Wednesday, November 7, 2012

Mobile is impacting cloud security issues

The burgeoning influx of employee-owned smartphones and tablets in the workplace has added to the complexity of securing cloud-based systems, according to a panel of experts who urged IT security teams to consider setting enforceable mobile policies alongside cloud policies.

Image source: chetansharma
The process for setting policies addressing both mobile and cloud is easier said than done.

Hybrid cloud policies developed in conjunction with mobile security policy should be as a collaborative effort involving all of an organization's data owners, administrators and others who know the business and can find a middle ground.

View what the panelists say in full detail in this article.

Thursday, November 1, 2012

Gartner: How big trends in security, mobile, big data and cloud computing will change IT

When you go to a Gartner conference one of he main things you'll notice is the sheer volume of data they can generate on just about any IT topic.

Image source: Gartner
The Gartner conference, attended by some 9,000 executives focused on the changes security challenges, mobile computing, big data and cloud will be bringing to IT in the near future.

Trying to get through it all can be daunting so we've tried to simplify that process by distilling a variety of Gartner ITxpo presentations and coming up with the most salient information.

What are you interested in? Mobile? Big Data? Cloud? All of the above? Read the article to learn more about each.

Tuesday, October 30, 2012

Lack of abuse detection allows cloud computing instances to be used like botnets

Some cloud providers don't detect attacks launched from their networks, researchers say.

Image source: YahooLabs
Some cloud providers fail to detect and block malicious traffic originating from their networks, which provides cybercriminals with an opportunity to launch attacks in a botnet-like fashion, according to a report from Australian security consultancy firm Stratsec.

Researchers from Stratsec, a subsidiary of British defense and aerospace giant BAE Systems, reached this conclusion after performing a series of experiments on the infrastructure of five "common," but unnamed, cloud providers.

What are your cloud instances up to? Read the article to learn more.

Wednesday, October 24, 2012

In security response, practice makes perfect

We've heard it many times in many forms -- expect to be breached, expect that you've been breached, expect that you are being breached.

Image source: imsmartin
The unfortunate reality is that most organizations don't even know that they've been compromised and therefore don't do anything to block spreading of the malware, control the damage, prevent loss of information, or even recover from the technical problems associated with the compromise.

Assuming the adversary makes it in, the question remains: How long after a breach occurs can the organization remediate and prevent further damage?

Which state is your CU in? Waiting to be breached? Already breached? Don't know? Regardless of the state, you should read the article to learn more about some best practices in response.

Wednesday, October 17, 2012

Managing Mobile Risk

What happens when data collaboration and delivery travels to the mobile devices we all carry? Most CIOs see the introduction of unnecessary risk, observed many experts.

Image source: Article
Controlling information is not a new concept

But today's unmanaged mobility — in the form of BYOD (bring your own device) to work programs — and equally unmanaged use of popular Web services such as Dropbox and Evernote — represent a seemingly unstoppable phenomenon.

This creates a set of issues that must be addressed before an information governance firestorm hits. Read the article to see where your CU sits in terms if mobile information governance.

Monday, October 15, 2012

Doing the Two-Step, Beyond the A.T.M.

BANK A.T.M.'s embody decades-old technology. A four-digit PIN?

Image source: judybaxter
What a seemingly crude security system. Where are the uppercase and lowercase letters and the random punctuation that we are continually told are crucial to hacker-resistant passwords?

In fact, though, the four-digit numbers required to use cash machines are one element of an extremely strong security model that most of today's Web sites fall well short of matching.

Is your CU planning to offer your Members the option of requiring two-step verification for added peace of mind? Read the article to learn more about two-factor authentication.

Friday, October 12, 2012

Technology report: Biometric banks and privacy

It may sound like something straight out of a James Bond movie, but believe it or not, Australia’s major banks are moving to embrace biometric security systems.

Image source: Cynic
There are two main reasons why the banks are moving in this direction; both of which revolve around customer experience. The first is to improve their customer's experience whilst utilising ATMs and Eftpos machines and terminals. The second is to remove the need for customers to carry around a wallet or purse full of plastic cards.

