Maya has expanded security features that allow customers to freeze or unfreeze cards and manage their use through its app. The platform also employs biometric authentication, fraud monitoring and dynamic CVVs for Maya credit cards to provide additional protection for online transactions.
Maya head of Corporate Affairs Kristoffer Rada said cybersecurity should be treated as part of the financial product itself rather than as a back-office function.
“For us in Maya, cybersecurity is not some back-office product, it’s really part of the product,” Rada said. “As more people depend on digital financial services every day, maintaining trust becomes a responsibility shared by financial institutions, regulators, government and the broader ecosystem.”
Rada said cybersecurity policy should balance strong safeguards and institutional accountability with the ability to respond to rapidly changing technologies and risks.
He said the focus should go beyond compliance with individual rules to outcomes such as protecting customers, maintaining service continuity, strengthening accountability and ensuring institutions can respond to and recover from cyber incidents.
“Technology evolves so fast. The rules that apply this year may no longer be applicable and could become archaic in five years,” Rada said. “Whatever technology evolves, you have to evaluate using the same standard because the risks are the same.”
Rada said technology-neutral and risk-based standards could help regulations remain relevant, but called for closer coordination among government and industry. He noted that cyber risks cut across banking supervision, data privacy, telecommunications, consumer protection and law enforcement.
“Cyber threats do not stop at the boundaries of one company, one regulator or one country,” he said. “The stronger the coordination across the ecosystem, the better we can protect customers and maintain confidence in digital services.”
Cybersecurity as enterprise responsibility
Maya director of Information Security Jan Martin Encina said cybersecurity should be treated as an enterprise-wide responsibility rather than an issue handled solely by information technology teams.
“Cybersecurity is no longer just an IT issue; it is a business imperative, a national security priority and a fundamental component of public trust,” Encina said.
He said stronger cyber resilience requires continuous monitoring, improved identity and access management, resilient infrastructure, regular security testing and established incident-response capabilities.
Encina also pointed to employee awareness and customer education as critical defenses as cybercriminals increasingly combine technology with social engineering and other tactics that exploit human behavior.
He stressed the importance of public-private partnerships, cross-border cooperation and threat-information sharing as cyberattacks become more sophisticated and interconnected.
“Ensuring that personal data is collected, stored and processed responsibly is not only a regulatory requirement, but also a moral obligation to the citizens and customers we serve,” Encina said.