ESG requirements, and for a global bank like Citi, this creates significant complexity in standardising processes across multiple regulatory environments. While challenging, this divergence also creates opportunities to develop scalable, cost-effective solutions that can adapt to various regulatory frameworks. Second, AI is revolutionising how we approach ESG challenges. It’s helping us structure data more effectively, enhance reporting capabilities, contextualise information, and identify trends that would have been impossible to detect manually.

“Previously, comprehensive ESG analysis required significant time, resources, and personnel. AI has made these processes more accessible and cost-effective. Most importantly, there’s been a fundamental shift in how the industry, and governments, view ESG. It’s evolved beyond compliance and emissions reporting to become a significant business opportunity. We need to capitalise on this transition – moving from reactive reporting to proactive opportunity capture. The capital is there, and if traditional banks don’t seize these opportunities, asset managers, private credit firms, and private equity will. We’re partnering strategically with reinsurance companies and asset managers to develop innovative solutions that unlock transition capital and help companies fund decarbonisation projects.”

“Trade flows are experiencing significant disruption due to current tariff policies. This creates both challenges and opportunities for our clients. Companies are reassessing their supply chain vulnerabilities and seeking greater resilience in their operations. I anticipate we’ll see a regionalisation of trade flows rather than a complete deglobalisation. European companies will likely increase intra-regional trade while reducing intercontinental transactions. We’re seeing similar patterns emerging in Asia and the Middle East. This shift requires banks to be more agile in how we structure trade finance and working capital solutions to meet these evolving needs.”

What pain points are you experiencing that you need to address?  How are you meeting the challenge?

“Working capital finance requires increasingly creative solutions that leverage advanced technology. Banks are recognising that FinTechs often have greater agility in developing and implementing these technologies. There’s significant efficiency in having one FinTech serve multiple banks rather than each institution developing independent solutions. This collaborative approach allows us to move faster while reducing development costs and time-to-market.”

Tell us about a recent success story…

“I designed and led the implementation of an early warning monitoring system for Citi’s credit portfolio. The project began with a fundamental concept: create a data lake, develop meaningful metrics, and engage data scientists to interpret the insights. We collaborated with trade officers and partnered with external specialists to enhance our capabilities.Initially, there was scepticism about the system’s value, particularly because we built it as an independent function within our portfolio management organisation, separate from traditional banking and risk management structures. However, this positioning allowed us to collect unique client data and develop insights that weren’t available elsewhere in the organisation. A critical component of our success was establishing a dedicated credit expert team that oversees the entire process.

“This team leads the engagement and communication of alerts, ensuring that insights are properly interpreted and actionable recommendations reach the right stakeholders. The evolution was remarkable. We progressed from generating a few alerts daily to dozens per day, and eventually to hundreds of alerts weekly. More importantly, we developed sophisticated processes for interpreting and acting on these alerts, with our expert team serving as the bridge between data insights and business action. Bankers and risk managers began to recognise the value, and today, three years later, the system is integral to how we conduct annual reviews and client presentations. It’s incredibly rewarding to provide our bankers with comprehensive data and insights that strengthen their client relationships.”

What’s next for Citigroup when it comes to ESG? What future launches and initiatives are you particularly excited about?

“While it may sound clichéd, AI truly is transformative for our industry. The breadth of use cases and the rapid pace of learning make it essential to our strategic direction. We’ve established a strategic partnership with Google and are investing significantly in AI use case development and implementation across our operations. From an operational perspective, AI will undoubtedly increase our efficiency as an industry. More importantly, it’s enabling us to evolve our business models and create client solutions that weren’t previously feasible. This opens entirely new avenues for innovative product development. Additionally, since CEO Jane Fraser joined, we’ve embarked on a comprehensive transformation program that’s delivering strong results in terms of financial performance and returns. We’ve restructured and simplified our operations, which positions us more competitively as we refresh our leadership teams and attract new talent. The trajectory is very promising.”

Why do you think the evolution of collaboration between banks and FinTechs is set to continue? What are you excited about?

“The current tariff environment is creating opportunities for FinTechs that facilitate connections between banks, investors, and corporations. It’s also presenting consolidation opportunities for private equity firms within the rapidly expanding FinTech ecosystem.”

Why Financial Transformation Summit? What is it about this particular event that makes it the perfect place to embrace innovation? What’s the response been like for Citigroup?

“The panel brought together diverse perspectives from FinTech, asset management, insurance, and banking – all addressing common challenges that span our sectors. This cross-industry dialogue creates tremendous opportunities for collaboration and mutual understanding. The key now is translating these conversations into action. We need to maintain these connections, expand the dialogue, and avoid making decisions in isolation. FinTechs possess the agility to implement changes in their operating models far more quickly than large incumbents like us. However, our procurement systems and processes aren’t always conducive to collaborating with smaller, innovative companies. Events like this highlight the need to streamline how institutions like Citi can collaborate with and learn from FinTechs. We must accelerate our ability to adapt to a rapidly changing world.”

Learn more at citigroup.com/global/our-impact

About Citgroup

A human bank…

We’re helping build more sustainable, economically vibrant communities around the world.

At Citi, helping our clients navigate the challenges and embrace the opportunities of our rapidly changing world is fundamental to our mission of enabling growth and economic progress.

  • Artificial Intelligence in FinTech
  • Events
  • Together in Events

The FinTech industry, sitting at the nexus of finance and technology, is a prime target for cybercriminals. With the growing…

The FinTech industry, sitting at the nexus of finance and technology, is a prime target for cybercriminals. With the growing prevalence of digital banking, mobile payments, and crypto-assets, cybersecurity has become a non-negotiable priority. In response, a new generation of tools has emerged to help FinTech companies stay ahead of threats. Here are the top five cybersecurity tools safeguarding the sector in 2025:

1. CrowdStrike Falcon – Endpoint Protection Powerhouse

CrowdStrike Falcon has become a leading choice for FinTech companies due to its advanced endpoint detection and response (EDR) capabilities. Powered by AI and cloud-native architecture, Falcon provides real-time monitoring and threat intelligence across endpoints, detecting suspicious behavior before it escalates. Its lightweight agent and scalable design make it ideal for rapidly evolving digital infrastructures.

2. Snyk – Securing FinTech DevOps

FinTech’s embrace of continuous development and integration demands security solutions built for speed. Snyk focuses on developer-first security, helping teams identify and remediate vulnerabilities in open-source dependencies, containers, and infrastructure as code. It integrates directly with GitHub, GitLab, and CI/CD pipelines, ensuring vulnerabilities are caught early—without slowing down development.

3. Fortinet FortiWeb – Web Application Firewall (WAF)

Web applications are the backbone of many FinTech platforms, and FortiWeb provides critical protection. This intelligent WAF defends against OWASP Top 10 threats, including SQL injection and cross-site scripting, while leveraging machine learning to tailor protections in real-time. FinTech platforms using APIs heavily benefit from FortiWeb’s deep learning inspection and bot mitigation features.

4. IBM Security QRadar – SIEM Intelligence

QRadar continues to lead as a top-tier Security Information and Event Management (SIEM) solution. It aggregates and analyzes data from across an organization’s digital ecosystem, detecting threats and providing actionable insights. FinTech firms rely on QRadar for compliance with financial regulations and for its ability to deliver fast, context-rich threat detection and response capabilities.

5. Auth0 – Identity and Access Management (IAM)

Auth0, a standout solution in identity and access management. In FinTech, controlling user access with precision is crucial. Auth0 provides secure, scalable authentication for apps and APIs, offering features like single sign-on (SSO), multi-factor authentication (MFA), and adaptive access policies. With rising threats targeting user credentials, IAM is no longer a back-office function—it’s frontline security.

Cybersecurity in FinTech requires agility, intelligence, and regulatory alignment. Tools like CrowdStrike Falcon, Snyk, Fortinet FortiWeb, IBM QRadar, and Auth) are not just protecting infrastructure. They’re enabling innovation in one of the world’s most dynamic industries. As threats grow more sophisticated, these platforms will continue to shape the future of secure financial technology.

  • Cybersecurity in FinTech

As cryptocurrency continues its march toward mainstream adoption in 2025, selecting a reliable, high-performing exchange has never been more critical….

As cryptocurrency continues its march toward mainstream adoption in 2025, selecting a reliable, high-performing exchange has never been more critical. With factors like security, liquidity, user experience, and range of offerings playing a pivotal role, here are the top five crypto exchanges currently leading the industry.


1. Binance

Overview: Still the largest exchange globally by trading volume, Binance offers a comprehensive platform that serves both retail and institutional traders.

Key Features:

  • Over 600 cryptocurrencies supported.
  • Advanced trading tools including spot, margin, and futures trading.
  • Binance Earn, Launchpad, and Staking features for passive income.
  • Highly competitive fees, starting at 0.1%.

Security & Regulation:
Binance has faced regulatory scrutiny in various countries but continues to work toward greater transparency and compliance. It holds licenses in several jurisdictions and maintains a robust SAFU (Secure Asset Fund for Users) for emergencies.


2. Coinbase

Overview: Widely regarded as the go-to platform for beginners, Coinbase maintains its stronghold in North America with a user-friendly interface and strong regulatory standing.

Key Features:

  • Offers 150+ digital assets.
  • Integrated with Coinbase Wallet for decentralised applications.
  • Recurring buys, portfolio tracking, and robust mobile apps.
  • Listed on NASDAQ, ensuring public transparency.

Security & Regulation:
Coinbase is regulated by U.S. authorities and is one of the few exchanges with full AML/KYC compliance. It employs best-in-class security practices, including cold storage for over 98% of customer funds.


3. Kraken

Overview: Kraken is a favorite among institutional and advanced traders thanks to its robust features and reputation for security.

Key Features:

  • Supports over 200 cryptocurrencies.
  • Offers spot, futures, and margin trading.
  • Kraken Pro for enhanced charting and order types.
  • Kraken Staking with competitive yields.

Security & Regulation:
One of the oldest operating exchanges (since 2011), Kraken has never suffered a major hack. It is regulated in the U.S. and holds a Special Purpose Depository Institution (SPDI) charter in Wyoming.


4. Bybit

Overview: Bybit has risen quickly by offering cutting-edge features tailored to derivatives traders, along with a fast and intuitive UI.

Key Features:

  • Specializes in crypto derivatives, with high leverage options.
  • Also supports spot trading, launchpad tokens, and NFT markets.
  • Popular for its trading competitions and rewards system.

Security & Regulation:
Bybit prioritises fund security with cold wallets and real-time risk audits. It has begun increasing compliance in jurisdictions where regulation is tightening.


5. OKX

Overview: OKX has emerged as a comprehensive crypto ecosystem, offering far more than just a trading platform.

Key Features:

  • Over 300 cryptocurrencies and DeFi integration.
  • Powerful tools for copy trading, bot trading, and options.
  • Active ecosystem for NFTs, DApps, and Web3 tools via OKX Wallet.

Security & Regulation:
OKX publishes monthly proof-of-reserves and maintains robust risk controls. It’s actively pursuing compliance in key regions including Hong Kong and the EU.


Conclusion

While the crypto landscape remains dynamic and subject to regulatory evolution, these five exchanges have proven resilient, innovative, and trustworthy. Whether you’re a newcomer or seasoned trader, choosing the right exchange depends on your specific needs. Be they security, advanced tools, or ease of use. Always consider using multiple platforms to diversify risk and maximise opportunities.

  • Blockchain & Crypto

Kristian Torode, Director & Co-Founder at Crystaline, on Closing the gap between digital convenience and regulatory compliance

As financial firms adopt more digital tools – from instant messaging to video calls – the challenge of capturing, storing and monitoring every conversation in line with regulatory expectations for comms has grown exponentially.

With regulators demanding stricter oversight of all business comms, financial firms must now rethink how they manage messaging across every level of the organisation. Unifiesd Communications (UC) software can help financial service providers remain compliant.

A recent Theta Lake survey revealed that over 70 firms were fined in 2024 for failing to comply with communications regulations. What is more, almost two-thirds of financial firms anticipate even more regulatory requirements on communications in the coming years.

Consequences of Non-Compliance

While fines for failure to comply with comms regulations are more prevalent in the US, there have been several cases affecting financial services firms in the UK.

In August 2023, Morgan Stanley was fined £5.4 million by Ofgem, the UK’s energy regulator, after the bank’s traders discussed wholesale energy prices over WhatsApp on private devices. Use of the platform does not meet regulatory standards for data retention and monitoring, as financial service providers are unable to record these messages concerning energy trading.

Despite industry speculation, the UK Financial Conduct Authority (FCA) has chosen not to implement an outright ban on WhatsApp for business use. Instead, the FCA expects firms to implement policies and monitoring tools to ensure compliance when using such platforms. While this provides some flexibility, it puts the onus on firms to maintain secure and auditable communication records across emerging technologies.

Balancing security and convenience

For financial businesses, the challenge lies in finding a comms solution that is both secure and convenient. WhatsApp appeals to many due to its familiarity and features like group chats, voice calls and file sharing. However, while convenient, it presents serious risks in data privacy, security and compliance, making it unsuitable as a primary communication platform for highly regulated industries like finance.

To address these concerns, many firms are turning to UC platforms that integrate multiple communication tools. These include voice, video, instant messaging and file sharing across a single, secure interface. These platforms provide the convenience of more familiar tools such as WhatsApp while addressing compliance concerns.

Several UC providers now offer platforms tailored to highly regulated industries like finance. Many include security features such as end-to-end encryption, centralised access management and real-time monitoring. This can detect potential compliance breaches, offer built-in archiving for regulatory adherence and consent management to meet data protection requirements.

Digital business communications will continue to play a key role in the financial services sector, but not at the expense of traceability and data security. Unified Communications offers a secure, compliant platform for financial services without sacrificing convenience.    

If your organisation is reassessing its communications strategy in light of evolving compliance demands, Crystaline can provide guidance on navigating the shift to unified communications.

  • Cybersecurity in FinTech

With the right approach, cybersecurity can be contagious argues Galeal Zino, Founder & CEO at NetFoundry – a provider of zero-trust connectivity solutions and originator of the open source tool OpenZiti

Modern financial services are composed of a digitally integrated secure ecosystem – networked together and codependent on ecosystem APIs, microservices and shared data. Complexity and ambiguity are high.

Sir Alex Younger, former head of the British Intelligence Service MI6 said recently that the job of the intelligence service is to dispel complexity and ambiguity.That would make a fine mission statement for the heads of information security in the financial sector.

Meeting a Complex Security Challenge

Most banks leverage core banking systems (CBS) from providers like Temenos, FIS and Finastra. This makes security complex. Connections are needed between the bank’s network and its CBS provider’s network. Traditionally, this necessitates nailing up VPNs. And managing permitted IP addresses in firewall ACLs, MPLS or dedicated circuit-based extranets. Also required are pre-shared certificates, shipping hardware, VDI and/or leaking routes. All of which have multiplied in complexity during digital transformation. And are about to multiply again with AI.

A different approach is secure-by-design. Rather than bolt-on the infrastructure described above, each session is strongly identified, authenticated and authorised. All before it is granted a virtual circuit on a network. This is similar to what the banks do internally with solutions for zero trust, but it is borderless. It works across their digital supply chains, including with their core banking platform and software providers.

One CBS leader, Euronet Worldwide, uses a third-party secure-by-design platform to enable their financial institution customers to connect to its core banking software. This is a great example of the supplier being proactive about their role in security. We’ll see this happen more as new legislation takes effect, the EU CRA. The Euronet example shows that it’s possible to remove some of the ambiguity from shared responsibility. Euronet’s secure-by-design system doesn’t just protect itself but makes every interaction with supply chain partners more secure.

Security designed-in for Financial Services

The same principles apply across financial services. Companies like Euronet can deploy their own zero trust supply chain connections, rather than putting the burden on their finance sector customers to figure it out. In large supply chain scenarios like CBS, this helps everyone. The reality now is that if the VPN of any one financial institution is compromised, then potentially all the banks who connect to the same CBS providers can be exploited. By removing complexity and ambiguity, Euronet is simplifying and securing the entire supply chain.

The big picture is that the WAN/SASE/firewall model is struggling in the post digital transformation, hyperconnected, soon to be AI- powered world. That model was built to secure the WAN. However, new workflows such as the financial supply chain are outside the borders of any single WAN. So, the precious SASE WAN gets connected to the internet via open firewall ports (ACLs) and vulnerable VPNs so the business can connect to supply chain partners. It’s like building a strong boat and then punching holes in it to get a better look at the water. 

AI is the nail in the WAN coffin because AI multiplies and accelerates these workflows. They have at least one leg outside the WAN and it makes them less predictable and more dynamic. More complexity and ambiguity. Good luck connecting AI agents via VPNs and firewall ACLs.

Secure-by-Design Supply Chain

So, what does a secure-by-design supply chain look like and how can financial services identify viable migration paths?

The main characteristics are:

  • Close all inbound “listening” ports on all network firewalls and servers to make your DMZ unreachable from the underlay networks.  Eliminate the reachable firewalls and VPN servers.  No more holes beneath the waterline!
  • End-to-end zero trust between supply chain participants, meaning least-privileged access not just to the network or firewall, but all the way through to applications, APIs, servers and devices. Nothing can connect to anything else without strong identity, authentication and authorisation. This includes end-to end-encryption – no sharing of encryption keys with cloud security providers (which also helps ensure data sovereignty).
  • Microsegmentation, the ability to define in granular detail who or what has access to which applications, and to limit lateral movement in the event of a breach. In effect, every application session becomes a private network-of-one, and it is quarantined by design.

Find out more at https://netfoundry.io/

  • Cybersecurity in FinTech

Rob Meakin, Director of Fraud & Identity at Creditinfo, on leveraging tech to tackle fraud

Financial fraud is increasing around the world, putting both mature and emerging digital economies at risk. The overall global economic impact of financial crime has been estimated to be $5 trillion. Furthermore, according to the 2024 Nasdaq global financial crime report, fraud losses totalled $485.6 billion worldwide. This from fraud scams and bank fraud schemes alone. As such, organisations face a series of challenges, from eroding profit margins to reputational risks to data breaches.

Many factors contribute to this growing wave of fraud. For example, digitisation in banking has created new opportunities for bad actors. With more identity data existing online, attack surfaces have expanded. Hackers now have more possible entry points to exploit vulnerabilities.

At the same time, new technologies, like machine learning (ML), artificial intelligence (AI), and automation are enabling bad actors to innovate faster and evade detection more effectively. AI, in particular, is a double-edged sword. While many businesses use the technology to improve efficiency and decision-making, it also gives bad actors a helping hand. Deepfakes and social engineering, for example, enable them to impersonate individuals with uncanny realism.

Additionally, cybercrime – especially financial crime – is becoming more sophisticated. Today, over two-thirds of financial institutions admitting they’re unprepared to defend against the rising wave of attacks.

Counting the many costs of fraud

Rising fraud creates challenges at local, national, and global levels. Financial loss is, obviously, a primary concern. But financial loss is only part of the total cost of cybercrime. Fraud also brings reputational damage, increased risk of data breaches, and potential legal consequences.

As organisations devise new strategies to tackle rising fraud, they must also heed regulatory requirements. Namely, Anti-Money Laundering (AML) registration, as well as other standards for privacy and consent. These regulations create further challenges for organisations as they aim to uphold rigorous compliance requirements without impacting sales, operating costs, or the customer experience.

It’s time for a different approach to fraud detection

On both local and global levels, mounting fraud threatens economic growth. In its Plan for Change, the UK government has recognised global co-operation will be necessary to tackle fraudsters. However, existing security strategies are too fragmented to suit the needs of diverse markets.

Emerging economies, for example, often lack mature controls, making them inherently vulnerable to hackers. Yet, with smaller digital infrastructures, they’re also less attractive targets for financial crime.

In contrast, more mature economies usually have stronger security defences. However, their larger digital ecosystems make them perhaps even more vulnerable to bad actors’ advances. After all, the more digital an economy becomes, the more fragmented and complex an individual’s identity and the more opportunities for bad actors to exploit or impersonate it.

Combatting fraud at a global scale requires going local

Considering the scale and sophistication of cybercrimes, combatting global fraud will require organisations to turn to localised data for more precise identity verification.

By integrating data from diverse, localised sources and tailoring fraud prevention strategies to market-specific risks, organisations can better detect fraud and establish identity trust. And in a way that both upholds the customer experience and promotes financial inclusion.

Combine credit, government, and digital data to enhance intelligence

Thwarting fraudsters begins with building intelligence to establish trust and verify presented identities. This is where localised data can help. By combining credit bureau data with government registries and digital signals, organisations can find a correlation across multiple digital identity attributes and digital risk signals to assess risk and enable real-time identity trust.

Credit bureau data associated with the presented identity can be used to determine risk and trust based on four vectors:

  • The bureau footprint: information comprising records from multiple contributing organisations
  • Activity history: evidence of recent and consistent payment activity
  • Data consistency: personal data stability
  • Application velocity: recent application history

Meanwhile, government information services and other registries can be incorporated to further cross-check the presented identity and strengthen verification.

By leveraging such a wide range of independent, localised data sources and correlating them with the presented identity attributes, organisations can significantly enhance intelligence to detect fraud without compromising the customer experience.

Tailor strategies to specific markets to support compliance and accessibility

It’s also important that organisations tailor their security and identity-verification strategies to the unique needs and maturity levels of specific markets. For example, in emerging economies, many people struggle to access financial services. This is often due to a lack of a formal credit history or other recognised financial records. Without this information, it can be a challenge for organisations to verify identity and reach trust decisions without inadvertently excluding legitimate users.

But by using localised data sources and market-specific strategies, organisations can make more informed decisions to bring more traditionally excluded parties into the financial system and promote broader financial inclusion without increasing risk or compromising security.

These targeted, market-specific fraud prevention strategies also help organisations with regulatory compliance. For example, for AML compliance, organisations must “identify, assess, and understand the money laundering and terrorist financing risk to which they are exposed.” Using localised data and market-specific strategies can help organisations meet this expectation by aligning fraud detection controls with region-specific threat intelligence.

Conclusion

Global financial crime continues to ramp up, creating new challenges for organisations to detect fraud, verify identities, and comply with regulations. But finding strategies to beat bad actors is made even more difficult by markets’ varying needs, maturity levels, and digital infrastructures.

To combat fraud and cyberthreats on a global scale, organisations should pivot to a localised approach. By combining credit, government, and digital data and tailoring fraud-prevention strategies to specific markets, they can enhance intelligence, maintain compliance, and better manage risk. In doing so, they can not only strengthen security but facilitate access to financial products and services for broader financial inclusion, worldwide.

  • Cybersecurity in FinTech

Intergiro’s CEO, Nick Root, on how payments providers can meet the challenges for cybersecurity in the war on fraud

We operate in the trenches of FinTech – real-time, full-stack and fully exposed to the relentless tide of digital fraud. As an embedded payments provider across the EU, Intergiro lives at the bleeding edge where innovation meets exploitation. And let me be clear: fraud isn’t a back-office nuisance anymore. It’s an existential threat. One that every modern financial company, especially those bootstrapped like ours, must treat as core business, not a support function.

Right now, 30% of our headcount is dedicated to fraud prevention, compliance and cybersecurity. That’s not a vanity metric – that’s the reality of staying alive in a hostile digital environment. We spend millions annually not just on tooling and infrastructure, but on reimbursing innocent victims. For a company building its future on resilience, programmatic control, and capital efficiency, these costs are brutal. But necessary.

The Scamdemic is Here

Fraud is no longer a sideshow; it’s the main event. In the past 18–24 months, we’ve seen a sharp escalation. Sweden’s financial police reported an 80% spike in investment fraud between 2022 and 2023. Our internal metrics tell the same story. Spiking fraud attempts, more advanced attack vectors and a user base under siege.

And this isn’t abstract. It’s personal. For example, I got hit by a fake Uniqlo storefront. Nearly lost money. Only Intergiro’s own controls saved me. It was a sobering moment: even a FinTech founder can fall victim. For digital natives, that’s embarrassing. For the less tech-savvy – think your parents’ generation – it’s a nightmare. My own father won’t use Uber unless one of us physically adds his card to the app.

Understanding the Threat Landscape

To address this epidemic, we first need to clarify the categories of fraud. Payment fraud and ID theft are mostly on us – as FinTechs. If a system fails, or a tool is exploited, we own that and cover the loss. But social engineering and investment fraud? They’re tougher. These rely on psychological manipulation – human vulnerabilities we can’t patch with software updates. Still, that doesn’t mean we’re powerless. We just need to shift our lens.

Upstream, Not Downstream…Fighting social engineering with regulation is like mopping up the floor while the roof’s still leaking. Necessary, but ultimately reactive. We need to move upstream. Way upstream.

Social Media: The Root of the Fraud Problem

Over 75% of fraud starts on social platforms. That’s the front door. If we don’t lock it, we’re just chasing shadows. Meta’s FIRE partnership with UK banks is a baby step in the right direction. But let’s be honest – it shifts responsibility onto banks to clean up the mess, while platforms avoid real-time accountability.

What we need is a pan-European version of FIRE, backed by the teeth of the Digital Services Act and centralised enforcement. FinTech alone can’t drive this. We need regulators, platforms and providers rowing in the same direction.

Public Awareness: Borrowing the Pandemic Playbook

Think about this: between 2020–2022, fraud cost the EU €157 billion. That’s not far off the public health spend from COVID. And fraud doesn’t recede – it compounds.

In a pandemic, we responded with mass public education: masks, distancing, handwashing. We need the same for digital fraud. A real, coordinated public awareness campaign built around these pillars:

  • Basic operational security –  Email is not secure. Banks don’t ask for details over email. Wire transfers aren’t reversible like card transactions.

  • Social media hygiene –  If it smells like a scam; even from a verified blue tick – assume it is. “Stop. Think. Click.”

  • AI as defence –  The same AI used to create scams can help spot them. Let’s teach users how to turn the tools around – scan that investment pitch, audit that wallet address.

Delivery matters here. Dry leaflets won’t cut it. Interactive quizzes, short-form video explainers, browser plug-ins – a toolkit that reaches people where the scams do: in-feed and in-app.

Collective Action Against Fraud: Collaboration Over Competition

FinTech has a reputation for speed, innovation and competition. But when it comes to fraud, isolation is the enemy. No single firm can win this war alone.

We need a secure, privacy-conscious layer for FinTech collaboration. A shared fraud intelligence layer that goes beyond blacklists and blocked BINs. We’re not talking about turning FinTechs into police forces, but enabling programmatic detection through pooled data, shared signals and joint tooling.

At Intergiro, we’re already piloting private data-sharing models with other European players. It’s early – but promising.

Final Word: It Takes a Village

This war against fraud won’t be won in the back office of your local neobank. It needs a whole-of-society effort. Platforms must step up. Regulators must align. And consumers must be trained – not blamed.

Fraud isn’t going away. As AI evolves, so will the threat. But so will we – if we move fast, stay dynamic, and invest in people, tools, and partnerships. Not just for ROI – but for resilience.

At Intergiro, we’re all in. But we can’t do it alone. If FinTech is the infrastructure of modern commerce, fraud is the fault line beneath it. And we can’t build the future on a fault line.

  • Cybersecurity in FinTech

AccessPay CEO Anish Kapoor examines the positive impact of DORA on the digital payments industry

The EU’s Digital Operational Resilience Act (DORA) is a positive step for the payments industry and will help boost the resilience of an ecosystem that has changed radically over the last twenty years. Even so, the implications of this landmark regulation for payment service providers (PSPs) are complex and far-reaching. It will require investment in processes and infrastructure, which must also factor in the ongoing shift to real-time payments.

The technology backstory

Two decades ago, payment technology predominantly referred to back-end systems used by banks and PSPs to process electronic transactions. Online banking was still in its infancy, the smartphone hadn’t yet been launched, and traditional payment methods such as cash and cheques were much more prevalent.  

Today, it is a very different story. The number of electronic payments made via cards and digital wallets, credit transfers and direct debits has exploded. Technology is front and centre in payment service delivery, as individuals and businesses use online portals and mobile apps to manage accounts and initiate payments. While the rise of real-time payments, such as the EU’s SEPA Instant Credit Transfer (SCT Inst), means an increasing proportion of bank transfers are settled instantly rather than over several working days, which also means that anti-fraud measures and other compliance checks have to take place in real-time given the heightened fraud risk.

So, if there is a technological failure at any point in this new world of payments, it can have immediate and considerable ramifications for individuals and businesses. The now-infamous CrowdStrike outage in July 2024 affected several sectors, including banking, with some PSPs unable to process payments. More recently, an hours-long glitch at Bank of Ireland in December 2024 caused delays in processing payroll transactions for some employers, while a two-day outage at Barclays in February 2025  left customers unable to make bank transfers and use their debit cards. To catch up, Barclays had to process payments over the weekend and extend call centre operating hours.  

DORA’s goals

DORA aims to make the EU’s financial institutions (FIs) more resilient to information and communication technology (ICT) risks. It will minimise the potential for IT outages and require FIs to be back online as quickly as possible when they do occur. From a practical perspective, it will oblige them to create and implement ICT risk management frameworks. And meet new requirements for resilience testing, outage reporting, and information sharing.

Of course, the advent of DORA adds to the compliance burden for FIs, who will partly be spurred to comply to avoid fines for non-compliance and the associated negative press. Still, its rollout should be seen as positive for the industry. It should help to improve resilience across the ecosystem and boost customer confidence in the sector.

Improving infrastructure resilience with DORA

One angle that is less widely discussed when it comes to DORA is its implications for a PSP’s infrastructure. Whether developed in-house or outsourced, payment systems will need to have the capacity to accommodate peak loads following any outage. This will require PSPs to scale by multiples of their standard throughput.

For example, if a PSP’s average processing volume is 1,000 transactions per hour and its systems are down for three hours, it will need to have the capacity to process those 3,000 outstanding transactions once service resumes. And without impacting new transactions coming through the system. Additionally, if they are real-time payments, the delayed transactions must be settled as soon as possible. In this hypothetical example, such an outage would mean the system needs to handle 4,000 transactions in one hour, four times its usual capacity.

This requirement to recover quickly from IT outages will necessitate additional investment in infrastructure and automation. Especially given the move towards real-time settlement. In particular, it will likely drive interest in cloud-native technology, which can scale more readily on demand.

Third-party vendor relationships

DORA will also significantly impact how PSPs manage third-party IT vendor relationships. This development has been driven by the growing complexity of the financial ecosystem in the wake of digitisation and the rise of open banking. Research from McKinsey Digital highlights how the growth in the number of apps and vendors has increased the complexity and pressure on IT leaders.  

Under DORA, FIs are expected to monitor third-party providers, update supplier contracts to cover IT resilience, and establish an oversight framework for critical third-party providers. Consequently, conducting due diligence on third-party providers, particularly new vendors, and their approach to resilience is essential. Generally, we are likely to witness a flight to quality, with the providers that invest in controls and resilience set to fare best in the long term.

Adjusting to DORA

The arrival of DORA is a positive development for the payments industry. The sector has changed significantly in recent decades and relies heavily on technology for service delivery. Likewise, its customers depend on the PSPs to deliver their services so that they can conduct their business uninterrupted. However, the changes required by DORA are extensive and will require PSPs to invest in their infrastructure, processes and third-party relationships. As they adjust to the requirements of DORA, PSPs should ensure that infrastructure is resilient and flexible enough to handle surges in transaction flows. And factor in the shift to real-time settlement, which will only add to the demands made of payment systems.

  • Cybersecurity in FinTech
  • Digital Payments

Nick Botha, Payments Lead at AutoRek, on meeting customer expectations for faster, cheaper and more transparent cross-border payments

As international trade and e-commerce continues to expand, cross-border payments have grown substantially. According to the latest report from EY, global cross-border payments are growing at around 9% annually. And they are expected to reach $290tn by 2030. As the digital economy continues to expand, the demand for more efficient, secure, and inclusive payment systems becomes crucial. The shift from traditional T+2 and T+1 settlement periods to real-time payments has already reshaped domestic transactions. Setting the stage for a similar revolution in cross-border payments.

Whilst there is plenty of opportunity for cross-border payments, sending and receiving payments can be a complex and challenging process. This is due to rising data volumes, fragmented systems, and different regulations across multiple territories. So, how can businesses best prepare for the evolving cross-border payments environment?

Breaking down the barriers for cross-border payments

It’s no secret that achieving real-time cross-border payments involves complexities beyond technology alone. Regulatory challenges are a significant hurdle. Multiple financial institutions across different countries have distinct rules around payments, fraud detection, and compliance. For example, the stringent regulations of the UK’s Financial Conduct Authority (FCA) contrasts with the relatively flexible approach of the US Federal Reserve. This diversity in regulations can lead to inefficiencies, increased costs, and compliance burdens. Harmonising these regulations will be crucial for creating a seamless global payment network.

