Information security in the real world. Without days off and holidays
David Rafalovsky headed the Technologies block of Sberbank
David Rafalovsky, Senior Vice President, CTO (chief technology officer) of Sberbank Group, has been appointed head of the Technologies block. He will carry out strategic management of the technological function of the Sberbank Group. ...
Nikita Volkov, Senior Vice President, Co-Head of the Technologies Block, Sberbank PJSC
“I believe that those who own information still own the world, and working with information is to analyze data. The more historical data, the longer we have the opportunity to accumulate, process, analyze and build models, the better we will feel themselves in the market, and they will be of better quality decisions taken... This applies to absolutely all areas of business. Those who are engaged in customer service will be able to better understand their client and his needs, offer the most popular products and services. Manufacturing enterprises through the use of data, they will be able to significantly reduce their costs, anticipate trends and make decisions in real time. This is truly a revolution, and I am sure that the main distinctive feature today - the ability to work with data. "...
Huawei and Sberbank for joint innovation
Huawei and Sberbank signed an agreement on cooperation in the development of information and communication technologies based on Huawei OpenLab and their further implementation in the banking industry. ...
Andrey Khlyzov became the head of Sberbank-Technologies
As Senior Vice President of Sberbank - general director of the company "Sberbank-Technologies" Andrey Khlyzov replaced Alisa Melnikova, who left the bank. Andrei Khlyzov himself has been working at Sberbank for 20 years, holding various positions, in particular, he was the chief IT architect at the bank. ...
Bart Schlatman transforms Sberbank
Bart Schlatman, COO of the Netherlands division of the ING group, has been appointed Senior Vice President for Transformation of Sberbank. This is a new position in the bank. In this role, Bart Schlatman will be responsible for implementing the omnichannel customer service model. In particular, for the introduction of a number of technological platforms. ...
Sberbank appointed Chief Technology Officer
On February 15, 2017, Vadim Kulik will leave the post of Deputy Chairman of the Management Board of Sberbank PJSC. In this position, he supervised and coordinated the work of two blocks of the bank, one of which was the "Technologies" block. Senior Vice President of Sberbank Nikita Volkov has already been appointed acting head of this block. ...
13.10.2017, Fri, 10:55, Moscow time
Modern banking business it is impossible to imagine apart from digital technologies. The financial arteries of the country are transferred not only cash, but also the latest developments in the field of big data, artificial intelligence and cybersecurity. CNews talked to Nikita Volkov, senior vice president, head of Sberbank's Technologies block, about whether the Fourth Industrial Revolution will take place in Russia, how Sberbank will participate in managing the country's digital economy and why mining is a waste of electricity.
Data as the foundation of the digital revolution
CNews: Today, many are talking about the so-called Fourth Industrial Revolution, the essence of which is that data is becoming the main driving force of the economy (which previously at different times was the energy of steam, electricity, production automation). Do you share this view of technology development?
Nikita Volkov: I absolutely share. I believe that those who own information still own the world, and working with information is analyzing data. The more historical data, the longer we have the opportunity to accumulate, process, analyze and build models, the better we will feel in the market and the better decisions will be made. This applies to absolutely all areas of business. Those who are engaged in customer service will be able to better understand their client and his needs, offer the most popular products and services. Manufacturing enterprises through the use of data will be able to significantly reduce their costs, anticipate trends and make decisions in real time. This is truly a revolution, and I am sure that the main distinguishing feature of today is the ability to work with data.
As for the IT infrastructure in the context of the Fourth Industrial Revolution, one of the most obvious trends today is the massive transition to the cloud. Large specialized companies will provide infrastructure and software as a service. All the rest will only have to enjoy using such cloud services and use the opportunities that modern information technologies give us directly in the work with their clients.
CNews: How will the approaches to building IT infrastructure change, how will computing platforms and data storage evolve? How will our economy develop in this vein?
