<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MKB Archives - SustainCase - Sustainability Magazine</title>
	<atom:link href="https://sustaincase.com/tag/mkb/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Insights on how you can protect the environment, maintain and increase the value of your company, through a structured CSR/Sustainability process with the use of the GRI Standards. Learn how Today&#039;s Best-Run Companies are achieving Economic, Social, and Environmental Success - and How You Can Too...</description>
	<lastBuildDate>Wed, 28 May 2025 06:41:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
	<item>
		<title>Case study: How MKB works with its clients and customers to encourage sustainable practices</title>
		<link>https://sustaincase.com/case-study-how-mkb-works-with-clients-and-customers-to-encourage-sustainable-practices/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Wed, 28 May 2025 05:53:28 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Principle 3: Clients and Customers]]></category>
		<category><![CDATA[Principle 4: Stakeholders]]></category>
		<category><![CDATA[Principles for Responsible Banking]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[MKB]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://sustaincase.com/?p=20730</guid>

					<description><![CDATA[<p>CREDIT BANK OF MOSCOW (MKB) ranks among the largest non-state public banks in Russia and has been recognized as a systemically important financial institution since 2017. MKB operates throughout Russia with a regional network of over 93 branches, offering a comprehensive array of banking services to corporate clients, small and medium-sized enterprises (SMEs), and individual customers, which includes private banking services. The bank serves more than 45,000 corporate clients and over 810,000 private clients. This case study is based on the 2023 PRB Report by MKB, prepared in relation to its implementation of the PRB, that can be found at this [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-mkb-works-with-clients-and-customers-to-encourage-sustainable-practices/">Case study: How MKB works with its clients and customers to encourage sustainable practices</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>CREDIT BANK OF MOSCOW (MKB) ranks among the largest non-state public banks in Russia and has been recognized as a systemically important financial institution since 2017. MKB operates throughout Russia with a regional network of over 93 branches, offering a comprehensive array of banking services to corporate clients, small and medium-sized enterprises (SMEs), and individual customers, which includes private banking services. The bank serves more than 45,000 corporate clients and over 810,000 private clients. <strong>MKB is a signatory of the Principles for Responsible Banking (PRB) and is, accordingly, working with its clients and customers to encourage sustainable practices and enable sustainable economic activities.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=MKB%20is%20a%20signatory%20of%20the%20Principles%20for%20Responsible%20Banking%20%28PRB%29%20and%20is%2C%20accordingly%2C%20working%20with%20its%20clients%20and%20customers%20to%20encourage%20sustainable%20practices%20and%20enable%20sustainable%20economic%20activities.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-mkb-works-with-clients-and-customers-to-encourage-sustainable-practices%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a></p>
<p><strong>This case study is based on the</strong><strong> 2023 </strong><strong>PRB Report </strong><strong>by</strong> <strong>MKB</strong><strong>,</strong> <strong>prepared </strong><strong>in relation to its implementation of the PRB, that can be found at this </strong><a href="https://ir.mkb.ru/en/sustainability/disclosures/reports" target="_blank" rel="noopener"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img fetchpriority="high" decoding="async" class="tie-appear alignnone wp-image-1719" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" alt="Layout 1" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<p><strong>Which </strong><strong>Principles for Responsible Banking have been addressed? </strong></p>
<p>The Principles for Responsible Banking addressed in this case are:</p>
<ul>
<li style="list-style-type: none;">
<ul>
<li style="list-style-type: none;">
<ul>
<li><strong>Principle 3: Clients and Customers</strong>
<ul>
<li><a href="https://www.unepfi.org/prb-reporting-and-self-assessment-template/" target="_blank" rel="noopener">3.1 Client engagement</a></li>
</ul>
</li>
</ul>
<ul>
<li><strong>Principle 4: Stakeholders</strong>
<ul>
<li><a href="https://www.unepfi.org/prb-reporting-and-self-assessment-template/" target="_blank" rel="noopener">4.1 Stakeholder identification and consultation</a></li>
</ul>
</li>
</ul>
</li>
</ul>
</li>
</ul>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li style="list-style-type: none;">
