⚠ Official Notice: www.ijisrt.com is the official website of the International Journal of Innovative Science and Research Technology (IJISRT) Journal for research paper submission and publication. Please beware of fake or duplicate websites using the IJISRT name.



NIST-Based Cybersecurity Risk Management for Mitigating Customer Data Breaches and Cyber Threats in Banking


Authors : Mercurius Broto Legowo; Budi Indiarto; Adzrani Haura Badzlinaya Novianto; Nasywa Aliyya Omar

Volume/Issue : Volume 11 - 2026, Issue 8 - August


Google Scholar : https://tinyurl.com/52jcamuv

Scribd : https://tinyurl.com/4h25yk96

DOI : https://doi.org/10.38124/ijisrt/26aug509

Note : A published paper may take 4-5 working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and ResearchGate.


Abstract : The rapid digitalization of business processes has heightened organizational vulnerability to cybersecurity threats, particularly customer data breaches, unauthorized access, malware, phishing, and cyberattacks. These threats can compromise sensitive information, disrupt operations, cause financial losses, and erode customer trust. This study aims to examine the implementation of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) for mitigating customer data breaches and cybersecurity threats. A qualitative research approach is employed to analyze cybersecurity risks, vulnerabilities, security controls, and risk mitigation practices in accordance with the NIST RMF. The framework encompasses a systematic process for categorizing information systems, selecting and implementing security controls, assessing control effectiveness, authorizing systems, and continuously monitoring risks. The results indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks, strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring. The findings suggest that strengthening customer data protection requires a holistic approach integrating technological safeguards, organizational governance, employee awareness, risk assessment, and effective incident response mechanisms. This study contributes to the cybersecurity risk management literature by proposing a structured approach to strengthening organizational resilience against customer data breaches and evolving cyber threats.

Keywords : Banking; Cyber Threats; Data Breach; NIST RMF; Risk Management.

References :

