Jagannath University
Department of Management Studies
BBA 2nd Year, 2nd semester
Course Title- Management Information Systems
Course code – MGT-2204
Report On
Towards a Secure Banking Environment: Cyber Security Challenges and
Solutions for Sonali Bank PLC.
Submitted to
Md. Shahidul Islam Fakir
Professor
Department of Management Studies,
Jagannath University, Dhaka
Date of Submission – 5/11/2025
1 of 17
Submitted by
Serial no. Name ID Number
1 Md. Shanto Hossain B220202038
2 Md. Sahinur Rahaman Tashin B220202038
3 Raiyan Rahaman B220202058
4 Antor Roy B220202033
5 Sameer Hossain B220202010
6 Shopon Chandra Pal B220202047
7 Shorif B220202032
8 Ariful Islam B220202051
9 Kamrul Islam B220202062
10 Foysal Kamal B220202039
2 of 17
Abstract
The report analyzes the cyber security measures of Sonali Bank PLC, which is one of the largest
state owned bank in Bangladesh and also upholds the importance of protecting the financial sector
from potential cyber threats. Currently the banking sectors are the main target of cyber-attacks
that's why Sonali Bank has developed a strong cyber security framework which uses tools like
Privilege Access Management (PAM), Vulnerability Assessment and Penetration Testing (VAPT),
and employee training to make their cyber security strong and safe. The study and details of these
report is based on the interview with the senior bank employees of the IT sector of Sonali Bank
who are tackling with threats like phishing, malware and data breaches.
3 of 17
Table of Contents
S.L
Number Name of the Chapter Page Number
1 Introduction 5-6
2 Past relevant studies 6-8
3 Theoretical Approach 9
4 Methodology 10-12
5 Empirical Results and Analysis 13-15
6 Discussion and Conclusion 16
7 References 17
4 of 17
1. Introduction.
Cyber risks are among the quickest-growing risks and challenges since, just like technologies,
they are in constant flux. These risks are not endemic only to the financial sector. The head office
of one of the largest state-owned commercial banks in Bangladesh, Sonali Bank PLC, is based
there, and it forms a significant part of the country's financial system with its widespread branch
and online network. The commitment of Sonali Bank to maintaining stability and security in the
financial system remains.
Cyber security has been at the leading edge of modern dangers in this cat-and-mouse game, from
threats like APT or DDoS attacks to phishing, ransomware, and data breach situations. The range
of these risks encompasses everything from secure financial transactions to the protection of
confidential customer-information.
Sonali Bank has an extended cyber security arrangement supported by advanced technologies,
solid policies, and regular training programs for the staff for such challenge-countering. Its best
practices, considering regulatory compliance requirements and consumer trust, have been
benchmarked against the best national and worldwide best practices. The foreword, therefore,
underlines Sonali Bank's commitment to cyber security in pursuit of safe and sound banking
facilities for Bangladeshis. In turn, Sonali Bank deploys the state-of-the-art security frameworks
complemented by round-the-clock monitoring of the cyber threat landscape in a proactive,
forward-looking effort in order to counter all forms of threats against it and its customers'
interests.[a]
Background of the study: Sonali Bank PLC, being one of the largest banks in Bangladesh,
place a critical role in nations financial ecosystem. However, like other financial institutions, it
faces escaleting cyber security risks. With increasing dependencies on online banking, the risks
of data breaches, ransomeware, phishing attacks hav grown significantly. Addressing these
challenges requires proactive strategies and investments in advanced technologies.[b]
Purpose and research questions: The purpose of this questionnaire is to gain insights into
the current cyber security practices, challenges, and improvements within the banking sector of
5 of 17
Bangladesh, with a focus on Sonali Bank PLC. This aims to collect critical data for analysing
cyber security readiness and effectiveness, helping inform a comprehensive report on the state of
cyber security in banking sector.
Specific Questions:
1. What Cyber security framworks and technologies does Sonali Bank PLC currently use to
prevent Cyber threats?
2. What are the most common Cyber threats the bank encounters, and how does it responds to
incidents?
3. What are the banks plan to enhance cyber security in the coming years?
Disposition of the report:
The report is structured as follows:
➢ An introduction providing an overview and research objectives.
➢ A literature review highlighting relevant studies on Cyber security in banking.
➢ Theoritical approaches to understanding Cyber security in banking.
➢ The methodology used to gather and analyse data.
➢ Emperical findings on challenges and solutions.
➢ Discussion and Conclusion with actionable recommendation.
