Parsa Aghabarari

Parsa Aghabarari

Deputy of AI & Information Security — Hamfekran Fanavari Sharif
Computer Engineering Student
Personal blog → Instagram Virgool

Parsa Aghabarari, a computer engineering student, is Deputy of AI & Information Security at Hamfekran Fanavari Sharif, responsible for protecting the data and infrastructure of the company's financial platforms. He specialises in ethical hacking, penetration testing and defence against advanced threats: he finds and fixes weaknesses before attackers do. He holds the CISSP from ISC2, one of the most respected and demanding information-security credentials in the world. It requires several years of verified professional experience and passing a comprehensive exam across eight security domains, and banks and large enterprises treat it as a mark of senior-level security expertise. He also holds the CEH and CompTIA Security+ certifications. His work includes implementing an ISMS based on ISO/IEC 27001, running Security Operations Centre (SOC) work and hardening systems. He also designed and conceived the Hamfekran Fanavari Sharif website, writes software and has built platforms for petty-cash management, office automation and incident reporting.

Work experience

Education

Certifications & courses

Skills

Projects

Languages

Parsa Aghabarari's blog → (69 posts)

HFS Podcast | S. Mohsen Shahmoradi on open banking and the future of fintech in IranThe first episode of the Hamfekran Fanavari Sharif podcast. Listen to the full conversation right here.PCI DSS v4: card data security in the digital payments eraAny organisation storing, processing or transmitting card data faces PCI DSS; v4 introduces a more flexible, risk-based approach.Cryptography in financial systems: from TLS to key management and HSMsStrong encryption only helps if keys are managed well; most failures stem from key handling, not algorithms.Identity and access management (IAM): least privilege in financial institutionsMost serious incidents begin with excessive access. IAM decides who can access what, for how long and at what level.Information security risk management: from assets to management decisionsAbsolute security does not exist; informed risk management targets security spending.Red, blue and purple teams: testing defence through the attacker’s eyesDefences never tested against realistic attacks give no assurance; red–blue collaboration closes the gap.Defence in depth: a layered strategy for financial systemsNo single control is perfect; independent layers stop one failure becoming a full breach.Respected cybersecurity certifications: from CISSP to OSCPProfessional certifications are the global job market’s common language; knowing each one’s role helps choose well.Ransomware in finance: from encryption to double extortionRansomware has become an organised industry; preparation before an attack is the only way to limit damage.Insider threats in financial institutionsSome of the most serious incidents come from people with legitimate access.Account takeover: the silent threat to digital bankingAccount takeover uses leaked passwords and deception and often goes unnoticed until funds move.Cyber attacks on banks: from messaging-network heists to stealthy intrusionsBanks are prime targets for organised attackers; known incidents reveal recurring patterns and lessons.Types of cyber attacks: a complete threat mapKnowing attack categories is the first step to effective defence.Protecting customer personal data: privacy principles in financeFinancial data is among the most sensitive; privacy by design builds trust and lowers legal risk.DDoS attacks: layered defence for financial servicesDDoS floods services offline; effective defence is layered and planned in advance.SMS fraud and banking phishing: protecting usersFake summons, subsidy and gateway SMS are the most common card-theft methods in Iran.Secure coding with the OWASP Top 10The OWASP Top 10 is the global reference for the most common web-application risks.Responsible AI: transparency, fairness and accountability in automated decisionsAs more decisions move to algorithms, fairness and transparency matter more.Incident response planning: the golden hours after an attackResponse quality in the first hours determines total damage; a prepared plan makes the difference.Software supply-chain security: when threats come from librariesModern software relies on hundreds of open-source packages; one poisoned dependency can compromise everything.Mobile banking app security: threats and countermeasuresMobile apps are now the main banking channel — and an attractive target.Vulnerability and patch management: a race against timeThe window between disclosure and exploitation keeps shrinking; a disciplined patch process keeps you ahead.Multi-factor authentication: the simplest, most effective defence layerMany breaches start with a stolen password. MFA blocks most of that path.Persian natural language processing: opportunities and challenges for AILanguage models now understand and generate Persian text, but Persian’s particular features demand a localised approach.ISO 27001-based ISMS: an implementation roadmapISO 27001 provides a systematic framework for identifying risks, selecting controls and continually improving information security.Security Operations Center (SOC): from event monitoring to intelligent threat responseThe SOC is the heart of cyber defence, where scattered data becomes meaningful alerts and alerts become rapid action.Process automation with RPA and AI: what to automate first?Not everything is worth automating. Repetitive, rule-based, error-prone tasks are the best start.What is penetration testing and how often do financial firms need it?A pen test is a controlled attack that finds weaknesses before a real attacker does.Zero Trust: security architecture for the borderless organisationWith remote work and cloud services, “inside the network” no longer means “trusted”. Zero Trust evaluates every request.AI assistants in the enterprise: from customer replies to document summariesLanguage models speed up repetitive text work — provided confidential data is controlled.Backup and recovery: business continuity against ransomwareRansomware can lock all data in hours. Organisations with tested backups recover instead of paying.Social engineering: people are the weakest link in securityMost successful breaches start by deceiving an employee, not by breaking encryption. Training and process