  1. A. Kurniawan, A. Rahayu, and L. A. Wibowo, “The Effect of Digital Transformation on the Performance of Regional Development Banks in Indonesia,” J. Ilmu Keuang. dan Perbank., vol. 10, no. 2, pp. 158–181, 2021, doi: 10.34010/jika.v10i2.4426.
  2. S. R. Vaidyula and J. Kavala, Enterprise Risk Management for Banks, no. August. 2018.
  3. A. Soemitra and Adlina, “Consumer Protection Against Data Leakage in Financial Services in Indonesia,” J. Insitusi Politek. Ganesha Medan Juripol, vol. 5, pp. 288–303, 2022.
  4. CNN Indonesia, “Kominfo Clarifies the Alleged BSI Data Leakage Circulating,” CNN News. 2023. [Online]. Available: https://www.cnnindonesia.com/teknologi/20230522122857-192-952382/kominfo-klarifikasi-soal-dugaan-bocoran-data-bsi-yang-beredar
  5. F. C. Rosana, “BRI Life Customer Data Leaks Evidence of Weak Protection and Regulation,” Tempo.co.id. 2017. [Online]. Available: https://fokus.tempo.co/read/1488710/kebocoran-data-nasabah-bri-life-bukti-lemahnya-proteksi-dan-regulasi
  6. P. Gowda and A. N. Gowda, “Data Breach as a Threat in the Banking Sector and Steps to Avoid It,” Int. J. Sci. Res. (IJSR, vol. 10, no. 4, pp. 2019–2022, 2021.
  7. S. Romanosky, R. Corporation, and S. H. St, “Examining the costs and causes of cyber incidents,” J. Cybersecurity, vol. 2, no. August, pp. 121–135, 2016, doi: 10.1093/cybsec/tyw001.
  8.    A. Altamimi, M. Al-Bashayreh, M. Al-Oudat, and D. Almajali, “Blockchain technology adoption for sustainable learning,” Int. J. Data Netw. Sci., vol. 6, no. 3, 2022, doi: 10.5267/j.ijdns.2022.1.013.
  9. I. Alhassan, D. Sammon, and M. Daly, “Critical success factors for data governance : a telecommunications case study,” J. Decis. Syst., vol. 28, no. 1, pp. 41–61, 2019, doi: 10.1080/12460125.2019.1633226.
  10. G. Iyawa and A. Gamundani, “Essential Components of an IT Risk Management Framework for the Financial Services Industry: A Review,” in Proceedings of International Conference on Information Systems and Emerging Technologies, 2023, 2023.
  11. ISACA, COBIT5: A Business Framework for the Governance and Management of Enterprise IT. 2012.
  12. NIST, Risk Management Framework for Information Systems and Organizations Risk Management Framework for Information Systems and Organizations. 2018.
  13. T. Tan and B. Soewito, “Implementing the NIST Cybersecurity Framework at ZXC University,” J. Inf. Syst. Applied, Manag. Account. Res., vol. 6, no. 2, pp. 411–422, 2022, doi: 10.52362/jisamar.v6i2.781.
  14. J. W. Creswell and J. D. Creswell, Research Design: Qualitative, Quantitative, and Mixed Methods Approaches, Sixth Edition. SAGE Publications Asia-Pacific Pte. Ltd., 2023. [Online]. Available: https://medium.com/@arifwicaksanaa/pengertian-use-case-a7e576e1b6bf
  15. K. Dan, A. Sheren, R. Sirait, A. S. Kamalia, A. Diska, and M. B. Legowo, “Cyber Attacks Using the NIST Risk Management Framework,” Pros. Sn. 2023, pp. 1–8, 2023.
  16. N. Nilamsari, “Understanding Document Analysis in Qualitative Research,” Wacana, vol. XIII, no. 2, pp. 177–181, 2014.
  17. T. Aven, “Risk assessment and risk management : Review of recent advances on their foundation,” Eur. J. Oper. Res., vol. 253, no. 1, pp. 1–13, 2016, doi: 10.1016/j.ejor.2015.12.023.
  18. M. B. Legowo, R. Desica, N. Rahsa, N. Batrisyia, and S. R. Julia, “Data Breach and Data Leak as a Threat in XYZ Bank : Risk Management Steps,” J. Business, Finance. Bank, vol. 2, no. 2, pp. 21–36, 2026.
  19. M. Sheleme and R. R. Sharma, “Cyber-attack and Measuring its Risk,” IRO J. Sustain. Wirel. Syst., vol. 3, no. 4, pp. 219–225, 2021.
  20. O. G. Khoirunnisa, “Implementasi Algoritma AES untuk Keamanan Data Rekam Medis,” PETIR J. Pengkaj. dan Penerapan Tek. Inform., vol. 15, no. 1, pp. 21–27, 2022.
  21. B. Stojanović and J. Boži´c, “Robust Financial Fraud Alerting System Based in the Cloud Environment,” Sensors-MDPI, vol. 22, no. 9461, 2022.

The rapid digitalization of business processes has heightened organizational vulnerability to cybersecurity threats, particularly customer data breaches, unauthorized access, malware, phishing, and cyberattacks. These threats can compromise sensitive information, disrupt operations, cause financial losses, and erode customer trust. This study aims to examine the implementation of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) for mitigating customer data breaches and cybersecurity threats. A qualitative research approach is employed to analyze cybersecurity risks, vulnerabilities, security controls, and risk mitigation practices in accordance with the NIST RMF. The framework encompasses a systematic process for categorizing information systems, selecting and implementing security controls, assessing control effectiveness, authorizing systems, and continuously monitoring risks. The results indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks, strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring. The findings suggest that strengthening customer data protection requires a holistic approach integrating technological safeguards, organizational governance, employee awareness, risk assessment, and effective incident response mechanisms. This study contributes to the cybersecurity risk management literature by proposing a structured approach to strengthening organizational resilience against customer data breaches and evolving cyber threats.

Keywords : Banking; Cyber Threats; Data Breach; NIST RMF; Risk Management.

Paper Submission Last Date
31 - August - 2026

SUBMIT YOUR PAPER CALL FOR PAPERS
Video Explanation for Published paper

Never miss an update from Papermashup

Get notified about the latest tutorials and downloads.

Subscribe by Email

Get alerts directly into your inbox after each post and stay updated.
Subscribe
OR

Subscribe by RSS

Add our RSS to your feedreader to get regular updates from us.
Subscribe