In addition, cross-border payments often take several days to process through traditional banking systems. This can be due to time zones, inefficient processes and the involvement of multiple intermediaries, including correspondent banks, and local financial institutions. Each intermediary adds time and cost to the transaction, and the entire process can take between two to five days. For businesses, these delays can disrupt cash flow, complicate supply chain management, and create issues with paying vendors and employees promptly. Worryingly, the delay can prove hugely problematic for SME’s who often operate with tighter cash reserves and need more immediate access to funds.

Furthermore, businesses engaged in cross-border transactions must also navigate the complexities of fluctuating exchange rates. Currency exchange rates can change dramatically, influencing the cost and value of transactions. This could lead to financial losses if a payment is delayed or if a favourable exchange rate changes before the transaction is processed.

Unlocking potential by reducing complexity

To overcome cross-border challenges, G20 leaders endorsed a roadmap for enhancing payments globally in 2020. This initiative set out to address the four key challenges related to cost, speed, access, and transparency. Therefore, paving the way for a more efficient and inclusive financial ecosystem. For example, the G20 aims for 75% of cross-border payments to be credited with the beneficiary within an hour by 2027. The past couple of years have undoubtedly brought major milestones with respect to this roadmap. Most notably, SWIFT has been a central figure in traditional cross-border payments. It provides a standardised network for financial institutions to send and receive information about transactions.

The challenges faced by businesses with cross-border payments has unlocked new opportunities for financial institutions to develop innovative solutions. FinTechs are leveraging advanced technology, including blockchain, artificial intelligence (AI), and digital currencies, to make cross-border payments faster, cheaper, and more transparent. Blockchain and cryptocurrencies are often cited as potential game changers in cross-border payments due to their ability to eliminate the need for intermediaries, whilst enabling instant and transparent transactions. For example, Ripple, one of the leading blockchain-based payment networks, uses its RippleNet platform to facilitate payments between countries. This provides faster and more cost-effective payments.

Cross-border payments traditionally have been more complex than domestic transactions due to multiple intermediaries. Furthermore, it’s important to note ongoing international collaboration will be crucial to ensuring cross-border payments remain seamless, secure, and inclusive. This opportunity can be maximised through automatic reconciliation. By automating the processing of high volumes of date from cross-border payments, businesses can remove the distractions of mismatched information, fraud concerns and accounting hold-ups. It also manages inbound payments, outbound payments, and inter-currency transfers through a centralised framework. This enables businesses to gain complete visibility of the data.

Opportunities on the horizon for cross-border payments

The pace of change within the payments and wider fintech industry is showing no signs of slowing down. Customer expectations for faster, cheaper and more transparent payments are driving change across the sector. It’s certainly an exciting time for the industry, but financial institutions cannot afford to rest on their laurels. Further growth can be found on the horizon for those who are equipped with the right knowledge to be able to pursue cross-border payments effectively.

  • Blockchain & Crypto
  • Digital Payments

Ben Parker, CEO at eflow Global, on how consolidating information can help organisations achieve a comprehensive view of their regulatory compliance

When it comes to compliance, financial institutions are constantly navigating a landscape that is not only highly complex, but also in a state of perpetual flux. Firms must ensure that they are meeting the current standards set by regulators. Furthermore, they must also stay ahead of the curve in a world where regulations are continuously evolving. It’s about keeping up with the rapid advancement of technology, particularly in areas like artificial intelligence. It reshapes both the methods of regulatory enforcement and the strategies employed by those who seek to circumvent the rules.

Accordingly, the importance of technology and data in compliance strategies is ever increasing. Traditional approaches, such as manual data entry and analysis, are increasingly inadequate in meeting the demands of modern regulations. Just look at the frequency and granularity of data reporting that is needed for the EMIR Refit regulations as a practical example.

However, as financial firms have recognised this shift and turned to technology as the solution, the transition has brought new problems of its own. Namely, the fragmentation of data across disparate, siloed systems. So, how do firms solve this issue?

The data fragmentation problem in compliance

The issue of data fragmentation has become a common occurrence in compliance. Firms are often deploying multiple technology solutions to manage their regulatory obligations. Across areas such as trade surveillance, eComms surveillance, best execution and transaction reporting. As a result, they often find themselves grappling with data silos caused by using multiple, disconnected systems.

While these tools are often very good at specific tasks, a lack of data integration between systems will harm a firm’s overarching compliance efforts. These platforms, if sourced from different vendors, may not be able to share data between one another. This ultimately undermines their effectiveness, negating the operational efficiency technology is supposed to add.

The use of multiple systems by firms can happen for a variety of reasons. For example, legacy technology that has been in place for a number of years, the need to comply with different regulations as the business has scaled and changes in regulatory strategy. Moreover, you also need to consider that reporting formats can differ between regions, as can protocols for monitoring market abuse. When you combine all of these variables, it means only one thing – identifying non-compliant activity is trickier for firms to achieve, as is demonstrating compliance to regulators.

This is a major problem as, perhaps more than ever before, different areas of compliance overlap. For example, being able to monitor suspicious messages shared through digital communications channels could help identify instances of market abuse. Or predict when it might take place. This relies on a firm being able to map its trade data over eComms surveillance data to create a complete picture of the activity. Without being able to do this, firms would have to spend huge amounts of time and resources manually cross-referencing data from separate systems. In turn this increases the risk of human error and the danger of breaching regulations.

Why a holistic system supports compliance

Rather than having to implement complex and costly integrations between in-house and third party apps, a holistic compliance platform can provide the seamless flow of data between various sources via straight-through processing. This creates a real-time overview of compliance processes and streamlines workflows, reducing human errors and enhancing efficiency.

With such technology in place, firms have a central digital hub from which to manage their holistic regulatory strategy. If chosen wisely, additional modules can be easily added and integrated to meet new regulatory requirements as they emerge. This allows firms to scale more effectively.

This ‘single source of truth’ also enables compliance professionals to have a broader understanding of trading activity taking place across their organisation. It also facilitates improved sharing of information between different departments, trading desks and regional offices. This ‘joined up’ approach is likely to become even more important. As the financial landscape becomes increasingly interconnected this will be incredibly challenging to achieve without a centralised digital platform.

New regulations such as EMIR Refit require significant extra reporting requirements. The sheer amount of data and the speed with which it needs to be processed means such automation and integration tools are crucial. Moreover, in such a digitally diverse landscape, a holistic system allows companies to assess the numerous data points needed to be compliant without any regulatory gaps. 

A future non-negotiable

While many firms are currently grappling with multiple compliance systems and data silos, employing a centralised system will become a non-negotiable in the future of compliance. Not only are regulations constantly changing, but trading strategies are evolving even quicker. This means that instances of market abuse, driven by trends like growing interest in digital assets and AI-powered trading, are only likely to increase. If firms are hindered by disparate compliance systems, they leave themselves open to significant regulatory risk.

The underlying challenge for companies is to find ways to maintain compliance and keep on top of changing regulations while also ensuring these efforts do not place an unnecessary strain on resources. In the face of these challenges, a holistic compliance system offers the simple solution to striking this balance – it enhances the efficiency, accuracy, adaptability and overall effectiveness of regulatory processes. Crucially, it is clear that regulators have growing expectations of firms to take a proactive approach to this challenge.

A centralised regulatory system also sets firms up to integrate more advanced tools like AI. There are already highly sophisticated compliance tools that have integrated features like natural language processing to ‘translate’ messages and link suspicious communication to abusive trading. The more comprehensive and diverse the data, the better these models work at analysing trends and spotting abuse.

A holistic solution to a complex compliance challenge

While a firm’s intention may be to drive efficiency, the adoption of compliance technology without a coherent strategy can in fact create more issues. If compliance systems can’t communicate effectively with each other, errors creep into datasets and gaps in regulatory processes appear. This means firms risk breaching regulations and suffering greater market abuse, with both outcomes bringing financial and reputational damage. 

The key lies in integrating these disparate data sources into a single, cohesive, holistic system. By consolidating information, businesses can achieve a comprehensive view of their regulatory compliance. Therefore, reducing the need for cumbersome IT infrastructure and ensuring they remain agile in the face of ongoing regulatory changes. Ultimately, a holistic system simplifies a regulatory and trading landscape that is increasingly varied and complex.

Ben Hunter, Senior Director of Financial Services at Gigamon, on the impact of the Digital Operational Resilience Act (DORA) and what financial institutions can do to ensure lasting compliance

The Digital Operational Resilience Act (DORA) came into force on January 17th. It’s high time for financial institutions to refine their compliance and Cybersecurity efforts. This regulation isn’t just another box-ticking exercise. It represents a shift in the financial services industry that touches everyone in the ecosystem. And every corner of the organisations within it. From IT teams to the board, every department must pull together under a cohesive cyber strategy to meet the challenge. It’s not simply about systems and software. DORA demands a cultural shift toward organisation-wide cyber resilience.

At this stage, the big changes should already be in place. However, the focus now must be on the finer details. The overlooked pieces that could potentially make or break compliance and prove extremely costly. Organisations must tweak processes and ensure every element of their plan works seamlessly and aligns with the broader goal of operational resilience. Here are three areas of focus to perfect preparedness and ensure DORA compliance is not just a box checked but a new standard embraced by the whole organisation.

Criticality of third-party Cybersecurity management

One of DORA’s requirements is reducing reliance on single ICT service providers. This is designed to safeguard financial institutions against concentrated risk. By now, all structural changes should already be in place, with organisations diversifying their ICT providers. Or improving internal capabilities to reduce their external dependencies. However, compliance doesn’t end with restructuring. The focus must now shift from restructuring to managing these relationships effectively. Organisations should be looking to perfect their third-party risk assessment, monitoring, and due diligence strategies. They must ensure their processes for vetting ICT service providers are not just in place but are meticulously detailed. Contracts need to leave no room for ambiguity, with explicit terms outlining providers’ security and risk management strategies. These agreements must be revisited and stress-tested to confirm they align with DORA’s standards.

Equally critical is ironing out the specifics of ongoing monitoring and oversight. Institutions should be finalising the structure and frequency of their performance reviews and audits. Ensuring these mechanisms are robust enough to identify and address any emerging vulnerabilities. Moreover, by focusing on the details now, organisations can build a resilient operational framework that doesn’t just meet DORA’s requirements but builds resilience into their core operations for years to come.

Global efficiency through multi-cloud environments

Adopting a multi-cloud strategy has become essential for financial institutions operating on a global scale. It mitigates concentrated risk by avoiding dependence on a single provider and allows organisations to address the unique regulatory and operational challenges of different regions. However, the complexity of multi-cloud environments brings its own challenges. Particularly in ensuring the visibility and control required under DORA. This is why it’s crucial for organisations and their third parties to refine the tools and processes that support this level of visibility and allow the security teams to continuously monitor their environments.

According to recent data, 50% of CISOs say their confidence in risk management hinges on having full visibility into all data in motion, including encrypted and lateral traffic across both on-premises and cloud environments. This underscores the importance of advanced monitoring capabilities to effectively manage the complexities of multi-cloud infrastructures. While DORA mandates comprehensive visibility, the benefits go beyond just meeting compliance requirements. Deep observability strengthens organisations’ ability to detect vulnerabilities in real-time, ensuring seamless operations across regions and providers, and service continuity. For multi-cloud strategies to be effective, they must be paired with the right network-level monitoring capabilities. It’s important to build resilience from the inside out.

Organisational alignment to demonstrate Cybersecurity compliance

Demonstrating compliance isn’t just about avoiding fines and ticking regulatory boxes. It’s about preserving trust and protecting the organisation’s reputation. Reputational damage and financial penalties hit the top of the organisation hardest. This makes board-level engagement essential to ensuring Cybersecurity efforts are prioritised and aligned with broader business objectives. Boards must recognise that Cybersecurity is not a siloed function; it’s a key aspect of business resilience.

While security leaders are responsible for designing and implementing security strategies, their ability to deliver is directly tied to the board’s involvement. Board members control the decisions that shape an organisation’s Cybersecurity posture, from budget allocation to strategic priorities. Without their active engagement, security leaders may lack the resources, influence, or organisational buy-in necessary to implement comprehensive security measures. This can lead to significant gaps in compliance efforts and overall resilience.

To demonstrate compliance effectively, organisations need a unified approach to gathering, standardising, and presenting evidence to regulatory authorities. This includes aligning on consistent formats for documenting key areas like risk assessments, incident management, security testing, and third-party oversight. By finalising internal policies and leveraging automation tools, institutions can ensure their compliance evidence is regulator-ready and accessible. Such coordination not only satisfies DORA’s demands but also signals a strong, unified commitment to operational resilience. One that must come from the top and ripple throughout the entire organisation.

With penalties for non-compliance reaching up to 2% of global annual turnover, financial institutions cannot afford to be anything less than fully aligned on their compliance strategies going forward. Furthermore, as the broader compliance frameworks are now finalised, the focus must shift to perfecting the finer details that will ensure long-term resilience and success.

About Gigamon

Gigamon offers a deep observability pipeline that efficiently delivers network-derived intelligence and insights to your cloud, security, and observability tools. This eliminates security blind spots, optimises network traffic and reduces tool costs. Therefore, enabling you to better secure and manage your hybrid cloud infrastructure.

  • Cybersecurity in FinTech

Bharat Mistry, Director – Product Management at Trend Micro, on why attack surfaces are more difficult to mange than ever and the need for greater Cybersecurity controls to tackle the problem

Some surprising news emerged in mid-December. A Freedom of Information request sent to the Financial Conduct Authority (FCA) revealed that the number of c

Cybersecurity attacks reported to the regulator by large financial institutions fell 53% from the previous year. Reported data breaches also fell, by 29%. While welcome news, there are some big caveats.

The fall in reports could signify attacks are getting more sophisticated and harder to spot. The reporting periods also didn’t quite align, meaning two-and-a-half months of possible regulatory reports weren’t included in 2024’s figures. In fact, we’re seeing attacks and breaches at financial services industry (FSI) firms surging. In line with these organisations ramping up investment in digital transformation and IT modernisation projects.

Threat actors are grasping the opportunity with both hands. To keep them at bay, IT and cybersecurity leaders in the sector may need to rethink their approach to cyber risk management.

Cybersecurity controls are urgently required

Digital transformation is on an inexorable path. Driven by customer demand for seamless cross-channel experiences, and the quest for more streamlined business processes and productivity gains. Cloud adoption, mobile and app-centric services, remote workforces, and expansive supply chains are the result. However, this rapid change comes at a price. Research warns that half (49%) of global FSI leaders believe their attack surface is spiralling out of control.

Put simply, the ‘attack surface’ is the total expanse of all the IT and OT systems in a business that could theoretically be hacked. It includes everything from on-premises desktops and servers to cloud containers and even employees. Vulnerabilities and misconfigurations across these systems and services are inevitable. And the more assets there are, the more chance there is that a determined threat actor will find a weakness. This allows them to compromise the corporate network or a critical cloud account.

Heeding the warning

The likelihood of them doing so is increasing all the time. Not just because the typical FSI attack surface is increasing, but also because cybercriminals and nation-state operatives are getting better at using AI to their advantage. The National Cyber Security Centre (NCSC) warned back in January 2024 that AI “will almost certainly increase the volume and heighten the impact of cyber-attacks over the next two years”. It’s right. Generative AI in particular lowers the bar for budding threat actors by enabling them to create highly effective social engineering campaigns. And perform reconnaissance at scale to find weaknesses in organisations’ attack surfaces. In some cases, these weaknesses may exist in AI tools brought in by workers themselves. One report claims over a third of firms are struggling with shadow AI.

Our adversaries are also aided by the sheer complexity and interconnectivity of modern digital environments. APIs, microservices and third-party integrations -including frequently buggy or downright malicious open source components – expand the attack surface yet further.

Why it’s time for change

Managing risk across these environments should be a priority for obvious financial and reputational reasons. Open Banking rules and the growth of FinTech have made it easier for dissatisfied customers to jump ship. Furthermore, providing more options for those looking for a new provider. A serious breach could be the catalyst for a mass exodus. It’s also expensive in other ways. FSI is the second-top sector overall in terms of the average cost of a data breach. This is estimated to be over $6m per incident, assuming no more than 113,000 records are compromised.

However, there’s increasingly a regulatory imperative for FSI firms to rethink their Cybersecurity strategy. Any operating in the EU now has to comply with a rigorous new set of requirements in the EU Digital Operational Resilience Act (DORA). From January 1, 2025, those in the UK deemed to be critical third parties (CTPs) will be required to put in place a number of “technology and cyber risk management and operational resilience measures”.

A new mindset

So what does this mean in practice? Modern technology environments are dynamic, with new assets appearing and disappearing. Furthermore, new vulnerabilities are emerging and fresh misconfigurations surfacing on a daily or even hourly basis. Managing risk across this vast, incredibly volatile and highly distributed environment requires a new approach. Traditional perimeter defences are no longer sufficient.

Instead, FSI firms need continuous monitoring of risk across their entire attack surface. From endpoints and networks to servers and cloud workloads. Ideally, such a platform will flag areas of concern and either suggest improvements or automatically remediate. It could be something as simple as changing an insecure password, or patching a critical vulnerability newly published by a key vendor. This is the way to build resilience for the long term.

But there’s more. Some threats will always sneak through corporate defences. That’s why it’s also vital to expand security operations capabilities with AI-driven analytics and cross-layer detection and response (XDR). The goal is to correlate threat data across multiple layers and automatically prioritise alerts for stretched analyst teams. Robust incident response processes are also key here, to ensure no time is wasted in containing the threat and minimising any damage caused.

More broadly, it’s about fostering a culture of cyber resilience. Continuous improvement, proactive defence, and a willingness to adapt are ingrained in the corporate mindset. More Cybersecurity regulations are promised by the government in 2025. The clock’s ticking.

  • Cybersecurity in FinTech

Simon James, CEO of PayComplete, on why 2024 was a pivotal moment for cash and what the future holds

After several years of doom and gloom and many proclaiming the death of cash, the last 12 months have well and truly put that idea to bed. Despite many expecting the COVID pandemic to be the last nail in the coffin, four years later, cash is still in widespread use. The future looks bright. Recent figures from the British Retail Consortium (BRC) underscore the story of 2024… Cash is no longer on the way out and is set to remain a critical part of the payment ecosystem and economy for the foreseeable future.

What happened with cash?

The resilience and ongoing importance of cash to payments, finance, and the economy is down to two factors. Firstly, it’s clear now that consumers care. Recent research from PayComplete’s ‘Why won’t cash just die?!’ report found 89% of consumers view the ability to pay in cash as important to customer satisfaction. More importantly, when it is removed as a payment option, only 26% of consumers comply. Meanwhile, an even larger group (36%) vote with their feet and walk away without making a purchase.

It’s not just customer experience that’s impacted by the absence of cash as a payment option. Brand perception also suffers. Research findings discovered nearly half (47%) of consumers believe organisations that don’t accept it are putting profits ahead of customer satisfaction. Moreover, when denied the opportunity to pay in cash, respondents felt a range of emotions, including inconvenience (54%), outright annoyance (52%) and, for those who walked out without making a purchase, anger (16%). Failure to offer this payment choice is a big risk for businesses. It can negatively impact customer satisfaction, brand reputation, and lead to outright anger from customers.

However, the value consumers place on cash goes beyond it being a way of completing a transaction. It is also seen as critical to supporting local communities. Interestingly, the research found 65% of consumers know card payments incur charges for businesses, resulting in nearly a quarter (22%) actively choosing to pay in cash instead. In fact, over half (57%) of consumers want to help businesses save money by paying in cash, which jumps to 71% for small businesses, tipping, and personal services. Paying with cash, therefore, is not simply a way of transacting with a company. For many shoppers, it’s a sign of support.

Regulators and lawmakers protect cash

However, consumers continuing to care is only part of the story. Furthermore, an important factor has been the steps regulators and governments have taken to protect access to cash. In the UK, 2024 was the year that the FCA’s Access to Cash came into force. This made it a legal requirement for banks and building societies across the UK to provide a minimum level of access to cash. Across the pond, similar measures have been taken by Connecticut, Massachusetts, Colorado and Tennessee as US states move to enshrine access to cash into law. With lawmakers realising its importance, and creating regulations to protect access to it, the long-term future of cash is now secure.

What does it all mean?

2024 has been a watershed year for cash and its future. No longer are there debates and discussions about a cashless society. Instead, it is here to stay, and, with that certainty, it makes it far easier for businesses to plan for their own future. Businesses waiting to see what would happen with cash before deciding if it was part of their future now have a conclusive answer and can plan accordingly. Moreover, those who have already taken steps to move towards a cashless future will need to reverse course or risk facing consumer wrath.

The rise of CashTech

The good news for businesses is that cash management and handling technology hasn’t stood still these past few years. There is a combination of smart hardware and software to finally unify management, processing, and handling. CashTech is a new set of solutions that make it quicker, easier, and more efficient than ever before for businesses to handle cash. Combining hardware and software, CashTech solutions enable enterprises to digitise their handling. Making it easy to assess business-critical areas like cash flow management and better support accounting and business management processes. By automating handling, businesses can also avoid the unnecessary costs of discrepancies and inefficiencies from manual processes.

In the coming years, when we look back on 2024, we will see it as the year the future for cash was confirmed. Talk of a cashless future and the death of hard currency was wide of the mark. While cash may not usurp debit and credit card payments, neither will they bring about its end. With the future now clear, it’s time for businesses to adopt CashTech in 2025 and turn inefficient processes into a game-changing competitive advantage.

About PayComplete

PayComplete is the global leader in cash management solutions, combining bleeding edge hardware solutions with game changing software, unifying cash management with other key payments and operational systems. Dedicated to innovating self-service experiences and operations for both consumers and employees, The PayComplete IoT platform is made up of an adaptable set of SaaS and machine software, intelligent devices, and professional, technical and merchant services. PayComplete Connect unifies the management of transactions, users, devices, and data across the enterprise, bringing digital precision to cash transactions and systems. PayComplete serves a broad range of industries, including retail, transportation, financial services, vending, cash centers, mints and more.Industry leaders, work with PayComplete to make their cash transaction-based businesses more innovative, agile, and efficient.

  • Digital Payments

Martin Greenfield, CEO of Quod Orbis, on a troubling paradox within the cybersecurity landscape: despite substantial investments in security infrastructure, confidence levels and actual capabilities remain worryingly misaligned.

Financial institutions face concrete regulatory pressure on Cybersecurity with the European Union’s Digital Operational Resilience Act (DORA) coming into force in February. This landmark regulation demands robust ICT risk management and comprehensive security monitoring. Currently, many organisations continue to rely on disparate tools and spreadsheets that may leave them vulnerable to sophisticated threats. These include AI-powered deep fakes and targeted spear phishing campaigns.

This challenge transcends the financial sector as organisations across all industries face mounting pressure to demonstrate both security effectiveness and regulatory compliance. Our research reveals a stark reality. Organisations typically maintain an average of 19 security solutions per team. However, a surprising 41% still cite insufficient technology as the primary obstacle to maintaining a robust security posture.

This misalignment points to a fundamental issue. Organisations must recognise effective cybersecurity isn’t achieved through quantity of tools, but through strategic selection of the right solutions. Furthermore, perhaps most concerning is the false sense of security prevalent among IT decision-makers. While 93% express confidence in their infrastructure visibility tools, an alarming 95% acknowledge difficulties in accessing specific digital assets over the past year. This creates dangerous blind spots leaving organisations exposed to both security breaches and compliance shortfalls.

Understanding the Cybersecurity challenge

Today’s enterprise infrastructure resembles a tapestry of critical assets, connections and endpoints. To put this complexity into perspective: IT teams now manage an average of 31 endpoints per person across their organisation. For a company of 1,000 employees, this translates to more than 30,000 devices requiring constant monitoring and protection. This challenge intensifies with the widespread adoption of cloud services, hybrid working arrangements and an ever-growing ecosystem of connected devices.

Scale amplifies these difficulties markedly. Our research reveals organisations with more than 1,250 employees demonstrate the lowest confidence in their existing tools (88%) and face the greatest challenges in accessing critical assets (97%). Moreover, these larger enterprises typically wrestle with an unwieldy combination of legacy systems, bespoke solutions and modern platforms. This results in notably lower visibility rates (79%) compared to their smaller counterparts.

Perhaps most revealing is the stark confidence gap between technical and compliance teams. While 94% of information security directors express confidence in their system visibility, merely 66% of compliance directors share this outlook. This disparity exposes a crucial misalignment between technical capabilities and compliance requirements. One that poses serious operational risks as regulatory frameworks increasingly demand continuous monitoring. Organisations clinging to manual compliance processes face an unstable burden. Teams are stretched thin handling routine tasks while regulations grow more complex. Embracing automated technologies to handle routine monitoring requirements will allow compliance teams to pivot from being reactive box-checkers to strategic risk managers.

Moving from reaction to prevention

The impulse to combat emerging threats by rapidly acquiring new security solutions has led many organisations to create sprawling, inefficient systems. These often compound the very problems they aim to solve.

This reactive approach has trapped organisations in a costly cycle of diminishing returns. Despite substantial technology investments, nearly 40% of firms report a troubling lack of actionable intelligence, while 37% struggle with budget limitations. This paradox is increasingly drawing board-level scrutiny. And rightfully so. After years of approving emergency technology purchases to plug cybersecurity gaps, boards are now questioning the value of new investments. Furthermore, tthis creates a dangerous stalemate: organisations need smarter, not just more, technology investment.

However, a more strategic approach is gaining traction through integrated system monitoring platforms. These comprehensive solutions unite previously disconnected tools under a single dashboard. This can offer real-time visibility across the entire cybersecurity landscape. This unified approach enables teams to identify and address vulnerabilities before they evolve into security incidents. A capability that resonates with the 82% of organisations who recognise enhanced visibility would substantially strengthen their cybersecurity posture.

It’s encouraging that 72% of IT teams have secured increased budgets over the past three years. However, the path forward requires more than mere financial investment. Organisations must shift from reactive spending to strategic deployment. Although this presents its own challenge: convincing board members that additional tooling represents an investment in comprehensive visibility rather than merely plugging security gaps.

The path forward

The transformation from fragmented security to comprehensive oversight demands more than technological upgrades. It requires a fundamental reimagining of how organisations approach cybersecurity monitoring and compliance.

The advantages of this strategic shift are compelling and quantifiable. Our analysis reveals security teams anticipate multiple efficiency gains: 38% expect automation to streamline document creation, 37% foresee improved board pack preparation, and 36% anticipate dedicating more time to strategic security assessments. Perhaps most significantly, 35% predict a reduction in human error alongside enhanced data accuracy. The efficiency gains are substantial. Teams could reclaim up to 60 hours annually per member on board reporting alone, time better invested in strategic security initiatives.

With regulatory frameworks growing increasingly sophisticated across sectors, including the forthcoming DORA regulation, maintaining current practices is no longer viable. The disparity between perceived and actual security capabilities poses a tangible risk that organisations must address proactively.

About Quod Orbis

Quod Orbis is the single source of truth across security, risk and compliance, providing an orchestration layer for the entire tech stack whether in the cloud, on-premise, legacy or bespoke. Founded in 2018, Quod Orbis became part of Dedagroup, one of the leading Italian IT players, in 2024.

A pioneer in Continuous Controls Monitoring (CCM), Quod Orbis provides complete and constant visibility into a company’s cybersecurity, compliance and risk posture. Quod Orbis’ ability to connect with every piece of technology within a business, unrivalled automation capabilities and continual support enables the company to serve a global client base across a wide variety of industries.

  • Cybersecurity in FinTech

Bryan Daugherty, Global Public Policy Director at the BSV Association (BSVA) and Co-Founder at SmartLedger Solutions, on how blockchain technology provides the accountability and cybersecurity needed to prevent widespread IT catastrophes across sectors

By Embracing Blockchain, We Can Create a Safer Digital Future

The rapid increase in cyberattacks poses a severe threat to businesses. These attacks are becoming more sophisticated and costly by the day. The average cost of a data breach in the UK is £3.58 million, and in the US now $9 million. It typically takes 200 days for organisations to detect a breach, followed by another 70 days to contain it. These delays expose significant vulnerabilities in traditional data management systems. They rely heavily on third parties, making them prime targets for cybercriminals.

Blockchain technology offers a transformative solution to these challenges by creating a secure, decentralised model that can effectively mitigate risks. It provides an opportunity for both individuals and organisations to take control of their data. Therefore, improving cybersecurity and ensuring operational resilience.

The Problem with Centralised Systems

Traditional cybersecurity systems are built on centralised models, where data is stored in one location or through third-party intermediaries. This structure makes them attractive targets for cybercriminals, creating a “honeypot” of information that can be breached. A concerning statistic is that, for over a decade, organisations have taken an average of 200 days to detect breaches. Despite claims from cybersecurity vendors that they provide “instant detection,” real-world results show significant gaps in protection, putting data at risk for extended periods.

Blockchain: Game-Changing Cybersecurity Features

Blockchain’s decentralised model provides a powerful alternative. By distributing data across a global network of nodes rather than a central location, blockchain makes it exponentially harder for cybercriminals to compromise large datasets. Even if one node is breached, the entire system remains intact. This eliminates the single point of failure that centralised systems suffer from.

Another key feature of blockchain is its immutability. Once data is recorded on a blockchain, it cannot be altered or erased, making tampering nearly impossible. Therefore, this ensures any unauthorised access is immediately detectable, enabling quicker response times and minimising damage.

Real-Time Threat Detection with CERTIHASH

Blockchain’s potential in cybersecurity is already being realised through solutions like CERTIHASH’s Sentinel Node. A blockchain-based tool that provides real-time threat detection. Built on the BSV blockchain, CERTIHASH can detect breaches within 10 seconds or less, offering a proactive approach to cybersecurity. This is a significant improvement over traditional systems, which often take months to identify breaches, leaving organisations vulnerable to prolonged data exposure.

By leveraging blockchain, cybersecurity shifts from being reactive to proactive. This gives organisations the tools they need to stay ahead of evolving threats and safeguard data more effectively.

Overcoming Misconceptions About Blockchain

Despite the clear advantages of blockchain, many organisations remain hesitant to adopt the technology, often due to misconceptions. Furthermore, some still associate blockchain with cryptocurrencies like Bitcoin, which have been linked to ransomware. This outdated view overlooks blockchain’s real potential as a secure, decentralised data management tool.

Blockchain is not just about crypto; it’s about creating a new standard for data integrity and security. Moreover, it offers decentralised, tamper-proof records that give users control over their own identity and data, reducing reliance on vulnerable third-party systems.

A Decentralised, Secure Future

As global reliance on centralised systems grows, so do the vulnerabilities they present. A single point of failure can lead to widespread outages, as seen in numerous cyberattacks and technical malfunctions. Blockchain, with its decentralised architecture, offers a robust alternative that enhances the security and resilience of critical systems. By distributing data across multiple nodes, blockchain ensures continuity even during attacks or outages.

Conclusion

Investing in blockchain cybersecurity is no longer optional. With cyber-attacks growing in scale and sophistication, organisations must adopt cutting-edge technologies to protect their data, operations, and customer trust. Blockchain’s decentralised and tamper-proof architecture offers the key to building a safer, more secure digital future. One where businesses and individuals alike can operate with confidence, free from the constant threat of cybercrime.

  • Blockchain & Crypto
  • Cybersecurity in FinTech

Misplaced confidence in visibility tools leaves organisations vulnerable amidst record high data breaches, according to latest research

A new report from Quod Orbis highlights that 95% of businesses are at risk of a cybersecurity blindspot. A reported 93% of UK organisations have confidence in their system visibility. However, nearly all (95%) of them have struggled to access critical assets in the last year, according to the research.

Over a third (38%) actually rank lack of visibility as one of their biggest challenges, further highlighting the gap between respondents’ perceptions and the reality of their situation. This comes at a time when data breaches this year have already surpassed one billion stolen records.

Quod Orbis Cybersecurity Research

Martin Greenfield, Quod Orbis CEO, comments: “Businesses are suffering from a blind spot that’s leaving them exposed. Misplaced confidence in existing cybersecurity tools means these same organisations are susceptible to data breaches and non-compliance fallout. This results in potentially crippling financial and reputational consequences.”

Quod Orbis commissioned a research study with international research house, Censuswide, to poll 500 board executives and IT decision makers, across enterprises of 500+ employees in the UK.

Cybersecurity Tech Stacks

Cybersecurity tech stacks are growing exponentially in the face of rising threats. The average team manages 19 security solutions at any one time. However, 41% still report a lack of technology as being their biggest challenge when it comes to maintaining a robust cybersecurity posture.

As 72% of IT teams have had their IT budget increased in the past three years, Greenfield urges businesses to break free from the typical cycle of throwing money at a problem and hoping something sticks. “It’s not about the biggest investment, it’s about the right investment.”

A quarter (26%) of IT decision makers are yet to allocate budget to basic security tools like asset visibility technology. This is despite 40% reporting a lack of actionable data.

