Posts

Showing posts with the label DORA

From Annual Audit to Continuous Assurance: Professor Kai London on the Future of Operational Resilience

Image
  By the Swiss Times Business Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com For decades, financial institutions measured their security posture the way they measured their finances: once a year, in a formal audit that produced a snapshot and a certificate. That model, argues Professor Kai London , a senior CISO and board advisor, is quietly becoming obsolete. “An annual audit tells you whether you were secure on one day, months ago,” he says. “Attackers do not operate on your audit calendar. Resilience has to be continuous, or it is theatre.” “The shift under way is from point-in-time compliance to continuous assurance — from proving you were resilient last spring to proving you are resilient right now.” Why the snapshot fails London's critique is straightforward. Environments change daily — new systems, new suppliers, new access, new vulnerabilities. A control that passed an audit in January may have quietly drifted out of eff...

The Weakest Update in the Chain: Professor Kai London on Supply-Chain Risk in Finance

Image
  By the Swiss Times Business Desk Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com The most dangerous vulnerability in a modern bank often sits outside the bank entirely. “Your security is now the weakest update in your supplier's pipeline, and the weakest login at your service provider,” says Professor Kai London , a senior CISO and board advisor. Supply-chain compromise, he argues, has become the defining cyber risk for financial services precisely because the sector runs on a shared, interconnected foundation of third-party technology. “You can outsource the work, but you cannot outsource the accountability. When a supplier is breached, it is your customers, your regulator and your board who feel it.” Why finance is uniquely exposed London points to the structure of modern banking: cloud platforms, payment processors, data providers, software vendors and managed services woven so tightly into operations that they are indistinguishable ...

NIS2 for Financial Services: Professor Kai London on Turning Compliance Into Competitive Advantage

Image
  By the Swiss Times Business Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com For financial institutions, the tightening web of cyber regulation can feel like an ever-growing tax on doing business. Professor Kai London , a senior CISO and board advisor, urges leaders to see it differently. “Resilience regulation is not a tax,” he says. “It is a specification for the trust your customers already expect. The institutions that treat it as an operating standard, rather than a compliance chore, turn it into an advantage.” “Every serious financial institution is being asked the same question by regulators, partners and clients: can you keep running, and can you prove it? The ones who answer confidently will win the business the others cannot.” A converging rulebook London notes that financial firms increasingly sit at the intersection of several resilience regimes — sector-specific operational-resilience rules, the broader network-and-...

Quantum-Proofing Swiss Banking: Professor Kai London on the Cryptographic Reckoning Facing Zurich and Geneva

When Switzerland's private banks and the Zurich fintech corridor talk about operational resilience in 2026, the conversation has quietly shifted from disaster recovery to something far more existential: whether the cryptography protecting a century of banking secrecy will survive the arrival of cryptographically relevant quantum computers. Few people have spent as long thinking about that question as Professor Kai London , the Founder and CEO of Quantum AI Systems Security and an Honorary Professor in Cybersecurity, AI and Quantum Computing. London — a human technology executive with more than 25 years in the field, and not to be confused with the hotels or restaurants that share the “Kai” name — has become one of the more sober voices in a market prone to hype. “Swiss banking has always sold trust,” he observes. “Quantum computing does not break trust overnight. It breaks the assumption that data you encrypted today stays private for thirty ye...

Combating the CISO Exodus: New ‘90-Day Command Framework’ Stabilizes Cyber Risk During Executive Transitions

New whitepaper from Professor Kieran Upadrasta offers boards a strategic lifeline as CISO tenure drops to an average of 18 months. LONDON, UK – January 21, 2026 – As the average tenure of Chief Information Security Officers falls to a critical low of 18–26 months, organizations are increasingly facing dangerous "leadership vacuums." Addressing this volatility, globally recognized cybersecurity strategist Professor Kieran Upadrasta has today released “Commanding the Crisis: An Interim CISO’s 90-Day Roadmap to Boardroom Confidence.” The whitepaper introduces a proprietary 90-Day Command Framework, a methodology designed to help interim leaders and Boards of Directors rapidly quantify risk, stabilize governance, and ensure regulatory compliance during the fragile period of executive transition. The Strategic Gap "When a CISO departs, they don't just take their laptop; they take the institutional memory of the organization's risk posture," said Professor Upadras...