International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1723404

1723404 Vol 10 · Issue 3 Download Paper

Cyber Resilience of Financial Market Data and Electronic Trading Integrations in Saudi Banks: Securing APIs, FIX Adaptors, Market Feeds, and Transaction Workflows

Zahed Ali Sohail Mohammed

Subject area: Science,Engineering and Technology  ·  Area of research: Cyber Resilience

Abstract

Saudi banks increasingly connect treasury, brokerage, custody, payment, risk and core-banking functions to external markets through application programming interfaces, Financial Information eXchange adaptors, real-time market-data feeds and automated transaction workflows. These interfaces create business agility but also form tightly coupled paths through which data corruption, credential compromise, latency shocks, third-party outages and malicious message injection can propagate from an edge connection into trading decisions, settlement records and liquidity positions. This review examines cyber resilience at the integration layer rather than treating cybersecurity as a perimeter problem. It synthesises literature published from 2020 to 2025 on banking cyber risk, open-banking APIs, microservice security, zero-trust architecture, algorithmic trading, market-data dependence, secure trading mechanisms and operational resilience. The analysis distinguishes four resilience properties: trustworthy identity, message and data integrity, controlled availability, and recoverable transaction state. It argues that Saudi banks require controls that remain effective under partial failure, preserve deterministic evidence of what occurred, and support rapid reconciliation after service restoration. The review develops an integrated architecture in which API gateways, FIX sessions, feed handlers and workflow engines are protected by mutually reinforcing identity, cryptographic, observability, isolation and reconciliation controls. It further proposes lifecycle metrics that connect technical events with operational and financial consequences. The resulting framework contributes a bank-oriented model for securing electronic-trading integrations while preserving performance, auditability and continuity. Research gaps remain in empirical testing of FIX-specific attacks, cross-interface dependency modelling, market-data integrity benchmarks and Saudi-specific recovery exercises across banks, vendors and market infrastructures.

Keywords

cyber resilience; Saudi banks; electronic trading; FIX protocol; API security; market data; transaction workflows; operational resilience

References

[1] M. H. Uddin, S. Mollah, and M. H. Ali, “Does cyber tech spending matter for bank stability?,” International Review of Financial Analysis, vol. 72, Art. no. 101587, 2020, doi: 10.1016/j.irfa.2020.101587. ScienceDirect

[2] T. M. Eisenbach, A. Kovner, and M. J. Lee, “Cyber risk and the U.S. financial system: A pre-mortem analysis,” Journal of Financial Economics, vol. 145, no. 3, pp. 802–826, 2022, doi: 10.1016/j.jfineco.2021.10.007. ScienceDirect

[3] A. A. Darem, A. A. Alhashmi, T. M. Alkhaldi, A. M. Alashjaee, S. M. Alanazi, and S. A. Ebad, “Cyber Threats Classifications and Countermeasures in Banking and Financial Sector,” IEEE Access, vol. 11, pp. 125138–125158, 2023, doi: 10.1109/ACCESS.2023.3327016. Crossref

[4] S. Wang, M. Asif, M. F. Shahzad, and M. Ashfaq, “Data privacy and cybersecurity challenges in the digital transformation of the banking sector,” Computers & Security, vol. 147, Art. no. 104051, 2024, doi: 10.1016/j.cose.2024.104051. ScienceDirect

[5] B. H. Min and C. Borch, “Systemic failures and organizational risk management in algorithmic trading: Normal accidents and high reliability in financial markets,” Social Studies of Science, vol. 52, no. 2, pp. 277–302, 2022, doi: 10.1177/03063127211048515. Crossref

[6] A. Frino, D. Gerace, and M. Behnia, “The impact of algorithmic trading on liquidity in futures markets: New insights into the resiliency of spreads and depth,” Journal of Futures Markets, vol. 41, no. 8, pp. 1301–1314, 2021, doi: 10.1002/fut.22224. Wiley

[7] S. Kognole, “FIX Protocol: The Backbone of Financial Trading,” International Journal of Computer Science & Information Technology, vol. 16, no. 4, pp. 97–114, 2024, doi: 10.5121/ijcsit.2024.16408.