It’s clear though that businesses recognise the advantage of implementing the right technology. More than eight in 10 (82%) agree that greater visibility over digital assets will greatly improve business security. This is a huge leap from the 93% of respondents who believe their businesses already provide them with the necessary tools.

According to the data, most upcoming IT investments will be allocated to Continuous Controls Monitoring (32%), privileged and identity access management (30%) and zero trust (29%).

The Future

Greenfield concludes: “Digital infrastructure has reached a level of complexity that not only warrants, but demands, complete visibility. Now is not the time to gamble with your company’s security. Furthermore, organisations need to stop adding layers of unnecessary technology as a way of solving the immediate problem. Instead, they must take a step back and think holistically about how to resolve their issues.

“Tools like CCM, powered by automation, help teams see and understand their security and risk posture in real time. This offers peace of mind that all of their data is relevant and up to date. This level of insight provides early awareness of potential problems and empowers teams to take a proactive approach to security, instead of being forced back into the same reactive position they’ve been in for years.”

About Quod Orbis

Quod Orbis is the single source of truth across security, risk and compliance, providing an orchestration layer for the entire tech stack whether in the cloud, on-premise, legacy or bespoke. Founded in 2018, Quod Orbis became part of Dedagroup, one of the leading Italian IT players, in 2024.

A pioneer in Continuous Controls Monitoring (CCM), Quod Orbis provides complete and constant visibility into a company’s cybersecurity, compliance and risk posture. Quod Orbis’ ability to connect with every piece of technology within a business, unrivalled automation capabilities and continual support enables the company to serve a global client base across a wide variety of industries.

  • Cybersecurity in FinTech

Innovative Systems, a leading provider of enterprise data, compliance, and integration solutions, has launched FinScan Marketplace

The platform will serve as a one-stop shop for anti-money laundering (AML) compliance. It offers a streamlined approach to managing compliance risk and unified case management via a central hub for all related activities. FinScan Marketplace positions itself as a trusted partner for organisations navigating today’s complex, global regulatory landscape.

Removing the complexity of AML compliance

“Our goal with FinScan Marketplace is to remove the complexity of AML compliance. We bring everything organisations need into one unified platform,” said Deborah Overdeput, Chief Marketing Officer at Innovative Systems. “This launch reflects our commitment to delivering solutions that simplify processes. We empower compliance teams to work smarter, and ensure organisations remain vigilant. And fully aligned with evolving regulatory requirements in a rapidly changing landscape.”

FinScan Marketplace revolutionises how organisations manage their AML portfolio. It provides a single, easy-to-navigate interface. Customers can seamlessly access a comprehensive suite of tools. These include sanctions screening, KYC checks, adverse media screening, payment screening, and risk scoring, with additional features continually in development.

FinScan Marketplace

At the heart of FinScan Marketplace is its unified case management system. This integrates all critical AML processes into a cohesive workflow. From performing due diligence checks to monitoring transactions and investigating potential risks, customers can manage everything within a single platform. This integration saves time, reduces errors, and ensures compliance efforts remain seamless and effective.

FinScan Marketplace provides customers with a clear vision of the platform’s evolution. Its intuitive interface lets users view in-progress product developments, register interest in upcoming features. Furthermore, they can participate in design feedback sessions. This approach ensures future enhancements align closely with real-world compliance needs.

“We are not just delivering tools; we are creating partnerships with our customers by building solutions that adapt to their challenges,” Overdeput added. “Transparency and collaboration are key pillars of the FinScan Marketplace.”

Innovative Systems for AML

FinScan Marketplace reflects Innovative Systems’ dedication to becoming a trusted partner for a host of organisations. These include financial institutions, insurance companies, fintechs, casinos and gaming entities, charities and non-profits, government agencies, and other organisations it serves. By continuously delivering value, anticipating industry needs, and prioritising customers’ feedback in its development process, the company demonstrates its commitment to supporting effective and reliable AML compliance.

Innovative Systems delivers enterprise data, compliance, and integration solutions through the company’s leading FinScan®, Enlighten®, and PostLocate® brands. These solutions offer actionable insights and enable organizations to identify the hidden opportunities or risks in their data. We have pioneered best-in-class data quality, data management, and risk and compliance solutions in thousands of applications across more than 65 countries. Our cloud-based (SaaS), on-premise, and hybrid offerings deliver dramatic, measurable improvements in accuracy, cost, and time to production over alternatives. Learn more at innovativesystems.com

About FinScan


Trusted by hundreds of organisations worldwide, Innovative Systems, Inc.’s FinScan offers advanced Anti-Money Laundering (AML) compliance technology and consulting solutions. Built on decades of experience in data management and proprietary matching technologies, FinScan provides a data-first, risk-based approach to ensure unparalleled accuracy and efficiency in identifying and reducing risk, accelerating AML compliance workflows, and optimising team productivity. FinScan’s comprehensive, integrated platform includes Know Your Customer (KYC), unparalleled sanctions screening, risk scoring, data quality, and advisory services for implementing a holistic compliance program. FinScan offers flexible deployment including SaaS, on-premise, and hybrid options. FinScan’s SaaS clients are screening more than 300 billion names a year. Learn more at finscan.com


  • Cybersecurity in FinTech

Alex Mosher, Chief Revenue Officer at Armis, on why businesses are prioritising their cybersecurity budgets, ensuring they have the resources needed to counteract emerging threats

Cybersecurity is no longer optional. In 2025, we expect a significant uptick in overall spending. With threats becoming more sophisticated, organisations recognise the imperative to invest adequately in cybersecurity measures. This trend is driven by the growing awareness that the cost of a cyber-attack far outweighs the investment required to prevent it.


Shift Toward Comprehensive Cybersecurity Solutions

In 2025, there will be a marked shift toward comprehensive security solutions that offer integrated functionalities. Companies will increasingly seek platforms that provide threat detection, incident response, and compliance management within a single solution. This trend arises from the need to simplify security management and reduce complexity. Siloed solutions are ineffective, expensive and reduce the efficiency of security teams with finite resources. Furthermore, by consolidating various security functions into a unified platform, businesses can streamline their processes and enhance their overall security posture. Integrated solutions offer a holistic approach to cybersecurity, addressing multiple aspects of an organisation’s security needs. The move toward comprehensive solutions also reflects a broader understanding of the interconnectedness of cybersecurity elements. A unified solution that addresses multiple areas provides a more robust defence against potential breaches.

Emphasis on Automation and AI

Automation and artificial intelligence (AI) are revolutionising the cybersecurity landscape. Organisations increasingly prioritise spending on AI-driven security solutions to enhance threat detection and response capabilities. The focus will be on tools that streamline incident response, reduce manual workloads, and enable security teams to focus on more strategic initiatives. Moreover, the trend will also include spending on analytics tools that help organisations understand and mitigate risks based on the current threat landscape. Threat intelligence and analytics play a pivotal role in enhancing an organisation’s security posture.

AI technologies offer a proactive approach to cybersecurity, allowing organisations to identify and mitigate threats in real-time. By leveraging machine learning algorithms and data analytics, businesses can gain deeper insights into potential vulnerabilities and respond swiftly to emerging threats. The emphasis on automation and AI is driven by the need to enhance efficiency and effectiveness in cybersecurity operations. By automating routine tasks and employing AI for advanced threat detection, businesses can optimise their resources and achieve a more robust security posture.

Investment in Cloud Cybersecurity Solutions

The migration to cloud environments continues to accelerate, driving the need for robust cloud security solutions. Key investment areas will include cloud security posture management (CSPM) and cloud workload protection platforms (CWPP). The emphasis on cloud security reflects the growing reliance on cloud services for business operations. Moreover, organisations recognise that securing their cloud environments is paramount to safeguarding digital assets and ensuring regulatory compliance. Investments in cloud security solutions also align with the broader trend toward digital transformation. Businesses are leveraging the cloud to drive innovation and agility. This neessitates a strong security framework to protect their evolving digital ecosystems.

Enhanced Budgeting for Compliance and Regulatory Needs

Data protection and privacy regulations are becoming increasingly stringent worldwide. Also, this necessitates enhanced budgeting for compliance-related cybersecurity solutions. I expect organisations to allocate more resources to auditing tools, risk management platforms, and solutions that help them meet regulatory requirements such as GDPR, CCPA, and HIPAA.

The emphasis on compliance reflects a growing awareness of the legal and reputational risks associated with non-compliance. Investing in compliance-related solutions also aligns with the broader trend toward data-driven decision-making. Moreover, by implementing tools that ensure alignment with regulatory requirements, organisations can demonstrate their commitment to ethical data practices and build trust among stakeholders.

Growth in Cybersecurity Insurance Expenditures

Cyber insurance is becoming an essential component of an organisation’s risk management strategy. The growth in cybersecurity insurance expenditures reflects a broader awareness of the financial implications of cybersecurity threats. Investing in cyber insurance aligns with the emphasis on accountability in cybersecurity spending. By securing coverage for potential losses, businesses can demonstrate their commitment to protecting their assets and ensuring business continuity in the face of unforeseen events.

By understanding the key cyber spending patterns outlined here, businesses can make informed decisions. They can enhance their security posture to protect their valuable assets and ensure business continuity as we move into 2025.

  • Cybersecurity in FinTech
  • InsurTech

Waheed Mahmood, Financial Services Lead at Rackspace Technology, on how cloud is elevating CX in the financial services industry

The importance of customer experience (CX) in financial services is growing. In July 2023, the Financial Conduct Authority (FCA) published its Consumer Duty guidelines, designed to set clearer standards of protection for consumers of financial services. The Consumer Duty was created to ensure that financial institutions (FIs) act fairly, while preventing customers from making poor financial decisions.

Despite the guidelines being implemented over a year ago, some FIs are still struggling to meet customers’ needs and are not working hard enough to protect them. In October 2024, for example, the FCA fined TSB Bank Plc £10,910,500 for failing to ensure that customers in arrears were treated fairly between 2014 and 2020.

According to Forrester, there has also been a significant decline in EU bank customer experience (CX) quality in 2024. This matters, because as CX quality declines, so does customer loyalty. Financial service executives must step up their game if they want to stay competitive and earn this loyalty. FIs that leverage technology can increase customer satisfaction, reduce the cost to serve and boost conversion rates and profitability. As we look ahead, here are some ways FIs can harness technology to drive customer satisfaction in 2025 and beyond.

Driving CX through the Cloud

The Consumer Duty’s objective was to guide individuals toward sound financial decisions. To achieve this, FI’s must leverage data and analytical insights. However, legacy systems often hinder effective data sharing and analysis, limiting the ability to provide personalised guidance.

Private cloud technology empowers banks to modernise their legacy systems. This can increase agility with the delivery of new services and products, enabling them to create and deliver enhanced CX. This includes offering seamless digital experiences, from smart self-service options and instant transaction tracking to tailored financial guidance and decision-making. Banks can also use cloud analytics to spot user pain points and service disruptions early, directly improving both customer satisfaction and profitability.

The integration of cloud services with existing banking systems also enhances data flow and interoperability. Real-time analytics platforms, such as Azure Stream Analytics help process and analyse vast amounts of data. This can reveal valuable insights into customer behaviour and preferences. Banks can then offer personalised advice and services, boosting customer satisfaction and interaction.

To maximise these benefits, FI’s need to ensure these customer insights are shared across departments. Eliminating departmental silos can drive improvements in product development, marketing strategies, and customer service protocols. Success requires integrating design expertise and data capabilities – involving teams from every business function to build a data framework and platform. This integration will help convert customer insights into actionable improvements.

Double down on service innovation for CX

Before leveraging cloud technology, FIs must evaluate their current technology stack to identify weak points before embarking on digital transformation initiatives. Legacy systems, which many FIs still depend on put them at a disadvantage as customer demands and expectations grow. This outdated infrastructure is particularly vulnerable, leaving sensitive customer data exposed to risk.

By updating their technology stack, FIs can improve customer interactions while streamlining critical systems for transaction handling and personalisation. These work together to deliver an experience that aligns closely with individual customer needs. 

FIs are also leveraging machine learning to gain insights into customer spending patterns, enabling them to offer personalised financial advice and recommendations. Additionally, GenAI is reshaping CX; AI-driven chatbots, for example, offer instance guidance and assistance, freeing up human staff to focus on more complex issues. However, to maximise the benefits of GenAI, FIs need robust infrastructure in place. GenAI models require high-quality, well-structured data for training and precise forecasting.

A cloud-based platform is particularly well-suited for FIs with specific demands around control, security and workload customisation. By adopting this approach, institutions can meet the high storage and encryption requirements of GenAI, thereby, enhancing both system performance and data security – key factors in scaling these technologies.

To respond to a continued decline in customer experience quality, financial service providers must make this a strategic priority. Delighting and engaging customers on a personal level has become vital and institutions that satisfy these expectations will be best equipped to attract new clients and build enduring loyalty.

  • Neobanking

Seth Ruden, Director of Global Advisory at BioCatch, on how the UK’s financial institutions can be better prepared to deal with authorised push payment (APP) scams

The focus on authorised push payment (APP) fraud scams – where scammers impersonate reputable individuals or institutions – has increasingly shifted to whether banks should reimburse customers for funds stolen by scammers. We can gain valuable insights from the approaches taken by financial institutions in the UK. They are leading the way with their cybersecurity efforts compared to their counterparts in other regions.

First, British banks established a standardised reporting system and typology. This is a fundamental first step that every financial institution should take to grasp the full scope of how financial fraud affects banking consumers. Banks may disclose the type of fraud, the amount of money stolen, and the bank measures used to prevent the scam from occurring. This centralised view brings the true scope of the totality of scams into focus.

Three ways the UK’s financial institutions are leading in the fight against fraud

Second, the UK has developed strategies to identify specific scams and reduce their losses. The regulator added a slew of new controls to banks, including confirmation of payee, scam and transaction-specific interventions, and money mule account controls for those receiving the illicit funds. Before regulation, not every financial institution had implemented these controls, providing an uneven playing field and allowing scams to flourish. Banks outside the UK should not wait for regulators to mandate controls like these. They should do it on their own accord to prove they realise the magnitude of the scam problem and the severity of its impact on bank customers.

Improved consumer financial scam controls should be a minimum requirement for financial institutions in 2024. These controls should cover: authorised push payment behavioural analysis, money mule behaviour around both account opening and account activity, and analysis of both inbound and outbound transactions. Furthermore, detecting and then closing money mule accounts – used by fraudsters as an intermediate stop between the victim’s account and the final destination for the stolen funds – is absolutely critical, as they serve as the backbone for every consumer-based financial scam.

The third? Getting involved. Banks need to integrate themselves and participate with industry and trade associations – such as the FS-ISACs and GASA (Global Anti Scam Alliance). These associations provide opportunities to network with peer institutions and others in the fraud value chain to share scam information and learn from each other.

Effective Fraud Prevention: A practical assessment of Key Strategies

Many banks today use precision anomaly detection and behavioural biometrics to notify them when a fraudulent transaction takes place. Financial institutions in the UK often issue actionable alerts to clients in real-time. Santander UK, for example, now asks customers if they have seen the item in person before approving a payment through Facebook Marketplace. For online account opening, there are good solutions for bot-detection to prevent automated bots from opening new accounts, behavioural biometrics to detect suspicious patterns of data entry, and solutions that can analyse the customer KYC data. A secondary benefit of strong account opening controls is the reduction of operational costs to close bogus accounts.

For detecting existing money mule accounts, traditionally it required tracking the circulation of funds, both the inbound and outbound transaction activity and looking for anomalies (e.g. high value in and then immediately transferred out). Now, user behaviour anomalies – such as changes in the user’s input/output device activity or navigation preferences – may indicate a change in account control before the suspicious transactions take place.

Protecting Customers: What the future holds for Financial institutions

Since the UK’s introduction to faster payments, the region has become a centre of research for the rest of the world. However, eliminating threats to UK customers and their money has remained difficult despite an increase in regulation. While Governments and international groups are starting to identify and take down some of these organisations there are still hundreds of thousands of scammers and coerced individuals involved in these intricate schemes. A key challenge for financial institutions is understanding how scammers get their customers to initiate authorised payment. However, these challenges can be combatted by understanding the psychology behind how scammers work which can be a prominent factor in tackling the problem. Financial institutions must ensure that, in a few years’ time, they can confidently answer ‘yes’ to the question: Did we do enough to help eliminate consumer financial scams?

  • Cybersecurity in FinTech

Other key findings include surge of info-stealers and botnets, an increase in evasive malware and a rise in network attacks across the Asia Pacific

WatchGuard® Technologies, a global leader in unified Cybersecurity, today released the findings of its latest Internet Security Report. The quarterly analysis details the top malware, network, and endpoint security threats observed during the second quarter of 2024. 

Among the report’s key findings was that 7 of the Top 10 malware threats by volume were new this quarter. Furthermore, this indicates threat actors are pivoting toward new techniques. The new top threats included Lumma Stealer. This advanced malware is designed to steal sensitive data from compromised systems. Also, a Mirai Botnet variant, which infects smart devices and enables threat actors to turn them into remotely controlled bots. And a LokiBot malware, which targets Windows and Android devices and aims to steal credential information. 

Cybersecurity fears for Blockchain

WatchGuard’s Cybersecurity Threat Lab also observed new instances of threat actors employing “EtherHiding”. A method of embedding malicious PowerShell scripts in blockchains such as Binance Smart Contracts. In these instances, a fake error message linking to the malicious script appears on compromised websites, prompting victims to “update your browser”. Malicious code in blockchains poses a long-term threat. As blockchains are not meant to be changed, theoretically, a blockchain could become an immutable host of malicious content. 

“The latest findings in the Q2 2024 Internet Security Report reflect how threat actors tend to fall into patterns of behaviour. Certain attack techniques become trendy and dominant in waves,” said Corey Nachreiner, CSO, WatchGuard Technologies. “Moreover, the report illustrates the importance of routinely updating and patching software and systems to address security gaps and ensure threat actors cannot exploit older vulnerabilities. Adopting a defence-in-depth approach, which can be executed effectively by a dedicated managed service provider, is a vital step toward combating these cybersecurity challenges successfully.”

Additional key findings from WatchGuard’s Report include: 

  • Malware detections were down 24% overall. This drop was caused by a 35% decrease in signature-based detections. However, threat actors were simply shifting focus to more evasive malware. Moreover, in Q2 2024, the Threat Lab’s advanced behavioural engine that identifies ransomware, zero-day threats, and evolving malware threats, found a 168% increase in evasive malware detections quarter-over-quarter. 
     
  • Network attacks increased 33% from Q1 2024. Across regions, the Asia Pacific accounted for 56% of all network attack detections, more than doubling since the previous quarter.
     
  • An NGINX vulnerability, originally detected in 2019, was the top network attack by volume in Q2 2024. It had not appeared in the Threat Lab’s Top 50 network attacks in previous quarters. The vulnerability accounted for 29% of total network attack detection volume, or approximately 724,000 detections across the US, EMEA, and APAC. 
     
  • The Fuzzbunch hacking toolkit emerged as the second-highest endpoint malware threat detected by volume. The toolkit serves as an open-source framework that can be used to attack Windows operating systems. It was stolen during The Shadow Brokers’ attack of the Equation Group, an NSA contractor, in 2016. 
     
  • Seventy-four percent of all browser-initiated endpoint malware attacks targeted Chromium-based browsers, which include Google Chrome, Microsoft Edge, and Brave.
     
  • A signature that detects malicious web content, trojan.html.hidden.1.gen, came in as the fourth most-widespread malware variant. The most common threat category caught by this signature involved phishing campaigns. These gather credentials from a user’s browser and deliver this information to an attacker-controlled server. Curiously, the Threat Lab observed a sample of this signature targeting students and faculty at Valdosta State University in Georgia. 
  • Blockchain & Crypto
  • Cybersecurity in FinTech

UnaFinancial study identifies cybersecurity as most influential factor driving FinTech growth

A recent study from UnaFinancial has identified cybersecurity as the most influential factor driving the development of FinTech worldwide, with a 63% significance. The second most impactful factor is the average hourly wage rate, with a 13% significance.

The study showed that FinTech growth in Europe, America, and globally has the strongest correlation with the size of the cybersecurity market, with correlation coefficients of 0.8714, 0.9762, and 0.8607, respectively.

In Asia, however, FinTech growth was more closely tied to the size of the consumer electronics market (0.9403). Meanwhile in Africa, it correlated with consumer spending volumes (0.7427). Therefore, globally, cybersecurity emerges as the most significant driver of FinTech growth. More vital protection facilitates a more robust FinTech environment.

Economic Disparities with Cybersecurity: High Income vs Low Income Economies

Economic status also plays a crucial role in shaping FinTech dynamics. High-income countries display pronounced correlations with various factors. Notably, the size of the cybersecurity market (0.6923), consumer electronics market (0.5839), average wage rates (0.6237), and consumer spending volumes (0.6971) are all significantly linked to FinTech growth.

Conversely, low-income economies exhibit no substantial correlations with these factors, highlighting a disparity in FinTech development influenced by financial resources and technological infrastructure.

Middle-income countries show a more nuanced relationship, with FinTech volumes correlating with nominal GDP (0.5373), the cybersecurity market (0.5727), consumer electronics (0.5637), fintech hubs (0.5409), and consumer spending volumes (0.6136). This suggests that while multiple factors impact middle-income countries, cybersecurity remains a vital component.

Quantifiable Cybersecurity Impact on FinTech

Furthermore, another interesting finding was the measurable impact of various factors on FinTech transactions. For example, for every $1 million increase in the global cybersecurity market, FinTech transactions per adult are expected to rise by $31.6. Similarly, a $1 increase in the average hourly wage could boost FinTech transactions by $67.5. The establishment of just one more FinTech hub could increase global FinTech transactions per capita by $839.

Remarkably, as a country’s income grows, the correlation between FinTech growth and two factors—cybersecurity market size and average wage rates—becomes stronger. This means these factors may indeed influence the development of FinTech across a country.

A deeper non-linear analysis further validated the significance of these factors. It revealed that the cybersecurity market is the most influential driver of FinTech growth, with 63% of significance, followed by the average wage rate (13%). As we advance into an increasingly digital future, the investment in and enhancement of cybersecurity will remain a cornerstone of FinTech innovation and expansion.

UnaFinancial Study

The UnaFinancial study considered data from 2022 for 146 countries, which were grouped into four regions: Asia, Europe, Africa and America. The potential factors under consideration included gender ratio, nominal GDP per capita, Internet penetration, cybersecurity market volumes per capita, consumer electronics market volumes, number of FinTech hubs per 100,000 people, average hourly wages, consumer spending per capita, direct investment as a share of GDP, unemployment rates, trade volume relative to GDP, and share of urban population.

The study not only illuminates the integral role of cybersecurity but also provides a roadmap for understanding how various factors interplay to influence the global FinTech landscape. In this digital age, safeguarding financial transactions and technologies is as critical as ever. Moreover, ensuring that FinTech continues to flourish amidst evolving challenges and opportunities.

  • Cybersecurity in FinTech

Digital banking offers increased convenience and accessibility. However, this growth also exposes banks to heightened cybersecurity risks. Protecting data and…

Digital banking offers increased convenience and accessibility. However, this growth also exposes banks to heightened cybersecurity risks. Protecting data and information is crucial to maintaining customer trust and preventing financial loss.

Cybercrime poses a significant threat to the digital banking industry. According to Cybercrime Magazine, cybercrime costs will increase by 15% over the next five years and reach $10.5 trillion by 2025. These attacks target sensitive information and funds, causing substantial damage to banks.

To mitigate these risks, banks must implement robust cybersecurity measures to safeguard digital systems and data.

1. Strong Authentication

The Payment Services Directive (PSD2) mandates strong customer authentication (SCA) to reduce fraud and enhance online payment security. This directive imposes specific requirements on market participants to meet new obligations. The European Banking Authority (EBA) developed regulatory technical standards (RTS) based on the Commission’s authority under PSD2. 

The RTS aims to protect consumers and create a level playing field within the evolving financial technology market. To achieve this, the RTS establishes security measures for payment service providers — including banks and other financial institutions — when processing payments or offering payment-related services. 

2. Encryption

Unencrypted data is a common cyber threat. Hackers can easily access this data type and give severe consequences for banks. According to Statista, the average cost of a data breach worldwide is $4.45 million dollars. However, data breaches not only cause substantial financial loss for recovery and ransom payments but also damage a bank’s reputation.

To prevent these issues, all digital banking data must be encrypted. This safeguards information and makes it difficult for cybercriminals to access even if stolen. Encryption transforms data into a coded format that requires a specific key to decipher. Only individuals with the correct key can view the original data. 

Encryption involves using an algorithm and a key to convert plain data into encrypted data. The original data can only be recovered by decrypting the ciphertext with the correct key.

3. Regular Cybersecurity Audit

A security audit is a thorough examination of an organisation’s IT infrastructure. This process verifies the effectiveness of security policies and procedures. Security audits assess how well an institution’s cybersecurity program operates. This includes reviewing policies, testing controls, and checking compliance with industry standards and regulations.

Banks and financial institutions face increasingly complex cyber threats. Regular security audits help identify vulnerabilities in systems. By discovering weaknesses, banks can strengthen defences with firewalls, antivirus, and antimalware software. A cybersecurity audit should be conducted by an independent expert to ensure objectivity.

4. Employee Training

The World Economic Forum reports that 95% of cyberattacks involve human error. This means hackers often exploit employee mistakes. They use tactics like phishing to deceive employees into revealing sensitive information. This can lead to data breaches and financial loss. For example, employees might click on malicious links, disclose confidential data, or leave devices unattended.

Therefore, bank employees must have training to recognize that cyberattacks are a constant threat. Moreover, the consequences of a breach can be severe for employees, customers, and the bank’s reputation. Cybercriminals operate in a lucrative industry, for that reason, it is imperative to equip employees with the knowledge to safeguard against these threats.

5. Incident Response Planning

An incident response plan is a formal document approved by bank leadership to guide the organisation before, during, and after a potential or confirmed security incident. The plan aims to reduce the impact of security events, limiting operational, financial, and reputational damage.

A successful incident response plan should be established before a security attack occurs and assigned to specific team members. IBM research shows companies with well-developed and tested response plans save an average of $2.66 million compared to those without such protocols. 

To create an effective incident response plan, banks can reference established frameworks. For specific incident handling steps, The National Institute of Standards and Technology’s SP-800-61 and SANS’s Incident Handlers Handbook provide detailed blueprints. Aligning the incident response plan with these resources ensures a focused and effective approach to managing cybersecurity incidents.

Importance of Cybersecurity Measures 

The increasing reliance on digital platforms exposes individuals and organisations to growing cybersecurity risks. Malicious actors exploit security weaknesses to steal personal information and compromise digital assets. Forbes reported a staggering increase in cyberattacks in 2023, impacting over 343 million people, with data breaches soaring by 72 percent from 2021 to 2023. These striking figures highlight the urgent need for state-of-the-art cybersecurity in digital banking.

  • Cybersecurity in FinTech

WatchGuard’s Threat Lab cybersecurity research team forecast headline-stealing hacks involving LLMs, AI-based voice chatbots and VR/MR headsets. They also assess…

WatchGuard’s Threat Lab cybersecurity research team forecast headline-stealing hacks involving LLMs, AI-based voice chatbots and VR/MR headsets. They also assess the impact of the war on talent, AI spear phishing and QR codes.

Watchguard leading on Cybersecurity

WatchGuard Technologies, a global leader in unified cybersecurity, offers an annual batch of predictions covering the most prominent attacks and information security trends that the WatchGuard Threat Lab research team believes will emerge each year. This year, these include malicious prompt engineering tricks targeting large language models (LLMs), managed service providers (MSPs) doubling down on unified security platforms with heavy automation, ‘Vishers’ scaling their malicious operations with AI-based voice chatbots, hacks on modern VR/MR headsets, and more…

“Every new technology trend opens up new attack vectors for cybercriminals,” said Corey Nachreiner, chief security officer at WatchGuard Technologies. “In 2024, the emerging threats targeting companies and individuals will be even more intense, complicated, and difficult to manage. Therefore, with an ongoing cybersecurity skills shortage, the need for MSPs, unified security, and automated platforms to bolster cybersecurity and protect organisations from the ever-evolving threat landscape have never been greater.”

Cybersecurity predictions

The following is a summary of the WatchGuard Threat Lab team’s top cybersecurity predictions for 2024:

Prompt Engineering Tricks Large Language Models (LLMs)

Companies and individuals are experimenting with LLMs to increase operational efficiency. However, threat actors are learning how to exploit LLMs for their own malicious purposes as well. During 2024, the WatchGuard Threat Lab predicts that a smart prompt engineer ‒ whether a criminal attacker or researcher ‒ will crack the code and manipulate an LLM into leaking private data.

MSPs Double Down on Security Services Via Automated Platforms

There are approximately 3.4 million open cybersecurity jobs, and fierce competition for available talent. More SMEs will turn to trusted managed service and security service providers, known as MSPs and MSSPs, to protect them in 2024. To accommodate growing demand and scarce staffing resources, MSPs and MSSPs will double down on unified cybersecurity platforms with heavy automation using artificial AI and Machine Learning.

AI Spear Phishing Tool Sales Boom on the Dark Web

Cybercriminals can already buy tools on the underground that send spam email, automatically craft convincing texts, and scrape the Internet and social media for a particular target’s information and connections. However, a lot of these tools are still manual and require attackers to target one user or group at a time. Well-formatted procedural tasks like these are perfect for automation via AI and machine learning. This makes it likely that AI-powered tools to combat cybersecurity will emerge as best sellers on the dark web in 2024.

AI-Based Vishing Takes Off in 2024

Voice over Internet Protocol (VoIP) and automation technology make it easy to mass dial thousands of numbers. Once a potential victim has been baited onto a call, it still takes a human scammer to reel them in. This system limits the scale of vishing operations. But in 2024 this could change. The combination of convincing deepfake audio and LLMs capable of carrying on conversations with unsuspecting victims will greatly increase the scale and volume of vishing calls. What’s more, they may not even require a human threat actor’s participation.


VR/MR Headsets Allow the Recreation of User Environments

Virtual and mixed reality (VR/MR) headsets are finally beginning to gain mass appeal. However, wherever new and useful technologies emerge, criminal and malicious hackers follow. In 2024, cybersecurity researchers forecast that either a researcher or malicious hacker will find a technique to gather some of the sensor data from VR/MR headsets to recreate the environment users are playing in.


Rampant QR Code Usage Results in a Headline Hack

Quick response (QR) codes provide a convenient way to follow a link with a device such as a mobile phone. They have been around for decades, but mainstream usage has exploded in recent years. Furthermore, Threat Lab cybersecurity analysts expect to see a major, headline-stealing hack in 2024 caused by an employee following a QR code to a malicious destination.

  • Cybersecurity in FinTech

As digital payments continue their rapid ascent, understanding the accompanying cybersecurity challenges has never been more critical. Furthernore, with Statista…

As digital payments continue their rapid ascent, understanding the accompanying cybersecurity challenges has never been more critical. Furthernore, with Statista forecasting a robust 9.52 percent annual growth rate for digital payments from 2024 to 2028, the urgency to address these security concerns intensifies.

While this growth brings unparalleled convenience, it also introduces new security vulnerabilities that must be addressed. Cybersecurity is fundamental in safeguarding confidential data against hacking, fraud, and data breaches. Implementing effective cybersecurity measures can also maintain trust between businesses and clients while preventing financial loss. To optimise cybersecurity, identifying the current threats to digital payment systems is a must for businesses and consumers.

Current Cybersecurity Threats

Digital banks face various threats that continually evolve as technology advances. By addressing these challenges head-on, banks can protect their users and continue the growth of digital payment.

Many types of cyber threats can disrupt digital payment systems:

Phishing attacks: These attacks use deceptive emails, phone calls, or texts to trick victims into revealing personal information, such as login credentials and financial details. The scam can lead to other types of cyber threats.

Malware: Malicious software that infiltrates systems to steal data, monitor activities, or lock accounts. Various forms of malwares have different functions, such as Trojans, Worms, and Spyware.

Man-in-the-Middle (MitM) Attacks: intercept communications between the user and the bank allowing attackers to steal sensitive information or funds.

Data breaches: Unauthorised access to digital bank databases exposes vast amounts of sensitive information, including personal and financial data.

Ransomware: It is an attack that employs malware to infiltrate computer systems to steal data, monitor activities, or lock accounts. The attackers then demand payment and keep disrupting the devices/websites until they are paid.

Credential stuffing: Attackers use stolen usernames and password combinations from other breaches to gain unauthorised access to accounts.

DDoS and DoS attacks: Distributed Denial-of-Service (DDoS) attacks overwhelm the bank’s servers, making online services unavailable to customers. Unlike the Denial-of-Service (DoS) attack where a single source is used to flood the target, DDoS use multiple sources of compromised devices (botnets).

Insider threats: Employees or contractors with access to sensitive information may intentionally or unintentionally cause data breaches or other security incidents.

