A Comprehensive Cybersecurity Maturity Study for Nonbank Financial Institution

Journal of System and Management Sciences · 2023

In today's era of digital disruption, information security holds paramount importance for institutions, demanding their utmost attention.Effective management of organizational information is a crucial component in achieving Good Corporate Governance.The level of protection measures serves as an indicator of an organization's cybersecurity awareness and its ability to safeguard business processes in the short, medium, and long term, especially within the realm of information and communication technology (ICT).To achieve this, organizations require a suitable security standard tailored to their specific needs, aiding them in assessing the maturity level of their cybersecurity measures and protecting their information security.This paper focuses on a case study conducted at an Indonesian Life Insurance firm, which manages critical infrastructure and digital financial transactions.The organization has already implemented several international security standards through comprehensive planning, implementation, evaluation documentation, and ICT activities.However, these initiatives have absorbed a substantial portion of the company's budget.Consequently, both management and stakeholders need to ascertain the effectiveness of these investments and gain insights into the company's preparedness to support its digitalization efforts, considering its extensive operations in the region and the prevailing cyber threats.To address these concerns, this study employs an analysis based on the NIST Cybersecurity Framework version 1.1, with a primary focus on operational effectiveness rather than mere compliance.The results and findings regarding the maturity level of cybersecurity within the organization are anticipated to inform improvements in ICT management.By conducting this analysis, the organization aims to bolster its information security posture, enhance its ability to combat cyber threats.Ultimately, this study aims to contribute to the overall advancement of information security within organizations operating in today's digitally disruptive landscape.

Read the paper · More papers on PaperTik