Cybersecurity measures are a priority at Royal Bank of Canada (RBC), from monitoring and mitigation to solution investment.
Banks rarely consider cybersecurity a finished process; the nimbleness of fraudsters and quick development of new hacking technology spur perpetually evolving security measures for risk and anti-money laundering (AML) divisions at most large financial institutions. But keeping cybersecurity agile goes far beyond yearly tweaks and minor investments, Shekher Puri, vice president of digital components and platforms at $1.4 trillion RBC, tells Bank Automation News in this episode of “The Buzz” podcast.
Cybersecurity is “an investment in perpetuity,” Puri says. “This is millions of dollars every single year that we’re putting in and investing into these various technologies. Some of them are proprietary, and some of them we’re going out to the marketplace, and we’re looking at the best vendor solutions and the best supplier solutions.”
Adding nuance to this “full-court press” approach, Puri tells BAN that tackling cybersecurity at the solution architecture stage of development is key to a top-quality technology and strategy stack.
“Make sure that cybersecurity is built up a lot higher in the process,” Puri says. “They should be at the table as you’re designing your product, as you’re designing your experience, as you’re designing your flow. They should not be an afterthought.”
Listen as Puri details RBC’s cybersecurity and risk management approach for BAN, and discusses best practices for smaller banks embarking on the cybersecurity journey.
Bank Automation Summit Fall 2022, taking place Sept. 19-20 in Seattle, is a crucial event on automation and automation technology in banking. Learn more and register for Bank Automation Summit Fall 2022.
Subscribe to The Buzz Podcast on iTunes, Spotify, Google podcast, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Welcome to the Buzz, a Bank Automation News podcast. I’m Associate Editor Alijah Poindexter. Recently I spoke with Shekher Peri, VP, digital components and platforms at Royal Bank of Canada. We discussed RBCs approach to cybersecurity innovation and investments and also discussed best practices for smaller banks embarking on a cybersecurity journey.Shekher Puri 00:43
Yeah, absolutely, Elijah. And first of all, thanks again for, for having me talk about this very important topic with you. So, you know, maybe just a step back, you know, as you can imagine, being one of Canada’s and, frankly, even North America’s leading financial institutions, trust and security are something that are absolutely paramount and foundational to us. You know, clients, as you know, they trust us with some of their most sensitive and personal information. And protecting clients and protecting their information is, is mission critical for us. So, you know, one of the trends that we’ve started to notice is that the look at the bad guys, the fraudsters, the surface area has expanded. And they are now starting to move to you know, what we used to see more on the physical channels, and they’re now starting to move more towards the digital channels. And, you know, those are, those are new threat vectors. And, like I said, a new playground for the bad guys to be playing in as more and more clients and more and more transactions are moving to digital channels, like online banking, and, and mobile, as well. So, you know, from an RBC perspective, we’ve taken a very deliberate approach to investing very heavily in various different technologies, you know, controls and monitoring mechanisms around the digital space. But basically, Elijah, it’s to ensure that clients continue to continue to be enabled, and have access to these various different digital products and services, and ways to interact with the bank, but still providing them, you know, top of the food chain, security, privacy, and fraud mitigation measures, as well. And that’s where Elijah, you would have seen, you know, some of the new products and services that we’ve either released or enhanced. Over the last little while, we’ve, as you may know, released a pin on mobile feature. Very recently, we have two step authentication, what we call multi factor authentication. As well, we’ve also been a leader when it comes to digital identity. So all of these pieces, Elijah speak to what what you’ve asked, which is, you know, enabling clients to do more delivering world class digital experiences, but all while making sure that trust and security are paramount for underpinning all of these,Alijah Poindexter 03:23
you know, fraudsters are a lot of things. But I think we can all agree that fraudsters are not stupid, right? They they’re extremely, you know, shifty and quick to adapt and address any and pretty much all cybersecurity measures that banks fintechs and the clients and customers themselves, whether commercial, or retail, can kind of put out there, right. And so obviously a best practice there is is doing due diligence, but from the bank angle, right, maybe talking about RBCs approach, and then maybe a best practice for other banks when it comes to being nimble, right, and sort of addressing the constantly shifting and always quick to find a new chink in the armor, so to speak of fraudsters in the digital age.Shekher Puri 04:03
