Enhancing Financial System Resilience Against Cyber Threats via SWIFT Customer Security Framework
Khawla Shalabi, Mustafa A. Al-Fayoumi, Qasem S. Abu Al-Haija · 2023
The financial industry has become a prime target for cybercriminals, with a particular focus on financial communication networks like SWIFT. Recent attacks have demonstrated the incredible skill, sophistication, and rewards associated with these attacks, causing institutions to shift their attention to larger targets. The 2016 Bangladesh bank cyber attack was a turning point, leading SWIFT to launch the Customer Security Program (CSP) to help secure the local SWIFT infrastructure of financial institutions. In this work, we propose a methodology for implementing the CSP framework introduced by SWIFT in 2017, specifically in a financial institution in Jordan connected to the SWIFT network. We evaluate the effectiveness of these security controls by measuring the system's Transaction per Second (TPS) throughput for sending and receiving messages. Our results show a 22% overall improvement in the financial system's security environment and enhancements in individual main controls. Furthermore, our evaluation indicates that compliance with the CSP framework did not negatively affect the system's TPS throughput, demonstrating the framework's compatibility with the financial institution's operations. This study highlights the importance of implementing robust security measures to protect financial institutions against cyber threats and the potential benefits of utilizing the SWIFT CSP framework.