Scaling Security Move fast and make things Paul Heffernan Revolut - - PowerPoint PPT Presentation

scaling security
SMART_READER_LITE
LIVE PREVIEW

Scaling Security Move fast and make things Paul Heffernan Revolut - - PowerPoint PPT Presentation

Scaling Security Move fast and make things Paul Heffernan Revolut CISO paul.heffernan@revolut.com Vision: Global mobile banking Local current accounts in 2 minutes Multi-currency accounts Full control of cards and accounts on


slide-1
SLIDE 1

Scaling Security

Move fast and make things

slide-2
SLIDE 2

Paul Heffernan Revolut CISO paul.heffernan@revolut.com

slide-3
SLIDE 3

Vision: Global mobile banking

  • Local current accounts in 2 minutes
  • Multi-currency accounts
  • Full control of cards and accounts on your phone
  • Safe transactions online
  • Spending control, budgeting and saving
  • Investment
  • Free instant transfers globally
slide-4
SLIDE 4

Traditional financial services is a target

  • Complex monolithic IT, hard to manage
  • Reliance on legacy systems
  • Supply chain complexity
  • Customer security burden
  • It’s where the money is!
slide-5
SLIDE 5

Security First

slide-6
SLIDE 6

Security = Trust

Instant transaction notifications Disable/enable as you go

  • Location-based security
  • E-commerce
  • ATM
  • Contactless
  • Magstripe
slide-7
SLIDE 7

Disposable virtual cards

  • More convenient, don’t have to worry about

misplacing your plastic

  • Card details automatically deleted and

updated after every transaction

  • Adds extra layer of security to online

purchases and helps reduce online card fraud

slide-8
SLIDE 8

Our Approach

slide-9
SLIDE 9

Technology: Simple cloud native architecture

  • Containerisation hosted on Google Cloud
  • Microservices with API automation
  • Leverage security services

Benefits:

  • Global resiliency
  • Fully automated infrastructure-as-code
  • Context-aware identity controls
slide-10
SLIDE 10

Culture: Making security scale within the organisation

  • Put tools into the hands of the people
  • Facilitate knowledge sharing rather than rulebooks
  • Find and elevate the champions

Examples:

  • Security toolbox for developers
  • Knowledge sharing sessions on security
  • Developer ‘hackathon’
slide-11
SLIDE 11

Getting security into the CI/CD pipeline

  • Deploy to production speed
  • Keep build time down

How:

  • Culture first, technology later
  • Automate the right tests and train the rest
  • Standardised components
slide-12
SLIDE 12

What’s next?

We’re hiring!