Banks aim to introduce biometric security systems to reduce the incidence of fraud. There’s also the fact that ATMs and Eftpos are time consuming, require customers to have a plastic card that stores account details and to remember a Personal Identification Number (PIN).

Is your CU and your members ready for biometric technology? Read the article to learn more about biometrics.

Wednesday, October 10, 2012

Trend Micro Identifies Malware Spreading via Skype

If you use Skype, you’ve likely been privy to an odd message coming from some of your contacts that says, “lol is this your new profile pic?”

Image source: Article
The explosion of this Trojan through various gaming communities was covered by SiliconANGLE earlier; but now Trend Micro’s malware labs have identified the malware as a variant of DORKBOT.

Users of Trend Micro’s product are already protected from this sort of intruder and the company has detected and blocked more than 6,800 associated files since Sunday.

Read up on the Skype-based attacks here to see why the payload is far more sinister than the silly name of this threat.

Friday, October 5, 2012

An eye for a buy: Banks look to retina and fingerprint technology

ANZ has floated the idea of retina-scanning automatic teller machines and is considering using electronic fingerprints as part of an effort to beat rival banks in the realm of technology.

Image source: Article
By the middle of next year, it would introduce 800 ATMs that allowed ''next generation'' deposit services, including coins, notes and cheques to be credited to customers' accounts immediately, the bank said yesterday.

It will plough about $1.5 billion into new technologies, including ATMs consumers could access through fingerprints or retina identification.

How much does your CU plan to invest in your ATM technologies? Read the article to learn more about how ANZ is using biometrics to deliver better security for their consumers transactions.

Wednesday, October 3, 2012

DDoS attacks on major US banks are no Stuxnet—here's why

The attacks that recently disrupted website operations at Bank of America and at least five other major US banks used compromised Web servers to flood their targets with above-average amounts of Internet traffic.

Image source: Article
The attacks used compromised Web servers to wield a bigger-than-average club.

The distributed denial-of-service (DDoS) attacks—which over the past two weeks also caused disruptions at JP Morgan Chase, Wells Fargo, US Bancorp, Citigroup, and PNC Bank—were waged by hundreds of compromised servers.

Your CU isn't on the list? So it must be safe then, right? Read the article to see why this may not be true.

MasterCard Plans Shift To EMV-enabled ATMs By 2016

After October 2016, banks can hold ATM operators liable for fraudulent withdrawals and cash advances from debit and credit cards.

Image source: Lexcel
The announcement gives banks, ATM operators, and equipment manufacturers more than four years to cycle EMV cards and equipment into circulation.

While not immune from fraud, EMV-enabled debit and credit cards require much more sophistication to clone, compared to the magnetic stripe cards popular among Americans today.

Is your CU planning to use EMV technology? Read the article to learn more about EMV-enabled ATMs.

Banks fail to repel cyber threat

A shadowy but well organized hacker group in the Middle East has disrupted the electronic banking operations of America's largest financial institutions in recent days, underscoring U.S. vulnerability to online terrorism.

Image source: Geograph
A group identifying itself as Izz ad-Din al-Qassam Cyber Fighters attacked the websites of Wells Fargo, U.S. Bancorp and Bank of America.

The strikes left customers temporarily unable to access their checking accounts, mortgages and other services.

Is your CU at risk of the same sort of attack? Read the article to see how this group operates.

Sunday, September 30, 2012

Adobe code signing infrastructure hacked by 'sophisticated threat actors'

Adobe has warned that an internal server with access to its digital certificate code signing infrastructure was hacked by "sophisticated threat actors" engaged in "highly targeted attacks."

Image source: Article
The compromise, which dates back to early July, led to the creation of at least two malicious files that were digitally signed using a valid Adobe certificate, according to Adobe security chief Brad Arkin.

Although only two files were signed, the hack effectively gave the attackers the ability to create malware masquerading as legitimate Adobe software and signals a raising of the stakes in the world of Advanced Persistent Threats (APTs). Guardtime keyless signatures were not in use, thereby allowing the tampering to go undetected.

Are your adobe products at risk? Read the article to learn more.

Saturday, September 29, 2012

Bank of America tests technology to pay with phones

Bank of America Corp is testing a technology that allows a customer to pay at a store register by simply scanning an image with a smartphone, such as Apple Inc's iPhone or Google Inc's Android devices.

