This episode of Tech on Deck, recorded for Cybersecurity Awareness Month's 20th anniversary, features host Maureen Olajarz interviewing Adam Ely, Fidelity's Chief Information Security Officer, and guest host Rob Hussey. Adam discusses the importance of a "Cybersecurity Mindset" in both professional and personal life, emphasizing that security should be integrated into every decision to mitigate risks for the firm and its customers. The cybersecurity team, comprising over 1,000 diverse associates, works year-round to educate, build defenses, and collaborate across departments. Rob explains the role of Information Security Officers as trusted advisors, focusing on engagement, advisory, cyber health, regulatory compliance, and awareness. Key trends include rising attack volumes, geopolitical cyber threats, ransomware, and AI-powered deep fakes, making cybersecurity increasingly complex. Fidelity assesses its posture through internal evaluations, external audits, and red teaming, sharing intelligence with other companies to stay ahead. For individuals, Adam and Rob recommend enabling multi-factor authentication, questioning suspicious messages, freezing credit reports, keeping devices updated, and spreading awareness to family and friends. The episode underscores that cybersecurity is a collective effort requiring constant vigilance and adaptation.
[MUSIC PLAYING] Welcome to Tech on Deck Podcast brought to you by Fidelity Investments. I'm your host, Maureen Olajarz, Domain Leader Software Engineering, and-- Adam Ely, Chief Information Security Officer. Each episode takes listeners inside the walls of a Fintech industry. Anything from cybersecurity, artificial intelligence, cloud, and crypto, to the intersection of product and technology. Tech on Deck breaks down the topics top of mind for technologists today. Plus, we'll give you insight into the exciting and challenging careers in Fintech. [MUSIC PLAYING] Welcome back to season two of Tech on Deck, where we will continue to take our listeners inside the walls of the Fintech industry. We're thrilled with our guest lineup for season two, all of whom are making innovative strides as Tech leaders at Fidelity. We're so excited to take you along on this journey with us as we continue to chat with these leaders on the topics that are top of mind for technologists around the globe. And for today's session, October is Cybersecurity Awareness Month, which is why we're going to turn the tables today. And I'll be interviewing Adam, our Chief Information Security Officer at Fidelity. All right, so I get the hot seat for a change. So thankfully, I won't be taking Maureen's question solo. As we also have a second guest host today for this first episode of season two, Rob Hussey. Rob is on my team as an Information Security Officer for Personal Investing. So welcome, Rob. Thank you both for having me up. So this October marks the 20th anniversary of Cybersecurity Awareness Month. And it's a great time to expand and strengthen our Cybersecurity Mindsense. Can you talk to us about the significance of Cybersecurity Awareness Month and how we amplify it across Fidelity? Yeah, absolutely. So first of all, I can't believe it's been 20 years that we've had a Cybersecurity Awareness Month. It doesn't feel that way. But it's a great thing that we have. In this day and age, Cybersecurity is this existential threat to every company. It doesn't matter their size or the industry. So taking just a moment, just taking a few weeks to say, hey, there's this threat that can affect consumers, that can affect employees, that can affect national and critical infrastructure is a great, just reasonable thing to do. And so here at Fidelity, we spend not only the month, but all the way throughout the year thinking about this, communicating this, and talking to everybody in the company about how we can be better to protect the company. But we also put out tips and communication for our customers about how they can protect themselves, either with their Fidelity accounts, or in the rest of their lives. So Adam, can you share with us what exactly do you mean when you talk about embracing a Cybersecurity Mindset? - Yeah, it's one of my kind of buds, wordy kind of things that I run around with, for sure. What I'm saying there, and really what the team is saying, 'cause I don't wanna take all the credit, but what the team is saying there is, in everything that we're trying to do in our lives or in our jobs, we should think about the risk. We should think about how the actions that we take, or the actions that we don't take, connectively affect us. If I click on that link, will I be possibly compromising my account? If I design technology a certain way, am I creating a risk for hackers to get into the organization? So while we're thinking about what we're trying to achieve in these great features, this great technology, we also have to have that security mindset of thinking how can things go wrong? So how do we protect all the people that rely upon that technology that we're building? - Wow, that makes a lot of sense. In your role as Fidelity's Chief Information Security Officer, you lead a team of professionals who are responsible for protecting the firm and our customers. Can you share a little bit about what they're responsible for each day? - Absolutely, so we have over a thousand associates on the cyber security team, spanning for re-contries, multiple time zones within countries, and they come from all walks of life. We have people who entered their career through technology. We have people who entered their career not through technology, but then came to Fidelity. We have people that came from non-technology roles within Fidelity, and people that have