6 of 17
2. Past Relevant Studies.
Banking sectors have gone through significant transformation, leading to a more digitalized world
as time goes by. But this change also made the banking sector a prime target for cyber threats. As
a result of trying to enhance customer accessibility and convenience, the banks now have to keep
up with evolving cyber threats that target their technical and human behavior vulnerabilities.
As the banking sectors have modernized, so have the attacks targeted at them. Studies show that
among the various threats, some notable ones arise from exploiting the vulnerabilities raised from
the massive digitalization of the services provided, namely, phishing, malware, ransomware, etc.,
that are products of the rapid sophistication and evolution of cyber-attacks, DDoS attacks, threats
from insiders, and technical vulnerabilities that are jeopardizing system integrity and data privacy.
These challenges mainly come from needing to adapt to newer attack vectors to keep customer
experience by taking extreme security measures and other measures to protect against financial
losses and reputational damage [c].
These threats have already done massive damage to many giants in different industries. Like, The
cyber heist of Bangladesh Bank (2016), the central bank of Bangladesh, was a major shock to the
world. Use of malware and manipulation of SWIFT systems by the hackers cost Bangladesh Bank
almost $81 million from their reserves. This incident taught them to implement strong network
segmentation, enhance authentication for high-value transactions, and regularly monitor and
update systems [d].
Another such case is the Equifax Data Breach of (2017), a top consumer credit reporting agency,
where the hackers used an unpatched Apache strut vulnerability of the organization to steal
personal information (including their names, credit card numbers, dates of birth, social security
numbers, etc.) of almost 148 million US citizens, causing damage that could barely be calculated.
After this incident, Equifax adopted a zero-trust security model, improved data segmentation and
encryption, and prioritized vulnerability management very strictly. [e]
7 of 17
Although there have been countless attacks on banking and financial institutions and other
organizations in different industries, they have tried and overcome these challenges through
adopting various different solutions depending on the many situations as they arise. As there are
various cases, there are just as many solutions.
To counter all these various threats and challenges, organizations must adopt a combination of
organizational and technical measures. These measures may include encryption and multi-factor
authentication, firewalls, intrusion prevention systems, security-conscious culture training,
incident response planning, risk management planning, continuous monitoring, etc. These
measures (along with others if needed depending on various situations) can help counter cyber
threats and challenges that arise in various situations. But they must always stay on their toes and
adapt to the various new challenges that may come along their journey to a more modernized
future.
8 of 17
[Link] Approach
To Analyze the Cyber security challenges and solutions, the following theoritical approaches are
adopted:
➢ CIA Triad: Ensuring confidentiality, integrity, and availability of data is peramount in
banking security.
➢ Risk Management Theory: Identifies, assesses, and mitigates risks associated with digital
banking operations.
➢ Regulatory framworks: Adherence to ISO 27001 standards and Bangladesh Banks IT
security Guidelines can strengthen Sonali Banks defences.
These frameworks provide the foundation for developing a secure baking environment.[i]
9 of 17
[Link].
This report examines the cyber security systems of Sonali Bank PLC, a leading financial
organization in Bangladesh, through a structured methodology focusing on collecting primary
data by doing indepth interviews with key personnel involved in the bank’s cyber security
activities and predominantly includes qualitative research methodologies. The following steps of
the procedure are:
4.1 Method Overview and Significance of Selecting Relevant Methods : The motive behind
this report’s descriptive research approach is to understand the cyber security rules and regulations
of SONALI BANK PLC. Due to the complexity and quick development of cyber security systems,
qualitative data collection was decided to be the most appropriate way for offering a
comprehensive picture of the bank’s objectives, rules, and policies about cyber security.
4.2 Background Information about the Company: Sonali Bank PLC is one of the biggest
government-owned banks in Bangladesh. It started its journey in 1972 and is still serving people.
The bank’s goal is to provide excellent banking service and help the country’s economy. Sonali
Bank has many branches and offers services like personal banking, business banking, and
international trade finance. Its dedication helps to earn the trust of its customers. [f]
Sonali Bank's journey in digital banking began with establishing core banking infrastructure. A
notable milestone came in 2013 when the bank partnered with Intellect Design Arena to
implement an integrated, centralized core banking system, which allowed real-time online
transactions and a more seamless banking experience across branches. This was a massive shift
from their previous manual and paper-based processes, especially for international trade finance,
which had been managed manually. [g]
In the 2020s, Sonali Bank introduced more accessible digital services such as mobile apps, "Sonali
eSheba" and "Sonali e-Wallet," which allowed users to conduct online transactions and make QR
code payments. These services were particularly beneficial for expatriates, enabling them to open
accounts and manage finances from abroad. The bank also introduced a call center and digital
security measures to address the rise in cyber threats as part of its commitment to secure banking
services. [h]
10 of 17
In August 2023, Sonali Bank held a workshop on cyber security awareness to counter the threats
of cyber-attacks in the financial sector. With the rise of digital banking, it became crucial to protect
sensitive information and financial transactions. [h]
Day by day, Sonali Bank tries to improve its cyber security and bring digitalization into its banking
process. The bank has implemented hard security policies and invested in staff training to
recognize and respond to cyber threats. As the bank’s digital services grow, so does its ability to
protect them.
