Connect with us

Financial News

The Balancing Act of Financial Organizations to Compete in a Technology-Driven World

Published

on

Written by: Ricardo Ferreira, EMEA Field CISO, Fortinet

Digital acceleration is impacting how we work, live, and consume services. In addition, the digital evolution of Financial Services Organizations (FSOs) raises essential questions about the future of banking. One looming concern is how FSOs will compete against fintechs, including addressing the need for innovation to improve customer experience.

Ricardo Ferreira, EMEA Field CISO at Fortinet

Adapt to changing times

The top three strategic areas outlined in the IDC Infobrief, sponsored by Fortinet, “Accelerating Transformation Through Cybersecurity in Financial Services,” highlight the core priorities for financial institutions: Trust, Security, and Resilience. So, the question is, how can FSOs lead and win through innovation while ensuring that risks do not overwhelm a traditionally risk-averse industry?

Many FSOs have begun adopting new digital business models to help them thrive in a digital-first economy. These include prioritizing investments in key areas such as data-driven security, legacy modernization, and personalized and contextual customer experiences. But for these business models to work, they will need to rely on data, analytics, and cloud platforms.

So, when we ask, “what does success look like for the future-ready bank?” we see three major themes:

  • Automation and cost reduction: Automation, managed services, and cloud platforms will enable FSOs to innovate faster. Automation allows business units to integrate with the rest of the organization, build self-service, and reduce manual labor costs, such as adopting Robotic Process Automation and artificial intelligence-powered chatbots to deal with insurance claims. In investment banking, robot advisors use machine learning-powered algorithms to help retail investors make better decisions. Thanks to cloud platforms and managed services, these new products and services are economically feasible because they shift traditional CapEx to activities that create more value.
  • Customer intelligence and centricity: New platforms provide data and analytics for anticipating customer needs and hyper-personalizing the customer journey. Customer data, such as investment patterns, can guide a robot advisor to recommend portfolio choices aligned to customer preference. Similarly, natural language processing can help an AI system quickly assess a customer’s issue to redirect them to the nearest branch or get the appropriate representative involved.
  • New value propositions: Open banking was a massive change for banks, helping them realize the power of APIs. Building Banking as a Service (BaaS) has allowed them to develop new services and create stronger partnerships.

But what about the customer experience?

Who is not irked when reminded of their first troubled mobile banking experience, with terrible UX and lack of integration? It’s why, when some fintechs launched their online mobile banking, it was a beacon of light in a dark room. A real-world security example that everyone might remember was the usage of biometrics for accessing online mobile banking. Big brands took a long time to adopt it, and while it might seem trivial from a UX perspective, it’s leaps and bounds towards progress.

Today, traditional brands regularly launch products that emulate offerings from nimbler fintech organizations. The lesson is clear: to gain a competitive advantage, banks must focus on creating a fast, intuitive, and seamless customer experience.

Are clouds grey in banking?

These business models require the accelerated consumption of new platforms, such as cloud computing. Financial organizations must understand they can create differentiated value and increase competitiveness by using the cloud to increase their speed of innovation and accelerate the go-to-market of new services and products.

Cloud platforms also serve as a bridge to modernize financial organization workloads. CIOs want to migrate workloads cohesively while ensuring the capabilities from their on-prem solutions are still available. Major Cloud Service Providers (CSPs) have jumped at the opportunity to integrate their environments into the same control plane.

Yes, but isn’t that risky?

Regulators have flagged the concentration risk. For example, the Bank of England has highlighted it in their stability reports. The latest Financial Conduct Authority (FCA) PS21/3 rules address third-party risk and operational resilience. And the European Union has gone a big step beyond with its Digital Operational Resilience Act (DORA).

All these activities and proposals are designed to address these concerns. The European Systemic Risk Board has flagged cyber as a systemic risk to the European financial system due to the increase in cyberattacks—especially in the financial industry, which is 300 times more likely to be the target of cyberattacks. The International Monetary Fund (IMF) emphasizes that cyber events propagate risk through the entire financial system via three broad transmission channels: risk concentration, risk contagion, and erosion of confidence.