Image source: VentureBeat
The pilot program is being tested in Charlotte, North Carolina, where the second-largest U.S. bank is headquartered, and marks the latest effort by a financial institution to come out on top in the race to determine how people will pay for things in the future.

In the trial, Bank of America has partnered with Paydiant, a startup that has developed a technology to allow such mobile payments. It doesn't require new phones or hardware for merchants.

Read the article to see how your members can scan QR codes with their phones to make payments.

Friday, September 28, 2012

Mobile tellers take banking by storm

Since taking the reins as chief information officer for Westpac, Clive Whincup has presided over the launch of the bank’s first iPad application; a trial to turn Android smartphones into contactless payment devices; the introduction of an iPad app to replace printed board papers; a 1000 iPad pilot for bank executives; and a St George innovation that allows payments to be made from a smartphone using only the recipient’s mobile number.

Image source: Article
It’s a fast-moving area: Whincup has been in the role for only nine months.

Payments analyst Edgar Dunn & Co predicts there could be 250 million mobile banking transactions each year in Australia by 2015.

Is your CU ready for the mobile teller phenomenom? Read the article to find out.

Thursday, September 27, 2012

eSignatures go Keyless in the Cloud

It has been 12 years since the United States passed a law to facilitate the use of electronic records and electronic signatures.

Image source: Article
Called the Electronic Signatures in Global and National Commerce Act (ESIGN), its general intent in black and white is quoted in the very first section of the legislation; that a contract or signature “may not be denied legal effect, validity, or enforceability solely because it is in electronic form.”

eSignatures save a lot of waste. No need to get into a car and drive paper documents to your attorney’s office for a real estate contract or to a bank to settle a mortgage application.

Does your CU use online digital signatures? Read the article to see how Avanza Bank asked Scrive to produce a bullet-proof e-signing service, whereby many stringent conditions would be met.

Wednesday, September 26, 2012

Why No NFC in the iPhone Hurts Banks More Than Apple

It took almost two decades for credit card payments (followed by debit cards) to become globally ubiquitous, so it might be reasonable to think that a paradigm shift at the POS will take years to become mainstream.

Image source: Article
Why would you spend money deploying expensive NFC-enabled (Near Field Communication) POS terminals unless consumers were going to use them, right? Is this why Apple chose to snub NFC technology in its latest iPhone?

In normal circumstances, if there were no competition, this would make good business sense.

Read the article to see how this could affect your CU.

Tuesday, September 25, 2012

Cybercrooks target credit union, bank employees

Local credit unions and small banks are being warned by the FBI that their employees may be the latest targets of cybercrooks.

Image source: Article
A new FBI fraud alert warns that these crooks are aggressively trying to steal login details of these employees with the goal of illegally wiring themselves hundreds of thousands of dollars.

Fraudsters obtain the logins through phishing and spam e-mails before installing keystroke loggers and remote access Trojans on their computer, gaining complete access to internal networks and logins to third party systems.

Read the article to see if your CU is at risk to these types of threats.

Monday, September 24, 2012

Firewall vs. IPS: Will next-generation firewalls nix stand-alone IPS?

Firewall vendors are in the business of providing network security, and as network security challenges evolve, so must firewalls.

Image source: imsmartin
As a part of this natural evolution, the firewall security engine has integrated intrusion prevention system (IPS) and other deep-packet inspection capabilities.

Many experts expect this general trend to continue as firewall vendors pack more security intelligence features into their devices, taking advantage of the strategic positioning that firewalls hold in customers' networks. The end result of this development could be a security gateway that is capable of monitoring the entire network.

What will your next perimeter protection invoice include? Read the article to see how IPS technologies stack up against traditional firewall technologies - in a single NextGen Firewall offering.

Friday, September 21, 2012

How Credit Unions Can Safely Embrace Bring-Your-Own-Device

Bring Your Own Device (BYOD) programs, which allow employees to use their own smartphones and tablets in the work environment, are significantly changing information technology.

Image source: imsmartin
Credit unions and other financial service firms are among the organizations embracing BYOD, as it allows senior executives and employees to use for work and pleasure the mobile devices, service providers and operating platforms of their choice.

