Beyond the phish: Fortifying our culture against AI and supply chain threats

In an era where a single compromised dependency can affect an entire ecosystem, and AI can craft a perfect phish in seconds, cybersecurity awareness must transcend the basics.
This October at Deriv, we elevated our annual initiative to confront the sophisticated, interconnected threats that define the modern landscape. Our program was built on a dual focus: democratising security ownership and arming our teams with expert knowledge on the AI and supply chain frontiers.
As a leading online trading platform, our foundation is trust. This year’s activities were engineered to reinforce that trust by ensuring every member of our team is an active, informed participant in our collective defence.

Pillar 1: Building a culture of active defence
A security policy is only as strong as the culture that upholds it. We brought this principle to life with two highly engaging, hands-on competitions:
.png)

- The Security Ambassador challenge: This four-week, gamified program transformed security best practices into a company-wide competition. Through weekly, points-based missions, employees across all departments moved from passive learning to active participation, reinforcing the critical mindset that security is a shared responsibility.
- The AI Capture The Flag (CTF) challenge: To prepare our technical teams for the future, we built a custom AI CTF. The mission: think like an attacker. Participants were challenged to use prompt injection and model deception tactics to trick our AI into revealing secrets. It was a practical masterclass in adversarial thinking, building the muscle memory needed to secure the AI-integrated systems of tomorrow.
Pillar 2: Expert insights on today’s most critical threats
Hands-on practice must be informed by expert strategy. We hosted a series of town hall sessions, bringing in industry leaders and our internal experts to provide in-depth discussions on the most pressing threats facing our organisation.

- AI-powered social engineering with Abnormal AI: Moving beyond spotting typos, this session explored the new reality of hyper-realistic phishing emails and business email compromise (BEC) attacks crafted by generative AI. Our partners at Abnormal AI demonstrated how modern defences use AI to fight AI, detecting subtle anomalies that the human eye can no longer be expected to catch.

- Securing the ecosystem with Qualys: An organisation’s security is inextricably linked to its partners. Our town hall with Qualys focused on supply chain security, dissecting the risks inherent in third-party software, APIs, and dependencies. The session provided critical frameworks for vetting vendors and managing the extended attack surface that defines modern development.

- Inside the walls: Deriv’s top 5 TTPs: Transparency builds trust and sharpens defences. Our own internal security team presented a candid look at the top 5 Tactics, Techniques, and Procedures (TTPs) we observe and defend against. This session provided our teams with real-world context, connecting their daily work directly to our defensive posture.
Sustaining a resilient security posture
Cybersecurity Awareness Month is a catalyst, not a conclusion. The insights from our challenges and the knowledge shared in our town halls are now being integrated into our security controls, threat models, and ongoing training programs.
At Deriv, we are committed to building a team that not only leverages cutting-edge technology but is also deeply invested in securing it—from our internal code to our external partners.
Want to be part of a team that’s defending the future of finance? Explore our open roles in AI, cybersecurity, and engineering, and see more of our work on the Deriv Tech blog and Medium.




.webp)


















%2520(1).png)
.webp)
.jpeg)



%2520(1).webp)
.webp)



.webp)
.webp)













.webp)