<ul>
<li style="list-style-type: none;">
<ul>
<li>How MKB proceeded with <strong><strong>stakeholder <strong>identification and consultation</strong></strong></strong>, and</li>
<li><strong>How MKB worked with its clients and customers</strong> to encourage sustainable practices and enable sustainable economic activities</li>
</ul>
</li>
</ul>
</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>Stakeholder identification and consultation</strong></p>
<p><em>Please describe which stakeholders (or groups/ types of stakeholders) you have identified, consulted, engaged, collaborated or partnered with for the purpose of implementing the Principles and improving your bank’s impacts. This should include a high-level overview of how your bank has identified relevant stakeholders, what issues were addressed/results achieved and how they fed into the action planning process</em>.</p>
<p>MKB regularly identifies and updates its stakeholder list each year, evaluating their influence on the Bank and their reliance on MKB&#8217;s performance (impact level).</p>
<p>In 2023, MKB recognized 12 primary stakeholder groups: shareholders and investors, employees, clients, suppliers and contractors, governmental authorities, regulatory bodies (the Bank of Russia), financial institutions, professional and expert communities, rating, ranking and ESG agencies, local communities, nonprofit organizations, and the media.</p>
<p>For each stakeholder category, the Bank employs specific communication channels to effectively ascertain their needs.</p>
<p>To evaluate the effectiveness of its stakeholder communication, MKB periodically conducts satisfaction surveys. Furthermore, the Bank conducts annual surveys to gauge the importance of material topics, which are later reported in the Bank’s annual reports.</p>
<p>The main channels, methods, and outcomes of stakeholder interactions in 2023 are detailed in the corresponding section of MKB’s Annual Report.</p>
<p><strong><a href="https://fbrh.co.uk/get-in-touch/" target="_blank" rel="noopener"><img decoding="async" class="alignright" src="https://sustaincase.com/wp-content/uploads/2024/04/UK-Principles-for-responsible-banking-PRB-assurance-iso9001-fbrh-uk-ISAE3000-ESG-GRI-SASB-ESRS.jpg" alt="" width="739" height="388" /></a></strong></p>
<p><strong>How did</strong> <strong>MKB </strong><strong>work with its clients and customers to encourage sustainable practices and enable sustainable economic activities? </strong></p>
<p>In its 2023 PRB Report MKB reports that it works with its clients and customers to encourage sustainable practices and enable sustainable economic activities as follows:</p>
<p>MKB aims to adopt a responsible approach in its dealings with clients, suppliers, and business partners.</p>
<p>To foster sustainable practices among its corporate clients and manage potential negative impacts, the Bank developed its Environmental and Social (E&amp;S) Procedure in 2021 and updated it in 2023.</p>
<p>Additionally, the Bank approved its Responsible Investment Policy during the reporting year.</p>
<p>Both the E&amp;S Procedure and the Responsible Investment Policy outline several measures for addressing the E&amp;S aspects of clients’ negative impacts, including:</p>
<ul>
<li>A commitment to refrain from providing financial support to projects or borrowers engaged in sectors deemed to have an unacceptable level of negative impact, as detailed in the E&amp;S exclusion/restrictive list.</li>
<li>Stricter requirements for Category A projects (those with significant adverse environmental and social risks) in line with the Bank’s approved model list of such projects.</li>
</ul>
<p>By developing its ESG finance framework, MKB aims to encourage clients to reduce their negative environmental and social impacts and support the shift towards sustainable development.</p>
<p>By assessing the ESG risks of its borrowers, recommending measures to enhance their environmental and social responsibility and offering green financing, MKB facilitates their transition to a sustainable and responsible business model.</p>
<p>MKB has established a set of bylaws for suppliers and contractors to promote sustainable practices, including:</p>
<ul>
<li>Supplier and Contractor Code of Conduct</li>
<li>Procedure for Managing Environmental and Social Impact during Design and Procurement Stages</li>
<li>Code of Corporate Ethics</li>
<li>Anti-Corruption Policy</li>
</ul>
<p>In 2024, MKB planned to revise its current E&amp;S, Health and Safety (H&amp;S), and Energy Efficiency &amp; Conservation (EE&amp;C) Integrated Management System Policy or develop a comprehensive Sustainability Policy.</p>
<p>&nbsp;</p>
<p class="norm mb10 mob_centr"><strong>UN Principles for Responsible Banking: Accelerating a positive global transition for people and the planet</strong></p>