Social engineering: Manipulating individuals into divulging confidential information through psychological manipulation.

Zero-Day Exploits: Attacks that exploit previously unknown vulnerabilities in software or hardware before patches are available.

Cybersecurity Measures

Encrypting data is essential to convert the personal information into a secure format. This encrypted data can only be accessed with the correct key or description. This ensures that the data remains secure and unreadable after interception.

Multi-Factor Authentication (MFA) adds a layer of security by requiring some form of verification before granting access to the platform. Tokenisation replaces critical payment data with a unique or random token that cannot be hacked once intercepted.

Biometric verification, such as fingerprint and facial recognition, provides additional security by utilising unique physical characteristics. These include the shape of the face and the outline of a fingerprint, both of which are difficult to replicate.

Financial institutions have also innovated to improve cybersecurity by implementing artificial intelligence (AI). For example, JPMorgan Chase has implemented an AI-driven fraud detection system. This application is used for monitoring transaction activity in real-time. It can also detect potential threats or fraudulent transactions using the data analytics tool.

Regulatory Requirements

Financial companies are obligated to meet regulatory compliance. It is important to build customers’ trust and avoid legal or financial penalties. For global financial institutions, regulatory issues might be more complex as each country has its version of rules. As cyber threats evolve, regulators continuously update and enforce these requirements to address new challenges in digital payment systems.

For instance, UK regulations have set strict rules to ensure the security of digital payments. These include data protection measures, and companies that do not prioritise cybersecurity will face substantial fines. Similar regulations have been implemented across European Union (EU) Member States, compelling financial institutions to enhance cybersecurity to create a safe digital payments environment for consumers.

  • Cybersecurity in FinTech
  • Digital Payments

With the growing popularity of digital payments, cybercriminals have found a lucrative target. Cybersecurity data breaches rose sharply by 72%…

With the growing popularity of digital payments, cybercriminals have found a lucrative target. Cybersecurity data breaches rose sharply by 72% in 2023 compared to the previous record-breaking year. This shows the need for financial technology companies to implement strong banking security.

While digital payments offer benefits, businesses must protect themselves and their customers from cyber threats. Understanding the common cyber threats and implementing effective countermeasures are key to long-term success.

The Importance of Cybersecurity for Digital Transactions

With the increasing reliance on online platforms for financial activities, the risk of cyberattacks has grown exponentially. These attacks can lead to significant financial losses, damage to reputation, and erosion of customer trust. From identity theft to data breaches, the consequences of compromised security can be severe.

To prevent such consequences, cybersecurity measures are required for every financial institution. By applying cybersecurity best practices such as encryption, strong authentication, and regular security audits, organisations can protect customer data, prevent fraud, and maintain operational resilience.

Threat Landscape

Cybercriminals employ various tactics to exploit vulnerabilities in digital systems. Phishing attacks, a common method, deceive users into divulging sensitive information through fraudulent emails or websites. Another prevalent threat is ransomware, where cybercriminals encrypt a victim’s data and demand payment for decryption.

Additionally, unauthorised access to accounts through stolen credentials can lead to financial loss. These cyber threats highlight the need for a security framework to protect digital transactions against malicious activities.

Best Practice 1: Encryption

Cybercriminals can easily exploit vulnerable systems, leading to substantial financial losses and reputational damage. A data breach can cost millions of dollars to rectify, including expenses for recovery and ransom payments. A recent IBM report indicates that the average global cost of a data breach exceeds $4.45 million. 

Encryption safeguards sensitive information by transforming it into an unreadable format, accessible only to authorised parties possessing the correct decryption key. This cryptographic process employs complex algorithms and keys to safeguard data integrity and confidentiality.

Best Practice 2: Multi-Factor Authentication

Cybercriminals can easily steal passwords and pins through brute-force attacks, systematically testing numerous combinations until successful. Multi-factor authentication (MFA) offers a robust defence against this threat.

Requiring users to provide multiple forms of identification strengthens account security. This authentication combines different types of verification. This includes information only the user knows, like passwords, items the user possesses, such as security tokens, and unique physical traits, like fingerprints.

By requiring multiple verification steps, banks and financial institutions create a formidable barrier against unauthorised access to sensitive information and funds. Additionally, multi-factor authentication enhances user account management by requiring unique authentication factors for each individual.

Best Practice 3: Employee Training

Organisations with regular cybersecurity training experience a 40% reduction in security incidents compared to those without, according to  This emphasis on employee education is justified as human error remains a primary target for cybercriminals.

Hackers frequently exploit employee vulnerabilities through tactics like phishing, social engineering, and other deceptive methods. By training employees to recognize these threats, financial institutions can mitigate the risk of data breaches and financial losses.

Such incidents can result in substantial financial losses and damage to an institution’s reputation. Consequently, comprehensive cybersecurity training is essential for all bank employees to mitigate these risks.

Best Practice 4: Regular Security Audits

A security audit is an evaluation of an organisation’s digital infrastructure, designed to identify vulnerabilities that could compromise digital transactions. This process involves examining security policies, testing safeguards, and ensuring compliance with industry regulations.

Given the escalating complexity of cyber threats, financial institutions must prioritise regular security audits. Banks can uncover weaknesses before malicious actors exploit them by scrutinising systems and processes.

Regular security audits empower organisations to proactively strengthen defences by implementing essential safeguards such as firewalls, antivirus software, and antimalware solutions. To ensure impartiality and objectivity, it is essential to engage an independent expert to conduct these assessments.

Best Practice 5: Incident Response Planning

As the frequency and sophistication of cyber threats continue to rise, the need for robust defences becomes increasingly critical. Safeguarding digital transactions requires a proactive approach, including a well-defined incident response plan.

An incident response plan is a crucial component of any organisation’s cybersecurity strategy. This formal document outlines strategies for preventing, detecting, and responding to security breaches that could compromise financial data. By establishing clear protocols and assigning specific responsibilities, banks can minimise the impact of cyberattacks and protect both their reputation and customers’ assets.

To be effective, an incident response plan must be established in advance and assigned to specific teams. By following established frameworks, such as those provided by the National Institute of Standards and Technology (NIST) and SANS, organisations can develop comprehensive plans. These resources offer detailed guidance on handling various types of security incidents to ensure a coordinated and efficient response.

Conclusion

Protecting digital transactions requires a multi-faceted approach. Implementing cybersecurity measures is essential for protecting sensitive financial data and maintaining customer trust.

Encryption and multi-factor authentication are foundational elements of a strong security posture. Encryption safeguards data by rendering it unreadable to unauthorised individuals, while multi-factor authentication adds an extra layer of protection by requiring multiple forms of verification. These are just two examples of critical best practices financial institutions should adopt.

Financial institutions must prioritise cybersecurity to maintain customer trust and protect their bottom line. By investing in advanced security measures and staying vigilant against emerging threats, organisations can effectively mitigate risks and ensure the integrity of digital transactions.

  • Cybersecurity in FinTech

From AI to multi-factor authentication, here are 7 cybersecurity solutions keeping financial institutions’ critical data secure.

Data belonging to 20.4 million UK citizens was affected by cyberattacks made against financial institutions at the end of 2023. This represents a 143% increase from the 8.4 million individuals affected in the previous year. The demand for robust cybersecurity is ever-increasing in financial institutions.

Financial Institutions encompass a wide range of businesses dealing with financial and monetary transactions, including banks, insurance companies, and brokerage firms. These institutions are pivotal for a functioning capitalist society, simplifying transactions, enabling individuals and entities to seek investment or lend money, and assisting in managing assets.

The increasingly digitalised nature of the economy, including the rise of online-only financial institutions like challenger banks, has accelerated the development of financial technologies and their adoption in the market. As a result, Software as a Service (SaaS) for finance, such as digital banking, electronic payment, online investment, and other online-based services, makes financial services more accessible to the consumer. But, with the ease of access technologies provided, new challenges have also emerged, especially regarding cybersecurity.    

Financial institutions are enticing targets for cybercriminals. Therefore, cybersecurity has become integral to banking security in protecting data from malicious attacks. 

Here are seven top cybersecurity solutions to secure data from online threats.

1. AI-Powered Threat Detection

The ability for AI models to perform pattern recognition on large amounts of unstructured data is opening up an exciting new frontier in threat detection for cybersecurity teams. AI tools can potentially flag subtle differences, anomalies, and patterns that could point to a zero-day threat or the presence of a bad actor in the system. 

Some industry experts believe that AI-powered threat detection will be pivotal in helping cybersecurity teams respond to rapidly evolving cyberattack strategies that are increasingly difficult to combat — somewhat ironically, this uptick in the frequency and sophistication of attacks is at least partially due to the availability of AI tools, which hackers are also putting to use. 

AI’s adaptive learning and advanced recognition capabilities enable automated responses to threats and can predict future risks by analysing past patterns. This helps reduce false positives and saves security teams time on assessments.

2. Multi-Factor Authentication

Multi-factor authentication has quickly become the standard in security and identity protection as more and more people bank, shop, and administer their lives entirely online. Put simple, it’s a multistep account login in which more information besides username and password must be provided. 

Typically referred to as “something you have, something you know”, multi-factor login procedures drastically reduce account hacking, allowing security teams to detect suspicious activity that occurs in the logging processes. 

3. DDoS Mitigation

Distributed Denial of Service (DDoS) is a coordinated cyberattack that overwhelmingly sends a request to the server simultaneously, which makes the server slow down or even go offline. DDoS mitigation is important for banking service security to prevent the interruption of vital services. 

Cynersecurity teams can perform DDoS mitigation by implementing a load balancer, restricting requests from certain places, and blocking communication from outdated or unused ports, protocols, and applications.

4. Compliance

Compliance is vital to both ensure the security of systems and organisations against cyber attack, but also to prevent legal penalties and repercussions if an organisation is found to be in breach of existing regulations. These regulations ensure that an organisation’s cybersecurity set up is in line with the security and data protection laws in the countries where it operates, with the end goal of mitigating risk to the consumer — or just people in general whose data is collected and kept by the company. 

There can be serious legal and financial risks associated with non-compliance — tied to both finance and cybersecurity. For example, in 2021, Natwest was fined over £264 million by the FCA for its extended failure to identify and prevent money laundering. Since the FCA was established, there has not been a year when its total fines issued have been less than £1 million. In the UK, other financial and cybersecurity compliance regulations are DPA 2018, UK GDPR, NIS regulations, and the Computer Misuse Act 1990.

5. Database Activity Monitoring

Database Activity Monitoring refers to any set of tools that monitors and analyses database activity. The goal of this monitoring is to flag and report deceptive, illegal, or undesired behaviour taking place within a system. Ideally, these tools run and operate without any serious impact on user experience.

Because most databases don’t monitor or flag suspicious activity by default, unless you have a tool that handles activity monitoring, making third party solutions a necessity in many cases. According to monitoring software solutions vendor Cyral, most systems also don’t collect enough data to enable “a full forensic investigation of historical breach events.” Also, databases that do often log and store this information inside the database itself. Any attacker that gains access to the database can then, supposedly, have write access to the full collection of tables (as is often the case), meaning they can easily delete any activity rows associated with their presence and theft of data.

6. SQL Injection Prevention

SQL injection is a code injection technique attackers use to steal, spoof, and manipulate data. An effective SQL injection attack can result in attackers gaining unapproved access to sensitive data like including credit card information, PINs, or other private information. In banking security, a failure to prevent SQL injection can result in attackers altering balances, voiding transactions, and even transferring money to their bank accounts. 

Cyberattackers inject malicious SQL code into the backend of a target system when they discover defenceless user inputs in a web application or web page. The hackers can then use this opening to locate the IDs of other users within the database, impersonating these users — usually those with data privileges such as the database administrator — to run malicious code within the system. 

7. Regular Risk Assessment and Training

Perhaps most importantly, the best defence against the rising tide of cybercrime is a cybersecurity conscious culture. Financial institutions should conduct regular risk assessments manually to identify potential vulnerabilities and threats to their systems and networks. 

They should regularly evaluate and revise systems and networks based on analytics and assessments to prioritise cybersecurity initiatives and protect vital assets. Security teams shouls also conduct periodic security awareness training, which can strengthen cyber-readiness among finance personnel. This is particularly important given the rise in generated AI-driven phishing campaigns and other technologically democratised forms of cyber crime.  

Case Study – Cybercriminals in UK Businesses

An investment article from IFA magazine reported 300,000 cybersecurity breaches in finance institutions across the UK in 2022 alone, making them the second-highest number of data breaches from all industries after the IT sector. Reports estimate losses in the region of £27 billion per year, with small businesses in the UK affected the most by cyberattacks, usually phishing. 

The UK authority encourages its citizens to be more aware of the possibility of cyberattacks, especially phishing and fake charity emails, as online threats are growing exponentially. Ledi Sallilari from the SEO consulting firm Reboot also suggested that more complex passwords can help prevent account breaches. 

The rapid expansion of internet usage brings new challenges for cybersecurity. Proper knowledge and awareness about cyber criminals should become mandatory for all Internet users to protect their online data.

Financial institutions, responsible for managing customer funds, need to implement strong cybersecurity measures. With more secure backend systems, they can protect assets and maintain customer trust in an increasingly digital world.

  • Cybersecurity in FinTech

AI, real-time monitoring, and machine learning are helping fintech firms stay ahead of growing cyber threats.

The financial sector faces a growing threat—cybercrime.

Cybersecurity Ventures predicts a significant rise in cybercrime costs, with the total impact of hacks, breaches, and data theft potentially reaching as high as $10.5 trillion a year by 2025. As attacks become more common and more severe, mitigating these risks and preventing fraud is paramount for financial institutions and financial technology companies alike.

Luckily, ongoing advancements in technology offer fintech organisations a powerful arsenal of weapons to combat cybercrimes. Adaptive fraud prevention systems use artificial intelligence (AI) to detect and prevent fraudulent activity in real-time. These intelligent systems continuously learn from new data, allowing them to identify evolving patterns and improve cybersecurity.

Introduction to cyber fraud protection

Cybersecurity is crucial in the financial services industry, where sensitive financial data and transactions are a prime target for cybercriminals. Moreover, cyber attacks can inflict significant financial losses, not just through direct theft but also via hefty regulatory fines, legal costs, and reputational damage.

Financial institutions have a responsibility to safeguard customer trust by implementing robust cyber fraud protection measures. This includes advanced technologies like network security, intrusion detection systems, and malware protection.

By securing financial transactions and customer data, these measures not only deter cyberattacks but also mitigate their impact, fostering customer confidence in the bank’s security posture.

Common types of Cyber fraud

The financial sector occupies a bull’s-eye for cybercriminals, ranking second only to healthcare in global cybercrime costs according to the IBM Cost of a Data Breach Report 2023. Financial institutions face an average loss of $5.9 million per cyber incident, highlighting the critical need for robust cyber fraud protection measures.

These attacks come in various forms. One of the most common isphishing scams. These are attempts to trick people into surrendering sensitive information. Meanwhile, ransomware attacks aim to disrupt operations or extort money by encrypting critical data. Distributed Denial-of-Service (DDoS) attacks overwhelm systems with traffic, making essential services unavailable to legitimate customers.

Advanced cybersecurity technologies

The fight against cyber fraud necessitates sophisticated tools, and advanced technologies like AI and machine learning (ML) are playing an increasingly crucial role.

AI fraud detection uses ML algorithms to identify fraudulent activities within vast datasets. These algorithms are trained to recognise patterns and anomalies that deviate from typical user behaviour and transaction patterns. Once the patterns are identified, attackers can be purged from the system before they have a chance to steal anything of value. Cybersecurity systems powered by ML can drastically reduce the amount of time bad actors spend inside a system.

ML algorithms excel at identifying patterns and trends that might signal potential fraud. Also, by analysing big data, these algorithms can adapt quickly to evolving fraud tactics.

They can detect and alert security teams within seconds of suspicious behaviour, such as unusual purchases or login attempts from unfamiliar locations. Thanks to continuous data analysis, businesses can gain an immediate advantage, allowing them to swiftly identify and respond to suspicious activity, ultimately minimising potential losses.

Case studies

The financial sector is actively exploring the potential of AI to combat cyber fraud. Mastercard’s Decision Intelligence technology exemplifies this trend. By analysing historical spending habits, this AI solution creates a personalised baseline for each cardholder’s behaviour.

This approach is a significant improvement over traditional, one-size-fits-all methods, which often lead to false declines. AI’s contextual analysis of transactions allows it to bypass common triggers for false positives, ultimately enhancing fraud detection accuracy.

Future prospects

The future of cyber fraud protection hinges on the continued evolution of technology. One promising area lies in adaptive technologies, such as behavioural biometrics. Additionally, these systems move beyond static passwords or fingerprints, creating a unique user profile based on a person’s interaction patterns.

These patterns are ‘behavioural fingerprints’ that include typing style, mouse movements, and even how an individual holds their phone. Over time, the system learns user habits, building a digital identity that can detect deviations indicative of unauthorised access.

This approach is particularly effective because it’s nearly impossible for hackers to replicate one’s unique behavioural traits, even if they steal the password. This adds a crucial layer of security that traditional methods cannot provide.

  • Cybersecurity in FinTech

The digital banking industry faces cybersecurity challenges. A Statista report shows a 10 percent jump in global malware attacks in…

The digital banking industry faces cybersecurity challenges. A Statista report shows a 10 percent jump in global malware attacks in 2023, reaching 6.06 billion incidents.

Cybercriminals are growing more skilled, leading to more frequent data breaches that expose vulnerabilities in banking security. Moreover, effective risk management and strong network protocols are essential to securing digital banking operations.

Introduction to Cybersecurity in digital banking

As online transactions become the norm, strong cybersecurity measures become more crucial. Banks keep sensitive financial data and handle high-value transactions, making them prime cyberattack targets.

Effective cybersecurity is a multi-layered approach. Also, it combines advanced technology, strict policies, and constant monitoring to fight cyber threats. These security measures shield not only a bank’s finances but also customer personal information.

For that reason, cybersecurity is the foundation of trust and reliability in finance. Without strong security protocols, the balance between innovation and managing risk is disrupted, potentially shaking customer confidence in digital banking.

Early Cybersecurity practices

The rise of the internet gave birth to a new genre of malicious activity. Cybercriminals emerged to target this new frontier. They launched worms, malware, and phishing attacks.

In response to these escalating threats, the 1990s saw the introduction of firewalls and antivirus software. Additionally, these early security measures acted as barriers between networks to protect systems from unauthorised access.

Cybercriminals constantly develop new viruses and threats. Likewise, antivirus companies continuously create new software patches and signature updates to stay ahead. Despite that, the possibility of new threats slipping through these defences remains a challenge.

Technological advancements

Fraud is a major challenge for financial institutions. Artificial intelligence (AI) has emerged as a powerful weapon in the fight against this threat.

This technology excels at detecting various types of fraud. AI algorithms can detect suspicious activity in real time, helping prevent fraud before it happens.

AI solutions go beyond simple detection. By creating detailed profiles of each customer and tracking their activities, AI can predict potential risks and prevent fraud proactively.

Current Best Practices

A strong foundation is critical to banking security. This includes constantly checking for weaknesses through risk assessments. Digital banks must update their security protocols regularly to keep pace with changing risks. Collaborations with other financial institutions and government agencies help banks stay informed about the latest threats and how to respond.

Data classification is also essential. Banks need strict controls on who can access sensitive information. Employee security training must be regular to make them aware of threats.

Case Studies

The digital bank Starling Bank partnered with cybersecurity firm HackerOne in 2019. This partnership created a streamlined system for anyone to report weaknesses found in its apps and website.

The initiative initially focused on specific areas and common vulnerabilities. This collaboration revealed valuable insights into weaknesses often missed during standard testing. The project’s findings allowed Starling to develop automated detection tools that proactively prevent security issues.

A report by Statista predicts the global cybersecurity market will hit $271.90 billion in 2029, highlighting the growing need for strong defences in digital banking. While still new, quantum computing presents a future hurdle. Its ability to crack current encryption methods means new, quantum-resistant cryptography needs to be developed for banking security.

However, machine learning and AI are expected to be adopted more widely in cybersecurity. Beyond just reacting to threats, financial institutions will also increasingly focus on proactive threat hunting. This means identifying and stopping potential vulnerabilities before they can be exploited.

  • Cybersecurity in FinTech

The FinTech sector has changed how we manage our money. From mobile banking apps to robo-advisors, FinTech offers a new…

The FinTech sector has changed how we manage our money. From mobile banking apps to robo-advisors, FinTech offers a new level of convenience and efficiency. But with this convenience come challenges and cybersecurity responsibilities: safeguarding the vast amount of sensitive financial data entrusted to these platforms.

Cybersecurity is no longer an afterthought for FinTech companies; it’s an essential foundation for their success. Breaches exposing financial information can have devastating consequences, not just for the companies involved but for their users as well.

Understanding these cyber threats is crucial for FinTech companies aiming to safeguard their operations and customer data. Here are the top 10 cybersecurity risks FinTech firms must be aware of in 2024.

1. Phishing Attacks

Phishing attacks trick people into divulging personal information. Cybercriminals often pose as legitimate companies through emails, texts, or phone calls. They llure victims into clicking malicious links or revealing passwords.

Phishing attacks significantly threaten financial companies because they target the human element rather than technological weaknesses. Hackers impersonate trusted sources like banks or colleagues to trick employees into revealing sensitive information or clicking malicious links. It can lead to data breaches, financial losses, and account takeovers.

2. Ransomware

Ransomware attacks involve cybercriminals holding sensitive data hostage and demanding a ransom from the victim. FinTech companies are particularly vulnerable to ransomware attacks because they rely on digital systems and customer financial data.

These attacks can impair operations, damage reputations, and lead to significant financial losses. They can be devastating, as there is no guarantee that paying the ransom will result in the safe return of the data.

3. Insider Cybersecurity Threats

FinTech companies may face a unique cybersecurity threat from their employees, known as insider threats. These insiders can be malicious, accidentally negligent, or even tricked into compromising sensitive data. Malicious insiders might steal financial information or sabotage systems for personal gain. Negligent insiders could leave data exposed or fall victim to phishing scams, unintentionally giving away access.

4. DDoS Attacks

Distributed Denial of Service (DDoS) attacks overwhelm online systems with traffic, making them inaccessible to legitimate users. FinTech firms are attractive targets for these attacks because they offer multiple entry points (banking systems, online accounts) and prioritise constant service availability.

DDoS attacks can severely hurt a FinTech company’s reputation and finances by causing downtime, raising security concerns among customers, and potentially leading to data breaches during the distraction.

5. Malware

FinTech companies are prime targets for malware attacks, accounting for 19 percent of all attacks and suffering nearly US$18.3 billion in losses in 2017. While the number of traditional banking malware strains is decreasing, it doesn’t represent a decline in overall threat. Instead, attackers are developing more sophisticated malware that uses techniques like obfuscation and slow, staged attacks to bypass antivirus detection.

6. Data Breaches

FinTech companies are under fire due to data breaches exposing sensitive financial information. Hackers exploit security flaws to steal user data, leading to financial losses, identity theft, and damaged trust. To combat this, strong encryption methods like end-to-end encryption and tokenisation can scramble data, making it useless to attackers.

7. Mobile Security Risks

Despite offering convenient access to financial services, mobile apps are a double-edged sword for FinTech companies. These apps are vulnerable due to their popularity, making strong security practices essential. Regular security updates, secure coding from the start, and robust data encryption during transmission are crucial to patching weaknesses.

8. Third-Party Cybersecurity Risks

The reliance on third-party vendors for services and integrations creates a security blind spot for FinTech firms. To address this, thorough vetting through due diligence and vendor risk assessments is crucial before forming partnerships.

9. API Vulnerabilities

FinTech companies rely heavily on Application Programming Interfaces (APIs) to enhance customer interfaces and share information across systems. While APIs are essential for data exchange, they also open doors for cyberattacks.

To fortify their defences, FinTech companies need to focus on secure API design with solid authentication methods (like OAuth or API keys), constant monitoring, and regular security assessments to identify and fix weaknesses before they become exploited.

10. Artificial Intelligence & Machine Learning Risks

The use of artificial intelligence (AI) and machine learning (ML) has increased in FinTech for decision-making processes. While beneficial, these systems also present risks if they make inaccurate decisions based on incorrect data. Rigorous testing and monitoring of AI and ML systems are necessary to minimise these risks.

Steps to mitigate threats

The cybersecurity threats facing FinTech in 2024 are varied and complex. FinTech firms must prioritise cybersecurity to protect customer data and maintain trust. By researching technology usage, training employees on cybersecurity, regularly monitoring suspicious activity, and building advanced security systems, FinTech companies can improve their defences against these evolving threats.

  • Cybersecurity in FinTech

With more financial transactions shifting to digital platforms, having proper cybersecurity measures becomes a priority.

Moreover, data is at the heart of every fintech company, which makes them attractive targets for hackers and malicious actors.

Financial technology has created new opportunities for customers and businesses in the finance industry. Individuals can now borrow, transfer, save, and invest from the convenience of their homes. Also, the growth of the industry is massive, with fintech revenues projected to grow sixfold from $245 billion to $1.5 trillion by 2030.

However, following that growth are security risks associated with it. Accounting services firm BPM predicts that cybersecurity attacks aimed at fintech companies will only continue to grow in 2024 and beyond. Furthermore, these attacks can end in monetary losses, reputational damage, and brand erosion.

To prevent such cases, fintech security leaders globally have implemented cybersecurity measures.

1. Stripe

Founded in 2010 by Patrick and John Collison, Stripe specialises in payment processing software and application programming interfaces (APIs).

Based in South San Francisco, California, the company offers top-tier encryption and secure transmission protocols. The protocols, which adhere to the PCI DSS standards, are in place to ensure the security of credit and debit card data.

Launched in 2018, Stripe’s innovative tool Radar detects and blocks fraudulent transactions. After its 2.0 update in 2018, the company claimed it helped reduce fraud rates by an additional 25% for its users.

With other services like Stripe Terminal, Stripe Tax, and Stripe Capital, Stripe has become a trusted name in online payment processing. It powers payments for major companies like Amazon, Google, and Shopify, all of which demand high-security standards.

2. Square

Owned by Block, Inc., Square was launched in 2009 by CEO Jack Dorsey and co-founder Jim McKelvey. Square offers an all-in-one financial services platform, including customer booking, e-commerce, payroll, shifts, loan financing, and banking.

In 2021, Square received FDIC approval from the Utah Department of Financial Institutions. Additionally, with end-to-end encryption, regular vulnerability assessments, and secure data storage, Square reached Level 1 PCI DSS certification. This is the highest level for payment processor certification.

3. PayPal

Launched in 2000 from the merger of Confinity and X.com, PayPal is a leader in secure online transactions.

Acquired by eBay in 2002, PayPal became the leading global payment application after eBay discontinued its Billpoint service. It has arguably outpaced competitors like Citibank C2IT, Yahoo! PayDirect, and BidPay from Western Union.

PayPal uses advanced encryption technologies and multi-factor authentication to protect user data. With its continuous monitoring and fraud prevention mechanisms, the company is compliant with industry standards.

According to the company, its fraud detection tools are informed by data from 1 billion monthly transactions. It claims that the tool gets smarter with each transaction.

4. Ant Financial (Alipay)

Ant Financial’s Alipay, is the second-largest international payment processor after Visa.

Founded in 2014 by Jack Ma as an affiliate of Alibaba, Ant Financial offers a range of products. Available services include electronic payment processing, banking, and mobile payments through brands like Yu’ebao, Huabei, and Xianghubou.

Ant Financial combines advanced cybersecurity measures such as AI-driven fraud detection, biometric authentication, and data encryption. Alipay itself also holds the internationally recognized ISO/IEC 27001 cybersecurity certification.

Used by more than 1.2 billion users, Ant Financial is protected by its AI-powered risk engine AlphaRisk. With the tool, Alipay’s fraud loss rate has been kept under 0.64 in 10 million, way lower than the industry average.

5. Plaid

Established in 2013 by Zack Perret and William Hockey, Plaid is an embedded financial platform. It facilitates secure online payments and transactions by connecting users’ bank accounts to finance applications.

Plaid ensures authorised access to bank data through secure bank portals, which eliminates the need for user credentials. In October 2020, Plaid introduced “Plaid-Link,” a service that enables real-time payments for loans, insurance, and wages. It securely connects 12,000 US financial institutions, plus many more in Canada, the UK, and Europe.

6. Chime

Founded in 2012 by Chris Britt and Ryan King, Chime partners with regional banks to offer fee-free mobile banking services. Chime uses encryption, access protocols, continuous monitoring, and proactive fraud prevention to keep its payment processes secure.

In April 2020, Chime launched the fee-free overdraft product “SpotMe.” It successfully processed $375 million in Economic Stimulus Payments one week from the scheduled government disbursement.

7. Adyen

Adyen, listed on Euronext Amsterdam, is a Dutch FinTech company founded in 2006 by Arnout Schuijff and Pieter van der Does. Primarily catering to businesses, Adyen offers e-commerce, mobile, and POS payment solutions. The company successfully achieved 1.3 billion euros in revenue in 2022.

Adyen’s cybersecurity measures include encryption, tokenization, secure data storage, and regular security assessments, all backed by Level 1 PCI DSS certification.

8. Sift

Founded in 2011, Sift is one of the cybersecurity companies providing AI-powered fraud platform. It uses machine learning combined with data network scoring 1 trillion events per year to offer security solutions.

The company notices that online fraud is a growing problem, especially for retailers and financial institutions. Therefore, Sift’s algorithm distilled over hundreds of millions of user actions to create fraud pattern recognition tool.

Sift has received several accolades, including being named a leader in 2023 Forrester Wave for Digital Fraud Management and G2’s Momentum Leader in Spring 2024.

9. Darktrace

Cybersecurity company Darktrace, established in 2013, uses AI to respond to cyber threats in real time. Since its inception, the tools it created has been deployed over 9,000 times.

With its Enterprise Immune System technology, Darktrace is able to handle Industrial Operational Technology, email, SaaS, cloud, network, and endpoint safety. More than 9,400 organisations, including major financial institutions, rely on its advanced solutions.

The company was included in The Cyber Award’s AI Product of the Year in 2020 and Fast Company’s top 10 most innovative AI companies for 2022.

10. Netskope

Cloud-based cybersecurity company Netskope was founded in 2012 to help organisations apply zero trust principles. The company’s solutions protect data across cloud services and apps, which makes it pivotal for fintech institutions relying on such technologies.

The California-based firm helps financial services companies meet compliance requirements such as FINRA, PCI-DSS, GLBA, and GDPR. Not only that, it provides necessary protection, such as SWG, CASB, ZTNA, DLP, Cloud Firewall and SD-WAN.

In 2024, Netskope is recognized as a leader in the Gartner Magic Quadrant for Cloud Access Security Brokers (CASBs).

What makes these a success

These top cybersecurity firms in fintech have set high standards in cybersecurity. Their efforts have significantly contributed to a safer digital landscape for fintech.

They have also demonstrated collaboration with fellow financial or cybersecurity experts. Collaboration means having access to specialised knowledge that may not be available in-house. This includes latest threat intelligence, security tools, and tailored audits.

Additionally, it is imperative that companies adhere to industry standards and regulations. Compliance is the first step in building trust with users and stakeholders alike.

With 64% of financial services institutions falling victim to ransomware attacks last year, finance organisations should follow best practices from these companies.

  • Cybersecurity in FinTech

Digital transformation has introduced new challenges in financial cybersecurity.

The banking industry has shifted towards online transactions, leaving behind the days of brick-and-mortar branch visits for check cashing or deposits. As more and more sensitive data is transferred through internet banking technology, ensuring its security becomes paramount.

According to a 2023 survey by the Financial Services Information Sharing and Analysis Centre, 89% of financial institutions are increasing their cybersecurity budgets in 2024. This investment underscores the need for advanced internet banking security measures despite the existence of various security protocols.

In this article, we’ll explore the latest trends in internet banking security, examine real-world cases of cyberattacks, and provide valuable insights into securing your financial institution’s technological infrastructure.

Introduction to Internet Banking Security

As online banking becomes increasingly prevalent, financial institutions must prioritise cybersecurity – implementing specific measures to safeguard their systems and networks from cyberattacks.

Cybersecurity challenges in internet banking are multifaceted. Hackers employ a variety of techniques, including hacking attempts, data breaches, identity theft, malware, and viruses, to gain unauthorised access to sensitive customer data and financial assets.

A successful cyberattack can not only compromise sensitive information but also disrupt critical bank operations, causing significant inconvenience for customers and potentially leading to financial losses.

Common Cybersecurity threats

A 2021 report by IBM highlights the high cost of data breaches in the financial sector, placing it second only to healthcare. This vulnerability stems from the immense value of economic data, which can be exploited for fraud and other cyberattacks.

Beyond data breaches, financial institutions must also be vigilant against ransomware infections, phishing scams, and account takeover attempts. These threats carry the potential for data loss, operational disruption, and significant financial consequences.

