Connect with us

Hi, what are you looking for?

HEADLINES

Banking industry needs to upgrade security, competencies – UCPB’s Joey Regala

As cyber threats targeting financial institutions become more sophisticated and coordinated, there is a need to beef up cyber security to fend off attacks in banks where the money is. This is according to Joey Regala, president of Information Security Officers Group (ISOG) and VP and head of IS Operations at United Coconut Planters Bank, during the ISOG Summit.

ISOG President Joey Regala (fourth from left) with other ISOG directors

As cyber threats targeting financial institutions become more sophisticated and coordinated, there is a need to beef up cyber security to fend off attacks in banks where the money is. This is according to Joey Regala, president of Information Security Officers Group (ISOG) and VP and head of IS Operations at United Coconut Planters Bank, during the ISOG Summit.

ISOG President Joey Regala (fourth from left) with other ISOG directors

ISOG President Joey Regala (fourth from left) with other ISOG directors

“Your money is what we’re trying to protect from unauthorized access, disclosure, destruction, multiplication, inspection, recording and deduction,” said Regala, who discussed the current state of the financial industry and how information security officers (ISOs) protect banks and the money in it.

Regala said they, as security officers, focus on minimizing risk by implementing and maintaining a defense mechanism across network infrastructure to secure users’ information, systems, networks as well as money.

“Currently, we’re using the defense in-depth security strategy. We defend your money through a series of different levels of defenses such as fiscal layers, network layers, application layers, and so on and so forth,” said Regala.

They use different levels of defenses so that in case one defense fails, there are others that can still secure the money in banks.

However, since they have been using this strategy for quite sometime, Regala stressed that as information security officers, “we believe we need to upgrade our defense.”

Advertisement. Scroll to continue reading.

The signature-based detection is another strategy to protect banks. Regala said this instrument is based on a certain footprint or signature of a file and in case there is no signature, it can compromise the system.

Aside from these defense strategies that secure operations of banks, Regala admits that the banking industry needs to upgrade competencies of its people in order to meet the requirements of the industry especially now that hackers are more intelligent and threats are more sophisticated.

“Admittedly, we have lack of skills but we have skilled people. We do need to upgrade our competencies,” said Regala. “People in the banking industry are competent but as the hacking or as the vulnerability increases, the competency should be parallel or we should align with the needs. That’s what we are seeking.”

Regala said they can solve this by engaging people to promote a web of trust in the finance industry; by establishing the right standard and equipping people not only with right competencies but also with tools, equipment, firewalls, and so on; and by collaborating with anti-cybercrime groups.

With the rise in sophisticated threats, Regala disclosed that the new breed of hackers has information asset as its new denomination. These assets consist of identity data – card number, account number, ATM number, information of a person and credentials.

Advertisement. Scroll to continue reading.

“They don’t steal money but they can steal something that can be used as an instrument to get the money,” said Regala. “As people update security, hackers will also upgrade their attacks. They are impatient and they are no longer hooded.”

Because of this new breed of hackers, Regala is warning people to be more vigilant, more conscious and be aware of the threat.

“You should be aware because you are the endpoint, you are the victim. You are the weakest link to our security chain and this is the new concern of information security,” said Regala. “Before, we just defend. Now, the advance way of defending your turf is going beyond. We’ll be using more sophisticated tools and process all activities through their behavior. This is now the culture of information security.”

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

HEADLINES

Password guessing and valid account misuse rank among the most effective tactics used by cyber criminals in 2025. This trend reflects a strategic shift,...

Advertisement