<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>rsa &#8211; Finance Colombia</title>
	<atom:link href="https://www.financecolombia.com/tag/rsa/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.financecolombia.com</link>
	<description>Connecting Colombia to the global capital markets, analysts, economists, investors, and executives that matter</description>
	<lastBuildDate>Mon, 23 Dec 2019 21:50:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.financecolombia.com/wp-content/uploads/2016/01/cropped-Favicon-32x32.png</url>
	<title>rsa &#8211; Finance Colombia</title>
	<link>https://www.financecolombia.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Kennedys Law Opens Office in Bogotá to Practice Insurance Law</title>
		<link>https://www.financecolombia.com/kennedys-law-bogota-colombia/</link>
		
		<dc:creator><![CDATA[Jared Wade]]></dc:creator>
		<pubDate>Tue, 02 Aug 2016 18:19:52 +0000</pubDate>
				<category><![CDATA[BFSI - Financial Services]]></category>
		<category><![CDATA[Law, Justice & Peace]]></category>
		<category><![CDATA[Alex Guillamont]]></category>
		<category><![CDATA[Andrea Londoño Agudelo]]></category>
		<category><![CDATA[DLA Piper]]></category>
		<category><![CDATA[Kennedys Law]]></category>
		<category><![CDATA[Mónica Tocarruncho Mantilla]]></category>
		<category><![CDATA[Nick Thomas]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[suramericana]]></category>
		<guid isPermaLink="false">https://www.financecolombia.com/?p=8156</guid>

					<description><![CDATA[The move into Colombia is part of Kennedy's larger push into Latin America, and its Bogotá practice will focus on claims, coverage, and corporate law for the insurance world....]]></description>
										<content:encoded><![CDATA[<p><a href="https://www.kennedyslaw.com/">Kennedys Law</a> has been making a big push into Latin America this year and has now added Colombia to its list of new locations. While the London-based firm had maintained an associate office in Bogotá previously, Kennedys&#8217; new, larger location represents its desire to div further into the insurance law market in the capital.</p>
<p>The practice will focus on claims, coverage, and corporate law for the insurance world. &#8220;The Colombian insurance market has become a more attractive prospect since new legislation opened it up to foreign insurers in 2013,&#8221; said Alex Guillamont, head of the firm&#8217;s Latin American and Caribbean practice.</p>
<p>The Bogotá office of Kennedys Law will be led by Mónica Tocarruncho Mantilla and Andrea Londoño Agudelo, both of whom have significant experience in the nation&#8217;s insurance sector. &#8220;In Mónica and Andrea we have recruited two of the best insurance lawyers in Colombia to set up what I am sure will quickly become one of the leading specialist practices in the country,&#8221; said Guillamont.</p>
<p>Before joining Kennedys Law, Tocarruncho was general counsel at <a href="https://www.rsaseguros.com.co/">Royal and Sun Alliance Colombia</a> (RSA), where she oversaw the firm&#8217;s local acquisition by <a href="https://www.sura.com/">Suramericana</a>. Londoño previously served as the head of <a href="https://www.dlapiper.com/en/us/globalreach/global/latin-america/colombia/">DLA Piper Martínez Neira&#8217;s</a> Colombian insurance law practice. She has also worked with insurance broker giant Aon in London.</p>
<p>In addition to its Bogotá office, the company also announced an expansion in Chile. “These latest office openings further reinforce our strategy to establish a presence in key Latin American jurisdictions,&#8221; said Nick Thomas, senior partner at Kennedys Law. &#8220;They complement our well-established Latin America hub in Miami by providing on-the-ground expertise.&#8221;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Opinion: What to Expect In Enterprise Security For 2016</title>
		<link>https://www.financecolombia.com/opinion-what-to-expect-in-enterprise-security-for-2016/</link>
		
		<dc:creator><![CDATA[Amit Yoran]]></dc:creator>
		<pubDate>Tue, 22 Dec 2015 18:29:22 +0000</pubDate>
				<category><![CDATA[OpEd, Expert, or Guest Contribution]]></category>
		<category><![CDATA[amit yoran]]></category>
		<category><![CDATA[emc]]></category>
		<category><![CDATA[predictions]]></category>
		<category><![CDATA[rsa]]></category>
		<guid isPermaLink="false">https://www.financecolombia.com/?p=6604</guid>

					<description><![CDATA[2015 was most notably characterized by security vendors claiming to be able to prevent advanced threat breaches when the reality is, they can’t.  It was characterized by enterprises recognizing the need to monitor and defend their digital environments differently, but continuing to center their secu...]]></description>
