Cybersecurity
In the context of institutional governance
Cyber and data security risks have meanwhile become among the key operational challenges facing financial market participants. Supervisory authorities such as BaFin and the Federal Office for Information Security (BSI) regularly highlight that attention should extend beyond firms’ own IT infrastructures to include outsourced processes and third-party service providers.
This development is reinforced from a regulatory perspective by the European framework on digital operational resilience, most notably the Digital Operational Resilience Act (DORA). The focus is on clearly defined responsibilities, robust control mechanisms and transparent, timely communication channels in the event of an incident.
“Cybersecurity is a core component and foundation of responsible governance in complex investment structures. Transparency, control and resilience – cybersecurity is where all of these come together.”
Dorothea Sztopko, Chief Operating Officer
For institutional investors, this implies a shift in perspective. Cybersecurity is no longer a purely technical consideration, but an integral part of modern governance and risk frameworks. What matters is how data flows are structured, which third-party providers are embedded in fund and transaction processes, and how escalation and information procedures function in a crisis scenario.
In practice, this brings into focus questions closely linked to the structuring of funds and mandates – ranging from the selection and ongoing review of external service providers to a continuous, structured exchange between fund managers, administrators and investors. A clear and reliable information framework is a key element of effective governance. At the same time, heightened awareness is advisable in fund-related communications, particularly in connection with administrative or payment-related requests.
“Cybersecurity is effective where governance and operational discipline come together. Every data flow, process and third-party relationship contributes to the resilience our investors expect.”
Nilesh Borole, IT Security Officer
A forward-looking approach to cyber and data security risks not only strengthens operational stability, but is increasingly a prerequisite for transparency, trust and long-term investment security in alternative investments.