In this Weekly Wrap episode of “The Buzz” podcast, the Bank Automation News editors drill down on what Russia’s threats to retaliate against U.S. sanctions could mean for the banking industry.
BAN spoke with experts who agree: Financial services companies, particularly regional banks, in the U.S. should be on heightened alert as cyberattacks are likely as the war on Ukraine escalates. To prepare, check out BAN’s list of 33 questions every banker should ask ahead of potential cyberwarfare.
Other news this week comes from the bank technology space, with SoFi’s acquisition of core banking platform Technisys for $1.1B in stock. The BAN team also discusses the Biden administration’s plans to increase anti-corruption regulations in financial services.
Tune in for a discussion of these topics and what’s ahead in today’s episode of the Weekly Wrap with BAN Deputy Editor Loraine Lawson and Associate Editor Alijah Poindexter for the week ended Feb. 25, 2022.
Bank Automation Summit, taking place March 1-2 in Charlotte, N.C., is the first and only event to focus solely on automation in banking. The event will feature the brightest minds from across financial services on intelligent automation strategies and deployment. Learn more and register here for Bank Automation Summit 2022.
Subscribe to The Buzz Podcast on iTunes, Spotify, Google podcast, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Hi, everyone, I’m Deputy Editor Loraine Lawson. And welcome to the Buzz from Bank Automation News, where we explore how automation and emerging technology is transforming the banking industry. It is February 25, 2022. And this is our Weekly Wrap of what’s happening. First, I’d like to say thank you to our sponsor, Glia for your support as always, this week, I’m pleased to be joined by Associate Editor Alijah Poindexter. The first thing that’s happening, obviously, is the Russian invasion of the Ukraine, which has led to cyber attacks in the Ukraine against banks and other institutions. Alijah, we both talked to cybersecurity experts this week. And they were unanimous in saying this invasion and the promised retaliation against sanctions that the US has imposed, could mean financial to, or should mean that financial institutions in the US should be on high alert. Well, who did you speak to? And what did you learn?
Yes, Loraine, so I had a chance to speak with Tari Schreider. I believe I’m pronouncing that correctly, we had an awesome conversation. He’s He’s a strategic cybersecurity adviser of the Aite-Novarica Group. You know, in our conversation yesterday, it was about 18 hours after the news broke. But you know, while the news was incredibly fresh, and getting constant updates, his insights were amazing. And they gave gave certainly gave me a lot to think about firstly, you know, that these Russian hackers, they have options, this is this is not a one size fits all strategy, where there will be a few ransomware attacks against big banks, the banks are going to adjust and then the ransomware attacks will settle down, it’s not going to be like that at all. Not only is the threat of ransomware, you know, going to nearly double for the foreseeable future of it, you’re gonna see DDoS attacks, which we’ve already seen in the Ukraine, and then we’ve seen retaliatory attacks against Russia from, you know, whoever. But we have seen that, you’re also going to see living off the land attacks where these hackers infiltrate the bank’s organizational network, and they start sort of attacking internal processes and programs and sort of a sneak attack. And then on the employee side, it’s extremely significant. It could be as simple as a hacker breaking or you know, taking control over a remote workers computer cutting off access to the bank and the back logging every single bit of data that’s on the remote workers computer back to wherever the hackers want it to go. Secondly, is the fact that for banks, you know, cybersecurity is only going to be as good as the cyber and the tech that you have underpinning it. And underpinning your underpinning your organization’s, you know, for these hulking tier one and tier two banks and institutions and fin servs, who have had contact with members of the Treasury, and they have the money in the tech to shore up their defenses, you know, quite honestly, they don’t have much to worry about, you know, yes, the attacks are likely, but the mitigation is equally as likely. But, you know, for the 5000, or more community banks in the US, along with their service, and tech providers, and core vendors and stuff, hackers are going to clue in and attack. So you know, you’ll find out more of my story today, but just quite frankly, the time to ramp up defenses for the majority of local, regional and national, you know, community banks in the US and the service providers. The time is yesterday.
Loraine Lawson
Yeah, look, I was speaking today with the University of Georgia Associate Professor Dave Chatterjee, and he’s in the department and is and is the author of Cybersecurity Readiness, a Holistic and High Performance Approach. He also runs a podcast called cybersecurity readiness. I asked him if people tended to underestimate the sophistication of attackers from countries such as Russia. And he shared this interesting story. He said, he’d spoken with the leader of a company, not a big but a big company. And it was breached in a ransomware attack. And he had to, they had to pay the ransom. But the group that they had ransom, the data, had to promise they would not sell the data, which is happening, hackers are selling this data online, we have seen banks that have data in the dark web for sale. And I’m not sure those banks know that. But anyway, they did promise that and he said the CFO CEO had relayed that they are very true to their promise, if you pay them, they keep their word, and they don’t mess with your data. But the second interesting comment that the CEO made was that their customer support service is as good as it gets. So think about that. They have a customer service, and it’s really good. So that tells you these are not small operations.
