Data Breach and Data Leak as a Threat in XYZ Bank: Risk Management Steps
DOI:
https://doi.org/10.56174/jbfb.v2i2.1345Keywords:
Data Breach, Data Leak, Banking Industry, Risk Management, COBIT 5, Information Security.Abstract
The rapid digital transformation in the banking sector has significantly increased exposure to cybersecurity threats, particularly data breaches and data leak incidents. These threats may compromise the confidentiality, integrity, and availability of sensitive customer and organizational information, resulting in financial losses, reputational damage, and regulatory sanctions. This study aims to analyse the risks associated with data breaches and data leaks in Banking XYZ and propose appropriate risk management measures using the COBIT 5 framework, specifically the APO12 (Manage Risk) and DSS05 (Manage Security Services) domains. The research employs a qualitative descriptive approach using literature review and risk analysis based on COBIT 5 processes. The findings indicate that both Data Breach and Data Leak are categorized as high-risk threats due to their high likelihood and significant business impact. The APO12 domain facilitates systematic risk identification, assessment, evaluation, and monitoring, while DSS05 supports the implementation of operational security controls. Furthermore, the study highlights that security measures such as Multi-Factor Authentication (MFA), Data Loss Prevention (DLP), Security Information and Event Management (SIEM), and continuous security monitoring are essential to mitigate cybersecurity risks. The study concludes that the COBIT 5 framework provides an effective, structured approach to strengthening information security governance and enhancing cyber resilience in the banking industry.
Downloads
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Mercurius Broto Legowo, Rachel Desica Patricia, Nabilah Rahsa, Nurraimi Batrisyiad, Siti Rosmah Julia

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.