In phishing attacks, cybercriminals impersonate bank representatives via emails, calls, or SMS messages. Their objective is to deceive customers into divulging sensitive information such as login credentials or credit card details.

Meanwhile, malware attacks take various forms, including worms, viruses, spyware, ransomware, and Trojans. These malicious programs can infiltrate devices, servers, or networks. If a customer’s infected device connects to the bank’s network, it poses a significant threat to overall financial cybersecurity.

Impact on consumers and banks

Cybersecurity breaches create huge consequences for both consumers and financial institutions. Consumers directly impacted by a breach may find their personal information exposed on the black market, thereby increasing their risk of identity theft.

The impact on banks, however, extends far beyond immediate financial losses from stolen funds. Beyond the initial financial blow, banks face the additional challenge of a potential erosion of customer trust. When customers fear their money is at risk, their confidence in the bank’s ability to protect them diminishes.

Mitigation Strategies

The first line of defense in ensuring robust financial cybersecurity lies within a well-trained workforce. Equipping employees with cybersecurity best practices empowers them to identify potential threats like phishing attempts or suspicious software. Regular training ensures awareness remains high and employees are prepared to act appropriately.

Organisations should also implement comprehensive cybersecurity policies and procedures. These policies should clearly outline acceptable online behaviour, data handling practices, and incident response protocols. Regularly reviewing and updating these policies ensures they remain relevant against evolving cyber threats.

Case Studies

One such case involved a social engineering attack on Experian’s South African office. A cybercriminal impersonated a representative from one of Experian’s clients and tricked an employee into releasing sensitive internal data.

Although Experian downplayed the information’s sensitivity, the South African Banking Risk Information Center reported that the breach affected a staggering 24 million customers and nearly 800,000 businesses. The compromised data eventually surfaced on a dark web forum in 2021. Fortunately, with law enforcement assistance, the data was promptly removed before widespread exploitation occurred.

The second case involves a data breach at Flagstar Bank, a major US financial institution. In 2022, the bank suffered a significant breach exposing the social security numbers of nearly 1.5 million customers. While Flagstar initiated incident response protocols and stated no evidence of data exploitation, they still advised customers to closely monitor their credit and promptly report any suspicious activity.

The cybersecurity landscape for banks is constantly shifting, demanding ongoing vigilance and adaptation. Advanced persistent threats (APTs) remain a major concern, as these actors employ sophisticated techniques to infiltrate networks and steal sensitive data.

Furthermore, the growing number of Internet of Things (IoT) devices introduces new vulnerabilities, potentially leading to large-scale breaches and botnet attacks. Emerging technologies like AI and quantum computing pose further challenges. 

While these technologies hold promise for enhancing security, they could also be exploited by malicious actors to launch more potent cyberattacks. Therefore, staying ahead of the evolving threat landscape will be a key focus for the future of cybersecurity in banking.

  • Cybersecurity in FinTech

Because digital banking involves sensitive personal and financial information, it has unique cybersecurity needs to protect against hackers and fraud.

Cybersecurity is a vital component of digital banking. Customers need to trust systems to manage their money online through apps or websites, without visiting a physical bank. This offers convenience, allowing users to check balances, transfer money, pay bills, and even apply for loans from their computers or smartphones.

Because digital banking involves sensitive personal and financial information, it has unique cybersecurity needs to protect against hackers and fraud. One key security measure is encryption, which scrambles data so that only authorised users can read it.

Another important measure is two-factor authentication, which requires users to provide two forms of identification, such as a password and a code sent to their phone, to access their accounts. These measures help ensure that digital banking remains safe and secure for users.

Cybersecurity Risks and Preventative Measures

One of the biggest concerns in the banking industry today is the security of mobile banking apps. As more people use these apps for financial transactions, weak security measures can make them vulnerable to hacks.

Additionally, banks face threats from third-party organisations, as hackers often target less secure shared banking systems. Third-party networks cab also be hijacked to gain unauthorised access. The growing field of cryptocurrency also presents new cyber threats… The unstable nature of cryptocurrency and limited understanding of securing these digital assets make them attractive targets for cybercriminals.

To protect against cyber attacks, banks are implementing various preventative measures. Conducting thorough security audits helps find system weaknesses. Setting up strong firewalls while updating antivirus and anti-malware software creates a solid defence against cyber threats. Multi-factor authentication (MFA) and biometrics add extra security layers, making it harder for unauthorised users to access accounts.

Automatic logout features end user sessions after inactivity. Meanwhile, banks are educating customers about secure practices like avoiding public Wi-Fi for banking and regularly updating passwords. These combined efforts enhance the overall cybersecurity of the banking sector.

The Importance of Regulatory Compliance

Regulatory compliance is crucial in digital banking cybersecurity for several reasons. First, it ensures the protection of customer data. Regulatory standards include guidelines that help banks protect sensitive information. This reduces the risk of data breaches and identity theft. Compliance also builds and maintains customer trust. When customers know that a bank follows security standards, they feel more confident about the safety of their financial information.

Following regulations helps banks avoid legal problems, including fines and sanctions, which can be costly and harm their reputation. Regulations provide a framework for consistent security practices across the industry. This ensures all banks meet a basic level of security to prevent gaps that hackers might exploit. Additionally, compliance requires banks to conduct regular risk assessments and audits, helping to identify weaknesses and strengthen their cybersecurity measures.

Regulatory compliance also ensures that banks are prepared to maintain operations and protect customer data, even during cyber attacks or other disruptions. This includes having disaster recovery and business continuity plans in place.

Lastly, compliance can drive innovation by encouraging banks to adopt new technologies and practices that enhance security. This proactive approach helps banks stay ahead of emerging threats and continuously improve their cybersecurity measures.

Case Study: Revolut

Revolut is known for its strong cybersecurity measures. The bank uses advanced encryption to ensure that data shared between users and the bank is secure, protecting personal details, transaction histories, and account balances from being intercepted by hackers.

Additionally, Revolut requires users to enable two-factor authentication (2FA), adding an extra layer of security by requiring a second form of verification, such as a code sent to their phone. The bank also employs biometric verification, such as fingerprint or facial recognition, to further secure user accounts.

Revolut also uses machine learning to detect and prevent fraudulent activities in real-time, ensuring that suspicious transactions are quickly identified and blocked.

Case Study: Chime

Chime is another digital bank that prioritises cybersecurity. Chime protects user data through encryption, ensuring that communication channels are secure. The bank also offers two-factor authentication to enhance account security, requiring users to verify their identity with a second form of verification.

Chime provides real-time transaction alerts, notifying users of any account activity immediately. This allows users to quickly identify and respond to any suspicious transactions. Additionally, Chime employs measures such as automatic logout after periods of inactivity to prevent unauthorised access. These security features help Chime maintain a secure banking environment for its users.

Looking ahead, cybersecurity trends in digital banking are likely to focus on several key areas to stay ahead of emerging threats. One trend could involve increased adoption of artificial intelligence (AI) and machine learning to enhance threat detection and response capabilities. AI can analyse vast amounts of data in real-time to identify unusual patterns or behaviors that may indicate potential security breaches.

Staying ahead of cybersecurity threats requires a combination of technological innovation, proactive defense strategies, and ongoing education. Digital banks that prioritise cybersecurity and adapt to these future trends will be better equipped to protect their customers’ data and maintain trust in an increasingly digital banking landscape.

  • Cybersecurity in FinTech

Increasing digitalisation is making financial services cybersecurity a crucial issue for banking technology.

Here are the most trends that affect it the most:

A growing reliance on banking technology as the industry digitalises has naturally brought both cybersecurity and financial services security into the limelight.

Digitalization will always come with cyber risks, and financial services will always come with security concerns. Banking is among the industries most vulnerable to cyber threats. A lack of financial services security is a gap cybercriminals can exploit, especially as banking goes through a digital transformation. 

Financial companies face much more challenging cyber threats in 2024. Cyber risks boomed as the world shifted online during the Covid-19 pandemic. This trend is getting amplified by the implementation of AI in financial services, as well as the proliferation of AI-enabled cyber-criminality broadly.

This period of innovation is creating a greater array of possible vulnerabilities for criminal groups to exploit  – a much bigger attack surface.

This extends to much bolder targets – the International Monetary Fund (IMF) said in March it was hit by a cyber attack. This is happening worldwide and continues the trend established last year, with Indonesia’s State Cyber Agency (BSSN) recording 350 million cyberattacks occurred in 2023. That includes a ransomware attack on its National Data Centre (PDN).

In previous years, the banking technology security system was linear. In an era with hundreds of interconnected devices, banks have a much more complex challenge to keep their networks secure. Cyber risks are intense and varied, including data breaches, Botnets, and DDoS attacks.

These attacks will hit consumer financial services, through temporary outages, the theft of personal data, and impacting company performance assessments.

Cyber security, biometric security to access financial transaction. Businessman use fingerprint scanning online connect to investment platform global network connecting, financial technology.

Trend 1: AI in Cybersecurity

Artificial intelligence (AI) technology has already created huge changes in business behaviour. It has also encouraged a shift from reactive to proactive approaches in detecting cyber-attack patterns.

As businesses are forced to respond to the widespread arrival of this revolutionary technology.

A simple example of threat increases due to AI is the use of generative AI to increase phishing attacks. It is easier to generate a lot more spam than it was before.

A better piece of news is that AI also brings more precision to recognizing cyber-attack patterns. Machine-learning can study cyber threats in depth and both identify them and identify vulnerabilities in financial services security, This ultimately helps fast and effective responses to evolving cyber threats.

Trend 2: Zero Trust Architecture

The “Zero Trust” security model will continue to evolve. This is where every user and devices is considered untrustworthy by default, until proven otherwise.

That means that testing and validation processes will apply for every user or device login. This approach helps mitigate the risk of internal and external threats.

Basically, every user and device has to continually verify that they are legitimate.

Trend 3: Cloud Security:

An increase in cloud adoption through 2024 will also mean a corresponding growth in cloud security solutions.

More integrated cloud security solutions are a natural part of protecting the cloud environment. They are also an important facet of banking technology security strategy, and will continue to be.

Trend 4: Blockchain-based Security

Adopting blockchain technology as a security solution will help ensure data integrity and transparency.

Blockchain effectively shuts off the tap for interference in the creation of the data records that underpin a given process. The lock security system will ensure optimal protection from unauthorised changes.

Trend 5: Increasing Mobile Security

Mobile devices are now an important player in digital financial transactions. That’s why financial services security is also focused on enhancing stronger mobile security.

Banking technology platforms are designed with strong encryption protocols. These will ensure data sent between devices is protected from unauthorised access. That includes bringing multi-factor authentication features, biometrics, and passcodes.

Trend 6: Biometric Authentication

As above, verifying the individual at the point of digital contact is a storing guaerantee of authenticity.

Authentication methods liike facial recognition and fingerprint scanning offer stronger security. This includes multi-modal biometric authentication that is also used to prevent forgery. There are banking apps that require occasional video recordings to authenticate by appearance and voice recognition to approve large transactions.

Trend 7: Changes in Privacy and Data Protection Regulations

Privacy rule changes will continue to evolve following as data protection requirements get stricter.

Banking companies will also follow global regulations that focus on consumer data privacy. Their clients will also have higher expectations of data security.

Trend 8: IoT Cybersecurity

The IoT (Internet of Things) ecosystem requires better security standards and device management in general.

Because IoT functions through the connection of physical infrastructure with the digital realm, penetrations of that infrastructure – especially through physical devices, require tough security measures.

Reducing the risks associated with unsecured IoT devices will be such a widespread trend that financial services security can rely on a huge body of evidence and best practice to control what attack surface is presented,

Trend 9: 5G Network Cybersecurity

The launch of 5G networks worldwide bring with them the network security expectations that any major shift in networking will create.

That  requires an emphasis on network security. Faster network speeds with lower latency creates new challenges that need to be solved. For financial services security, protecting IoT devices connected to the 5G network, ensuring infrastructure support, and mitigating the risk of vulnerabilities appearing where network breaks happen during authentication procedures are all areas of concern.

Trend 10: Cyber ​​Insurance

The cyber insurance market will see significant growth in the future.

Because cybersecurity threats evolve so quickly, assessing how to insure for will require totally new approaches across Insurtech, client-side decisions, and consumer protection.

This falls neatly into concert with the need for financial protection from cyber threats. Insurance will adjust to banking technology risks and the changing compliance environment that maintaining financial service security will now require.

Conclusion

Cybersecurity trends encourage banks to improve their security architecture. Old methods used to secure banking technology systems will most likely be ineffective as the demands on banking technology to evolve are inescapable.

Financial companies will need better financial services security capabilities – but they will be able to get them.  The industry will respond with more sophisticated security solutions to the increasing threat from cyberspace.

  • Cybersecurity in FinTech

Welcome to the latest issue of CEOstrategy where we highlight the challenges and opportunities that come with ‘the’ leadership role

Our cover story focuses on the work of Nigel Vaz, the CEO of Publicis Sapient – a digital business transformation company that partners with organisations globally to help them create and sustain competitive advantage – and his approach to change management.

Welcome to the latest issue of CEOstrategy!

Tasked with accelerating business growth, while building the synergies across an organisation that can drive innovation to meet diverse customer needs and keep revenues on track, the modern CEO must be mentor, marshall and motivator on the journey to success.

Read the latest issue here!

Publicis Sapient: Advice for the modern CEO

“I lead Publicis Sapient with a set of principles to keep me on track, and which I offer to fellow CEOs as a guide,” says CEO Nigel Vaz. “Embrace change, and view challenges as opportunities for growth and innovation; Foster a culture of continuous learning within yourself and your organisation; Advance the organisational capabilities that will enable your company to deliver on your brand promise; Adopt a data-driven approach to decision-making, utilising analytics and advanced technologies and Stay rooted in purpose to realise your competitive advantage.”

EMCS: Leading a small fish making a big impact

“If you look after your people and you have the right people in place, the customer experience takes care of itself,” explains EMCS Industries CEO Trevor Tasker. “A lot of entrepreneurs say the same, but you don’t always see it in action. If I have to micromanage somebody, I’ve made a hiring mistake. When I’ve found the right person, all I have to do is support them and trust them. If I can’t trust them, I can’t lead them. And being trusted makes my employees so much better at their jobs. It makes choosing the customers you deal with very important as well…”

Moneypenny: People at the heart

We are consistently listed in the best places to work rankings and have created a happy and fun working environment,” says Moneypenny CEO Joanna Swash. “We strive to be authentic, and that starts at the top. If the leadership team walks the walk and talks the talk, then trust is built. Trust fosters a culture where employees are motivated, engaged and empowered with a culture of transparency and honesty…”

Bupa: Choice, care and compassion driving digital transformation

“In a fast-changing world, it’s essential that we harness the power of technology to keep improving health outcomes for our customers,” says Global & UK CEO Carlos Jaureguizar of the digital transformation journey helping Bupa become the world’s most customer-centric healthcare company. “We give our people the tools to give customers the best care, streamline the customer experience and drive innovation.”

Also in this issue, we hear from Rachel Youngman, Deputy CEO at the Institute of Physics, on how organisations can leverage ESG targets to meet the Net Zero challenge; we get the lowdown on a fintech success story from RTGS.global CEO Jarrad Hubble; discover the importance of Strategic Thinking with Institute for Management Development Professor Michael Watkins and count down ten reasons why integrity is key to business success with Serenity In Leadership CEO Thom Dennis.

Enjoy the issue!

Dan Brightmore, Editor

This issue’s Big Question explores whether procurement would be better prepared should a similar situation occur.

COVID-19 affected everyone in different ways.

It caused death, illness, chaos and disruption the world over. It shut down airports, overwhelmed the NHS and left our streets empty. With March 2024 marking four years since the UK announced its first national lockdown, how ready would procurement and our supply chains be in the event of a similar scale this time around? 

To go forward, unfortunately, we must look at the chain of events last time around.

Having been declared a global pandemic on 12th March 2020 and with cases of coronavirus accelerating to uncontrollable levels, many businesses’ supply chains collapsed. When the pandemic hit, businesses were left footing the bill for billions of pounds worth of unsold goods, causing inventory-to-sales ratios to rise high.

As a result of lockdowns, organisations were left with no choice but to cut their activity or shut down entirely for a brief period as guidance continued to change at little to no notice. As such, production was halted in factories across the world causing mass layoffs and redundancies across the majority of industries, particularly in manufacturing and logistics, resulting in a reduction in shipping which affected delivery times globally. 

Consumer demands also shifted significantly. The demand for personal protective equipment (PPE) as well as the likes of toilet paper and pasta rose dramatically. There was an increase in office furniture amid a surge in demand in remote working. This, alongside the likes of government help such as furlough, helped enable a surge in demand for e-commerce as consumers bought online in record numbers. The shift in demand for goods led to a reduction in experiences such as attending events, eating at restaurants or going out to pubs.

In order to meet this increase in demand, factories pumped out goods quicker than ports could handle them. US ports were full of exports from Asia with too small of a workforce to unload them and too few truck drivers to transport the goods. While ports were full, compounding the issue was a labour shortage, especially truck drivers. And talent remains a concern to this day to procurement and supply chain.

But COVID-19 is only one of procurement’s fires. There’s been the Suez Canal disaster, wars in Ukraine and Israel and inflation concerns to contend with too.

So if the worst were to happen and another ‘black swan’ event was to take place, what lessons has procurement learned? 

Jack Macfarlane, Founder and CEO, DeepStream

As a result of the generative AI boom, Jack Macfarlane, Founder and CEO, DeepStream, believes that  the industry is in a much stronger position to overcome a future pandemic. “It proved that procurement needed to brush up on its ability to adjust to black swan events swiftly by investing in the right technology and training for the industry to respond to sudden challenges and changes,” explains Macfarlane. “With the growing use of generative AI, the industry is now in a much stronger position to contend with a future pandemic. Generative AI can scrape vast datasets regarding global trends, using the data to predict shortages, price fluctuations and supplier risks before they happen. 

“Regardless of the industry you’re in, procurement leaders should always focus on ensuring the right policies are in place to prevent declining quality control in a future black swan event.” 

Omer Abdullah, Co-Founder and Chief Commercial Officer at The Smart Cube

Omer Abdullah, Co-Founder and Chief Commercial Officer at The Smart Cube, agrees that procurement finds itself in a more secure place than that of four years ago. “Procurement is undoubtedly readier than it was prior to the COVID-19 pandemic. CPOs and their teams have learned where potential value drivers are, and they also understand supplier relationships and supply chain intricacies more intimately,” he reveals. “Procurement has also moved further along the digital spectrum. Organisations have tools at their disposal to operate effectively, and on a dispersed basis, should a similar event take place. Additionally, there are now far more risk management solutions in place versus before the pandemic – allowing practitioners to identify problems, and potentially risky situations, before they arise. Add to this more diversified supply chains and established alternative sources for essential categories, and the function is far more prepared than pre-2020.”

However, Abdullah went on to explain that while “no one would be absolutely ready for another unexpected pandemic”, he insists the industry did learn lessons from COVID-19. “It must be noted that there’s still a recency effect at play – procurement professionals tangibly remember the pandemic’s impact,” he explains. “As time progresses, though, this may change but for now, the industry knows how to operate if a comparable scenario were to unfold soon.”

Bindiya Vakil, CEO and founder of Resilinc

Bindiya Vakil, CEO and founder of Resilinc, believes the pandemic has showcased how better prepared companies are for the next global disruption. “Fortunately, the COVID-19 pandemic taught businesses some valuable lessons. Not nearly as many companies are flying blind in the face of disruption,” explains Vakil. “Many organisations learned that having visibility into their entire supplier network is the foundation for mitigating disruptions. Mapping their supply chain down to the part-site level and then using AI-powered technology to monitor it 24/7 for potential threats gives procurement leaders an early-warning system with actionable insights to make mitigation plans within hours.”

Vel Dhinagaravel, CEO and President Beroe Inc

While Vel Dhinagaravel, CEO and President Beroe Inc, reveals that COVID-19 “took the mask off” procurement and exposed the true character of teams. “Some were much more partnership-oriented and some a lot less. Some of these memories endure and will either help or handicap their responses to future disruptive events,” Dhinagaravel reveals. “During 2020-2022 as different countries and regions were in varied states of lockdown there were tremendous constraints on supply chains. As a result, procurement got an opportunity to be part of discussions around product mix optimisation and product pricing which previously had been largely off limits to them.”

He adds that while the future is uncertain, he believes the function is in a healthier position to thrive should the worst happen again. “Post-pandemic, these relationships have endured, and we have also seen these teams consciously building agility and resilience into their operating models and supply chain,” he discusses. “They’ve been using data and analytics as key levers to get visibility of their supply chain and suppliers – identifying points of failure, assessing scenarios, and proactively running simulations to develop diversification strategies. While these actions don’t give procurement a crystal ball to predict the next disruptive event, it puts them in a much better position to be able to handle another pandemic or major supply chain shock.”

Betsy Pancik, Senior Vice President at Proxima

And Betsy Pancik, Senior Vice President at Proxima, says that the pandemic was procurement’s “time to shine” with business leaders recognising the importance of a robust procurement function to keep business running smoothly. “COVID-19 caused major supply shortages, which drove price surges and quality issues – many procurement teams had to quickly mobilise capability and capacity to support immediate business needs,” she explains.

“Some companies learned this the hard way by not having the right processes and teams in place, which led to insufficient inventory, spend increases, and strained supplier relationships. Many companies realised the need for alternative suppliers to prevent these issues in the future and started proactively seeking additional sources of supply. Others realised the need for emergency buying procedures, systems, and processes that enable quick action, automated buying, supply chain visibility, and investment in talent – all of which will help businesses respond in a more organised and robust way if a similar situation were to happen again.”

In truth, procurement teams learned a lot from the events of March 2020. Procurement and supply chains can’t be complacent. The function can’t afford to let the mistakes of the past define its future. Supply chains must have alternative methods of supply and Chief Procurement Officers must be agile and ready to respond. Procurement can’t drop the ball and must stay ready. 

As procurement becomes more important, digitally-driven, and strategic, so has the role of the Chief Procurement Officer.

15 years ago, the Chief Technology Officer role rarely appeared on a roll call of the C-suite outside Silicon Valley. If you weren’t a tech company, you had a “head of IT” or even just an “IT guy”. Now, “every company is a technology company”, and every boardroom has a CTO. (And a Chief Information Officer, and a Chief Security Officer, and probable a Chief Digital Transformation Officer, and so on).

As technology has changed the way that we do business at a near-molecular level, so too has it changed the roles of the leaders overseeing it. No longer can you have someone in your C-suite who is technologically illiterate, just like you can no longer be a tech genius without at least a little flair for business. As the role has become more integral, it has become more strategic, and the demands placed upon executives and employees have changed.

That’s all ancient history, but history repeats itself. The same thing is happening to procurement right now.

In the last several years, the procurement function has started to show genuine signs of transformation from what David Ingram, CPO for Unilever, calls a “insular, contract-and-process-heavy organisation to a wider, more insightful function that is connected to what is happening in the broader market.”

Hervé Le Faou, CPO at Heineken, goes further, stating that “Fundamentally, the CPO is evolving into a ‘chief value officer,’ a partner and co-leader to the CEO who is able to generate value through business partnering, digital and technology, and sustainability, which are new sources of profitable growth in a shift toward a future-proof business model.”

A white paper from AI procurement company Zycus points out that the role of CPO has grown to include new duties, and preexisting duties have become more important in an increasingly fast-moving, easily-disrupted business landscape. “Today, CPOs are responsible for compliance. They play an active role in merger & acquisitions and participate in strategic initiatives. This is in addition to handling supply risk management, environmental responsibility, as well as the traditional job of ensuring cost-efficiency,” the report’s authors note. “Hence, it comes as no surprise that some companies have started inducting CPOs into the board of directors. In many others, the employee- hierarchies are undergoing a change, with procurement function reporting directly into the C-level executives or the board. The CPOs of today enjoy greater autonomy and improved control over budgets than before.”

As a result, the role of CPO has transformed from a tactical, functional one to something broader, more strategic, and typically more autonomous.

By Harry Menear

Coupa Software and Acquis Consulting Group has released an eBook offering tips on how to navigate the challenges of the procurement landscape.

A new eBook from Coupa Software and Acquis Consulting Group providing guidance on how to navigate the challenges of the procurement landscape has been released.

The eBook offers real-life success stories from the likes of Dent Wizard, Sun River Healthcare and Eyecare Partners while uncovering essential strategies for enhancing efficiency and driving growth.

Additionally, the eBook provides expert guidance on mastering procurement and compliance in today’s economic landscape as today’s leaders are forced to re-examine their internal processes, particularly when it comes to business spend management.

As a result of rising inflation, as well as the cost of capital and labour, it has meant businesses need to identify new ways to improve margins, drive sustainable growth and scale productivity. However, many existing solutions at mid-market companies are already stretched to the limit.

This led to Dent Wizard, Sun River Healthcare and Eyecare Partners coming to the same conclusion – digital transformation can take painful and antiquated processes and make them stress-free and efficient.

The new eBook is considered a must-read for leaders seeking to overcome the complexities of today’s procurement space amid a challenging economic climate.

To find out more about how Dent Wizard, Sun River Healthcare and Eyecare Partners recommend organisations can transform their business spend management, download Coupa and Acquis’s free eBook here.

Kathleen Anne Harmeston discusses some of the key items sitting on the 2024 agenda amid seismic digital transformation.

Procurement, in my opinion, has experienced one of the largest direct knock-on effects of unprecedented inflation and geopolitical issues over the last two years (including supply-chain issues caused by Brexit, the US-China Trade War, and European instability of the Russia-Ukraine War).

Procurement’s challenges

We are seeing this impact in the form of cost increases across nearly all industries and challenges in securing and maintaining reliable, dynamic, and cost-effective supply partners.

Boardrooms are struggling to understand why they should invest further funds to bolster the CPO remit, including investment to help them technologically revolutionise the business and the function. Possibly this is due to a lack of visibility on how procurement can be a high performing business partner, which offers a proactive, seamless, automated and value-adding service supporting profitability and ESG efforts. CPOs are now tasked to sell the benefits of investing in procurement over and above the safety blanket of ‘cost reduction’ as the signature sell.

The above obstacles will also be underpinned by the phenomenal opportunity of integrating AI into the procurement function alongside many other digitisation opportunities. Those companies who welcome technological innovation of their P2P systems and supplier management processes are likely to have better competitive advantage and risk management as a consequence.

Kathleen Anne Harmeston

CPO’s five key items on the 2024 agenda

The general consensus I have gained from speaking with my peers are:-

  1. Profitability (of course).
  2. Agility and digital readiness within the P2P and business management systems.
  3. Delivering ESG for the firm and not just  giving  “lip service” to the exercise.
  4. Risk management within the elaborate complex web of supply chain networks.
  5. Driving Innovation through the supply chain.

2023 saw the same old issues in limited control over and transparency in third-party spend. This was due to supply instability, semi manual processes, rising costs and value leakage from off-contract spend.  With this in mind, boardrooms are more likely than ever to push back on the CPOs call for further investment. But this creates a circular argument of investment needed in the function, combined with business’ commitment to approved supplier compliance to meet the board challenges in 2024. 

Moving to 2024

Digital readiness has become imperative as team members continue to work in hybrid or remote ways, but also because inefficient manual processes and limited digital visibility and automation of spend management causes significant lost opportunity and risk. Recent studies from KPMG and SAP show that 37% of procurement processes are still semi auto and manual and 77% of Executives complain they cannot access a good spend data real time. These studies have been further supported by research from Ivalua which states:

  • 53% of procurement and supplier management processes have yet to be digitised.
  • 22% of procurement teams estimate that they are wasting their time each year dealing with paper-based or manual processes.
  • 50% of procurement leaders think the rate of digitisation within procurement is too slow.
  • 47% say existing procurement systems are not flexible enough to keep up with constant change and market uncertainty. 

Inefficient procurement processes often result in disorganised data management and reporting -ultimately leading to executive frustration. These issues further invite problems such as duplication of payments or delays in payment.

What are the technological innovations for 2024?

The shape and structure of the procurement division in the future will change quite dramatically with the ever-increasing integration of AI. When the second wave of more sophisticated generative AI software arrives – which improves its reliability of output, data leakage, and data security – AI and machine learning may well plug the gap of manual human input for certain portions of the procurement division. With AI (or any kind of automatic digitization for that matter) we will soon embrace the automation and celebrate the headcount savings in procurement, and instead ask for investment in greater strategic skills and the next level of development for our procurement staff.

AI truly has the potential to transform procurement. From specifically supply chain management, to helping with demand forecasting and inventory management to logistics optimisation, new product development cycle time improvement, and supplier engagement. AI will also help with managing our spend via creating predictive reports for cost reduction opportunities.

Specifics for CPOs look for in 2024

Advanced AP Invoice Automation Platforms

Advanced accounts payable invoice automation platforms process invoices in any format with good speed and accuracy. It means going touchless eliminates the pain of managing paper invoices. By reducing the cost per invoice, shortening cycle times, and increasing spend control, these cloud-based electronic invoicing systems offer built-in matching and automatically identify errors, duplicates, and overpayments. They ensure payments are only made for ordered and received goods. Many APIA platforms can be tailored to specific organisational needs. This is with features like cognitive OCR invoice capture, smart coding, and invoice approvals to further streamline the process. These platforms can integrate with existing financial or ERP systems for seamless digital payments. While their advanced features like duplicate invoices and fraud checks, along with integrated exception handling, demonstrate the future of invoice processing in the P2P cycle.

Mobile P2P solutions

Mobile platforms are becoming more useful and available in the P2P process by shifting to cloud and software-as-a-service (SaaS) solutions. The convenience of mobile apps allows users to manage procurement activities on the go. This is also while offering real-time access to crucial data and processes. This mobility not only increases efficiency but also enables quicker decision-making. CPOs can also integrate their P2P systems with other cloud-based applications, such as ERP, CRM, and BI, to create a seamless and holistic view of your procurement performance.

Data analytics and visualisation

Data analytics tools are the applications that enable you to analyse your P2P data in an actionable way. These tools will help you improve your decision making, performance measurement, and reporting. For example, you can use dashboards, charts, and graphs to visualize your spend patterns, savings achievements, and compliance levels. You can also use predictive analytics, machine learning, and natural language processing to generate forecasts for your P2P strategies. Visualisation software has also made huge strides in being able to share new product development ideas. This is also while helping progress the supplier collaboration and management agenda.

Integration of blockchain for greater transparency and security

Blockchain technology is rapidly transforming the P2P sector with its unparalleled transparency and enhanced security features. By integrating blockchain, businesses are able to establish immutable records for every transaction. This will significantly boosting both transparency and security within their procurement processes. This technology is particularly effective in fraud prevention and compliance adherence and supply chain tracking.  It ensures that each transaction is reliably recorded and easily verifiable, underscoring its growing importance in the P2P landscape.

Supplier collaboration

Supplier collaboration is the practice of building long-term and mutually beneficial relationships with your key suppliers, based on trust, transparency, and value creation. It can help you improve your supplier performance, reduce risks, and drive innovation. For example, you can use supplier portals, e-procurement platforms, and digital contracts to communicate with your suppliers more effectively. You can also use supplier scorecards, feedback mechanisms, and incentives to monitor and reward your suppliers for their performance.

Sustainability and social responsibility

Global supply chains are complex and can be multi-tiered. This presents a serious challenge for CPOs with limited visibility into the supply chains for sustainability and social responsibility.  AI-powered reporting will enable teams to keep track of supplier and product information. This is via using global data sources from different countries, regions and languages. The key is to raise the issues and gain the sponsorship to address the risks proactively. Mapping systems and technology can help but only if this policy is embedded within the business. There is movement from tier one contract management of supply chains to managing the supplier networks.

User experience and engagement

User experience and engagement with your P2P system, such as ease of use, functionality, design, and feedback is important for the function. Alongside engagement, it can help you increase your user adoption, satisfaction, and loyalty. For example, you can use mobile apps, chatbots, voice assistants, and gamification to make your P2P system more accessible, intuitive, responsive, and fun.

Concluding remarks

The P2P landscape in 2024 will be shaped by technological advancements and a shift in business priorities. From the integration of AI and blockchain to the emphasis on sustainability and mobile solutions, these trends are redefining how companies approach procurement and supplier relationships. Despite executive reluctance to engage in further investment, during periods of inflation and market stagnancy, digitisation must be embraced with the option to either pivot or perish. Adoption of new systems and processes requires training and capacity planning within procurement departments. This is so that the business-as-usual services can continue without a downturn in service levels. Businesses that adapt to these changes will enhance their operational efficiency and position themselves strategically for future growth and success.

By Kathleen Anne Harmeston, CEO, CXO, Director, Advisor, C Suite Coach

CPOstrategy’s cover story this month features a fascinating discussion with Rick Sisk, Director of Procurement at Gen4 Dental

CPOstrategy’s cover story this month features a fascinating discussion with Rick Sisk, Director of Procurement at Gen4 Dental, who explains how he’s revolutionising procurement for the dental industry, and why doctor-led care is so important…

Read the new issue here!

