Banks at the Fault Line: Systemic Fragility, Hybrid Threats and Europe’s Security Blind Spot
A cross-border Global CSNN analysis of financial-system fragility, institutional complacency and the physical and digital security of European banks.
A common European warning from leaders of the CSNN network
This publication brings together the perspectives of CSNN Germany and CSNN Italy within the Global CSNN editorial structure. The article is presented in full in three language versions and addresses systemic financial vulnerability, hybrid destabilisation risks and the insufficient digital and physical protection of banking institutions.
Banks at the Fault Line: Systemic Fragility, Hybrid Threats and Europe’s Security Blind Spot
The economic and financial situation of the world is catastrophic.
Colossal debt, virtual assets, stock-market shells, etc. may at any moment lead to a collapse.
Even a single serious trigger, such as the failure of a major bank, is enough for the avalanche to begin.
And there are no alternative solutions.
To make matters worse, banks, which are the rotten foundation of the system, behave with complete carelessness.
Although serious problems are emerging in many banks practically all over the world, they still draw no conclusions from them and do not remove the causes.
To make matters worse, in the world of hybrid wars that currently prevails, a doctrine has emerged and is in force which assumes that destroying the opponent’s financial system is one of the priority objectives.
An example of such a preliminary action is what is happening in Poland with VeloBank.
It appears that, with a minimal expenditure of forces and resources from “an unknown side,” one of the easiest methods of causing very serious turbulence and attempting destabilisation is being tested.
Despite the obvious convergence with the doctrine mentioned above, the bank’s Management Board and the services responsible for security not only do nothing — apart from the bank’s chaotic and inconsistent actions — but also seem completely unaware of the situation and of possible larger threats.
This example should give banks and all services of the Democratic West much to think about — and act upon.
While there is still a chance, everything possible must be done to prevent such attempts.
And there is an enormous amount of work to be done within the banks themselves.
Banks’ security measures are at an embarrassingly low level.
And, even more strangely, the level of physical protection is even lower.
Our specialised unit, which tests all types of bank security, is not only capable of breaking software safeguards, but was also able, without difficulty and without leaving any trace, to physically penetrate Management Board offices, server rooms and open-plan work areas of various departments.
Of course, this was done in agreement with the Management Board, meaning that bank employees had been informed in advance.
It is easy to imagine what opportunities penetration into those rooms provides.
Lest it appear that this is a single case completely detached from reality.
Such an operation was physically carried out in five banks and in ALL of them it ended in 100% fully documented success.
Despite such alarming results, the Management Boards did not implement — or did so to an insufficient extent — the recommendations presented in the reports from the physical security tests.
The failure to take into account the proposals resulting from the penetration tests meant that the tests succeeded again.
The lack of critical reflection on the part of bank management boards and security departments calls into question the security of the banking sector in Europe.
Banken an der Bruchlinie: Systemische Fragilität, hybride Bedrohungen und Europas Sicherheitslücke
Die wirtschaftliche und finanzielle Lage der Welt ist katastrophal.
Kolossale Verschuldung, virtuelle Vermögenswerte, Börsenhüllen usw. können jederzeit zu einem Zusammenbruch führen.
Schon ein einziger ernsthafter Impuls, etwa der Zusammenbruch einer großen Bank, genügt, und die Lawine kommt ins Rollen.
Alternative Lösungen fehlen.
Erschwerend kommt hinzu, dass sich die Banken, die das morsche Fundament des Systems bilden, völlig sorglos verhalten.
Obwohl praktisch weltweit bei vielen Banken ernsthafte Probleme auftreten, ziehen sie daraus weiterhin keine Schlussfolgerungen und beseitigen die Ursachen nicht.
Erschwerend kommt hinzu, dass in der heute vorherrschenden Welt hybrider Kriege eine Doktrin entstanden ist und gilt, nach der die Zerstörung des Finanzsystems des Gegners zu den vorrangigen Zielen gehört.
Ein Beispiel für ein solches vorbereitendes Vorgehen ist das, was in Polen mit der VeloBank geschieht.
Es sieht so aus, als werde mit minimalem Einsatz von Kräften und Mitteln von „unbekannter Seite“ eine der einfachsten Methoden erprobt, um sehr schwere Turbulenzen herbeizuführen und einen Destabilisierungsversuch zu unternehmen.
Trotz der offenkundigen Übereinstimmung mit der genannten Doktrin tun weder der Vorstand der Bank noch die für die Sicherheit zuständigen Dienste etwas — abgesehen von chaotischen und widersprüchlichen Maßnahmen der Bank — und scheinen sich der Lage sowie möglicher größerer Bedrohungen überhaupt nicht bewusst zu sein.
Dieses Beispiel sollte den Banken und sämtlichen Diensten des Demokratischen Westens viel zu denken geben und sie zum Handeln veranlassen.
Solange noch eine Chance besteht, muss alles Mögliche getan werden, um solchen Versuchen vorzubeugen.
Und in den Banken selbst gibt es eine enorme Menge an Arbeit zu leisten.
Die Sicherheitsvorkehrungen der Banken befinden sich auf einem beschämend niedrigen Niveau.