IT research firm Gartner Inc. predicts that by 2013, 80% of businesses will support a workforce using tablets, and by 2014, 90% of organizations will support corporate applications on personal devices.

To learn more about BYOD considerations, prohibitions, and partnering, read the full article.

Thursday, September 20, 2012

Good Technology debuts new BYOD services for speedier migrations

Good Technology is rolling out two new services designed to deal with the prevalent BYOD (bring your own device) issue, but the motivation behind the solutions might be more telling.

Image source: Spark PR
Essentially, Good learned that customers such as Nationwide Insurance, UBS and Franklin Templeton wanted help accelerating their moves from BlackBerry to devices like iPhones, iPad and Android.

According to Good, many were originally planning for 3-year transitions, but later speeded that up to six months given the rocky future of Research In Motion.

What's your CU's mobile strategy? Are you migrating more quickly than originally planned? Read the article to see how Good could help with your migration.

Tuesday, September 18, 2012

Gartner: Cloud to grow 20% this year to $109B market

The cloud computing market will grow almost 20% this year to become a $109 billion industry, research firm Gartner predicts.

Image source: Frank IT Lab
Gartner predicts business process as a service (BPaaS) and software as a service (SaaS) will dominate the market, with infrastructure as a service (IaaS) quickly gaining momentum.

n 2011, the market stood at $91.4 billion and the research firm expects it to grow to $206.6 billion by 2016. Cloud is still only a very small part of the overall IT spending market though. In July, Gartner predicted total IT spending would be $3.6 trillion in 2012.

How much Cloud does your CU use?

Friday, September 14, 2012

The 10 best IT certifications: 2012

When it comes to IT skills and expertise, there are all kinds of “best certification” lists. Pundits are quick to add the safe bets: Cisco’s CCIE (Cisco Certified Internetwork Expert), Red Hat’s RHCE (Red Hat Certified Engineer), and other popular choices.

This isn’t that list.

Image source: IT Hire Wire
Based on years of experience meeting with clients and organizations too numerous to count, this list was built with the idea of cataloging the IT industry’s 10 most practical, in-demand certifications. That’s why I think these are the best; these are the skills clients repeatedly demonstrate they need most. In this list, I justify each selection and the order in which these accreditations are ranked.

MCITP: Enterprise Administrator on Windows Server 2008 tops the list.

Read the article to see the other 9 certifications listed.

Tuesday, September 4, 2012

For Banks, Digital Currency Poses Threat — and Opportunity

While the digital currency known as Bitcoin does have its obstacles, it can also mean business opportunities for financial institutions.

Image source: purkrabek.com
The Bitcoin, which is a highly encrypted digital file based on open-source code and is distributed through peer-to-peer networks, lacks centralized issuing authority; thus any savvy techie with the right hardware can "mine" this algorithm-based currency.

On the other hand, it could be a an alternative to currencies being printed at whim and guarded irresponsibly. The software was programmed to create a finite supply to preserve the currency's long-term value, and cryptography would eliminate the need for trusted third parties to store and transfer money.

In any case, as new innovations for managing Bitcoin transactions emerge, financial institutions could have a big role in the movement as well, including payment processing, providing escrow services, facilitating international cash transactions, helping customers exchange their money for Bitcoins, and even issuing Bitcoin loans.

Read up on the Bitcoin system here.

Friday, August 31, 2012

1 MILLION accounts leaked in megahack on banks, websites

A cache of over one MILLION user account records was leaked by hacker collective Team GhostShell in a huge data dump over the weekend.

Image source: Imperva
Targeting banks, consulting firms, government agencies, and manufacturing firms, the team extracted usernames, passwords, credit histories, and other files and documents from 100 different websites. Much of the data was pulled from the targets' databases and content management systems, some of which contained more than 30,000 records each.

Imperva analysis indicates that the breaches were executed mostly using the SQLmap tool, a common SQL injection method used by hackers.

The importance of staying on top of your CU's security system and closing up vulnerabilities can't be stressed enough. Get more info about the megahack here.