Gen4Dental: Changing the procurement landscape for dentistry 

Gen4 Dental is an organisation that strives to be a true partner to dental practices. It is a truly dentist-first DSO, promoting excellence at every level and working to improve by at least one percent every day. Through mergers and acquisitions, the organisation is also growing at an incredible rate, and this expansion and ambition requires a sturdy procurement department to support it. Enter: Rick Sisk, Director of Procurement at Gen4.

Prior to Sisk joining Gen4 Dental, the procurement landscape certainly wasn’t what it is today. The organisation has grown so quickly in its short lifetime; Sisk says that Gen4 has expanded so rapidly in a way that had the potential to cause problems. “When I came in, there was no real purchasing platform. I called my industry friends and said ‘hey, I need help’. We needed to start at ground zero. I had all these ideas and I was told that procurement was mine to shape. I was really excited about that…”

Read the full story here!

RBI Procurement: Success through technology, innovation and community building 

We speak to Edzard Janssen and several of his team members at Raiffeisen Bank International (RBI) to see how the procurement function is enhancing value creation, mitigating risk and dealing with increasing regulatory requirements… 

Now, more than ever, procurement leaders are having to harness innovation as they seek to prosper in highly uncertain times. Successful procurement teams are fostering emerging technologies and strategically aligned operating models and processes as they strive to unlock value across their enterprises. The procurement function at the Austria-based Raiffeisen Bank International AG (RBI) is such an entity, dedicated to delivering value through a future-orientated approach, at scale. 

Edzard Janssen, Head of Group Procurement, Outsourcing & Real Estate Management at RBI, joined the Austrian bank in 2011, where he was tasked with building a state-of-the-art value-creating function. The latest strategy of RBI Procurement focuses on four strategic areas as guidance for all initiatives: value-centric procurement, state-of-the-art capabilities, mastering the data journey and safeguarding the bank. 

1. Value-centric procurement: Focusing on value, not on price, and what truly brings value to the bank. 

2. State-of-the-art capabilities: The procurement systems, the total procurement infrastructure landscape and the capabilities of staff. 

3. Mastering the data journey: Harvesting and utilising the huge pools of data across the bank. 

4. Safeguarding the bank: Covering regulatory compliance, IT and cybersecurity as well as operational and business risk. 

Value-centric procurement 

The ability to deliver value-centric procurement is of course directly related to strategic sourcing and Janssen and his team have made great strides in recent years, establishing an innovative category management approach at the bank. “There are two parts that cover the source-to-pay process,” Janssen tells us from his Vienna office.

“One is the sourcing part of the process mainly fueled by the capabilities of our people and strategy formulation – the right way of approaching the market is pretty much driven by the quality of the people running the process. And then you have the second part of the process: procure-to-pay. So, doing the call-offs and executing the contracts. All that is powered by the quality of systems and efficiency of processes.”

Read the full story here!

Tipico Services: A single source of truth 

We speak to Kiran Menghnani, Director, Tipico Services Ltd (part of the iGaming and Sports Betting brand Tipico Group) to see how he and his team have transformed procurement at the company… 

Kiran Menghnani, Director Tipico Services Ltd – part of the online iGaming and Sports Betting brand Tipico Group – almost stumbled into procurement by accident. As the Malta Head-Officed enterprise Tipico Group started to experience rapid growth midway through the 2010s, combined with complicated regulatory developments, the maturity of the Group realised the tangible need for a dedicated procurement function.

And in 2016, Gibraltar-based Kiran, who had already been with the company since 2011 building internal processes and structures, was asked to look into creating a future-ready procurement hub that could deliver a more strategic and agile business-facing function. 

Tipico had a somewhat disjointed procurement approach to purchasing, prior to its transformation, a situation that resulted in a lack of transparency and an antiquated siloed approach. It was clear to Kiran whilst settling into his new assignment, that as the company continued to grow at pace, that this casual approach to procurement needed to change.

“We were still a young but rapidly growing company. We needed to work fast to get the tasks done while finding our way when dealing with our suppliers. Now the responsibility was on me to better understand the pain points being faced. And so I went about asking the basic questions challenging any purchasing requests. Has the contract been reviewed internally? Is there any data processing by the supplier? Has the price been benched with the market? How can I access past/existing contracts?”

“I soon started to realise that I wasn’t getting the answers to comfort me as Director, and that this humble piece of paper called a contract needed more attention, so I needed to protect both myself and the company as regulatory requirements had evolved. And that’s how this journey really started: someone questioning as to what we were doing and accepting that there were obvious gaps and opportunities.”

Read the full story here!

Richmond’s Department of Procurement Services (DPS): Leadership, relationships and the power of technology 

We speak to Rene Almaraz, Director, Department of Procurement Services, City of Richmond, Virginia to see how public procurement is transforming at the city… 

The values of the City of Richmond’s Department of Procurement Services (DPS) are set out on the opening page of its first ever annual report: teamwork, integrity, innovation, customer focus and leadership. The report is the work of the department’s relatively new director, Rene Almaraz, and his staff, and highlights the team’s achievements – in fiscal year 2023 – and priorities for the future, and also the guiding principles that influence how and why decisions are made.

Almaraz says: “Our goal is to build an organisation that’s more nimble, that provides faster and higher quality service, and supports the customer to the highest degree possible, which includes explaining to them why and when they should follow a specific process.  This, in turn leads to how we can get it done better the next time.”

It will be two years in January since Almaraz took on the role, with clear goals for creating a more agile department that delivers for internal customers and the people of Richmond…

This brings us to two of the points on the DPS list of values: teamwork and leadership. This means within the department itself, but also with external partners, suppliers and customers. The DPS team has grown by around 40% to 28 staff since Almaraz took the reins, as he explains. “We’ve needed to grow. Before I got here, coming out of the pandemic, there wasn’t a lot of stability in terms of headcount. It’s now stabilised and we’ve built a good team here, a really focused team. Plus, I’ve received a lot of support from my leadership and my peer departments to continue improving.”

The team has grown, but can be considered relatively small when you consider the scope of work they’re responsible for, which is why collaboration is so important for Almaraz and, above all else, trust and communication within the team. He explains: “I’m a huge believer in trust – my staff has to trust me, that I’m doing the right thing.  I need to know when to communicate and what to communicate, but they’ve got to trust me and then I must trust them.”

This mutual trust allows everyone to feel inspired and to grow, he says, and develop the skills needed to conduct complex procurement projects. Part of this means asking for help when it’s needed and, crucially, learning from mistakes. Almaraz adds: “Be honest with me: if you need some support, let me know. This is a project I’m giving you so you can grow and so I can grow. We’re going to lead and put this department on the map, through our expertise and professionalism. That’s our objective here.”

Read the full story here!

Maarten van der Borden, Customer Transformation Director at Celonis, discusses the influence digital tools such as generative AI is having on procurement’s workforce.

“When something new arrives on the scene, people have a tendency to immediately think of the worst-case scenario.”

Maarten van der Borden is a Customer Transformation Director at Celonis. As AI gets increasingly complex and advanced, there are concerns from some sections of the workforce that robots will take human jobs in procurement. Indeed, one of the biggest draws of automation is the cost savings and efficiency it brings, with AI able to complete some tasks almost instantly. But van der Borden challenges that notion and believes technology should be used as an enabler.

AI’s impact on jobs

AI will, in my opinion, not replace anyone anytime soon,” he reveals. “What it will do is make life easier and change the way we operate. In the late 90’s, we couldn’t envision what having a mobile phone would be like. When those were first introduced, we thought how annoying it would be that you would always be reachable. Now we can’t imagine living without a phone.

“I don’t envision the elimination of procurement positions due to AI. Rather, a significant shift may occur in the transactional aspects of process analytics. Currently, individuals proficient in creating complex Excel macros or adept at extracting and transforming data into actionable insights are highly valued. These roles are likely to undergo changes, but this should be seen as an opportunity for enhancement, not a threat. It’s crucial to recognise this. My belief is that AI won’t be replacing jobs, particularly in procurement where human involvement is key. The role of technology should be to empower and improve processes in procurement, not to replace the human element.”

Maarten van der Borden, Customer Transformation Director at Celonis

The journey

Over the years, Van der Borden has distinguished himself through a series of impactful transformations and strategic developments, primarily at the nexus of IT, business operations, and finance. His journey has been marked by the successful management of large-scale programs, where his ability to engage cross-functional teams and collaborate with stakeholders at all organisational levels has consistently led to the achievement of key goals. Notably, he has a history of taking on complex and challenging projects, steering them from concept to completion under stringent conditions. This track record has established him as an influential change agent, known for transforming underperforming organizations into models of high performance and efficiency.

Having began his career in the Dutch Military, he experienced a similar journey to many procurement practitioners. Van der Borden fell into the space by a “happy accident” and never left.

He shares, “I didn’t know much about procurement initially, but I quickly grew to love it.” His journey led him to DS Smith, a major packaging organisation, where he successfully spearheaded a comprehensive global procurement transformation. Subsequently, he transitioned to head the finance transformation within the same company. In this role, he sought a tool that could effectively navigate the unique challenges of procurement compared to finance.

“I needed something that would show me how our financial processes really ran. It meant finding the most impactful inefficiencies and developing an action plan to deal with them.”

Celonis today

This search brought him to Celonis’ process mining capability, a product that resonated with him so profoundly that he decided to join the company. “Right now, I am a Customer Transformation Director at Celonis, which means I help our customers organise themselves around this solution because I firmly believe implementing a tech solution by itself doesn’t do anything. We will always need the human element to make the change and create value, based on the insights tech provides. I’m very happy to be here.”

Today, Celonis is the global leader in process mining, providing companies with a modern way to run their business processes entirely on data and intelligence. The firm pioneered the process mining category more than a decade ago when it first developed the ability to automatically X-ray processes, find inefficiencies and implement immediate, targeted, and automated action to resolve them.

Gen AI drive

Procurement is in a transformative moment. At DPW Amsterdam, generative AI was the buzzword on attendees’ lips everywhere you looked. For van der Borden he acknowledges how rapidly the space is changing as a result of an increased influence of digital tools.

“To me, the first big thing to realise when we talk about gen AI is the democratisation of data and process analytics,” explains van der Borden. “I think what’s really important is that procurement realm to me is a prime example of where gen AI can have a huge impact. I think what gen AI will do is open up the capabilities of analytics to a much wider audience than today. People who may previously have trusted some Excel sheets or PowerPoint slides presented to them to make decisions can now freely explore, or even converse with their own data and make informed decisions themselves. You start to build a community of data analysts rather than just having consumption of data analytics. That to me is the big game changer that gen AI is actually providing procurement with.”

Procurement’s perception

CPOstrategy sits down with Maarten van der Borden, Customer Transformation Director at Celonis, at DPW Amsterdam 2023

By its own common admission, procurement used to be boring. A function hidden out of sight and kept far away from the c-suite. Now, it’s front and centre, firing on all cylinders. Indeed, the Covid pandemic helped drive it towards the top of the agenda, in addition to other enablers such as transformation and ESG. For van der Borden, he believes procurement is beginning to shake off that old skin and be seen as more of a strategic function.

“We’ve received a bad reputation in the past because the impact has not always been clear,” he tells us. “Some analysis that people do on procurement as a strategic function is to ask what’s the real impact? Yeah, you manage the supply and demand but as long as I have my blue ball point where and when I need it, you’re doing a good job. If things start to fall over then procurement used to get the blame. What I’m really happy to see is that more and more CEOs are seeing procurement as a strategic function, not only driving value in the financial domain but also more and more as the primary contributors to a more sustainable future and the guardians of our corporate brands.

An evolution

“There’s been a noticeable evolution in procurement, particularly in the merging of processes like source-to-pay, procure-to-pay, and purchase-to-pay. Our definitions in these areas haven’t always been crystal clear. However, when you delve into purchase-to-pay, it’s apparent that this is where the transactional activities occur. Due its very transactional nature, this phase is measurable and reveals the outcomes of our upstream actions in sourcing. I’ve observed that these areas, despite often being managed by separate divisions or functions, are intrinsically linked. The transactional aspects are commonly seen in shared services, while the sourcing aspects represent traditional procurement.

“Bridging these two areas, in my view, is a significant shift. This is where technology truly demonstrates its value. By integrating and examining the transactional processes to understand their shortcomings, we can trace back to the root causes, often found in sourcing. This integration is fascinating to me. It allows us to assess the real impact of our efforts.”

Michael van Keulen, CPO at Coupa, discusses the emergence of gen AI and whether procurement is in a golden era amid technology transformation.

Generative AI, or gen AI for short, is one of the hottest topics in procurement today.

Indeed, the introduction of ChatGPT has only accelerated its prominence into wider consumption. Gen AI allows its users to quickly generate new content based on inputs. These models could include text, images, sounds, animation, 3D models or other types of data. One of its biggest draws is the ability to understand different learning approaches and allows organisations to move quickly to leverage large quantities of data.

But despite obvious benefits such as time and cost, Michael van Keulen, Chief Procurement Officer at Coupa, stresses caution should be used particularly when it comes to valuable tasks. “If you look at ChatGPT, it’s fine if you’re looking for recommendations for something low-risk. I need something for my wife’s birthday next week, you input three things that she loves and ask it to help. It’s great,” he tells us. “But it comes from data sources on the web that aren’t always governed, controlled or trustworthy. It’s whatever is out there. What about the algorithms that come with ChatGPT? I don’t know what’s influencing the search criteria. On Google, if you pay you are at the top of the search bar. But I don’t know what ChatGPT is governed by.”

Van Keulen is a passionate and seasoned procurement evangelist with a comprehensive track record of driving value through business transformation at global companies. Since March 2020, van Keulen has been the Chief Procurement Officer at Coupa, a leader in cloud-based business spend management software, where he is responsible for driving best-in-class procurement practices across the company, supporting business development and being a source for peers looking to elevate and transform procurement. Van Keulen is especially passionate about building teams, driving value, organisational transformation, CSR, and diversity and inclusion.

CPOstrategy speaks with Michael van Keulen, CPO at Coupa, at DPW Amsterdam

The rise of AI

In the case of Coupa, the firm has been conducting its community.ai platform for the past decade which has been at the heart of the company’s strategy. Community.ai analyses real-time spend data, applies AI to compare company’s metrics against others and offers ways for organisations to be more efficient, profitable and sustainable. Van Keulen believes that the biggest difference between what Coupa offers and what gen AI provides is the trust factor.

“At Coupa, we measure information based on real spend, data and suppliers that are doing real business together – the internet isn’t doing that,” he discusses. “We’ve got nearly $5 trillion of spend under management from real transactions and real suppliers. That number continues to grow as customers and suppliers join the Coupa community. Pretty much all of our customers have trusted us with access to their sensitive data which we anonymize and then share back with the entire Community.  As a member of the community I know I can trust it because it comes from a source that is reliable, sanitised, relevant and well-governed. As well, we have certain standards and algorithms that we built-in all based on outcomes that our customers are looking to receive.”

Van Keulen believes there is a misconception in procurement that ready-made data sets are out there that are capable of meeting customer requirements. “The truth is most tech companies out there today don’t have access to customer data because their customers won’t let that happen,” he explains. “But at Coupa, our customers have already given us access to their data. This means we now have a real, reliable, accessible, governed and structured data set that has been anonymized.  When we then apply AI, you actually get prescriptions that are meaningful and relevant to procurement. I think the misconception is that this type of data set is easily found, but it’s not, we’ve been building this for over 10 years. There’s no other company out there that has the same level of spend data as Coupa.

“It’s the same as Google Maps. The only way that Google Maps works is because everybody uses it.  It allows me to get from A to B to C to D, back to A in the quickest time and with the least amount of disruption. The only way that that works is because we’re all using it. And I look at AI no differently in spend as I do with AI in my private life.”

Michael van Keulen, CPO at Coupa

Bridging the talent gap via AI

The need for fresh talent in procurement has never been so important. Procurement, like many industries, is lacking a defined path to welcome the next generation of talent, a feeling which has only been amplified on the back of COVID-19. This means the need to find ways to meet that shortage head-on, whether that’s through education, an industry rebrand or via AI. In van Keulen’s mind, he believes developing the correct tech landscape could hold the key.

“I’ve actually said this for a while,” he explains. “For too long, we brought in super smart people and then we would let them work in some antiquated old-school ERP, in Excel and run RFPs in emails. Nobody wants that, especially the current workforce because they’re used to and have been raised with Amazon, they all have TikTok accounts and are used to all these other e-commerce websites which have very seamless systems. If they come into the workforce and I let them work in some outdated ERP environment with email as the means of communication, that talent is either going to leave procurement because they think it’s boring or they’re just going to leave the overall organisation and work somewhere else. We don’t want that to happen, so you need to have the right tech landscape in place.”

Once the strategy is formed, van Keulen explains that is where the fun of procurement begins. “Then procurement’s the coolest function in the world and we will close the talent gap,” he says. “The talent is out there, they’re just not coming to procurement. They’ll go to finance, marketing, legal or IT instead. If you execute procurement properly, it’s the best because you’re right at the heart of everything. But you need the right people, operating model and operationalisation of your procurement process as well as the right technology. You need all of those elements or it’s never going to work.”

The greatest time in procurement?

Given the disruptive nature of global challenges and its ripple effect on procurement and the supply chain over the past few years, organisations are increasingly waking up to the importance of developing greater strategic relationships with suppliers. COVID-19, inflation issues, natural disasters and wars have meant today’s CPOs have been forced to firefight and think more strategically than ever before. Van Keulen recognises the turbulent nature of recent years and believes major transformation is already underway in procurement. “Historically most executives in any company would pay very little attention to their supply chain,” he reveals. “Due to recent events, companies are realising that they need to be closer to their suppliers. Perhaps in the past, the CEO would only spend a small fraction of their time with suppliers but those metrics are changing rapidly.”

As the ground lies in procurement, some sections of the industry now believe it is the industry’s greatest era given the level of possibilities. Widely considered a back-office function tucked in a corner and working in a silo, procurement is a totally different beast in today’s world. For van Keulen, he likes the variety.

“I wear so many different hats every single day,” he explains. “I always say sometimes I’m an accountant, others I’m an environmentalist. Sometimes I’m the treasurer or a finance person, but I’m also sometimes a psychiatrist. Sometimes I’m a doctor, a nurse, a lawyer, a judge, an environmentalist and yes even a wizard. I never know what my day looks like. I can plan it, but something may happen where everything goes out the window. Procurement will always be going through some type of disruption and it’s about how you drive the competitive edge and how you drive value despite that. Procurement really is the best gig in the world and it’s great that more people have started to see that now too.”

Our exclusive cover story this month centres around Versuni, home to some of the world’s most renowned home appliance brands

Versuni: Procurement excellence to drive growth 

Our exclusive cover story this month centres around Versuni, home to some of the world’s most renowned home appliance brands. Versuni is a company with a rich history, dating back to 1891, albeit under a different name. Philips Domestic Appliances was renamed Versuni after the Netherlands-based giant sold the business to China-based global leading Private Equity company Hillhouse Capital in September 2021. And so began a process of disentanglement as Versuni embarked on its journey to becoming a successful and independent entity with a simple yet clear purpose of turning houses into homes. 

Read the new issue here!

“We refer to ourselves as a 130-year-old company with a scale-up mentality,” explains Hugo Sparidans, Chief Procurement Officer, Versuni. “We combine the legacy we have with Philips with all the goodies here in this new, agile environment where things can happen much faster and with a different mindset fully focused on growth.” 

Versuni is now operating under private equity ownership following its separation from Philips two years ago. “My boss called me and said, ‘So, we’re going to spin off Domestic Appliances. Do you have the interest to lead the transition for Procurement within that spin-off, and then potentially after?’ That was an interesting question for me,” Sparidans explains. “I’d had a great career within Philips working for a successful business, but I was now facing the idea of leaving that behind for a trip into the unknown.” 

Read the full story here!

Mars LATAM: Shaping the world of tomorrow  

Mars Pet Nutrition LATAM is changing the sustainability game within the pet food sector. Gabriel Guzman, VP Procurement LATAM, and Ana Milena Zambrano, Climate & Sustainable Sourcing Head LATAM, explain how…

Gabriel Guzman, VP Procurement LATAM, and Ana Milena Zambrano, Climate & Sustainable Sourcing Head LATAM, are leading a major ongoing evolution within Mars Pet Nutrition LATAM. Guzman has worked in some of the world’s largest organisations over 25 years, spearheading many high-profile projects during this time. Zambrano’s career spans 15 years across consumer goods and supply chains, with sustainability as a core lifelong passion. 

A focus on sustainability and the environment is nothing new for Mars – it’s part of the culture. It’s a business with firm ESG pillars and a clear concept of what sustainability means to the organisation. “We believe the world we want tomorrow starts with how we do business today,” says Guzman. “It is the vision at the heart of our Sustainable in a Generation Plan – one where the planet is healthy, people and their pets are thriving, and society is inclusive.”

Read the full story here!

EMCS: A small fish making a big impact 

We sit down with Trevor Tasker, CEO of EMCS, for the second time to discuss partnership, leadership, and the state of the industry 

EMCS Industries is one of the best-kept secrets in its sector. An innovator from day one, EMCS Industries invented the world’s first electrolytic marine growth protection system (MGPS). This set the basic standard for the field, to the extent that everybody else now uses the same or similar technology based on the EMCS Canadian engineered and manufactured antifouling system. Trevor Tasker is the CEO of the company, and he’s not only passionate about what EMCS does, but his rich background in leadership puts him in excellent stead as head of an industry-leading company. 

Tasker’s first job at the age of 16 was as a self-employed wedding DJ. Since then, he has honed his entrepreneurial spirit on an international scale in industries such as financial, large scale digital signage, steel manufacturing, and others. He has experience in both building his own businesses, and being an employee, giving him a good foundation of what it means to both lead and be led. 

“It allows you to get a good mix of what you like, what you don’t like, how you’d like to be treated, and how that shapes the way you treat others as you move through your career,” says Tasker. He’s worked across a variety of industries but the common denominator has been that he’s always either been in a leadership position within a company or running his own company. He’s conducted business all over the world and collected the tools he’s needed to be the best leader he can. 

Read the full story here!

AlphaSense: Making procurement a priority 

Joaquin Rivamonte, Director of Procurement at AlphaSense, talks about how he’s bringing scalability to the organisation, and the benefits of procurement working hand-in-hand with the wider business 

Joaquin Rivamonte has enjoyed a rich and varied career, one which taught him numerous lessons in preparation for his role with market intelligence platform, AlphaSense. He cut his teeth in the financial service sector; he was the Director of Procurement for some medium-sized investment banking companies in San Francisco, helping support Silicon Valley before the businesses he worked for were bought by bigger banks. One was acquired by JP Morgan Chase, where Rivamonte became VP of Procurement. He was then asked to move to New York, just as Silicon Valley was experiencing the dotcom boom.  

Office photos at AlphaSense, 24 Union Square East in New York City.

Rivamonte’s background in building procurement departments from the ground up continued, and eventually, Microsoft took him on. He moved to Seattle to be part of the Microsoft team in 2005, and this was the beginning of his education in how very large procurement departments work. “I did have experience in large groups of people reporting to me already,” Rivamonte says, “but at Microsoft, I had $2-3bn dollars of category responsibility under me. 

“I was responsible for putting together the consulting category, which was almost $1bn, and the outsourcing category of about $1.2bn, plus the web development category and a lot of different IT contracts.” 

Read the full story here!

CPOstrategy compiles five ways that ChatGPT can transform procurement amid the rise of generative AI in the space.

ChatGPT is seen by many as a catalyst for the next wave of technology transformation.

The technology, which was developed by OpenAI, has quickly become the buzzword of the year and one of the hottest topics on the c-suite agenda.

And its promise extends to procurement – an industry that relies heavily on the need for achieving efficiency, transparency and cost savings. Having already made its mark on a variety of industries already, procurement hopes that by embracing ChatGPT it will allow teams to make greater strategic decision-making to drive long-term value.

Here are five ways ChatGPT can transform procurement.

1. Rapid research

Through ChatGPT, time-consuming and cumbersome tasks such as research can now be completed almost instantly. Generative AI tools such as ChatGPT can analyse significant amounts of data and provide insights on market fluctuations while also searching for new suppliers, products and capabilities to secure better deals.

2. Automated procurement processes

ChatGPT can be used to discover patterns and identify trends which will allow procurement teams to make data-driven forecasts. Through leveraging predictive analytics, organisations can anticipate demand, optimise inventory levels and manage their supply chain more effectively.

3. Easier communication with suppliers

Tools such as ChatGPT can improve supplier performance tracking through automating data collection and analysis. Its focus on cooperation and transparency throughout the procurement process allows for stronger supplier relationships and more innovative thinking.

4. Enhanced risk management

A major benefit of generative AI in procurement is improved risk management and the ability to foresee potential dangers. Through identifying potential hazards such as financial instability among suppliers or non-compliance with procurement processes, ChatGPT can help businesses manage and reduce risks.

5. Cost savings and increased efficiency

ChatGPT can help organisations to save costs by automating operations, increasing stakeholder participation and allowing real-time data analysis. By reducing the amount of time and effort for tasks like evaluating bids and selecting a vendor, ChatGPT could shake up the procurement process immeasurably.

This month’s cover story features Fiona Adams, Director of Client Value Realization at ProcurementIQ, to hear how the market leader in providing sourcing intelligence is changing the very face of procurement…

It’s a bumper issue this month. Click here to access the latest issue!

And below are just some of this month’s exclusives…

ProcurementIQ: Smart sourcing through people power 

We speak to Fiona Adams, Director of Client Value Realization at ProcurementIQ, to hear how the market leader in providing sourcing intelligence is changing the very face of procurement… 

The industry leader in emboldening procurement practitioners in making intelligent purchases is ProcurementIQ. ProcurementIQ provides its clients with pricing data, supplier intelligence and contract strategies right at their fingertips. Its users are working smarter and more swiftly with trustworthy market intelligence on more than 1,000 categories globally.  

Fiona Adams joined ProcurementIQ in August this year as its Director of Client Value Realization. Out of all the companies vying for her attention, it was ProcurementIQ’s focus on ‘people power’ that attracted her, coupled with her positive experience utilising the platform during her time as a consultant.

Although ProcurementIQ remains on the cutting edge of technology, it is a platform driven by the expertise and passion of its people and this appealed greatly to Adams. “I want to expand my own reach and I’m excited to be problem-solving for corporate America across industries, clients and procurement organizations and teams (internal & external). I know ProcurementIQ can make a difference combined with my approach and experience. Because that passion and that drive, powered by knowledge, is where the real magic happens,” she tells us.  

To read more click here!

ASM Global: Putting people first in change management   

Ama F. Erbynn, Vice President of Strategic Sourcing and Procurement at ASM Global, discusses her mission for driving a people-centric approach to change management in procurement…

Ripping up the carpet and starting again when entering a new organisation isn’t a sure-fire way for success. 

Effective change management takes time and careful planning. It requires evaluating current processes and questioning why things are done in a certain way. Indeed, not everything needs to be changed, especially not for the sake of it, and employees used to operating in a familiar workflow or silo will naturally be fearful of disruptions to their methods. However, if done in the correct way and with a people-centric mindset, delivering change that drives significant value could hold the key to unleashing transformation. 

Ama F. Erbynn, Vice President of Strategic Sourcing and Procurement at ASM Global, aligns herself with that mantra. Her mentality of being agile and responsive to change has proven to be an advantage during a turbulent past few years. For Erbynn, she thrives on leading transformations and leveraging new tools to deliver even better results. “I love change because it allows you to think outside the box,” she discusses. “I have a son and before COVID I used to hear him say, ‘I don’t want to go to school.’ He stayed home for a year and now he begs to go to school, so we adapt and it makes us stronger. COVID was a unique situation but there’s always been adversity and disruptions within supply chain and procurement, so I try and see the silver lining in things.”

To read more click here!

SpendHQ: Realising the possible in spend management software 

Pierre Laprée, Chief Product Officer at SpendHQ, discusses how customers can benefit from leveraging spend management technology to bring tangible value in procurement today…

Turning vision and strategy into highly effective action. This mantra is behind everything SpendHQ does to empower procurement teams.  

The organisation is a leading best-in-class provider of enterprise Spend Intelligence (SI) and Procurement Performance Management (PPM) solutions. These products fill an important gap that has left strategic procurement out of the solution landscape. Through these solutions, customers get actionable spend insights that drive new initiatives, goals, and clear measurements of procurement’s overall value. SpendHQ exists to ultimately help procurement generate and demonstrate better financial and non-financial outcomes. 

Spearheading this strategic vision is Pierre Laprée, long-time procurement veteran and SpendHQ’s Chief Product Officer since July 2022. However, despite his deep understanding of procurement teams’ needs, he wasn’t always a procurement professional. Like many in the space, his path into the industry was a complete surprise.  

To read more click here!

But that’s not all… Earlier this month, we travelled to the Netherlands to cover the first HICX Supplier Experience Live, as well as DPW Amsterdam 2023. Featured inside is our exclusive overview from each event, alongside this edition’s big question – does procurement need a rebrand? Plus, we feature a fascinating interview with Georg Rosch, Vice President Direct Procurement Strategy at JAGGAER, who discusses his organisation’s approach amid significant transformation and evolution.

Enjoy!

Dominic Fitch, Head of Creative Change at leadership development specialist Impact International, outlines five forward-looking skills for the next generation of leaders.

There is no denying that the world of business is evolving at an incredibly fast pace. With the constant launch of new tools and innovative tech, workers are required to embrace a wide range of modern equipment on a regular basis.

As employees continue to up their game, it is only natural that the next generation of leaders will need a set of updated skills too.

Dominic Fitch, Head of Creative Change at leadership development specialist Impact International

Here, with some insights from Dominic Fitch, Head of Creative Change at leadership development specialist Impact International, we take a look at some crucial future requirements that business owners and managers will have to nail to guide their team in an efficient, successful fashion.

1. Technological inclination

In the same way that youngsters jump at the latest technology at the first opportunity, it is important for future leaders to emulate that same drive and curiosity.

The world is becoming increasingly digitalised, and the business sector is no exception. This is why company owners and managers should have a basic understanding of today’s technologies, exploring how modern equipment can actively aid their business. From cloud computing to artificial intelligence and UX development, there are many different tools that can increase your organisation’s chance of success.  

Of course, nobody expects you to be an expert in computing coding or programming. But getting precious digital and tech skills under your belt can provide you with more than one ace up your sleeve.

2. Empathy and emotional intelligence

Just like an experienced, Michelin-star chef, future leaders have to juggle and balance several different aspects to create a perfect menu. Yes, technology will play an essential role in developing and driving your company forward. But software and robots have not yet mastered emotional intelligence, which means they cannot help on the more human side of things.

A business owner or manager should always strive to harness their relationship with colleagues and team members. Empathising, sympathising, supporting, and understanding the necessities of your employees is crucial, as this can inspire confidence and a sense of belonging in your people. If workers feel appreciated and cared for, there is a good chance they will go the extra mile to spur the growth of your business.

Hence, taking an interest in your team’s well-being and nurturing a shared feeling of unity is a fundamental attribute to possess.

3. Openness to diversity

One of the most prominent advantages of modern technology is that it’s abating boundaries and favouring connections with people worldwide. Hence, as time goes by, it is becoming more and more important to collaborate with colleagues from all over the globe. This means that, on a daily basis, you are working with teams from different cultures and who may even speak another language.

Engaging with people from all walks of life and with diverse backgrounds can open the doors to endless opportunities. Not only will you benefit from a vast range of experience, knowledge, and expertise, but you will also learn precious lessons on how to enter and succeed in global markets. Therefore, as the world becomes increasingly connected, future managers need to embrace diversity and make the most of its invaluable benefits.

4. Clarity and communication

Dominic Fitch, Head of Creative Change at leadership development specialist Impact International, outlines five forward-looking skills for the next generation of leaders.

Clarity and effective communication are timeless features of strong leadership. Managers need to build bridges between their team members and outline the company’s missions in a concise, transparent manner. In this respect, leadership development training is an excellent place to start when it comes to learning how to deliver messages and strategies that are straight to the point.

Future leaders have to be able to identify the right channels to carry this out in a smooth, effective way. With the many digital platforms at our disposal, it is important to choose one that can keep people on the same page at all times. What’s more, as innovations and possibilities arise, future managers need to communicate the essence of the question at hand in a digestible fashion.

Simplifying a complex situation or task is a crucial skill, and it is one that can aid both your team’s productivity and your business’ efficiency.

5. Foresight and adaptability

As technology evolves, artificial intelligence progresses, and the business sector continues to mutate, future leaders need to be flexible. Business owners and managers have to be ready to adapt and make sure they are not fazed by what the future holds. They should monitor trends and look at how to welcome change with a positive attitude.

