A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Bibby Financial Services

Building Safe and Secure Business Strategies to Combat Cyber Threats

Kam Karaji

Kam Karaji, the Chief Information Security Officer (CISO) at Bibby Financial Services, is known for his expertise in cyber security.  With over a decade of experience as a decorated former Police Officer and Commander, Kam’s expertise is unrivalled. He excels in developing and executing cutting-edge cyber security to protect the company’s sensitive data, which is unbeaten. His eminent career has also been published in the New York Times and the Wall Street Journal. He is an award-winning speaker at conferences and events and an accomplished author of several influential cybersecurity publications. His innovative strategies for protecting organisations against the constantly changing landscape of cyber threats have established him as a highly regarded expert in the industry.

In an interview with CIOReview, Karaji emphasises the cybersecurity strategies that align with business objectives and strengthen overall business resilience.

Navigating Transparency and Digital Security Challenges

I’ve been associated with Bibby Financial Services for over two years, during which we encountered significant challenges, primarily stemming from a lack of transparency with the board. There was an evident absence of clear communication about our forthcoming milestones and the appropriate framework to adopt. During this period, the company was transitioning from traditional, paper-based processes to digital solutions. This shift aimed to enhance efficiency and customer experience, marking a significant advancement. However, it was imperative to establish a robust security framework to support this digital transformation effectively.

From Cyber Metrics to Key Risk Indicators

Cyber resilience has become pivotal, particularly in understanding how a business can sustain operations post-cyberattack. In a cyber incident that disrupts operations, critical questions arise—What are the next steps for recovery? How can we continue supporting our customers and most crucially, how swiftly can we restore business operations to minimise impact? To address these concerns, we shifted our focus from traditional cyber metrics to Key Risk Indicators (KRI) that provide more concrete, business-aligned insights. For instance, in the case of a ransomware attack, KRI would detail the attack path, response timeline, recovery costs and potential commercial losses, equipping the board with a clear understanding of the tangible risks and required actions.

The company also leverages various AI applications to enhance business efficiency. However, there is a lack of explicit guidance on protecting the sensitive data in these applications’ processes. There is a pressing need for clear policies that specify what types of data can be entered into AI systems and the safeguards that must be implemented. Without these policies, there is a significant risk of misusing AI or exposing sensitive information, jeopardising our operations and client relationships.

Building a Resilient Cybersecurity Framework

We developed our cybersecurity strategy around three core pillars—people, process and technology. Security was viewed as a once-a-year comprehensive plan, which failed to maintain employee engagement throughout the year. To address this, we introduced the 3S strategy—Smart, Safe and Secure.

‘Smart’ focuses on educating employees about phishing emails and distinguishing typical from atypical attack paths. ‘Security’ should be an ingrained behaviour, integrated into the organisational culture rather than seen as a sporadic effort to be ‘safe.’

At Bibby Financial Services, while existing policies were in place, they lacked actionable steps and defined consequences for non-compliance. For instance, although there were guidelines on safely using the internet and commercial laptops, there was no clarity on the repercussions of visiting unauthorised websites or installing unapproved software. This oversight presented significant risks, particularly for a financial institution. To remedy this, we enhanced accountability by clearly defining employee responsibilities and the consequences of non-adherence. By integrating actionable steps with HR and board alignment, we reinforced accountability and strengthened compliance.

Technology’s effectiveness hinges on people. We established a Security Operations Center (SOC) to monitor and manage threats and vulnerabilities. Detected threats are fed back into our incident management process, which actively involves our team, sustaining a dynamic cycle of people, process and technology working in unison. We have implemented technical controls, such as CIS IG1 and IG2 and regularly conduct penetration testing to validate these measures. This ensures our security controls are effective and allows us to promptly rectify any vulnerabilities, maintaining the integrity of our cybersecurity framework.

"There is a pressing need for clear policies that specify what types of data can be entered into AI systems and the safeguards that must be implemented. Without these policies, there is a significant risk of misusing AI or exposing sensitive information, jeopardising our operations and client relationships"

Implementing Robust Cybersecurity Measures

While we already had PCI DSS in place and initially did not see the necessity for ISO 27001 or SOC 2, we recognised deficiencies in our technical security controls. To address these gaps, we developed a three-year roadmap to implement CIS IG1 and IG2 standards and initiated the preliminary steps toward IG3. A critical element of IG2 was enhancing our detection and response to cyber incidents, including isolating affected endpoints while ensuring business continuity. This was facilitated by establishing our Security Operations Center (SOC), which is pivotal in achieving our strategic milestones.

Regarding risk management, our approach to cyber risk was previously integrated within the IT risk register, without a dedicated cyber risk team. The primary concerns outlined in the register included business ownership, revenue and customer retention. To enhance our risk management strategy, I took two significant steps. I established a dedicated cyber risk register, separate from the IT register, which provided clearer visibility to the board and helped prioritise cyber risks more effectively. Then, I extended tabletop exercises to include the board, not just our technical teams. These exercises demonstrated the potential impacts of underinvestment in critical areas. As a result of these concerted efforts, cyber risk has now been elevated to the highest priority within the risk register of our parent company.

Advice for Aspiring Cybersecurity Professionals

Cybersecurity forms the backbone of any business, transcending mere skill to embody a behaviour. It involves conveying the threats and risks to the board, enabling them to understand and commit to necessary investments.

Regular check-ins and presentations on prevented threats are crucial, highlighting the proactive efforts of the cybersecurity team. This comprehensive understanding across the organisation elevates everyone to the role of a vigilant observer, helping to identify and mitigate risks before they escalate. Such a culture fosters accountability and positions cybersecurity as an essential business priority. This transparency is not just a practice but a pathway leading the business toward sustained success and momentum.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
Top