Showing posts with label Banking Services. Show all posts
Showing posts with label Banking Services. Show all posts

There's a great article today on Network World written by Ellen Messmer. Here's a sampling and my thoughts about the article (which I shared with Ms. Messmer)



Providing online bank customers with security software an imperfect cybercrime antidote

By Ellen Messmer, Network World  



In online banking and payments, customers' PCs have become the Achilles' heel of the financial industry as cyber-crooks remotely take control of the computers to make unauthorized funds transfers, often to faraway places. The dilemma for banks boils down to this:



How far can they go to help protect customer desktops that function like part of their shared network but aren't owned by the bank?



MY Answer: How about they provide something that IS owned by the bank (and uses existing bank rails) i.e.: Issue bank-owned PCI Certified PEDs...so they have a dedicated machine for online banking.



Banks are faced with the prospect that "customers own PCs that have been in the hands of Russian crime syndicates," says Jeff Theiler, senior vice president at Hancock Bank, which primarily operates along the Gulf Coast region. Like many other banks, Hancock finds itself getting more involved in helping customers defend their machines. <<read more>>



Editor's Note: Here's my response to Ellen's story (which was picked up by BusinessWeek today)...



Good morning Ellen: I enjoyed your article today on Network World and thought you might be interested in hearing that there is indeed a simple solution to the online banking problem to which you refer, specifically:  "The dilemma for banks boils down to this: How far can they go to help protect customer desktops that function like part of their shared network but aren't owned by the bank?"





Question: If you are 2000 miles from your bank, at 2:00 AM and need $200.00 what process is trusted to authenticate you and disperse the $200?

Answer: You insert/swipe your "bank issued card" then enter your "bank issued PIN" into a "bank owned ATM" and voilla. In seconds, you get your $200. That same trusted process is what should be used to authenticate online banking sessions.





Did you know that in Europe, almost 30% of consumers use a card reader for online banking (see graphic above) In America that number is ZERO.





Cost? WAY Less than what banks are already dishing out for "useless giveways. (When I say "useless" I am simply implying that the promotions they run don't "solve the problem.") The purpose of these give

aways is to attract customers. Well guess what? The purpose of "typing" is to provide online banking credential "giveaways" to the hackers, keyloggers and/or phishermen.





Consumers are already clamoring for a more secure online banking login process and they would "flock" towards the most secure online banking site in America, which is what a bank that deploys PCI Certified PED's to their online banking customers would become. Do you doubt me? Ask your friends. Would they rather type their online banking credentials into a box in a browser or swipe their card and enter their PIN?





Our device plugs into the USB port or smartphone and encrypts the cardholder data (including the Track 2 data) at the maghead using 3DES encryption. It then DUKPT encrypts the PIN for the only genuine end-to-end encryption.





The most important thing our device does is it "eliminates" typing "login" data into a box in a browser. That's the inherent problem. That's why (as you mention in your article) the Russian's get/got control of the PC's. (malware/phishing) Our PED eliminates the usage of inadequate and way obsolete "username/password" login...thus it eliminates phishing.





What do phishers phish phor? "Online Banking Credentials" AND "credit/debit card numbers. How do they get them? They fool people into thinking they are "typing" their card numbers/online banking authentication into a legitimate site when in fact it is not. That problem would be "eradicated" with our device.





Thus if all a banks customers securely login by doing what they do at an ATM, swipe their bank issued card, enter their bank issued PIN and do it on a bank issued PCI certified PIN Entry Device the problem created by "typing" would be eliminated by "swiping."I'd be happy to provide further insight as to why this is a "no-brainer" for banks to deploy.





Kaspersky Labs (which provides software security) knows that hardware is required as their recent proclamation calling for "mass adoption of card readers" professes. Software helps but at the end of the day it is simply a band-aid.





The internet was NOT designed to conduct financial transactions. It's called a "browser" for a reason and between malware, keylogging and phishing, the only solution to the problem is to replicate what we do at ATM's and/or brick and mortar retailers. Swipe vs. Type. As I like to say on the company blog. "If someone is going to "Swipe" your card information online, shouldn't it be you?