Wednesday, August 29, 2012

How National Australia Bank Uses Cloud Computing to Cut Costs and Shrink Its Carbon Footprint

How much money, energy, and time get drained by your CU's current systems and processes?

Image source: freeaussiestock.com / CC BY 3.0
More and more financial institutions around the globe are finding that revising their energy policies and shifting toward "green IT" practices are key in optimizing resource management.

Spanning everything from IT to travel fleet, the energy reduction program adopted by the $782 billion-asset bank and Open Data Center Alliance member National Australia Bank (NAB) exemplifies the significant cost-savings and environmental benefits made possible by data virtualization through scalability, increased efficiency, and resource conservation.

Time for a data center overhaul for your CU? Read the BTN interview with NAB's Dennis McGee to learn about this large and complex institution's approach to green IT.

Monday, August 27, 2012

Convenience is Key for Bank Consumers: Report

When it comes to day-to-day banking, convenience is where it's at for your members, as found in a recent poll of 1,231 U.S. consumers conducted by Angus Reid Public Opinion in conjunction with TD Bank.

Image source: denn / CC BY-SA 2.0
This should come as no shock, especially in today's rapidly evolving technological world. The poll also found that online banking is the most frequent banking activity engaged in by consumers, with those surveyed reporting that they go online to manage their finances at an average of five times each month.

Also not surprisingly, "easy online banking" was the top response in terms of the most important factor for basic checking accounts.

What else is important to your members? Check out the results of the poll and hear it from them.

Friday, August 24, 2012

Zeus Variant Targets U.S. Accounts

The FBI has issued a warning to financial institutions about a new wave of ransomware which freezes and hijacks endpoint computer operating systems and attempts to extort funds from users while simultaneously working in the background to also rob their account data.

Image source: Article
Powered by the Zeus malware variant Citadel and the drive-by virus Reveton, these "targeted and convincing" attacks generate messages - often under the guise of the FBI - notifying users of their "illegal" Internet activity and demand that they pay fines in order to regain control of their computers. Meanwhile keyloggers are launched to steal online account credentials and other financial information.

Enhancing back-end fraud-prevention systems and processes so that malware is blocked from taking over your members' accounts even if their endpoints do become infected is critical, as is quick detection and removal.

The best defense, however, is educating your members. Given the lack of familiarity with ransom attacks, users in the U.S. have proven to be easy targets. Find out what both your CU and your members need to know.

Wednesday, August 22, 2012

Man-in-the-Mobile Attacks Target the Bank Accounts of Android Users

Android users in Portugal, Spain, the Netherlands, and Germany have been plagued by man-in-the-mobile (MITMO) attacks which enable cybercriminals to gain access to victims' banking data and make fraudulent transfers.

Image source: Photozou / CC BY 2.1
Powered by malwares such as Tatanga and SpyEye (SPITMO), these attacks start off as web injections via Windows users' PCs and come under the guise of notices from the victims' financial institutions instructing them to install a security application onto their mobile phones. If installed onto a device that runs on Google's operating system, the app gives the attacker access to all SMS traffic, including banking transaction authorization codes.

With Android devices accounting for most of the smartphone market in these countries, the Android platform is the obvious target and you must ask how many of your CU's members are also Android users. On the upside, there are preventative technologies out there, such as Guardtime's keyless data integrity validation service which shows when a MITMO attack has occurred and can help your CU intercept the attacker.

Learn more about how to spot these attacks.

Monday, August 20, 2012

Technology change agents make e-discovery better or worse

Change agents in technology, including social networking, cloud computing, and bringing your own devices to work, are changing how we do business and communicate, and impacts how organizations need to approach e-discovery.

Image source: imsmartin
With so much data and so many different data sources and destinations to keep track of, companies are struggling to keep up with security, forensics, and e-discovery.

Proper e-discovery is driven by proper forensics, which is fed by proper security management. These three functional turfs are converging at breakneck speed, and vendor offerings are starting to merge.

Read the full article to learn what the merging of these three trends means for your credit union.

A portion of this article reprinted with permission from ALM's Legal Technology News. Further duplication is prohibited.

Friday, August 17, 2012

Understanding the risks of different types of Mobile Banking transactions...