are the strongest defence.Crypto and regulation: the Iranian policy approachFrom licensed mining to limits on domestic payments—an overview and what it means for businesses.AI in credit scoring: a review of Iranian researchDomestic studies find machine-learning models outperform traditional scoring—given good data.Swift gpi: Tracking Cross-Border Payments Like a ParcelSince 2017 Swift gpi has let banks track international payments end to end, improving transparency of fees and timing.The FATF Travel Rule: Transparency for Crypto-Asset TransfersSince 2019 FATF has required virtual asset service providers to pass originator and beneficiary information with transfers.Zero Trust Architecture: NIST SP 800-207In zero trust, no user or device is trusted merely for being on the internal network; every access is authenticated and authorised.ISO/IEC 27001:2022: The Information Security Standard with 93 ControlsThe 2022 edition regrouped controls into organisational, people, physical and technological themes and added new controls for cloud and threat intelligence.Explaining Loan Denials Even with Complex Algorithms: CFPB GuidanceIn 2022 the US CFPB said complex AI models do not exempt lenders from giving specific reasons for credit denials.The CJEU SCHUFA Ruling: An Automated Credit Score Is a “Decision”In December 2023 the EU Court of Justice ruled that automated credit scoring that plays a determining role in lending falls under GDPR Article 22.The EU AI Act: Credit Scoring as a “High-Risk” SystemRegulation 2024/1689, the world’s first comprehensive AI law, classifies creditworthiness assessment of individuals as high-risk with strict obligations.NIST Cybersecurity Framework 2.0: Governance at the Heart of SecurityPublished in February 2024, CSF 2.0 adds “Govern” as a sixth core function and broadens the framework to all organisations.ISO/IEC 42001: Artificial Intelligence Management SystemsThe first international AI management system standard gives organisations a certifiable framework for responsible AI.The OECD AI Principles: The First Intergovernmental AI StandardAdopted in 2019 and updated in 2024, the OECD AI Principles set five values for trustworthy AI.IOSCO Recommendations for Crypto Markets: Same Risk, Same RulesIn 2023 IOSCO published 18 recommendations for regulating crypto-asset markets, from conflicts of interest to custody of client assets.Principles for Financial Market Infrastructures (PFMI)The CPMI-IOSCO principles set 24 principles for safe, efficient payment, clearing and settlement systems and 5 responsibilities for authorities.BCBS 239: Data Quality as a Precondition for Sound Risk ManagementThe Basel Committee’s principles require banks to aggregate and report risk data quickly, accurately and completely, a lesson from 2008.Basel Committee Principles for Operational ResilienceIn 2021 the Basel Committee published seven principles for bank operational resilience, from governance and mapping dependencies to resilient ICT.EU Instant Payments Regulation: Euro Transfers in 10 SecondsRegulation 2024/886 requires euro instant transfers at no higher cost than standard ones, with payee verification before payment.PCI DSS v4: Securing Payment Card DataThe PCI Security Standards Council’s version 4 emphasises multi-factor authentication, e-commerce page security and a more flexible approach.Cyber Risk: A Growing Threat to Financial Stability, Says the IMFThe IMF devoted a full chapter of its April 2024 Global Financial Stability Report to cyber risk.Third-Party Risk and Cloud Services: The FSB ToolkitIn December 2023 the FSB published a toolkit for managing financial institutions’ reliance on third-party providers.New Technologies Against Money Laundering: The FATF ViewFATF examines how machine learning and data analytics can make AML more effective and less costly.Regulators and Fintech: Sandboxes, Innovation Hubs and Proportionate RulesThe BIS Financial Stability Institute compares how authorities respond to fintech innovation.Credit Decisions by Complex Algorithms: Customers Must Know WhyThe CFPB says complex models do not exempt lenders from explaining why credit was denied.NIST AI Risk Management Framework: Practical Guidance for OrganisationsNIST’s voluntary framework helps organisations identify and manage AI risks.Basel and Cryptoassets: How Much Capital Should Banks Hold?In December 2022 the Basel Committee published the global standard for banks’ cryptoasset exposures.The FATF Travel Rule: Transparency in Virtual Asset TransfersFATF requires virtual asset service providers to send originator and beneficiary information with each transfer.AI in Financial Services: Findings of Cambridge’s 2026 Global ReportThe latest CCAF survey shows fintechs lead incumbents in advanced AI adoption, with agentic AI emerging as the next frontier.Post-Quantum Cryptography: Preparing Finance for Quantum ComputersNIST published the first quantum-resistant cryptography standards, and the BIS has tested migrating financial systems to them.MiCA: A Unified Crypto-Asset Framework for EuropeWith MiCA, the EU set common rules for issuing and servicing crypto-assets and stablecoins for the first time.The EU AI Act and Credit Scoring: High-Risk SystemsThe EU AI Act classifies creditworthiness assessment as high-risk and sets strict requirements.DORA: Digital Operational Resilience for European FinanceSince January 2025, the EU’s DORA regulation requires financial entities to manage ICT risk in a coherent way.Generative AI in Finance: IMF Risk ConsiderationsThe IMF weighs the opportunities of generative AI for finance against the risks to manage before adoption.Stablecoins: Why the BIS Says They Are Not Sound MoneyThe BIS argues stablecoins fail the key tests of sound money and, without regulation, threaten financial stability.AI-Driven Fraud and Deepfakes: A Threat to Financial TrustThe FSB warns AI-driven fraud and disinformation could erode trust and amplify market volatility.SupTech: Technology in the Service of Financial SupervisionThe BIS Financial Stability Institute examines how supervisors use big data and generative AI.AI in Lending and Credit Scoring: Opportunities and RisksThe FSB examines how machine learning sharpens credit assessment and which new vulnerabilities it brings to the financial system.AI and Cybersecurity in the Financial SectorThe IMF warns the main AI risk is not new attacks but the speed and scale at which vulnerabilities are found and exploited.

HFS team