Paramin Chuangmanee

“Technology alone isn’t enough, we need to improve the process and the people too”

“To make cybersecurity tools truly effective, we need mature processes and capable people who can operate, govern, monitor and continuously improve the technology. The real value of technology comes when people and processes are able to drive it efficiently.”

Paramin Chuangmanee is a seasoned cybersecurity expert and the Manager of the Thailand Banking Sector Computer Emergency Response Team (TB-CERT). In a recent interview with Bonik Barta, he discussed the deceptive accuracy of AI-driven phishing campaigns, why establishing proactive regional intelligence networks remains the ultimate defence against modern infrastructure attacks, and why financial institutions must proactively invest in cybersecurity tools and frameworks to mitigate the dual threats of Shadow AI and automated fraud. Interview conducted by Minhazul Abedin.

From your experience managing Thailand’s banking sector defences, what are the most critical and immediate lessons that Bangladesh’s financial institutions could adopt to counter modern infrastructure attacks?

For Thailand, we found that cyberattacks are now moving more towards cybercrime. And in Thailand, they have shifted to attacking the system by going directly after the end-user. They try to attack the bank customers, using phishing to trick the victims into transferring money and creating authorised fraud. To counter this, institutions need to have tools to closely monitor transactions and adopt Artificial Intelligence within the system.

There are immediate lessons that Bangladesh’s financial institutions and others could adopt. First, there should be a strong cybersecurity policy and regulatory direction from the central bank. A clear policy framework helps provide common security expectations, minimum requirements and guidance for the entire financial sector.

Second, we need to have an effective threat intelligence sharing mechanism. The banking sector is very large, with many banks participating, so we must have a protocol to share information together. When one bank is attacked, we can immediately share that data with the second and third banks. In the banking sector, we are not only protecting systems from hackers; we are also protecting customers from fraud.

And third, financial institutions should conduct regular cyber exercises. These exercises should simulate realistic attack scenarios, including phishing, fraud, ransomware, infrastructure compromise, and cross-bank incidents. The goal is to test whether the organisation can detect, respond, communicate, and recover quickly enough during a real attack.

Recently Bangladesh Bank is integrating anti-money laundering (AML) screening tools into its SWIFT infrastructure. From a central banking perspective, is this kind of technological upgrade enough, or do financial institutions need to rethink their entire cyber-risk framework?

From my perspective, I would say that the AML upgrade is very important, but it’s not enough. We need to focus on the broader cybersecurity framework and thoroughly apply a Zero Trust Architecture (ZTA) to the system. We also need to prepare for monitoring and continuous improvement. If we focus only on the technology, it cannot protect us — we need to improve the process and the people too.

Most importantly, technology alone cannot protect the organisation. To make cybersecurity tools truly effective, we need mature processes and capable people who can operate, govern, monitor and continuously improve the technology. The real value of technology comes when people and processes are able to drive it efficiently.

Central banks need to follow established cybersecurity frameworks — adopting the NIST framework for the banking sector and using a Zero Trust Architecture to implement it. It’s also important to understand that if we have only the tool, we cannot handle threats effectively. We must have the process and the people to support the technology.

Cybercriminals are increasingly targeting supply chains and third-party vendors to compromise major networks. How should financial institutions approach and mitigate these specific ecosystem vulnerabilities?

First of all, we need to treat the supply chain as an extension of the attack surface of the institution and the financial sector. To manage this, we need to implement a third-party risk management framework first, and then we need to set minimum controls for the supply chain and the vendors who work with the bank. We also need to apply Zero Trust principles and completely separate our network from the supplier’s network.

I highly recommend establishing a formal third-party management framework. We need to evaluate every vendor we choose as part of our attack surface, and we need to enforce a minimum policy for them to follow. If they want to connect with the banking network, or if they want to serve the bank, they must follow these minimum requirements.

Most importantly, financial institutions must maintain visibility and oversight of third-party risks. If a bank cannot control, monitor or enforce security requirements on a vendor, that vendor becomes a direct risk to the institution. Therefore, supply chain security should be managed as a continuous governance process, not just a one-time vendor approval activity.

Cybersecurity is often viewed as a compliance cost rather than a strategic asset. How can policymakers leverage minimum regulatory standards and risk management to force businesses to justify larger security budgets?

I think policymakers first need to mandate a baseline of standards and establish strict minimum requirements for cybersecurity. Cybersecurity is the ultimate foundation; when we choose not to invest, or if we fail to continue investing, we will inevitably face major disruptions.