Question: Why would banks want to fork out $18 to give their customer a PCI Certified PED?

Answer: Well besides the obvious (they would save the millions of dollars lost to phishing) online banking is destined to fail. Most everyone is aware that fraud is running at epidemic levels and that what banks report is only a fraction of the real losses. (see graphic on right)





Other benefits: In addition to providing "True Two-Factor Authentication (and NO, a username and password is NOT really 2FA) Our device also completely eliminates the threats and fraud losses/costs created by typing...AND there is a return on investment in the form of Interchange revenue every time the device is used for online shopping or P2P payments.



Related articles by Zemanta

Enhanced by Zemanta

Posted by John B. Frank Friday, June 18, 2010 0 comments



http://www.researchandmarkets.com

Research and Markets: The Mutation of Threats against Corporate Online Banking Customers

DUBLIN--(BUSINESS WIRE)--Research and Markets (http://www.researchandmarkets.com/research/f86405/the_mutation_of_th) has announced the addition of the "The Mutation of Threats against Corporate Online Banking Customers" report to their offering.
“The Mutation of Threats against Corporate Online Banking Customers”
The number of attacks targeting companies has increased over several years to reach an unprecedented level in 2009. Modus operandi have evolved: payment systems for professionals are more and more targeted and associated prejudices reach hundreds of thousands of Euros.
This report shall examine the specific risks impacting business banking clientele - risks that often have direct or indirect repercussions on the banking institution as well.
Indeed, over the past two years, cybercrooks have substantially innovated in terms of business fraud, combining traditional scams with increasingly numerous technical means (particularly with the help of targeted Trojans). Todays targeted scams are a subtle weaving of social engineering and technical intrusion, with the aim of confiscating company trade secrets or, more often than not, draining company bank accounts. The latest developments concerning payment systems (the ACH Network, the SEPA area) have also created significant windows of opportunity for hackers.
In this report, we shall also take another look at the stock spam phenomenon that seems to have lost steam over the past few years. Nonetheless, certain evidence leads us to believe that this type of spam could develop in the near future into considerably more cunning and highly targeted forms.
Our recommendation to banks is to adapt business banking management to the level of risk that this clientele represents: first, by providing special training to staff dealing with business clientele, and second, by tuning authentication methods and fraud detection systems to the level of banking transactions carried out by businesses.
Key Topics Covered:
1. Distinctions from individual customers
2. Means of payment theft
3. New forms of fraud
4. Other specific risk
5. Recommendations

Contacts

Research and Markets

Laura Wood, Senior Manager,

press@researchandmarkets.com

U.S. Fax: 646-607-1907

Fax (outside U.S.): +353-1-481-1716
Permalink: http://www.businesswire.com/news/home/20100416005324/en/Research-Markets-Mutation-Threats-Corporate-Online-Banking


Reblog this post [with Zemanta]

Posted by John B. Frank Friday, April 16, 2010 0 comments



http://www.researchandmarkets.com

Research and Markets: The Mutation of Threats against Corporate Online Banking Customers

DUBLIN--(BUSINESS WIRE)--Research and Markets (http://www.researchandmarkets.com/research/f86405/the_mutation_of_th) has announced the addition of the "The Mutation of Threats against Corporate Online Banking Customers" report to their offering.
“The Mutation of Threats against Corporate Online Banking Customers”
The number of attacks targeting companies has increased over several years to reach an unprecedented level in 2009. Modus operandi have evolved: payment systems for professionals are more and more targeted and associated prejudices reach hundreds of thousands of Euros.
This report shall examine the specific risks impacting business banking clientele - risks that often have direct or indirect repercussions on the banking institution as well.
Indeed, over the past two years, cybercrooks have substantially innovated in terms of business fraud, combining traditional scams with increasingly numerous technical means (particularly with the help of targeted Trojans). Todays targeted scams are a subtle weaving of social engineering and technical intrusion, with the aim of confiscating company trade secrets or, more often than not, draining company bank accounts. The latest developments concerning payment systems (the ACH Network, the SEPA area) have also created significant windows of opportunity for hackers.
In this report, we shall also take another look at the stock spam phenomenon that seems to have lost steam over the past few years. Nonetheless, certain evidence leads us to believe that this type of spam could develop in the near future into considerably more cunning and highly targeted forms.
Our recommendation to banks is to adapt business banking management to the level of risk that this clientele represents: first, by providing special training to staff dealing with business clientele, and second, by tuning authentication methods and fraud detection systems to the level of banking transactions carried out by businesses.
Key Topics Covered:
1. Distinctions from individual customers
2. Means of payment theft
3. New forms of fraud
4. Other specific risk
5. Recommendations

