Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Technology > Automation key to making compliance easy as regulatory challenges prevail
    Technology

    Automation key to making compliance easy as regulatory challenges prevail

    Automation key to making compliance easy as regulatory challenges prevail

    Published by Jessica Weisman-Pitts

    Posted on November 24, 2021

    Featured image for article about Technology

    By Elizabeth Williams, Senior Director at Puppet

    Financial services (FSI) organisations are confronted by more cyber security challenges today than ever before. Over the past year, regulatory bodies have responded to a proliferation of cyberattacks with new laws under Australia’s updated Cyber Security Strategy 2020 and the Essential Eight strategies.

    The proposed changes to Australia’s critical infrastructure bill will allow intervention in major attacks to an expanded list of essential services, including financial services. Businesses in these sectors are required to improve baseline security for critical infrastructure to ensure products and services are protected from cyberattacks.

    The threat of regulatory intervention is very real. The recent NSW’s Auditor-General report found that none of NSW’s lead government agencies have not reached even level one maturity for at least three of the Essential Eight strategies, effectively failing to improve cyber security safeguards.

    Apart from heavy fines and the potential loss of banking licenses, FSI organisations have a duty to maintain trust and integrity in the financial system and support the national agenda to enhance cyber resiliency and security.

    Addressing various compliance needs

    As regulatory standards shift upwards, maintaining compliance to pass audits and to maintain costs has become more complex. IT leaders need to enhance their technology security posture and remain aligned to the Australian Signals Directorate (ASD) and APRA’s guidance, including achieving the right maturity level in the implementation of the Essential Eight.

    This is in addition to, and conflicts with the growing demands on product development and innovations, addressing quickly changing customer expectations. Finding the balance between both requires many pieces that must coalesce to create a holistic solution.

    A big part of the problem lies in how most security and ITOps teams still work in silos with disparate tools and priorities. The inconsistency leads to increased spending and duplicated work, visibility gaps between teams, and creates more challenges in the painstaking and time-consuming processes to pass audits.

    Infrastructure as code is becoming the leading approach in FSI’s environments to drive efficiencies and increase flexibility.

    Automation platforms allow teams to manage compliance without disrupting, or duplicating, the security team’s workflow. Having visibility into infrastructure changes as they happen and homing in on the types of changes that could be malicious enables the operations team to work more closely with the security team to provide a clear view of what’s happening. Tools that provide a holistic view of compliance status throughout cloud and on-prem environments can generate automatically updated reports that depict the current state of the infrastructure and can be easily interpreted without deep technical knowledge.

    Importantly, it helps IT teams follow a consistent, reliable process for each stage of the compliance lifecycle — from assessment to remediation to enforcement – and gain confidence in their compliance posture.

    Automate compliance without impacting agility 

    FSI IT leaders that incorporate continuous compliance policies into their infrastructure can save thousands of dollars and countless hours by reducing the complexities and overhead of audits.

    Gartner found that by 2023, 60% of organisations in regulated verticals will have integrated continuous compliance automation into their DevOps toolchains, improving their lead time by at least 20%.

    Puppet recently worked with DBS, one of Asia’s leading financial services groups to enhance overall security and efficiency through automation of its security configuration management. The security configuration definitions set by international organisations were converted into an automated capability to scan servers in the bank for the purpose of non-compliance reporting and rectification. With the automation, DBS was able to reduce the equivalent effort of 13 staff down to three while freeing up the time and energy for engineers to invest in other value-driven innovation or projects that the organisation could benefit from in the long term.

    Closer to home, ANZ Bank rapidly enforced compliance across operating systems with the 22 regulatory bodies. By partnering with Puppet to redirect engineer hours from audit explanations, the bank was able to improve its scalability and enforce consistency across platforms.

    The challenge will remain in the foreseeable future for the sector to meet strict rules and regulatory requirements, from strengthening cybersecurity governance, controls including vulnerability remediation and everything in between. Failing to maintain compliance can put the organisation at risk of everything from lost business to substantial fines.

    By encouraging operations and security teams to better leverage scalable and intelligent platforms, FSI organisations can drive better collaboration and ensure they comply with the most rigorous security requirements without compromising on agility.

    About the Author:

    Elizabeth Williams is the Senior Director at Puppet and is based in Australia. Lizzie is a professional with global technology experience spanning 24 years, including some of the UK’s and Australia’s leading tech companies and consultancy firms.  She has a proven track record of growing technology businesses, recognised for her customer advocacy and results focus.  Lizzie is known for initiating high value relationships to drive business outcomes across industry and specifically in FS&I.

    By Elizabeth Williams, Senior Director at Puppet

    Financial services (FSI) organisations are confronted by more cyber security challenges today than ever before. Over the past year, regulatory bodies have responded to a proliferation of cyberattacks with new laws under Australia’s updated Cyber Security Strategy 2020 and the Essential Eight strategies.