Well, you said it really well, Alicia and love the way you frame this look, the fraudsters are smart. The bad guys are smart, and they’re always on the cutting edge. And, and the nimble and agile approach is correct. So structurally, what we’ve done at RBC, which may or may not be unique, but it works really well for us is we partner extremely tight and closely with our global cyber service teams, our fraud teams, our various different digital channel teams in our lines of businesses. So we come come at this across multiple teams and how we collaborate and really make sure that we are looking at things from not only a perimeter perspective, so what’s going on in the macro environment in regards to new threats and ways to detect them as well. But then what we’re also doing is shoring up a lot of our core properties, whether that’s our front door from a sign in perspective, and then a lot of the monitoring that happens once you or in our container. And once you’re transacting as well, and looking for some of those anomalies or those behaviors, that could be great indicators that this is this is a fraudster or someone that’s impersonating our clients. So really, Elijah, it’s a multi pronged approach, and really leveraging the full court press across our various different teams to really collaborate and making sure that we’re on the cutting edge of detecting new risks and new new new threats as well. And that’s one of the reasons why we’ve we’ve continued to be, you know, first for a lot of these different rollouts of capabilities, whether you know, even if it’s our card lock feature as well, a lot of the AI capabilities that we’ve invested in with our fraud monitoring as well, this is Elijah an investment in perpetuity, like, this is millions of dollars every single year that we’re putting in and investing in these various different technologies. Some of them are proprietary, and some of them, we’re going out to the marketplace. And we’re looking at the best vendor solutions and the best supplier solutions. So again, full court press on what we’re bringing in to our to our environment to protect our clients.
Alijah Poindexter 06:14
You know, one of the big talking points in the FinTech and digital banking environment, right is build versus buy. And and it’s not even really that interesting of a discussion, because the answer is it depends. On the cybersecurity and the risk front, it’s less build versus buy and more partner or program, right? So are you going to partner with with some somebody in the FinTech of the cyber digital cybersecurity ecosystem, right for a solution? Or are you going to maybe again, like you say, proprietary, it’s more internal, your response to that, again, would be probably it depends on the situation for the bank. Right?
Shekher Puri 06:48
But yeah, absolutely. Elijah, it depends on you know, what the situation is, and, you know, how sometimes how scalable solutions are, if there’s something that’s a very, you know, unique and niche specialization that’s being offered? And, you know, how do some of these solutions integrate with our existing stack, as well. So when we look at solutions, that’s not only, you know, looking at them in absolute terms, but also looking at them in relative terms in regard to interacting with our existing platform as well. So I think you hit the nail on the head. This isn’t, you know, a filler a philosophy word, no, no, no, we’re always going to build or no, we’re always going to be looking out and buying, but it’s really looking at what’s the problem that we’re looking to solve, and what makes the most amount of sense in regards to bringing out the very best version of of any particular solution. I mean, Elijah, my team takes a lot of time and and part of our role is really scanning the marketplace. Looking at a lot of the the the innovators in the technology space, looking at some of the, you know, the cutting edge suppliers and the fintechs, and the innovators and what they’re doing in this space. And a good part of our job is meeting with with a lot of these technology, technology companies as well and assessing some of their solutions and working through some of these problems collectively, Elijah, we, we have a lot of a lot of strengths and a lot of things that we’re proud of. But we also have a lot of humility to know that look, there could be other companies that can be doing great things and why wouldn’t we collaborate? Be crazy for us? Not too
Alijah Poindexter 08:30
often does RBC take, you know, sort of take stock, if you will, the sort of cybersecurity and risk capabilities on offer right. So is it? Is it a bi annual, annual as a monthly, daily, weekly? Or is it some combination of those when it comes to sort of analyzing the existing cybersecurity and risk and trust stack? What walk me through what that looks like from RBCs? perspective?
