ارائه مدل امنیت سایبری در بانکداری الکترونیک با رویکرد آمیخته

نوع مقاله : مقاله پژوهشی

نویسندگان

1 گروه مدیریت فناوری اطلاعات، واحد تهران مرکزی، دانشگاه آزاد اسلامی، تهران، ایران

2 گروه مدیریت بازرگانی، واحد تهران مرکزی، دانشگاه آزاد اسلامی، تهران، ایران

3 گروه مدیریت دولتی، واحد تهران مرکزی، دانشگاه آزاد اسلامی، تهران، ایران

4 گروه مدیریت مالی و حسابداری، واحد تهران جنوب، دانشگاه آزاد اسلامی، تهران، ایران

چکیده

این پژوهش به صورت آمیخته (کیفی-کمی) انجام شد. روش تحقیق در بخش کیفی بر مبنای هدف، بنیادی بود. تحلیل داده­ها در بخش کیفی با استفاده از رویکرد گرندد تئوری انجام شد. جامعه آماری، شامل 15 نفر از خبرگان حوزه بانکداری الکترونیک و امنیت سایبری بودند. روش نمونه­گیری از نوع هدفمند بود. ابزار گردآوری داده، مصاحبه­های نیمه ساختاریافته با پرسش­های نیمه­باز پاسخ بود. روش تحقیق در بخش کمی از نظر هدف، کاربردی (در بانک ملت) بود و از منظر اجرا از نوع توصیفی پیمایشی بود. برای تحلیل داده­ها از روش معادلات ساختاری استفاده ‌شد. جامعه آماری، شامل کلیه کاربران استفاده کننده از بانکداری الکترونیک بانک ملت بود. جهت تعیین حجم نمونه از فرمول کوکران در جوامع نامحدود استفاده شد که برابر با 384 نفر بودند. روش نمونه­گیری از نوع تصادفی بود و از پرسشنامه محقق­ساخته استفاده گردید. در این تحقیق، نتایج داده‌های کیفی به نتایج داده‌های کمی در توسعه و آزمون مدل کمک کرد. بررسی مطالعات نشان داد که شکاف نوظهوری بین اقدامات بانک‌ها و انتظارات کاربران وجود دارد و در تحقیقات موجود تأثیر برخی از فناوری های جدید در بانکداری الکترونیک بر امنیت سایبری بررسی نشده است. این پژوهش، با شناسایی عوامل و شرایط موثر و تعیین متغیرهای مهم امنیت سایبری، این شکاف را برای اقدامات بانک‌ها در کاهش ریسک‌های امنیت سایبری برای کاربران، پر کرد و در نهایت یک مدل امنیت سایبری جامع، کارآمد و بومی را برای بانکداری الکترونیک ارائه کرد که ضمن پوشش ابعاد فنی، مدیریتی و انسانی بتواند اعتماد مشتریان را افزایش داده و هزینه ها را کاهش دهد. نتایج نشان داد که استفاده از فناوری‌های نوین مانند بلاک‌چین و یادگیری ماشین، به همراه شناسایی رفتارهای کاربران و فرهنگ سازمانی، می‌تواند به بهبود امنیت و افزایش اعتماد مشتریان به خدمات بانکداری الکترونیک کمک کند.

کلیدواژه‌ها


عنوان مقاله [English]

A Cybersecurity Model in Electronic Banking with a Mixed-Methods Approach

نویسندگان [English]

  • Hossein Babaee 1
  • Mansoreh Aligholi 2
  • Daryoush gholamzadeh 3
  • Mohammadreza Radfar 4
1 Department of Information Technology Management, CT.C., Islamic Azad University, Tehran, Iran
2 گروه مدیریت بازرگانی، واحد تهران مرکزی، دانشگاه آزاد اسلامی، تهران، ایران
3 گروه مدیریت دولتی، واحد تهران مرکزی، دانشگاه آزاد اسلامی، تهران، ایران
4 گروه مدیریت مالی و حسابداری، واحد تهران جنوب، دانشگاه آزاد اسلامی، تهران، ایران
چکیده [English]