[8] Lin, S. S. Zhang, and M. Zachariadis, “Open data and API adoption of U.S. banks,” Journal of Financial Intermediation, vol. 63, Art. no. 101162, 2025, doi: 10.1016/j.jfi.2025.101162. ScienceDirect

[9] P. Modesti, L. Freitas, Q. Shotomiwa, and A. Almehrej, “Security analysis of the open banking account and transaction API protocol,” Cyber Security and Applications, vol. 3, Art. no. 100097, 2025, doi: 10.1016/j.csa.2025.100097. ScienceDirect

[10] F. Tanveer, F. Iradat, W. Iqbal, and A. Ahmad, “Towards Secure APIs: A Survey on RESTful API Vulnerability Detection,” Computers, Materials & Continua, vol. 84, no. 3, pp. 4223–4257, 2025, doi: 10.32604/cmc.2025.067536. Crossref

[11] A. Pereira-Vale, E. B. Fernandez, R. Monge, H. Astudillo, and G. Marquez, “Security in microservice-based systems: A multivocal literature review,” Computers & Security, vol. 103, Art. no. 102200, 2021, doi: 10.1016/j.cose.2021.102200. ScienceDirect

[12] J. Singh and N. K. Chaudhary, “OAuth 2.0: Architectural design augmentation for mitigation of common security vulnerabilities,” Journal of Information Security and Applications, vol. 65, Art. no. 103091, 2022, doi: 10.1016/j.jisa.2021.103091. ScienceDirect

[13] M. G. de Almeida and E. D. Canedo, “Authentication and Authorization in Microservices Architecture: A Systematic Literature Review,” Applied Sciences, vol. 12, no. 6, Art. no. 3023, 2022, doi: 10.3390/app12063023. MDPI

[14] F. Minna and F. Massacci, “SoK: Run-time security for cloud microservices. Are we there yet?,” Computers & Security, vol. 127, Art. no. 103119, 2023, doi: 10.1016/j.cose.2023.103119. ScienceDirect

[15] M. Gounari, G. Stergiopoulos, K. Pipyros, and D. Gritzalis, “Harmonizing open banking in the European Union: an analysis of PSD2 compliance and interrelation with cybersecurity frameworks and standards,” International Cybersecurity Law Review, vol. 5, pp. 79–120, 2024, doi: 10.1365/s43439-023-00108-8. Springer

[16] S. AlBenJasim, H. Takruri, R. Al-Zaidi, and T. Dargahi, “Development of cybersecurity framework for FinTech innovations: Bahrain as a case study,” International Cybersecurity Law Review, vol. 5, pp. 501–532, 2024, doi: 10.1365/s43439-024-00130-4. Springer

[17] N. F. Syed, S. W. Shah, A. Shaghaghi, A. Anwar, Z. Baig, and R. Doss, “Zero Trust Architecture (ZTA): A Comprehensive Survey,” IEEE Access, vol. 10, pp. 57143–57179, 2022, doi: 10.1109/ACCESS.2022.3174679. IEEE

[18] C. Daah, A. Qureshi, I. Awan, and S. Konur, “Enhancing Zero Trust Models in the Financial Industry through Blockchain Integration: A Proposed Framework,” Electronics, vol. 13, no. 5, Art. no. 865, 2024, doi: 10.3390/electronics13050865. Crossref

[19] S. Pollmeier, I. Bongiovanni, and S. Slapničar, “Designing a financial quantification model for cyber risk: A case study in a bank,” Safety Science, vol. 159, Art. no. 106022, 2023, doi: 10.1016/j.ssci.2022.106022. ScienceDirect

[20] N. Gatzert and M. Schubert, “Cyber risk management in the US banking and insurance industry: A textual and empirical analysis of determinants and value,” Journal of Risk and Insurance, vol. 89, no. 3, pp. 725–763, 2022, doi: 10.1111/jori.12381. Wiley

[21] M. Gale, I. Bongiovanni, and S. Slapničar, “Governing cybersecurity from the boardroom: Challenges, drivers, and ways ahead,” Computers & Security, vol. 121, Art. no. 102840, 2022, doi: 10.1016/j.cose.2022.102840. ScienceDirect

[22] D. H. Elsayed, T. H. Ismail, and E. A. Ahmed, “The impact of cybersecurity disclosure on banks’ performance: the moderating role of corporate governance in the MENA region,” Future Business Journal, vol. 10, Art. no. 115, 2024, doi: 10.1186/s43093-024-00402-9.

[23] E. Shafie, “Securing mobile banking in Saudi Arabia: key insights on confidentiality, authentication, and device trust,” Journal of Umm Al-Qura University for Engineering and Architecture, vol. 16, pp. 1401–1416, 2025, doi: 10.1007/s43995-025-00175-4. Springer

[24] Y. T. Y. Azura, M. A. Azad, and Y. Ahmed, “An integrated cyber security risk management framework for online banking systems,” Journal of Banking and Financial Technology, vol. 9, pp. 85–104, 2025, doi: 10.1007/s42786-025-00056-3. Springer

[25] J. Cartlidge, N. P. Smart, and Y. Talibi Alaoui, “Multi-party computation mechanism for anonymous equity block trading: A secure implementation of Turquoise Plato Uncross,” Intelligent Systems in Accounting, Finance and Management, vol. 28, no. 4, pp. 239–267, 2021, doi: 10.1002/isaf.1502. Wiley

