
Open banking · 2 min readHFS Podcast | S. Mohsen Shahmoradi on open banking and the future of fintech in IranThe first episode of the Hamfekran Fanavari Sharif podcast. Listen to the full conversation right here.

Regulation & security · 2 min readPCI DSS v4: card data security in the digital payments eraAny organisation storing, processing or transmitting card data faces PCI DSS; v4 introduces a more flexible, risk-based approach.

Digital money · 2 min readCryptography in financial systems: from TLS to key management and HSMsStrong encryption only helps if keys are managed well; most failures stem from key handling, not algorithms.

Fintech · 2 min readIdentity and access management (IAM): least privilege in financial institutionsMost serious incidents begin with excessive access. IAM decides who can access what, for how long and at what level.

Regulation & security · 2 min readInformation security risk management: from assets to management decisionsAbsolute security does not exist; informed risk management targets security spending.

Fintech · 2 min readRed, blue and purple teams: testing defence through the attacker’s eyesDefences never tested against realistic attacks give no assurance; red–blue collaboration closes the gap.

Fintech · 2 min readDefence in depth: a layered strategy for financial systemsNo single control is perfect; independent layers stop one failure becoming a full breach.

Regulation & security · 2 min readRespected cybersecurity certifications: from CISSP to OSCPProfessional certifications are the global job market’s common language; knowing each one’s role helps choose well.

Fintech · 2 min readRansomware in finance: from encryption to double extortionRansomware has become an organised industry; preparation before an attack is the only way to limit damage.

Fintech · 2 min readInsider threats in financial institutionsSome of the most serious incidents come from people with legitimate access.

Fintech · 2 min readAccount takeover: the silent threat to digital bankingAccount takeover uses leaked passwords and deception and often goes unnoticed until funds move.

Regulation & security · 2 min readCyber attacks on banks: from messaging-network heists to stealthy intrusionsBanks are prime targets for organised attackers; known incidents reveal recurring patterns and lessons.

Regulation & security · 2 min readTypes of cyber attacks: a complete threat mapKnowing attack categories is the first step to effective defence.

Fintech · 2 min readProtecting customer personal data: privacy principles in financeFinancial data is among the most sensitive; privacy by design builds trust and lowers legal risk.

Fintech · 2 min readDDoS attacks: layered defence for financial servicesDDoS floods services offline; effective defence is layered and planned in advance.

Regulation & security · 2 min readSMS fraud and banking phishing: protecting usersFake summons, subsidy and gateway SMS are the most common card-theft methods in Iran.

Regulation & security · 2 min readSecure coding with the OWASP Top 10The OWASP Top 10 is the global reference for the most common web-application risks.

AI · 2 min readResponsible AI: transparency, fairness and accountability in automated decisionsAs more decisions move to algorithms, fairness and transparency matter more.

Fintech · 2 min readIncident response planning: the golden hours after an attackResponse quality in the first hours determines total damage; a prepared plan makes the difference.

Regulation & security · 2 min readSoftware supply-chain security: when threats come from librariesModern software relies on hundreds of open-source packages; one poisoned dependency can compromise everything.

Regulation & security · 2 min readMobile banking app security: threats and countermeasuresMobile apps are now the main banking channel — and an attractive target.

Fintech · 2 min readVulnerability and patch management: a race against timeThe window between disclosure and exploitation keeps shrinking; a disciplined patch process keeps you ahead.

Fintech · 2 min readMulti-factor authentication: the simplest, most effective defence layerMany breaches start with a stolen password. MFA blocks most of that path.

AI · 2 min readPersian natural language processing: opportunities and challenges for AILanguage models now understand and generate Persian text, but Persian’s particular features demand a localised approach.

Regulation & security · 2 min readISO 27001-based ISMS: an implementation roadmapISO 27001 provides a systematic framework for identifying risks, selecting controls and continually improving information security.

Regulation & security · 2 min readSecurity Operations Center (SOC): from event monitoring to intelligent threat responseThe SOC is the heart of cyber defence, where scattered data becomes meaningful alerts and alerts become rapid action.

