Cybersecurity and Governance Masterclass for Bank Management
Leaders leave able to recognise executive-targeted fraud, verify high-risk instructions, oversee cyber risk with confidence and lead the first hours of a major incident.
Overview
In a bank, one convincing voice call or email can move money before the controls catch it. The attacks leaders now face include spoofed corporate portals, deepfake voice instructions to Treasury, ransomware on core banking and compromised vendors. When one lands, the decisions fall to the Managing Director, the board and the heads of division.
This 2-day programme gives bank top management both halves of the job. Day 1 is practical awareness. It covers how executive credentials are intercepted, how a deepfake of the MD can trigger a high-value manual settlement, how attackers use travel and social media to study executives, and what the core defences are in plain business language. It ends with a “first 60 minutes” incident drill. Day 2 moves from operational awareness to fiduciary duty: governance and the three lines of defence, regulatory compliance, risk, and crisis leadership.
The course is non-technical and built around the Bangladesh banking environment: SWIFT, RTGS, NPSB, BACH, core banking, the SOC and ICCD.
Core Regulatory Anchors
- Bangladesh Bank Guideline on ICT Security for Banks and FIs (v4.0)
- Bangladesh Bank Circulars on SWIFT, NPSB, BEFTN, RTGS & MFS Security
- Critical Information Infrastructure (CII) directives under the National Cyber Security Agency (NCSA) / Cyber Security legal framework
- Incident escalation protocols for BGD e-GOV CIRT
Course Objectives
By the end of the programme, participants will be able to:
- Recognise credential interception, spoofed regulatory circulars, malicious invoices, CEO fraud and BEC.
- Spot and stop voice-deepfake instructions to Treasury or Operations, using call-back and dual-authorisation verification.
- Reduce personal and executive exposure through travel, device and social media discipline, and by separating personal and bank devices.
- Explain, in business language, payment-rail segmentation, MFA and PAM for core banking, immutable backups and 24/7 SOC monitoring, and ask the right questions of the CISO and CIO.
- Run the first 60 minutes of an incident: preserve logs, escalate to the CISO, Head of ICCD and MD without compromised email, and use out-of-band communication.
- Define board, management and CISO accountability within the three lines of defence.
- Understand fiduciary duty, regulatory obligations and legal liability for cyber failures.
- Lead a crisis and leave with a 90-day governance action plan. (Confirm against Modules 7 to 10 once you send them.)
Course Outcomes
What participants will be able to do after the course
- Spot and stop attacks aimed at executives. They can recognise spoofed corporate portals, spoofed regulatory circulars, malicious invoices, CEO fraud and BEC before acting on them.
- Verify high-value instructions. They apply call-back and dual-authorisation checks, so a deepfake voice of the MD or CEO cannot trigger a manual settlement by Treasury or Operations.
- Protect themselves and the bank’s information. They follow safe travel and device practice, keep personal and bank devices separate, and cut what their social media profiles reveal.
- Question the technical teams with confidence. They can ask the CISO and CIO informed questions about payment-rail segmentation, MFA and PAM for core banking, immutable backups and 24/7 SOC monitoring.
- Handle the first 60 minutes of an incident. They preserve logs, escalate to the CISO, Head of ICCD and MD without relying on compromised email, and use out-of-band communication.
- Understand their governance duties. They can explain board, management and CISO roles within the three lines of defence, and their fiduciary and legal liability for cyber failures.
- Lead through a crisis. They make timely decisions on ransom, disclosure, regulators, customers and media, as practised in the tabletop exercise.
