Beyond Technology: Why Banking’s Strongest Cyber Defence Starts with Understanding People

Singapore, July 27, 2026 – For years, the financial services industry has approached cybersecurity as a technology challenge. Organisations have invested billions in firewalls, endpoint protection, encryption, identity management and increasingly sophisticated security operations centres. Every new threat has been met with another layer of technology, reinforcing the belief that stronger systems naturally lead to stronger protection.

Yet despite unprecedented investment, financial scams continue to surge across Asia. Banks are reporting increasingly sophisticated fraud attempts, regulators are introducing tougher intervention measures, and customers are facing attacks that no longer rely on hacking systems but on manipulating people.

According to Subhalakshmi Ganapathy, Chief IT Security Evangelist at ManageEngine, this shift requires a fundamental rethink of how organisations define cybersecurity. The greatest vulnerability today is no longer hidden within servers or cloud environments. It lies in human judgement, emotion and trust.

Speaking with CIO World Asia, Ganapathy explains why cybersecurity has become as much a behavioural discipline as a technical one, why traditional authentication models are rapidly losing effectiveness, and how financial institutions across Asia can build security strategies that protect customers without compromising trust.

Learning That Technology Alone Was Never Enough

Unlike many cybersecurity professionals whose careers are defined by a single incident or breakthrough, Ganapathy describes her own journey as one shaped by gradual observation rather than dramatic moments. “I don’t think it was a single dramatic moment. It was more of a slow, uncomfortable realisation.”

Early in her career, she repeatedly witnessed organisations fall victim to attacks that did not exploit weaknesses in software but instead exploited something far more predictable. Well-intentioned employees trusted familiar processes. Customers believed messages that appeared legitimate. People acted based on confidence in the systems around them because that is exactly how digital services are designed to function.

What struck her was not that people made mistakes. It was that organisations often expected technology to compensate for fundamentally human behaviour. “They trusted the system, the process, and the person on the other end of a message.”

For Ganapathy, this became the lens through which she would later view cybersecurity. Technical controls remain essential, but they only address part of the problem. Every decision made by a customer, employee or partner is influenced by context, familiarity and emotion. Attackers understand this remarkably well, often better than the organisations defending against them.

Rather than attempting to eliminate trust from digital interactions, she believes organisations need to acknowledge it as an inevitable part of human behaviour and design security around it. “Security isn’t just about hardening systems. It’s about understanding what people believe, why they act the way they do, and how attackers exploit both. That’s as much a psychological question as it is a technical one.”

That perspective has become increasingly relevant as cybercrime evolves. Today’s attackers are not simply looking for technical vulnerabilities. They are studying how people think, react under pressure and make decisions. Understanding human behaviour has therefore become just as important as understanding system architecture.

Making Cybersecurity a Business Conversation Instead of an IT Discussion

One of the defining characteristics of Ganapathy’s career has been her ability to bridge cybersecurity, product management and enterprise advocacy. That combination has shaped how she communicates security to executives who are responsible for far more than technology alone.

She recalls sitting through business reviews where security teams presented detailed discussions about encryption standards, patch cycles and network controls. While technically accurate, those conversations rarely resonated with senior decision-makers. “The turning point, honestly, was sitting in business reviews and realising that the language of security such as firewalls, encryption, and patch cycles simply didn’t land.”

The problem, she explains, was never a lack of interest. Business leaders cared deeply about cyber risk, but they viewed it through an entirely different lens. They wanted to understand customer confidence, operational resilience, regulatory exposure and organisational reputation rather than technical specifications.

Recognising this disconnect fundamentally changed how she approached enterprise conversations. “Once I started translating security into notions, including what a breach cost in customer confidence, what friction does to digital adoption rates, and what a false positive means for someone trying to access their savings, the conversation changed entirely.”

That simple shift in language transformed cybersecurity from a specialist IT discussion into a strategic business priority. For banks in particular, the implications are significant. Every cybersecurity decision now affects customer experience, digital adoption, regulatory trust and competitive differentiation. A successful fraud incident is no longer viewed solely as an operational failure. It has become a business risk capable of damaging customer relationships that may have taken years to build.

This evolution also explains why cybersecurity increasingly commands attention in boardrooms across Asia. Security leaders are no longer expected simply to secure infrastructure. They are expected to explain how cyber resilience enables growth, protects reputation and preserves trust throughout the organisation.