That is why cybersecurity is a priority as part of the EU’s “Europe fit for the digital decade” policy program. Programs such as EU-HYBNET, ACCORDION, and DORA for financial services ensure Europe works as a single entity by harmonizing requirements to increase resilience and protect citizens.

What can financial organizations do about it?

To start, security needs to be woven into transformation efforts to ensure that innovation and transformation are conducted securely. For this to work, security must be included from a project’s inception, not as a bolt-on after a project and its services are launched.

What about protecting financial assets?

55% of European financial organizations already use some form of zero-trust strategy for their authorization and authentication. Zero-trust shifts the traditional paradigm from the implicit trust for users and resources inside a static, network-based perimeter to an authentication model that focuses on users, assets, and resources. Zero-trust requires authentication and authorization to be performed every time access is granted to a specific resource.

How do we address the ‘weakest link’ problem?

While people are an organization’s most critical asset, they are also the primary source of data breaches and network compromise. Organizations must be prepared for a loss of control if their workforce is not educated on cyber awareness. Some large financial organizations have created partnerships with e-learning portals and vendors to provide tailored courses using nudges and financial instruments to reskill the workforce with new technologies. Similarly, financial organizations must plan to mitigate the rampant cybersecurity skills shortage, which will impact 90% of organizations by 2025, resulting in delays in the transformational journey.

What can we do?

Digital acceleration is essential for competing in today’s financial marketplace. However, it doesn’t come without risk. First, ensure employees are trained and reskilled in the organization’s technologies. Second, share data with industry peers to learn best practices and identify potential issues. Transaction Monitoring Netherlands (TMNL) is an excellent example of transaction data sharing to mitigate Anti-Money Laundering (AML).

Finally, work with vendors and partners committed to cross-vendor openness and integration. When vendors work together across the threat landscape, the sum of their products is greater than the individual parts, deepening your level of cyber protection.

Financial

Al Ansari Exchange Partners with RTA Dubai to Offer nol Travel Cards

Published

on

Al Ansari Exchange, the UAE’s leading remittance and foreign exchange company and a subsidiary of Al Ansari Financial Services PJSC (DFM: ALANSARI), has partnered with Dubai’s Roads and Transport Authority (RTA) and in association with MDX Technology Solutions ME, to make nol Travel Cards available at selected branches across Dubai.

The collaboration broadens Al Ansari Exchange’s portfolio of third-party products and extends access to Dubai’s integrated mobility payment system through the UAE’s largest branch networks. It also reflects the company’s strategy of building a connected physical and digital ecosystem that provides customers with convenient access to a wider range of everyday financial and lifestyle services.

Residents and visitors can now purchase nol Travel Cards from selected Al Ansari Exchange branches, distributed through MDX Technology Solutions ME, the RTA-authorised distributor of nol Travel Cards, providing an additional point of access to one of Dubai’s most widely used mobility payment solutions.

The nol Travel Card enables cashless payments across Dubai’s public transport network, including the Dubai Metro, Dubai Tram, public buses, marine transport and public parking. It is also accepted at more than 14,000 retail outlets across the UAE. Through the nol Pay App, cardholders can access more than 200 lifestyle offers and discounts.

Commenting on the collaboration, Musad Ibrahim Alhammadi, Director of Automated Collection Systems at Corporate Technology Support Services Sector, Roads and Transport Authority (RTA), said: “Expanding the availability of nol Travel Cards through strategic collaborations supports RTA’s efforts to make mobility services more accessible across Dubai. Providing additional distribution channels contributes to wider adoption of digital payment solutions and enhances the travel experience for residents and visitors.”

