Santander aims to guarantee the security of both our customers and society in general in the online world 🔐.
Cybercrime is a globally expanding business, so the threats are constantly growing. We are committed to maintaining effective security through state-of-the-art security infrastructure, always seeking a balance between the robustness of our systems and the best customer experience across all our channels.
To support all these activities, the Santander Fusion Center brings together our security operations center and our monitoring capabilities to protect Santander 24/7 worldwide. Our cyber defence approach is based on a model consisting of various towers or defensive walls: Protect, Detect, Respond and Fraud Prevention.
Global Cybersecurity Towers
The Protect tower is responsible for preventing cyber attacks and protecting the information of both Santander and its customers. It includes elements such as firewalls, anti-virus software, email web filters and privileged access management.
The Detect tower monitors and identifies anomalous or malicious activities as early as possible, contributing to ensure comprehensive defence.
The Respond tower investigates and responds to cyber attacks in order to limit their impact. We use different forms of intelligence and track different threats to minimise any risk. Our intelligence and monitoring sources include the dark web and joint work with law enforcement agencies.
Finally, to deal with this ever-growing threat we believe it is essential to have advanced and harmonised Fraud Prevention capabilities across the Group. This includes expanding best practices, establishing common solutions and adapting quickly to new global threats and trends. This is the role of the Fraud Prevention Tower, which aims to reduce fraud losses and enhance customer satisfaction and awareness.
Continuous learning
We are conscious of the constant evolution of cyber threats and sophisticated attack techniques, which is why we are committed to continuous training and development.
As part of our talent management strategy, we organise regular cybersecurity bootcamps and constantly encourage upskilling and reskilling of our employees in cybersecurity. We invite experts and industry leaders to deliver workshops and interactive sessions, allowing the participants to learn and gain hands-on experience.
These activities provide opportunities for knowledge exchange between different areas and departments, fostering diversity of thought and innovation.
In addition, we work closely with Metared and prestigious universities around the world to organise Capture the Flag (CTF) challenges. We also share our knowledge and expertise through talks at universities and visits to our renowned Fusion Centre, which provides cybersecurity training and educational experiences for a range of academic institutions and professional development centres.
Investment in hyper-specialisation
Finally, we invest in companies to drive technology and innovation in the field of cybersecurity as a key part of our mission to create added value for society and build trust, thereby helping to create a safer ecosystem.
In 2022, Santander and Forgepoint Capital, a leading venture capital firm specialising in cybersecurity, announced a strategic alliance to drive investment and innovation in cybersecurity in Europe and Latin America.
Strategic partnerships like these allow us to offer a wide range of services and maintain a safe and trustworthy environment for our customers and society in general.
Cyber TechStack
Our cybersecurity team relies on cutting-edge technology to strengthen our defences against the ever-evolving threat landscape and provide global cybersecurity services.
These include protection domains (network security, cloud security, anti-malware, workplace and IAM), detection (security event monitoring, attack surface management, cyber threat surveillance), fraud prevention and response (cyber threat intelligence, cyber preparedness, CERT).
We use a wide range of world-class technology solutions based on a multi-layered architecture that allows intelligence to be shared between different components.