Continuously, they are improving their cyber security structure. Since the world is being more
digitalized, the risk related to cyber security is also increasing, and for that reason they are
adopting modern technologies to face those problems.
4.3. Data Collection Strategy: A predetermined interview with the Assistant General Manager
(AGM) of Information Security, IT Risk Management & Fraud Control Division of Sonali Bank
PLC provided the required core data needed for this report. The interview covers these topics
within the bank-
• Cyber security Infrastructure
• Cyber security Policies
• Incident Response Protocols
• Programs for Training and Awareness
• Limitations and Challenge
In addition to the interview, Secondary Data from various public documents including the
bank’s official reports, IT policies, documents and any relevant industry reports on cyber
security in banking sector was collected.
4.4. Data Analysis Strategy: To identify the trends and recurring worries about cyber security in
Sonali Bank, a qualitative analytical method was applied. The following procedures were used:
• Transcription: A verbatim transcription of every response was obtained.
11 of 17
• Coding: After closely reviewing the transcriptions, recurring themes about the bank’s
cyber security strengths and weaknesses, including particular technical measures and
policies, were discovered.
4.5. Ethics in Reaearch Process: Given the sensitive nature of cyber security and internal
operations of Sonali Bank’s, some ethical considerations were taken into account during the
research process:
• Confidentiality: All information submitted by interview was kept private. Anonymity was
ensured by removing personal information from the transcripts, and the study only used
aggregated findings.
• Informed Consent: Prior to the interviews, all participants received information about the
study’s goals, the planned use of data, and their right to withdraw participation at any time.
The participant provided his consent before the interview was conducted.
• Data Security: To avoid unwanted access, the collected data, including transcripts and
recordings of interviews, was safely kept.
Restrictions: Even if this report offers valuable information about Sonali Bank’s cyber security
framework, there still remain certain limitations:
• Limited Sample Size: Due to time restrictions and interviewee unavailability, only one
related individual was questioned. In spite of providing valuable insights, it might not
accurately provide the opinions of all employees working in the bank.
• Access Restriction: The research was incapable of examining the bank’s cyber security
infrastructure up close or gaining network security logs.
12 of 17
[Link] Results and Analysis.
This section details current cyber security practices at Sonali Bank PLC, including:
PAM (privilege access management), ISO 27001, VAPT (Vulnerability Assessment and
Penetration
Testing), spam deployment, employee awareness, and firewall.[i]
5.1 Policies and Protocols: Privileged Access Management (PAM) focuses on managing,
monitoring, and evaluating privileged accounts and access. PAM seeks to reduce the possibility
of data breaches and illegal access. Vulnerability Assessment and Penetration Testing (VAPT) is
a thorough security evaluation procedure that finds and takes advantage of weaknesses in
programs and systems. "SPAM" typically refers to unsolicited email, while cyber security refers
to specific tools or techniques used for testing or deployment of the spam. Awareness of the
employee policy makes the employees very careful about sharing any confidential passwords with
anyone.
5.2 Technologies and Tools: Firewall is the barrier between a private internal network (like home
or office network) and the public internet. Through the monitoring and filtering of incoming and
outgoing network traffic, it prevents potentially dangerous or unauthorized activities while
permitting only permitted traffic and blocking unauthorized traffic to flow. Using spam detecting
advanced tools.
5.1. Employee training: Cyber security awareness programs and seminars, phishing
awareness, compliance and regulations about security, and social engineering defense
training.
5.2. Incident response: Sonali Bank PLC has never experienced significant hacking
issues, either in the past or the present, but for the near future they are trying to improve
their security skills by training their employees, upgrading their policies, and giving focus
on adapting more advanced technologies.
Synthesis of Findings The qualitative data gained from interviews was combined with
secondary data from available public sources to create a comprehensive image of Sonali Bank’s
cyber security strengths and weaknesses. In the latter sections of the report, this analysis will
inform the recommendations.
13 of 17
Analysis of Findings (with Relevant Digital Business Theory).
