Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Banking
    3. >WHY BANKS NEED TO BE ‘RED TEAM’ SECURE
    Banking

    Why Banks Need to Be ‘red Team’ Secure

    Published by Gbaf News

    Posted on July 7, 2015

    5 min read

    Last updated: January 22, 2026

    Add as preferred source on Google
    Illustration depicting the concept of red teaming in banking security. This image emphasizes the importance of proactive security measures and vulnerability identification in the finance sector.
    Conceptual illustration of banking security and red teaming strategies - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    By Robert Wood, Technical Manager, Cigital

    The need for strong security in the banking industry is not a new concept; the threats and methods utilised to exploit and steal from the industry however, are constantly evolving. Consequently, security controls need to adapt to the targeted, yet holistic nature, of these new attacks. However, determining the correct path for that adaptation requires significant effort. Red teaming is the process of modeling an adversary: determining how they think, what they see, and how they will attack your critical assets using any techniques and attack surface accessible to them. Operationally, this may mean that a Red Team leverages vulnerabilities across many domains (such as web application security, network security, social engineering, process manipulation, or physical security) into a singular composite attack, driven by the set of objectives they are working to achieve. This process can be applied in a security assessment or strategic planning capacity to help improve the intelligence, awareness, and effectiveness of a security initiative.

    3 advantages to red teaming

    Robert Wood, Technical Manager, Cigital

    Robert Wood, Technical Manager, Cigital

    From a security assessment perspective, red teaming processes can be used to gauge the effectiveness of an organisation’s security posture in a production environment. The key advantages of using a true red team are:

    1. Utilising the entirety of the organisation to identify vulnerabilities and subsequent composite attacks, rather than operating in a vacuum. This emphasizes the importance thatsystems, software, people, and processes are able to prevent vulnerabilities in the first place, identifying areas for improvement along the way.
    2. Operating in a covert manner relative to operations and engineering teams. The ability for those teams and any automated infrastructure to detect and alert on red teaming activities is critical to detecting real world attacks.
    3. Coercing incident response teams into reacting to their efforts, highlighting any process weaknesses or bottlenecks along the way. The ability for an organisation to swiftly and successfully react to an attack is a critical step in minimising the impact.

    Contrary to the traditional vulnerability scan or penetration test,which is a targeted effort on components that are considered important by the organisation, red teams operate with a different mindset. The red team attacks what an adversary considers important and relative to achieving the established objectives. However, red teaming is not meant to replace targeted security assessments. Red teaming augmentsthese assessments and provides a different set of results and attack intelligence back to the security initiative.

    What does it mean to be red team secure?

    Being red team secure means that an organisation can withstand the simulated attack efforts of a red team as they model different types of adversaries, such as insider threats, criminal organisations, and coordinated hacker groups. The prevention, detection, and response capabilities of any security organisation are paramount to its overall success in protecting critical assets. It also ensures that these capabilities extend to the entire organisation and not just select pieces. This is critical given the interconnected nature of a modern financial services organisation.

    Over time, things naturally change within an organisation to facilitate job efficiency. This may cause a significantshift away from an original design or intention. This shift from a known, understood state frequently introduces new connections, storage locations, communication channels, and configurations. This createsattack surfacesthat are completely unknown to a security team, and, therefore, never reviewed. As a result, these new changes may introduce new vulnerabilities in addition to not being considered in a standardised risk management review.

    Adversaries are opportunistic and do not restrict themselves to specific attack vectors or pieces of attack surface based on risk management policies or organisational structure. Adversaries look at organisations in a holistic manner, driven by the assets they’re targeting; therefore they will identify vulnerabilities across many different aspects of an organisation and how those vulnerabilities fit together into composite attacks.This composite attack approach can be used to highlight more specific risk measurements to a class or set of vulnerabilities, depending on how it can be leveraged to compromise critical assets.

    The bottom line

    Security leadership in the banking industry should start by understanding the adversaries they need to defend against, including their capabilities and motives. An effective definition should include qualitative analysis and quantitative measurements regarding attack skills, time to dedicate, number of resources available, etc. Once these adversaries are understood, they can be effectively modeled through red teaming processes to stress test the security posture of an organisation. Without a sound understanding of relevant adversaries, organisations cannot answer the “secure against what/whom?” question and can only perform very general red teaming activities, degrading the potential benefit.

    In summary, the industry as a whole is responsible for protecting a very sensitive collective set of assets. That value and sensitivity has historically and will continue to attack malicious actors, who will attempt to access or steal those assets. Red teaming is a proactive measure to identify the methods and paths that an adversary may take to compromise a set of assets, instead of simply identifying more vulnerabilities.

    More from Banking

    Explore more articles in the Banking category

    Image for Nominate Today for the Leadership Awards 2026
    Nominate Today for the Leadership Awards 2026
    Image for Submit Your Entries for Insurance & Takaful Awards 2026
    Submit Your Entries for Insurance & Takaful Awards 2026
    Image for Calling for Entries: ESG & Sustainability Awards 2026
    Calling for Entries: ESG & Sustainability Awards 2026
    Image for Call for Entries: Deal of the Year Awards 2026
    Call for Entries: Deal of the Year Awards 2026
    Image for Submit Your Entry Today for Customer Service Awards 2026
    Submit Your Entry Today for Customer Service Awards 2026
    Image for Submit Your Entry Today for CSR Awards 2026
    Submit Your Entry Today for CSR Awards 2026
    Image for Submit Your Entry Today for Retail Banking Awards 2026
    Submit Your Entry Today for Retail Banking Awards 2026
    Image for Nominations Open for Islamic Banking Awards 2026
    Nominations Open for Islamic Banking Awards 2026
    Image for Submit Your Entry Today for Fund & Asset Management Awards 2026
    Submit Your Entry Today for Fund & Asset Management Awards 2026
    Image for Entries Open for Forex Banking Awards 2026
    Entries Open for Forex Banking Awards 2026
    Image for Call for Entries for Brand of the Year Awards 2026
    Call for Entries for Brand of the Year Awards 2026
    Image for Nominations Open for Corporate Banking Awards 2026
    Nominations Open for Corporate Banking Awards 2026
    View All Banking Posts
    Previous Banking PostBank Resolutions – What You Need to Know
    Next Banking PostHow Technology Is Driving Positive Change in the Banking Industry