This study was conducted using a mixed-methods approach (qualitative-quantitative). The qualitative phase was fundamental in purpose, and data analysis employed the grounded theory approach. The statistical population consisted of 15 experts in electronic banking and cybersecurity, selected through purposive sampling. Data were collected via semi-structured interviews with open-ended questions.
The quantitative phase was applied in purpose (conducted at Bank Mellat) and descriptive-survey in execution. Data were analyzed using structural equation modeling. The statistical population included all users of Bank Mellat’s electronic banking services. The sample size was determined using Cochran’s formula for infinite populations, resulting in 384 participants, selected through random sampling and surveyed using a researcher-designed questionnaire.
In this study, qualitative findings informed the quantitative phase in developing and testing the model. The review of literature indicated a gap between the banks’ current measures and user expectations, and the impact of certain emerging technologies in electronic banking on cybersecurity had not been fully examined. By identifying effective factors and determining key cybersecurity variables, this study addressed the gap and proposed a comprehensive, efficient, and localized cybersecurity model for electronic banking. This model covers technical, managerial, and human dimensions, aiming to enhance customer trust while reducing costs. The results showed that the use of emerging technologies such as blockchain and machine learning, combined with user behavior analysis and organizational culture, can improve security and increase customer confidence in electronic banking services

کلیدواژه‌ها [English]