What the bank gains
- A leadership team with a shared understanding of cyber risk and the same language as the CISO
- A tested escalation and crisis-communication path, with gaps found in the drill
- A 90-day cyber governance action plan with named owners
- Take-home tools: the board reporting template, the 10-question director checklist and the personal cyber hygiene self-check
- A post-course report with observations from the tabletop and recommended next steps
Course Outline:
Day 1: Cybersecurity Awareness & Executive Defense
Morning: Financial Cyberthreat Landscape & The Kill Chain
| Time | Session and Content |
| 09:00 – 09:30 | Opening & Baseline Cyber Climate Assessment
• Opening address by MD/CEO or Board Representative. • Executive assessment: Gauging cybersecurity posture across executive leadership. • Why banking in Bangladesh is a high-value target for state-sponsored and financially motivated APT groups. |
| 09:30 – 10:45 | Module 1: The Banking Threat Landscape & Case Deconstruction
• Global and local cyber trends: Ransomware-as-a-Service, double-extortion, and data dumping. • Anatomy of the 2016 Bangladesh Bank Cyber Heist: Re-evaluating the perimeter breach, SWIFT Alliance Access tampering, credentials compromise, and printer sabotage. • Modern threats targeting Bangladeshi FIs: ATM malware/black-box attacks, fast-cash out schemes, fraudulent remittance diversions, and attacks during national holidays (Eid/Puja alert windows). • Insider threats: Rogue privileged users, IT admins, and third-party vendor staff. |
| 10:45 – 11:00 | Tea / Refreshment Break |
| 11:00 – 12:30 | Module 2: How Attacks Infiltrate Financial Institutions
• Attack kill chain: From a single spear-phishing mail to Active Directory domination. • Social engineering weaponized: Targeting corporate email, branch staff, and call centers. • Exploiting Remote Working, VPNs, and privileged access. • Live Executive Demonstrations: – Interception of executive credentials via spoofed corporate portals. – Voice deepfake simulation: Mimicking the MD/CEO instructing Treasury or Operations to authorize a high-value manual settlement. |
| 12:30 – 13:30 | Lunch & Networking |
Afternoon: Executive Whaling, Defense Controls & First-Hour Incident Drill
| Time | Session and Content |
| 13:30 – 14:45 | Module 3: Executives as Targets (Whaling, Travel & Reputation)
• CEO Fraud & Business Email Compromise (BEC): How attackers study board announcements and executive movements. • Travel security & device hygiene: Securing laptops/smartphones during overseas business trips, hotel Wi-Fi risks, and public airport charging stations. • Social media and OSINT (Open Source Intelligence): What C-suite profiles expose to attackers about bank infrastructure and vendors. • Segregation of personal and bank devices: Preventing WhatsApp/Signal leakage of sensitive board memos. |
| 14:45 – 15:45 | Module 4: Core Banking Defense Controls in Plain Business Language
• Segmenting payment rails: Strict air-gapping and network isolation for SWIFT, RTGS, NPSB, and BACH environments. • Multi-Factor Authentication (MFA) and Privileged Access Management (PAM) for Core Banking Systems (CBS). • Immutable, offsite, and offline backups to counter ransomware. • AI-driven defenses: SOC (Security Operations Center) monitoring 24/7/365 and endpoint detection. |
| 15:45 – 16:00 | Tea / Refreshment Break |
| 16:00 – 16:45 | Workshop 1: Executive Threat Detection & Personal Audit
• Interactive exercise: Identifying modern financial phishing, malicious invoices, and spoofed regulatory circulars. • Quick check: Reviewing personal two-factor setups, password hygiene, and privacy settings on personal devices. |
| 16:45 – 17:15 | Module 5: Incident Management – The First 60 Minutes
• “Golden Hour” protocols: Preserving logs vs. panicking (what to pull, what to leave untouched). • Internal alert channels: Escalating to CISO, Head of ICCD, and MD without using compromised bank email servers. • Establishing out-of-band crisis communication lines (encrypted voice lines, isolated channels). |
| 17:15 – 17:30 | Day 1 Recap & Key Takeaways |
Day 2: Governance, Regulatory Compliance & Crisis Leadership
Morning: Roles, Board Accountability & Regulatory Frameworks
| Time | Session and Content |
| 09:00 – 09:15 | Day 1 Reflection & Day 2 Governance Agenda
• Transitioning from operational awareness to fiduciary duty, board oversight, and legal liabilities. |