<p class="norm mb50 mob_centr">With over 300 signatory banks representing almost half of the global banking industry, the Principles for Responsible Banking are the world’s foremost sustainable banking framework. Through these Principles, the banking community takes action to align core strategies, decision-making, lending and investment with the UN Sustainable Development Goals and international agreements such as the Paris Climate Agreement.</p>
<p class="norm mb20"><a href="https://fbrh.co.uk/principles-responsible-banking-assurance/" target="_blank" rel="noopener"><strong>FBRH Principles for Responsible Banking (PRB) Assurance</strong></a>:</p>
<p class="norm mb10 mob_centr">First class PRB assurance services: The result of solid, hands-on ESG/ Sustainability experience</p>
<ul>
<li style="list-style-type: none;">
<ul>
<li style="list-style-type: none;">
<ul>
<li class="norm mb10 mob_centr">FBRH is a GRI Certified Training Partner (Global), ISEP Training Centre and a member of CPD.</li>
<li class="norm mb10 mob_centr">FBRH builds trust. Over <a href="https://www.fbrh.co.uk/reviews" target="_blank" rel="noopener">200 reviews from top professionals</a> from around the world demonstrate our ability to build strong, trusting business relationships.</li>
<li>FBRH possesses a unique skill set that combines ESG/sustainability certified training, experience in advisory services and report preparation, and ESG/sustainability report assurance.</li>
<li style="list-style-type: none;"></li>
</ul>
</li>
</ul>
</li>
</ul>
<p class="norm pb30 mob_centr">The combination of all the above empowers FBRH to provide first class Principles for Responsible Banking (PRB) assurance services.</p>
<p>&nbsp;</p>
<p>References:</p>
<p>This case study is based on published information by MKB, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original please revert to the following link:</p>
<p><a href="https://ir.mkb.ru/en/sustainability/disclosures/reports" target="_blank" rel="noopener">https://ir.mkb.ru/en/sustainability/disclosures/reports</a></p>
<p>Note to MKB: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-mkb-works-with-clients-and-customers-to-encourage-sustainable-practices/">Case study: How MKB works with its clients and customers to encourage sustainable practices</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How MKB promotes information security</title>
		<link>https://sustaincase.com/case-study-how-mkb-promotes-information-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 19 Feb 2021 07:06:09 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[MKB]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12264</guid>

					<description><![CDATA[<p>MKB is one of the largest private banks in Russia, offering a full package of financial services through a regional network that includes more than 130 offices in 19 regions. Adhering to the principles of socially responsible business conduct, This case study is based on the 2019 Sustainability Report by MKB published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-mkb-promotes-information-security/">Case study: How MKB promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>MKB is one of the largest private banks in Russia, offering a full package of financial services through a regional network that includes more than 130 offices in 19 regions. Adhering to the principles of socially responsible business conduct, <strong>MKB complies with both Russian and international laws on personal data processing and protection.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=MKB%20complies%20with%20both%20Russian%20and%20international%20laws%20on%20personal%20data%20processing%20and%20protection.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-mkb-promotes-information-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a></p>
<p><strong>This case study is based on the</strong><strong> 2019 Sustainability Report by</strong> <strong>MKB</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/80711/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>The design of MKB’s current and future processes and products assumes obtaining consents from customers, counterparties, and the bank’s employees for the processing of their personal data, for the minimum use of their data when in interaction between the employees and the bank’s systems, and for the provision of the “security by design” and “security by default” concepts. In order to promote information security MKB took action to:</p>
<ul>
<li>combat fraud</li>
<li>promote cybersecurity</li>
<li>identify and eliminate vulnerabilities</li>
<li>respond to information security incidents in a timely manner</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) MKB has identified;</li>
<li>How MKB proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by MKB to promote information security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified? </strong></p>
