Financial institutions can avoid becoming the next victim of a costly cyberattack by leveraging automation and existing legislation.
Automation can help to mitigate risk when handling personal client information by storing records efficiently and securely, Kayne McGladrey, senior member of professional association for electronics engineers IEEE and field chief information security officer at Hyperproof, told Bank Automation News.

“If you don’t automate, that has a cost, because now people are spending their time doing control testing,” he said. “The organizations that recognize that are going to probably spend a lot less time on compliance and have a happier team, because they’re not doing routine stuff that they should have automated.”
There have been 2,084 ransomware complaints reported to the FBI so far this year, an increase of 62% year over year with an average cost of $5.7 million to resolve, according to an IBM report.
RPA to block spam bots
KeyBank, for one, is working toward automation security using robotic process automation (RPA) to block outside bots using its own bots to reduce fraud and fake transactions.
Additionally, banks can reevaluate their respective cybersecurity frameworks by looking at existing legislation, according to McGladrey.
“[Banks] should be considering looking at formal cybersecurity control frameworks, like the Center for Internet Security’s critical security controls, or the NIST cybersecurity framework,” he told BAN. “Most U.S.-based financial institutions should be looking at New York Department of Financial Services section 500. It’s otherwise known as the cybersecurity regulation, but that should be looked at as part of a larger program to improve cybersecurity.”
Part 500 of New York Codes, Rules and Regulations (NYCRR) details financial services requirements and helps protect nonpublic information of a covered entity, including customer social security numbers and their biometric records. This can help shield personal information from cybercriminals with a blueprint for how banks can remain steadfast against incoming cyberthreats.
“About two-thirds of the requirements that are in there are mapped directly to controls that are inherently built into those other two frameworks [NIST and critical security controls],” McGladrey said.
Banks and financial institutions “should look into automated control tests” as part of compliance operations to guarantee they are continuously secure, rather than being secure at the point a test was run, he added.