Nikita Volkov: It seems to me that the basic laws have already been formulated, and it is possible to predict quite clearly that computing power will grow exponentially. Data storage systems will become cheaper. The data centers that will handle the underlying transactions will go to the cloud. All kinds of organizations will increasingly use the cloud. They will be more concerned with development, including the use of data processing and analysis technologies. And the questions related to which servers to buy, which communication channels to order, or how to protect data centers from intruders, will be dealt with by professionals who will perfectly cope with this.
CNews: At what stage is the construction of your data center at Skolkovo now? Previously, the terms of their commissioning were adjusted, what are the plans for launching now?
Nikita Volkov: We will finish the construction this year and will start with equipment. It will actually start working in December this year. There will be a phased migration of existing equipment and systems to the new data center. A data center is needed because the volume of processed information is constantly growing. This will be the second large, rather serious data center of Sberbank. In the long term, by 2020, the structure of the bank's data center is being transformed: the data centers leased today will be completely replaced by two mega-data centers - the existing data center “Yuzhny Port” and the data center “Skolkovo”. This will simplify the structure and connectivity of the data center, and increase the efficiency of resource use due to the consolidation of equipment and applications. In the future, the new structure of the data center will become the basis for other Sberbank businesses, the foundation for the ecosystem.
Large-scale implementation of blockchain is not far off
CNews: How will the software change in the next 5-10 years?
Nikita Volkov: Oh, the software will be very different. Access to it will be easier, the choice will be wider. We will have free software for all occasions, easy to obtain, easy to use, and customizable by becoming a member of the community. I believe that open source software will be the main trend in the next few years. The same applies to business applications: they will also go to the "clouds", and companies will more often use cloud services rather than buying licenses. I think that in the next few years, the ratio between the volume of costs for acquiring licenses and costs for subscription fee for using the services. In favor of the second.
CNews: How will the IT services market change in the world and in Russia as a whole?
Nikita Volkov: IT services will grow side by side with disruptive areas of human activity, such as genetics, modern medicine, and robotics. Computer science is very important in these areas, and the volume of the IT market will grow, including in conjunction with these successful industries. This includes blockchain, artificial intelligence, and the Internet of Things. In my opinion, all this will grow exponentially and ensure the growth of the IT market as a whole.
CNews: Since we are talking about blockchain, how do you feel about this technology and the possibility of its application in the banking business?
Nikita Volkov: Blockchain is an interesting, wonderful technology. We believe in it and are already doing some pilot projects... I think that in a few years, large-scale use of blockchain will begin in many areas. And it is absolutely certain that this technology will be supported by the development of server equipment, processors different kind etc. As for cryptocurrencies, we are not engaged in mining, we are not engaged in issuing cryptocurrencies, and, to be honest, I am somewhat skeptical about the fact that there are already several thousand cryptocurrencies in the world. People mine a lot of things, but now this is no longer the trend, in pursuit of which it is worth making any strategic plans. It is quite obvious to me that a large number of electricity is wasted today. Well, the fact that processors are getting faster is great. This means we will be able to solve our problems with greater efficiency.
More data, good and different
CNews: Where do you think it is important to start digital business transformation? What steps need to be taken - managerial, personnel, what changes need to be made?
Nikita Volkov: In every company, if it counts on success, there should be Chief Specialist on working with data. This person, in fact, becomes one of the main actors in the company, uniting at the same time IT, business and support divisions of the company. This is extremely important because how we work with data determines our success, which means that we need to be very careful with any information flows that go through the company. You can't miss out on any important data about customers, their habits, how often they visit you, why they leave, and so on. This, in my opinion, is the number one question for today.
Nikita Volkov: You shouldn't make strategic plans for cryptocurrencies
The second issue is the quality of the staff. It seems to me that almost every employee of the company should have an understanding of the essence of digitalization and basic IT ideas. Many processes within the company need to be rebuilt in such a way that, on the one hand, provide information for data processing, and on the other hand, use the results of such processing as widely as possible in practice: in management processes, customer service, for decision-making. Using models is extremely important and leads to success. Digitization in general is very important, and people need to be focused on these technologies - I would just suggest that companies do entrance tests on their ability to use basic digital technologies.
