Ahmed Younes: Strengthening Cybersecurity and Information Security in Financial Services

Combining engineering expertise, security leadership and business risk management to protect financial systems, data and customers.
A security incident rarely waits for a convenient moment. In financial and payment services, it can arrive when systems are carrying millions in transactions, customers are relying on them to work and senior leaders are asking one urgent question: what happens next? The pressure is high; the regulatory scrutiny is constant and the cost of getting a decision wrong can reach far beyond the IT team.
Ahmed Younes has built his career around answering that question before the pressure arrives.
As Head Information Security Expert in the financial and payment services sector, Ahmed’s remit covers the strategy, governance, architecture and operations that keep systems, data and customers protected. His route into security began on the engineering side rather than through compliance, and that background still forms the way he approaches the job. He wants to understand how a system genuinely works before deciding how to defend it.
That instinct became particularly important during his first serious incident. It gave him a lesson that stayed with him long after the incident itself was over: technology tends to fail predictably, while people can fail under pressure. When an organisation is dealing with a real security problem, preparation rather than brilliance often decides the outcome. The right plans, clear responsibilities and the ability to make decisions under pressure matter when there is little time to think.
His move from hands-on technical work into leadership brought another lesson. Technical knowledge could take him deep into a problem, yet leadership required something different. People had to understand the direction, trust the judgement behind it and choose to follow. Younes learned that influence matters far more than authority.
Then security entered the boardroom.
The challenge there was less about explaining how a threat worked and more about explaining why it mattered. Ahmed had to translate technical risk into the language of revenue, continuity and reputation. A security weakness could affect the ability to keep services running, protect customers and maintain confidence in the business.
That translation has defined his work ever since. His engineering roots keep him close to how systems actually operate, while his leadership experience helps him bring people into the decisions that protect them. For Ahmed, security is ultimately about being ready for the moment when technology, people and business pressure collide.
Below are the interview highlights:
What inspired you to build your career in cybersecurity, and what continues to drive your passion for protecting organizations in an increasingly digital world?
Two things drew me in. The first was the intellectual honesty of the discipline. In security you cannot pretend something works: an attacker either gets in or does not, and the evidence is unforgiving. The second is that the stakes are human.
When an organisation is breached, the consequences land on ordinary people, salaries delayed, personal records exposed, services suspended, and trust that took years to earn lost in an afternoon. What drives me today is not what started me. In the beginning it was the puzzle.
Now it is the responsibility: colleagues rely on our systems being available tomorrow morning, and customers trust us with information they cannot replace. That obligation keeps me in a permanent learning posture, because the adversary refuses to stand still and neither can the defender.
As the cybersecurity landscape continues to evolve, how has your leadership approach changed to address emerging threats, technologies, and business risks?
My approach has moved from control to enablement. Early in my career I measured success by how many risks I could block. Today I measure it by how much the business can safely attempt. Three changes made that real. I stopped presenting threat reports and started presenting risk decisions, each with a named owner, a cost and a deadline. I moved the security function upstream into architecture review and procurement, so that we shape systems rather than audit them after the fact.
And I began designing for assumed compromise, segmentation, least privilege and tested recovery, because prevention alone is a losing wager. The hardest adjustment was cultural: accepting that a risk knowingly accepted by an accountable executive is a legitimate business outcome, not a personal failure of the security team.
What emerging cybersecurity trends do you believe will have the greatest impact on digital businesses over the next five years?
Five stand out. Identity has become the primary attack surface, as most serious intrusions now begin with valid credentials rather than malware. Non-human and machine identities are multiplying faster than governance can follow, and agentic AI will accelerate that sharply.
Software supply chain risk continues to compound, because many organisations still cannot say precisely what code runs in production or where it originated. Post-quantum cryptography will shift from a research topic to a multi-year migration programme, driven by harvest-now-decrypt-later collection that is already taking place.
And regulation is converging across jurisdictions, turning security from a technical obligation into a board-level and legal one. The organisations that come through this well will treat all five as funded engineering programmes with dates attached, not as slides in a strategy deck.
How is your organization leveraging technologies such as AI, machine learning, automation, cloud security, zero-trust architecture, threat intelligence, or other advanced cybersecurity solutions to address real-world business challenges?
My bias is toward capability that survives contact with reality, and the most valuable work has been unglamorous. We apply machine learning primarily to detection triage, clustering and prioritising alerts to reduce analyst fatigue, rather than promising autonomous decision-making.
Our zero-trust programme is built around identity, device posture and segmentation, and I would argue the sequencing matters more than the label. Cloud security is handled as code, with policy guardrails enforced in the deployment pipeline so that misconfigurations are prevented at commit rather than discovered in an audit months later.
Threat intelligence only earns its cost once it is operationalised, so we map it to adversary techniques and convert it into detection rules with measured coverage. Automation now carries containment steps that once consumed an analyst’s evening.
What are the biggest challenges organizations face in protecting their digital infrastructure, data, and customers, and how have you addressed these challenges?
Visibility, identity sprawl and tempo. Most organisations cannot produce an accurate inventory of their assets, data and privileged access, and nothing can be defended that has never been enumerated. We addressed this by treating inventory as a permanent product with a named owner rather than a project with an end date.
The second challenge is that much of the attack surface now sits outside the organisation, in cloud platforms, suppliers and third-party code; we tightened that through tiered supplier assessment, contractual security requirements and continuous monitoring.
The third is speed: attackers move in hours while approval cycles take weeks. Our answer was pre-authorised response playbooks, with decisions taken in advance under calm conditions so responders can act without waiting for a meeting.