Ali Al Najjar, Chief Executive Officer of Al Ansari Exchange, added: “As customer expectations continue to evolve, we are expanding the role of Al Ansari Exchange beyond traditional financial transactions by bringing together financial, payment and everyday lifestyle services through both our branch network and digital platforms. Making nol Travel Cards available through our branches complements our broader strategy of creating a seamless customer experience while supporting Dubai’s vision for a smart, digitally connected city.”

Continue Reading

Financial

The rights you think you have: five legal stress tests for a more resilient business

Published

on

Resilience is not only about cash reserves, backup servers or alternative suppliers. It also depends on whether a company’s legal rights and permissions still work when the business is under pressure.

By: Maroun Abou Harb, Associate at BSA LAW

Resilience is discussed as an operational or financial discipline. Businesses test liquidity, back up systems and diversify supply chains. Yet every continuity plan rests on legal infrastructure: licenses, delegated authorities, contracts, data permissions, employment arrangements, security rights and evidence.

That infrastructure can fail when needed most. The replacement supplier cannot be appointed without third-party consent. Customer data cannot lawfully be moved to the backup provider. An insurance claim is compromized by late notification. A guarantee was signed incorrectly. The company owns a platform, but not all of its intellectual property.

The most dangerous legal risk is not the missing clause. It is the right management assumes the business has, but cannot use.

In the UAE, the Central Bank’s 2026 Operational Risk Management Regulation now requires licensed financial institutions to implement a comprehensive operational risk and resilience proecedure. The principle is valuable for every company: identify what must continue, locate the legal points of failure and test them before disruption does.

  1. Can the business lawfully act?

Start with corporate authority, check that licenses match actual activities, constitutional documents reflect the ownership and governance structure, and beneficial-owner, shareholder and director records are accurate. Review reserved matters, signing matrices, powers of attorney and banking mandates.

A deal, borrowing or emergency payment can stall because the authorized signatory is unavailable, a power has expired or an approval threshold was misunderstood. Group companies should confirm which entity employs people, owns assets, contracts with customers and receives revenue.

Run this scenario: if the chief executive and chief financial officer were unreachable tomorrow, who could bind the company, access its accounts and appoint an alternative supplier? If the answer is uncertain, the business has a legal single point of failure.

  • Which contracts become dangerous under stress?

Most contract reviews examine value and liability. A resilience review asks a different question: what happens when performance is interrupted?

Build a heat map of critical customer and supplier contracts, ranked by operational importance and consequence of failure. For each, test termination and suspension rights, force majeure and change-in-law provisions, service levels, price-adjustment mechanisms, liability caps, indemnities, insurance, governing law and dispute forum, subcontracting, assignment and change-of-control restrictions. Check notice methods and cure periods; a valuable right can disappear if a notice is sent late or to the wrong address.

Then examine optionality, can the company use a replacement supplier, obtain transition assistance, retrieve its data in a usable format and continue using essential intellectual property? Is there a source-code escrow or step-in mechanism where appropriate?

The aim is not to renegotiate every contract. It is to know which five contracts could stop the business and to fix those first.

  • Can technology fail without the legal part failing too?

A technical recovery plan is incomplete if the contracts do not support it. Cloud, payment, telecommunications and managed-service arrangements should align promised recovery times with the company’s tolerance for disruption. Audit rights, incident cooperation, subcontractor controls, data-location commitments and exit assistance should be tested.

The incident playbook must allocate legal decisions. Who determines whether regulators, customers, insurers or affected individuals must be notified? Who preserves evidence and engages external advisers? How will legal privilege or professional confidentiality be preserved? A cyber incident moves quickly; ambiguity over decision-making wastes the hours that matter most.

Conduct an exercise with management, technology, legal, communications and finance. Introduce a realistic vendor outage or data breach and follow the contracts: who calls whom, what must be notified, and what can actually be recovered?

  • Does the company know what data and technology it is using?

Across the GCC, privacy and cybersecurity regimes increasingly regulate how data is collected, processed, retained, transferred and protected. A company cannot comply, or recover confidently, without knowing where its data goes.