The New Battlefield Is Human Psychology

Across Southeast Asia, scam-related fraud has evolved at an alarming pace. Criminals no longer need sophisticated malware or advanced intrusion techniques when psychological manipulation often delivers faster results. Ganapathy believes the industry has significantly underestimated this change. “Absolutely, and I’d say we’ve underestimated it significantly.”

For many years, cybersecurity strategies focused on strengthening authentication. Banks introduced stronger passwords, biometric verification, multi-factor authentication and One-Time Passwords, believing that verifying identity would naturally reduce fraud. Attackers responded by changing tactics rather than attempting to overcome technology. “They’re not breaking into systems. They’re convincing people to open the door.”

This distinction fundamentally changes the nature of cyber defence. Modern scams increasingly rely on urgency, fear and authority. A customer receives a convincing message claiming that their account has been compromised. A phone call appears to come from a trusted institution. An urgent request creates enough emotional pressure that rational analysis gives way to immediate action.

“When someone receives a message saying their account has been compromised and they need to act immediately, the psychological pressure overrides rational scrutiny. That is not a failure of intelligence. It is human cognition being weaponised.”

Ganapathy deliberately rejects the notion that scam victims lack awareness or intelligence. Instead, she argues that cybercriminals have become exceptionally skilled at exploiting universal human behaviour. This understanding requires banks to rethink their security priorities. Instead of asking whether customers entered the correct credentials, institutions increasingly need to understand whether the overall behaviour surrounding a transaction genuinely reflects that customer’s normal activity.

“The more meaningful question is whether the pattern of behaviour, including the timing, the device, the transaction type, and the sequence of actions, genuinely reflects who the customer is.” Behavioural intelligence therefore becomes more than another fraud detection tool. It represents a new way of thinking about digital identity, recognising customers through context rather than relying exclusively on credentials.

Why More Authentication Does Not Always Mean Better Security

For many financial institutions, adding additional authentication steps has long been viewed as a practical response to emerging threats. Every new verification screen appears to strengthen security while reassuring customers that protective measures are in place. Ganapathy believes this assumption deserves closer scrutiny. “Adding friction through extra steps, OTP prompts, and confirmation screens feels like doing something. It’s visible, auditable, and creates the impression of control.”

However, visible security is not necessarily effective security. Sophisticated attackers have already demonstrated that authentication mechanisms such as OTPs can themselves become tools for manipulation. Rather than defeating technical controls, criminals simply persuade customers to authorise fraudulent activity on their behalf. This creates an uncomfortable paradox. The same security controls designed to protect customers can inadvertently become part of the attack process. Instead of repeatedly asking users to prove their identity, Ganapathy advocates for continuous identity awareness throughout every interaction. “A truly identity-centric framework starts from a different premise.”

Rather than relying on isolated authentication events, banks should continuously assess contextual information including familiar devices, transaction history, geographic behaviour, session activity and customer habits. When those patterns remain consistent, the customer experience should remain seamless. When behaviour changes significantly, security should respond proportionately rather than automatically introducing unnecessary friction.

This adaptive approach is particularly important across Asia Pacific, where digital maturity differs significantly between markets. A globally mobile customer in Singapore may regularly conduct international transactions, while someone accessing digital banking for the first time in an emerging economy presents an entirely different behavioural profile. Adaptive authentication acknowledges these realities instead of forcing every customer through identical verification processes regardless of actual risk.

Protecting Customers Without Taking Away Their Control

Governments and financial regulators throughout Asia have introduced increasingly proactive anti-scam measures, including delaying suspicious payments and freezing customer accounts when fraud is suspected. While these initiatives have undoubtedly prevented financial losses, they also raise important questions about customer autonomy. Ganapathy believes the answer lies not in choosing between security and convenience but in applying intervention intelligently. “The severity of an intervention should match the confidence level of the threat signal.”

Freezing an account can have significant consequences. Customers may suddenly lose access to emergency savings, be unable to pay suppliers or miss critical financial obligations. Such interventions should therefore remain proportionate to the confidence that fraudulent activity is genuinely occurring.

Equally important is transparency. “If a bank or regulator intervenes in a customer’s account, the customer must be informed promptly, given a clear explanation, and offered a fast path to resolution.”