										<content:encoded><![CDATA[<p>2015 was most notably characterized by security vendors claiming to be able to prevent advanced threat breaches when the reality is, they can’t.  It was characterized by enterprises recognizing the need to monitor and defend their digital environments differently, but continuing to center their security programs on the same technologies and approaches they have been using – hoping for a different outcome, but not acting differently.</p>
<p>2015 saw threats continuing to evolve faster than most organizations’ ability to detect and respond to them. What was considered an “advanced” threat in years past has become a commodity today with sophisticated malware and exploits available for the price of a movie ticket.  As troublesome as these observations seem, the most impactful evolution goes almost entirely unreported and misunderstood.  The threats that matter most, today’s pervasive threat actors execute attack campaigns comprised of multiple compromise methods and multiple backdoors to assure persistence. Incomplete incident scoping has become a critical failure point.</p>
<p>We’re starting to see progress in some areas as security investments begin to shift from a maniacal focus on prevention, toward greater balance on monitoring, detection, and response capabilities.  It’s become cliché to say that breaches are inevitable and that faster detection and more accurate incident scoping is the way forward, but too many organizations are trying to do these very different tasks using the technologies and processes they have on hand…not designed nor capable of answering their need. Here are some of the emerging trends that our industry and organizations need to be ready for in 2016:</p>
<div id="attachment_6603" style="width: 530px" class="wp-caption alignright"><a href="https://www.financecolombia.com/wp-content/uploads/2015/12/AmitYoran2.jpg" rel="attachment wp-att-6603"><img fetchpriority="high" decoding="async" aria-describedby="caption-attachment-6603" class="size-full wp-image-6603" src="https://www.financecolombia.com/wp-content/uploads/2015/12/AmitYoran2.jpg" alt="RSA's Amit Yoran says: &quot;Foolish investments have been made in strategies and technologies that are little more than snake oil.&quot;" width="520" height="520" srcset="https://www.financecolombia.com/wp-content/uploads/2015/12/AmitYoran2.jpg 520w, https://www.financecolombia.com/wp-content/uploads/2015/12/AmitYoran2-480x480.jpg 480w, https://www.financecolombia.com/wp-content/uploads/2015/12/AmitYoran2-250x250.jpg 250w, https://www.financecolombia.com/wp-content/uploads/2015/12/AmitYoran2-150x150.jpg 150w, https://www.financecolombia.com/wp-content/uploads/2015/12/AmitYoran2-300x300.jpg 300w" sizes="(max-width: 520px) 100vw, 520px" /></a><p id="caption-attachment-6603" class="wp-caption-text">RSA&#8217;s Amit Yoran says: &#8220;Foolish investments have been made in strategies and technologies that are little more than snake oil.&#8221;</p></div>
<ol>
<li><strong>Strategic Data Manipulation and Disruption –</strong> Organizations will begin to realize that not only is their data being accessed inappropriately, but that it is being tampered with. Data drives decision making for people and computer systems. When that data is unknowingly manipulated, those decisions will be made based on false data.  Consider the potentially devastating consequences of misrepresented data on the mixing of compounds, control systems, and manufacturing processes.</li>
<li><strong>Increasing Attacks on Application Service Providers – </strong>As organizations become more comfortable with the “as a Service” model, many of their most sensitive applications and data reside in the Cloud. The aggregation of this valuable data from many companies creates an incredibly lucrative target for cybercriminals and cyber espionage. A deeper appreciation of third party risk is needed.</li>
<li><strong>Hacktivism and the Attack Surface – </strong>Per my earlier comment, as cyber-attack tools and services become increasingly commoditized; the cost of attacking an organization is dropping dramatically, enabling more attacks that do not have financial gain as the primary focus. Sophisticated hacktivist collectives like Anonymous have been joined by relatively unsophisticated cyber vigilantes.  Organizations need to realize that financial gain is no longer the only or even the biggest driver of some of their adversaries.  Security operations and risk managers should evolve their understanding not only of the threat, but also of what, why, where, and how they are being targeted.</li>
<li><strong>ICS (Industrial Control Systems) pushed to the Breaking Point – </strong>Intrusions into systems that control operations in the chemical, electrical, water, and transport sectors have increased 17-fold over the last three years. The advent of connected and automated sensors with the IoT aggressively exacerbates these issues. The growth in the use of cyber technology for terrorism, hacktivists and other actors, combined with the weakness of ICS security generally, combined with the potential impact of bringing down a power grid or water treatment plant (hello, California), makes the critical breach of an ICS in 2016 extremely concerning and increasingly likely.</li>
