FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

Federal cybersecurity agency warns RPA use may increase attacks

Bots often have unfettered IT access, security expert says

Loraine LawsonbyLoraine Lawson
January 11, 2022
in Risk & Security
Reading Time: 3 mins read
0
Share on Facebook

The Cybersecurity and Infrastructure Security Agency (CISA) last week issued a brief that warns of potential cyberattacks in the manufacturing sector due to increased use of robotic process automation (RPA), a threat that also extends to financial institutions. The federal agency is a division of the U.S. Department of Homeland Security.

US cybersecurity agency warns RPA use may increase attacks
Image by CanStock

Today, a CISA spokesperson confirmed to Bank Automation News that the potential security threat extends to all critical infrastructure owners and operators, including those in the financial services sector.

The warning came “in light of persistent and ongoing cyber threats,” the spokesperson said. It’s part of the government’s broad effort to encourage “critical infrastructure owners and operators to take immediate steps to strengthen their defenses against potential malicious attacks.”

Previously “air-gapped” or offline processes that are now online using RPA for remote management may create a path for cyberattacks, according to the CISA brief. For banks and credit unions, that means cloud and automation could present cybersecurity risks, if not properly governed.

The agency recommends retraining RPA operators on new processes and implementing secure connectivity to control robots, or bots.

The CISA brief notes that “Industry adoption of RPA helps ensure business continuity during the ongoing pandemic, yet cybersecurity threats identified by CISA complicate RPA uptake.” “Without developing secure automation, the benefits of RPA on future scenarios may be negated by increased vulnerability to cyberattacks.”

However, while CISA’s brief does not cite specific incidents or threats, it more broadly addresses the potential for RPA to be leveraged in attacks.

Bot governance can limit RPA vulnerabilities

Cyberattacks in any industry could leverage RPA software to gain access to networks and data, Justin Estadt, head of product at SEI Sphere and a 20-plus-year veteran of IT security, told BAN.

“When we look at RPA with what we’re doing, and how it theoretically functions and what it’s supposed to do, it’s really no different than any of the other aspects that you’d want to design for or have a policy around when you’re talking in respect to technology, software, or properties or platforms,” Estadt said. “So that’s the good news — that the procedures and policies that you already have in place can be leveraged.”

The question is whether those policies are in place for bots, which often have privileged accounts with wider access than IT might give to humans. Bot governance can address this issue.

FIs should avoid letting bots loose without any restrictions, Karen Reichle, bot expert at RPA company Nintex, told BAN. She spoke with one bank that had done just that, and recommended bot governance as one way to ensure it doesn’t happen. An attacker who gains access via a bot vulnerability could theoretically do anything they want, Estadt said, citing a bot “automation malfunction” at Amazon Web Services in December that affected a wide range of Amazon offerings, including Roombas, Netflix and Amazon deliveries.

“You want to make sure that you are fully watching what that RPA system has access to,” he said. “That would include assuming it only has the minimum rights that it needs to perform its job.”

If a bot needs to be able to read from a database, it should only be able to read that specific table, he said. “It should be, again, the bare minimum. Don’t give it anything more than what it needs.”

Bot governance is simple when there are a few bots, but as institutions deploy more, they tend to skip this precaution, Estadt said. “We see that pretty often though, with RPA, that people just grant administrative privileges across the board because it’s easier for them to make the function work.”

Granting only the required access can be time-consuming, but, he added, “that’s a very important level of effort based on risk.”

Bank Automation Summit, taking place March 1-2 in Charlotte, N.C., is the first and only event to focus solely on automation in banking. The event will feature the brightest minds from across financial services on intelligent automation strategies and deployment. Learn more and register for Bank Automation Summit 2022.

Tags: bot governancePremiumRPAU.S. Cybersecurity and Infrastructure Security Agency (CISA)
Previous Post

Listen: Real-time payments pose real-time fraud risk

Next Post

Bank of America launches cash-forecasting tool for businesses

Related Posts

humans and AI work together to pinpoint risk and suspicious activity
Risk & Security

Retaining the human component as AI combats fraud

July 28, 2026
a digital grid superimposed over a globe
Risk & Security

AI finding twice as many cyber flaws in 2026 as it did in 2025

July 27, 2026
uipath
Risk & Security

Inetco launches agentic AI fraud investigation tool

July 24, 2026
Next Post
Bank of America Launches Cash-Forecasting Tool for Businesses

Bank of America launches cash-forecasting tool for businesses

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account