Alijah Poindexter
Now, look, these hackers are nothing to underestimate, especially in a circumstance, like what we’ve seen over the past, you know, 48 or 72 hours, many of the tactics and strategies that these hackers are using, they’re not new, I mean, these are dating back to the late 2000s, specifically 2008, when Russian ransomware and DDoS. And other attack methods played a key role in the Russian the Russian Georgian conflict that we saw, I mean, they quite literally nearly took over the country. And a key factor to that were their cyber attack strategies. Just recently, we can look at elections, we can look at the hacking of politicians, we can look at public release of sensitive information. You know, these hackers are not they’re not interested in a credit card number. They’re not in interested in taking out a fraudulent loan for a new car or a pair of shoes. They’re not interested in releasing your search history on Facebook that these are highly advanced, highly organized, and quite frankly, brilliant cyber warfare actors who are acting on behalf of a national entity. And I think this is going to and analysts agree this is going to surprise a whole lot of people in the next few weeks.
Loraine Lawson
Yeah, one of the things Chatterjee and I talked about is that a lot of organizations have outsourced their security, which sounds fine. But ultimately, these are supporting your mission critical apps. And you know, have we shifted from a place where it’s not good enough to outsource security where it is mission critical. We also talked about you talked about, you know, the sophistication, I think there’s this tendency for people in general to view cyber attacks as like a natural event like, Oh, we got attacked, what can you do, it can be done, but that’s not going to be acceptable anymore. As these attacks ramped up, you know, they have organizations have warning they know they’re coming. It’s time to get real about security, I think. So be sure to check out a legit story today and bake automation news. And we’re also going to publish a list of questions every Baker should be asking ahead of potential cyber warfare. Be sure to check that out today as well. Now, it’s hard to believe there was other news this week, but there was including news that sofa is acquiring the core banking platform technosys for 1.1 billion in stocks, it will operate as a subsidiary of so fi and technosys co CEO told us that there are future integration plans with Sophos other subsidiary Galileo, and they’ll sort of act together as a service provider to fintechs and banks, much like AWS does. He also said that Technics is taking the size data on other banks will be kept separate from Sofi. Elijah, you published a podcast with Daniel hazle, Head of Customer Lifecycle Management and intelligence automation, FinTech workfusion. And you looked at what the Biden administration plans to do to increase anti corruption, financial services, what sort of new money anti money laundering regulations might we see in corporate Biggie cryptocurrency?
Alijah Poindexter
Yeah, so first off this announcement and the ensuing strategy, this occurred late last year, this occurred in December. And one thing that I think is important to note is that this is an awesome win for the Biden ministration. Just from a public relations point of view, you know, Mr. Hazel, he was quick to point out that pretty much any type of you know, effort to to increase cybersecurity and to increase anti money laundering to increase the Insure up the defenses of financial security is always welcome, and will always give you a win in the public sector. But in terms of actual you know, sort of nitty gritty technical details, you’re going to see one increased transparency for banks, both here and abroad. So these sort of obscure corporate structures where money can get passed along can kind of blend into the background, this is gonna be a move in the right direction from that perspective. Another thing US courts, they now have expanded powers of subpoena against foreign banks. So this, of course, is going to weigh extremely, extremely heavily on the minds of any bad agents that are out there in the AML space. And finally, on the crypto side, there’s going to be a newly formed crypto task force of sorts, I use that term. You know, I use that pretty lightly, but a task force which is going to help the DOJ investigate a misuse of crypto digital assets and crypto exchanges. So you know, for some more, for deeper details, definitely check out the podcast. But yeah, definitely some interesting stuff there learning.
Loraine Lawson
You know, Chatterjee told me this was interesting, I thought to bring it back to our original conversation. There actually, he said, like, in one state, there was like 70 or 80 bills file that related to cybersecurity and issues like this. And they’re just not seeing the light of day right now. So it’s interesting to see, you know, regulations that are and are moving ahead, but I think if we see a big attack, we will see more regulations that will see the light of day, I won’t get vetoed in the Committee stage. So readers Be sure to check out all of our content, as well as alleges podcast which is on iTunes, Spotify or transistor and of course bank automation news.com Next week, we’ll be at the bank automation Summit, which is March 1 through second in Charlotte, North Carolina. Join us as we explore real world business use cases and the technologies that are helping automate business processes for better efficiencies and improve customer experience. You can learn more about the bank automation summit at Bank automation summit calm meanwhile, for more podcast content, check out bank automation news and search the buzz from big automation news on Spotify and iTunes.