AI · 2 min readProcess automation with RPA and AI: what to automate first?Not everything is worth automating. Repetitive, rule-based, error-prone tasks are the best start.

Fintech · 2 min readWhat is penetration testing and how often do financial firms need it?A pen test is a controlled attack that finds weaknesses before a real attacker does.

Regulation & security · 2 min readZero Trust: security architecture for the borderless organisationWith remote work and cloud services, “inside the network” no longer means “trusted”. Zero Trust evaluates every request.

AI · 2 min readAI assistants in the enterprise: from customer replies to document summariesLanguage models speed up repetitive text work — provided confidential data is controlled.

Fintech · 2 min readBackup and recovery: business continuity against ransomwareRansomware can lock all data in hours. Organisations with tested backups recover instead of paying.

Regulation & security · 2 min readSocial engineering: people are the weakest link in securityMost successful breaches start by deceiving an employee, not by breaking encryption. Training and process are the strongest defence.

Regulation & security · 2 min readCrypto and regulation: the Iranian policy approachFrom licensed mining to limits on domestic payments—an overview and what it means for businesses.

AI · 2 min readAI in credit scoring: a review of Iranian researchDomestic studies find machine-learning models outperform traditional scoring—given good data.

Payments · 2 min readSwift gpi: Tracking Cross-Border Payments Like a ParcelSince 2017 Swift gpi has let banks track international payments end to end, improving transparency of fees and timing.

Regulation & security · 2 min readThe FATF Travel Rule: Transparency for Crypto-Asset TransfersSince 2019 FATF has required virtual asset service providers to pass originator and beneficiary information with transfers.

Regulation & security · 2 min readZero Trust Architecture: NIST SP 800-207In zero trust, no user or device is trusted merely for being on the internal network; every access is authenticated and authorised.

Regulation & security · 2 min readISO/IEC 27001:2022: The Information Security Standard with 93 ControlsThe 2022 edition regrouped controls into organisational, people, physical and technological themes and added new controls for cloud and threat intelligence.

AI · 2 min readExplaining Loan Denials Even with Complex Algorithms: CFPB GuidanceIn 2022 the US CFPB said complex AI models do not exempt lenders from giving specific reasons for credit denials.

AI · 2 min readThe CJEU SCHUFA Ruling: An Automated Credit Score Is a “Decision”In December 2023 the EU Court of Justice ruled that automated credit scoring that plays a determining role in lending falls under GDPR Article 22.

AI · 2 min readThe EU AI Act: Credit Scoring as a “High-Risk” SystemRegulation 2024/1689, the world’s first comprehensive AI law, classifies creditworthiness assessment of individuals as high-risk with strict obligations.

Regulation & security · 2 min readNIST Cybersecurity Framework 2.0: Governance at the Heart of SecurityPublished in February 2024, CSF 2.0 adds “Govern” as a sixth core function and broadens the framework to all organisations.

AI · 2 min readISO/IEC 42001: Artificial Intelligence Management SystemsThe first international AI management system standard gives organisations a certifiable framework for responsible AI.

AI · 2 min readThe OECD AI Principles: The First Intergovernmental AI StandardAdopted in 2019 and updated in 2024, the OECD AI Principles set five values for trustworthy AI.

Regulation & security · 2 min readIOSCO Recommendations for Crypto Markets: Same Risk, Same RulesIn 2023 IOSCO published 18 recommendations for regulating crypto-asset markets, from conflicts of interest to custody of client assets.

Regulation & security · 2 min readPrinciples for Financial Market Infrastructures (PFMI)The CPMI-IOSCO principles set 24 principles for safe, efficient payment, clearing and settlement systems and 5 responsibilities for authorities.

Regulation & security · 2 min readBCBS 239: Data Quality as a Precondition for Sound Risk ManagementThe Basel Committee’s principles require banks to aggregate and report risk data quickly, accurately and completely, a lesson from 2008.