For the digital economy to be successful in Russia, I think it is necessary to improve the quality of education within the region. We do not sufficiently teach people the basics of the digital economy, digitalization, working with data, the basics of programming and artificial intelligence. I think in the highest educational institutions first of all, it is necessary to increase the volume of teaching such disciplines and to dramatically increase the number of specialists in these areas. Then we will succeed with the digital economy.
Sberbank's future in the digital economy
CNews: What place do you assign to Sberbank in the new digital economy?
Nikita Volkov: Banks have always been at the forefront of technology development, this situation persists in the whole world and in Russia in particular. And we consider ourselves responsible for the digitalization of our society. We have a huge number of clients, and we do what depends on us, so that people receive the most modern services in digital format. And our role in this is quite large. In addition, we are not only making banking digital, but we are working in a number of industries, where we also strive to increase the level of digitalization. We must not forget that now the number of cybercrimes has increased dramatically. We see our task in educating the population - what can and should be done, and what should in no case be done to the holders plastic cards and to those who use Internet services. Our educational role, in my opinion, is very important.
CNews: Recently the government approved the program management structure “ Digital economy". For this, a self-named autonomous non-profit organization, which, according to Dmitry Medvedev, is ready to include Sberbank. How will you participate in the management or coordination of the Digital Economy?
Nikita Volkov: There are a number of areas for the development of the digital economy in Russia. For each of them, the corresponding centers of competence have been identified. Sberbank is mandated to be the center of competence in the field of cybersecurity. This is a very responsible role for us, and we believe that we will cope with it. We have good specialists and very serious experience, we work in this market and will make our contribution to the development of the digital economy. But not limited to only this. We carefully study all areas of development, see how we can help, how to participate. The Digital Economy is a very serious program, and we will participate in work on it in almost all areas.
CNews: At the St. Petersburg Economic Forum, the President called on the largest state-owned companies to create divisions that will substantively work with start-ups and small innovative companies. Are you going to participate and do you already have any specific plans or examples of projects?
Nikita Volkov: Of course, we have plans, and we already have results. About two years ago, just for these purposes, a specialized unit was created in the bank - the Digital Business Development Department. There is quite active work with startups, they are selected, invested in them and help to develop. In addition, we have created a venture fund - we invest in a number of startups with the expectation that this will benefit both society and us, in the form of dividends from their development.
Innovation sometimes conflicts with job stability because it gets in the way of stability. Therefore, Sberbank never strives to be the first in the field of introducing any new technologies. This was announced by the senior vice president of Sberbank for IT Nikita Volkov at the briefing on the preliminary results of the implementation of the program "Reliability automated systems bank ", as well as the IT development strategy of the bank until 2018. The briefing took place on January 21, 2015. But the bank is trying to be the second, because if somewhere there appears at least some breakthrough technology that can significantly improve the situation in a certain market sector, then Sberbank will introduce it into its work in 3-6 months, Volkov added.
As part of the IT development strategy until 2018, Sberbank will not abandon any of its projects. But some projects will be in 2015, according to Nikita Volkov, "calendarized", that is, postponed to the next years. So, approximately 10% of the total budget for the development of IT technologies in the bank will be attributed to the costs of 2016.
“We looked at what projects could be postponed to next year, and found it possible to move several projects to 2016,” Volkov said. According to him, the same thing happened in a number of other areas, including construction, he added.
The bank is designing a second Data Processing Center (DPC), said Nikita Volkov. He noted that the design of the data center is underway. Skolkovo is one of the locations. But a concrete decision on the location and start of construction has not been received. It was planned to start construction in 2016.
Sberbank already has one data center - Yuzhny Port, which was launched on November 12, 2011. This project was called the largest banking data center in Eastern Europe... According to Volkov, Sberbank is a very large international structure, in fact, an IT company with banking license... The bank's IT development strategy was adopted at the end of 2013, and since the beginning of its implementation, the bank's indicators have significantly increased. Thus, the bank's unified retail center serves over 9.9 million customers and handles over 1.5 million transactions a day. The system for servicing clients from the small and medium-sized business sector employs more than 800 thousand active clients and processes more than 900 thousand documents per day, mobile bank about 15 million active clients use it, and more than 35 million SMS messages are sent per day. The bank also has a heavy load on processing, where more than 37 million transactions are performed per day on 126 million cards issued by the bank.