<p>In its 2019 Sustainability Report MKB identified a range of material issues, such as customer satisfaction, increasing the accessibility of services, economic efficiency, professional development and training of employees. Among these, promoting information security stands out as a key material issue for MKB.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups MKB engages with:</strong></p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Customers</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Customer service, including development of the network of branch offices</p>
<p>·      Receiving queries</p>
<p>·      Remote banking service (mobile banking, contact centre, internet banking)</p>
<p>·      Information about bank products, reporting, availability of branch offices of the Bank, environmental plans and actions, and other important information as published on the MKB website (Russian or English version)</p>
<p>·      Analysis of customer satisfaction</td>
</tr>
<tr>
<td width="135">Employees</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Advanced training</p>
<p>·      Benefits package</p>
<p>·      Support and assistance in developing internal corporate sports clubs and events for the company employees</p>
<p>·      Participation in sports events, charitable, and other public and environmental events</p>
<p>·      Corporate portal</p>
<p>·      The hotline that allows sending complaints and queries to the members of the Audit and Risk Committee under the MKB Supervisory Board</td>
</tr>
<tr>
<td width="135">Society</td>
<td width="344">·      Participation in social and environmental projects of the Russian Government, other governmental bodies, and development of its own projects</p>
<p>·      Development of financial products for different categories of people</p>
<p>·      Support of small and medium business entities</p>
<p>·      Development of a regional network of offices and creation of additional jobs in the regions</p>
<p>·      Interaction with higher educational institutions, probation programmes, training</td>
</tr>
<tr>
<td width="135">Shareholders and investors</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Meetings of shareholders</p>
<p>·      Communication using different channels (including conference calls, meetings, correspondence via email, webcasts)</p>
<p>·      Disclosure of information important for shareholders and investors on the electronic page for investors (in Russian and English)</p>
<p>·      Publication of financial and nonfinancial reports</td>
</tr>
<tr>
<td width="135">Counterparties and partners</td>
<td width="344">·      A transparent competitive procurement system</p>
<p>&nbsp;</td>
</tr>
<tr>
<td width="135">Governmental bodies and regulators</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Information disclosure and compliance with all legislative requirements in the field of banking activities</p>
<p>·      Participation in projects and work meetings on the improvement of laws in different areas (expert councils, work groups, round-table discussions, and other forms of communications)</p>
<p>·      Contribution to the development of regions with the extension of the regional network of presence</td>
</tr>
<tr>
<td width="135">Mass media</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Regular communications with the key media, prompt response to incoming questions</p>
<p>·      A high level of content mobility on the MKB website, in social networks, and other sources of communication</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics MKB engaged with its stakeholders through an interactive survey tool.</p>
<p><strong>What actions were taken by</strong> <strong>MKB</strong> <strong>to</strong> <strong>promote information security</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report MKB reports that it took the following actions for promoting information security:</p>
<ul>
<li><strong>Combating fraud</strong></li>
<li>MKB pursues a zero-tolerance policy toward illegal actions against its customers. For this purpose, MKB:
<ul>
<li>has implemented and maintains fraud monitoring processes for remote banking;</li>
<li>investigates any attempts of stealing funds from the bank’s customers;</li>
<li>interacts with the Bank of Russia and other credit institutions, communication service providers, and law enforcement agencies for the exchange of information about the actions of fraudsters and for the timely prevention of fraudulent activities;</li>
<li>implements the programme for enhanced protection of systems and data, which is reviewed annually and updated completely every three years.</li>
</ul>
</li>
<li>The above activities resulted in dozens of prevented attempts of stealing funds from legal entities and individuals, which saved them dozens of million rubles. The only loss by a legal entity because of the fraudster’s actions in the remote business education system (RBES) in 2019 amounted to RUB 3,000; the transaction was marked as suspicious but was additionally confirmed by the customer itself.</li>