Shekher Puri 08:52
It’s, I would say, Alicia, the simple answer is, it’s an always on, right. So we are constantly monitoring the environment. We’re constantly monitoring, you know, for new threats, we’re on the dark web, we’re looking at all of these, all of these different occurrences and bringing them in and we have various different exercises that we go through. And they do have various different frequencies attributed to them. Some of them, like I said, our monitoring, some of them could be weekly, some of them could be a little bit less frequent. And that can be broader table, tabletop type, risk exercises that we conduct as well. But I can tell you that you know, with the various different roles and responsibilities across the organization, whether it’s cyber security, whether it’s fraud, whether it’s digital, we all are sharing the collective responsibility to not only independently work but also bring our collective intelligence to the table and have regular reviews of what we’re seeing and working through through those various different types of situations. Elijah, so sorry, it’s a bit of a mixed answer I’m giving you here. But, but it really isn’t an old way, Vaughn. For us. It’s mission critical, Elijah, and one of the things that’s been ingrained in our DNA is that this is everyone’s responsibility. So and it truly is, but we do have defined, you know, roles and mandates associated with them. But collaboration, I think, is really the key here.
Alijah Poindexter 10:27
Absolutely. And that kind of brings me to my next point, right is is, you know, what does, what role does automation play when it comes to comes to these, these trust risks? cybersecurity, what role does automation play from RBCs? Perspective?
Shekher Puri 10:40
Yeah, so there is automation throughout our various different processes. As well, Elijah, you know, we do use a lot of automation and AI in our in our fraud control environment as well, we use it a lot in our monitoring environment as well. We tend to use a lot of automation, when we have known patterns, and aligning that automation against known patterns. But to also augment automation, we do have various other mechanisms to detect new patterns, new attack vectors, and such as well. So it is a little bit of a combination, but we do automate, and try to index a little bit more on the known threat vectors.
Alijah Poindexter 11:24
Yeah, and you know, when it comes to automation, obviously, there’s always a bit of a battle on the bank. And, you know, what does automation look like? What’s under automated? What does over automation look like? So obviously, would you say at RBC, the human plays an equally important role in these automated environments when it comes to cybersecurity, right? Oh, yeah,
Shekher Puri 11:42
yeah, absolutely. And again, it it, you have to have that built in Elijah, you have to have the human factor into it, you have to have the automation, and they have to be working together as well. Because you know, you still need to be checking on the systems to ensure that they are performing the way that they are. And you are having a little bit of that independent testing as well, to validate some of those results, and ensure that you are, you know, feeding the right types of data elements into that automation process. So the humans have to work very, very closely with any of these automated processes that we have in place.
Alijah Poindexter 12:21
What are some of the pain points that you encountered? If you can speak about that when it comes to sort of implementing and deploying these these hyper digital, hyper automated cybersecurity sort of efforts and integration? What were some of the pain points there? And how did you kind of overcome those hurdles?
Shekher Puri 12:36
Well, look, a lot of times you’re, you know, it’s particularly Elijah Wood, maybe where I could take this. This question is more on the on the novel areas, or the new technologies or the new patterns that we introduce the the balance that you’re always trying to achieve by introducing these patterns is you’re balancing client experience and friction with these new patterns as well, right. And that’s the key piece for us here. And you want to get that balance, right? Look, I can put up such high controls and make fraud zero, but guess what, none of our clients are going to be able to bank anymore, and they’re not going to be able to access their online properties. And their digital properties. Like that’s the the one end of the goalposts or the other end of the goalposts, I make it so easy that that fraud is getting through very, very, very easily as well. So you have to achieve this right level of balance, where you are introducing, you know, the right security and the right friction, but and keeping the bad guys out and making their lives very, very difficult. But at the same time, not so much friction, where the clients are getting frustrated with the experience, and they’re dropping off. And basically, you know, they’re saying, Look, your experience sucks, and, and I don’t want to bank with you anymore. I’m just gonna go into a branch channel, which completely defeats the purpose. I think that’s the piece, I think, Elijah that we’re always trying to strike the right balance for, right. You know, when do we have to be more overt? With our security posture? When can we be a little bit more passive behind the scenes? And when do we need to, you know, we introduce the right amount of friction, because it just, it absolutely makes sense. So I think Elijah, that’s, that’s, that’s the one that keeps us up at night.