majored in just about everything you can think of, which makes for some really interesting debates and conversations from day to day. But this collective, if you boil down their mission, the core of their job, the core of their day to day, the core of their role within Fidelity, is thinking about how bad things happen in the world, and trying to educate everyone, build technology processes and defenses to try to counter that, and work with people so that it's not binary. It's not about, yes, you can do that, no, you can't do that, but there's a thing that we all collectively want to do as a company, and part of that thing is being secure. So how can they work with everyone across the company to make sure we're launching new products, new services that we're doing these new initiatives, but we're doing them with that security mindset, we're doing them with security, top of mind, to manage that risk for our consumers, our clients, and our employees. - That's great. And a lot of what we see here is that passion that you all bring, as well as the knowledge around that, and then make it connect with all of our, whether it's our associates, our product owners, our engineering leads, business folks, so that they can actually operate the right way every day. - And that's where we're really lucky with the makeup of our team. We have people that came from three-letter government agencies, we have people from military, we have people from the commercial sector, from big company, small company, startups, US companies, overseas companies. We have diversity makeup of backgrounds, social, economic, gender, race, because we have such diversity in how people look at the world, when we go out to work with people in other functions, technology, business, even some of our clients, it's easier for us to see the world through their eyes, understand the pressures they have, understand the outcomes they're trying to achieve, and then figure out those solutions, whether it's a technical solution, and we're building technology, or it's a process solution. It really, really helps us. - I think that's great. And since we have Rob here as a guest, Rob, I'm gonna reach out to you and just ask, as an information security officer, can you tell us about your overall responsibilities in the firm? - Sure, happy to. As information security officers at Fidelity, we call ourselves trusted advisors, and we wanna be viewed as trusted advisors of the business units that we support. We also wanna help business partners accelerate, but do it in a secure way. We're not there to block things, but we wanna make sure that folks are doing things in a secure way. The way that we're organized in the ISO team in cybersecurity is each line of business has a dedicated ISO team to consult with and answer questions on cybersecurity. And I think, if I think about the work that we do, it's really broken down into like five areas of focus. The first one is around engagement. And that's both on the client side and on the internal partner side, our business partners with infidelity. So on the client side, we engage with a broader team and meet with potential and existing clients to educate them on our cybersecurity posture. And make sure that they understand our commitment to cybersecurity. Our people, as Adam mentioned, the backgrounds and certifications at fidelity. Internally with partners, we also wanna embed as much as possible within our BUs and ensure that cybersecurity and cybersecurity is prioritized into their roadmaps, into their capabilities, and into their products that are coming down the pike. The other area I would say that we get involved in is security advisory. So through the engagement that I mentioned before, we wanna ensure that our partners are leveraging the capabilities and the processes that cybersecurity provides to help mitigate risk in their environment. One area that gets pretty exciting is Cyber Health and Risk Reduction. So this is where, as I associate, we provide a line of sight to our business partners into here's how things look. And in your group, here's the health, here's any issues, in your risk posture. And we provide consulting on which ones to tackle first and go after from a mitigation standpoint through reporting. And we also get involved in vulnerability remediation, monitoring, and managing those issues to closure. On the regulatory side, the ISOs get involved in supporting our business partners that are subject to regulations, the Fidelity is a diverse, very diverse company. There's many regulations that are imposed on different BUs. And we support them through participating in exams, board presentations, making sure that we are properly describing our cybersecurity program here in our posture to those regulators. And then finally, lastly, I would say, and this is really a foundational activity that we do from the ISO office is education awareness. So this is across the entire company, as Adam mentioned, through, especially next month in October. But we educate, we advise, we influence activities with Cyber Risk implications with our business partners. And we do that, like we drop into staff meetings, we'll drop into accordingly all hands with our BUs, and we'll try to provide sort of relevant, timely, cybersecurity topics that updates that sort of hit the mark in those settings. So that's how I would explain kind of the five areas of focus from the ISOs bit. - Thank you, thank you Rob. So that's really great. And as I think about Fidelity and the programs that you're all running, they continue to get stronger, more connected to associates. And when I think about the growth and the firm over the past couple of years, people on board into this, right? So they come into the firm.