</ul>
<ul>
<li><strong>Promoting cybersecurity</strong></li>
<li>MKB pays much attention to information security and resistance to cyber threats. The following biggest threats for MKB were identified within the frames of its information security strategy:
<ul>
<li>External attacks as a result of actions of hacker groups, which are aimed at stealing data or money via payment systems</li>
<li>Attacks aimed at customers and stealing customers’ funds via remote banking services</li>
<li>Fraudulent actions of the bank’s employees or counterparties, which may cause data leaks or thefts using authorised access to MKB’s information systems</li>
<li>Logical attacks at ATMs (use of special software for money disbursement without using cards and for debiting accounts) and payment terminals (use of special software to reload cards without cash)</li>
</ul>
</li>
<li>The following projects were initiated and successfully finished for the implementation of measures to prevent the materialisation of threats:
<ul>
<li>Implementation of the next generation firewall as a basic element of protection against external attacks</li>
<li>Implementation of a solution to counter targeted attacks made using malicious emails or malicious websites, which use 0-day vulnerabilities and are not detected by standard means of protection, for example, antivirus software (as a result of system operation, over 650 targeted attacked were repelled)</li>
<li>Implementation and development of the personnel training system simulating sending of malicious attachments and fishing links by hackers and appointing testing automatically if an employee opens such attachments or types a password to their account on the websites available at the fishing links</li>
<li>Development and implementation of an antifraud system to identify abnormal and illegal payments sent to the Bank of Russia or to the international data transfer and payment system SWIFT</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Identifying and eliminating vulnerabilities</strong></li>
<li>To minimise the probability of merely technical vulnerabilities typical of information systems and logical vulnerabilities affecting customer service processes and products, MKB started supporting the following processes in 2019:
<ul>
<li>External scanning of vulnerabilities; full coverage was reached for all 179 publications of MKB’s services on the web and external networks, scanning results are recognised by auditors as performed by the Approved Scanning Vendor as part of the PCI DSS (Payment Card Industry Data Security Standard) standard conformity audits.</li>
<li>A red team was set up—that is, a group of specialists with qualifications similar to hackers, whose main task is to conduct penetration tests and identify vulnerabilities through the eyes of hackers for the purpose of thorough identification of vulnerabilities that cannot be identified instrumentally.</li>
<li>The Information Security Department participates in, and controls, all tasks of IT development, including the following:
<ul>
<li>Analysis of business requirements</li>
<li>Analysis of technical assignments</li>
<li>Formation of a set of requirements for the implementation of security-by-design and security-by-default concepts for all services and products developed by MKB</li>
<li>Verification of the fulfilment of requirements before bringing the implemented tasks in action</li>
<li>Participation of red team specialists for the purpose of vulnerability analysis in any services published on the web and in any payment applications</li>
</ul>
</li>
<li>External penetration tests organised by the internal audit are performed by specialised companies with highly proficient specialists.</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Responding to information security incidents in a timely manner</strong></li>
<li>To monitor and provide timely response to information security incidents, MKB has a security incidents response team. In 2019, the work of this team, operating as part of the Information Security Department, resulted in the creation of the monitoring system architecture, implementation of the subsystem of collection and primary analysis of incidents, implementation of the incident response platform, and automation of the formation of any incidents as tasks for the team members in the implemented platform. The ongoing processes are built so that the time from the attack to the analysis of the processes within the attack and to the termination of the attack usually does not exceed 4 hours.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed?</strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by MKB, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to MKB: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-mkb-promotes-information-security/">Case study: How MKB promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
