Security is an innovation enabler, not a constraint: Cezary Piekarski of Standard Chartered

Cezary Piekarski, Group CISO, Standard Chartered
Cezary Piekarski, Group CISO, Standard Chartered

In an age of rapid digital transformation, where banking innovation is driven by new technologies such as artificial intelligence, the tension between security and speed has never been more acute. For Standard Chartered, a bank that operates across some of the world’s most dynamic and digitally complex markets, security isn’t a barrier to innovation but the foundation of it.

In this exclusive interview with The Digital Banker, Cezary Piekarski, Group Chief Information Security Officer at Standard Chartered, walks us through the bank’s forward-thinking approach to cybersecurity — from embedding CISOs into business teams and automating threat detection, to preparing for the quantum future and using AI to fight financial crime.

As October marks Cybersecurity Awareness Month, we also explore how Standard Chartered is turning its people, including employees and clients, into powerful partners in security.

The Digital Banker: As the financial services sector continues to digitalise, how are you ensuring security at Standard Chartered, without compromising on innovation?

Cezary Piekarski, Group CISO, Standard Chartered: Our priority is to embed security into innovation rather than add it as an afterthought. We are building secure-by-design platforms, where controls and vulnerability detection are integrated into the software development lifecycle, and standardising security processes to reduce complexity and create consistency, allowing teams to innovate safely and at scale. We have also embedded CISOs into our business teams, which has aligned the understanding of cybersecurity risk across the Bank, and allows us to be an early mover in areas such as digital assets. This approach of designing security controls as business enablers, rather than constraints, extends beyond internal development to the wider ecosystem, including how we manage third parties and vendors.

In an era of AI, cloud adoption and API-led services, what are currently the biggest tech security challenges and how are you tackling them?

Our biggest challenges lie in balancing robust security with seamless client experience and faster time-to-market. Both are necessary to earn and maintain our clients’ trust. Overly strict controls can create friction and slow down innovation. We are tackling this by embedding security into the design from the start, automating vulnerability detection and controls into the software development lifecycle, and adopting solutions that scale dynamically with business needs. Through close collaboration with the business and technology teams, we build security that enables innovation rather than restricting it, protecting our clients while supporting growth and delivering safe, frictionless services at speed.

With sophisticated cyberattacks on the rise, how is Standard Chartered strengthening its capabilities to detect and respond to such threats in real-time?

Our approach to strengthening our defences against faster and more sophisticated cyberattacks continues to be automation and collaboration. With the help of automation, we are driving real-time detection, containment and response to attacks. Through our cross-functional, integrated fusion approach, we have brought together risk signals from across the organisation enabling and end-to-end view of potential criminal activity, enabling seamless coordination and rapid decision-making. This combination of automation and human expertise not only strengthens our security and resilience, but also benefits our clients through a safer and smoother experience.

What new anti-fraud strategies and technologies are you deploying to safeguard customers and payment ecosystems?

AI plays a role and will play an even more critical role in the way we combat fraud and cyber incidents, and we are actively incorporating use cases to improve cyber and fraud detection rates and reduce false positives. This includes using machine learning for anomaly detection, behavioural analysis and fraud pattern recognition, as well as AI-assisted alert triage. All implementations follow the Bank’s AI safety and governance framework to ensure they are explainable, unbiased, and aligned with regulatory expectations. This allows us to adopt AI safely and responsibly – ultimately helping our analysts focus on the most critical threats while maintaining transparency and client trust.

October is Cybersecurity Awareness Month. How do you make sure employees as well as customers become strong partners in security?

The majority of cyber incidents involve a human element and exploit human behaviours, rather than purely technical weaknesses. Therefore, we put a lot of emphasis on engaging, informing and empowering our employees and clients, who are our first line of defence.

Specifically for Cybersecurity Awareness Month this year, we are running ‘CyberFEST’, a month-long event with over 40 live sessions, games, activities and resources, run across three different tracks for all employees, cybersecurity and technology teams, and risk managers.

While cyber awareness and education happen year-round for all our employees, we focus on building a strong cybersecurity culture by making security simple, relevant and embedded into daily behaviours at all levels, including our management team and the Board. We are also actively measuring our cybersecurity culture and using those insights to drive continuous improvement.

Our clients are our key partners in security through their vigilance in identifying and responding to cybersecurity and fraud incidents.

Last year, we set up a new team – Client & Third-Party Intelligence – which provides a part-security and part-business development role, proactively identifying security threats to third parties that may impact the Group, as well as providing impactful threat intelligence and briefings to strategic clients to strengthen and enhance the banking-client relationship. Through this capability, we drive a unique service offering within the banking industry.