<li><strong>Shake-out of the Security Industry –</strong> Our industry has been awash in venture capital and as a result, foolish investments have been made in strategies and technologies that are little more than snake oil.  As organizations’ security programs continue to mature, they are learning that claims of being able to prevent advanced threat breaches are nothing more than fantasy.  Expect to see a shake-out in the security industry as organizations maturing understanding of advanced threats increasingly drives their security investment decisions.</li>
</ol>
<p style="text-align: right;"><em>This is a guest contribution by RSA&#8217;s Amit Yoran. <a href="https://www.emc.com/domains/rsa/index.htm" target="_blank">RSA</a> is a division of <a href="https://www.emc.com/en-us/index.htm" target="_blank">EMC</a> Corporation</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RSA Research Finds Americas Financial Services Industry Lacks Cybersecurity Maturity</title>
		<link>https://www.financecolombia.com/rsa-research-finds-americas-financial-services-industry-lacks-cybersecurity-maturity/</link>
		
		<dc:creator><![CDATA[Loren Moss]]></dc:creator>
		<pubDate>Sun, 28 Jun 2015 16:55:25 +0000</pubDate>
				<category><![CDATA[BFSI - Financial Services]]></category>
		<category><![CDATA[PressRelease - Edited & Rewritten From Contributed Information Submitted to Finance Colombia]]></category>
		<category><![CDATA[amit yoran]]></category>
		<category><![CDATA[cybersecurity framework]]></category>
		<category><![CDATA[cybersecurity poverty index]]></category>
		<category><![CDATA[emc]]></category>
		<category><![CDATA[emea]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[rsa]]></category>
		<guid isPermaLink="false">https://www.financecolombia.com/?p=5765</guid>

					<description><![CDATA[RSA, The Security Division of EMC (NYSE: EMC), released its inaugural “Cybersecurity Poverty Index” that compiled survey results from more than 400 security professionals across 61 countries. The survey allowed participants to self-assess the maturity of their cybersecurity programs leveraging the N...]]></description>
										<content:encoded><![CDATA[<p>RSA, The Security Division of EMC (NYSE: EMC), released its inaugural “Cybersecurity Poverty Index” that compiled survey results from more than 400 security professionals across 61 countries. The survey allowed participants to self-assess the maturity of their cybersecurity programs leveraging the <a href="https://www.nist.gov/cyberframework/cybersecurity-framework-faqs.cfm">NIST Cybersecurity Framework</a> (CSF) as the measuring stick. The research provides valuable global insight into how organizations rate their overall cybersecurity maturity and practices across a variety of organizational sizes, industries and geographies. While larger organizations are typically thought of as having the resources to mount a more substantive cyber defense, the results of the survey indicate that size is not a determinant of strong cybersecurity maturity and nearly 75% of all respondents self-reported insufficient levels of security maturity.</p>
<ul>
<li>Nearly 75% surveyed lack the maturity to address cybersecurity risks</li>
<li>83% of large organizations ranked themselves as below “developed” in maturity</li>
<li>Up to 45% admit inability to measure, assess and mitigate cybersecurity risk</li>
<li>The most mature capability revealed in research is in the area of Protection, Detect and Response capabilities lag</li>
<li>Only one-third of financial services organizations report being adequately prepared</li>
</ul>
<ul>
<li>NIST Cybersecurity Framework used as the measuring stick; yet the Americas rank themselves behind both APJ and EMEA in overall maturity</li>
</ul>
<p>The lack of overall maturity is not surprising as many organizations surveyed reported security incidents that resulted in loss or damage to their operations over the past 12 months. The most mature capability revealed in the research was the area of Protection. The research results provide quantitative insight that organizations&#8217; most mature area of their cybersecurity program and capabilities are in preventative solutions despite the common understanding that preventative strategies and solutions alone are insufficient in the face of more advanced attacks. Further, the greatest weakness of the organizations surveyed is the ability to measure, assess and mitigate cybersecurity risk with 45% of those surveyed describing their capabilities in this area as “non-existent,” or “ad hoc,” and only 21% reporting that they are mature in this domain. This shortfall makes it difficult or impossible to prioritize security activity and investment, a foundational activity for any organization looking to improve their security capabilities today.</p>
