• Svitlana Yehorycheva National University “Yuri Kondratyuk Poltava Polytechnic”
  • Svitlana Onyshchenko National University “Yuri Kondratyuk Poltava Polytechnic”
Keywords: information risks, information security, financial security, banks, threats, risk management


The purpose of the article is to deepen scientific approaches to information risk management to increase the level of financial security of banking institutions. The relevance of the topic is due to the fact that the gradual digitization of society means not only positive consequences for economic development, but also is associated with the increase of risks, which is mostly found in the banking sector, where they can cause significant damage to the banks’ financial security. The latter is understood as the protection of the bank’s financial interests; sufficiency of financial resources to achieve defined goals; ensuring financial stability, efficient operation and stable development; the ability to resist negative influences (threats). Information risks are a component of operational risks and can be analyzed and assessed using qualitative and quantitative methods. The article identifies problems related to the quantitative assessment of information risks due to the dynamism of the bank’s information environment and the complexity of collecting data. Identification of information assets is recommended to be carried out with reference to the bank’s business processes. The article provides a description of threats to the bank’s information security, based on the approach of Basel Committee. Among the vulnerabilities of individual information assets, two groups are distinguished, which differ in the mechanism of collecting information about them: those inherent in software and hardware, and those characteristic of business processes and the sphere of control. Among the methods of minimization information risks – acceptance, avoidance, limitation and transfer, special attention is paid to such a method as reducing them due to the improvement of internal control methods. The role of corporate governance in this process is emphasized. The considered methods make it possible to assess the current state of information security of banking institutions, reduce potential losses, and propose a mechanism of protection against identified threats, which will contribute to strengthening the financial security of banks.


Baranovskyi O., & Lahno A. (2022) Pryroda finansovoi bezpeky bankivskoi systemy [The nature of financial security of the banking system]. Svit finansiv – The world of finance, no. 3(72), pp. 141-155. (in Ukrainian)

Fedorushchenko B., & Baranovskyi O. (2021) Formuvannia systemy zabezpechennia finansovoi bezpeky bankivskoho sektoru [Formation of the system of ensuring financial security of the banking sector]. Finansovo-kredytna diialnist: problemy teorii i praktyky – Financial and credit activity: problems of theory and practice, no 5(40), pp. 16-27. (in Ukrainian)

Karcheva H., & Karcheva I. (2022) Teoretychni ta praktychni aspekty upravlinnia finansovo-ekonomichnoiu bezpekoiu bankiv [Theoretical and practical aspects of managing the financial and economic security of banks]. Ekonomichnyi analiz – Economic analysis, vol. 32, no.1, pp. 168-198. (in Ukrainian)

Kovalenko V. (2022) Finansova bezpeka bankiv: realii ta perspektyvy zabezpechennia [Financial security of banks: realities and prospects of provision]. Ekonomichnyi forum – Economic Forum, no. (2), pp. 141-151. (in Ukrainian)

Kovalenko V. (2022) Finansova bezpeka bankiv v umovakh voiennoho stanu [Financial security of banks under martial law]. Finansovyi prostir – Financial space, no. 4(48), pp. 81-93. URL: (in Ukrainian)

Onyshchenko V., Yehorycheva S., Maslii O., & Yurkiv N. (2020) Impact of Innovation and Digital Technologies on the Financial Security of the State. In: Proceedings of the 3rd International Conference on Building Innovations. ICBI 2020. Lecture Notes in Civil Engineering, vol 181, pp. 749-759.

Bozhenko V. V., Pakhnenko O. V., & Koibichuk V. V. (2023) Dosvid YeS shchodo rozrobky ta vprovadzhennia natsionalnoi stratehii kiberstiikosti finansovoho sektora [The experience of the EU regarding the development and implementation of the national strategy of cyber resilience of the financial sector]. Tsyfrova ekonomika ta ekonomichna bezpeka – Digital economy and economic security, no. 8, pp. 125-129. (in Ukrainian)

Dyba M., Zubok M., & Yaremenko S. (2007) Informatsiini ryzyky u bankivskii diialnosti [Information risks in banking]. Visnyk Natsionalnoho banku Ukrainy – Bulletin of the National Bank of Ukraine, no. 9, pp. 28-35. (in Ukrainian)

Yermoshyn V. V., & Nevoit Ya. V. (2014) Analiz i otsinka ryzykiv informatsiinoi bezpeky dlia bankivskykh ta komertsiinykh system [Analysis and assessment of information security risks for banking and commercial systems]. Suchasnyi zakhyst informatsii – Modern information protection, no. 3, pp. 26-29. (in Ukrainian)

