Authors :
Mercurius Broto Legowo; Budi Indiarto; Adzrani Haura Badzlinaya Novianto; Nasywa Aliyya Omar
Volume/Issue :
Volume 11 - 2026, Issue 8 - August
Google Scholar :
https://tinyurl.com/52jcamuv
Scribd :
https://tinyurl.com/4h25yk96
DOI :
https://doi.org/10.38124/ijisrt/26aug509
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
The rapid digitalization of business processes has heightened organizational vulnerability to cybersecurity
threats, particularly customer data breaches, unauthorized access, malware, phishing, and cyberattacks. These threats can
compromise sensitive information, disrupt operations, cause financial losses, and erode customer trust. This study aims to
examine the implementation of the National Institute of Standards and Technology (NIST) Risk Management Framework
(RMF) for mitigating customer data breaches and cybersecurity threats. A qualitative research approach is employed to
analyze cybersecurity risks, vulnerabilities, security controls, and risk mitigation practices in accordance with the NIST
RMF. The framework encompasses a systematic process for categorizing information systems, selecting and implementing
security controls, assessing control effectiveness, authorizing systems, and continuously monitoring risks. The results
indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks,
strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring.
The findings suggest that strengthening customer data protection requires a holistic approach integrating technological
safeguards, organizational governance, employee awareness, risk assessment, and effective incident response mechanisms.
This study contributes to the cybersecurity risk management literature by proposing a structured approach to
strengthening organizational resilience against customer data breaches and evolving cyber threats.
Keywords :
Banking; Cyber Threats; Data Breach; NIST RMF; Risk Management.
References :
- A. Kurniawan, A. Rahayu, and L. A. Wibowo, “The Effect of Digital Transformation on the Performance of Regional Development Banks in Indonesia,” J. Ilmu Keuang. dan Perbank., vol. 10, no. 2, pp. 158–181, 2021, doi: 10.34010/jika.v10i2.4426.
- S. R. Vaidyula and J. Kavala, Enterprise Risk Management for Banks, no. August. 2018.
- A. Soemitra and Adlina, “Consumer Protection Against Data Leakage in Financial Services in Indonesia,” J. Insitusi Politek. Ganesha Medan Juripol, vol. 5, pp. 288–303, 2022.
- CNN Indonesia, “Kominfo Clarifies the Alleged BSI Data Leakage Circulating,” CNN News. 2023. [Online]. Available: https://www.cnnindonesia.com/teknologi/20230522122857-192-952382/kominfo-klarifikasi-soal-dugaan-bocoran-data-bsi-yang-beredar
- F. C. Rosana, “BRI Life Customer Data Leaks Evidence of Weak Protection and Regulation,” Tempo.co.id. 2017. [Online]. Available: https://fokus.tempo.co/read/1488710/kebocoran-data-nasabah-bri-life-bukti-lemahnya-proteksi-dan-regulasi
- P. Gowda and A. N. Gowda, “Data Breach as a Threat in the Banking Sector and Steps to Avoid It,” Int. J. Sci. Res. (IJSR, vol. 10, no. 4, pp. 2019–2022, 2021.
- S. Romanosky, R. Corporation, and S. H. St, “Examining the costs and causes of cyber incidents,” J. Cybersecurity, vol. 2, no. August, pp. 121–135, 2016, doi: 10.1093/cybsec/tyw001.
- A. Altamimi, M. Al-Bashayreh, M. Al-Oudat, and D. Almajali, “Blockchain technology adoption for sustainable learning,” Int. J. Data Netw. Sci., vol. 6, no. 3, 2022, doi: 10.5267/j.ijdns.2022.1.013.
- I. Alhassan, D. Sammon, and M. Daly, “Critical success factors for data governance : a telecommunications case study,” J. Decis. Syst., vol. 28, no. 1, pp. 41–61, 2019, doi: 10.1080/12460125.2019.1633226.
- G. Iyawa and A. Gamundani, “Essential Components of an IT Risk Management Framework for the Financial Services Industry: A Review,” in Proceedings of International Conference on Information Systems and Emerging Technologies, 2023, 2023.
- ISACA, COBIT5: A Business Framework for the Governance and Management of Enterprise IT. 2012.
- NIST, Risk Management Framework for Information Systems and Organizations Risk Management Framework for Information Systems and Organizations. 2018.
- T. Tan and B. Soewito, “Implementing the NIST Cybersecurity Framework at ZXC University,” J. Inf. Syst. Applied, Manag. Account. Res., vol. 6, no. 2, pp. 411–422, 2022, doi: 10.52362/jisamar.v6i2.781.
- J. W. Creswell and J. D. Creswell, Research Design: Qualitative, Quantitative, and Mixed Methods Approaches, Sixth Edition. SAGE Publications Asia-Pacific Pte. Ltd., 2023. [Online]. Available: https://medium.com/@arifwicaksanaa/pengertian-use-case-a7e576e1b6bf
- K. Dan, A. Sheren, R. Sirait, A. S. Kamalia, A. Diska, and M. B. Legowo, “Cyber Attacks Using the NIST Risk Management Framework,” Pros. Sn. 2023, pp. 1–8, 2023.
- N. Nilamsari, “Understanding Document Analysis in Qualitative Research,” Wacana, vol. XIII, no. 2, pp. 177–181, 2014.
- T. Aven, “Risk assessment and risk management : Review of recent advances on their foundation,” Eur. J. Oper. Res., vol. 253, no. 1, pp. 1–13, 2016, doi: 10.1016/j.ejor.2015.12.023.
- M. B. Legowo, R. Desica, N. Rahsa, N. Batrisyia, and S. R. Julia, “Data Breach and Data Leak as a Threat in XYZ Bank : Risk Management Steps,” J. Business, Finance. Bank, vol. 2, no. 2, pp. 21–36, 2026.
- M. Sheleme and R. R. Sharma, “Cyber-attack and Measuring its Risk,” IRO J. Sustain. Wirel. Syst., vol. 3, no. 4, pp. 219–225, 2021.
- O. G. Khoirunnisa, “Implementasi Algoritma AES untuk Keamanan Data Rekam Medis,” PETIR J. Pengkaj. dan Penerapan Tek. Inform., vol. 15, no. 1, pp. 21–27, 2022.
- B. Stojanović and J. Boži´c, “Robust Financial Fraud Alerting System Based in the Cloud Environment,” Sensors-MDPI, vol. 22, no. 9461, 2022.
The rapid digitalization of business processes has heightened organizational vulnerability to cybersecurity
threats, particularly customer data breaches, unauthorized access, malware, phishing, and cyberattacks. These threats can
compromise sensitive information, disrupt operations, cause financial losses, and erode customer trust. This study aims to
examine the implementation of the National Institute of Standards and Technology (NIST) Risk Management Framework
(RMF) for mitigating customer data breaches and cybersecurity threats. A qualitative research approach is employed to
analyze cybersecurity risks, vulnerabilities, security controls, and risk mitigation practices in accordance with the NIST
RMF. The framework encompasses a systematic process for categorizing information systems, selecting and implementing
security controls, assessing control effectiveness, authorizing systems, and continuously monitoring risks. The results
indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks,
strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring.
The findings suggest that strengthening customer data protection requires a holistic approach integrating technological
safeguards, organizational governance, employee awareness, risk assessment, and effective incident response mechanisms.
This study contributes to the cybersecurity risk management literature by proposing a structured approach to
strengthening organizational resilience against customer data breaches and evolving cyber threats.
Keywords :
Banking; Cyber Threats; Data Breach; NIST RMF; Risk Management.