Ravindra Kumar, Chief Information Officer, outlines how a layered defence, quantum-ready systems, and customer engagement form the backbone of Maybank Singapore’s cybersecurity strategy, protecting both operations and trust
Singapore’s financial sector in early 2025 faced a stark reminder of digital interdependence. A series of breaches targeting key suppliers highlighted how even the strongest banks remain exposed to vulnerabilities beyond their direct control.
For Ravindra Kumar, Chief Information Officer of Maybank Singapore, the incidents confirmed what he had long anticipated. “Our digital ecosystem is deeply interconnected,” he says. “A single weak link in a third-party vendor can become an open door. Managing this sprawling digital supply chain is a paramount challenge, as attackers consistently target the path of least resistance.”
At Maybank Singapore, resilience begins with realism. Kumar’s team operates on what he calls an “assume breach” mindset—one that accepts that intrusions will happen and focuses instead on rapid detection, containment and recovery.
“We build resilience at every level—from code development to customer interaction—to protect the confidentiality, integrity and availability of our services,” he explains. “The goal isn’t perfection, it’s preparedness.”
That preparation extends beyond the bank’s own systems. Maybank Singapore now embeds stringent cybersecurity clauses and incident-reporting rules in every vendor contract. Its most sensitive data are stored on WORM (Write Once, Read Many) systems, ensuring that backups remain unaltered. “Once data are written, they cannot be changed, even by privileged administrators,” Kumar says. “This guarantees a clean source from which to rebuild and renders extortion tactics useless.”
Evolving threats, advancing defences
Cyberattacks are growing more sophisticated, and the lines between human manipulation and technical exploitation have blurred. “Phishing remains the primary method of intrusion,” Kumar notes. “But what’s changed is scale and sophistication. Generative technology is now industrialising the creation of hyper-personalised scams and deepfakes, making traditional awareness training less effective.”
Ransomware has also escalated. “Triple-extortion tactics—data theft, encryption and public disclosure—are designed to maximise pressure and bypass traditional recovery strategies,” he says. “That’s why immutable backups and redundancy are essential.”
On another front, Kumar is preparing for the quantum era. “Adversaries are already stealing encrypted data with the intention of decrypting it later, once a powerful quantum computer becomes available,” he says. Maybank’s answer is a crypto-agile framework that incorporates post-quantum algorithms with existing encryption.
The bank is also deepening its Zero Trust architecture, where every user, device and application is continuously verified. “Zero Trust minimises the risk of breaches, limits the impact of compromised credentials, and strengthens both compliance and customer confidence,” Kumar says.
People at the centre of protection
Technology may be the front line, but customers are part of the defence.
“Confidence comes not just from robust controls, but from transparency and consistency,” Kumar says. Maybank’s customer communications now highlight new controls—such as Secure2u authorisation, digital signing and real-time fraud surveillance—to build awareness and trust.
The strategy echoes Maybank’s long-standing “humanising banking” ethos. “Technology alone is insufficient,” he says. “Our customers are an essential layer of defence. Human error and social engineering remain significant vulnerabilities.”
To address this, the bank runs continuous education programmes built on what Kumar calls “education, enablement and engagement.” These include scam advisories within the app, in-branch training and social media alerts. “We encourage customers to enable multi-factor authentication, recognise phishing attempts and stay vigilant,” he says. “Our goal is to build a community shield.”
Leading under pressure
Few roles test composure like that of a CIO during a cyber crisis. For Kumar, leadership is measured by accountability and calm. “In a crisis, there’s no room for blame,” he says. “My role is to own the problem, empower the teams and take decisive action.”
He describes his function as “translating chaos”—turning complex technical information into clear guidance for boards, regulators and customers.“Protect first, prove later,” he says. “Immediate containment and customer protection take precedence over perfect information.” That mindset, he adds, depends on emotional steadiness. “Teams take their cues from leadership. Maintaining a calm, visible presence helps the organisation think clearly and act effectively.”
Kumar also reframes cybersecurity spending as strategic investment. “We don’t treat cybersecurity as a cost centre,” he says. “We position it as a protector of revenue and reputation.”
He quantifies each initiative’s value in financial terms: “A one-million-dollar investment in data loss prevention isn’t a technology expense—it’s protection against a fifty-million-dollar fine or loss. Once the conversation is framed in business language, priorities shift.”
The next frontier: intelligent trust
Kumar sees “intelligent trust” as the principle that will define the next decade of cybersecurity. “The future lies in continuous verification,” he says. “Identity, behaviour and context must be assessed in real time. Static defences are no longer enough.”
Still, technology alone cannot guarantee safety. “Cybersecurity is everyone’s responsibility—from product design to frontline operations,” he says. “You can’t bolt trust on at the end. You have to build it in from the start.”
For Kumar, the essence of resilience remains unchanged. “Cyber resilience isn’t just about technology,” he says. “It’s about people, discipline and trust—the things that have always defined good banking.”





