Bank of England CIO Sets A Cybersecurity Challenge

Bank of England CIO Robert Elsey plays a central role in protecting the UK's financial sector. Elsey runs a cyber security division that protects around £575 billion sterling payments and securities every day, helps to track all bank notes in circulation and secures £140 billion of gold deposits in the vault. 

The Bank's unique challenges are intensified by a nationwide digital skills gap, which led Elsey to a novel way to boost the bank's defences: a face-to-face cyber security competition that tests the skills of 30 of untapped talents in the UK to identify the next-generation of experts.

The 30 best applicants earn an invitation to the iconic building on Threadneedle Street (pictured) that has been the Bank of England’s home since 1734. They then compete in teams on a series of banking-themed tasks developed by the Bank's security team to simulate the experience of working at a leading financial institution. The competitors combat and contain a cyber attack by planning and improving security architecture, educate staff on the threats and carry out a forensic investigation of the attack.

The event helps the Bank attract talent from diverse backgrounds and show them that technology careers are more varied than they might imagine.

"It starts to show the different qualities you need," says Elsey. "It's not just coding anymore. There's everything from business case history to the climate and sponsoring initiatives. We've got people from all kinds of different backgrounds now working in technology and it's making it a much better place."

The competition combines technical challenges with tests of broader skills. An exercise inspired by Dragons Den requires teams to improve a network design by spending a £1 million budget on a cyber security shopping list, while a pitching competition invites them to present their ideas for a phishing awareness training programme.

"What was nice is that those people that did get involved through a less technical setting could flex their skills in different areas, and could appreciate why it would attract different people in the future," says Elsey.

New sources of cyber security talent

The top 10 performers in the challenge will then attend three-day masterclass in November, and the top performers earn an interview for a role on the Bank of England's security team.

Elsey hopes they will inject some youth into an aging workforce. Only 12% of the cyber security workforce is under the age of 35, while 53% of it is over 45, according to the Center for Cyber Safety and Education’s Global Information Security Workforce Study. This could create new dangers as more experts reach retirements.

"We try to avoid and weed out those who are in the industry," says Elsey. "We're looking for more of the younger students who are interested, or people who are thinking about moving into cyber security."

Their efforts paid off. Around 60% of the competitors were in secondary or further education, while two-thirds were participating in their first event involving Cyber Security Challenge UK, the non-profit organisation that arranged the competition with the Bank.

"It was more about raising awareness that it's not just people who can code that go to these competitions and add value," says Elsey. "In fact, some of our big success stories are people who did mathematics, who hadn't considered technology and coding before, but actually, as mathematicians, they're data scientists and they're analysts.

"Those types of individuals fit in really well with that kind of inquisitive mindset...Where we have done very well in the bank in trying to attract good, diverse employee base is by trying to look in those pockets of people that wouldn't normally think about it, but when they're in it, they love it".

CIO:

You Might Also Read:

Bank of England: Cyberattacks A 'Clear and Present Danger':

US Banks Face A Growing Threat

« Police Are Mishandling Digital Forensic Evidence
Cybercrime Is Increasing In Scotland »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

National Institute of Standards & Technology (NIST)

National Institute of Standards & Technology (NIST)

NIST is a measurement standards laboratory, and a non-regulatory agency of the United States Department of Commerce. Areas covered include IT and cybersecurity.

WireX Systems

WireX Systems

WireX is an innovative network intelligence and forensics company that is changing the way businesses resolve cyber-attacks.

Wallix

Wallix

Wallix is a software company offering privileged access management solutions for enterprises, public organizations and cloud service providers

IDnext

IDnext

IDnext is the open and independent platform to support innovative approaches in the world of the Digital identity.

ZyberSafe

ZyberSafe

ZyberSafe is an innovative Danish company specialized within building hardware encryption solutions.

Bowbridge

Bowbridge

Bowbridge provides anti-virus and application security solutions for SAP systems.

Baffin Bay Networks

Baffin Bay Networks

Baffin Bay Networks operates globally distributed Threat Protection Centers™, offering DDoS protection, Web Application Protection and Threat Inspection.

ZEBOX

ZEBOX

ZEBOX is an international incubator & accelerator of innovative startups. Focus is on Transport/Logistics and Industry X.0 including technologies such as AI, Blockchain and Cybersecurity.

Boeing

Boeing

Boeing is the world's largest aerospace company and leading manufacturer of commercial jetliners, defense, space and security systems.

ADVA Optical Networking

ADVA Optical Networking

ADVA is a company founded on innovation and focused on helping our customers succeed. Our technology forms the building blocks of a shared digital future and empowers networks across the globe.

Bugv

Bugv

Bugv is a crowdsourcing cybersecurity platform powered by human intelligence where we connect businesses with cyber security experts, ethical hackers, bug bounty hunters from all around the world.

Technivorus Technology

Technivorus Technology

Technivorus is a deep-tech firm delivering customized Cybersecurity, Digital Marketing, Web & App Development, and multifarious IT services for businesses across the globe.

Cytek

Cytek

Cytek is a leading provider of cybersecurity and HIPAA compliance for dental practices and other industries.

Oz Forensics

Oz Forensics

Oz Forensics is a global leader in preventing biometric and deepfake fraud. It is a developer of facial Liveness detection for Antifraud Biometric Software with high expertise in the Fintech market.

Bearer

Bearer

Bearer helps modern teams ship trustworthy products with the help of our code security solution built for security, privacy and engineering teams.

Metrodata Group

Metrodata Group

PT. Metrodata Electronics, known as Metrodata Group, is the leading information communication technology company in Indonesia.