AIRLINK 73.00 Decreased By ▼ -2.16 (-2.87%)
BOP 5.35 Decreased By ▼ -0.10 (-1.83%)
CNERGY 4.31 Decreased By ▼ -0.08 (-1.82%)
DFML 28.55 Increased By ▲ 0.91 (3.29%)
DGKC 74.29 Increased By ▲ 2.29 (3.18%)
FCCL 20.35 Increased By ▲ 0.06 (0.3%)
FFBL 30.90 Decreased By ▼ -0.15 (-0.48%)
FFL 10.06 Increased By ▲ 0.09 (0.9%)
GGL 10.39 Increased By ▲ 0.12 (1.17%)
HBL 115.97 Increased By ▲ 0.97 (0.84%)
HUBC 132.20 Increased By ▲ 0.75 (0.57%)
HUMNL 6.68 Decreased By ▼ -0.19 (-2.77%)
KEL 4.03 Decreased By ▼ -0.17 (-4.05%)
KOSM 4.60 Decreased By ▼ -0.17 (-3.56%)
MLCF 38.54 Increased By ▲ 1.46 (3.94%)
OGDC 133.85 Decreased By ▼ -1.60 (-1.18%)
PAEL 23.83 Increased By ▲ 0.43 (1.84%)
PIAA 27.13 Decreased By ▼ -0.18 (-0.66%)
PIBTL 6.76 Increased By ▲ 0.16 (2.42%)
PPL 112.80 Decreased By ▼ -0.36 (-0.32%)
PRL 28.16 Decreased By ▼ -0.59 (-2.05%)
PTC 14.89 Decreased By ▼ -0.61 (-3.94%)
SEARL 56.42 Decreased By ▼ -0.91 (-1.59%)
SNGP 65.80 Decreased By ▼ -1.19 (-1.78%)
SSGC 11.01 Decreased By ▼ -0.16 (-1.43%)
TELE 9.02 Decreased By ▼ -0.12 (-1.31%)
TPLP 11.90 Decreased By ▼ -0.15 (-1.24%)
TRG 69.10 Decreased By ▼ -1.29 (-1.83%)
UNITY 23.71 Increased By ▲ 0.06 (0.25%)
WTL 1.33 Decreased By ▼ -0.01 (-0.75%)
BR100 7,434 Decreased By -20.9 (-0.28%)
BR30 24,206 Decreased By -44.4 (-0.18%)
KSE100 71,359 Decreased By -74.1 (-0.1%)
KSE30 23,567 Increased By 0.5 (0%)

Events over past six weeks have exposed cyber threats to Pakistan’s digital payments infrastructure. Issued last week, the central bank’s specific guidelines on digital payment security are a belated, but much-needed awakening. A lot more needs to be done. To start with, Pakistani state needs to recognize that organised cyber crimes, especially of the financial kind, pose a direct threat to national security.

In the wake of the recent breach, there is confusion over where the buck stops. The SBP is the banking custodian. But its mandate covers reducing financial risk and ensuring business continuity – not fighting off cyber threats in particular. Globally, central banks like the Federal Reserve and the Bank of England regularly issue guidelines on cyber security and take steps to ensure compliance, but they are not responsible for or expected to reduce cyber thefts in the broader environment.

So who is in charge? It was in 2007 when the Pakistani state decided to fight cyber crimes in an organised manner, through a ‘National Response Centre for Cyber Crimes’ (NR3C). The institution chosen to house NR3C was the Federal Investigation Agency (FIA), which falls under the Ministry of Interior. (Countries such as the US, France and India have housed their cyber-security wings under their Interior/Homeland ministries; the UK, however, opted for a military umbrella in its GCHQ directorate).

But the NR3C may be ill-equipped to fight organised cyber crime, especially of trans-national nature. Its current mandate is really broad – covering cyber crimes (hacking, cyber bullying/stalking, data/identity theft, financial fraud, denial of service attacks, etc.) and providing forensic services (computer/ mobile/video forensics, network forensics and technical training).

And as the name suggests, NR3C is a reactive organisation that mostly “responds” to cyber crimes, often undertaken by individuals and small groups. Even there, a complaint’s journey through “enquiry” to “case” to “prosecution” to “conviction” to “arrest” is terribly slow. A different, “cross-sectional” setup is required to proactively focus on reducing “systemic risk” arising from a spectrum of “organised” cyber crimes.

Until that happens, the banking regulator has, between the lines, made it clear it won’t be made a scapegoat. As differences emerged last month between FIA and SBP over how to reduce banking system’s cyber exposure, the SBP officials reportedly told FIA officials that “the ultimate responsibility for IT security rests with the board of directors and the senior management of the banks/DFIs”.
https://www.dawn.com/news/1445665

For the matter in question, digital payments security, it is the responsibility of the banks to boost their IT capabilities and secure their customers’ deposits and trust. (In the coming days, this column will analyze the likely impact of the SBP’s recent payment security rules on the banking and IT industries). But that alone will not cut it in the absence of an effective cyber-coordination mechanism among the state’s financial, telecoms, judicial and law enforcement authorities.

Copyright Business Recorder, 2018

Comments

Comments are closed.