A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Banca Ifis
Cyber Resilience in Finance: Building Trust in a Quantum Future


Laura Quaroni
Laura Quaroni, Head of Privacy & Security at Banca Ifis, is an experienced cybersecurity leader specializing in ICT risk management, data protection, and regulatory compliance. She has built dedicated security teams from the ground up, driving resilience, awareness, and innovation across the banking sector.
In this article she shared invaluable insights on Building true cybersecurity resilience in finance requires a proactive culture, supply-chain vigilance, quantum-safe encryption strategies, and AI-aware defenses to stay ahead of evolving digital threats.
1. Can you share the key experiences and milestones in your career that have led you to your current role at Banca Ifis?
I joined Banca Ifis in 2013, also thanks to the supervisory regulations which began to focus attention on ICT risk management, IT security, etc.
There was no specific department in the Bank, I had the opportunity to create a team of dedicated and competent people in security, business continuity and privacy starting from nothing, from my only professional experience, with dedication to work and stubbornness. I have witnessed managerial evolutions that have always supported me on security issues and initiatives, up to an absolutely shared corporate culture of Cyber Security, supported by Management and the Board itself. As often happens, it takes time, commitment and dedication, also dedicating space to working groups, communities and networking and sharing one's skills and knowledge on the market.
2. Given your experience with privacy audits, what are the most common compliance gaps you observe in financial institutions, and how should they be mitigated?
The legislation about Data Protection is now consolidated. Companies, financial institutions, but not only, adhere to the GDPR by applying all its requirements in their daily lives, adopting processes and systems already designed from a privacy perspective. However, we often become aware of data breaches, which sometimes affect our own personal data. Often, they arise from incidents that occur along the supply chain of service itself. Well, perhaps greater attention, not only formal and contractual, but also substantial along the entire supply chain, would help ensure the safety of the entire system. From this point of view, regulations on cyber security and resilience (DORA, NIS2, etc.) are helpful.
3. With increasing cyber threats targeting the financial sector, what strategies do you employ to enhance IT risk resilience at Banca Ifis?
Being resilient requires facing several significant challenges. It is essential that staff are adequately trained in new regulations and digital operational resilience practices. Close oversight of digital service providers is also desirable, which can be difficult for institutions with numerous partners to manage.
Overcoming these challenges requires a holistic approach and, above all, the collaboration of different structures within financial institutions. The key to success lies in strategic planning and implementation of processes that ensure continuous compliance and effective digital operational resilience.
4. How do you see quantum computing impacting encryption and cybersecurity preparedness in the financial sector?
The G7 Cyber Expert Group recently released a statement highlighting the potential cybersecurity risks associated with quantum computing developments. The birth, as well as the relative evolution, of quantum computers represents important technological progress but, paradoxically, this technology risks jeopardizing the "encryption" technology which is currently used in many activities of our digital society.
Quantum computers can solve computational problems currently considered too complex for conventional computers in a reasonable time frame. While quantum computing can offer significant benefits to the financial system, it also poses unique cyber security risks.
“Cyber resilience isn’t built overnight, it’s a culture of awareness, collaboration, and foresight, ensuring data protection evolves as fast as the threats we face”
The computing power released by quantum computers is such that it can undermine current cryptographic systems, putting data at serious risk, violating the confidentiality and integrity of financial entities' data, including customer information.
The G7 Cyber Security team of experts encourages authorities and financial institutions to undertake a migration path towards quantum computing in order to mitigate the risks associated with the developments of this innovative technology.
5. Beyond regulatory compliance, what proactive measures should financial institutions take to build a culture of security resilience at all organisational levels?
The continuous evolution of cyber threats represents one of the most important challenges for those involved in Cyber Security and for the very resilience of organizations.
Awareness activity has become fundamental to maintaining a high level of awareness on cyber risks that can compromise the security of companies and the protection of sensitive, personal and customer data, highly confidential financial and business data.
It cannot be ignored that all the people who make up an organization receive adequate training and are informed and sensitized in the conscious use of IT systems.
It therefore becomes crucial to develop a correct and effective cybersecurity culture, regardless of the role and responsibilities of the individual employee: everyone must have the right awareness of the risks and their ability to prevent accidents and/or manage them, becoming an active part of an increasingly complex mechanism.
6. How do you see artificial intelligence impacting privacy and security practices in the banking sector?
The use of AI is undoubtedly a source of opportunities, also for the banking sector. However, rapid advances in AI capabilities, the increased availability of computational resources, and the widespread availability of public and open-source AI tools have lowered the barrier to entry for attackers, giving rise to more sophisticated, persistent, and potentially more damaging threats.
Using artificial intelligence, bad actors can automate and optimize their attacks, making them more efficient, scalable and adaptive, thus posing greater challenges to traditional defenses.
7. What advice would you give to IT leaders in the financial sector who are looking to strengthen their organisation’s cyber security posture while driving digital transformation and regulatory compliance?
Digital transformation requires an increase in the amount of data and information to be stored and managed, therefore requiring an approach to security and data protection different from the traditional ones and increasingly risk oriented.
These challenges need to be addressed with a growing involvement of cybersecurity and data protection specialists in the various project initiatives, particularly those with a high digital connotation. The return on investment of cybersecurity initiatives is difficult to quantify and is generally not realized immediately, post-implementation of new security systems and solutions. Only with full awareness not only that information security and data protection are the basis of the digital project but also that the relative return on investments will be in the medium to long term. The innovations introduced in the European legislation on data protection and digital resilience favor this corporate culture, allowing companies to present customers with an increasingly secure, transparent and resilient service and product.