Thank you for Subscribing to Insurance Business Review Weekly Brief
Salinawati Salehuddin is the Section Head of IT Risk Management at Agrobank, Malaysia. She oversees strategies to identify, assess, and mitigate IT risks, ensuring regulatory compliance and information security. Her leadership helps safeguard Agrobank’s technological infrastructure and maintain operational resilience in a rapidly evolving digital landscape. With experience in both risk management and information technology, Salinawati plays a critical role in protecting the bank’s assets and supporting its business continuity objectives.
In an exclusive interview with Enterprise Security Magazine APAC she shares her invaluable insights regarding the latest developments in the sector, the prevailing challenges as well as the possible solutions. Can You Briefly Describe Your Leadership Role As Section Head Of It Risk Management? What Are Your Key Responsibilities? As the Section Head of IT Risk Management, I am entrusted with leading and overseeing the organization’s technology risk posture, ensuring that it remains aligned with regulatory expectations, industry best practices, and business objectives. While my core responsibilities include managing IT risk assessments, policy governance, and risk mitigation planning, my role extends beyond traditional boundaries. I am also responsible for handling highly confidential incidents, including those involving fraud and data breaches, where discretion, accuracy, and swift coordination with key stakeholders are critical. Additionally, I actively contribute to shaping the organization's cybersecurity awareness initiatives, promoting a risk-conscious culture across all levels. I am involved in key digital strategy projects and supporting the risk evaluation of emerging technology initiatives. My approach is grounded in proactive engagement, collaboration, and strategic foresight to ensure technology risks are not only managed but also positioned as a value-added component of business resilience and innovation. With Threats Constantly Evolving, What’s Your Approach To Ensuring That An It Risk Framework Remains Dynamic And Aligned With Real-World Vulnerabilities Rather Than Just Theoretical Ones? In today’s environment, where cyber threats evolve faster than ever, I believe an effective IT risk framework must be living, practical, and deeply connected to real-world conditions—not just compliance checkboxes or theoretical models. My approach is to ensure the framework remains adaptive and intelligence-driven. I actively promote the integration of threat intelligence, lessons from incidents, and feedback from our frontline teams—because they’re the ones who often see risks emerging before they’re on a formal radar. It's essential that our framework reflects what's actually happening in our environment, not just what's written in policies. Equally important is maintaining strong relationships across business and technical teams. I’ve found that when people feel heard and involved, they’re more likely to surface potential risks early. That collaboration allows us to adjust controls and priorities in real time—especially when business objectives shift or when we detect patterns that suggest something’s not quite right.Leadership in this field isn't just about managing threats; it's about inspiring trust, enabling innovation, and fostering a culture where security is seen as a shared responsibility
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info
However, if you would like to share the information in this article, you may use the link below:
https://www.insurancebusinessrevieweurope.com/cxoinsight/salinawati-salehuddin-nwid-887.html