| 09:15 – 10:30 | Module 6: Cyber Governance & The Three Lines of Defense
• Governance architecture under BB ICT Security Guideline v4.0: – 1st Line: Business Units, IT & Branch Operations. – 2nd Line: Risk Management Division (RMD), Information Security Unit, and CISO independence. – 3rd Line: Internal Control & Compliance Division (ICCD) and periodic IS Audit. • Delineating Board Risk Committee vs. Management-Level IT Steering Committee (ITSC) & IT Security Committee (ITSC). • Director and Officer responsibilities: Fiduciary accountability for digital resilience and systemic financial stability. |
| 10:30 – 10:45 | Tea / Refreshment Break |
| 10:45 – 11:45 | Module 7: The Regulatory & Compliance Matrix in Bangladesh
• Compliance mandates with Bangladesh Bank ICT Security Guideline v4.0. • Legal frameworks: Obligations under national cybersecurity legislation and regulations governing Critical Information Infrastructure (CII). • Mandatory incident notification windows: – Submitting alerts to Bangladesh Bank (Department of Off-Site Supervision & BRPD). – Reporting protocols to BGD e-GOV CIRT and the National Cyber Security Agency (NCSA). • Consequences of regulatory non-compliance: Penalties, operational restrictions, and supervisory ratings degradation. |
| 11:45 – 12:45 | Module 8: Cyber Risk Appetite & Board Metrics
• Quantifying cyber risk in financial terms (Taka impact on capital adequacy and liquidity). • Establishing Cyber Risk Appetite and Risk Tolerance thresholds. • Reading a Board Cyber Dashboard: Key Risk Indicators (KRIs), patch cycles, failed CBS logins, vendor audit gaps, and open penetration testing findings. |
| 12:45 – 13:45 | Executive Networking Lunch |
Afternoon: Vendor Risk, Tabletop Crisis Simulation & Action Plan
| Time | Session and Content |
| 13:45 – 14:45 | Module 9: Third-Party & Supply Chain Risk Management
• The vendor dilemma in Bangladesh: CBS providers, card switch vendors, MFS aggregators, and fintech APIs. • Cross-border support and offshore vendor access: Secure jump-hosts, continuous session monitoring, and data sovereignty compliance. • Cyber insurance: Coverage scope, exclusions related to state-sponsored actors, and claims conditions. |
| 14:45 – 15:00 | Tea / Refreshment Break |
| 15:00 – 16:30 | Module 10: Crisis Simulation (Tabletop Exercise – War Room)
• Scenario: At 03:00 on a holiday weekend, the bank’s Core Banking System suffers ransomware encryption; simultaneous fraudulent SWIFT/EFT requests hit the clearing queue, and an extortionist leaks customer NID data online. • Executive Decision Points: – 0 to 30 min: Do you disconnect the bank from NPSB, BEFTN, and SWIFT? Who holds the authority? – 30 to 60 min: Managing liquidity runs, branch closures, and ATM downtime. – 60 to 90 min: Responding to ransom demands, managing press queries, notifying Bangladesh Bank and CIRT, and executing legal disclosures. • Post-simulation evaluation and gap analysis. |
| 16:30 – 17:00 | Workshop 2: 90-Day Banking Cyber Governance Road Map
• Aligning immediate priorities across people, controls, and audits to meet Bangladesh Bank baseline compliance. • Formalizing reporting lines and risk sign-offs among CEO, CISO, and CRO. |
| 17:00 – 17:30 | The 10-Question Board Cybersecurity Checklist & Valedictory |
Features
- Live spoofed-portal demonstration of how executive credentials are intercepted
- Executive threat-detection workshop on financial phishing, malicious invoices and spoofed regulatory circulars
- Personal security audit: two-factor setup, password hygiene and privacy settings on personal devices
- "First 60 minutes" incident drill with escalation and out-of-band communication
- Crisis tabletop exercise (banking ransomware scenario)
- Pre-course confidential survey to tailor case studies
- Residential setting outside Dhaka for focused leadership time
- Take-home kit: board reporting template, 10-question director checklist, 90-day action plan template and personal cyber hygiene self-check
Target audiences
- Managing Director, CEO, Deputy and Additional MDs
- Board members and independent directors
- Heads of divisions, including Treasury, Operations, Cards, Retail and Corporate
- Head of ICCD, CRO, CFO, Head of Compliance, Head of Internal Audit, and Legal
- CIO, CISO and Head of IT, who join to align with the board
- No technical background is required.