[26] D. Yuferova, “Algorithmic trading and market efficiency around the introduction of the NYSE Hybrid Market,” Journal of Financial Markets, vol. 69, Art. no. 100909, 2024, doi: 10.1016/j.finmar.2024.100909. ScienceDirect

[27] T. Havakhor, M. S. Rahman, T. Zhang, and C. Zhu, “Tech-Enabled Financial Data Access, Retail Investors, and Gambling-Like Behavior in the Stock Market,” Management Science, vol. 71, no. 2, pp. 1646–1670, 2025, doi: 10.1287/mnsc.2021.01379. INFORMS

[28] E. Akyildirim, T. Conlon, S. Corbet, and Y. G. Hou, “HACKED: Understanding the stock market response to cyberattacks,” Journal of International Financial Markets, Institutions and Money, vol. 97, Art. no. 102082, 2024, doi: 10.1016/j.intfin.2024.102082. ScienceDirect

[29] H. Cheraghali, P. Molnár, M. Storsveen, and F. Veliqi, “The impact of cryptocurrency-related cyberattacks on return, volatility, and trading volume of cryptocurrencies and traditional financial assets,” International Review of Financial Analysis, vol. 95, Art. no. 103439, 2024, doi: 10.1016/j.irfa.2024.103439. ScienceDirect

[30] D. Duggan, “The impact of the Digital Operational Resilience Act on financial market infrastructures in Europe,” Journal of Securities Operations & Custody, vol. 16, no. 4, pp. 344–350, 2024, doi: 10.69554/KHFM3582.

How to cite this paper

Zahed Ali Sohail Mohammed "Cyber Resilience of Financial Market Data and Electronic Trading Integrations in Saudi Banks: Securing APIs, FIX Adaptors, Market Feeds, and Transaction Workflows" Iconic Research And Engineering Journals Volume 10 Issue 3 2026 Page 2723-2735
Zahed Ali Sohail Mohammed "Cyber Resilience of Financial Market Data and Electronic Trading Integrations in Saudi Banks: Securing APIs, FIX Adaptors, Market Feeds, and Transaction Workflows" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026
Zahed Ali Sohail Mohammed (2026). Cyber Resilience of Financial Market Data and Electronic Trading Integrations in Saudi Banks: Securing APIs, FIX Adaptors, Market Feeds, and Transaction Workflows. Iconic Research And Engineering Journals, 10(3).
Zahed Ali Sohail Mohammed "Cyber Resilience of Financial Market Data and Electronic Trading Integrations in Saudi Banks: Securing APIs, FIX Adaptors, Market Feeds, and Transaction Workflows" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026.
@article{1723404,
      author = {Zahed Ali Sohail Mohammed},
      title = {Cyber Resilience of Financial Market Data and Electronic Trading Integrations in Saudi Banks: Securing APIs, FIX Adaptors, Market Feeds, and Transaction Workflows},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {3},
      pages = {2723-2735},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1723404.pdf},
      abstract = {Saudi banks increasingly connect treasury, brokerage, custody, payment, risk and core-banking functions to external markets through application programming interfaces, Financial Information eXchange adaptors, real-time market-data feeds and automated transaction workflows. These interfaces create business agility but also form tightly coupled paths through which data corruption, credential compromise, latency shocks, third-party outages and malicious message injection can propagate from an edge connection into trading decisions, settlement records and liquidity positions. This review examines cyber resilience at the integration layer rather than treating cybersecurity as a perimeter problem. It synthesises literature published from 2020 to 2025 on banking cyber risk, open-banking APIs, microservice security, zero-trust architecture, algorithmic trading, market-data dependence, secure trading mechanisms and operational resilience. The analysis distinguishes four resilience properties: trustworthy identity, message and data integrity, controlled availability, and recoverable transaction state. It argues that Saudi banks require controls that remain effective under partial failure, preserve deterministic evidence of what occurred, and support rapid reconciliation after service restoration. The review develops an integrated architecture in which API gateways, FIX sessions, feed handlers and workflow engines are protected by mutually reinforcing identity, cryptographic, observability, isolation and reconciliation controls. It further proposes lifecycle metrics that connect technical events with operational and financial consequences. The resulting framework contributes a bank-oriented model for securing electronic-trading integrations while preserving performance, auditability and continuity. Research gaps remain in empirical testing of FIX-specific attacks, cross-interface dependency modelling, market-data integrity benchmarks and Saudi-specific recovery exercises across banks, vendors and market infrastructures.},
      keywords = {cyber resilience; Saudi banks; electronic trading; FIX protocol; API security; market data; transaction workflows; operational resilience},
      month = {September},
  }