While leaving responsibility for personal mobile banking security solely in the hands of financial institutions is a poor strategy, your CU needs to do its part. Is yours?

Image source: gadgetdude / CC BY 2.0
There are a number of different mobile banking techniques, and with each comes a specific set of security rationale. Both your CU and its members need to understand the various possible attack scenarios against mobile banking systems and what can be done to minimize risk.

Security controls built into smartphone operating systems are now thought to be stronger than those built into desktop computers; however mobile device malware threats are growing rapidly. Your members can easily undermine mobile banking security and thus actively monitoring the health of their devices can help them to protect their data.

Read the article and learn about the various types of mobile banking transactions and their associated risks.

Wednesday, August 15, 2012

Criminals push malware by 'losing' USB sticks in parking lots

Finders keepers...or so it seems that's what a cybercriminal was counting on in order to hack into DSM's corporate network.

Image source: Article
Employees of the Dutch branch of the multinational chemical company recently found several USB sticks on the ground in the company parking lot which appeared to be lost by their original owner. When DSM's IT department examined the sticks, they were found to be loaded with malware set to autorun on company computers and harvest employee login credentials.

Did a cybercriminal drop these infected USB sticks in the company parking lot in hopes that unsuspecting employees would find and use them?

Don't let cybercriminals outsmart your CU's personnel. Read the full article for more details.

Monday, August 13, 2012

Phishing the financial and banking seas

Thanks to the emergence of mobile devices, social networks, and new technologies such as Near Field Communications, the attack surface area against financial institutions has expanded at an explosive rate, providing cybercriminals more opportunities than ever to go "fishing" at your CU's expense.

Image source: Hitchster / CC BY 2.0
The top threats are payment card fraud, cheque fraud, phishing/vishing, account takeover, and third-party point-of-sale skimming, with about 80% of such incidents experienced by banking customers and an exponential escalation of malware attacks targeting financial transactions. Many large financial institutions are confident in their security measures and preparedness against the modern threat landscape, but recent history suggests otherwise.

Yet the painfully long list of increased security breaches within the past year is only the tip of the iceberg. As pointed out by U.S. Vice Admiral J. Mike McConnel (Rtd), "if you can just contaminate the data in one large bank, you could cause global banking to collapse."

Is your CU one of these overconfident institutions? Take a look at this Malta Independent report for a reality check...

Friday, August 10, 2012

Apple acquisition of AuthenTec fuels speculation on mobile payments debut

Does Apple's acquisition of fingerprint security firm AuthenTec mean that Apple is on its way into the mobile payments arena?

Image source: PDI
There is much anticipation that the next version of the iPhone will include mobile payment services, given that AuthenTec's fingerprint-scanning technology is used for authentication in mobile payment-processing - not to mention the fact that Apple competitors have already launched or are getting ready to launch mobile payment offerings.

Google Wallet has already been released, and Microsoft plans to roll out a wallet feature in its up-and-coming Windows Mobile 8 operating system towards the end of 2012. But with Microsoft, Apple, and Google "at loggerheads" and pushing their own agendas, will room have to be made for more than one type of mobile wallet?

See what Ovum Telecoms' principal analyst Tony Cripps suggests your CU can expect to transpire in the near future.

Thursday, August 9, 2012

RSA 2012 CYBERCRIME TRENDS REPORT: The Current State of Cybercrime and What to Expect in 2012

With 232 computers being infected by malware every minute, it doesn't seem like cybercrime slowing down. But is your CU's security program keeping up?

Image source: PDI
2011 brought new awareness to cybercrime worldwide, and in response, the RSA Anti-Fraud Command Center (AFCC) has issued an EMC-sponsored white paper with a list of the top six trends we can expect to see throughout 2012.

Not only are advanced threats increasing, but so is the sophistication level of attacks. As cybercriminals continue to find new ways to exploit stolen data, hactivism-related attacks meanwhile are also on the rise.

Download the RSA AFCC report and learn how your CU can better prepare for the new wave of threats.

Wednesday, August 8, 2012

Worldwide IT Outsourcing Services Spending To Surpass $251B In 2012: Gartner

A new Gartner report predicts that worldwide spending on outsourced IT services (ITO) will reach $251.7 billion in 2012, a 2.1 percent increase from the $246.6 billion spent on ITO in 2011.

