CIMA Members in Europe

 View Only
  • 1.  Cyber, fraud and resilience

    Posted 04-30-2026 10:07 AM

    Interesting how these key conversations still get split internally:

    ·       Cyber sits in one corner.

    ·       Fraud in another.

    ·       Operational resilience somewhere else.

    ·       Finance gets pulled in once the consequences become measurable.

    But my view from various risk management roles in finance and planning is that these are increasingly the same conversation. They all land in the same place eventually: losses, disruption, accountability failures, damaged reputation.


    I'd be interested to hear how others have handled this organisationally. 
    What helped move these topics from "technical issue" to "business and finance priority" in your company?



    ------------------------------
    Gerrit Wilhelmij
    Qafco
    Madrid
    +44 7703546132
    ------------------------------


  • 2.  RE: Cyber, fraud and resilience

    Posted 05-14-2026 06:45 AM


    Cybersecurity started with finance because I identified the risk and then made it a priority to get done.

    I came in at the early stage of my company's development so I ended up sponsoring and directing the build out of my firms cybersecurity infrastructure which included selection of the cybersecurity vendor to get a Managed SIEM, Penetration test, and Cyber Essentials and Cyber Essentials Plus audits done.  Getting third party backup in place, mandating the use of VPN's since my company is largely remote, and implementing a vulnerability and patching system to ensure people's systems are up to date.



    ------------------------------
    Jason Knox
    London
    +4407954243429
    ------------------------------



  • 3.  RE: Cyber, fraud and resilience

    Posted 05-24-2026 12:59 PM

    Great to hear Jason that Finance in your company has been setting the agenda for cyber and taking the lead.

     

    My experience in various finance and governance roles at corporate and operational levels in an international energy company has been varied, with plenty of silos and inconsistencies.  In the international investment business, Finance took the lead for business resilience and risk while cyber was addressed by IT.  In the corporate area, Finance only led on risk management with cyber left to a specialist IT team, while compliance and addressing fraud was a legal responsibility. In operating entities Finance generally had little to do with cyber which was left to IT, and little to do with resilience and risk except to bear the consequences of data process failures.

     

    This situation does not align with the expectation that Finance should provide some level of reassurance on the integrity and reliability of data underpinning corporate performance, financial reporting and associated decisións. This expectation implies it has the right to set priorities and requirements for data process and technology resilience, and for compliance controls. Finance also has the appropriate professional competencies and critical mindset.

     

    However Finance seems pushed to the side with an overall agenda set by others.

     

    Is this the experience of others? If so, what are blockers and challenges for Finance, and what steps should we in Finance be taking?  Are there examples of organisational approaches where the data integrity priorities and emerging concerns of Finance and other functional áreas are addressed in a balanced and agile way?  Is anyone aware of moves towards something like a multi-disciplinary "resilience (or risk) operations centre"?








  • 4.  RE: Cyber, fraud and resilience

    Posted 05-26-2026 04:19 AM

    Based on experience and networking, I would say your position is not isolated although different organisations can be at different stages of maturity. Having separate and specialised functions for Cyber, Fraud, Business Resilience especially in larger businesses is common and not necessarily a bad thing.

    What is important is that they they do talk to each other where subjects intersect and that such interaction is structurally built into the system and not ad hoc and solely dependent on people's personalities.

    I was recently a part of an organisational project to map out the roles of the 3 lines (of defense), where they overlap, where there are gaps and what needs to be done to make the approach more cohesive. I would recommend such an exercise for any medium or large organisation which has not already done it. Ideally with sponsorship from the Board, Audit Committee and/or Senior Leadership Team. That will put the spot light on (expectations) of Finance, Compliance, Legal, Operations and what challenges are faced including any missing links when priorities/strategies are made for a business or function.

    I hope this is useful to you.



    ------------------------------
    Shehan Goonewardene
    The Hague
    ------------------------------



  • 5.  RE: Cyber, fraud and resilience

    Posted 05-30-2026 08:14 AM

    Thank you Shehan for outlining a helpful context and overall considerations for cross-disciplinary control arrangements.

     

    With an appropriate control environment in place, as Vivek indicates, people aspects and maintaining awareness is important.  Having a "Phish Alarm" or "Incident Reporting button" to alert all concerned departments is an interesting, practical consideration.  This raises the question on what trigger / escalation criteria apply and, as follow on, what are the criteria to convene response teams at operational, management or executive levels.

     

    To get a non-finance perspective on this overall topic, I reached out to a cyber professional colleague who provided the following on the need to speak more in the language of numbers:

     

    "Even when there are highly specialized teams, collaboration and coordination should be made mandatory and systemic - not ad hoc. Certainly if cyber risk, and all risk for that matter, is quantified then the conversation becomes more structured and grounded on data.

     

    Finance doesn't operate in the realm of questionable business theory and colorful, visually pleasing make-believe reports. The moment we in cyber and risk disciplines start speaking in the language of numbers, finance teams will understand and respond appropriately.

     

    So who's to blame? Largely risk and cyber professionals. Next is of course top management for failing to understand that all risk is financial risk in most businesses."

     

    Any views on this from a finance perspective and for other functional stakeholders?








  • 6.  RE: Cyber, fraud and resilience

    Posted 05-25-2026 01:38 AM

    Indeed an interesting topic, in my view and experience even when these roles sits in different departments/Functions if there is an organization wide "Awareness" about the Risks and Threats, Cyber or Physical, it helps in creating a Control Environment. If we provide tools like "Phish Alarm" or "Incident Reporting button" which alarms all concerned departments whenever an employee uses these alarms, which helps different Defending teams to work in tandem and mitigate the risks.

    Creation of right Control Environment

    Creating Awareness about the Risks and existing mitigating Controls

    Clearly defined Roles and Actions, irrespective of the Functions and Departments in case of an Alarm is raised

    I think these are some important considerations in addition to roles and controls in place.



    ------------------------------
    Vivek Sharma
    Ipg Advertising And Business Services Llp
    Navi Mumbai
    +919160101118
    ------------------------------



  • 7.  RE: Cyber, fraud and resilience

    Posted 06-11-2026 10:56 AM

    Cyber security remains a hot topic, and rightly so. As cyber risk continues to rise, expectations on finance professionals are increasing too.
    We want to help CIMA members feel more equipped and confident to navigate this complex area, which is why – in partnership with Templar International Group – we are launching our Cyber Clinic.
    This initiative offers free, confidential 1:1 sessions with cybersecurity experts, giving you practical, tailored advice to help strengthen your organisation's resilience. First sessions start 17 June!
    Invitations have already been sent to all CIMA members across Europe-please check your inbox for full details. More dates are also planned for September and November, but we recommend booking early to secure your slot.
    👉 https://forms.office.com/r/XMdP0qs2TG

    For full details, visit the Events section in the community.



    ------------------------------
    Anna Hopcroft
    ------------------------------