NIST-Based Cybersecurity Risk Management for Mitigating Customer Data Breaches and Cyber Threats in Banking
The rapid digitalization of business processes has heightened organizational vulnerability to cybersecurity threats, particularly customer data breaches, unauthorized access, malware, phishing, and cyberattacks. These threats can compromise sensitive information, disrupt operations, cause financial losses, and erode customer trust. This study aims to examine the implementation of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) for mitigating customer data breaches and cybersecurity threats. A qualitative research approach is employed to analyze cybersecurity risks, vulnerabilities, security controls, and risk mitigation practices in accordance with the NIST RMF. The framework encompasses a systematic process for categorizing information systems, selecting and implementing security controls, assessing control effectiveness, authorizing systems, and continuously monitoring risks. The results indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks, strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring. The findings suggest that strengthening customer data protection requires a holistic approach integrating technological safeguards, organizational governance, employee awareness, risk assessment, and effective incident response mechanisms. This study contributes to the cybersecurity risk management literature by proposing a structured approach to strengthening organizational resilience against customer data breaches and evolving cyber threats.