Image source: Article
The cloud computing services market, which is part of the cloud-based infrastructure as a service (IaaS) segment, is the fastest-growing segment of ITO, with an estimated growth of 48.7 percent in 2012 to $5.0 billion, up from $3.4 billion in 2011. Meanwhile the application outsourcing (AO) segment is expected to reach $40.7 billion, a two-point increase from the $39.9 billion spent on AO in 2011, and data center outsourcing's (DCO) 34.5 percent representation of the entire ITO market in 2011 is expected to drop by one point in 2012.

In spite of current business slowdowns, Gartner forecasts that the ITO market in the emerging Asia/Pacific region will represent the highest growth of all regions.

What impact will the evolving ITO market have on your CU? Read the article and get more insights from the Gartner research team.

Friday, August 3, 2012

Beyond Dropbox: Security is only part of the cloud's problem

Cloud computing = security breaches + data theft/loss + service disruptions...choose your vendors wisely!

Image source: TechNewsPedia
A bit discouraging for CUs seeking data management solutions. Yet this is the message we keep hearing over and over; it's no wonder that there are still a lot of businesses that aren't about to just dump their precious data into the cyber snake pit also known as the Cloud. The potential security breach that's now got cloud storage provider Dropbox in the hot seat again with its 50 million users is merely another addition to the never-ending list of wakeup calls about how precarious an environment the Cloud can be.

As this article points out, nailing down proper security is only half the battle. The other part of the equation for a safe cloud environment is availability. Cloud collaboration service provider ftopia's usage of Amazon S3 cloud infrastructure, for instance, mirrors data across multiple physical locations - critical for cloud storage, as it backs up the data and ensures that the service is always up and running.

On the security front, extra points go to ftopia for its self-validating data integrity feature powered by Guardtime which enables users to determine whether data has been compromised - something to think about in light of Dropbox's current situation.

Know what you're signing up for before you give up your data. Read networking technology analyst Dave Greenfield's take on reaching a higher level of confidence in cloud computing.

Thursday, August 2, 2012

Black Hat is Over, But SQL Injection Attacks Persist

Privacy Rights Clearinghouse reported that 312 million data records have been lost since 2005 and 83% of hacking-related data breaches were executed via SQL injection attacks.

Image source: imsmartin
In a period of six months, UK-based secure cloud hosting company FireHost reported a huge 69% jump in SQL injection attacks. It tracks these numbers based on the hundreds of thousands of total attacks it blocks on behalf of its cloud hosting clients.

Consider the stance from cloud hosting providers. If they can detect and block an attack against one website residing on their network, then they can collect this information over time, building knowledge that can be used to protect the entire hosted community.

For the most part, SQL injection attacks are automated and website owners may be blissfully unaware that their data could actively be at risk. Sites continue to lose customer data to digital thieves. Is your CU one of them? Read the article to learn more.

Monday, July 30, 2012

Visa's PCI compliance policy change: The end of the PCI assessment?

Does Visa's recent policy change on compliance assessments for the Payment Card Industry Data Security Standard (PCI DSS) mean the death of the PCI assessment?

Image source: Searunner
This change, which provides that merchants meeting certain criteria no longer need to undergo PCI assessments, may have many merchants and security professionals jumping at the idea of not having to fill out those lengthy annual self-assessment questionnaires (SAQs) anymore during the compliance validation process, but the PCI DSS program is here to stay and the SAQs probably are too.

The good news for merchants is that several movements on the rise may limit the number of merchants required to fill out the assessment forms and reduce the amount of time needed to complete them, including clearly defining the cardholder data environment, outsourcing credit-card processing, and using Europay, MasterCard, and Visa (EMV) "chip and PIN"-enabled terminals.

Read Mike Chapple's discussion on the PCI community's shift toward "a risk-based approach that reduces the burden on merchants not engaged in high-risk activities."

Friday, July 27, 2012

Square Expects New Financing and a Loftier Value

As on-the-go payment-processing technologies continue to gain popularity with merchants and consumers, the mobile payments market is becoming increasingly competitive, with more and more new innovations on the rise and more and more investors dropping large chunks of change into it.