  • Electronic Banking
  • Cybersecurity
  • Cyber Threats
  • Emerging Technologies
  • Paradigmatic Model
آپرناک، آرش و گازری نیشابوری، آرزو و سراج بردیا (۱۴۰۱)،  رابطه بین امنیت ادراک شده و اعتماد مشتریان به سیستم بانکداری الکترونیک مبتنی بر رویکرد NFC-Mobile، پنجمین کنفرانس بین­المللی مطالعات بین رشته­ای در مدیریت و مهندسی، 674-691
احمدی، سعیده،(1402)، راهبردهای توسعه اقتصاد دیجیتال در ایران، ماهنامه علمی امنیت اقتصادی، 11(4)، 4-16 https://civilica.com/doc/1717234
افراشته، نسرین و محمدی، افسانه و آهنگری، آرام و آسور، امی،(1403)، بررسی چالش­ها و راهکارهای امنیت سایبری در دنیای امروز، دومین کنفرانس بین­المللی پژوهش­های مدیریت، تعلیم و تربیت در آموزش و پرورش، تهران، https://civilica.com/doc/2039579
باطنی، زهره و شاهی قره بلاغ، پرویز،(1390)،مدیریت فناوری امنیت اطلاعات،اولین همایش تخصصی سیستمهای هوشمند کامپیوتری و کاربردهای آنها،تهران،https://civilica.com/doc/139258
شکرزهی، مبین و حسین­بر، بهمن و حسین­بر، معصومه و ارباب ناهوک، عنبرخاتون،(1402)، نقش امنیت سایبری در آموزش فناوری اطلاعات، پانزدهمین کنفرانس بین­المللی پژوهش­های مدیریت و علوم انسانی در ایران، تهران، کنفرانس مدیریت و تحقیقات علوم انسانی در ایران، 15(15)، 775-780،https://civilica.com/doc/2013859
طهماسبی آقبلاغی، داریوش و سلطانی، مرتضی و شهبازی، میثم و اوضاعی، افسانه(1400)، ارائه چارچوب همکاری راهبردی بین نظام بانکی خصوصی و فین­تک­ها در ایران، مدیریت توسعه فناوری, 9(1)، 41-66. doi: 10.22104/jtdm.2021.4781.2761
عسکری، مریم و مدیری، ناصر، (1399) ، معماری خودارزیابی امنیت سایبری، چهارمین کنفرانس ملی پژوهشی کاربردی در علوم برق و کامپیوتر و مهندسی پزشکی. https://civilica.com/doc/1016778
کاویانی، حسن و میرسپاسی، ناصر،(1400)، طراحی مدل قابلیت­های سازمانی در حوزه امنیت سایبری، مطالعات راهبردی بسیج، 24(92)، 121-151،https://civilica.com/doc/1472913
مازندرانی، علی و خیرآبادی، محمدتقی و بزازی، امین،(1400)، یک پروتکل احراز هویت سبک وزن آگاه از مکان برای اینترنت اشیا، مجله علمی محاسبات نرم و فناوری اطلاعات، 12(4)، 12-22.،https://civilica.com/doc/1447733
موسوی، سید احمد، (1403)، بررسی تاثیر ابعاد عینی امنیت سیستم­های پرداخت الکترونیکی با واسطه درک مشتریان از امنیت و اعتماد (مطالعه موردی: شعب بانک ملی استان کهگیلویه و بویراحمد)، https://civilica.com/doc/1976050
وجدانی، بنفشه، (1403)، بررسی اثرگذاری حریم خصوصی و امنیت خدمات بانکداری الکترونیک بر وفاداری مشتریان بانکی با تاکید بر قابلیت اطمینان، اولین کنفرانس بین­المللی مدیریت، مهندسی صنایع، حسابداری و اقتصاد در علوم انسانی،  https://civilica.com/doc/2025680
نگهدار، ایرج و پورقهرمانی، بابک و بیگی، جمال،(1402)، رهیافت­های پیشگیری وضعی سیاست جنایی ایران در قبال نقض امنیت سایبری در پرتو اسناد بین المللی، سیاست عمومی، 9(2)، 97-114، https://civilica.com/doc/1654075
Adedoyin Tolulope Oyewole, Chinwe Chinazo Okoye, Onyeka Chrisanctus Ofodile & Chinonye Esther Ugochukwu, (2024), Cybersecurity risks in online banking: A detailed review and preventive strategies application, World Journal of Advanced Research and Reviews 21(3):625-643, https://doi.org/10.30574/wjarr.2024.21.3.0707
Admass, W. S., Munaye, Y. Y., & Diro, A. A., (2024), Cyber security: State of the art, challenges and future directions. Cyber Security and Applications, 2, 100031. https://doi.org/10.1016/j.csa.2023.100031
Aldahidhavi, H. M. K., Abdulreza, J. Z. S., Sebai, M., & Harjan, S. A., (2020), An efficient model for financial risks assessment based on artificial neural networks. Journal of Southwest Jiaotong University, 55(3). https://doi.org/10.35741/issn.0258-2724.55.3.8
Al-khawaja, H. A., & Aburub, F. A. (2025). Blockchain for Securing Data Storage in Digital Banking Services. SN Computer Science, 6(1), 56
Anwaar, S., (2024), Harnessing Large Language Models in Banking: Banking Innovation with Operational and Security Risks. World Journal of Advanced Engineering Technology and Sciences, 13(1), https://dx.doi.org/10.30574/wjaets.2024.13.1.0426
Ayinaddis, S. G., Mirete, T. G., & Getahun, B. W. (2025). Evaluating the factors influencing electronic banking adoption in Ethiopia: analysis from customer perspective. Journal of Innovation and Entrepreneurship, 14(1), 56
Bixhaku, S., Polo, A., Zyberi, I., & Caca, E. (2025). Electronic banking risks: Challenges, security concerns, and mitigation strategies. Sustainable Regional Development Scientific Journal, 2(1), 44-53
Cele, N. N., & Kwenda, S. (2025). Do cybersecurity threats and risks have an impact on the adoption of digital banking? A systematic literature review. Journal of Financial Crime, 32(1), 31-48
Creado, Y., & Ramteke, V., (2020), Active cyber defence strategies and techniques for banks and financial institutions. Journal of Financial Crime, 27(3), 771-780. https://doi.org/10.1108/JFC-01-2020-0008