To change the mindset, policymakers need to clearly define what constitutes critical infrastructure. Based on risk management, we then need to assess how cybersecurity problems directly impact business operations. By doing this, we can translate cybersecurity investment into a business opportunity, which makes it much easier to justify the budget.

Moreover, policymakers must define these minimum standards for critical infrastructure and banking. This provides organisations with a solid, justifiable reason to secure their investment. If policymakers can define and justify these baselines well, it makes it much easier for those who have to follow the policy.

Finally, the key is to shift the mindset from “cybersecurity as a cost” to “cyber resilience as protection for business operations and national economic stability”.

Cyber threats ignore national borders. How critical is regional cooperation within Asia, and where do you see immediate opportunities for Bangladesh to collaborate with countries like Thailand to secure the banking sector?

Collaboration is absolutely key because cybersecurity has no borders anymore. A hacker can target multiple systems globally and move from one country to another in a matter of minutes. Because of this, we need cross-border collaboration.

The first priority must be regional intelligence sharing — passing data about active hacker attacks from one country to another so we can prevent them rapidly. Now that we have AI technology allowing attackers to strike faster, our regional networks must collaborate and share data even faster than the attackers can move.

This is exactly where Bangladesh and Thailand can collaborate. We can scale up our defence protocols beyond single nations. Just as we share threat intelligence between domestic banks, we need a cross-border protocol so that if a bank in Thailand is struck, that threat intelligence is instantly shared with banks in Bangladesh to protect their customers. Furthermore, we should conduct joint regional cyber exercises, simulating cross-border attacks to ensure our collective response is fast and coordinated enough.

Ultimately, cooperation is not optional. It is a necessary part of modern banking cyber resilience. By sharing intelligence, building trusted protocols, and conducting joint exercises, Bangladesh and Thailand can strengthen collective defence and protect the financial sector more effectively.

Artificial intelligence is transforming cybersecurity. How are attackers already using AI, and what should organisations be doing differently to protect themselves?

Attackers are already using AI to accelerate reconnaissance, identify vulnerabilities, generate phishing content, automate social engineering, write or modify malicious code, and test systems much faster than before. This means the speed, scale and precision of cyberattacks are increasing.

Because attackers are using AI, organisations also need to adopt AI for defence. AI can support continuous monitoring, anomaly detection, fraud detection, threat intelligence analysis and faster identification of suspicious behaviour across networks, endpoints, applications and transactions. However, AI should not replace human security teams. It should help analysts work faster and make better decisions.

We also need to focus heavily on threat hunting. We need to apply a Zero Trust Architecture (ZTA) and adopt an “assume breach” mindset. We need to operate under the belief that attackers are already inside our network, and we must actively hunt for malware and hackers within the system right now.

In the AI era, attackers are becoming faster, so defenders must become faster too.

In recent times, many organisations have been encouraging their employees to use AI tools. What cybersecurity risks do these AI systems introduce, particularly when handling sensitive or confidential information?

First of all, the rapid adoption of AI has introduced a new risk to the world. Everyone is using AI tools now, but they often do not have enough literacy regarding the technology. They put private information, personal data and sometimes even the company’s secret information into the AI. That data can then be lost to another vendor, which is not good for the company.

While AI is very important, it has introduced a major risk when employees may accidentally upload personal data, customer information, internal documents, source code, banking transaction details or other confidential business information into public AI tools.

We also have the issue of Shadow AI; this happens when employees use unapproved AI tools without the organisation’s knowledge or security review. In the banking sector, this can create serious risks because sensitive customer data, financial information or internal operational details may be exposed outside approved security controls.

To manage this risk, organisations need a clear AI governance policy. The policy should define which AI tools are approved, what types of data can and cannot be used, who is allowed to use AI tools and what security controls must be applied. Employees also need AI literacy and security awareness training so they understand the risks before using these technologies.

I suggest we must implement true Data Loss Prevention (DLP) systems. We can define sensitive keywords or sensitive contexts — like customer databases or banking transactions — and ensure they are completely blocked from being uploaded to any public AI tool.

AI is very useful, but it must be adopted safely. For financial institutions, the key is to enable innovation while protecting sensitive data through clear policy, approved tools, employee awareness, DLP, access control and continuous monitoring.

People are using deepfakes and cloned voices to contact individuals and ask them for their security details. How concerned should financial regulators and businesses be, and what practical infrastructural safeguards do you recommend?