Nikita Volkov also dwelled on those issues that could not be resolved in the field of the bank's IT systems in 2014. The bank failed to manage complex portfolios of programs, build high-quality IT processes, and realize the reliability and scalability of critical systems. The strategic goals of Sberbank's IT block for the period up to 2018 will be maximum reliability, which guarantees the availability of all IT services, and flexibility, which ensures fast time-to-market for products by simplifying and standardizing technologies and business processes.
One of Sberbank's key programs is the implementation of the 99.99 program for the reliability of the bank's critical automated systems, which is scheduled to be completed in 2018. With an indicator of 99.99, the downtime of the bank's IT systems is no more than 52 minutes per year. Now the bank's reliability does not fall below the level of "99.5". Current results of the program implementation: the total downtime of the bank's critical systems has been reduced by four times, the downtime during technological works- 2.5 times, the number of incidents in systems - 2.4 times.
“The new mission of the bank's IT block is to support Sberbank as an efficient and reliable supplier of traditional banking services as well as a fast and innovative conductor of new services and revolutionary business models, both inside and outside the banking sector, ”said Nikita Volkov.
All systems of the bank have geo-redundancy. In addition to its own data center, in which the briefing took place, and plans to build its own second data center, two more leased data centers of the bank are now operating. The bank processes 2 thousand transactions per second only on the territory of Russia. Any client's appeal to an ATM when withdrawing money is confirmed in two data centers of the bank. If it happens that an abnormal situation occurs at once in these two data centers, then the third data center is involved, and the time to process the transaction takes 26 seconds, which, of course, goes unnoticed by the client.
In addition, Sberbank is exploring the possibility of import substitution in the information technologies, said the chief IT architect of the bank and its vice president Andrey Khlyzov.
“We are working on import substitution on a number of infrastructure elements. There is an alternative for database management systems, but they will not necessarily be Russian, ”Khlyzov said. So he answered the question of whether Sberbank plans to abandon the development of the American corporation Oracle.
According to Nikita Volkov, outside interference in the bank's databases is impossible. “In any scenario, no changes to our systems can be made from the outside without our control,” Volkov said. True, there are certain risks that foreign IT companies will refuse to support equipment already supplied to Russia. “This will dramatically increase the demands on our own team,” he added.
Andrey Khlyzov also said that the bank is working on creating a single centralized IT platform for the bank called Centralization 2.0. The program is designed for 4 years and employs 32 thousand people. Program for this moment applies only to the territory of Russia and has already reached payback. So, by 2015, none of the territorial banks of Sberbank left separate IT systems - by the end of 2014, everything was transferred to the mega data center. The last in the mega data center were the data processing systems of the northeastern bank (Magadan, Chukotka and Yakutia), where communication channels in the national sense are generally poor, and the systems worked through satellite communications. “So, just one satellite was replaced by another,” said Nikita Volkov.
At the same time, in December 2014, several landslide days were recorded in Sberbank - in terms of the volume of demand for services, first of all, for withdrawing money from cards. “But even these days, there were no cases that were critical for the bank or even very complicated from the point of view of IT systems,” Volkov said. True, these days have revealed the bank's weaknesses - somewhere these are communications, somewhere - the relationship between systems (the so-called "bus"), somewhere the narrowness of communication channels. “December 2014 was a good test for checking the performance of Sberbank,” said Nikita Volkov.
At the Siberian Bank PJSC Sberbank a new deputy chairman, Maxim Volkov, has been appointed. Now he is in charge of the Retail Business block. In an interviewStatus Maxim Volkov told why he does not limit his career horizon and whether it is possible, while working at Sberbank, not to be a workaholic.
- Sberbank is practically the only place of work in your career. How did it happen?