Evren, R., & Milson, S., 2024, The Cyber Threat Landscape: Understanding and Mitigating Risks. Tech. rep. EasyChair.
Goering, S., Beck, A., Dorfman, N., Schwarzwalder, S., & Wohns, N., (2024), Privacy protections in and across contexts: why we need more than contextual integrity. AJOB neuroscience, 15(2), 149-151. https://doi.org/10.1080/21507740.2024.2326932
Kenney, Martin & Patton, Donald, (2005), Entrepreneurial Geographies: Support Networks in Three High‐Technology Industries, Economic Geography 81(2):201 - 228, DOI:10.1111/j.1944-8287.2005.tb00265.x
Kabir, M. S., & Alam, M. N., (2023), IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A Review. International Research Journal of Engineering and Technology (IRJET), 10(05), 1777-1789.
Kim, Y., Park, Y. J., Choi, J., & Yeon, J., (2015), An empirical study on the adoption of “Fintech” service: Focused on mobile payment services. Advanced Science and Technology Letters, 114(26), 136-140, http://dx.doi.org/10.14257/astl.2015.114.26
Kraus, S., Jones, P., Kailer, N., Weinmann, A., Chaparro-Banegas, N., & Roig-Tierno, N., (2021), Digital transformation: An overview of the current state of the art of research. Sage Open, 11(3), 21582440211047576, https://doi.org/10.1177/21582440211047576
Kumar, M., (2023), An overview of cyber security in digital banking Sector. East Asian Journal of Multidisciplinary Research, 2(1), 43-52, https://doi.org/10.55927/eajmr.v2i1.1671
Mehenaj Jerin Mohona, 2024, Emerging cyber security threats in banking sector; Loopholes and solutions in the eye of law, International Journal of Law, International Journal of Law, Volume 10, Issue 3, 2024, Page No. 214-219
Najaf, K., Schinckus, C., Mostafiz, M. I., & Najaf, R., (2020), Conceptualising cybersecurity risk of fintech firms and banks sustainability. https://shura.shu.ac.uk/id/eprint/27504
Parlour, Richard & Bouyon, Sylvain & Krause, Simon, (2018), Cybersecurity in finance: Getting the policy mix right. Rowman & Littlefield
Reis, O., Oliha, J. S., Osasona, F., & Obi, O. C., (2024), Cybersecurity dynamics in Nigerian banking: trends and strategies review. Computer Science & IT Research Journal, 5(2), 336-364. https://doi.org/10.51594/csitrj.v5i2.761
Rohan, R., Pal, D., Hautamäki, J., Funilkul, S., Chutimaskul, W., & Thapliyal, H., (2023), A systematic literature review of cybersecurity scales assessing information security awareness. Heliyon, 9(3), https://doi.org/10.1016/j.heliyon.2023.e14234
Sadlakowski, D., & Sobieraj, A., (2017), The development of the FinTech industry in the Visegrad group countries. World Scientific News, 85, 20-28.
Selvaraj Nagasundari, (2021), The essence of cybersecurity through fintech 3.5 in preventing and detecting financial fraud: a literature review, Electronic Journal of Business and Management (Volume 6, No. 2, 2021, Pages 18 to 29)
Shaikh, A. A., Glavee-Geo, R., Karjaluoto, H., & Hinson, R. E., (2023), Mobile money as a driver of digital financial inclusion. Technological Forecasting and Social Change, 186, 122158. https://doi.org/10.1016/j.techfore.2022.122158
Shakeel, waria & Mardani, Abbas & Gholamzadeh, Abdoulmohammad, Ariani Goni, Feybi, (2020), Anatomy of sustainable business model innovation, Journal of Cleaner Production, DOI:10.1016/j.jclepro.2020.121201
Sharma, L. R., Bidari, S., Bidari, D., Neupane, S., & Sapkota, R., (2023), Exploring the mixed methods research design: types, purposes, strengths, challenges, and criticisms. Glob Acad J Linguist Lit, 5. 10.36348/gajll. 2023.v05i01.002
Tristan Lim, Patrick Thang, (2021), Outsourcing life cycle model for financial services in the fintech era. https://ink.library.smu.edu.sg/sis_research/6116/
Van Voorhis, C., Hatcher, W., Kalat, T., Wang, Y., & Hammad, E., (2024), Towards an Automated Cybersecurity Risk Assessment of Next Generation Emergency Communication Networks-NG911. In 2024 IEEE World Forum on Public Safety Technology (WFPST) (pp. 175-181). IEEE, https://doi.org/10.1109/WFPST58552.2024.00042
Widodo, D. P., Syah, T. Y. R., & Negoro, D. A., (2020), Digital Channel and Customer Satisfaction on Financial Services. Journal of Multidisciplinary Academic, 4(3), 159-163. https://www.kemalapublisher.com/index.php/JoMA/article/view/461
Yiu Ting Yan Azura, Muhammad Ajmal Azad & Yussuf Ahmed, (2025), An integrated cyber security risk management framework for online banking systems, Journal of Banking and Financial Technology, https://doi.org/10.1007/s42786-025-00056-3
Zhuang, P., Zamir, T., & Liang, H., (2020), Blockchain for cybersecurity in smart grid: A comprehensive survey. IEEE Transactions on Industrial Informatics, 17(1), 3-19. https://doi.org/10.1109/TII.2020.2998479