<p>“This research demonstrates that enterprises continue to pour vast amounts of money into next generation firewalls, anti-virus, and advanced malware protection in the hopes of stopping advanced threats. Despite investment in these areas, however, even the biggest organizations still feel unprepared for the threats they are facing,” said Amit Yoran, the president of RSA. “We believe this dichotomy is a result of the failure of today&#8217;s prevention-based security models to address the advancing threat landscape. We need to change the way we think about security and that starts by acknowledging that prevention alone is a failed strategy and more attention needs to be spent on strategy based on detection and response.”</p>
<p>Counter to expectations, the research indicates that the size of an organization is not an indicator of maturity. In fact, 83% of organizations surveyed with more than 10,000+ employees rated their capabilities as less than “developed” in overall maturity. This result suggests that large organizations&#8217; overall experience and visibility into advanced threats dictate the need for greater maturity than their current standing. Large organizations&#8217; weak self-assessed maturity ratings indicate their understanding of the need to move to detect and response solutions and strategies for a more robust and mature security.</p>
<blockquote><p><em>Inaugural Cybersecurity Poverty Index Shows A Troubling Lack Of Maturity And An Over-reliance On Prevention</em></p></blockquote>
<p>Also counterintuitive to expectations were the results from financial services organizations, a sector often cited as industry-leading in terms of security maturity. Despite conventional wisdom, however, the financial services organizations surveyed did not rank themselves as the most mature industry, with only one third rating as well-prepared. Critical infrastructure operators, the original target audience for the CSF, will need to make significant steps forward in their current levels of maturity. Organizations in the Telecommunications industry reported the highest level of maturity with 50% of respondents having developed or advantaged capabilities, while Government ranked last across industries in the survey, with only 18% of respondents ranking as developed or advantaged. The lower self-assessments of maturity in otherwise notably mature industries suggest a greater understanding of the advanced threat landscape and their need to build more mature capabilities to match it.</p>
<p>Despite the fact that the CSF was developed in the United States, the reported maturity of organizations in the Americas ranked behind both APJ and EMEA. Organizations in APJ reported the most mature security strategies with 39% ranked as developed or advantaged in overall maturity while only 26% of organizations in EMEA and 24% of organizations in the Americas rated as developed or advantaged.</p>
<p><strong>Methodology</strong></p>
<p>To assess cybersecurity maturity, respondents self-assessed their capabilities against a sampling of the <a href="https://www.nist.gov/cyberframework/cybersecurity-framework-faqs.cfm">NIST Cybersecurity Framework</a> (CSF). The CSF provides guidance based on existing standards, guidelines, and practices for reducing cyber risks, and was created through collaboration between industry and government. While the CSF was initially developed in the United States with the aim of helping to reduce cyber risks to critical infrastructure, organizations worldwide have found it to be a prioritized, flexible, repeatable, and cost-effective approach for managing cyber risk. Thus, it serves as an excellent baseline to assess any organization&#8217;s core cyber security and cyber risk management maturity.</p>
<p>Organizations rated their own capabilities in the five key functions outlined by the CSF: Identify, Protect, Detect, Respond, and Recover. Ratings used a 5 point scale, with 1 signifying that the organization had no capability in a given area, and 5 indicating that they had highly mature practices in the area.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Exclusive Interview: Praxis Head Discusses Growth in Colombia’s Finance Sector, But Critical Data Security Challenges Remain</title>
		<link>https://www.financecolombia.com/exclusive-interview-praxis-head-discusses-growth-in-colombias-finance-sector-but-critical-data-security-challenges-remain/</link>
		
		<dc:creator><![CDATA[Loren Moss]]></dc:creator>
		<pubDate>Mon, 13 Apr 2015 01:03:45 +0000</pubDate>
				<category><![CDATA[BFSI - Financial Services]]></category>
		<category><![CDATA[Interview]]></category>
		<category><![CDATA[agile]]></category>
		<category><![CDATA[caribbean]]></category>
		<category><![CDATA[carlos chiquillo]]></category>
		<category><![CDATA[cmmi]]></category>
		<category><![CDATA[colombia]]></category>
		<category><![CDATA[ethical hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[infosys]]></category>
		<category><![CDATA[isqb]]></category>