and you're already helping them with, you know, it can be fishy, it can be, you know, all manner of things that I'm sure we'll go through later in the interview here. But thanks for sharing that. So if we take a step back and look at the broad state of cyber security, what is some of the increasing trends we're seeing by cyber criminals and threat actors? - Yeah, I think it's really interesting. I said this a couple of years ago, and I feel like it was true then, true or statement now, this is simultaneously the best time and the worst time to be in cyber security. There are so many interesting things that are happening, but it's become an even more challenging job for day-to-day practitioners in cyber security groups like ours. The number of attacks are rising year-to-year, I think last time I saw, so it's something like 7%, I think it's actually much bigger based on larger datasets we're now starting to look at. We're seeing geopolitical attacks that are increasing. Every conflict that we're seeing in the world has some sort of cyber element to it now as well that we have to watch. And so it used to be that we could only just be technologists and then we had to understand tech and policy, but now we have to understand global affairs as well, which is very challenging. Additionally, we're still seeing a lot of attacks that are leading to ransomware and stolen personal information of people, which is always concerning. So we're seeing these attackers continue to find ways to monetize every technique they have to demand ransoms, take companies offline, work for other cyber criminals, and as we look out on the horizon, there's emerging technology. So artificial intelligence is leading to deep fake videos and voice, which in turn is being used to defraud people, either for the theft of personal information or the theft of financial accounts or anything in between. So it's a bit of a dizzying space at the moment. - I think it would be fair to say after that description that is a group that doesn't sleep. - Unfortunately, we don't get to sleep very much. - That's right. So recognizing you don't have a crystal ball. What do you think are some of the biggest challenges as we look out a year or three years or so? And what keeps you up at night? - Yeah, so when I look out, really at the landscape, I think I probably always worry about roughly the same things. It's just new variances of those things. So the fact that cyber criminals are getting better, and more efficient, and they're faster. They're leveraging the same technology that technologists at like big scale companies are leveraging. They run their operations in the cloud. They automate. They're using AI and their attacks. The fact that the cost of technology is coming down to where attackers can use it, and they can attack companies faster and have a higher success rate. They can just automate those attacks. That means that we as a company, and really all companies need to be able to move faster and defend faster, and respond to the signals they see, while also using that same automation and that same artificial intelligence. And then I think the evergreen thing that stays on my mind, and I sort of mentioned, is that as technology continues to change, and those attackers get better, we just have to continue to think about how the world around us changes. So if the products that we launch change our risk profile in some way, we have to make sure that we're countering that risk before we launch that new product. If vendors, the cloud providers, if they're changing how they operate, we have to think about how that changes our risk profile. So it's the ever-changing nature of technology that leads to the ever-changing nature of cybersecurity, which back to the earlier comment means I don't get to sleep unfortunately. That's right. Thanks, Adam. That's really helpful. So Adam, if we build on what we've just been talking about, how do you think about cybersecurity? We work really hard. You and the organization really drive that across fidelity as an enterprise. But how do you look at how fidelity and how do you decide how fidelity matches up against peers in the industry? Yeah, it's a great question. First and foremost, I think cybersecurity is a team sport. No individual practitioner and no company can go at it alone. We all have to share ideas, new trends that we're seeing. Cyberintelligence between us-- we staff our own cyber intelligence team here at Fidelity-- that is constantly looking at what criminals are talking about, what actions are taking. That team works with other companies, some of which may be competitors in the market. Because we all have the same shared goal, which is to protect our companies, protect our customers. That's the job. So we share that as much as we can. But the way that I think about it is through scenarios, how are attackers trying to attack us? And what are their objectives? So is it they're trying to break in to steal money or break into an individual account or intellectual property or research notes, or whatever it might be? And we think about those scenarios, and we form the risk scenarios around those objectives. And we look at what controls we have in place that can help protect us and where we should invest. And we do this not only through our own internal assessments, but we leverage several external companies that come in and assess our security controls. And these might be very specific things. They might be looking at just how we do software development and the security lifecycle there. Or they may be looking at the maturity of our overall operation. So we have a different set of external firms that come in. And they audit us and they measure that. And they do real live red teaming testing, trying to break in. And we get those results and we work with those partners. That's how we really test ourselves and know how well we're doing. We take that and we prioritize that. And think about, for every dollar we spend, how can we buy down the most risk possible? And the whole idea is buying down risk, eliminating as much as risk as possible. And that's how we do our prioritization. That work, though, has some really great outcomes. It leads us to having a high functioning team. That's very high maturity. It leads to the ISO certifications that we have. It leads to us being able to generate this evidence in industry that we really care about this, that we're doing a lot and that we continue to work at it because the world around us continues to change. Raising the bar every day. I mean, we have to be attackers are, so we have to as well. Right. Thank you. Bring it back to