Contacts

Research and Markets

Laura Wood, Senior Manager,

press@researchandmarkets.com

U.S. Fax: 646-607-1907

Fax (outside U.S.): +353-1-481-1716
Permalink: http://www.businesswire.com/news/home/20100416005324/en/Research-Markets-Mutation-Threats-Corporate-Online-Banking


Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments



 Auriemma Consulting Group

LONDON--(BUSINESS WIRE)--On 15 March 2010, the Department for Business, Innovation & Skills (BIS) released the response to the consultation on credit and store cards. As part of the consultation process, BIS commissioned Auriemma Consulting Group (ACG) to research features of international credit card markets and how they are regulated, and to identify what lessons could be learned. A number of markets outside of the UK, particularly the US and Canada, have recently implemented regulatory proposals related to credit cards. The ACG study provided evidence on market structure and credit card usage in the international markets and included detailed data and analysis of current regulations and its impact on the payments industry and consumers. Key findings include:
  1. Measuring the impact of the BIS regulation will be difficult since it is also coinciding with unprecedented economic changes.

  2. Limiting issuers’ ability to change terms in a reactive fashion impacts their ability to manage risk.

  3. Having an open dialogue between politicians, regulators and industry participants will ensure that the impact and goals of the regulation are understood by all parties, and that changes are made in a organised and effective fashion.

  4. Regardless of the scope of the regulation, it is critical that the industry is provided with enough time to implement and appropriately test any necessary changes.

  5. The consumer credit industry is creative and innovative. The industry will adapt to the regulation and will develop products, services and strategies that appropriately reflect the new market constraints.

These findings will have significant impact on the UK credit industry. The most impactful result is the limitations on the ability that credit issuers have to manage risk (i.e. change terms) reactively, particularly when a consumer demonstrates financial hardship. This fundamental change to the industry’s long-standing business practices will result in less credit being available to consumers and the credit that is available will be more expensive in terms of higher interest rates and fees. Other potential changes we predict are:
  • It is expected that benefits and features associated with these products will reflect the new requirements for increased transparency and/or be re-purposed versions of old best practices. Some examples include the re-introduction of charge cards as a mainstream product, widespread annual fees on cards, no interest free periods and rewards being only offered to the most affluent and/or profitable cardholders.

  • New credit industry regulation is likely to continue in reaction to the unintended consequences of the current regulation, though these are not expected to be introduced for 1-2 years.

  • Some issuers, particularly those who are categorised as being small- or medium-sized lenders, may cease to issue credit and/or store cards, due to the high financial and human resources required to comply with the new rules.

  • Financial education efforts, particularly those focused on improving consumer financial literacy, will become more prevalent and focused.

  • As credit becomes more difficult to obtain, the migration of consumers to debit and prepaid will accelerate. It also seems likely that short-term lending products like payday loans will gain interest among the mainstream public.

All data included in this study was obtained by ACG using a combination of interviews, desktop research, consumer surveys (using ACG’s proprietary market research platform, Cardbeat®) and internal industry insight. The full version of the report is available to download at http://www.bis.gov.uk/creditconsultation/response).
About Auriemma Consulting Group
Since 1984, ACG has offered comprehensive management consulting, research, industry roundtable and benchmarking services to the financial services industry. ACG clients include credit card issuers and networks, commercial banks, mortgage lenders, merchants, and other industry participants. With offices in London and New York, ACG offers actionable solutions to help clients make important business decisions to maximise their efficiencies and revenues.

