Cybersecurity in Iraqi FinTech Applications: Are We Testing Security at the Expense of Citizens' Accounts?

Two months ago, a prominent FinTech company discovered a security vulnerability that allowed unauthorized individuals to access the data of thousands of users. The company issued a carefully worded public statement saying that "the situation is under control," but reportedly did not provide the Central Bank with full details of the incident or compensate those affected.
This is not an isolated case. Security research uncovers thousands of vulnerabilities every year in banking and FinTech applications across the Middle East. The difference is that developed countries have strict regulatory frameworks requiring companies to disclose security incidents promptly and compensate affected users where appropriate.
In Iraq, however, there is still no clear legal framework defining the responsibilities of FinTech companies when it comes to protecting users' data. Who is responsible—the company or the Central Bank? Who should compensate those affected?
This lack of clarity is perhaps the biggest enemy of trust.