		<category><![CDATA[mexico]]></category>
		<category><![CDATA[outsourcing]]></category>
		<category><![CDATA[panama]]></category>
		<category><![CDATA[peru]]></category>
		<category><![CDATA[pmi]]></category>
		<category><![CDATA[praxis]]></category>
		<category><![CDATA[rcp]]></category>
		<category><![CDATA[rep]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[sarbanes oxley]]></category>
		<category><![CDATA[sox]]></category>
		<category><![CDATA[tcs]]></category>
		<category><![CDATA[tercerizacion]]></category>
		<category><![CDATA[tmmi]]></category>
		<category><![CDATA[two factor authentication]]></category>
		<category><![CDATA[white hat]]></category>
		<category><![CDATA[work life balance]]></category>
		<guid isPermaLink="false">https://www.financecolombia.com/?p=5280</guid>

					<description><![CDATA[Finance Colombia recently sat down with the Director General of Praxis in Colombia, Carlos Chiquillo, fresh off their celebration of a successful first year of operations in the Andean nation. The Mexican based multinational opened operations in Colombia due to strong demand from existing clients, w...]]></description>
										<content:encoded><![CDATA[<p>Finance Colombia recently sat down with the Director General of <a href="https://www.praxisglobe.com.co/">Praxis</a> in Colombia, <a href="https://www.praxisglobe.com.co/">Carlos Chiquillo,</a> fresh off their celebration of a successful first year of operations in the Andean nation. The Mexican based multinational opened operations in Colombia due to strong demand from existing clients, who wanted their provider to have a local presence, and their analysis of the growth prospects for Colombia’s banking and finance sectors, as well as other business areas that the IT services firm serves.</p>
<p>Praxis opened with a strategy of establishing a strong presence in their 14 specialty service areas, bringing their customized “Software Factory” to Colombian customers; and also their specialized Capability Maturity Model Integration methodology, which according to the firm, is a way of analyzing and evaluating business processes of customers to improve operations.</p>
<p>Praxis has obtained CMMI Level 5 certification, adopting AGILE software development methodologies, and RCP &amp;REP certification from the PMI (Project Management Institute). The 15 year old firm has a service offering in Mexico, the United States, Brasil, Puerto Rico, Argentina, Central America, Chile, Perú, and Spain; as well as representatives and sales offices throughout the Americas, the Middle East, Russia, Asia, and the Pacific.</p>
<p><strong>FINANCE COLOMBIA: Speaking of the financial sector, what is the opportunity that Praxis sees here in Colombia with the banking sector, the insurance sector, the securities sector?</strong></p>
<p><strong>Chiquillo:</strong> The opportunity that we have detected here relates to quality; quality and testing. That is something that here has been a bit unattended. When we started to research the market and spoke to people in the industry, everybody had software development capabilities. But we noticed they didn&#8217;t have quality assurance suppliers, facilities for testing, something really important. It appeared to us as a flaw because in terms of method: if someone is developing, they should test too. The person who creates your systems must take care of them, control them, they are in charge. The testing team should be completely independent, where they assess the quality of what is given to you as two different teams. We have found a couple of banks who have quality teams that are working well, and with good methods. In Praxis when we spoke to them we started offering coaching and mentoring services in ISQB, the quality standard in testing, and in TMMI, the equivalent of CMMI. That was the main idea.</p>
<p><strong>Finance Colombia: Praxis has stability; it has a presence in several countries, but what next? You are in Colombia, also in Mexico and other countries, fighting against ‘elephants’ such as Infosys and TCS. What is the difference between Praxis and the competition? Because the giants are big in the region and they can go to a client and say: &#8220;yes, we are here, we are worldwide and have the size to do what you need done.” Praxis is by no means a startup, but how do you face and compete with those global giants?</strong></p>