staying cyber safe in our day-to-day lives. What are some of the things that we need to-- that we all should be vigilant about? Yeah. So-- and that's the thing. I always try to boil things down to what are the actions that an individual can take and then build off of there. So if I think about us in our personal lives-- and this is going to-- to the technical listeners, this is going to sound repeated probably from your own company's cyber awareness month information. But the very first thing is just think about how secure your accounts are everywhere online. Start with your mobile provider and your email provider. That's the chain of trust to your online identity right there. So turn on the multi-factor. And I know everybody tells you that. But it really is good advice. Turn on the multi-factor. Be a little suspicious of the things you see, question them when they come in. If you get something that says, oh, you have to reset your password because something is not working. Ask yourself, is there a reason that it wasn't working? It should you actually click that link. And then continue through your life and take actions such as freezing your credit report. Make sure that you can't be a victim of identity theft. And the reason I start there versus on the bigger enterprise things is I think we as individuals have to focus on protecting ourselves. So then we can actually be in that mindset to then work with other people or be in that mindset when we're in our jobs, when we're in our roles. So we have to start closest to home if you will. Rob, we'd love to hear from you as we build on what can individuals do themselves to stay vigilant about cybersecurity? Yeah, absolutely. In addition to what Adam had mentioned, I would add in a few things. One of them always keep your devices updated, whether it's mobile device or your laptops, accept those updates. Don't snooze them off. They're important from a security standpoint to keep those up to date. From a social engineering standpoint, we're seeing it's not just emails anymore. It's coming in through various channels, whether it's through SMS or real voice phone calls. So just be vigilant when people reach out to you and you don't know who it is. And then lastly, I would say in the spirit of cybersecurity awareness month, it just helps to spread the word with family, with friends, help them out and get the word out there from a cybersecurity standpoint to be vigilant. Yeah, thanks. Let's go into some background. So if we think about folks in cybersecurity and what's your background, what do you view into cybersecurity of fidelity? I think the answer both of those questions with one answer. So I started my career as a co-op here at Fidelity. I attended a university locally in Boston area. And my first co-op or an internship was with our internal auto group here at Fidelity in the IT group. And coming from an engineering standpoint, I was always really into computers. But it gave me exposure to the work that that auto group was doing to interrogate systems to make sure that they're configured correctly, look for vulnerabilities and things like that. to my end.
internship, my project that summer was around, you know, we had the group had some shell scripts that were written to go against Unix operating systems. And this was the time when Linux and I'm aging myself, Linux was just beginning to become accepted in the corporate environment. We had some, I think, non-production instances out there. So my role was to port the Unix shell scripts to the Linux shell script. So it gave me a good opportunity to learn about security. And I think that's where I got the bug, because ever since then I've been into cybersecurity. I've been here for a long time, Maureen, as you know, 22 years and roles in various roles across cybersecurity. I did a quick count coming in. I think I've had seven roles averaging around three years each in each of those roles. I think that's great. Thanks for sharing. As a co-op student, I like that. Yes. I didn't know you'd been here 22 years. It's a long time ago. Yeah, I just learned something. That's awesome. Congrats. It was like just yesterday. It was like, "Just yesterday." Adam, would you like to share? Sure. You know, my story, my story's a little different. I got interested in technology and very specifically cybersecurity at a young age. The story goes, I was using the computer and I was trying to do something and the computer told me no, and I didn't understand that. I didn't understand how the computer could tell me the human operator. No. This perplexed me. I started learning the internals. I wanted to understand how this was possible, mostly because I wanted to tell it no. I actually started by learning how to reverse engineer software. I had to learn how to develop first and then reverse engineer software. I could reverse engineer these controls so that I could then break the controls so the computer would always do what I wanted it to do. That's where I started. I entered into the enterprise. I had a number of roles. I worked for some big companies, some small companies, some various verticals. I found it a cybersecurity startup that was acquired, came back to enterprise. Two and a half years ago, I just said yes to come to Fidelity because when I was talking to a few people and I said, is this a place to go? I'm happy. I'm not looking. Is this a place to go? Everyone said it's a great culture. They're driving a lot of technology over there. You're going to see a lot of really interesting things that you probably wouldn't have thought just looking on the outside of financial services, in Fintech. Then when I interviewed and I talked to people and it was all levels, it was all the way through the company. There was such a passion for tech but also a deep passion for doing the right thing around cybersecurity and protecting our clients and our customers. I was like, this feels like a really interesting place with interesting things happening. Two and a half years in, I have yet to regret that. Excellent. That's great. We have someone who grew up here and we have someone who's had a lot of other experiences and that could be a whole lot of podcasts to talk through that. As we think about our audience for the people who are listening here, there may be folks out there who, hearing this, would say I'd love to have a career in cybersecurity. What advice would you offer to them? Rob, let's start with you. Yeah, definitely. If you're still in school, obviously consider cyber as a discipline or as a major or a minor. There are many schools that offer that now. Also look into internships or