This is indeed the case. True, the first entry in my work book is not connected with Sberbank - I started work in a small company, but stayed there for only a few months. My entire career path, all development took place at Sberbank. This year marks twenty years of my work in this structure.
How did it all happen? I was offered to participate in the competition for the position of “chief dealer of resource management of Altai Bank”. I won this competition, despite the fact that out of five applicants I was the only candidate from the street with no bank experience. For two days I read literature intensively, day and night. Knowledge of the English language helped, since the information was not so available then, and I was able to demonstrate a good knowledge of the current trends in the financial sector.
- How old were you then?
I was 24 years old.
- So you started in the late nineties. This is not an easy time for the banking sector.
I came to work at the bank on August 13, 1998. And on Monday, August 17, there was a reset of all banking and financial histories, due to the moratorium on the repayment of external and domestic debt Russian Federation... The dollar was growing, stocks and bonds were falling, and I had the position of the main dealer! By the way, there was a mistake in my ID, the word dealer was written with two letters "l" - almost like a killer. And it was funny to be the main dealer at a time when some markets practically ceased to exist.
The position was later renamed several times, the functionality changed, but, nevertheless, I worked in this direction for almost seven years. If you look at my computer screen, you will immediately understand that I still cannot live without it. I cannot exist without seeing online all the main parameters of the financial market.
Let's talk about career success. What are your most significant achievements, and what preceded them?
Such complex issue... It does not happen with us that a person works, works, develops, develops, and then once - success comes. At Sberbank, we work every day for a result that we will see much later. Relatively speaking, if in this quarter we got an excellent result, it means that a year ago we did a good job. This is a long chain of correct decisions that were made by people in different positions, in different territories, and so on.
Answering your question, I want to say that I have not had any lightning-fast personnel changes in my career. I worked at each position for a long time, came to certain results and after that I started further. In the first position I worked for seven years, in the second five, then four years, and in the last three - life is accelerating.
If you want to develop and succeed, you need to be a workaholic. Successful people live in a mode of continuous self-development.
In a structure like Sberbank, is personalized success possible in principle, or is it always a team product?
Success here is always a 100% team result. If something does not work out, then the command mechanism has not developed. For me, a team is when people around them think the same way, speak the same language. It is an amazing feeling when your team is working like clockwork. By the way, I consider such moments to be potentially dangerous - you start to calm down, you lose your grip. Good teamwork is a sign that something needs to be changed.
- What is the main thing for you when forming a team? How do you design it?
First, effective communication is essential. Secondly, a team cannot definitely be called a team if it has no goal. That is why in all the previous stories I have created a situation of overcoming a certain crisis. First, we say: "Guys, everything is bad with us," then we look for a solution and generate a goal. If the team “buys” this story, accepts it, then the real work on the result begins without delays and shirking.
- Without days off and holidays?
Sometimes it does.
- In general, is it possible, while working at Sberbank, not to be a workaholic?
No ( laughs). If you want to develop and succeed, then, of course, you need to be a workaholic. We exist in a multitasking mode: everything around us is constantly changing and we need to catch up with this world every day. Successful people live in a mode of continuous self-development. Today it is a luxury to just run on a treadmill - at this moment you need to watch or listen to something so that time does not go to waste. You can watch financial news in English on Bloomberg, listen to a book from the Sberbank library, read something. Many things have to be "paralleled", otherwise you won't be able to do anything.
How in this rhythm, in this bustle, do you find a balance between work and family? I know you have three children. Do they have some kind of fixed, legal time for dad?
There are no standards, no templates. Most of the time for family and hobbies is the weekend. I'm a morning person, and it's a common thing for me to get up at four in the morning. The family wakes up at nine. By this time, I have time to go fishing, and hunting, and do sports, and all the rest of the hours - with the children.
- I know that you are running. At what point did you realize that you need it?