Contacts

Auriemma Consulting Group

Megan Bramlette or Matt Simester

+44(0)207-629-0075

megan.bramlette@acg.net

matt.simester@acg.net
Permalink: http://www.businesswire.com/news/home/20100326005341/en/Auriemma-Consulting-Group-Analyses-Lessons-Learnt-International


Reblog this post [with Zemanta]

Posted by John B. Frank Friday, March 26, 2010 0 comments



 Auriemma Consulting Group

LONDON--(BUSINESS WIRE)--On 15 March 2010, the Department for Business, Innovation & Skills (BIS) released the response to the consultation on credit and store cards. As part of the consultation process, BIS commissioned Auriemma Consulting Group (ACG) to research features of international credit card markets and how they are regulated, and to identify what lessons could be learned. A number of markets outside of the UK, particularly the US and Canada, have recently implemented regulatory proposals related to credit cards. The ACG study provided evidence on market structure and credit card usage in the international markets and included detailed data and analysis of current regulations and its impact on the payments industry and consumers. Key findings include:
  1. Measuring the impact of the BIS regulation will be difficult since it is also coinciding with unprecedented economic changes.

  2. Limiting issuers’ ability to change terms in a reactive fashion impacts their ability to manage risk.

  3. Having an open dialogue between politicians, regulators and industry participants will ensure that the impact and goals of the regulation are understood by all parties, and that changes are made in a organised and effective fashion.

  4. Regardless of the scope of the regulation, it is critical that the industry is provided with enough time to implement and appropriately test any necessary changes.

  5. The consumer credit industry is creative and innovative. The industry will adapt to the regulation and will develop products, services and strategies that appropriately reflect the new market constraints.

These findings will have significant impact on the UK credit industry. The most impactful result is the limitations on the ability that credit issuers have to manage risk (i.e. change terms) reactively, particularly when a consumer demonstrates financial hardship. This fundamental change to the industry’s long-standing business practices will result in less credit being available to consumers and the credit that is available will be more expensive in terms of higher interest rates and fees. Other potential changes we predict are:
  • It is expected that benefits and features associated with these products will reflect the new requirements for increased transparency and/or be re-purposed versions of old best practices. Some examples include the re-introduction of charge cards as a mainstream product, widespread annual fees on cards, no interest free periods and rewards being only offered to the most affluent and/or profitable cardholders.

  • New credit industry regulation is likely to continue in reaction to the unintended consequences of the current regulation, though these are not expected to be introduced for 1-2 years.

  • Some issuers, particularly those who are categorised as being small- or medium-sized lenders, may cease to issue credit and/or store cards, due to the high financial and human resources required to comply with the new rules.

  • Financial education efforts, particularly those focused on improving consumer financial literacy, will become more prevalent and focused.

  • As credit becomes more difficult to obtain, the migration of consumers to debit and prepaid will accelerate. It also seems likely that short-term lending products like payday loans will gain interest among the mainstream public.

All data included in this study was obtained by ACG using a combination of interviews, desktop research, consumer surveys (using ACG’s proprietary market research platform, Cardbeat®) and internal industry insight. The full version of the report is available to download at http://www.bis.gov.uk/creditconsultation/response).
About Auriemma Consulting Group
Since 1984, ACG has offered comprehensive management consulting, research, industry roundtable and benchmarking services to the financial services industry. ACG clients include credit card issuers and networks, commercial banks, mortgage lenders, merchants, and other industry participants. With offices in London and New York, ACG offers actionable solutions to help clients make important business decisions to maximise their efficiencies and revenues.

Contacts

Auriemma Consulting Group

Megan Bramlette or Matt Simester

+44(0)207-629-0075

megan.bramlette@acg.net

matt.simester@acg.net
Permalink: http://www.businesswire.com/news/home/20100326005341/en/Auriemma-Consulting-Group-Analyses-Lessons-Learnt-International


Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers