{"id":{"repo_id":"malta","oai_identifier":"oai:www.um.edu.mt:123456789/30578"},"canonical_url":"https://search.dev.ndltd.org/etd/malta/oai:www.um.edu.mt:123456789/30578","repository":{"repo_id":"malta","name":"University of Malta","base_url":"https://www.um.edu.mt/library/oar/oai/request"},"display":{"title":"An analysis of the cyber risk management practices in the local banking industry","abstract":"Purpose: Banks rely heavily on technology, and while technology innovation is ever-increasing, it also provides new opportunities for cyber criminals. The researcher sought to acquire an indepth insight of the cyber risks that Maltese banks are exposed to, with the aim of analysing the relevant risk management processes these banks have in place to control and mitigate cyber risks to an acceptably low level. By using the acquired information, the study intends to assess whether the local banking industry as a whole is appropriately postured to defend against cyber threats. Design: By virtue of its nature, the study makes use of qualitative research. Semi-structured interviews were set up with personnel from local banks working in the risk management function or those affiliated with risk, particularly those involved in cyber risk management. Being an inductive study, the research is supplemented by reference to other available literature. Findings: The findings resulting from this study illustrate that there is a considerable discrepancy between the cybersecurity controls adopted by the core domestic banks and those implemented by the majority of the other banks. This is typically due to the fact that the latter have lesser available resources; however, in view of their size, some mistakenly believe they would most probably not be a target for cyber attacks. In contrast, the safeguards and robust controls set by the larger banks are very meticulous, which allow for adequate management of any cyber threats that may be encountered. Conclusion: In spite of having lesser resources, the majority of the other banks still apply certain risk management practices to mitigate cyber risks, albeit the need for improvement. Nonetheless, considering the whole sector, it may be concluded that the local banking industry is sufficiently postured to defend against cyber threats, as evident from the fact that none of the interviewed banks have been a victim of a significant cyber attack in the past 12 months, despite receiving multiple cyber attacks on a daily basis. Value: This study intends to raise awareness about the importance of cybersecurity in the local banking industry, as cyber risks can otherwise disrupt business activities resulting in loss of revenue and can cause considerable reputational damage, including eroding shareholder, investor and customer confidence. This study can be beneficial for local banks in identifying any area of weakness, while also receiving a number of recommendations submitted by the author.","abstract_html":"Purpose: Banks rely heavily on technology, and while technology innovation is ever-increasing, it also provides new opportunities for cyber criminals. The researcher sought to acquire an indepth insight of the cyber risks that Maltese banks are exposed to, with the aim of analysing the relevant risk management processes these banks have in place to control and mitigate cyber risks to an acceptably low level. By using the acquired information, the study intends to assess whether the local banking industry as a whole is appropriately postured to defend against cyber threats. Design: By virtue of its nature, the study makes use of qualitative research. Semi-structured interviews were set up with personnel from local banks working in the risk management function or those affiliated with risk, particularly those involved in cyber risk management. Being an inductive study, the research is supplemented by reference to other available literature. Findings: The findings resulting from this study illustrate that there is a considerable discrepancy between the cybersecurity controls adopted by the core domestic banks and those implemented by the majority of the other banks. This is typically due to the fact that the latter have lesser available resources; however, in view of their size, some mistakenly believe they would most probably not be a target for cyber attacks. In contrast, the safeguards and robust controls set by the larger banks are very meticulous, which allow for adequate management of any cyber threats that may be encountered. Conclusion: In spite of having lesser resources, the majority of the other banks still apply certain risk management practices to mitigate cyber risks, albeit the need for improvement. Nonetheless, considering the whole sector, it may be concluded that the local banking industry is sufficiently postured to defend against cyber threats, as evident from the fact that none of the interviewed banks have been a victim of a significant cyber attack in the past 12 months, despite receiving multiple cyber attacks on a daily basis. Value: This study intends to raise awareness about the importance of cybersecurity in the local banking industry, as cyber risks can otherwise disrupt business activities resulting in loss of revenue and can cause considerable reputational damage, including eroding shareholder, investor and customer confidence. This study can be beneficial for local banks in identifying any area of weakness, while also receiving a number of recommendations submitted by the author.","abstract_has_math":false,"creators":[],"institution":"University of Malta","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2017,"date_issued":"2017","date_published":"2017","updated_at":"2026-07-27T20:12:17Z","subjects":["Risk management -- Malta","Computer crimes -- Malta -- Prevention","Computer security -- Malta","Banks and banking -- Malta"],"languages":["en"],"rights":["info:eu-repo/semantics/restrictedAccess"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://www.um.edu.mt/library/oar//handle/123456789/30578","outbound_label":"Repository record","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2018-05-31T07:26:30Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2018-05-31T07:26:30Z"]},{"key":"dc:date.issued","label":"Date","values":["2017"]},{"key":"dc:publisher.department","label":"Dc Publisher Department","values":["Faculty of Economics, Management and Accountancy. Department of Accountancy"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["University of Malta"]},{"key":"dc:type","label":"Dc Type","values":["masterThesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Risk management -- Malta","Computer crimes -- Malta -- Prevention","Computer security -- Malta","Banks and banking -- Malta"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["info:eu-repo/semantics/restrictedAccess"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://www.um.edu.mt/library/oar//handle/123456789/30578"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["M.ACCTY."]