Cyber Risk
Credential 1: Risk Management – Revamping of the Key Risk Indicators worldwide reporting
Client: US Branch of a Global Asset Manager
Sia's Approach
- Analysis of the current process and recommendations to enhance the production of the quarterly dashboard
- A matrix of comparison for different BI tools in order to analyze data more accurately. Implementation of Tableau dashboards
- Implementation of the new process of KRI reporting by integrating a database and the BI framework
- Development of a Web Application (.NET) where users input their data and comments, and generate the report
Sia's Added Value
- The deliverables on the project were a proposition of 3 options to enhance the production process (by adding a database/GUI/BI Tool) and a matrix of comparison for the BI Tool. In addition, we developed a tailor-made reporting application(.NET/DevExpress) with respect to the client's IT technologies and policies.
- The development of the application was performed in an agile mode, having weekly status meetings with weekly deployment to ensure testing is performed correctly.
- Sia Partners has extensive knowledge of the KRI reporting process and has been involved in several projects at the Client over time.
Credential 2: IT Risk Assessment of Internet Banking Application
Client: US Branch of a Global Bank
Sia's Approach
- Assessed the possible risks introduced by the integration of the new Internet banking system into the bank’s business
- Reviewed legal, compliance and governance issues, vendor due diligence and contractual terms, IT architecture, security and privacy controls, as well as inherent risks to each functionality of the platform.
- Devised a solution to meet the new CFPB requirements under the Dodd-Frank Act.
Sia's Added Value
- Performed the risk assessment with 13 areas in scope, ranging from internal controls/processes to integration with external applications and third parties
- Provided an after-action report that detailed the strengths and weaknesses of security processes around the banking application
- Drafted remediation plans to address security gaps found during the assessment