HomeBANKINGSecuring the Digital Future: How Bank of Ceylon is Strengthening CYBER RESILIENCE

Securing the Digital Future: How Bank of Ceylon is Strengthening CYBER RESILIENCE

Published on

Chief Information Security Officer Mr. Iresh Ratnayaka discusses emerging cyber threats, digital banking security, AI-driven fraud, and the importance of building a culture of cyber resilience across Sri Lanka.
As Sri Lanka continues its rapid digital transformation, cybersecurity has emerged as one of the most critical priorities for financial institutions. With increasing adoption of digital banking, mobile payments, cloud technologies, and interconnected financial ecosystems, banks face a growing range of cyber threats, from phishing attacks and financial fraud to sophisticated AI-driven scams, attacks and ransomware incidents.

n this evolving environment, cybersecurity is no longer simply an IT concern. It has become a strategic business imperative that directly influences customer trust, operational resilience, regulatory compliance, and long-term sustainability.

To gain deeper insights into the challenges and opportunities shaping the cybersecurity landscape, Global CEO Magazine spoke with Mr. Iresh Ratnayaka, Chief Information Security Officer of Bank of Ceylon.

With more than two decades of experience in information security, IT risk management, governance, and cyber resilience, Mr. Ratnayaka shares how Bank of Ceylon is strengthening its security posture, safeguarding customer information, addressing emerging cyber risks, and fostering a culture of cybersecurity awareness across the organisation and beyond.

In this exclusive interview, he discusses the evolving threat landscape, the impact of artificial intelligence on cybercrime, the importance of proactive cyber defence strategies, and the practical steps individuals and organisations can take to remain secure in an increasingly connected digital world.

As digital banking adoption continues to rise rapidly in Sri Lanka, what key measures has Bank of Ceylon implemented to safeguard customer data, online transactions, and digital banking platforms?

At Bank of Ceylon, cybersecurity is not viewed merely as a technology function; it is a business imperative that underpins customer trust and confidence. As digital banking adoption accelerates across Sri Lanka, protecting customer information and ensuring the security of digital transactions have become central to our digital transformation strategy.

We have adopted a layered security approach that combines people, processes, and technology to protect our customers and banking services. Our digital banking platforms are supported by strong authentication mechanisms, including multi-factor authentication, device recognition capabilities, secure session management controls, and advanced encryption technologies that safeguard customer data both in transit and at rest.

In addition to preventive controls, we operate continuous security monitoring capabilities designed to identify and respond to potential threats in real time. Regular vulnerability assessments, penetration testing exercises, secure application reviews, and infrastructure security evaluations are conducted to ensure that our systems remain resilient against evolving cyber threats.

From a governance perspective, we continue to strengthen our cybersecurity maturity by aligning our practices with globally recognised frameworks such as COBIT 2019 and international security standards. This enables us to enhance governance, risk management, regulatory compliance, and operational resilience across the organisation.

Importantly, cybersecurity is embedded into every stage of our digital initiatives, from solution design and implementation to ongoing operations. Our objective is not only to provide innovative digital banking services but also to ensure that customers can engage with those services confidently, knowing their information and transactions are protected by robust security controls.

Sri Lanka has witnessed a growing number of cyber threats in recent years, including phishing attacks, financial fraud, ransomware incidents, and data breaches targeting both public and private sector institutions. From your perspective, what are the most pressing cybersecurity challenges currently facing the country’s banking sector?

The threat landscape facing the banking industry is becoming increasingly complex and dynamic. Financial institutions remain attractive targets because they manage critical financial infrastructure, sensitive customer information, and high-value transactions.

One of the most significant challenges today is the growing sophistication of cybercriminals. Traditional attacks are evolving into highly targeted campaigns that combine phishing, social engineering, credential theft, business email compromise, and, increasingly, AI-assisted fraud techniques. Attackers are investing significant effort in understanding human behaviour and exploiting trust, often making attacks more convincing and difficult to detect.

Another challenge is the rapid expansion of digital ecosystems. Modern banking services rely on interconnected technologies, third-party vendors, fintech partnerships, cloud services, and digital channels. While these innovations provide tremendous opportunities for customer convenience and operational efficiency, they also expand the attack surface that organisations must secure.

Cybersecurity talent and skills development also remain critical considerations. The demand for highly skilled cybersecurity professionals continues to outpace supply globally, making capability development, retention, and continuous learning essential priorities for financial institutions.

Additionally, regulatory expectations and customer expectations continue to evolve. Customers expect seamless digital experiences, while regulators expect

robust security, resilience, and risk management. Balancing innovation, usability, compliance, and security requires careful strategic planning and continuous investment.

Ultimately, cybersecurity is no longer purely a technology challenge. It has become a business resilience challenge requiring strong leadership, effective governance, cross-functional collaboration, and a culture of security awareness across the entire organisation.

With cybercriminals becoming increasingly sophisticated through AI-driven scams and social engineering tactics, how is Bank of Ceylon strengthening its cybersecurity infrastructure to proactively detect and respond to emerging threats?

As cyber threats continue to evolve through AI-driven scams, phishing campaigns, and sophisticated social engineering tactics, Bank of Ceylon has adopted a proactive and multi-layered cybersecurity strategy to safeguard its local and international operations.

At the core of this strategy is the Bank’s Security Operations Centre (SOC), which operates 24 hours a day, seven days a week, providing continuous incident monitoring, threat detection, and rapid response capabilities. The SOC also conducts proactive threat hunting to identify potential risks before they impact operations, while dark web monitoring and takedown services help detect compromised credentials, fraudulent activities, and emerging threats targeting the Bank or its customers.