},{"key":"dc:description.abstract","label":"Abstract","values":["Purpose: Banks rely heavily on technology, and while technology innovation is ever-increasing, it also provides new opportunities for cyber criminals. The researcher sought to acquire an indepth insight of the cyber risks that Maltese banks are exposed to, with the aim of analysing the relevant risk management processes these banks have in place to control and mitigate cyber risks to an acceptably low level. By using the acquired information, the study intends to assess whether the local banking industry as a whole is appropriately postured to defend against cyber threats. Design: By virtue of its nature, the study makes use of qualitative research. Semi-structured interviews were set up with personnel from local banks working in the risk management function or those affiliated with risk, particularly those involved in cyber risk management. Being an inductive study, the research is supplemented by reference to other available literature. Findings: The findings resulting from this study illustrate that there is a considerable discrepancy between the cybersecurity controls adopted by the core domestic banks and those implemented by the majority of the other banks. This is typically due to the fact that the latter have lesser available resources; however, in view of their size, some mistakenly believe they would most probably not be a target for cyber attacks. In contrast, the safeguards and robust controls set by the larger banks are very meticulous, which allow for adequate management of any cyber threats that may be encountered. Conclusion: In spite of having lesser resources, the majority of the other banks still apply certain risk management practices to mitigate cyber risks, albeit the need for improvement. Nonetheless, considering the whole sector, it may be concluded that the local banking industry is sufficiently postured to defend against cyber threats, as evident from the fact that none of the interviewed banks have been a victim of a significant cyber attack in the past 12 months, despite receiving multiple cyber attacks on a daily basis. Value: This study intends to raise awareness about the importance of cybersecurity in the local banking industry, as cyber risks can otherwise disrupt business activities resulting in loss of revenue and can cause considerable reputational damage, including eroding shareholder, investor and customer confidence. This study can be beneficial for local banks in identifying any area of weakness, while also receiving a number of recommendations submitted by the author."]},{"key":"dc:title","label":"Title","values":["An analysis of the cyber risk management practices in the local banking industry"]}]}],"canonical_facts":{"dc:date.accessioned":["2018-05-31T07:26:30Z"],"dc:date.available":["2018-05-31T07:26:30Z"],"dc:date.issued":["2017"],"dc:description":["M.ACCTY."],"dc:description.abstract":["Purpose: Banks rely heavily on technology, and while technology innovation is ever-increasing, it also provides new opportunities for cyber criminals. The researcher sought to acquire an indepth insight of the cyber risks that Maltese banks are exposed to, with the aim of analysing the relevant risk management processes these banks have in place to control and mitigate cyber risks to an acceptably low level. By using the acquired information, the study intends to assess whether the local banking industry as a whole is appropriately postured to defend against cyber threats. Design: By virtue of its nature, the study makes use of qualitative research. Semi-structured interviews were set up with personnel from local banks working in the risk management function or those affiliated with risk, particularly those involved in cyber risk management. Being an inductive study, the research is supplemented by reference to other available literature. Findings: The findings resulting from this study illustrate that there is a considerable discrepancy between the cybersecurity controls adopted by the core domestic banks and those implemented by the majority of the other banks. This is typically due to the fact that the latter have lesser available resources; however, in view of their size, some mistakenly believe they would most probably not be a target for cyber attacks. In contrast, the safeguards and robust controls set by the larger banks are very meticulous, which allow for adequate management of any cyber threats that may be encountered. Conclusion: In spite of having lesser resources, the majority of the other banks still apply certain risk management practices to mitigate cyber risks, albeit the need for improvement. Nonetheless, considering the whole sector, it may be concluded that the local banking industry is sufficiently postured to defend against cyber threats, as evident from the fact that none of the interviewed banks have been a victim of a significant cyber attack in the past 12 months, despite receiving multiple cyber attacks on a daily basis. Value: This study intends to raise awareness about the importance of cybersecurity in the local banking industry, as cyber risks can otherwise disrupt business activities resulting in loss of revenue and can cause considerable reputational damage, including eroding shareholder, investor and customer confidence. This study can be beneficial for local banks in identifying any area of weakness, while also receiving a number of recommendations submitted by the author."],"dc:identifier.uri":["https://www.um.edu.mt/library/oar//handle/123456789/30578"],"dc:language.iso":["en"],"dc:publisher.department":["Faculty of Economics, Management and Accountancy. Department of Accountancy"],"dc:publisher.institution":["University of Malta"],"dc:rights":["info:eu-repo/semantics/restrictedAccess"],"dc:subject":["Risk management -- Malta","Computer crimes -- Malta -- Prevention","Computer security -- Malta","Banks and banking -- Malta"],"dc:title":["An analysis of the cyber risk management practices in the local banking industry"],"dc:type":["masterThesis"]},"updated_at":"2026-07-27T20:12:17Z"}