Alijah Poindexter 14:27
What you know, let’s say a bank is embarking on a digital journey, and it’s a bit of a cliched sort of phrase, but it still rings true. It’s, it’s still only been, you know, about two a little over two years since the COVID. 19 pandemic obviously changed the entire landscape of financial services, let’s say let’s say a community bank is embarking on their digital journey. Let’s say they get the core provider, they get the payments in place, they have the infrastructure in place. Now they come to cybersecurity and trust and risk and AML all that good stuff. What are some best practices there? Where should they be looking at kind of start with, you know, what should they be keeping a close eye on? How can they best embark on that sort of digital trust and risk? And in the cybersecurity portion, where should they start?
Shekher Puri15:12
Yeah, well, look, I would like to see a, you know, a financial institute institution that starting off, actually make sure that cyber and security are actually built up a lot higher in the process, right, like part of this really should be, you know, they should be at the table, as you’re designing your product, as you’re designing your experience as you’re designing your flow, they should not be an afterthought. And that’s some of the issues that we sometimes see with, with with some of the institutions as they get so busy in designing Oh, it’ll be this onboarding experience. And this will be the product offering and getting really focused on how clients are clicking through the different screens and what they need to look like. And then they’re like, oh, yeah, now let’s bring in our security folks, and make sure things are cinched up. And I think that’s where you’re already behind. I think what you need to have is you need to have, and this works really well with us is we actually have our fraud and our security partners, when we’re actually at that solution architecture. And we’re designing out what these products and solutions and experiences look like. So that way, we’re not trying to retrofit and fix things that are wrong. But we actually have security built right into the design, right into the pattern right into the flow. And that’s been really one of our differentiators, when we started to really double down on our digital experiences, recognizing that look, our security teams and our fraud teams need to be there with us on day one, when we’re designing out these experiences, and, and ensuring that we get it right right away. So that’s probably like one of the things I would highly recommend. The other piece is, look, when you break out security, you have to really break it out, as I mentioned this earlier, like, you have to look at things on the perimeter, right? What’s going on in the macro environment, making sure that you have the right detection and defenses before he even hits our front door. And then when it hits our front door, what are your security and controls on that front door, making sure that you have the right authentication in place, that you do have that high level of assurance that this is Elijah? He says he’s Elijah, he claims these Elijah, but how do we get that high level of assurance that it is light, and that’s one of the reasons why, you know, we we rolled out multi factor authentication, as well. So that way, there was a higher level of assurance that we know who this person is that we’re that we’re dealing with, once they’re in your properties, I mean, the third thing I would say is you’ve got to have strong monitoring and controls. So let’s For argument’s say, Say say Elijah, the bad guy gets through the perimeter, the bad guy somehow manages to get through the front door. And remember, there’s layers of of authentication security we’re putting in. So it’s gonna have to be a pretty sophisticated attack. Then once they’re in, in your properties, you’ve got to have strong monitoring and controls, you’ve got to be able to recognize that look, these are not your typical patterns, you know, whether that’s using, you know, behavioral biometrics, or other different types of authenticators. But you got to be able to then recognize the various different patterns and, and monitoring and controls to ensure that you’re comfortable with this. And if you’re not, how do you put a stop and then alert the client that hey, is this us? That’s not you. And that’s again, Elijah, one of the features that we put out was to a fraud alerts, is to make sure that if we detect something that might be a little suspicious, that we alert the client and ensure that we stopped that transaction, and we alert that client to say, hey, is this you? We want to be sure. And that way, you can kind of do a little bit of that intervention. So I mean, Elijah, that’s kind of how I would break it down, look at the perimeter, make sure you have a strong strong front door and your back doors are all covered off. And then once you have someone in the environment, or what kind of strong monitoring and controls he had placed in that particular environment, that’s probably the best advice I’d give. You know, one of the things Elijah that we looked at really strongly was the front door more recently into various different authentication experiences. And one of the things that we’re really happy and proud of is our is our pin on on mobile device. Authentication. We what we’ve done here is we’ve taken a pattern that Canadians are already used to like Canadians are used to, you know, going to merchants and tapping their card and entering their pin going to an ATM to do that as well. So they do that for E comm are taking money out of ATMs. Why are we not using that same pattern? That’s so well recognize you have ubiquity for you, no clients, no way and using that to authenticate a client. And we thought that was a novel way of introducing a new way of authenticating high security. But the pattern already exists in the marketplace, clients already know it, they already trust it. So now what we’ve done basically Elijah is we said to a client, look, you got to have your client card physically present, you have to be able to and making sure that that chip on that card, we can read that card, so it hasn’t been tampered with. You tap it on a device where we know you, and you’re entering the pin. So you think about it, that’s layers of security and authentication that built into that simple tap and pen to provide us that high level of assurance that this client is who they say they are. And those are the types of patterns Elijah that we’re always looking out for.