<p><strong>Chiquillo:</strong> There is something complicated in the Colombian market, I have to tell you. Those “elephants” came with really low prices. If I am to be honest, at this moment, our competition strategy is not price. We try to level up or bring it a bit higher. As you put it, the difference between being big and being gigantic, that&#8217;s the most significant thing. We have three main strategies: 1. We have to level up. What are we doing? This year is an acquisition year. We are investing in the Caribbean, which has very good universities, the education has improved, and there are good development resources, much cheaper, in order to compete. Nevertheless, that is not our main purpose at Praxis, we do not compete on prices, we compete on quality. We have <a href="https://www.praxisglobe.com.co/html/home/SuperEmpresas.html">certification as a super company</a>; we have been awarded that ever since 2008, every year as being a “Best place to work.” Our professionals enjoy working here; our specialties are well distributed to attend to the different aspects of our clients’ business, so at this moment what we offer is service and quality. That is the factor that differentiates us; our financial clients are happy, they have no problems and have a long, ongoing relationship. When we replicate the model in a new country—it&#8217;s been a year and a half here in Colombia—it happens to be much easier.</p>
<p><strong>Finance Colombia: That is because your clients told you: &#8220;Look, we want your presence in Colombia because we have operations there”—or how did it happen?</strong></p>
<p><strong>Chiquillo:</strong> Praxis started as a small company, it kept growing, and now our objective is to work anywhere in the same way. When we started the expansion project, that was the first thing we saw: we have to manage global accounts, and this financial service sector is very global. We have to take possession of it. So that was the starting point, although not the main objective. In the end, we decided that was the way we wanted to handle Praxis Global. Currently we are developing India, New York, London and have representatives in Israel and Australia, for instance. We reached a point where we want to attack at a global level, fully global. Banking strategy is the same. We want to tell them: &#8220;You opened operations in Mexico, we are also in Mexico and can help you in the same way.&#8221;</p>
<p><strong>Finance Colombia: Apart from banks, and speaking of security and regulation, governance; if we see the insurance sector and stock exchange, what are the specific challenges?</strong></p>
<p><strong>Chiquillo:</strong> If we want to be specific, we offer them security. We approached the security issue with two main aspects, products and consultancy. In product we try to reach authentication systems, filtering and control. What does &#8220;authentication&#8221; mean? To give them all those things you mentioned, e-mail systems, two factor authentication…So we have products, integration and consultancy. Over 10 years of experience so, regardless of the organization, when they need double security—beyond a password—we implement all those services for critical data.</p>
<blockquote>
<p style="text-align: right;"><em><strong>&#8220;We reached a point where we want to attack at a global level, fully global.&#8221;</strong></em></p>
</blockquote>
<p>Our bet is not to compete with the services of the giants, but to give clients a version of cloud based software development, of strong authentication where they do not have that high level of investment. We charge per user, we provide software-as-a-service, they connect to the cloud, and all those authentication services run through us. Likewise we do it with SOX (Sarbanes Oxley Act) Compliance.</p>
<p>Mail is filtered so that everything is real. We don&#8217;t want spammers or malware; we want the data to be real. We are at that level; Security Control and coaching as a product. Protocol management, security control, virtual courses and training sessions for all organizations, telling them, &#8220;These are the security mechanisms in organizations worldwide,&#8221; to avoid personal hacking, phishing, apart from control and analysis, to say: &#8220;please don&#8217;t use personal data in your passwords.&#8221; We are also working on that.</p>
<blockquote>
<p style="text-align: right;"><em><strong>&#8220;Human talent is really good; the students come out well prepared from the universities.&#8221;</strong></em></p>
</blockquote>
<p>And consultancy is secular financial management, we attend to what the Colombian government tells financial entities they have to comply with, in order to attack those concerns first in terms of security, for instance in one case it was a requirement for a strong authentication network, so we had to bring the banks into compliance last year. And now we continue with controlled hacking. Lots of ethical hacking, we want to certify our systems are safe.</p>
<p>So the thing we want to offer and work on mostly, is consultancy, ethical hacking, and all the services of control. We already have strong experience with the energy sector, there are companies where we have found the flaws through the use of our ethical hacking and fortunately, remediated them. The companies were pleased.</p>
<p><strong>Finance Colombia: Yes, I imagine that here or in Mexico, in the US they are very worried. The energy network is so smart now, so controlled, that hackers are able to try and go for a power grid shutdown. They have to be worried about those aspects of their critical infrastructure.</strong></p>