co-ops that companies provide. I had a very positive experience here at Fidelity as an intern in the audit group. If you're already in a career, I would first step back and take a look at cyber security the discipline because there's many paths in product areas and things to do in cyber and see which ones are of interest to you. There's engineering, there's operations, there's very specific roles within cyber and look for some training opportunities in those areas. There's many training opportunities. Education, you can go for formal education or there's many sort of instructor, self-paced digital opportunities there. In network within the company that you're in today, reach out to the cyber group, ask to meet with some folks, spend some time seeing what they do, build your network within that group. And then lastly, it's always I think good to go out and take a look at public job listings in cyber across all companies to see what they're looking for, what skills they're looking for, competencies, tools that they use, etc. I mean we know technology in general, there's no shortage. There's a major shortage of technology talent out there and I would imagine that as both of you as professionals in enterprise cyber, that's a very hot market. Looking for talent. Cyber security is one of the most in demand spaces right now and it's both within the technology side of it but we have many roles that are not technology as well and they're all very hard to fill. In the interesting and I go something that Rob said, I think one of the kind of pro tips for people trying to find a job is one, look at the company you're in today. If you're already working, every cyber security team is trying to hire and they're trying to find the right candidates. So go and make those connections and say why you think you can do the job even if your resume does not show it. If you don't have the background, you didn't go to school for cyber security or comp-sci, go have the conversation, take the swing. If you're not working or you're maybe working but you want to switch companies or locales, get out there and network with as many people. Send a note to a CISO on LinkedIn. Do one a week and just send them a note and say I'd love to pick your brain. You will find that people are more open and welcoming to those conversations than you probably realize and will help you get in the door and build that connection. But it'll also help you hear the signals of what people are asking, what they're looking for and how to tell your story and your value prop. Even if you're not the most technical or you don't have the classic background but you know that you have something to apply that can help protect the company and the people that rely upon them. I think that's really great advice. Anything else you'd offer in that space to folks because I think that sounds like really sage advice to people. The only other thing I would say in Rob mentioned this is we have different types of roles so we have product security, advanced and response on that. If you know yourself and you know what you like to do, go out and talk to people about where you think the type of work that you enjoy lines up. If you don't know, don't be scared to just start somewhere. Go explore and move around in a company, gain more skills until you find that niche that really speaks to you. Excellent, thanks. Thanks for sharing. So Rob, this has been a great conversation but in this spirit of you know closing out with you know some positive messages to people. We did cover somebody for it but maybe let's just have you go through one last time one of the things that are really important for individuals to take take their own agency to be able to protect themselves. Yeah sure I would offer maybe three or four quick hits as we close out. I mean I would say be vigilant, don't get fished, be aware of things that are coming in through all your channels, communication channels. Consider password managers to manage your passwords. They offer strength and complexity and some of them offer auto rotation. And then lastly MFA multi-factor authentication. Adam mentioned this I think at least twice. Enable MFA on those accounts that matter or all accounts that offer it really. It's something that should be considered to strengthen your security posture online. Wonderful. So Rob, I'm sure there is some fun facts about you that we just need to know. You know we always love to close out you know before we finish a session of our podcast. You know what are some fun facts about you? Yeah I mean I would say you know I'm an avid snowmobiler so I enjoy getting out in northern Maine, out in the woods, places where maybe there isn't cell phone service and unplugged for a little bit. It's a hobby that I've been doing with my dad. Now for over 20 years and it's something that I really enjoy. So when we go out on any given day we call it a success if we if we hit a hundred miles on a day trip. When I think of fun I think of snow, I think of the winter and I think of snowmobiler. And Adam let's hear from you. What's your fun fact? I don't know if this is fun but people tend to find this entertaining. I dropped out at college five times. I ended up going back, I ended up going to get a master's, then I ended up going to get another master's, which then I also dropped out of, I guess six times technically. And now I actually teach in that second master's program. But for me it was important for me to get in the industry and try to get that work experience because that's also how I learn and I progress. But I knew at the time I needed to go back and finish the degree. Which is interesting I think that really for others listening to this is now you know degrees are so varied and people can start their career without a degree. But when I went to school and was in the career field it was a very different thing. So I look back on that and just how different it was back then. Well thanks so much that's a you know that's really a unique story. So I think that's great. I want to thank both of you for joining us today. Adam thank you for being gracious. So I'm flipping the script for today for Cyber Security Month and Rob thanks for joining us today. Thank you. Thanks for joining us for Tech on Deck. We hope you enjoyed the episode. If you haven't yet please give us a five star rating and subscribe to the podcast on Apple Podcasts Google Podcasts or wherever you get your podcast from. Thank you to our listeners and recording studio
and editors who make our episodes possible. To learn more about tech opportunities, head over to tech.fidelitycareers.com. See you next time.