In this section, we analyze Sonali Bank's cyber security practices based on research and relevant
digital business theory. The bank has implemented various strategies and technologies, a
comprehensive framework, modern security technologies, and a set of policies to ensure a secure
banking environment. However, there are areas of potential improvement to increase resilience
against cyber threats.
Cyber Security Framework: ISO 27001.
Sonali Bank uses ISO 27001, an internationally recognized information security management
system. By using ISO 27001, the bank ensures that data is secure and protected from breaches,
unauthorized access, and other online threats; sensitive farm data can be systematically managed.
The application of ISO 27001 is consistent with Information Security Management System
(ISMS) theory, which highlights the importance of a systematic, risk-based approach to
information security management within the framework of digital business theory.[i]
Policies and Governance.
Sonali Bank has developed around 20 cyber security policies that address issues such as employee
conduct, incident response, data privacy, and access management. These policies are essential to
establish a strong governance framework and ensure uniform application of security measures
across the company.
This policy-driven strategy is consistent with risk management theory, which, viewed from a
digital business perspective, emphasizes the importance of well-defined policies and
organizational oversight in managing cyber risk. By ensuring that all departments and employees
follow security measures, strong governance helps reduce the likelihood of policy violations or
human error. It encourages a culture of accountability within the company and raises awareness
of cyber security.
Latest Technologies and Firewalls.
Sonali Bank uses new security technologies like firewalls to protect personal information from
external threats and keep its systems secure. By using pre-established security rules to monitor
14 of 17
and control incoming and outgoing network traffic, firewalls act as the first line of defense. Sonali
Bank implements state-of-the-art firewalls and continuously modernizes its technology
infrastructure to better identify and counter potential cyber threats.
Sonali Bank’s commitment to using the latest technologies reflects the principles of the
Technology Acceptance Model (TAM) from digital business theory, which suggests that the more
useful and userfriendly a technology is perceived to be, the more likely it is to be embraced and
used effectively within an organization. Sonali Bank exhibits a proactive approach to safeguarding
client data and enhancing productivity by implementing cutting-edge cyber security solutions. In
addition to bolstering the bank's defenses against cyberattacks, this commitment to technological
innovation fosters confidence and trust among its stakeholders and clients.
Identification of Gaps and Recommendations.
Although Sonali Bank has put in place a robust cyber security structure, policies, and cutting-edge
technologies, there may be a need for improvement in the following areas:
i. Improved Threat Detection: Because firewalls provide some security, banks can use more
advanced threat detection tools, such as Intrusion Detection Systems (IDS) and Security
Information and Event Management (SIEM) systems, to more successfully detect and prevent
threats.
ii. Continuous Employee Training: They should train their employees continuously because the
effectiveness of cyber security regulations depends on the people who comply with them. A major
cyber security risk is human error, which can be reduced through regular employee training and
awareness initiatives.
iii. Better Data Encryption: Data encryption is required to protect sensitive client data. By
implementing more sophisticated encryption techniques for both transmitted and stored data,
Sonali Bank can improve its data security procedures.
15 of 17
[Link] and Conclusion.
In short, Sonali Bank has laid a solid foundation for cyber security through its ISO 27001, strong
policies, and use of the latest security technologies. By aligning its practices with digital business
theories such as ISMS, risk governance, and TAM, the bank is well positioned to manage cyber
risks. However, staying ahead of evolving threats in the digital landscape requires continuous
improvements in technology and training. The main findings of this report show that strong tools
like PAM, VAPT, ISO 27001, and employee training are making the cyber security system strong,
safe, and resilient. To combat the threats and strengthen the security system more, the bank should
implement multiple factor authentication, end-to-end encryption, and the SIEM system in their
technical solution sector. Looking
ahead, while technical solutions are essential, the bank also should embrace some practices like
conducting regular audits, employee training, real time monitoring, and so on.
16 of 17
References:
[a] Accenture (2023).
[b] Sonali Bank PLC Annual Report (2023).
[c] Darem, A. A., Alhashmi, A. A., Alkhaldi, T. M., Alashjaee, A. M., Alanazi,
S.M., & Ebad, S. A. (2023). Cyber threats classifications and countermeasures
in banking and financial sector. IEEE Access, 11, 125138-125158.
[d] Bukth, T., & Huda, S. S. (2017). The soft threat: The story of the Bangladesh
bank reserve heist. SAGE Publications: SAGE Business Cases Originals.
[e] Thomas, J. (2019). A case study analysis of the Equifax data breach 1 A case
study analysis of the Equifax data breach. December). [Link]
researchgate. net/publication/337916068.
[f] [Link]
[g] Bangladesh Post.
[h] The Daily Star.
[i] Bangladesh Bank IT security Guidelines (2022).
17 of 17