How can you prepare for upcoming possibilities? One effective way is to run through various scenarios and start outlining all possible outcomes. What’s more, engaging with new circumstances and journeying out of your comfort zone can be an important learning curve. In fact, it will teach you how to deal with unfamiliar situations. If an unexpected opportunity comes about, you will have both the skills and confidence to respond to them with confidence.

To keep in step with the times, business leaders of the future will need to polish their set of skills. From emotional intelligence and adaptability to clear communication and openness to diversity, there are many aspects that will strengthen your leadership. By showing an interest for new software and technological developments, you can make sure your company is expanding its reach and exploring new, successful paths.  

In EY’s January 2023 European CEO Outlook Survey, it was discovered European CEOs expect short-term challenges but have reason for optimism.

Today’s CEO faces unprecedented challenges like never before and is tasked with navigating choppy waters.

Amid global uncertainty caused by a potential recession and on the back of war in Ukraine and disruption caused by COVID-19, it can feel overwhelming for even the most experienced leaders.

A positive horizon?

Despite this, consulting giants EY has discovered reason for optimism in its January 2023 CEO Outlook Pulse survey which includes 390 responses from CEOs across Europe. While the survey found 98% of respondents are indeed expecting a global recession, the majority of European CEOs (52%) anticipate it to be temporary and not a persistent one. These figures are a greater percentage than CEOs worldwide (48%) who point to more long-term optimism for the global economy among European CEOs.

According to the survey, 47% of European respondents believe this recession will be different from previous slowdowns. The recent crisis is more driven by myriad geopolitical challenges and an ongoing fallout from the COVID-19 pandemic compared with previous recessions primarily as a result of financial and credit market factors. Many CEOs are aware of this difference and acknowledge the necessity for new and sustainable approaches that build resilience in uncertain times.

In EY’s last survey in October 2022, ongoing pandemic-related concerns such as supply chain issues were the most important topics. However, since then supply chain pressures have eased to some extent with data from S&P Global Purchasing Managers’ Index (PMI) showing improvement. Only 32% of European CEOs now cite supply chains as the key issue which is down from 41% in October. Given inflationary pressures and the upward movement in interest rates, European CEOs are increasingly focusing on the policies and steps they believe European governments should take to help businesses mitigate the downturn.

About 35% of European respondents, in comparison to 32% globally, consider uncertain monetary policy and increasing cost of capital as the biggest challenge to growth. With inflation beginning to decline in November 2022 after 17 months of upward trajectory, CEOs are closely following central bank activity for potential course changes.

A strategy change

In response to the current recession, EU policymakers are considering more dovish economic recovery proposals instead of top-down austerity rules seen during the sovereign debt crises a decade ago. This includes rethinking debt rules to help countries navigate this downturn. Alongside this, EU governments now face pressure on how to handle the discontent of people protesting against the rising cost of living crisis and questions still remain on how extensively they will intervene. In particular, governments are reluctant to pursue austerity measures as a result of protests from the crisis 10 years ago. Meanwhile, for CEOs, financing will continue to be a challenge as a result of increased capital costs that are set to persist which disrupted growth plans.

European CEOs have learned from previous financial crises and recognise that it is essential to think of new and sustainable strategies to capitalise on the opportunities.

What is the way forward?

According to EY, there are five directives which are worth exploring over the next few years.

Investing in operations
European CEOs identify investing internally to boost operations as extremely important. Risk isn’t only about extraordinary events; day-to-day operational failures can also lead to losses, regulatory action and reductions in share prices. Operations such as finance, accounting and supply chain have emerged as the top priority area of investment for European CEOs (41%).

Recognising disruption and accelerating digital transformation

Amid ongoing global pressure to embrace new technologies and a digital transformation, COVID-19 further accelerated a trend toward digitalisation. Around 38% of European CEOs (in line with 37% globally) are looking to invest in digital transformation, data and technology to emerge stronger from this downturn.

Developing a strong environmental, social and governance (ESG) strategy

Businesses need to ensure ESG processes are moved to the centre of business strategy. Sustainability, including net zero and other environmental issues, as well as societal priorities, is one of the key areas that European CEOs identify as a need for more investment.

Nurturing talent

Despite the recession, the labour market remains tight in Europe. European CEOs are weighing cost management options, with 37% considering a move to contract employment and 38% planning on reducing learning and development investments. About one third are also considering a restructuring of their workforce compared with global and Americas CEOs (36% and 42%) considering the same approach.

Portfolio transformation

Looking ahead, portfolio rebalancing is expected to be a key theme as CEOs will be compelled to make bold decisions regarding their business portfolio. During a recession, companies must critically assess what their core businesses are, what their focus should be and where they can create value by spinning out or selling non-core assets. Some 93% of European CEOs consider prioritising restructuring opportunities as an important initiative in the next six months.

Mike Randall, CEO at Simply Asset Finance, discusses how to build a people-first strategy that enables growth.

As the UK economy continues to balance on the edge of a recession, employee retention is quickly being pushed to the top of CEOs’ lists. Over the past couple of years, the job market has shifted dramatically with previously unheard terms such as ‘the great resignation’, ‘quiet quitting’ and ‘hybrid working’ becoming commonplace. People are rightly prioritising their working situation and job satisfaction levels, questioning whether they believe in the organisations they are committing so much time to.

Consequently, there has been a power dynamic shift in favour of the workforce. Reportedly in the third quarter of 2022 businesses witnessed over 365,000 job-to-job resignations across the UK. In similar fashion, the phenomenon of ‘quiet quitting’ – doing the bare minimum required of a job – has become a growing concern but its rise is prompted by a growing number of employees feeling disengaged in their roles.

Against this backdrop of a highly turbulent job market, and increasingly difficult macro-economic pressures, it’s vital for CEOs to prioritise a people-first strategy to ensure healthy growth for their business in 2023. Data from Deloitte has even revealed that experts believe how engaged a workforce feels can directly correlate to overall business output, with 93% of HR and business leaders in agreement that building a sense of belonging is crucial for organisational performance.

Mike Randall, CEO at Simply Asset Finance

However, creating the right environment and recruiting, maintaining and nurturing the right talent to ensure a people first approach can be daunting. With this in mind, here are four learnings CEOs might want to consider when approaching this challenge:

1. Define your beliefs

Before CEOs and founders can hope to attract the right talent, it is critical to first distil and translate the business vision into something that can be understood by employees. Put simply, this means defining the business’ beliefs.

Some business leaders may already refer to this as an ‘employer brand’, and it can be key to not only securing better talent, but also saving a business money in the long-term. Data from LinkedIn for example, recently found that a strong employer brand can help to reduce employee turnover by as much as 28% and cost-per-hire by 50%. Defining these beliefs – or the tenets a business does and doesn’t stand for – is therefore the perfect exercise to put a vision onto paper, and clearly communicate it to its prospective talent.

2. Build a solid culture

Once these beliefs have been defined, they must be reflected, and built into a strong culture. A business’ beliefs should permeate through the whole organisation – from customer communications, to how staff are treated, to how leaders run the business. Culture should essentially be a representation of a business’ beliefs being put into practice.

Building a strong culture in a business, however, is not solely about these beliefs but also extends into how employees are equipped with the tools they need to succeed. Companies that invest in learning and development for example, have been found to benefit from a 24% higher profit margin than those that don’t, according to the Association of Talent Development. Training and development should therefore be seen as a worthwhile and necessary investment that can solidify your culture and ensure profitability, not just an unavoidable cost.

3. Invest in retention

With research from Oxford Economics estimating the average turnover per employee earning £25,000 a year to be £30,000 plus, there is an evident cost to businesses that fail to invest in retention. Tackling this will mean regularly taking the time to truly understand what makes employees tick – and more specifically, understanding their motivations, attitudes, behaviours, strengths and weaknesses.

As the past few years have evidenced, individuals are no longer deciding where they work solely based on salary, but are also thinking about employer values, flexibility, and benefits. To avoid employee churn, businesses should regularly take time to understand what drives their employees and implement retention strategies to address these drivers. Gathering and analysing employee data will play an important role here over the coming years, and should be built into a long-term strategy to optimise employee satisfaction.

4. Build for the future

A common challenge encountered by modern businesses and startups wanting to take a people first approach, can be their ability to stay committed to it. As a business grows in size and becomes successful, it can be all too easy to let external factors dictate its purpose and for it to lose sight of what it initially stood for. The reality is that when this happens, a business is in its most vulnerable state – as its beliefs become increasingly distant, and worse, employees no longer understand what it stands for.

When creating a people-first strategy its therefore important to think long-term. If there are external factors that will potentially put this strategy at risk in future, it’s crucial to identify them, and put in practical steps to mitigate them where possible. The pandemic, for example, is a prime example of an external factor that interrupted the status quo of many businesses – disrupting employees, customers and operations in general. While they can be unpredictable in nature, having a plan to get through these times can help to get you back on track and reassure talent that a solution is in place.

In this economic climate, defining beliefs, building a solid culture, and retention plan should be at the core of every business’ strategy. It’s only when these things are in place that a business can hope to attract and retain talented people that exude the same passion and values built into the heart of a business. As while a business’ growth may be defined by its leaders, it is delivered by its people who are putting that vision into practice.

Mike Randall, CEO at Simply Asset Finance.

Diane Lightfoot, CEO of Business Disability Forum, on changing the narrative around diversity and inclusion in the workplace

Disability is still often parked in the “too difficult” box when it comes to Diversity, Equity and Inclusion. Employers are often afraid of doing or saying the wrong thing and as a result, do or say nothing.

As a CEO, the stakes feel (and often are) higher. That high profile platform can feel daunting at the best of times; when tackling an unfamiliar topic, it can feel positively overwhelming.

Talking about Disability

What we do and say as senior leaders has a huge impact. Indeed, it is critical in driving change. In 2020, we published our global research report, ‘Towards a Disability-Smart world: Global disability inclusion strategy’ . Conducted with our Partner, Shell, the research found that 91 per cent of respondents across multi-national businesses agreed that identifying a senior global disability champion is essential. Talking about disability and diversity – normalising the conversation so it becomes business as usual, has a massive role to play in creating a culture of “psychological safety” in organisations; one in which employees feel safe to share a difference and to ask for the support they need.

As senior leaders, it is easy to forget our privilege and that the environment we inhabit, and how we think the culture feels, may look very different to others. I often quote a research study by our partner Accenture which showed a marked gap (of around 20% across the board) between senior executives’ perception of how “safe” their employees would feel to raise a sensitive topic (including talking about a disability) and how safe they actually felt.

Changing the narrative

So, what can CEOs do to change the narrative? At Business Disability Forum (BDF), we see time and time again that CEOs or senior leaders who have a personal knowledge of and interest in disability issues – perhaps because of their own experience or that of a close family member – are champions in driving change. Senior leaders are less likely to publicly identify as being disabled – the Valuable 500 campaign often quotes the stat that 1 in 7 C suite leaders have a disability, but 4 out of 5 are hiding it. Yet if you as a senior leader are willing to talk about a disability or long-term condition it is hugely powerful in enabling others to do the same.

Storytelling and sharing personal stories can have a huge impact – for good or for bad! The good: A high profile CEO we work with talks openly about his disabled adult children and the moral imperative that he believes that large businesses have in breaking down barriers and opening up opportunities to people who face greater barriers to employment. The bad: I vividly recall being in a meeting with an organisation (not a BDF member!) to plan a possible disability awareness campaign. At the end of the meeting, the CEO then told an anecdote about having had an operation in the past year and being back at work the next day – unlike one of their counterparts who had taken two weeks off to recover. What message does that send? I’ll warrant that those who overheard that story were less likely, not more, to talk about a disability as a result.

Being a disability ally

But you don’t need to have your own lived experience to be an ally. For many businesses, the pandemic brought many senior leaders “up close and personal” with their disabled employees for the first time. In a survey we carried out to find how out how BDF Members and Partners were responding to Covid19, we found that in 83 per cent of organisations the general response to Covid-19 – including arranging internal communications, home working, and ensuring staff have the adjustments they need – was being led by the Chief Operating Officer or Chief Executive.

Whilst the figure for responsibility for ensuring staff with disabilities and long-term conditions specifically can move to home working was much lower – 31 per cent said this was the direct responsibility of the COO or CEO as compared to 69 per cent for HR – this is still encouraging in giving senior leaders much greater insight into the issues facing their disabled employees. Too often we “don’t know what we don’t know” – but once we do, we can call it out.

I was very heartened by a discussion with one of our members who was planning an office relocation in which the senior champion leading the project told me that he had vetoed one possible option because it had cobbled paving directly outside – inaccessible to wheelchair users and difficult for anyone with a mobility or visual impairment.

Role Modelling

Leadership is also critical in modelling adjustments and different ways of working. As a CEO, you probably have the freedom to quietly get on with making the adjustments you need, whether that is working from home one day a week (and it’s worth remembering that pre-COVID-19 home working was the most frequently requested workplace adjustment), different/flexible working times or buying some ergonomic equipment. You don’t need to go through a process or to ask HR – but if you share a different way of working with the wider team again it can be hugely powerful in making it ok for others to ask for the support they need. And again, people are often afraid to ask for even simple adjustments that could transform the quality of their working life.

Our Great Big Workplace Adjustments Survey 2019 found that 28 per cent of those with adjustments and 34 per cent of those without adjustments (but who would have benefited from them) said they did not make requests because they were worried their employer might treat them differently. Again, actions speak louder than words. If the boss doesn’t take a lunch break, the rest of their team is unlikely to.

I hope that one positive legacy of COVID-19 will be a kinder and more human style of leadership. During the pandemic, we were forced to be more human in the way we worked; viewed in our home setting without the “trappings of office” or our workplace “armour” in terms of a formal dress code. The intimacy of letting people into our homes (albeit via our video camera) was a powerful thing. The blurring of lines between work and home has its downsides but has positives too as we started to see the “whole people” in our teams; ironically, since the pandemic began, many of us have got to know our colleagues better than we did before.

Culture Change

Of course, culture needs to be backed up by practical action. Make sure you equip people managers throughout your business with the tools and knowledge they need to have a conversation about disability, to identify any barriers people may be facing and to know where and how to get practical support. Our free Disability Essentials resources is a good place to start.

As Peter Drucker famously said: “Culture eats strategy for breakfast.” Like it or not, what you do as a CEO not only matters but has a disproportionate impact. Why not use that for the good?

https://www.youtube.com/watch?v=g-TRCm1dv6o

Read more insightful features like this in the latest issue of CEOstrategy

Welcome to the launch issue of CEOstrategy where we highlight the challenges and opportunities that come with ‘the’ leadership role

Our first cover story explores how Vodafone is leveraging strong leadership to drive the collaborations enabling businesses to champion change management and better use technology.

Welcome to the launch issue of CEOstrategy!

Tasked with accelerating business growth, while building the synergies across an organisation that can drive innovation to meet diverse customer needs and keep revenues on track, the modern CEO must be mentor, marshall and motivator on the journey to success.

Read the launch issue here!

Leadership with purpose at Vodafone

“Leadership is purpose, it’s why do you do the things you do…”

Our cover story throws the spotlight on Vodafone US CEO David Joosten; also Director for Americas & Partners Markets at Vodafone Business, he talks to CEOstrategy about leading from the front and setting the standards to deliver growth while keeping employees and customers happy.

“People follow leaders that are honest about themselves. If you can reflect on what you’ve done well, but also where you need to improve it can inspire others to do the same.”

EMCS Industries Ltd: How a CEO can navigate change management

“Why hire talent and then tell them what do? You have so much to learn from the great people you hire. Micromanaging is not management, and it’s certainly not leadership. Let your people thrive!”

Read our interview with EMCS Industries Ltd CEO Trevor Tasker for more thought-provoking insights on leadership from the shifting tides of the marine industry in this maiden issue.

How to be an authentic leader

“At the most basic human level, everyone knows what it’s like to feel heard by another person, and how that changes our behaviour. It can help anger and sadness subside and enable us to start seeing things differently. So, when employees are being listened to by their leaders, it can only help how an organisation operates.”

Dr Andrew White, director of the Advanced Management and Leadership Programme at the University of Oxford’s Saïd Business School and host of the Leadership 2050 podcast series, explores transformative approaches to leadership for the modern CEO.

How can CEOs drive forward culture change around diversity and inclusion?

Diane Lightfoot, CEO of Business Disability Forum, explores the changing the narrative around diversity and inclusion in the workplace.

“Disability is still often parked in the “too difficult” box when it comes to Diversity, Equity and Inclusion. Employers are often afraid of doing or saying the wrong thing and as a result, do or say nothing. As a CEO, the stakes feel (and often are) higher. That high profile platform can feel daunting at the best of times; when tackling an unfamiliar topic, it can feel positively overwhelming. But what we do and say as senior leaders has a huge impact. Indeed, it is critical in driving change.”

https://www.youtube.com/watch?v=g-TRCm1dv6o

Also in this launch issue, we get the lowdown on agile ways of working from Kubair Shirazee, CEO of Agile transformation specialists Agilitea. Elsewhere, we speak with Nirav Patel, CEO of the consultancy firm, Bristlecone – a subsidiary of Mahindra Group and a leading provider of AI powered application transformation services for the connected supply chain – who discusses the challenges facing CPOs and supply chain leaders in our uncertain times. And we analyse the latest insights for CEOs from McKinsey and Gartner.

Enjoy the issue!

Dan Brightmore, Editor

Mark Weil, CEO at TMF Group, discusses the rise of staff attrition in the industry

At the start of 2023 many companies are still struggling to find employees. The job market favours the applicant far more than before Covid-19 across many sectors. Higher interest rates and lower economic growth so far haven’t reduced the pressure on labour availability.

High staff turnover isn’t just a matter of the cost it creates. The disruption from running with a lot of open roles and with less experienced staff can disrupt client service, increase error rates and lead to more serious compliance and reputation damage.

Mark Weil, CEO at TMF Group

Examining the data

A lot of commentary on the situation has been based on surveys of employees’ intentions rather than their actual decisions. By managing our clients’ financial, legal and employee administration we have access to large volumes of data. This provides insight on the overall recruitment and resignation levels across workforces, from several hundred thousand employees, covering a broad range of sectors and job levels in more than 90 countries.

As a starting point, the data tells us that there was indeed a significant global increase in staff resignation during and after the pandemic. Across the 90 countries, average company staff attrition rose from around 15% annually in mid-2020 to 25% at the end of 2021. That’s a dramatic 67% increase in just 18 months.

Global annualised employee attrition trend

Digging deeper reveals a much more nuanced picture by company and country. In 2021, staff attrition averaged around 20% across the 90 countries but was below 10% in a small number, with Argentina the lowest at 6%. Of those above 20%, India, the UK and Poland topped the list with a rate of 26%. Both India and Poland are now major destinations for companies establishing regional service centres – locations that are supposed to be low cost, stable hubs that support many other countries. So rising staff turnover there will be particularly painful.

2021 average employee attrition by country

When examining the data at company level, annual attrition levels vary  even more widely, from a low of around 5% to a high of 40%. Some of that will be a result of challenges in specific industries and companies. Some will arise from the underlying attrition in the labour market of the countries they operate in. To disentangle how much is company versus country, we compare in the chart below the attrition a firm is seeing with the average attrition it should be seeing given the mix of countries where it operates.  The wide spread in the data shows that that country averages matter far less than individual company factors. For example, looking at companies whose country mix should give them expected attrition of around 15-20%, we see many at 30%-40% and others at just 5%-10% attrition.

Company actual 2021 attrition versus average for the countries where they operate

Staff attrition is a problem at any time, but becomes a significant threat to a business if it gets too high. How high is a matter of judgement and depends on the particular company. In professional services, for example, when staff attrition is above 20% it starts to impact client service and above 30% it can pose a risk to regulatory and reputational integrity.

The rise in global staff attrition, coupled with big spikes by country and company means that multinational firms will have an increased number of locations where attrition is high and potentially well beyond manageable levels. From 2020 to 2021 the number of employees in company locations experiencing more than 20% attrition nearly doubled, from around 15% to 27%. Looking at where the levels were highest, employees in countries experiencing more than 35% attrition rose from 1% to 7%. That means there’s an increasing number of hotspots, where extremely high staff attrition means companies need to intervene quickly to avoid staff resignations spiralling due to increased workload.

Factoring in country complexity

An important additional factor is the complexity of a particular country to operate in. Many countries  have onerous business rules which are enforced vigorously. High staff turnover in complex countries is particularly dangerous because of the added risk of compliance breaches.

We can look at country complexity using TMF Group’s Global Business Complexity Index. It ranks countries annually based on 292 criteria, covering the fiscal, legal and employment environments for doing business in each location.  

Jolyon Bennett, CEO of Juice, discusses how sustainability has moved to the forefront of his organisation’s operations

A green approach is quickly transitioning away something that is ‘nice to have’ to an essential component of a company’s strategy.

To Jolyon Bennett, who heads up UK tech accessories manufacturer Juice, being environmentally friendly is non-negotiable. Bennett has transformed the mobile phone accessories sector, having consistently introduced a series of quality, vibrant and consumer-focused products to market, ranging from portable power banks through to super-fast chargers.

He takes us under the bonnet of his firm’s sustainability drive.


You have recently removed all single-use plastic from your entire product range – why?

Jolyon Bennett (JB): “Why wouldn’t you? Single-use plastic is one of the biggest polluters in manufacturing – it uses 3% of the entire planet’s oil consumption. This year, it’s forecast that there will be 50kg of plastic waste for every single one of the eight billion human beings on planet earth – that’s a lot! Consumers, manufacturers and brand owners like myself all need to get on board with the fact that we’re going to need to use and re-use plastic packaging to make different things.

“Why have we done it? Because it’s totally the right thing to do. We need to stop making so much plastic and we need start reusing what we’ve already got. We need to stop cutting down trees in order to make paper and cardboard – let the trees grow and re-use what we’ve got. It just makes sense on a planetary level to stop consuming quite so much and start being just a bit more content with what we’ve got. Why do we need to make ‘new new new’ all the time?”


What have you used instead of virgin plastic?

JB: “We’re reusing, reusing, reusing. Did you know that recycled plastic – depending on its quality and density – can be recycled and re-used between seven and 200 times. Isn’t that unbelievable? It’s such an amazing material. Plastic is a vibe, and we should be re-using it. Juice is using post-consumer waste such as Evian bottles to make speakers, old milk cartons to make power banks and so much more!”


Why do you love plastic?

JB: “I just think we’ve got a lot of it so why not reuse it? I admire the material because it’s so durable – it’s an incredible scientific breakthrough to be able to make something that’s not only waterproof and heatproof but lasts for up to 3,000 years. There are so many different elements that make plastic a great material. I would prefer it if we didn’t have any, but that’s not going to solve the current (and ever-growing) problem of plastic waste finding its way into our oceans, and burying it isn’t the answer either. The problem is with us humans is that we just shy away from the truth – l don’t want to shy away, I want to face these problems head on and meet the challenge.”


Has Juice taken a financial hit to make this happen?

JB: “As an example, we sell around three million cables a year (based on last year’s figures) and each piece of packaging that we are making using post-consumer waste costs us between $0.15 and $0.25 more, so as a minimum, our increased cost for doing this is almost half a million dollars. But I still think it’s the right thing to do. Money is made up – the world could end and money would no longer matter, so let’s stop making decisions based purely on money and let’s start making decisions based on the right thing to do.”


How do you rate the overall quality of the ‘Eco’ products compared to the ones they have superseded?

JB: “There is absolutely no difference whatsoever, so I rate them just as highly.”


Do customers really want these eco products or is this more for your own conscience?

JB: “I don’t suffer from guilt so in that respect I don’t feel driven by my conscience to do this – doing the right thing has its own gravity and its own way of whisking you forward. Generally, I believe that people and businesses that do the right things will prosper. I’m a firm believer in the philosophy of ‘do the right thing and good things will happen’ so it’s a strategic choice to do something that has a positive impact because positive things attract positive things. While not every consumer or every retailer is especially interested in our sustainability drive, I do think this is shifting slightly. Maybe I do have a conscience, but the reality is that it’s the right thing to do, and the right thing gets rewarded in the end.”


Are retailers keen to stock them?

JB: “We haven’t given them a choice! We changed all of our products because we wanted to and we are adamant that even though the materials we are using are different, our products still perform just as well, if not better.”


Should other tech brands follow suit?

JB: “Of course they should, and we would happily help them do so. We’re willing to introduce other tech brands to our suppliers and guide them through the same process we’ve taken, sharing our knowledge – including the hurdles we’ve overcome – because it’s the right thing to do. I don’t understand why any brand would want to continue producing virgin plastic when they don’t have to, it just doesn’t make any sense to me.”


What advice would you give to other brands wanting to embark on this process of removing single-use plastic from their products?

JB: “Do it. Stop messing about – get on with it and do it. Although it may cost you a bit more in the short term, we’ve proven that consumers do generally buy more of your products if you are making the right decisions towards the environment, so you will reap this extra cost back whilst also doing the right thing.”


What is next for Juice?

JB: “I want Juice to be a brand that limits its impact. We’re currently doing this with our manufacturing and through our supply chain and the way that we conduct ourselves in general. I want to start releasing products that have a positive impact on humans as well as the planet – I’m a firm believer that everyone can win. There will always be a demand for technology, so I don’t believe that we should be fighting against it, however, I would very much like to see people taking their technology off grid.

“My dream is to be able to take every mobile phone on planet earth off grid and start generating our own personal electricity. I want to create products that link to your activity – imagine if you could run 5k and the kinetic activity could generate enough energy to a charge a device such as a phone or a laptop while you do it? I’m interested in organic solutions to current chemical problems such as organic battery cells using salt water and algae as a storage method of electricity – so much so that we’re currently in discussions with a photosynthesis harvesting electronics brand about using photosynthesis as a charging capability!

“I want to get more connected with nature and I think you can have it all – I think we can still enjoy modern technology as well as the beautiful world around us. If we can utilise our intelligence in the right way, we can all live in a perfectly harmonious symbiotic relationship with amazing technology products and a sustainable environment for all wildlife.”

Procurement is in a state of flux. Against a backdrop of economic uncertainty, the procurement landscape is volatile and requires…

Procurement is in a state of flux.

Against a backdrop of economic uncertainty, the procurement landscape is volatile and requires agility to navigate turbulent waters. But, despite significant disruption could there still be opportunity?

Simon Whatson, Vice President of Efficio Consulting, is optimistic about the future of digital procurement and despite a challenging few years he is confident of a successful bounce back. He gives us the lowdown on the direction of travel for digital procurement in 2023. 

As an executive with considerable experience in the space, we’d love to learn more about your background and how you ended up in procurement. Why was this the specialism for you and how did you get involved to begin with?

Simon Whatson (SW): “I think the one-word answer of how I came into procurement was accidental. I studied maths at university, with a year in France, before I began looking for different roles to apply for.

“Eventually, I was offered a position with a big plumbing and heating merchant with global operations. I worked in that supply chain team for two and a half years. Although it was called supply chain, a lot of the work was procurement, which involved negotiating with suppliers. It was after that stint there, that I discovered consulting and joined a boutique procurement consultancy. Now I am onto my third consultancy and I’m very happy here!

“In terms of why I’ve stayed, one of the success factors in procurement is being able to work cross-functionally. Procurement doesn’t own any of the spending that it is responsible for helping to optimise. It must work with other functions and the spend owners. I quite like the people side of that, building relationships, almost selling internally to bring teams together. That really appeals to me and is a key reason why I’ve been very happy in procurement.”

As we move into exploring procurement today in 2023. The space is filled with challenges and complexities. You only need to look at the last few years. Covid, war in Ukraine, inflation – how would you describe the world’s recent challenges and their effect on the industry and what do you feel CPOs and leaders can do to combat these issues?

SW: “I would flip it around and say that these are not so much challenges but rather opportunities for procurement. When I started my career 18 years ago, procurement was often fighting to get a voice and there were complaints that procurement was not represented at the top table, but the war in Ukraine, inflation, COVID and ESG, these are things which are now on the C-suite agenda and procurement is ideally positioned to help companies face those challenges. If you think about COVID and the war in Ukraine, procurement is in a privileged position to help with this.

“I see some procurement functions that prefer to do what they know, which focuses on the process and transactional side. However, there are also many forward-thinking CPOs and procurement professionals out there, that have really seized this opportunity of being on the C-suite agenda and drive the thinking and the solutions to some of these big challenges we’re seeing.”

Although new technology in procurement has been around for well over a decade, digitalisation has become so much more of an important topic. How would you sum up where procurement and supply chain are in terms of digital transformation today?

SW: “It’s a bit laggard, but digital transformation is difficult, and we have to recognise there are some real trailblazers. There are some firms doing some fantastic things in digital to produce better outcomes. If you contrast your experience when you’re buying something in your private life, it’s much easier than 20 years ago. You can get access to a wealth of pre-sourced things, whether it’s food, a holiday, a car, or a book. You can see reviews of what other people think of these things.

“But when you go into your workplace as a business user and you want to buy something, it doesn’t quite work like that yet. You often have to fill in a form, send it off and wait for them to come back to you. They might come back a little bit later than you were hoping and might tell you that they don’t have that part on the supply frameworks. I think people sometimes get confused about how it can be so easy to buy something as large as a car or a holiday on their sofa at home, but when they want to buy something at work, it seems to be quite cumbersome. Digital can help a lot with that, but it is incumbent on organisations and procurement functions to figure out how to recreate that customer experience that we’ve become accustomed to in our private lives.”

With a new generation of leaders growing up with technology, some might say that it could be a key driver in helping to speed the adoption in procurement along. Is this something you would agree with or what would you point to as a key driver?

SW: “I do think that it will act as one of the catalysts for further digital transformation in organisations, because if procurement doesn’t manage to recreate that customer experience that the new generation expects, then they won’t use procurement going forward and will look to bypass it.

“The analogy that I’ve used previously in this case is one of travel agents. I remember as a child, my parents were able to take us on holiday and I remember the whole process. We would walk into town to the travel agent, and look at some of the brochures of options. They often then had to phone the various airlines or resorts on our behalf. They might not be able to get through, so we’d have to come back the next day. I remember as a child being quite excited by the whole process but actually, thinking back, it was quite cumbersome. You compare that to now, with being able to review online, and you can get instant answers to your questions. It’s not a coincidence that travel agents don’t really exist anymore.”

How much of a challenge is it to not get caught leveraging technology for technologies sake? How important is it to stay true to your approach and be strategic?

SW: “We conducted a study of many procurement leaders and CPOs a few years ago, and one of the things that we found was that about 50% of procurement leaders admitted to having bought technology just on the basis of a fear of missing out, without any real understanding of the benefits that technology was going to bring. That was a real shock and a revealing find because technology is not cheap, and its implementation is quite disruptive. If you’re purchasing a system because everybody else is using it, then there could be some pretty costly mistakes. It is really important to make sure that when buying technology, it is because the benefits are fully understood.

“My advice to companies when looking to digitalise is own your data, visualise that data, and manage your knowledge. If you can focus on getting those things right in that order, and make your technology decisions to support that goal, then that’s a much better way of thinking about it rather than just jumping in and buying a piece of technology.”

It’s clear that the procurement space is an exciting, but challenging, place to be. What do you think will play a key role in the next 12 months to push the digital conversation further to take procurement to the next level?

SW: “Looking forward, one thing that procurement needs to do and continue to do is attract the best people. Ultimately, people are what makes an organisation, and it is what makes a function successful. I think procurement has often not looked for the right skills in the people that it employs. Traditionally, it’s looked for people with procurement experience and while they are valuable and required, we also need leadership potential. People who think a bit more outside the box and aren’t so process driven. A lot of what procurement has done in previous years has been process driven, so if you’re just limiting your search of people to those that have had procurement experience, you’re inevitably going to end up with a lot of people who are process driven.

“I think being bolder and recruiting people from different backgrounds with different skill sets is the way to go. If procurement can ‘own’ the ESG space, that will help with the younger generation see procurement make a difference. I think that’s one thing that will be key to success going forward.”

Check out the latest issue of CPOstrategy Magazine here.

Paul Farrow, Vice President of Hilton Hotels’ Supply Management, sits down with us to discuss how his organisation’s procurement function has evolved amid disruption on a global scale

The hospitality industry has endured a rough ride over the past few years.

Following the COVID-19 pandemic which stopped the world in its tracks and now with millions facing a cost-of-living crisis, it’s been a period of unprecedented disruption for those involved in the space and beyond.

But it’s a challenge met head-on by Paul Farrow, Vice President of Supply Management at Hilton Hotels, and his team who have been forced to respond as the world continues to shift before their eyes.

Farrow gives us a closer look into the inner workings of his firm’s procurement function and how he has led the charge during his time with Hilton Hotels.

Could we start with you introducing yourself and talking a little about your role at Hilton Hotels? 