    The proposed changes to Australia’s critical infrastructure bill will allow intervention in major attacks to an expanded list of essential services, including financial services. Businesses in these sectors are required to improve baseline security for critical infrastructure to ensure products and services are protected from cyberattacks.

    The threat of regulatory intervention is very real. The recent NSW’s Auditor-General report found that none of NSW’s lead government agencies have not reached even level one maturity for at least three of the Essential Eight strategies, effectively failing to improve cyber security safeguards.

    Apart from heavy fines and the potential loss of banking licenses, FSI organisations have a duty to maintain trust and integrity in the financial system and support the national agenda to enhance cyber resiliency and security.

    Addressing various compliance needs

    As regulatory standards shift upwards, maintaining compliance to pass audits and to maintain costs has become more complex. IT leaders need to enhance their technology security posture and remain aligned to the Australian Signals Directorate (ASD) and APRA’s guidance, including achieving the right maturity level in the implementation of the Essential Eight.

    This is in addition to, and conflicts with the growing demands on product development and innovations, addressing quickly changing customer expectations. Finding the balance between both requires many pieces that must coalesce to create a holistic solution.

    A big part of the problem lies in how most security and ITOps teams still work in silos with disparate tools and priorities. The inconsistency leads to increased spending and duplicated work, visibility gaps between teams, and creates more challenges in the painstaking and time-consuming processes to pass audits.

    Infrastructure as code is becoming the leading approach in FSI’s environments to drive efficiencies and increase flexibility.

    Automation platforms allow teams to manage compliance without disrupting, or duplicating, the security team’s workflow. Having visibility into infrastructure changes as they happen and homing in on the types of changes that could be malicious enables the operations team to work more closely with the security team to provide a clear view of what’s happening. Tools that provide a holistic view of compliance status throughout cloud and on-prem environments can generate automatically updated reports that depict the current state of the infrastructure and can be easily interpreted without deep technical knowledge.

    Importantly, it helps IT teams follow a consistent, reliable process for each stage of the compliance lifecycle — from assessment to remediation to enforcement – and gain confidence in their compliance posture.

    Automate compliance without impacting agility 

    FSI IT leaders that incorporate continuous compliance policies into their infrastructure can save thousands of dollars and countless hours by reducing the complexities and overhead of audits.

    Gartner found that by 2023, 60% of organisations in regulated verticals will have integrated continuous compliance automation into their DevOps toolchains, improving their lead time by at least 20%.

    Puppet recently worked with DBS, one of Asia’s leading financial services groups to enhance overall security and efficiency through automation of its security configuration management. The security configuration definitions set by international organisations were converted into an automated capability to scan servers in the bank for the purpose of non-compliance reporting and rectification. With the automation, DBS was able to reduce the equivalent effort of 13 staff down to three while freeing up the time and energy for engineers to invest in other value-driven innovation or projects that the organisation could benefit from in the long term.

    Closer to home, ANZ Bank rapidly enforced compliance across operating systems with the 22 regulatory bodies. By partnering with Puppet to redirect engineer hours from audit explanations, the bank was able to improve its scalability and enforce consistency across platforms.

    The challenge will remain in the foreseeable future for the sector to meet strict rules and regulatory requirements, from strengthening cybersecurity governance, controls including vulnerability remediation and everything in between. Failing to maintain compliance can put the organisation at risk of everything from lost business to substantial fines.

    By encouraging operations and security teams to better leverage scalable and intelligent platforms, FSI organisations can drive better collaboration and ensure they comply with the most rigorous security requirements without compromising on agility.

    About the Author:

    Elizabeth Williams is the Senior Director at Puppet and is based in Australia. Lizzie is a professional with global technology experience spanning 24 years, including some of the UK’s and Australia’s leading tech companies and consultancy firms.  She has a proven track record of growing technology businesses, recognised for her customer advocacy and results focus.  Lizzie is known for initiating high value relationships to drive business outcomes across industry and specifically in FS&I.

    Related Posts
    Treasury transformation must be built on accountability and trust
    Treasury transformation must be built on accountability and trust
    Financial services: a human-centric approach to managing risk
    Financial services: a human-centric approach to managing risk
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    How Integral’s CTO Chidambaram Bhat is helping to solve  transfer pricing problems through cutting edge AI.
    How Integral’s CTO Chidambaram Bhat is helping to solve transfer pricing problems through cutting edge AI.

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Technology PostNissan unveils $18 billion electrification push in bid to draw level with rivals
    Next Technology PostStaying One Step Ahead of Your Rivals: Selecting the Right Technology

    More from Technology

    Explore more articles in the Technology category

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Compliance Has Become an Engineering Problem

    Why Compliance Has Become an Engineering Problem

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    How Nclude.ai   turned broken portals into completed applications

    How Nclude.ai turned broken portals into completed applications

    The Silent Shift: Rethinking Services for a Digital World?

    The Silent Shift: Rethinking Services for a Digital World?

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    View All Technology Posts