In the third grade, in the first physical education lesson. I remember we jumped in length, and I jumped three meters sixty centimeters. That evening I was called to workout, and since then I have been running. To be honest, I feel pleasure when I realize that I am in good shape. A belly hanging over a belt is for me a story of wild discomfort, although there was such a period in my life too. Today, daily sports are my constant. If the weight goes down, I go to the gym, if up - welcome to the treadmill.
This is the very moment when you have to be tough and say: “Get up! It's time to go to the gym! " In this sense, the “I” internal and external should also be a team working for the result.
- You said that a team cannot exist without a goal. What tasks do you set for yourself? How difficult are they?
If we are talking about a career, then over the years I realized that there are no unattainable goals in this plane. I remember that once in the Altai Territorial Bank the position of deputy chairman was the ultimate dream. In those days, vice-chairmen were literally demigods for me. And later I calmly stepped over this position. The only downside is that, having taken a position that you never dreamed of, you find it difficult to set yourself the next goal.
- What exactly will happen here with your arrival? What will you do?
For me, the key things are the growth of the business and the growth of our efficiency. Different territories are different components of overall success. Somewhere this is a story of growth, somewhere changes in formats, optimization. But in general, this is a strategy of growth in the market, involvement in all the changes that are taking place. The challenge is to be at the forefront of these changes. This can only be done with the right team that has shared common goals. Today we are starting to introduce a number of fine-tuning in the retail business. If in general strokes, then this is a strategy of growth, rapid and high-quality implementation of changes, new technologies and technological innovations.
I always tell myself and those people who think that they are doing well that today's point is not the point from which I want to retire. There is still a lot to come. My personal strategy: eat less and run more. By the way, it fits well on the topic of business. Today you need to generate less costs, consume less resources and run more after clients, for results.
Julia Dorn
Sberbank's cybersecurity service invites you to visit a series of events and learn from leading experts how theory is applied in practice ( https: //sberbank-talents.ru/Info/cy ...)
After reading clever books and listening to many courses on information security and everything connected with it, an employee in charge of information security grows wings: he builds an ideal picture of the world in his head and, rolling up his sleeves, tries to "pull" it onto the object entrusted to him ... But after a while, it turns out that no one needs information security standards, “best practices” do not actually work, over-current information security risks are not realized for years, it’s easier to pay a fine for non-compliance with legislation, and the information security officer himself is not at all an authority for other departments. Such an attitude cuts the wings of an information security officer, his hands drop, he becomes angry and all he can do is generate "sticks" for reporting to the management. At the master class, you will learn how the presenter went through all this, what mistakes he made and how he got out of difficult situations what saved him from turning into a "stick generator" and how he managed to make information security an integral part of the business and life of employees in his company. No boring theory - just fun practice!
Dates: 10.12.2016
- who needs laws, standards and “best practices”? Three points of view: information security, IT and business;
- "IB-waste paper": why does what you have developed not work?
- how to become an information security politician in an organization and why is it needed;
- separation of powers as a major stumbling block;
- assessment of information risks: a process elevated to the degree of absurdity;
- classification of information assets and assessment of their value: dancing with a tambourine or real benefits?
- differentiation of access to information as an object of fierce hatred on the part of "advanced businessmen";
- personnel safety: we check potential ones, monitor current ones and fire “former” ones;
- raising awareness of employees in the field of information security, or how to organize happy holidays in kindergarten;
- "What are you getting paid for?" Performance indicators that satisfy everyone;
- "What if everything is done?" Professional degradation of the information security officer, and how to avoid it.
Alexey Volkov, Managing Director-Head of the Department of Information Security Standards and Processes of Sberbank
About the author: Graduated from the Cherepovets Military Engineering Institute of Radio Electronics, specializing in radio equipment. For most of his career, he worked in the Severstal group of companies, where he recently held the position of Head of Information Security Operations Department at Severstal Management JSC. He is married and has a son and daughter. Leads an active lifestyle, goes in for sports, loves to travel, is fond of music. He has published 54 articles on professional topics, regularly makes reports and conducts master classes at specialized conferences. In 2014, he was recognized as the best leader in the field of information security according to the expert community of the Business Information Security Association and the Job.ru website.