Alijah Poindexter 20:46
Yeah, absolutely. And going back to, you know, sort of, again, I think you’ve made an amazing point, which is, again, for a lot of these banks and financial institutions to have the cybersecurity partners there have the cybersecurity team, they’re at the stage of solution architecture at our RBC, that apply is that’s enterprise wide, right. So that’s payments, Wealth Management, obviously, you know, banking from both commercial retail, from RBC side, when it comes to, you know, driving that solution architecture, and having a cybersecurity sort of partners and team there. That’s really enterprise wide, you’d say,
Shekher Puri 21:19
yeah, yeah, that’s ingrained in our DNA, Elijah. And that’s, that’s something that we’re really proud of, as well. I mean, these are our functional partners, we see the value that they bring to the table. And it really is our secret sauce. It’s been ingrained in our DNA is how well we partner with.
Alijah Poindexter 21:36
Yeah, absolutely. You know, wrapping up with a little time we have lap once again, this has been an amazing conversation. What’s next, right? So for RB on RBCs. And maybe you can walk me through, you know, you know, to whatever extent you can, of course, what’s next for RBC when it comes to cybersecurity, risk anything in this area? We know what can people expect? Well, look,
Shekher Puri 21:55
I in absence of you signing an NDA with us. I’ll try to share what I can but look, one of the things that we’re really zeroed in and focused in on Elijah, and I’m glad you asked that question is around data sharing, as well and, and moving traffic away? You know, look, let me let me again, step back on this one, we value the fact that clients want to use RBC for their primary banking relationships. But what we also acknowledge is that clients want to they want to use third party FinTech applications, whether that’s, you know, for money management, whether that’s for budgeting, that’s for insights, as well, they want to use these applications, they really like using these FinTech apps as well. But what we want to do is if clients do want to use these FinTech apps, and they want to share their financial banking data with these third parties, like should, we want to ensure that clients are able to do it in a safe and secure manner, in a manner where their their privacy is also protected as well. And frankly, Elijah, our clients don’t need to give up their login credentials, their passwords as well. And that is today, traditionally, what the methodology has been visa vie screen scraping, what our focus right now is to move the screen scraping traffic away, or starting to move this traffic away from screen scraping. And moving on to an off YDC API based methodology, where clients no longer need to share their login credentials with third parties. And they have full access and control over which data elements are being shared, and what they’re being used for. So what we’re trying to tackle is trust, security and privacy. And that’s really our focus. It’s it’s top of mind for us. And you would have seen Elijah, you know, us make some real strong momentum over the last couple of weeks with us, you know, announcing that we’ve signed data access agreements with two of the largest data networks in in North America, namely plaid and and Yodlee. And really what those agreements are saying is we’re going to start to move that traffic away from screen scraping to using this consent based API solution.
Alijah Poindexter 24:13
You’ve been listening to the buzz, a bank automation news podcast. Thank you for your time, and be sure to visit us at Bank automation news.com For more automation news, you can also follow us on Twitter and LinkedIn. Please don’t hesitate to rate this podcast on your podcast platform of choice. Thank you






