DAY 1: 24 April 2024
09:00 - 09:30 Welcome and opening remarks
09:30 - 10:00 Keynote: Fintech Security 10:00 - 10:30
Group Photo & Coffee Break
10:30 - 11:30 Session 1: Introduction to ITU DFS Security Lab and ITU activities in the region on Digital FinanceThis session provided a general overview of the ITU DFS Lab and the assistance that it provides to developing countries to adopt the DFS Security recommendations. The ITU DFS Security Knowledge Sharing Platform was designed to foster collaboration among regulators and other stakeholders in the development and implementation of security guidelines and best practices for Digital Financial Services (DFS). The session also provided an overview of the activities of the ITU on Digital Finance and highlight how the State Bank of Pakistan implemented the ITU DFS security recommendations.
Moderator: Ariff Olan Kholid , Project Manager, FNSValue Malaysia
11:30 - 12:30 Session 2: Blockchain Secure Authentication (BSA) and deployment for passwordless authentication for DFS
The objective of this session was to provide an overview of Blockchain Secure Authentication technology and how it could be used for passwordless authentication in mobile payments.
The session also introduced the ITU developer resources for BSA.
Moderator: Akanksha Sharma , Programme Officer, ITU Area Office for South Asia and Innovation Centre, New Delhi
12:30 - 13:00 Session 3: Introduction to the ITU BSA Application Challenge 13:00 - 14:00
Lunch
14:00 - 15:30 Session 4: Fintech Security and Digital Financial Inclusion in Asia Pacific RegionThis session provided an overview of the Fintech security measures implemented in different countries in the Asia Pacific region.
Moderator: Akanksha Sharma , Programme Officer, ITU Area Office for South Asia and Innovation Centre, New Delhi - Rehan Masood , Joint Director Digital Financial Services, State Bank of Pakistan [Presentation]
- Heung Youl Youm , Chair of ITU-T SG17/Professor of Soonchunhyang University, Korea (Republic of): Security assurance framework for digital financial services (X.1150) [Presentation]
- Sung Kyun Son , General Manager, Fintech Center Korea: Korea Fintech Industry Trend and major policies [Presentation]
- Ng Lee See, Risk Specialist, Risk Specialist and Technology Supervision Department, Bank Negara Malaysia: Overview of the digital security measures in Malaysian financial sector [Presentation]
- Sonam Tobgay , Deputy Executive Engineer, InfoComm and Infrastructure Division, Bhutan InfoComm and Media Authority (BICMA) [Presentation]
15:30 - 15:45
Coffee Break
15:45 - 17:30 Session 5: DFS security recommendationsThis session highlighted the security best practices and standards to be implemented by DFS regulators and providers as mentioned in the
ITU DFS security recommendations to secure the applications layer, telecom infrastructure and payment system infrastructure. In particular, the following measures were presented:
The session also delved into mobile device security best practices.
Day 2: 25 April 2024
09:00 - 10:00 Session 1: Managing risk in digital financial services DFS providers put in place adequate measures to address the security threats and vulnerabilities and demonstrate compliance against regulatory measures. This session considered the various threats and vulnerabilities that can impact the confidentiality, integrity, and availability of digital financial services from a value chain perspective. The session also highlighted mitigation measures that DFS providers can implement to reduce the impact of these risks and discussed a framework that can be implemented by DFS providers to better manage the risks and show compliance.
Moderator: Radhilufti Madehi , Chief Operating Officer, FNSValue Malaysia
10:00 - 10:45 Session 2: DFS cyber resilience toolkit tabletop exercice (Part 1)
This session introduced the ITU DFS cyber resilience toolkit for regulators to safeguard critical digital finance infrastructure. This session also included an exercise designed as an interactive tabletop session, where participants were organized into groups, each focusing on a distinct aspect of cyber security: Risk management, governance, testing, training & awareness, protection and incident response.
10:45 - 11:00 Coffee Break
11:00 - 13:00 Session 3: DFS cyber resilience toolkit tabletop exercise (Part 2)
This exercise was designed as an interactive tabletop session, where participants were organized into groups, each focusing on a distinct aspect of cyber security: Risk management, governance, testing, training & awareness, protection and incident response. (Prerequisites for participants and details – see below).
Facilitators:
13:00 - 14:00
Lunch
14:00 - 15:00 Session 4: DFS cyber resilience toolkit tabletop exercise (Part 3) 15:00 - 15:15
Coffee Break
15:15 - 17:00 BSA sandbox bootcampModerator: Ariff Olan Kholid , Project Manager, FNSValue Malaysia
17:00 - 17:15 Closing of the Security Clinic