Trust is difficult to build and remarkably easy to lose. Customers are generally willing to accept temporary inconvenience when they understand why it is necessary and believe they are being treated fairly.

Ganapathy also believes banks should view account freezes as the final safeguard rather than the primary response. “The goal is precision: stopping the fraud without stopping the customer.” As behavioural analytics continue to improve, institutions should increasingly identify unusual activity early enough to verify customer intent before resorting to disruptive interventions.

Artificial Intelligence Must Earn Customer Confidence

Artificial Intelligence is rapidly becoming central to fraud detection, allowing banks to identify behavioural anomalies that traditional rule-based systems frequently overlook. Yet greater automation also introduces new challenges surrounding transparency, fairness and accountability. Ganapathy believes organisations must avoid allowing AI to become an invisible decision-maker. “The risk is real.”

Financial decisions that cannot be explained naturally undermine customer confidence, regardless of how accurate the underlying algorithms may be. She believes responsible AI deployment depends on three essential principles: 

  1. Explainability
  2. Accountability 
  3. Continuous calibration.

Explainability ensures that security teams understand why AI reaches particular conclusions. Accountability ensures humans remain responsible for decisions with meaningful customer impact. Continuous calibration enables organisations to monitor false positives, reduce unintended bias and refine models as customer behaviour evolves.

When these principles are applied consistently, AI becomes more than a fraud detection engine. “Customers begin to notice that the bank can recognise when something unusual is happening while their normal activity is not disrupted without good reason.” Rather than creating additional friction, well-governed AI allows banks to become more responsive, more accurate and ultimately more trusted.

Compliance Alone Will Never Create Resilience

Although cybersecurity regulations continue expanding across Asia Pacific, Ganapathy warns organisations against confusing compliance with preparedness. “The most persistent misconception is that compliance equals security.”

Meeting regulatory requirements undoubtedly matters. Certifications, audits and governance frameworks establish important foundations for operational discipline. However, they do not guarantee that organisations can respond effectively when sophisticated attacks inevitably occur.

Cyber resilience depends on far more than documented controls. She also cautions organisations operating within highly developed financial markets against becoming complacent. “Singapore is a sophisticated financial hub, but sophistication attracts sophisticated adversaries.”

Digital maturity often increases organisational complexity, expands the attack surface and creates additional opportunities for attackers. Perhaps the greatest source of overconfidence, however, remains the belief that technology alone can solve cybersecurity.

“As long as humans remain part of the banking process, whether as customers, employees, or third-party vendors, there will always be a human attack surface.” The organisations best prepared for the future will therefore be those investing equally in technology, employee awareness, organisational culture and customer education. Sustainable cyber resilience requires all four working together rather than relying on technology alone.

Cybersecurity Is Becoming a Human Discipline

Looking ahead, Ganapathy believes tomorrow’s technology leaders must undergo one fundamental mindset shift. “We should stop thinking of cybersecurity as a problem to be solved and start thinking of it as a condition to be managed.” There will never be a moment when organisations can declare themselves permanently secure. Threat actors continue evolving, increasingly supported by Artificial Intelligence and ever more sophisticated psychological manipulation techniques.

Success will therefore be measured less by preventing every attack and more by an organisation’s ability to detect incidents quickly, respond decisively and continually improve after each event. “There is no permanent state of being secure.” Ultimately, Ganapathy believes the future of cybersecurity depends on recognising a simple but often overlooked truth. “The most dangerous attack surface is not found in code or cloud infrastructure. It is found in the minds of the people who use and operate these systems.”

That observation captures the direction in which the entire industry is moving. As digital banking becomes increasingly intelligent, connected and automated, the strongest security strategies will not simply protect technology. They will be designed around people, understanding how trust is formed, how decisions are made and how resilience can be strengthened through both innovation and empathy. For banks seeking to build lasting customer confidence, that may prove to be the most important security investment of all.

Connect with Subhalakshmi Ganapathy

Cybersecurity is evolving beyond technology into an increasingly human-centred discipline, and conversations like these are helping shape the future of digital trust across Asia. To follow Subhalakshmi Ganapathy’s latest insights on cybersecurity, identity, AI and enterprise resilience, connect with her on LinkedIn.