How do you balance strong cybersecurity protection with business agility, innovation, customer experience, and the need to adopt new digital technologies quickly?
By treating security as a design constraint rather than a gate. A gate creates an incentive to go around it; a constraint gets engineered into the product. In practice that means secure defaults and paved-road platforms, because when the easiest path to production is also the most secure one, most teams take it without being asked. It means risk-tiering, since a marketing microsite and a payment service should not carry the same review burden.
And it means my team owns its response times as a published commitment. When a security review takes a day or two instead of three weeks, people stop routing projects around us. Friction is not evidence of rigour; more often it is evidence of poor design on our side.
What role do collaboration, threat intelligence sharing, cybersecurity partnerships, research institutions, startups, and government organizations play in strengthening the overall security ecosystem?
It is decisive, because attackers already collaborate more effectively than defenders do. A technique used against one organisation in a sector tends to appear against its peers within weeks, and sharing indicators compresses the gap between discovery and defence.
I invest in sector forums, national response bodies and direct working relationships with peers, law enforcement and technology partners. Research institutions and startups matter for a different reason: they meet problems before the enterprise market does, and some of the most useful capabilities I have deployed came from early engagement with small teams.
Government partnership contributes what no private organisation can achieve alone, attribution, legal reach and coordinated disruption. The barrier to sharing is rarely technical. It is fear of reputational exposure, and that fear protects the attacker rather than the victim.
How do you build a strong cybersecurity culture within an organization and ensure that employees, leadership, and technology teams understand their role in managing cyber risk?
Culture is what people do when no policy covers the situation. Three things have worked. First, we stopped punishing reporting: anyone who reports a mistake, whether a clicked link or mishandled data, is thanked visibly for it. Fear of blame is the most reliable way to delay detection, and minutes matter.
Second, we replaced generic annual training with role-specific, short and frequent exposure, secure coding delivered inside the developer workflow, payment fraud simulations for finance, tabletop exercises for executives.
Third, leadership visibility: when senior management asks about security in ordinary operational reviews, the whole organisation recalibrates within a quarter. I also insist that security metrics are shared with business owners rather than held inside my team, because shared numbers create genuinely shared ownership.
Can you share a cybersecurity initiative, breakthrough, or achievement under your leadership that created a significant impact on your organization, customers, or the wider industry?
One of the achievements I am most proud of is leading a broad information security and compliance transformation programme within the financial and payment sector. The challenge was larger than obtaining individual certifications.
The organisation needed to bring security governance, cyber risk, regulatory compliance, business continuity, technical and physical security, and operational resilience into a single coordinated and sustainable model across multiple environments.
I led initiatives spanning PCI DSS, PCI PIN, PCI 3DS, PCI Card Production, ISO 27001, ISO 22301 and SOC 2, working across technology, operations, risk, compliance and business functions alongside external assessors and senior management. The work meant identifying control gaps, establishing clear ownership and accountability, strengthening technical and physical controls, improving vulnerability and evidence management, sharpening business continuity and incident readiness, and embedding security requirements into daily operations rather than treating compliance as an annual audit exercise.
We achieved and have since maintained multiple major certifications and attestations, supported by a stronger governance structure and a more proactive, risk-driven culture. Collecting certificates was never the objective. The real achievement was moving information security from a compliance obligation to a business capability that underpins trust, resilience, regulatory confidence and sustainable growth. I am now applying the same philosophy to AI governance.
With the rapid rise of generative AI and AI-powered cyberattacks, how do you see artificial intelligence changing both the cybersecurity threat landscape and the way organizations defend themselves?
AI has changed the economics on both sides. For the attacker the gain is scale and quality rather than novelty: phishing that is fluent in any language, faster reconnaissance, quicker exploit development, and synthetic voice and video that dismantle the old assumption that recognising someone proves who they are.
We have revised approval and verification procedures accordingly, because a convincing call from a familiar voice is no longer evidence of anything. For the defender, AI is genuinely useful in triage, correlation and summarisation, where the binding constraint has always been human attention rather than data.
The risk I watch most closely is the AI we deploy ourselves: models with access to sensitive data, agents holding credentials and integrations with standing permissions form a new attack surface that most governance frameworks have not yet caught up with.
What qualities, technical capabilities, and leadership skills do you believe are essential for the next generation of cybersecurity leaders?
Technically, fluency in identity, cloud architecture and data, because that is where modern risk concentrates, plus enough engineering skill to automate work rather than accumulate it. But technical depth alone stops a career at a certain ceiling.
The differentiators are commercial literacy, meaning the ability to read a profit and loss statement and argue for investment in terms an executive accepts; clear written communication, because most influence travels through documents rather than meetings; and composure, since a security leader is judged during an incident, not during a planning cycle.
I would add intellectual humility. This field punishes certainty. The strongest leaders I know actively look for evidence that their assumptions are wrong, and they build teams that feel safe enough to bring them that evidence directly.
Looking ahead, what is your vision for the future of cybersecurity and digital business, and what advice would you give to emerging cybersecurity professionals and leaders who want to shape a more secure digital future?
I expect security to become less visible and more embedded, enforced through platforms, pipelines and secure defaults rather than review boards, and measured as an engineering discipline in which resilience and recovery are taken as seriously as prevention. Digital business will keep accelerating, and the organisations that win will be those that made security a capability rather than a constraint.
To those beginning: build real depth in something specific before pursuing breadth, because certifications open doors while demonstrated work keeps them open. Learn how your organisation actually earns its money, as it will change every recommendation you make. Contribute back to the community that trained you. And protect your own sustainability, because burnout ends more security careers than any technical shortcoming. This is a long responsibility, not a sprint.