Paul Farrow (PF): “I’m the Vice President of Hilton’s Supply Management, or HSM as we call it. I’ve been with Hilton Hotels for 12 and a half years, and my role is to head the supply chain function for our hotels across Europe, the Middle East and Africa.

“Over the past few years, Hilton has grown rapidly and has now got 7,000 hotels in over 125 countries globally. What is really exciting is Hilton Supply Management doesn’t just supply Hilton Hotels and the Hilton Engine because we also now supply our franchisees and competitive flags. While we have 7,000 hotels globally, Hilton Supply Management actually supplies close to 13,000 hotels. That’s an interesting business development for us, and a profit earner too.”

You’re greatly experienced, I bet you’ve seen supply chain management and procurement change a lot in recent years? 

PF: “The past two to three years have been tremendously challenging on so many industries but I’d argue that hospitality got hit more than most as a result of the Covid pandemic. Here at Hilton, supply management was really important just to keep the business operational throughout that tough time, but I’m delighted to say we’re fully recovered now.

“Looking back, it was undoubtedly difficult, and you only have to look at the media to see that we’re now going through a period of truly unprecedented inflation. On top of the normal day job, it’s certainly been a very busy time.”

Hospitality must have been under an awful lot of pressure during the pandemic… 

PF: “Most of our teams as a business and all functions have worked together far more collaboratively than ever before through the use of technology and things like Microsoft Teams and Zoom. Trying to work remotely as effectively as possible changed the way we all had to think and the way we had to do. Now we’re back in the workplace and in our offices, we’re actually looking to take advantage of that new approach.”

Inflation, rising costs, energy shortages, as well as drives towards a circular economy means it’s quite a challenging time for CSCOs and CPOs right now, isn’t it?

PF: “Those headwinds have caused and created challenges of the like that we’ve not seen before. The war in Ukraine and Russia has meant significant supply chain disruption and supply shortages of some key ingredients and raw materials. China is a significant source of materials and they’re still having real challenges to get their production to keep up with demand.

“All the local and short-term challenges are around energy and fuel pricing, so throughout the supply chain that’s been a major factor to what we’ve had to deal with. On top of that is the labour shortages. We rely heavily throughout the supply chain and within our business to utilise labour from around the world. In my region, particularly from say Eastern Europe as well as other businesses all fighting for a smaller labour pool than we had before. We are fighting with the likes of the supermarkets, Amazon’s, not just other hotel companies to capture the labour pool we need both in our properties but also within our supply chain supplies themselves.

Hilton operates a rather unique procurement function, doesn’t it?  

PF: “We trade off the Hilton name because our brand strength is something that we are able to utilise and we’re very proud of, but we’ve also got additional leverage by having that group procurement model.

“We’ve got essentially two clients. We’ve got our managed estate which is when an owner chooses to partner with Hilton, they’re signing a management agreement because they want the benefit and value of the Hilton engine. That could be revenue management, how we manage onboarding clients and customers through advertising, as well as the other support we give in terms of finance, HR, marketing and sales as well as procurement.”

HSM is a profit centre and revenue driver through its group procurement model but how does this work?

PF: “Our secret sauce is our culture. It’s our people and that filters across all of our team members and indeed all of our functions. The key strategic pillars are the same for health and supply management around culture, maximising performance and so on as they are across the overall global business.

“Across our 7,000 plus hotels, the majority are actually franchised hotels because that’s the legacy of what still is the model in the US. When I joined Hilton 12 and a half years ago, the reverse is true where nearly all of our hotels in Europe, Middle East and Africa, and indeed in Asia Pacific, were and are managed. In the Europe, Middle East and Africa regions right now we’re building up close to a 50/50 split between managed, leased and franchised.”

What has pleased you most about the roll-out of the HSM?

PF: “It’s certainly not been easy because we’ve got 70 countries that sit within our region here in EMEA and Hilton’s penetration in those individual countries is very different. We may have 100 hotels in one of those markets and only one or two in specific countries. Our scale and our ability to get logistics solutions is different by market.

“Getting everyone on board to what we want to achieve to our guests and to our owners means we have to pull different levers. We have very effective brand standards. If you’re signing up to Hilton, you’re signing up to delivering against those brand standards that we believe are right for our organisation.”

What kind of feedback have you had from your clients? 

PF: “Integrity is in our DNA, and we work very closely with our suppliers who we value as partners. These are long-term relationships, and we work hand in hand because we have to see that they’re successful so that we can be successful – it’s really important to what we do and we constantly look for feedback.

“With our internal and our external customers, we’ll have quarterly business reviews and so we’ll get that feedback through surveys where we are asking them to tell us what we do well and what we could do better. Our partners are now asking what additional value can you do to bring support to our organisation through ESG? So that’s what’s on the table now when it wasn’t before. But it’s not just that – it’s about the security of supply competitiveness, competitiveness of pricing, and a whole bunch of other very important things as well.”

Looking to the future, what’s on the agenda for the next few years?

PF: “We’re out there meeting and greeting people in person and there’s always new opportunities that make things exciting in what we do and how we work. Innovation’s very high on our agenda and we’re very proud of what we do in food and beverage. In non-food categories, it’s about how we support our owners and our hotel general managers to find that competitive edge and do the next big thing ahead of our competitors.”

Anything else important to know?

PF: “One thing we’ve been able to take full advantage of is how we’ve been able to grow our business by bolting on new customers. I think it’s fantastic that our competitors choose to use Hilton Supply Management because they benchmarked what our capabilities are and how competitive we are.

“Another key part of the agenda is environmental, social and governance (ESG) sustainability. Responsible sourcing and everything that sits within that is front and centre of what we do. Within that you’ve got human rights, animal welfare, single use plastics as well as general responsible sourcing like managing food waste. The list is very long, but they’re all very important.”

Check out the latest issue of CPOstrategy Magazine here.

Here are 10 of the most important leadership skills that CEOs need to demonstrate in 2023.

In today’s world, a CEO needs to be lots of things to different people. The importance of having the leadership skill to being able to lead through unprecedented disruption was highlighted by the COVID-19 pandemic and helped to define what makes a good CEO.

Here are 10 of the most important leadership skills that CEOs need to demonstrate in 2023.


1. Clear communication

Communicating effectively with employees is one of the most vital skills any leader can have. By adopting a transparent mindset, it leaves little room for miscommunication or misunderstandings. But rather than just being eloquent, CEOs should deliver meaningful content too. A CEO needs to be able to communicate the essence of the business strategy and the methodology for achieving it.

2. Strong talent management strategy

People are the most important component of all businesses. CEOs who are able to recruit and retain key employees have a greater chance of increasing productivity and efficiency. After recruiting good people, the key to retaining them is by harnessing a positive work environment that empowers employees to succeed.

3. Decision-making

As a leader, thinking strategically to make effective decisions is vital to the success of an organisation. Making decisions is a key part of leadership as well as having the conviction to stand by decisions or agility to adapt when those decisions don’t have the required outcome. While all decisions might not be favourable, making unpopular but necessary calls are important characteristics of a good leader.

4. Negotiation

Negotiation is a fundamental part of being a CEO. In a top leadership position, almost every business conversation will be a negotiation. Good negotiations are important to an organisation because they will ultimately result in better relationships, both with staff inside the company and externally. An effective leader will also help find the best long-term solution by finding the right balance and offering value where both parties feel like they ‘win’.

5. Creativity and innovation

Being quick-thinking and ready to explore new options are great skills of a CEO. Creative leadership can lead to finding innovative solutions in the face of challenging and changing situations. It means in the midst of disruption, of which it has been increasingly prevalent, leaders can still find answers for their teams. Creative CEOs are those who take risks and empower employees to drop outdated and overused practices to innovate and try new things that could lead to greater efficiency.

6. Agility

Without agility over the past few years, businesses would have failed. CEOs were forced to embrace remote working following the advent of the COVID-19 pandemic whether they liked it or not. Now, faced against a potential recession, these macroeconomic events are unavoidable and have to be managed carefully. Effective leaders will have their fingers on the pulse and ready to respond to changes.

7. Strategic forecasting

Creating a clear path forward is essential to achieving uninterrupted success. The ability to look into the future and identify trends and issues to then react to is vital. Good CEOs are able to plan strategically and make informed decisions to set goals and plan for the future easily.

8. Delegation

CEOs can’t do everything. A leader tends to be pulled in a number of different ways every day and it is impossible to be on top of everything. This means the importance of bringing in a team of people who are trusted and skilled in their respective areas of expertise. Successful CEOs are expert delegators because they recognise the value of teamwork and elevating those around them.

9. Approachability

An approachable CEO who welcomes conversation and is an active listener will help employees feel at ease raising issues or concerns. This approach will help build strong relationships with staff and customers and encourage a healthy culture which is beneficial to employee retention. Leaders with strong, trusting and authentic relationships with their teams know that investing time in building these bonds which makes them more effective as a leader and creates a foundation for success.

10. Growth mindset

If a CEO arms themselves with a growth mindset it allows them to meet challenges head-on and evolve. This shines a light on improving through effort, learning and persistence. As others may back down in the face of adversity and upheaval, successful CEOs will strive to move forward with confidence. Those with a growth mindset are unlikely to be swayed as they have the tools needed to reframe challenges as opportunities to grow.

In McKinsey’s latest report ‘Actions the best CEOs are taking in 2023’, we examine three of the biggest trends on the c-level agenda

Anyone can sail a ship when things are going well. But it takes a strong, robust and characterful CEO to steer a business through choppy waters and out the other side.

In McKinsey’s latest report ‘Actions the best CEOs are taking in 2023’, the research and advisory firm uncovered which trends are set to have the biggest impact on how CEOs lead their business throughout the year.

McKinsey’s CEO Excellence Survey surveyed 200 of the best corporate CEOs of the past 15 years. This was completed by whittling down a list of all the current and former CEOs of the 1,000 largest public companies during that timeframe. The list was subsequently filtered based on tenure, including only those who had completed at least six years in the role. From there, the CEOs were continuously shortlisted until the best 200 were determined.

Each CEO was asked to identify the top three trends that are set to determine how leaders tackle the future. Here is an insight into those findings.

1. Actions to deal with digital disruption

CEOs are targeting digital trends in three key ways: developing advanced analytics, enhancing cybersecurity and automating work. OpenAI’s launch of ChatGPT has accelerated the demand of companies looking to embrace advanced analytics for a competitive advantage. Improving cybersecurity is another key action for CEOs with the importance of guarding against external threats paramount amid strengthening and more mature cyberattacks. Lastly, automating work is another key priority to scale efficiency and eliminate boring and manual tasks which free up people’s time.

2. Actions to deal with the risk of high inflation and economic downturn

One CEO who is worried about economic uncertainty told McKinsey: “Act early to lower costs and protect the balance sheet so that you are stronger and leaner when the economy begins to turn more favourably.” McKinsey found that companies that outperformed the 2008 financial crisis cut operating costs by 1% before the downturn while the others expanded costs by the same percentage. The best performers reduced their debt by $1 for every $1 of book capital before the downturn. This can be done by reducing operating expenses, redesigning products and services as well as reassessing strategic and economic assumptions.

3. Actions to deal with the escalation of geopolitical risk

According to McKinsey, there are three actions to help manage the escalation of global and national crises. CEOs are targeting building robust compliance capabilities, creating resilience in supplier networks and investing in monitoring and response capabilities. These actions come following the challenges presented by COVID-19, the war in Ukraine and now inflation concerns. Many firms are choosing to build their trade compliance organisations and improve how they screen different customers and companies. While a defensive approach is the way forward for many, some companies see the turbulent times as an opportunity.

What does today’s CEO need to do to accelerate an organisation’s digital transformation journey?

Digital transformation journeys are no one-size-suits-all. There is no singular way to welcome a new wave of technology into operations.

Since the turn of the century, digitalisation has had an increasingly influential impact on the way CEOs make decisions. Today’s world is full of disruption and potential risk. And with technology growing in complexity it can be challenging to lead such a revolution against a backdrop of economic uncertainty.

Embracing digital

According to KPMG 2022 CEO Outlook, which draws on the perspectives of 1,325 global CEOs across 11 markets, 72% of CEOs agree they have an aggressive digital investment strategy intended to secure first-mover or fast-follower status.

Advancing digitalisation and connectivity across the business is tied (along with attracting and retaining talent) as the top operational priority to achieve growth over the next three years. This digital transformation focus could be driven as a result of increasingly flexible working conditions and greater focus on cybersecurity threats.

However, the prospect of recession is threatening to halt digital transformation in the short-term. KPMG research found that four out of five CEOs note their businesses are pausing or reducing their digital transformation strategies to prepare for the anticipated recession.

This is reinforced further when 70% say they need to be quicker to shift investment to digital opportunities and divest in those areas where they face digital obsolescence.

When a company’s digital transformation ambition is mismatched to its readiness, it is the CEO’s responsibility to close the gap. According to Deloitte, in order to do this successfully, the CEO must assess the current level of organisational readiness for change.

This covers four key pillars that are mixed together to work out an organisation’s overall readiness: leadership, culture, structure and capabilities.

How CEOs can close the gap

Leadership: CEOs need to ensure their c-suite and other key executives are motivated and equipped to execute the vision. CEOs interviewed by Deloitte in a recent study emphasised the importance of the leadership team supporting the transformation vision and having a positive attitude and willingness to transform.

Culture: A large potential barrier to readiness in the organisation is down to culture. Low cultural readiness takes the form of bureaucratic, reactive and risk-averse ways of working that are at against the collaborative, proactive learning mindset needed for ambitious transformation.

Structure: If a company hopes to operate differently, it could mean the need for organising in an alternative way. CEOs will often need to lead the reorganisation of teams, assignment of new roles, revision of incentives, strategies to collapse organisational hierarchies or layers to increase agility.

Capabilities: CEOs need to equip their organisation with four key capabilities to harness digital for a superior capacity for change. These are nimbleness, scalability, stability and optionality which are often enabled or supercharged by digital technologies which are critical factors for competing in an increasingly disrupted world.

For now, one of the CEOs most important roles when steering the ship through disruption is to be ahead of the latest trends and tackle change head-on. By embracing a new digital future that will provide the company with long-lasting benefits, it will help create a brighter and future-proofed firm for years to come even after the CEO is gone.

Gartner surveyed 400 senior business leaders about the challenges faced and their priorities for 2022-23. We analysed the results

Priorities change in a business; they evolve all the time to match the societal landscape around them. Following a major worldwide disruption like the COVID-19 pandemic, it’s no surprise that the focus for CEOs has shifted to match the way our outlooks and challenges have changed.

Gartner surveyed 400 senior business leaders about their 2022-23 priorities and found that – for the first time – environmental sustainability has made its way into the top 10. Additionally, workforce issues are a bigger priority than ever before.

Mark Raskino, VP Analyst at Gartner, said of the results: “In 2022, the Gartner CEO and Senior Business Executive Survey showed that, catalysed by multiple macro trends and economic factors, business leaders are reprioritizing some key areas of enterprise purpose and management focus.”

The last time there was such a dramatic change in the priorities of CEOs was in 2009-10, during the recovery from the last major recession. Here, we’ll dig into the key challenges for CEOs in 2023…

Growth

While growth remains the primary challenge, with 51% of respondents stating that it’s in their top three priorities, it’s actually down 8% from 2021-22. Gartner has surmised that the reason for this is that, due to ongoing supply chain disruptions, business leaders are less focused on driving up demand if they don’t necessarily know whether they can supply. Many organisations are working hard to revamp and improve their supply chains, but uncertainty remains and nobody wants to make promises that they can’t keep.

Gartners top 10 strategic business priority areas for 2022-2023

Technology

Technology has also dropped slightly as a top three priority, though it remains the second biggest focus at 34%. While the survey respondents are 5% less concerned about tech-related issues than in 2021-22, it’s still hugely important – especially as the world recovers from the pandemic.

Many businesses have taken the pandemic as a sign that they need better digitalisation, as a lack of that made the transition to home working difficult for some. Additionally, cybercrime is a major concern, especially when ensuring employees have the hardware and software they need to work safely from multiple locations.

Workforce

A focus on the workforce is up 32% from 2021-22, putting it at 31% in third place. This is the second consecutive year that workforce has become more of a priority, and there are multiple reasons for this.

Attracting and retaining employees is a challenge because older generations are retiring and there aren’t always enough replacements for specific roles. Plus, the younger generations joining the workforce are more likely to align themselves with businesses they truly believe in, meaning they are more picky, so organisations have to be the best they can and transparent with it.

Additionally, diversity, equality, and inclusion are bigger focuses than ever, and these have been boosted by the spotlight being shone on such topics during the pandemic. All in all, almost half (49%) of CEOs agreed with the statement that ‘it is very difficult for us to find and hire the kind of people we need in our business’.

Corporate

At 29%, corporate has dipped only a little since 2021-22 – just 5% – and remains a top priority. Corporate includes company structure and culture changes, and this is a focus right now due to the challenges of employee retention, as well as the drive towards digitalisation. Corporate change is required to improve business efficiency and performance, hence its position on this list.

Financial

The financial side of business has decreased in importance to CEOs for 2022-2023, dropping by 27% since 2021-22. However, it’s still in the top three for 20% of respondents. CFOs are making a major push towards finance transformation through technology to boost efficiency in their departments. Despite the ongoing challenge of building digital competencies in finance, 82% of CFOs have reported that their investments in digital are accelerating and exceeding investments in many other areas.

Products & Services

Products and services remain in the top three spot for 15% of respondents, up 43% from 2021. As the world recovers from the pandemic, the products and services a business produces are in the limelight. Competition is more fierce than it’s ever been, so innovation is key to remain in the best position.

Customer

The customer as a priority is up 26% from 2021-22, at 15% – and it’s no surprise. Linking into products and services, and the challenge of hiring the latest generation of workers, costumers have very high standards and hard work is required to impress them and retain loyalty.

In a Gartner survey about customer service trends, 74% of respondents stated that improving operational excellence to create a seamless customer journey is either ‘important’ or ‘very important’, and the survey found that business growth is best achieved through positive customer experience outcomes.

Environmental sustainability

Nine per cent of respondents to the Gartner survey stated that environmental sustainability is a top three priority – up a huge 292% from 2021-22. This is the first time it’s broken into the top 10, which is telling. Businesses are increasingly under pressure to do more when it comes to their own environmental impact. Many leading nations are aiming to be carbon neutral within the next few decades and being more sustainable undeniably leads to growth.

ESG

Cost

Also at 9% is cost, which is actually down 24%. Despite it being less of a concern than in 2021-22, cost remains a major focus. Supply chain shortages and the government support offered to help people through lockdowns have driven inflation, and Russia’s invasion of Ukraine has made that worse. As a result, we’re seeing the prices of products from the region shoot up, and those cost increases inevitably become the problem of business leaders.

Sales

While it’s number 10 (6%) on Gartner’s list of priority areas, sales is a 77% bigger priority in 2022-2023 than it was in 2021-22. Sales falls into a similar category to cost; with rising inflation comes an inability for customers to spend as freely as they once may have, making the landscape more competitive. Having said that, as we touched on with growth, sales aren’t necessarily being driven to the same degree due to supply chain disruptions.

Sara Malconian, Chief Procurement Officer at Harvard University & Jim Bureau, CEO of JAGGAER explain how ESG & the Circular Economy is changing the evolution of procurement.

We speak to Sara Malconian, Chief Procurement Officer at Harvard University and Jim Bureau, CEO of JAGGAER to see how ESG and the Circular Economy is changing the evolution of procurement…

Sara, how have you seen your role evolve as a procurement leader over the years as ESG and supplier diversity come into focus? 

Procurement leaders have gone from ‘cost cutters’ to ‘problem solvers’ within their organisations. Our core mandates used to be to drive cost savings and efficiency. We were hyper-focused on getting the most out of the organisation’s spend and supplier relationships. Those priorities haven’t gone away, especially in today’s inflationary environment, but the expectations of the procurement function are significantly higher and broader today. 

Procurement functions saved their companies during COVID and the confluence of disruptions that followed. We showed we are a strategic linchpin. We are now looked upon to drive value and impact and strategically guide our organisations to achieve broader goals, including diversity and environmental, social, governance (ESG). Internal stakeholders realised the benefits of procurement and sought help with advancing their department’s agendas or solving their challenges. We listen to their needs, allocate the right resources, and ultimately enable them and the overall organisation to be successful.  

I’ve been in procurement for over 20 years, and I can honestly say you’d be hard-pressed to find a more rewarding and exciting career. Procurement professionals have a real opportunity to make a tangible difference within their organisations, communities, and the world through the way we source products and services. 

What is Harvard doing to have a positive impact on society? Can you share some examples, Sara?

Across the Harvard community, students, alumni, faculty, and staff are advancing scholarship and teaching on the world’s most significant challenges, and everyone wants to do their part to address inequities. Supplier diversity and inclusion have been a priority for Harvard for years, but we wanted to make even more of an impact and really invest in the growth and development of diverse businesses, especially as the pandemic highlighted inequities and disparities within our communities.

In 2021, we formed the Office for Economic Inclusion & Diversity (OEID), which is dedicated to reaching out to diverse suppliers, giving them opportunities, and providing them with tools, training, and resources to be successful. The office also encourages the use of underrepresented business enterprises (UBEs) in the purchasing of all goods, services, and construction at Harvard and standardises procurement practices with these businesses across the university. 

We’re proud of the work this office is doing. We’re actively training suppliers on Harvard’s policies and how they can work with us. We’re creating a central location for them to access bid and RFP opportunities. UBEs can also apply to be mentored by Harvard Business School students.

We’ve created a dashboard to track and analyse spend with diverse suppliers across all of Harvard’s schools and measure progress over time. Everything we’re doing is aimed at increasing spend with our existing diverse suppliers, as well as the number of diverse suppliers that work with Harvard, and helping these suppliers grow their businesses.

Jim, why is prioritizing ESG and supplier diversity important and what steps can companies take today to progress in their journey? 

Beyond being the right thing to do, investors, boards, regulators, customers, and employees now expect organisations to prioritise ESG and diversity initiatives and walk the talk. There’s also a clear business impact. Supplier diversity drives competitive bidding processes that lead to cost savings. Working with partners who are sustainable and have different ideas and perspectives fuels innovation and creates a competitive advantage. Sourcing from a sustainable and diverse supplier pool also reduces risk by broadening organisations’ access to multiple resources for various materials, products, and services. 

One of the most critical steps companies can take to progress on their ESG journey is to make it clear to suppliers that environmentalism is a priority for their organisation. They will attract suppliers with higher levels of ESG maturity and provide suppliers who are earlier on in their ESG journey with sustainability toolkits and training to help educate them on eco-friendly best practices and sustainability innovations.

This step avoids having to overhaul their supply chain to account for ESG. Strategically managing suppliers by leveraging third-party data, scorecards, and supplier audits are crucial for understanding the ESG risks that suppliers pose and minimizing disruptions by working with them to correct these issues. 

Successful supplier diversity programs start with a top-down culture shift. If a company’s culture isn’t diverse, inclusive, and supportive for all its stakeholders, they won’t be able to drive supplier diversity in a meaningful way. Supplier diversity strategy should map back to company goals and include an executive-level champion to sponsor the program internally and help bring in the resources they need.

Outside of leveraging technology to identify diverse suppliers and build a program, businesses can talk with people who have been in their shoes. They can collaborate with like-minded companies at industry events, engage in relevant LinkedIn groups, and connect with organisations such as the National Minority Supplier Development Council.

Once diverse suppliers are on board, organisations can create a supplier diversity policy that clearly outlines how many diverse suppliers need to be invited to bid for each event to ensure teams are executing on the strategy. Leading supplier diversity programs go beyond simply spending with diverse suppliers to providing mentorship and training them on how to respond to RFPs correctly, as well as creating environments where it’s easier for them to engage. 

Jim, what role does technology play in helping organisations achieve ESG and supplier diversity goals?

Technology is a key enabler of ESG and supplier diversity initiatives. One of the biggest obstacles to supplier diversity and ESG is a lack of reliable supplier data. Suppliers don’t always keep their information up to date in self-service portals. The data procurement teams have isn’t always enriched to the level they need, with insights on diversity status, certifications, and proof of ESG compliance.

Researching and assessing suppliers is tedious and time-consuming, which leads many organisations to skip the verification step. Without this information, organisations don’t have a true picture of the inclusivity and sustainability of their supplier network, which makes it impossible to identify the right partners to source from to meet their ESG and supplier diversity goals and make an impact.

Technology addresses this challenge by automatically collecting, enriching, validating, and integrating the supplier data needed to obtain this level of supply base visibility and make decisions that drive ESG and diversity. AI-powered tools are available to match buyers with specific diverse suppliers who also have the capabilities to help drive ESG objectives and meet broader procurement criteria.

Software that segments the supply base and helps visualise spending with small and diverse suppliers across a variety of classifications is critical for setting benchmarks and measuring progress and ROI. 

Jim and Sara, how do you expect the ESG and diversity conversation to shift and where should procurement leaders focus for the future?

Sara: I expect we’ll see the conversation shift to emphasise measurement. It’s not enough anymore to say you’re committed to ESG – you need to prove it and show demonstrable progress and ROI. Maintaining the momentum on ESG initiatives is hard. Technology is key for setting benchmarks and goals, ensuring accountability for hitting key milestones, and measuring progress and return in a credible way. 

Jim: In a declining economic environment, choices inevitably need to be made. I expect the conversation around ESG will center around where companies can focus to maintain progress on ESG initiatives as financial and economic pressures come to the forefront. While some companies may need to scale back in some areas to preserve cash and resources to navigate a downturn, I’d advise them to be careful about slowing ESG down too much as it will be much harder to catch up to current levels after the economy bounces back.

I’d argue that when ESG is done right it can be a strategic lever for navigating a down economy, saving organizations money and resources, driving innovation, and helping them achieve broader business objectives and resilience. 

Here are five of the biggest procurement events happening during 2023 that chief procurement officers won’t want to miss.

Procurement Futures 


London, UK  |  1-2 February 2023 

Held at the QEII Centre in central London, Procurement Futures is a new conference, launching in 2023. It promises delegates the chance to find out how to make supply chains more resilient, with thought-provoking and presentations and discussions designed to inform and inspire.

There is a flexible programme of content that can be tailored to attendees’ preferences, with networking opportunities throughout and a huge variety of sessions to attend and take part in.

This CIPS event has three streams of content: Insights, Ignite and Interact. Insights will showcase presentations and panel discussions from leaders, Ignite will consist of hands-on workshops to help delegates optimise their procurement strategies and Interact will be smaller groups taking part in interactive roundtables and debates.

Speakers across the two days will include Ross Grierson, Director of Procurement, Primark; Patrick Dunne, Director of Group Property, FM & Procurement (CPO), Sainsburys Plc; Rebecca Simpson, Procurement and Supply Chain Director, Balfour Beatty; and Nick Jenkinson, Chief Procurement Officer, Santander. In addition, delegates are ablew to book a one-to-one career workshop, where they’ll get advice on professional development from coaches covering a variety of specialisms. 

Tickets are £795 for CIPS member, £995 for a non-member and £2240 for a supplier/solution provider, and there is a discount of 30% for tickets purchased before 30 November 2022. 


3rd World Digital Procurement Summit 


Berlin, Germany  |  2-3 March 2023 

The third World Digital Procurement Summit is aimed at procurement directors, VPs, managers and other industry specialists. The two-day event will focus on accelerating procurement processes, adopting emerging technologies, finding the right talent, overcoming the barriers to progress and embarking on a journey of transformation. It’s a hybrid event, bringing together procurement experts from various industries, which will maximise knowledge exchange opportunities. The event organisers list five key learning points for delegates: 

  1. Exploring the latest advances in data and cognitive technologies to gain greater insights and improve procurement processes 
  1. Overhauling the procurement ecosystem with new technologies and strategies to drive business value 
  1. Sharing the best practices of monitoring and managing a range of risks to hedge against future disruptions 
  1. Developing capabilities and skillset required for the digital transformation of procurement 
  1. Defining ESG metrics of the procurement strategy to ensure business continuity 

Speakers will include Paul Harlington, Group Procurement Director at TUI Group and Patrick Foelck, Head of Strategy and Transformation Procurement at Roche. 

Click here to check out a video from a previous event. Tickets cost €1495. 


Women in Procurement & Supply Chain 


Sydney, Australia  |  6-8 March 2023 

Returning for its 8th annual event, Women in Procurement & Supply Chain will deliver two days dedicated to leadership and the future of procurement. The event will feature a series of exclusive panel discussions and keynote addresses examining career development, overcoming imposter syndrome, working with confidence, developing an unbeatable talent pool, mentoring, diversity and inclusivity.

It will also address risk mitigation, digital disruption, ESG, sustainability, economic development, ethical sourcing, category management, cultural diversity, strategic sourcing, supplier relationships, procurement with purpose, and supply chain resilience. There are two pre-conference masterclass options on 6 March – that can be booked separately – covering either contract law or leadership skills. 

Some of the reasons to attend include: 

  • Discover the path to taking your procurement career to a new level while elevating your organisation with dedicated days on leadership and the future of procurement 
  • Learn best practice strategies to facedown supply chain vulnerabilities and reduce risk exposure 
  • Get ahead of the game with insights into the future of procurement and the impact of globalisation on modern supply chains 
  • Put yourself at the cutting edge of ESG and procurement with the latest updates and trends in procurement with purpose 

Speakers for the main two-day conference include Michelle Richard, Director of Procurement, Thales; Karina Davies, Chief Procurement Officer, icare NSW; and Kylie McKinlay, Procurement Partner – Property and Business, Australian Broadcasting Corporation. 

Tickets start at $3,495 with discounts available until 25 November 2022. 


Americas Procurement Congress 


Miami, USA  |  21-22 March 2023 

The Americas Procurement Congress will feature the region’s most progressive CPOs sharing their expertise

With a focus on what makes CPOs tick, the Americas Procurement Congress will feature the region’s most progressive CPOs sharing their expertise in keynote presentations and working groups.

Giving delegates the tools to stay on the cutting edge of procurement developments, there are also sessions aimed at those with responsibilities over governance, procurement capabilities and quantifying data. Unsurprisingly, sustainability will also be a key theme in 2023, and attendees will hear from a diverse range of sustainability leaders about how to transition from traditional metrics to a purpose-driven function. 

The agenda for Americas Procurement Congress 2023 will include: 

  • Sustainability of the future  
  • How to transition from traditional metrics to a purpose-driven function   
  • Harnessing the power of digital transformation  
  • Utilizing data as a driver of sustainable value, supply continuity and transparency   Agile procurement  
  • New approaches and skills that facilitate speed and agility   
  • Frictionless procurement  
  • Removing friction from the procurement process to support high-velocity sourcing   
  • Beyond Just in Time 
  • Designing future-fit supply networks for an age of chaos and conflict 

Tickets start at $3649. 


Americas Procurement Congress 


Orlando, Florida  |  8–10 June 2023 

Gartner Supply Chain Symposium/Xpo 2022 addressed the most significant challenges that chief supply chain officers and supply chain leaders face as they mitigate risk and navigate uncertainty in an increasingly dynamic and challenging environment.  

At the conference, the top 5 sessions that CSCOs and supply chain leaders met on included: 

  • Signature Series: The Future of Supply Chain 
  • What the Pivot to Sustainable Profit Means for Procurement Leaders 
  • The Art of the New Age One Page Dashboard: Why Your Current Perfor-mance Measures May Be Doing More Harm Than Good 
  • Manage Supplier Risk With Technology 
  • Procurement Role Redesign: Stop Fitting Square Pegs Into Round Holes 

Tickets start at $4725. 

CPOstrategy’s cover star this month is procurement transformation expert, and CEO and Co-Founder of Tropic, David Campbell…

Right now, procurement excellence is blooming. Experts determined to create change are coming to the fore and aligning procurement with SaaS to bring an end to the do-it-yourself way of working that decimates technology budgets. Tropic is one such game-changer, providing the tools to navigate software procurement’s complexities for competitive advantage.

Read the latest issue here!

The CEO and Co-Founder of Tropic is David Campbell, a born entrepreneur. He grew up on a cattle ranch in California and has always had at least one side-hustle on the go. Even as a child, he was running some form of money-making venture at any one time – but he didn’t necessarily consider that entrepreneurial pursuits were his calling until later.

CEO and Co-Founder of Tropic, David Campbell
CEO and Co-Founder of Tropic, David Campbell

Campbell studied English at UC Berkeley, and on graduating assumed he’d go into the arts. He’s a lifelong musician and writer, and he moved to a cabin in the woods to write the ‘next great American novel’. This venture, while it didn’t have the exact results he had hoped for, planted the seed in his mind that perhaps entrepreneurialism was for him because he loved setting his own hours and vision, creating a strategy, and executing that…

Elsewhere, we have exclusive interviews with supply chain and procurement leaders at the City of Edmonton and QSC, as well as the results of our first Sustainable Procurement Champions Index. We also have some exciting news from DPW too, ahead of its conference later this month.

Enjoy the issue!