·
All episodes
Marijo Sutlović
Episode · #764

RITAM POSLA Marijo Sutlović

Guest Marijo SutlovićHosted by Lidija KiseljakMay 3, 2026
About this episode
What you'll hear in this conversation

Marijo Sutlović sees the front lines of cybercrime shifting. Where attacks once targeted the fortified perimeters of banks, they now aim for what he calls the 'weakest link' — the individual user. As Director of Cyber Information Security at OTP Bank, Sutlović has a direct view of how criminals adapt to a rapidly digitalizing world, moving from credit card theft on fake sites to sophisticated smishing attacks that can hijack a user's entire digital identity.

Insights from the conversation
What to take from this episode
01
Marijo Sutlović pinpoints the 'weakest link' in modern cybersecurity not as a system vulnerability, but as the client. When attacks shift from a bank's perimeter to phishing and smishing, the institution's defense must extend beyond its own walls into public education. If you're building a secure digital service, your perimeter now includes the user's phone.
02
The rapid rise in online fraud over the last two to three years isn't a separate problem, Sutlović notes; it's a direct consequence of the world's accelerating digitalization. As more transactions move online, so do the criminals, adapting their methods to match every new digital service. The growth of your digital channels will directly correlate with the growth of new threats.
03
Smishing attacks, where fake SMS messages trick users into renewing their mobile banking apps, are no longer just about stealing data for a single fraudulent transaction. Sutlović describes how these attacks aim for a complete takeover of a client's digital identity. If an attack can take over the app, it can take over the user.
04
The Digital Operational Resilience Act (DORA), though a 'buzzword' for those in IT, has fundamentally changed how banks approach security, Sutlović explains. While not introducing entirely new concepts, it has mandated stricter documentation and monitoring, making security a transparent, budgeted operational requirement rather than an optional investment. Regulation doesn't invent new security needs; it makes existing ones non-negotiable.
05
Banks no longer wait for attacks; they proactively use cyber threat intelligence services to reduce risk. Sutlović details how OTP Bank gets early warnings about potential phishing sites, compromised client cards on the dark web, and even issues with employee accounts. The best defense is to block the threat before it ever reaches your users.
06
When the first major attacks hit the Croatian market, banks that were typically competitors began sharing information and supporting each other through the Croatian Banking Association's Security Committee. Sutlović highlights this as a critical step, proving that in the face of an industry-wide threat, collective defense outweighs individual competitive advantage. Some threats are too big for any single entity to fight alone.
07
Attacks on business clients, especially those with high transaction volumes, present a particular challenge, Sutlović notes. Fraudulent transactions can go unnoticed longer amidst the sheer number of legitimate ones, making these businesses attractive targets. When your operational scale increases, so does the surface area where fraud can hide.