This is a very serious problem because we now see real cases happening in the world, including in Thailand. We have had real cases where hackers tried to use deepfakes and fake voices to call a parent to ask for money, but the scam failed because the child on the line didn’t know their own birthday. That is a very important point. We need to introduce secret fallback questions. We also need to educate people to recognise these tricks. We also must report this problem immediately by calling the bank.

Financial institutions need to continually invest in fraud detection and deepfake detection capabilities. Systems should be able to identify abnormal customer behaviour, unusual transaction patterns, suspicious device activity, changes in login behaviour, and possible voice or video manipulation. Where possible, banks should compare current interactions with historical customer patterns to detect inconsistencies.

Public awareness is also critical. Customers need to understand that even a familiar voice or face may be fake. If they receive a suspicious call asking for money, credentials, OTPs or security details, they should stop, verify through an official channel, and report the incident to the bank immediately.

Overall, regulators and businesses should treat deepfake-enabled fraud as a serious financial crime risk. The response must combine stronger customer verification, fraud analytics, deepfake detection, customer education, secure reporting channels and rapid response procedures.

Phishing attacks have become far more sophisticated. What warning signs should ordinary users watch for, especially when scams are increasingly personalised through AI?

Think of it like traditional fishing — if someone finds an area where they get a lot of fish, they will keep coming back. With AI, phishing has become much more precise. When dealing with AI phishing, we need to be very aware of the new warning signs.

Ordinary users should watch for three major warning signs.

First, look at the context and urgency. Most phishing attempts try to pressure the victim into acting quickly, such as by saying that an account will be suspended, a payment must be corrected or immediate verification is required. This sense of urgency is one of the strongest warning signs.

Second, verify the sender carefully. Even if the message looks professional, users should check whether the email address, phone number, domain name or sender profile is legitimate. If the sender is unknown or slightly different from the official source, users should not click any links or open attachments.

Third, be careful with requests for sensitive information or financial action. Any message asking for passwords, OTPs, banking details, money transfers or account verification should be treated with caution.

If there is any doubt, users should stop and confirm through an official channel, such as calling the organisation directly using a trusted phone number.

With AI-driven phishing, we can no longer rely only on grammar mistakes as a warning sign. The safest habit is to slow down, verify the sender, avoid clicking suspicious links and confirm important requests through official channels before taking action.

Many people assume that using a strong password is enough for their own personal cybersecurity. But in the context of 2026, what are the three most important cybersecurity habits every Internet user should adopt?

Many people still believe that a strong password is enough, but in 2026 passwords alone are no longer sufficient. Passwords can be leaked, reused, phished or cracked through automated tools.

The first thing I suggest is to implement multi-factor authentication (MFA). We cannot trust passwords anymore because we now have supercomputers that are so fast they can crack passwords in a second. That is why we need to have multi-factor authentication combined with risk-based management.

Second, every single password needs to be unique. We need to use a password vault that can generate and save unique, strong passwords. We then only need a single master key to decrypt all of those passwords.

And third, users need to be highly aware of phishing and fraud, because you simply cannot trust anything blindly anymore. You have to be aware that AI technology can be used to trick you into becoming a victim. You always need to remain vigilant and verify everything.

If you were advising the Government of Bangladesh today, what would be your top cybersecurity priorities for the banking sector over the next five years?

If I were advising the government of Bangladesh, my top cybersecurity priorities for the banking sector over the next five years would be cyber resilience, critical infrastructure protection and talent development.

My first priority would be to focus heavily on cyber resilience. We are under constant attack, so the mindset must shift from purely trying to stop incidents to ensuring we can withstand them when they happen. Cyber resilience means hardening your infrastructure so that even under a major attack, the institution stays alive and can continue providing critical services to its customers.

Second, we must strengthen our broader critical national infrastructure, because the banking sector cannot operate in isolation. We rely completely on ecosystem partners in sectors like telecommunications and energy. If the energy grid or telecom networks are attacked and go down, it directly impacts banking operations too. For instance, if a customer wants to use mobile banking but there is no cellular internet signal, the system becomes useless. We must secure these interdependencies together.

Third, we need systemic talent development. Right now, there is a global shortage of cybersecurity expertise. We must establish structured training programmes to develop professionals who understand both technical security and the complexity of financial systems, payment infrastructure, and core banking operations. Building this specialised talent pool is vital for long-term security.

Finally, the banking sector’s cybersecurity strategy should not focus only on technology. It should build long-term resilience by protecting critical infrastructure, developing skilled people and ensuring that banks can continue operating securely even under attack.

আরও