Looking ahead, what do you think will be the biggest cybersecurity challenge for banks — and how can the industry start preparing now?

Quantum computing poses significant cyber risks by potentially breaking current encryption methods, impacting data security, and enabling new attack vectors. Quantum computers will be able to efficiently solve the hard mathematical problems that asymmetric public key cryptography (PKC) relies on to protect our networks today. In essence, quantum computing presents a paradigm shift in cyber security, requiring a fundamental rethinking of how we protect data and systems. These risks only manifest once viable PQC computers exist, so they are potential future, not current, risks.

However, organisations need to prepare for this shift by adopting quantum-resistant cryptography and developing strategies to mitigate potential vulnerabilities, before they manifest. We have taken a proactive approach to prepare for the quantum threat. This includes having a resilient cryptography preparedness strategy that balances Group agility and long-term security and establishing a multi-year initiative to meet the challenges of the emerging threat and address associated risks.

Besides proactively preparing for the risks posed by quantum computing, we are also contributing to accelerating the practical application of quantum technologies through our recent collaboration with Fujitsu via SC Ventures. The project will enable corporates to develop and explore quantum computing and quantum-inspired applications, with an initial focus on financial services use cases such as fraud detection, risk simulations, derivative pricing, algorithmic trading, and credit decisioning algorithms.

Another cybersecurity challenge for banks is securing usage of AI at scale. AI is no longer a distant possibility, we are already embracing it across the industry, and at Standard Chartered specifically, for use cases across risk management, productivity, and client experience. But as adoption accelerates, so does the attack surface, and adversaries will try to exploit vulnerabilities in AI model and data pipelines while at the same time using AI themselves for faster more sophisticated attacks like deepfakes and social engineering.

Banks must carefully manage ethical considerations when scaling use of AI, particularly around access to sensitive data, ensuring unbiased and fair outcomes, and where accountability of decisions made by AI sits. We are managing this with strong safeguards and governance (including a data risk committee reporting to the Board), and applying secure-by-design AI practices, validation, and testing to uncover weaknesses early (as with traditional software).

At an industry level, collaboration, intelligence sharing, and development of standardised frameworks will help in setting strong ethical guardrails.

Shopping Cart

Media Kit

    Data Protection

    Personal Data (“Data”) submitted for Media Kit (“Media Kit”), and/or collected in the form of first name, last name, email address and other contact details may be used for the purposes of inviting you to future events and for reaching out to you with content which may be of interest to you. For these purposes, Coeus Intelligence will share the Data with our associate companies (including event and content sponsors) to promote their products and services. If you would like to opt-out, email us at [email protected].

    By clicking Submit, you acknowledge that you consent/ have sufficient informed consent to the collection, use and disclosure of Data as set out above.

    Contact Us

      Data Protection

      The information you provide will be held on our database and may be used to keep you informed of our and our associate companies’ products and for selected third party mailings. Please tick the box if you would prefer not to be contacted for these purposes:

      Request Nomination Pack

        Data Protection

        The information you provide will be held on our database and may be used to keep you informed of our and our associate companies’ products and for selected third party mailings. Please tick the box if you would prefer not to be contacted for these purposes:

        Registration Form

          Data Protection

          The information you provide will be held on our database and may be used to keep you informed of our and our associate companies’ products and for selected third party mailings. Please tick the box if you would prefer not to be contacted for these purposes:

          Registration Form

            Data Protection

            The information you provide will be held on our database and may be used to keep you informed of our and our associate companies’ products and for selected third party mailings. Please tick the box if you would prefer not to be contacted for these purposes:

            The world’s preeminent Private Banks and Wealth Managers are demonstrating a committed drive in innovation, advisory, new products and services to meet the sophisticated needs of their clients.

            COVID-19
            Amid economic activity revival on the back of the Covid-19 vaccine program, organisations moving from business continuity plans to stable working environments, together with the slightest improvement in unemployment numbers, forced the world to adjust to new realities. Coming to terms with the “new normal”, global investors are now on the look-out for attractive and stable investment opportunities.

            Needs of Private Wealth customers and families worldwide have drastically changed due to the pandemic and banks have had to accelerate efforts to deploy a multi-channel service strategy and safeguard clients’ businesses and wealth against negative impacts of economic uncertainly.

            The Global Private Banking Innovation Awards will recognise the world’s best private banks, wealth managers and asset managers that are championing innovation across advisory, service, products, customer experience and more.

            Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. 

            Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

            Request Nomination Pack

            Error: Contact form not found.