Regulation & security · 2 min readBasel Committee Principles for Operational ResilienceIn 2021 the Basel Committee published seven principles for bank operational resilience, from governance and mapping dependencies to resilient ICT.

Regulation & security · 2 min readEU Instant Payments Regulation: Euro Transfers in 10 SecondsRegulation 2024/886 requires euro instant transfers at no higher cost than standard ones, with payee verification before payment.

Regulation & security · 2 min readPCI DSS v4: Securing Payment Card DataThe PCI Security Standards Council’s version 4 emphasises multi-factor authentication, e-commerce page security and a more flexible approach.

Regulation & security · 2 min readCyber Risk: A Growing Threat to Financial Stability, Says the IMFThe IMF devoted a full chapter of its April 2024 Global Financial Stability Report to cyber risk.

Fintech · 2 min readThird-Party Risk and Cloud Services: The FSB ToolkitIn December 2023 the FSB published a toolkit for managing financial institutions’ reliance on third-party providers.

Regulation & security · 2 min readNew Technologies Against Money Laundering: The FATF ViewFATF examines how machine learning and data analytics can make AML more effective and less costly.

Regulation & security · 2 min readRegulators and Fintech: Sandboxes, Innovation Hubs and Proportionate RulesThe BIS Financial Stability Institute compares how authorities respond to fintech innovation.

AI · 2 min readCredit Decisions by Complex Algorithms: Customers Must Know WhyThe CFPB says complex models do not exempt lenders from explaining why credit was denied.

AI · 2 min readNIST AI Risk Management Framework: Practical Guidance for OrganisationsNIST’s voluntary framework helps organisations identify and manage AI risks.

Regulation & security · 2 min readBasel and Cryptoassets: How Much Capital Should Banks Hold?In December 2022 the Basel Committee published the global standard for banks’ cryptoasset exposures.

Regulation & security · 2 min readThe FATF Travel Rule: Transparency in Virtual Asset TransfersFATF requires virtual asset service providers to send originator and beneficiary information with each transfer.

AI · 2 min readAI in Financial Services: Findings of Cambridge’s 2026 Global ReportThe latest CCAF survey shows fintechs lead incumbents in advanced AI adoption, with agentic AI emerging as the next frontier.

Digital money · 2 min readPost-Quantum Cryptography: Preparing Finance for Quantum ComputersNIST published the first quantum-resistant cryptography standards, and the BIS has tested migrating financial systems to them.

Regulation & security · 2 min readMiCA: A Unified Crypto-Asset Framework for EuropeWith MiCA, the EU set common rules for issuing and servicing crypto-assets and stablecoins for the first time.

AI · 2 min readThe EU AI Act and Credit Scoring: High-Risk SystemsThe EU AI Act classifies creditworthiness assessment as high-risk and sets strict requirements.

Regulation & security · 2 min readDORA: Digital Operational Resilience for European FinanceSince January 2025, the EU’s DORA regulation requires financial entities to manage ICT risk in a coherent way.

AI · 2 min readGenerative AI in Finance: IMF Risk ConsiderationsThe IMF weighs the opportunities of generative AI for finance against the risks to manage before adoption.

Digital money · 2 min readStablecoins: Why the BIS Says They Are Not Sound MoneyThe BIS argues stablecoins fail the key tests of sound money and, without regulation, threaten financial stability.

Regulation & security · 2 min readAI-Driven Fraud and Deepfakes: A Threat to Financial TrustThe FSB warns AI-driven fraud and disinformation could erode trust and amplify market volatility.

AI · 2 min readSupTech: Technology in the Service of Financial SupervisionThe BIS Financial Stability Institute examines how supervisors use big data and generative AI.

AI · 2 min readAI in Lending and Credit Scoring: Opportunities and RisksThe FSB examines how machine learning sharpens credit assessment and which new vulnerabilities it brings to the financial system.

Regulation & security · 2 min readAI and Cybersecurity in the Financial SectorThe IMF warns the main AI risk is not new attacks but the speed and scale at which vulnerabilities are found and exploited.
همفکران فناوری شریف