<p><strong>Chiquillo:</strong> If we speak about Colombia, the government is really concerned—about everything.</p>
<p><strong>Finance Colombia: It&#8217;s more than hacking down an electrical tower; rather a hacker sneaking in the system&#8230;They are hacking with a hammer. <em>“I&#8217;m a hacker!”</em></strong></p>
<p><strong>Chiquillo:</strong> And then it appears on the news: <em>&#8220;Electrical network hacked with a hammer.&#8221;</em> The idea is education and consulting mainly. That&#8217;s what they need. That is, products&#8230;in one area what we are doing is developing easy products, the right fit for companies, and that secures them. Because, one of the greatest challenges of selling security is that, if a company is big, it will require protection, but inn each level [of company size], everybody needs to have access to secure platforms.</p>
<p><strong>Finance Colombia: I believe that many businesses, small businesses are scared, and think &#8220;we cannot afford a consultancy which will cost a lot and require a big contract…&#8221; they know they need something but they are scared of the price tag.</strong></p>
<p><strong>Chiquillo: </strong>What do we do in those cases? We take risks, just like the example you just gave: A company who says &#8220;I need to protect myself, I cannot by the RSA solution used for strong authentication, which costs $120.000 USD, plus integrating my systems and so on,&#8221; so what we do is, ask: &#8220;How many users do you want?&#8221; &#8220;Two&#8221; (a small company); &#8220;which resources do you want to protect?&#8221; &#8220;These ones.&#8221; So we provide strong authentication for users and we charge them monthly, let&#8217;s say a crazy number, $3 USD. Two users, that&#8217;s it.</p>
<p><strong>Finance Colombia: One thing I have seen that impresses me is the quality of talent that exists here in Colombia.</strong></p>
<p><strong>Chiquillo: </strong>I wanted to tell you that. Something really cool that has happened to us is that Mexico and Colombia are quite similar. Culturally and in terms of normal interaction between management and teams and so on. Ecuador, which is right next to us, is different, yes? Venezuela is quite different, almost another planet. And they are there on the border. But if you ask me, all the media we received here in Colombia since the 40s and 50s, was Mexican, from when TV arrived until the 90s more or less, when the Peruvians entered [the Colombian media market].</p>
<blockquote>
<p style="text-align: right;"><em><strong>&#8220;We want our employees to feel well, to have time for everything, for their personal lives.&#8221; </strong></em></p>
</blockquote>
<p>But I assure you that culturally, Colombia is very similar to Mexico, and it has helped our company work. You said it: you have seen in both Mexico and Colombia the level of innovation, of trying to give solutions instead of applying ready-made answers.</p>
<p>Human talent is really good; the students come out well prepared from the universities. I believe we are the sector who offers the best pay to recently graduated professionals. I think every day, how do I have to fight with [competitors] for a human resource, a good, recently graduated Java developer, to compete against all the giant firms. So what did we have to do? Good planning and development practices, work-life management. &#8220;Sir, you check in and have to work 8 hours. Arrive anytime you want, within reason do your eight hours. If you have to stay longer, then there is a planning and resource allocation problem. But it&#8217;s not your problem, it&#8217;s ours!</p>
<p><strong>Finance Colombia: It is important to believe in having balance; as the saying goes &#8220;work-life-balance&#8221;, because otherwise, in most cases, somebody changes his or her job not only because of salary, but other reasons such as lifestyle and office pressure, &#8220;It leaves me no time to attend to my personal affairs, family, whatever.&#8221; Companies who have more balance in those aspects, will have more loyal employees. If it is pleasant, then I want to be at my office, with my co-workers, and producing, if it is a healthy, functional work environment.</strong></p>
<p><strong>Chiquillo: </strong>We want our employees to feel well, to have time for everything, for their personal lives. And it has gone well for us and attrition levels are low, even while everybody is looking to poach resources from us all the time.</p>
<p><strong>Finance Colombia: It&#8217;s also better for clients, because they are working with the same team, with some tenure and stability, without people always coming and going.</strong></p>
<p><strong>Chiquillo: </strong>And with our financial clients that stability is really important.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Minified using Disk

Served from: www.financecolombia.com @ 2026-09-06 05:14:10 by W3 Total Cache
-->