News

Bank Cybersecurity in 2026: 12 Protection Layers for the Financial Sector of the Caucasus and Central Asia

News | 29.07.2026

The financial sector of the Caucasus and Central Asia is digitalising faster than any other industry in the region: mobile banking, QR payments and fintech ecosystems have become the norm, while the Central Bank of Azerbaijan is completing its Financial Markets Cybersecurity Strategy 2023–2026 and building a national SOC. The flip side: every new digital channel is a new attack surface, and fraud is migrating from branches to customers' smartphones. Softprom — a value-added IT distributor since 1999, operating in 33 countries including Armenia, Azerbaijan, Kazakhstan and Uzbekistan — has broken digital bank protection down into 12 layers and covered each with solutions from its portfolio of 90+ cybersecurity vendors.

An anti-fraud system analyses user behaviour (interaction biometrics, session patterns) in real time and stops a fraudulent transaction before it executes — instead of investigating afterwards.

Twelve Protection Layers of a Digital Bank

All solutions are available in Armenia, Azerbaijan, Kazakhstan and Uzbekistan; exceptions are footnoted. Vendors in each row are listed alphabetically.

Digital bank risk / what happens Solutions from the Softprom portfolio

Fraud in channels
social engineering, account takeover

Google Cloud (fraud detection), ThreatMark (behavioural anti-fraud)

Weak authentication
SMS interception, OTP phishing

CyberArk, OneSpan (transaction signing), ProID (MFA), Syteca

Mobile app protection
vulnerabilities in the bank's code

Aikido Security, GitLab (DevSecOps), ImmuniWeb, Veracode

Online channel protection
DDoS, bots, API attacks

Akamai¹, Barracuda, Cloudflare, Radware³, Thales (Imperva), TR7

Phishing under the bank's brand
fake sites, clone domains

BrandShield, Red Sift (DMARC), ZeroFox

Credential leaks
the bank's access for sale on the dark web

HackNotice, KELA

Data compromise
leak of customers' personal data

Forcepoint (DLP), Fortanix, Infognito, Seclore⁴, Thales (encryption, HSM)

Insider risk
an employee with access to accounts

Forcepoint, Syteca, Teramind

Privileged access
the administrator = the biggest risk

CyberArk, Ivanti, Segura (PAM)

Channel trust
forged certificates

DigiCert (PKI and digital certificates)

Invisible vulnerabilities
shadow assets, outdated services

Bugcrowd (crowdsourced pentesting), Cymulate, Rapid7, RedSeal

SOC and response
seeing the attack in real time

Google SecOps, Intezer (autonomous SOC), Logsign, NetWitness, Rapid7 MDR, SecureGate, Stellar Cyber

Additionally (alphabetically): Acalvio / Deceptive Bytes — deception technologies; CrowdStrike / ESET² — endpoint protection; CybeReady — staff training; Menlo Security — browser isolation for tellers; Vanta — regulatory compliance automation.

¹ Akamai — Azerbaijan, Kazakhstan. ² ESET — Armenia, Kazakhstan, Uzbekistan. ³ Radware — Azerbaijan. ⁴ Seclore — Azerbaijan, Kazakhstan, Uzbekistan.

Why the Regulator Is Your Ally

The Central Bank of Azerbaijan's strategy and the cyber resilience requirements of the national banks of Kazakhstan and Uzbekistan are not bureaucracy — they are a ready-made business case for the CISO: a security budget is easier to defend when it maps to a regulatory requirement. Softprom helps partners build that mapping during pre-sales.

Where a Bank Should Start

  1. An attack surface assessment of digital channels (Rapid7) — 2–3 weeks.
  2. A behavioural anti-fraud pilot (ThreatMark) on real traffic.
  3. A privileged access audit (Segura) — the fastest quick win for a regulator's audit.

FAQ

Behavioural anti-fraud: it spots fraud within the session before the transaction, with no friction for the customer.

No, they work together: OneSpan confirms identity, ThreatMark watches behaviour throughout the session.

SOC development, incident response and financial market cyber resilience; solutions are mapped to these requirements in Softprom pre-sales.

Encryption and centralised key management (Fortanix, Thales HSM) plus privileged session control (Segura).

Yes: the same 12 layers scale from a neobank to a processing centre; local teams operate in all four countries.