From aviation to cyber security at DNB
‘I collect information on cyber threats and compile threat assessments based on reports and data. Then I analyse everything to get a weighted picture of potential threats to the Dutch financial sector. It is analytical work, where you are constantly identifying links and making connections. My team also supervises ethical hacking tests: we mimic attacks by malicious hackers on financial institutions’ systems to help them boost their cyber resilience. The Bank of England was first with such tests. We followed, and it was truly groundbreaking work in the Netherlands. Meanwhile, other countries both in Europe and further afield are also doing these tests. These days, ethical hacking is more relevant than ever.’
‘Such tests and threat assessments make financial institutions stronger and more resilient, keeping threats at bay and preventing incidents. In the unlikely event that something does happen, such as a major ATM network breech, our crisis management cluster responds to the crisis immediately to limit its impact. I coordinate the group of cyber experts from throughout the sector who advise on such crises.’
From aeroplanes to digital threats
Christel has no background in IT. She studied business administration at University College and worked at a big four accounting firm. She also worked for KLM for five years. ‘Working at KLM was a dream come true for me. I improved operational processes such as efficient loading and refuelling and, in winter, de-icing of aircraft for quicker turnarounds. During the pandemic, I arranged the transport of medical supplies, such as refrigerated COVID vaccines. It was an enjoyable, exciting job, but in the end KLM is a commercial organisation. Partly because of the pandemic, I realised I wanted to do something meaningful for society. The environment and general prosperity are also important to me.’
Our society relies heavily on digital systems. Cyber threats are often invisible to the general public: what you read in the newspaper is often just the tip of the iceberg.
Why DNB?
Christel made the switch three years ago. ‘At DNB, the issues include financial stability and access to payment systems. I found that really appealing. A former classmate tipped me off about a vacancy at DNB. I joined the “TIBER team”, which supervises ethical hackers who test the cyber resilience of financial institutions. Cyber security was new to me, but that is precisely what made it interesting. My work is far from boring: developments take place at lightning speed and all around us.’
How important is cyber resilience?
‘Our society relies heavily on digital systems. Remember how a while ago rogue hackers got their hands on the results of a population health screening? So many things are happening that affect all of us. If power or phone systems get knocked out, parts of society come to a standstill. Cyber threats are often invisible to the general public: what you read in the newspaper is often just the tip of the iceberg. A lot is going on behind the scenes, also involving state actors such as Russia, China and Iran. The details are generally not publicly disclosed. Such actors also take up strategic positions in critical infrastructure of other countries, think waterworks, power plants, airports, so that they can strike later at an opportune moment. It is difficult to find out exactly who is behind an attack, as these actors often pose as known criminals or hacktivist groups. They obviously do everything they can to make sure nothing leads back to them.’
‘Clearly, there is a lot of money to be made in the financial sector. There are also groups of hackers who are only after money. They use ransomware, which is still a real threat to financial institutions. One of DNB’s core tasks is to ensure financial stability. That’s why the Payments, Cash & Market Infrastructure division, which my team falls under, works with banks, insurers, pension providers and others to keep payments secure and accessible.’
Collaboration with other parties
‘We collaborate intensively with the financial sector on security issues, both public and private. We also provide input for policy, nationally and internationally, and share our knowledge and experience with the sector and with the central government.’
New challenges
The threat landscape is constantly changing. Cyber threats are becoming increasingly sophisticated, and partly due to AI, phishing emails are more convincing and numerous than ever. Those emails from a Nigerian prince written in poor English are a thing of the past. Using AI, anyone can act very credibly. That only makes our work all the more important.’
‘I feel right at home working in cyber security. It’s an amazingly dynamic field, you work with different parties – from banks to government agencies – so the work really has societal impact. That gives me a genuine feeling of satisfaction.’