Create a data map covering customers, employees, vendors and website users. Record the purpose and legal basis for processing, storage location, access rights, retention period, cross-border transfers and third-party processors.

The same exercise should include artificial intelligence, by identifying public and embedded AI tools, the information supplied to them, the outputs relied upon and the human review applied. Confidential information, personal data and third-party intellectual property should not enter a tool because an employee can access it. An approved-use policy, procurement review and output-verification process are proportionate safeguards.

  • Can the company protect value when conditions deteriorate?

Management should monitor covenant breaches, unpaid taxes, overdue receivables, expiring insurance, threatened claims and counterparties showing signs of insolvency. The legal team should know which rights permit suspension, security enforcement, contract termination or protective court relief, and whether exercising them could create risk.

People and intellectual property also require continuity planning. Confirm that employment and consultancy terms contain appropriate confidentiality, invention-assignment and post-termination protections, tailored to the governing law. Identify key-person dependencies, succession gaps and access held by departing staff. Register intellectual property where appropriate and maintain evidence of creation and ownership.

Business needs also to review insurance as a contract, not a certificate. Map material risks to coverage, exclusions, deductibles, notification deadlines and consent requirements. The policy is only useful if the company knows how to activate it.

In brief, the output should be that for every critical risk, record the business service affected, relevant entity and contract, responsible owner, required action, deadline and escalation threshold.

Report the highest exposures to the board and repeat the exercise after major acquisitions, restructurings, regulatory changes or technology deployments.

A focused review can produce four useful assets:

  1. an authority and obligations calendar;
  2. a critical-contract heat map;
  3. a data and AI inventory; and
  4. a tested incident playbook.

No company can remove disruption. It can, however, remove the uncertainty surrounding who may act, what must be done and which rights remain available.

Continue Reading

Financial

Al Ansari Exchange and Dubai Municipality mark decade-long partnership as annual collections rise 710%

Published

on

Al Ansari Exchange, the UAE’s leading remittance and foreign exchange company and a subsidiary of Al Ansari Financial Services PJSC (DFM: ALANSARI), and Dubai Municipality are celebrating a decade-long partnership that has enhanced access to government payment services, with annual collections rising by approximately 710% over the course of 10 years.

Established in 2016, the partnership enables individual and corporate customers to pay for Dubai Municipality services through Al Ansari’s extensive branch network across the UAE, expanding the availability of government services.

This growth reflects strong customer adoption, the service’s operational reliability, and rising demand for convenient payment channels. The collaboration also supports Dubai’s vision for customer-centric, digitally enabled government services by connecting public services with trusted private-sector payment infrastructure.

Marking the tenth anniversary of the partnership, Sayed Ismail Al Hashemi, Acting CEO of the Corporate Support Services Sector at Dubai Municipality, said: “We highly value our decade-long partnership with Al Ansari Exchange. This collaboration has contributed to enhancing service delivery efficiency and simplifying the customer journey for the payment of Dubai Municipality fees.”

Al Hashemi added: “The partnership has had a tangible impact by improving payment collection efficiency and expanding the range of available payment channels, making our services more accessible and enhancing customer satisfaction. At Dubai Municipality, we remain committed to leveraging digital transformation to deliver smart and efficient services that enhance the quality of life and wellbeing of our customers.”

Rashed A. Al Ansari, Group Chief Executive Officer of Al Ansari Financial Services, added: “Our ten-year partnership with Dubai Municipality reflects a shared commitment to making essential services more convenient and accessible. Over the past decade, we have combined Dubai Municipality’s service excellence with our extensive network and payment capabilities to provide customers with a reliable and efficient channel for completing their transactions. We look forward to building on this strong foundation and continuing to support Dubai’s evolving smart service ecosystem.”

Building on these foundations, both organisations will explore new opportunities to strengthen the partnership and support the continued evolution of Dubai’s smart service ecosystem.

Continue Reading

Trending

Copyright © 2023 | The Integrator