Und, was noch merkwürdiger ist, das Niveau des physischen Schutzes ist noch niedriger.
Unsere spezialisierte Einheit, die sich mit der Prüfung sämtlicher Sicherheitsvorkehrungen von Banken befasst, ist nicht nur in der Lage, softwarebasierte Schutzmaßnahmen zu überwinden, sondern konnte auch ohne Schwierigkeiten und ohne irgendwelche Spuren zu hinterlassen physisch in die Räume des Vorstands, in Serverräume sowie in offene Arbeitsbereiche verschiedener Abteilungen eindringen.
Selbstverständlich geschah dies in Absprache mit dem Vorstand, das heißt, die Mitarbeiter der Bank waren zuvor informiert worden.
Welche Möglichkeiten das Eindringen in die genannten Räume eröffnet, kann man sich leicht vorstellen.
Damit nicht der Eindruck entsteht, es handle sich um einen einzigen, völlig lebensfremden Fall.
Eine solche Aktion wurde physisch in fünf Banken durchgeführt und endete in ALLEN mit einem zu 100 % vollständig dokumentierten Erfolg.
Trotz derart alarmierender Ergebnisse setzten die Vorstände die in den Berichten über die physischen Sicherheitstests enthaltenen Empfehlungen nicht um — oder nur in unzureichendem Umfang.
Die Nichtberücksichtigung der aus den Penetrationstests resultierenden Vorschläge führte dazu, dass die Tests erneut erfolgreich waren.
Die fehlende Reflexionsfähigkeit der Bankvorstände und Sicherheitsabteilungen stellt die Sicherheit des Bankensektors in Europa infrage.
Banche sulla linea di faglia: fragilità sistemica, minacce ibride e il punto cieco della sicurezza europea
La situazione economica e finanziaria del mondo è catastrofica.
Un indebitamento colossale, asset virtuali, gusci vuoti quotati in borsa, ecc. possono in qualsiasi momento portare a un crollo.
È sufficiente anche un solo impulso serio, come il fallimento di una grande banca, e la valanga si mette in moto.
E mancano soluzioni alternative.
A peggiorare la situazione, le banche, che costituiscono il fondamento marcio del sistema, si comportano con totale noncuranza.
Nonostante praticamente in tutto il mondo emergano gravi problemi in numerose banche, esse continuano a non trarne conclusioni e a non eliminare le cause.
A peggiorare ulteriormente la situazione, nel mondo oggi dominato dalle guerre ibride è nata ed è in vigore una dottrina secondo cui la distruzione del sistema finanziario dell’avversario costituisce uno degli obiettivi prioritari.
Un esempio di tale azione preliminare è ciò che sta accadendo in Polonia con VeloBank.
Sembra che, con un impiego minimo di forze e mezzi da parte di “non si sa quale parte”, venga testato uno dei modi più semplici per provocare turbolenze molto gravi e tentare una destabilizzazione.
Nonostante l’evidente convergenza con la dottrina menzionata, né il Consiglio di Amministrazione della banca né i servizi responsabili della sicurezza fanno qualcosa — al di là delle azioni caotiche e incoerenti della banca — e sembrano essere del tutto inconsapevoli della situazione e di eventuali minacce più ampie.
Questo esempio dovrebbe indurre le banche e tutti i servizi dell’Occidente Democratico a riflettere e ad agire.
Finché esiste ancora una possibilità, bisogna fare tutto ciò che è possibile per prevenire tali tentativi.
E nelle banche stesse c’è un’enorme quantità di lavoro da fare.
Le misure di sicurezza delle banche sono a un livello vergognosamente basso.
E, cosa ancora più strana, il livello della protezione fisica è ancora più basso.
La nostra unità specializzata, che si occupa di testare ogni tipo di protezione bancaria, non solo è in grado di violare le protezioni software, ma è anche riuscita, senza alcuna difficoltà e senza lasciare alcuna traccia, a penetrare fisicamente negli uffici del Consiglio di Amministrazione, nelle sale server e nelle postazioni open desk di diversi reparti.
Naturalmente ciò è avvenuto d’intesa con il Consiglio di Amministrazione, vale a dire che i dipendenti della banca erano stati avvisati in anticipo.
È facile immaginare quali possibilità offra la penetrazione nei locali menzionati.
Affinché non sembri che si tratti di un unico caso completamente scollegato dalla realtà.
Un’azione di questo tipo è stata condotta fisicamente in cinque banche e in TUTTE si è conclusa con un successo del 100%, pienamente documentato.
Nonostante risultati così allarmanti, i Consigli di Amministrazione non hanno applicato — oppure lo hanno fatto in misura insufficiente — le raccomandazioni presentate nei rapporti sui test fisici di sicurezza.
La mancata considerazione delle proposte derivanti dai test di penetrazione ha fatto sì che i test avessero nuovamente successo.
La mancanza di capacità critica da parte dei consigli di amministrazione delle banche e dei dipartimenti di sicurezza mette in discussione la sicurezza del settore bancario in Europa.