In this Weekly Wrap episode of “The Buzz” podcast, the Bank Automation News editors drill down on what Russia’s threats to retaliate against U.S. sanctions could mean for the banking industry.
BAN spoke with experts who agree: Financial services companies, particularly regional banks, in the U.S. should be on heightened alert as cyberattacks are likely as the war on Ukraine escalates. To prepare, check out BAN’s list of 33 questions every banker should ask ahead of potential cyberwarfare.
Other news this week comes from the bank technology space, with SoFi’s acquisition of core banking platform Technisys for $1.1B in stock. The BAN team also discusses the Biden administration’s plans to increase anti-corruption regulations in financial services.
Tune in for a discussion of these topics and what’s ahead in today’s episode of the Weekly Wrap with BAN Deputy Editor Loraine Lawson and Associate Editor Alijah Poindexter for the week ended Feb. 25, 2022.
Bank Automation Summit, taking place March 1-2 in Charlotte, N.C., is the first and only event to focus solely on automation in banking. The event will feature the brightest minds from across financial services on intelligent automation strategies and deployment. Learn more and register here for Bank Automation Summit 2022.
Subscribe to The Buzz Podcast on iTunes, Spotify, Google podcast, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Hi, everyone, I’m Deputy Editor Loraine Lawson. And welcome to the Buzz from Bank Automation News, where we explore how automation and emerging technology is transforming the banking industry. It is February 25, 2022. And this is our Weekly Wrap of what’s happening. First, I’d like to say thank you to our sponsor, Glia for your support as always, this week, I’m pleased to be joined by Associate Editor Alijah Poindexter. The first thing that’s happening, obviously, is the Russian invasion of the Ukraine, which has led to cyber attacks in the Ukraine against banks and other institutions. Alijah, we both talked to cybersecurity experts this week. And they were unanimous in saying this invasion and the promised retaliation against sanctions that the US has imposed, could mean financial to, or should mean that financial institutions in the US should be on high alert. Well, who did you speak to? And what did you learn?
Yes, Loraine, so I had a chance to speak with Tari Schreider. I believe I’m pronouncing that correctly, we had an awesome conversation. He’s He’s a strategic cybersecurity adviser of the Aite-Novarica Group. You know, in our conversation yesterday, it was about 18 hours after the news broke. But you know, while the news was incredibly fresh, and getting constant updates, his insights were amazing. And they gave gave certainly gave me a lot to think about firstly, you know, that these Russian hackers, they have options, this is this is not a one size fits all strategy, where there will be a few ransomware attacks against big banks, the banks are going to adjust and then the ransomware attacks will settle down, it’s not going to be like that at all. Not only is the threat of ransomware, you know, going to nearly double for the foreseeable future of it, you’re gonna see DDoS attacks, which we’ve already seen in the Ukraine, and then we’ve seen retaliatory attacks against Russia from, you know, whoever. But we have seen that, you’re also going to see living off the land attacks where these hackers infiltrate the bank’s organizational network, and they start sort of attacking internal processes and programs and sort of a sneak attack. And then on the employee side, it’s extremely significant. It could be as simple as a hacker breaking or you know, taking control over a remote workers computer cutting off access to the bank and the back logging every single bit of data that’s on the remote workers computer back to wherever the hackers want it to go. Secondly, is the fact that for banks, you know, cybersecurity is only going to be as good as the cyber and the tech that you have underpinning it. And underpinning your underpinning your organization’s, you know, for these hulking tier one and tier two banks and institutions and fin servs, who have had contact with members of the Treasury, and they have the money in the tech to shore up their defenses, you know, quite honestly, they don’t have much to worry about, you know, yes, the attacks are likely, but the mitigation is equally as likely. But, you know, for the 5000, or more community banks in the US, along with their service, and tech providers, and core vendors and stuff, hackers are going to clue in and attack. So you know, you’ll find out more of my story today, but just quite frankly, the time to ramp up defenses for the majority of local, regional and national, you know, community banks in the US and the service providers. The time is yesterday.
Loraine Lawson
Yeah, look, I was speaking today with the University of Georgia Associate Professor Dave Chatterjee, and he’s in the department and is and is the author of Cybersecurity Readiness, a Holistic and High Performance Approach. He also runs a podcast called cybersecurity readiness. I asked him if people tended to underestimate the sophistication of attackers from countries such as Russia. And he shared this interesting story. He said, he’d spoken with the leader of a company, not a big but a big company. And it was breached in a ransomware attack. And he had to, they had to pay the ransom. But the group that they had ransom, the data, had to promise they would not sell the data, which is happening, hackers are selling this data online, we have seen banks that have data in the dark web for sale. And I’m not sure those banks know that. But anyway, they did promise that and he said the CFO CEO had relayed that they are very true to their promise, if you pay them, they keep their word, and they don’t mess with your data. But the second interesting comment that the CEO made was that their customer support service is as good as it gets. So think about that. They have a customer service, and it’s really good. So that tells you these are not small operations.