Podcast Summary
Key Points:
The podcast episode marks the 20th anniversary of Cybersecurity Awareness Month, with host Maureen Olajarz interviewing Fidelity's Chief Information Security Officer Adam Ely and guest host Rob Hussey.
Adam Ely emphasizes that cybersecurity is an "existential threat" to all companies, and Fidelity promotes a "Cybersecurity Mindset" year-round, encouraging employees and customers to consider risks in every action.
Fidelity's cybersecurity team of over 1,000 associates, diverse in background and expertise, focuses on educating, building defenses, and collaborating across the company to manage risk for clients and employees.
Rob Hussey outlines the role of Information Security Officers as "trusted advisors," covering five areas: engagement, security advisory, cyber health, regulatory support, and education awareness.
Key cyber threats include rising attack volumes, geopolitical cyber elements, ransomware, AI-driven deep fakes, and automated attacks; Adam notes this is both the best and worst time for cybersecurity.
Fidelity assesses its security through internal evaluations, external audits, red teaming, and sharing intelligence with peers, prioritizing investments to buy down risk.
Personal cyber safety tips include enabling multi-factor authentication, being suspicious of unsolicited messages, freezing credit reports, keeping devices updated, and educating family and friends.
Summary:
This episode of Tech on Deck, recorded for Cybersecurity Awareness Month's 20th anniversary, features host Maureen Olajarz interviewing Adam Ely, Fidelity's Chief Information Security Officer, and guest host Rob Hussey. Adam discusses the importance of a "Cybersecurity Mindset" in both professional and personal life, emphasizing that security should be integrated into every decision to mitigate risks for the firm and its customers. The cybersecurity team, comprising over 1,000 diverse associates, works year-round to educate, build defenses, and collaborate across departments.
Rob explains the role of Information Security Officers as trusted advisors, focusing on engagement, advisory, cyber health, regulatory compliance, and awareness. Key trends include rising attack volumes, geopolitical cyber threats, ransomware, and AI-powered deep fakes, making cybersecurity increasingly complex. Fidelity assesses its posture through internal evaluations, external audits, and red teaming, sharing intelligence with other companies to stay ahead.
For individuals, Adam and Rob recommend enabling multi-factor authentication, questioning suspicious messages, freezing credit reports, keeping devices updated, and spreading awareness to family and friends. The episode underscores that cybersecurity is a collective effort requiring constant vigilance and adaptation.
FAQs
The Tech on Deck Podcast, brought to you by Fidelity Investments, takes listeners inside the fintech industry, covering topics like cybersecurity, AI, cloud, crypto, and the intersection of product and technology.
Cybersecurity Awareness Month, now in its 20th year, highlights the existential threat of cybersecurity to all companies. Fidelity uses it to amplify its year-round efforts to protect the company and customers by promoting a cybersecurity mindset.
It means thinking about risk in all actions, such as considering if clicking a link could compromise an account or if designing technology a certain way could create risk for hackers, while still aiming to achieve great features.
The team, with over a thousand associates, focuses on thinking about how bad things happen and educating everyone, building technology processes and defenses to counter threats, and working with the company to launch new products and services securely.
The ISOs focus on engagement with clients and internal partners, security advisory, cyber health and risk reduction, regulatory support, and education awareness across the company.
Attacks are rising yearly, with increases in geopolitical attacks and ransomware. Attackers are using emerging technology like AI for deep fake videos and voice to defraud people.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.