Cyber Cube

The Dual Guard: Balancing Fintech Growth with Data Protection

todayJanuary 17, 2026 41 5

Background
share close

The financial sector is undergoing a digital revolution, but with rapid growth comes a massive increase in data responsibility. In CyberCube Episode 5, Mohammed Aldoseri, who uniquely holds the titles of both Chief Information Security Officer (CISO) and Chief Data Officer (CDO), explains how to navigate the complex intersection of cyber defense and data governance.

1. The Emergence of the CDO (Chief Data Officer)

While the CISO protects the systems, the CDO governs the data itself. Dr. Aldoseri explains that in Saudi Arabia, the CDO role is essential for implementing the SDAIA National Data Management Office (NDMO) framework.

  • Data Ownership: Identifying who owns the data and its quality.
  • Risk Assessment: Understanding the value of data and the potential impact if it is compromised.
  • Governance for Analytics: Clean, well-governed data is the only way to achieve accurate AI forecasting and business analytics.

2. Privacy by Design: The PDPL Framework

The region is tightening regulations through laws like Saudi Arabia’s Personal Data Protection Law (PDPL). Dr. Aldoseri breaks down the critical acronyms every professional should know:

  • PII: Personal Identification Information (The identity).
  • PCI: Payment Card Industry data (The money).
  • PHI: Personal Health Information (The health).
  • PDPL: The law that protects all the above, giving users the right to know how their data is used and who has access.

3. The “No-Flexibility” Rule

In the modern fintech landscape, the “marketing exception” is gone. Organizations no longer have the flexibility to use customer data for secondary purposes (like marketing) without explicit consent from the data owner. This shift requires a “Privacy by Design” approach—incorporating data protection into a project from its very first day of development.

4. ROI: Avoiding the Cost of Non-Compliance

How do you convince the board to invest millions in data protection?

  • Regulatory Fines: Non-compliance isn’t just a risk; it’s a legal and financial liability.
  • Reputation: In fintech, trust is the primary currency. One breach of customer data can destroy years of brand building.
  • Security by Design vs. Patching: Investing $100k early in a secure architecture is vastly cheaper than trying to fix a $1M problem after a breach.

Written by: Rakesh

Rate it

Post comments (0)

Leave a reply

Your email address will not be published. Required fields are marked *

Tick the switch to enable the submit button.


GET IN
TOUCH

CONTACT US

Phone: +97313331072

Email: [email protected]

LOCATION

LiveFM 107.2,
Studio 5
Ministry of Information Complex
Building 3500
National Charter Highway
Isa Town 840
P.O. Box 253
Kingdom of Bahrain