Alijah Poindexter
Now, look, these hackers are nothing to underestimate, especially in a circumstance, like what we’ve seen over the past, you know, 48 or 72 hours, many of the tactics and strategies that these hackers are using, they’re not new, I mean, these are dating back to the late 2000s, specifically 2008, when Russian ransomware and DDoS. And other attack methods played a key role in the Russian the Russian Georgian conflict that we saw, I mean, they quite literally nearly took over the country. And a key factor to that were their cyber attack strategies. Just recently, we can look at elections, we can look at the hacking of politicians, we can look at public release of sensitive information. You know, these hackers are not they’re not interested in a credit card number. They’re not in interested in taking out a fraudulent loan for a new car or a pair of shoes. They’re not interested in releasing your search history on Facebook that these are highly advanced, highly organized, and quite frankly, brilliant cyber warfare actors who are acting on behalf of a national entity. And I think this is going to and analysts agree this is going to surprise a whole lot of people in the next few weeks.
Loraine Lawson
Yeah, one of the things Chatterjee and I talked about is that a lot of organizations have outsourced their security, which sounds fine. But ultimately, these are supporting your mission critical apps. And you know, have we shifted from a place where it’s not good enough to outsource security where it is mission critical. We also talked about you talked about, you know, the sophistication, I think there’s this tendency for people in general to view cyber attacks as like a natural event like, Oh, we got attacked, what can you do, it can be done, but that’s not going to be acceptable anymore. As these attacks ramped up, you know, they have organizations have warning they know they’re coming. It’s time to get real about security, I think. So be sure to check out a legit story today and bake automation news. And we’re also going to publish a list of questions every Baker should be asking ahead of potential cyber warfare. Be sure to check that out today as well. Now, it’s hard to believe there was other news this week, but there was including news that sofa is acquiring the core banking platform technosys for 1.1 billion in stocks, it will operate as a subsidiary of so fi and technosys co CEO told us that there are future integration plans with Sophos other subsidiary Galileo, and they’ll sort of act together as a service provider to fintechs and banks, much like AWS does. He also said that Technics is taking the size data on other banks will be kept separate from Sofi. Elijah, you published a podcast with Daniel hazle, Head of Customer Lifecycle Management and intelligence automation, FinTech workfusion. And you looked at what the Biden administration plans to do to increase anti corruption, financial services, what sort of new money anti money laundering regulations might we see in corporate Biggie cryptocurrency?
Alijah Poindexter
Yeah, so first off this announcement and the ensuing strategy, this occurred late last year, this occurred in December. And one thing that I think is important to note is that this is an awesome win for the Biden ministration. Just from a public relations point of view, you know, Mr. Hazel, he was quick to point out that pretty much any type of you know, effort to to increase cybersecurity and to increase anti money laundering to increase the Insure up the defenses of financial security is always welcome, and will always give you a win in the public sector. But in terms of actual you know, sort of nitty gritty technical details, you’re going to see one increased transparency for banks, both here and abroad. So these sort of obscure corporate structures where money can get passed along can kind of blend into the background, this is gonna be a move in the right direction from that perspective. Another thing US courts, they now have expanded powers of subpoena against foreign banks. So this, of course, is going to weigh extremely, extremely heavily on the minds of any bad agents that are out there in the AML space. And finally, on the crypto side, there’s going to be a newly formed crypto task force of sorts, I use that term. You know, I use that pretty lightly, but a task force which is going to help the DOJ investigate a misuse of crypto digital assets and crypto exchanges. So you know, for some more, for deeper details, definitely check out the podcast. But yeah, definitely some interesting stuff there learning.
Loraine Lawson
You know, Chatterjee told me this was interesting, I thought to bring it back to our original conversation. There actually, he said, like, in one state, there was like 70 or 80 bills file that related to cybersecurity and issues like this. And they’re just not seeing the light of day right now. So it’s interesting to see, you know, regulations that are and are moving ahead, but I think if we see a big attack, we will see more regulations that will see the light of day, I won’t get vetoed in the Committee stage. So readers Be sure to check out all of our content, as well as alleges podcast which is on iTunes, Spotify or transistor and of course bank automation news.com Next week, we’ll be at the bank automation Summit, which is March 1 through second in Charlotte, North Carolina. Join us as we explore real world business use cases and the technologies that are helping automate business processes for better efficiencies and improve customer experience. You can learn more about the bank automation summit at Bank automation summit calm meanwhile, for more podcast content, check out bank automation news and search the buzz from big automation news on Spotify and iTunes.