Kuznietsova N. V. (2014) Deiaki aspekty minimizatsii informatsiinykh ryzykiv u bankivskoi diialnosti [Some aspects of minimizing information risks in banking]. Systemni doslidzhennia ta informatsiini tekhnolohii – System research and information technologies, no. 1, pp. 7-19. (in Ukrainian)

Kravchenko A.M., Oriekhov A.A., & Harkunov A.H. (2013) Osoblyvosti zakhystu informatsiinykh system u bankivskykh ustanovakh [Peculiarities of protection of information systems in banking institutions]. Suchasnyi zakhyst informatsii – Modern information protection, no. 2, pp. 53-55. (in Ukrainian)

Domariev D. V., & Domariev V. V. (2013) Metodyka upravlinnia informatsiinoiu bezpekoiu v bankivskykh ustanovakh za dopomohoiu SUIB «Matrytsia» [Methodology of information security management in banking institutions with the help of SUIB “Matrytsia”]. Bezpeka informatsii – Information security, vol. 19, no. 1, pp. 60-70. (in Ukrainian)

Kibalnyk L. O., & Napora I. Yu. (2016) Kontseptualnyi pidkhid do formuvannia informatsiinoi bezpeky bankivskykh ustanov v systemi ekonomichnoi bezpeky [A conceptual approach to the formation of information security of banking institutions in the system of economic security]. Efektyvna ekonomika – Efficient economy, no. 12. URL: ?op=1&z=5303. (in Ukrainian)

Kibalnyk L. O., & Napora I. Yu. (2016) Vprovadzhennia polityky informatsiinoi bezpeky bankivskykh ustanov [Implementation of the information security policy of banking institutions]. Prychornomorski ekonomichni studii – Black Sea Economic Studies, vol. 12-2, pp. 119-122. (in Ukrainian)

Akhramovych V. M., & Chehrenets V. M. (2019) Upravlinnia ryzykamy informatsiinoi bezpeky komertsiinoho banku [Information security risk management of a commercial bank]. Suchasnyi zakhyst informatsii – Modern information protection, no. 2(38), pp. 54-59. (in Ukrainian)

Hladkykh D. M. (2019) Bankivska bezpeka derzhavy v umovakh rozvytku informatsiinoi ekonomiky (transformatsii bankivskykh operatsii) [Banking security of the state in the conditions of the development of the information economy (transformation of banking operations)]. Kyiv : NUOU. (in Ukrainian)

Basel Committee on Banking Supervision. The Basel Framework. 2023. URL:

Natsionalnyi bank Ukrainy (2018). Polozhennia pro orhanizatsiiu systemy upravlinnia ryzykamy v bankakh Ukrainy ta bankivskykh hrupakh [Regulations on the organization of the risk management system in Ukrainian banks and banking groups]. URL: (in Ukrainian)

Natsionalnyi bank Ukrainy (2021). Polozhennia pro zdiisnennia kontroliu za dotrymanniam bankamy vymoh zakonodavstva z pytan informatsiinoi bezpeky, kiberzakhystu ta elektronnykh dovirchykh posluh [Regulations on monitoring compliance by banks with the requirements of legislation on information security, cyber protection and electronic trust services]. URL: (in Ukrainian)

Average cost of a data breach worldwide from May 2020 to March 2023, by industry. Statista. URL:

Natsionalnyi bank Ukrainy (2017). Polozhennia pro orhanizatsiiu zakhodiv iz zabezpechennia informatsiinoi bezpeky v bankivskii systemi Ukrainy [Regulations on the organization of measures to ensure information security in the banking system of Ukraine] URL: (in Ukrainian)

Stoneburner G., Goguen A., & Feringa A. (2002) Risk Management Guide for Information Technology Systems. Recommendations of the National Institute of Standards and Technology. NIST Special Publication 800-30.

National Cyber Security Centre. Risk management (2023) A basic risk assessment and management method. URL: risk-management/a-basic-risk-assessment-and-management-method.

Information Systems Audit and Control Association (2012) COBIT 5: A Business Framework for the Governance and Management of Enterprise IT. ISACA.

How to Cite
Yehorycheva, S., & Onyshchenko, S. (2023). MANAGEMENT OF BANKS’ INFORMATION RISKS AS A CONDITION FOR STRENGTHENING THEIR FINANCIAL SECURITY. Digital Есопоmу and Economic Security, (8 (08), 224-231.