Super funds fortify cybersecurity amid growing digital threats

19 December 2024
| By Super Review reporter |
image
image image
expand image

Superannuation funds are stepping up their cybersecurity efforts as reliance on digital infrastructure exposes them to growing risks of cyber-attacks, according to new research from J.P. Morgan.

The evolving threat landscape includes sophisticated AI-driven scams, supply chain vulnerabilities, and the bypassing of traditional security measures like multi-factor authentication.

John Livanas, CEO of State Super, said funds must prepare for the inevitability of cyber incidents.

“We believe that at some stage, there will be a cybersecurity incident. We can’t predict what this will be or how we should react to it. Therefore, like most, we play out some scenarios to get used to the cadence and rhythm of handling such incidents. In addition, we have created a playbook as a holistic guide,” Livanas said.

He highlighted proactive measures, such as implementing additional checks during the COVID-19 early release of super scheme, which thwarted fraudulent activity.

“During the COVID era, when people were withdrawing $10,000, we put an added check in there. You won’t believe how much that stopped people from trying to game the system,” Livanas said.

Adonis Polychronopoulos, APAC head of Cybersecurity & Technology Controls at J.P. Morgan, noted the increasing sophistication of cyber threats, including AI-generated deepfakes and advanced social engineering.

Automating controls and adopting technologies like Endpoint Detection and Response (EDR) and Zero Trust principles are essential, he stressed.

“Automate these controls as much as possible so you are not reliant on manual processes, use template configurations - for example, so that non-approved tools and configurations are automatically blocked in your technology environment,” said Polychronopoulos.

He also pointed to emerging solutions like password-less authentication and AI manipulation detection tools as critical defences for funds that rely on remote onboarding of members or employees.

“There are also interesting and rapid developments in identity and access management to include password-less authentication, which can be highly effective against credential phishing, and the ability to detect AI-manipulated video/audio/ images. The latter is key if funds rely on remotely onboarding members or employees,” Polychronopoulos elaborated.

The broader industry is also taking action, J.P. Morgan highlighted.

Namely, the Association of Superannuation Funds of Australia (ASFA) released a Better Practice Guidance on Minimum Fraud Controls in July and a Financial Crime Protection Initiative in September to enhance fraud prevention across the sector.

AUTHOR

Recommended for you

sub-bgsidebar subscription

Never miss the latest developments in Super Review! Anytime, Anywhere!

Grant Banner

From my perspective, 40- 50% of people are likely going to be deeply unhappy about how long they actually live. ...

11 months 3 weeks ago
Kevin Gorman

Super director remuneration ...

11 months 4 weeks ago
Anthony Asher

No doubt true, but most of it is still because over 45’s have been upgrading their houses with 30 year mortgages. Money ...

11 months 4 weeks ago

Superannuation funds are cautiously integrating artificial intelligence (AI) into their operations, leveraging its potential to streamline processes, improve decision-mak...

1 week 3 days hence

Superannuation funds are stepping up their cybersecurity efforts as reliance on digital infrastructure exposes them to growing risks of cyber-attacks, according to new re...

6 days 23 hours hence

The two life insurers have announced a merger following the total acquisition of Resolution Life’s Australiasian subsidiary by Nippon Life Insurance Company....

27 minutes 58 seconds ago

TOP PERFORMING FUNDS