Recognising the growing importance of brand and executive protection in the digital age, the Bank has implemented executive monitoring and brand protection measures to identify and mitigate impersonation attempts, fraudulent websites, and other forms of cyber-enabled reputational attacks. In addition, comprehensive Third-Party Risk Management and External Attack Surface Management (EASM) programmes ensure that risks originating from vendors, partners, and internet-facing assets are continuously monitored and addressed.

The Bank further strengthens its cybersecurity posture through a robust Vulnerability Management Programme, regular security assessments, and an Annual Assessment Plan that evaluates critical systems and infrastructure against emerging threats. Pre-implementation security audits are also conducted for new technologies and digital initiatives to ensure that security considerations are embedded from the outset.

To protect sensitive customer and organisational data, Bank of Ceylon has deployed advanced Data Leakage Prevention (DLP) solutions that monitor and prevent unauthorised access, transfer, or disclosure of confidential information. Complementing these measures, the Bank’s Anti-Money Laundering (AML) systems leverage advanced monitoring capabilities to detect suspicious transactions and financial crime indicators, contributing to a more secure banking environment.

Cybersecurity is not viewed as a one-time investment but as a continuous journey. Through ongoing technology enhancements, risk assessments, employee awareness programmes, and adherence to industry best practices, Bank of Ceylon remains committed to maintaining a resilient cybersecurity framework capable of proactively detecting, preventing, and responding to emerging cyber threats in an increasingly complex digital landscape.

Cybersecurity awareness among customers and employees has become equally important as technological safeguards. What initiatives has Bank of Ceylon undertaken to educate stakeholders on safe digital banking practices and fraud prevention?

Cybersecurity is a shared responsibility. Even the most advanced technologies cannot fully protect an organisation if people are not aware of cyber risks. This responsibility extends beyond employees and customers to include vendors, service providers, and business partners who form part of the broader banking ecosystem.

At Bank of Ceylon, we conduct continuous cybersecurity awareness and education initiatives for employees, customers, and relevant third-party stakeholders. For employees, we deliver structured training programmes, awareness campaigns, phishing simulations, and role-based security education designed to strengthen their ability to identify and respond to emerging threats.

For customers, we regularly share security advisories, fraud prevention guidance, educational content, and awareness messages through multiple communication channels. These initiatives help customers recognise phishing attempts, fraudulent communications, social engineering scams, and other evolving cyber threats.

We also engage with vendors and service providers to promote cybersecurity awareness and reinforce security expectations. As organisations become increasingly interconnected, maintaining strong security practices across the supply chain is essential to protecting the overall resilience of the banking ecosystem.

Our objective is not simply to educate stakeholders but to foster a strong security culture in which everyone understands their role in protecting information and maintaining trust in digital banking services.

Drawing from your extensive experience in the information security industry, what important message or advice would you like to share with Sri Lankans on protecting themselves from cyber threats?

My advice is straightforward: cybersecurity begins with awareness, personal responsibility, and healthy scepticism.

Many people assume cyberattacks are highly technical events that only affect large organisations. In reality, many successful attacks target individuals and exploit simple human mistakes rather than technological weaknesses. Cybercriminals often succeed because they create urgency, fear, trust, or curiosity that encourages people to act without verification.

I encourage everyone to adopt a mindset of “pause and verify”. Before clicking a link, sharing information, transferring funds, or responding to unexpected communications, take a moment to verify the source and legitimacy of the request.

A few seconds of caution can prevent significant financial and personal consequences.
Practically speaking, individuals should use strong and unique passwords, enable multi-factor authentication whenever available, keep software and devices updated, avoid sharing sensitive information through unverified channels, and regularly monitor their accounts for unusual activity.

As artificial intelligence and digital technologies continue to evolve, cyber threats will inevitably become more sophisticated. However, awareness, vigilance, and responsible digital behaviour remain among the most effective defences available to every individual.

Most importantly, cybersecurity is a collective responsibility. Banks, businesses, government institutions, and citizens all have important roles to play. By fostering a culture of cyber awareness and good digital hygiene, we can strengthen not only our individual security but also Sri Lanka’s overall resilience in an increasingly connected digital world.

LATEST NEWS

South Asia’s Export Momentum: Signals Growing Regional Resilience

South Asia’s export sector continues to demonstrate resilience despite persistent geopolitical tensions, supply chain...

Sarah Mensah The Executive Behind a Billion Dollar Legacy

From the basketball courts of Portland to the boardrooms of one of the world’s...

The Jobless Youth Who Was Turned Away at the Gate and Came Back as the Owner

History remembers many business leaders for the empires they built, the fortunes they accumulated,...

Wasanthi Murugesu Makes History as Sri Lanka’s First Woman Security Marshal at AASL

Wasanthi Murugesu has marked a historic milestone in Sri Lanka’s civil aviation sector by...

MORE LIKE THIS

South Asia’s Export Momentum: Signals Growing Regional Resilience

South Asia’s export sector continues to demonstrate resilience despite persistent geopolitical tensions, supply chain...

Sarah Mensah The Executive Behind a Billion Dollar Legacy

From the basketball courts of Portland to the boardrooms of one of the world’s...

The Jobless Youth Who Was Turned Away at the Gate and Came Back as the Owner

History remembers many business leaders for the empires they built, the fortunes they accumulated,...