DSF : Cybersecurity and digital risk in finance

Catalogue des cours de Institut Mines-Télécom Business School

Code

MGFE MIS 6215

Niveau

M2

Discipline

Systèmes d’information

Langue

Anglais/English

Crédits ECTS

2

Heures programmées

20

Charge totale étudiant

40

Coordonnateur(s)

Département

  • Data analytics, Économie et Finances

Equipe pédagogique

Introduction au module

This course introduces students to cybersecurity and digital risk issues in the financial sector. It examines the current threat landscape, the main forms of cyberattacks, the evolution of cybercrime, the exposure of citizens and companies, the role of public defence strategies, and the structure and prospects of the cybersecurity market. Students will learn how to analyse cyber threats, understand the actors involved, and assess the strategic importance of cybersecurity for financial institutions and digital ecosystems.

Bloc de compétences

  • 1. S’approprier les usages avancés et spécialisés des outils de l’intelligence digitale en s’assurant de leur impact durable et responsable

Compétences du bloc

  • 1.1 - Auditer les usages avancés et spécialisés des outils de l'intelligence digitale, afin de les mobiliser avec pertinence, en tenant compte du contexte stratégique des organisations.

Objectifs d'apprentissage du cours

By the end of this PGE M2 course, students will be able to:

Describe the main cybersecurity fundamentals and explain their relevance to financial institutions and digital financial activities.
Identify and classify the main cyber threats affecting citizens, companies and financial organisations.
Analyse recent cyberattack patterns at global and French levels in order to assess the evolution of the threat landscape.
Explain the business models, actors and organisational logic of cybercriminality.
Evaluate the role of State defence strategies in preventing, detecting and responding to cybersecurity threats.
Analyse the structure, characteristics and technological prospects of the cybersecurity market.
Present a structured case analysis of a cybersecurity or digital risk situation in finance, using relevant concepts, evidence and recommendations.

Contenu : structure du module et agenda

Threat Landscape: Analysis and Decryption
1.1 Cybersecurity fundamentals
1.2 Main cyber threats
1.3 Review of cyberattacks: global and French perspectives
1.4 Evolution of threats and emerging digital uses
Current Situation of Key Actors
2.1 Citizens
2.2 Companies
Cybercriminality
3.1 Cybercrime as a business
3.2 Cybercriminal actors
State Defence Strategy
4.1 Role of the State in cybersecurity
4.2 Public defence, prevention and response strategies
Cybersecurity Market
5.1 Characteristics of the cybersecurity sector
5.2 Technological outlook and future trends

Contribution à l'atteinte des ODD (Objets du Développement Durable)

SDG 16 – Peace, Justice and Strong Institutions: This course contributes to SDG 16 by helping students understand and address cybercrime and digital security risks, thereby supporting more resilient, trustworthy and secure financial institutions.

Nombre d'ODD abordés parmi les 17

1

Apprentissage

Mixte

Méthode pédagogique

The course combines lectures, examples, case studies and student presentations. Lectures introduce the main concepts, threat categories, actors and strategic issues related to cybersecurity and digital risk in finance. Examples and case studies allow students to analyse real or realistic cyber risk situations and assess their implications. Student presentations help develop the ability to communicate a structured diagnosis and recommendations on cybersecurity issues.

Système de notation et modalités de rattrapage

The assessment evaluates students’ ability to analyse cybersecurity threats, understand digital risk exposure, identify relevant actors and defence strategies, and formulate a structured response to a cybersecurity case in a financial context. It measures their capacity to apply the concepts covered in class to a concrete case, produce a clear written analysis and present their reasoning orally.

The final grade is based on a case study assessment:

Individual written assignment: 15/20.
Oral presentation: 5/20.

Unjustified absences will result in a penalty equal to 20% of the module grade.

The second-chance assessment, CF2, consists of an individual written in-class exam.

Règlement du module

1. Professor–Student Communication

The professor will communicate with students through their institutional school email address (IMT-BS/TSP) and/or the Moodle portal. No communication will be sent to personal email addresses. Students are responsible for regularly checking their IMT-BS/TSP mailbox and Moodle announcements.

Students may contact the professor by email using the professor’s institutional email address. When necessary, students may meet the professor during office hours or by appointment.

2. Students with Accommodation Needs

Students who have a disability or any specific accommodation need that may affect their ability to complete the required work must inform the professor during the first class, in order to facilitate the necessary arrangements in accordance with the school’s applicable procedures.

3. Class Attendance and Behaviour

Students are expected to attend class, arrive on time and behave respectfully throughout the session.

Unless explicitly authorised by the professor, the use of electronic devices, including computers, mobile phones and tablets, is prohibited during class. Students are not allowed to take photos, videos or audio recordings in the classroom without the professor’s explicit consent.

Students must avoid disruptive or disrespectful behaviour, including arriving late, leaving early, sleeping, reading non-course material, using inappropriate language, speaking over others, eating or drinking during class, or engaging in any behaviour that disturbs the class. A warning may be given for a first violation. Repeated violations may lead to penalties, exclusion from the class and/or disciplinary proceedings.

A delay of up to 10 minutes is tolerated at the beginning of class. Attendance will be recorded on Edusign during this 10-minute period using a QR code provided by the professor at the start of each session.

Leaving the classroom before the end of the session without the professor’s approval will be considered an absence.

In the case of remote learning, students must keep their camera on unless instructed otherwise by the professor.

4. Exams and Assessments

Students must arrive on time for exams and other assessments. A delay of up to 10 minutes is tolerated.

No student may continue the exam once the allocated time is over. No student may leave the room during an examination unless they have finished the exam and handed in all required documents.

Only the following items are allowed during exams:

pens;
student card;
a non-programmable calculator, or a programmable calculator with activated EXAM mode.

All other items are prohibited.

Possession of any unauthorised electronic device, even if turned off, will be considered cheating.

Possession of a programmable calculator without activated EXAM mode, even if turned off, will be considered cheating.

A random check may be carried out after students are instructed to activate EXAM mode. Failure to prove that EXAM mode has been activated after this instruction will be considered cheating.

Students are responsible for knowing how to activate EXAM mode on their calculator before the exam.

Any violation of the instructions given by the professor or the examination supervision team will be reported to the Discipline Committee.

Références obligatoires et lectures suggérées

Anderson, R., Security Engineering: A Guide to Building Dependable Distributed Systems.
Singer, P. W. and Friedman, A., Cybersecurity and Cyberwar: What Everyone Needs to Know.
Schneier, B., Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World.
Hadnagy, C., Social Engineering: The Science of Human Hacking.
McGraw, G., Software Security: Building Security In.
Chabinsky, S. and Panetta, L., Cybersecurity for Executives: A Practical Guide.
National Institute of Standards and Technology, Framework for Improving Critical Infrastructure Cybersecurity.
ANSSI, Guides and recommendations on cybersecurity risk management.

Mots-clés

Cybersecurity; digital risk; financial institutions; cyber threats; cyberattacks; cybercriminality; digital fraud; threat landscape; State defence strategy; cybersecurity market; technological outlook; risk management; financial sector resilience; information security; cybercrime.