Image source: Article
Rumor has it that mobile payments service provider Square is on the verge of bringing in yet another hefty round of funding – this one said to be roughly $200 million – which would give the start-up an implied valuation of $3.25 billion and would strengthen its posture against competitors such as Google, Intuit, and PayPal.

Best known for its square, “pint-size” credit card reader for smartphones, Square’s number of users doubled to roughly two million in the first half of 2012 and it is currently processing $6 billion in transactions a year. The company also rolled out its Square Register, an app for small businesses to use iPads as credit card registers, and Pay With Square, an app for consumers to open “tabs” with vendors for in-store shopping by linking in their credit card accounts.

Square does have competition however, with so many other players out there also introducing new mobile payments products. Read up on the growing market for these technologies and see what’s working for Square.

Wednesday, July 25, 2012

Confidence in credit unions up, banks down

Credit unions once again take the lead over banks when it comes to trustworthiness in the public eye.

Image source: Geograph
According to the latest Chicago Booth/Kellogg School quarterly survey results, respondents’ confidence in credit unions rose to 63 percent, a few points up from the previous quarter’s 58 percent. Meanwhile the percentage of respondents who trust large banks dropped from 25 percent to 23 percent. In contrast, trust in small community banks got a more favorable 55 percent, up from 51 percent the previous quarter.

As a whole, trust in the overall financial system isn’t looking so good, down to only 21 percent of respondents stating that they do trust the system – the lowest result this category has seen since the March 2009 poll was taken as the global economic crisis steamrolled through the industry.

What else is on your members’ minds? Get more survey results from the article and see where people are putting their trust and what gives them cold feet.

Monday, July 23, 2012

Android app steals contactless credit card data

Better not let your members get too comfy with their contactless cards.

Image source: Article
paycardreader, the Android application capable of siphoning credit card data from contactless bank cards has been posted on Google Play Store by a German penetration tester.

The app, which skims card numbers, expiration dates, transaction data, and merchant IDs, was launched at Integralis Security World 12 in Germany while considered still unstable. Developer and senior consultant for Integralis Thomas Skora said the app was "only for technical demonstration" to show how data could be swiped from contactless cards, such as PayPass Mastercard and GeldKarte.

Not the first time contactless cards have been proven hackable by security researchers. And thankfully for all your CU's contactless card holders, paycardreader was available for download on Google Play Store and GitHub. Get the full story from SC Magazine.

Friday, July 20, 2012

Financial Regulators Address Cloud Security

In effort to help financial institutions address and understand the risk of cloud computing and avoid outsourcing haphazardly, the US Federal Financial Institutions Examination Council (FFIEC) has published Outsourced Cloud Computing.

Image source: Article
This resource document stresses the importance of due diligence when shopping cloud service providers. Vendors may be unaware of the regulatory requirements applicable to financial institutions, but the financial institutions are still responsible for the compliance and security of their records and therefore must make sure their providers meet risk-management, compliance, quality-of-service, and cost standards.

Focused on business continuity planning, regulatory and legal compliance, audits, information security, vendor management, and due diligence, this FFIEC resource is an excellent guide for outsourcing cloud services and hammering out your vendor contracts and service-level agreements.

Read the story in CloudTimes and take advantage of this invaluable resource for your CU.

Wednesday, July 18, 2012

How PDFs can infect your computer via Adobe Reader vulnerabilities [VIDEO]

Read at your own risk...

Image source: Article
Beware of PDFs booby-trapped by cybercriminals which can infect your computer and even potentially enable the attackers to gain access to your corporate network. These PDFs may be sent to victims via spam, or they may be planted on websites where they sit, waiting for unsuspecting visitors to click on them.

These booby-trapped PDFs exploit vulnerabilities in PDF-reading software such as Adobe Reader. The simple act of opening them can initiate automatic downloading of malicious code from the Internet and the decoy PDFs that are displayed cover up the malicious activity.

When was the last time you updated your applications like Adobe Reader with the latest security patches? Watch this video by Chet Wisniewski and see how hackers can leverage PDFs to pwn your computer.

Monday, July 16, 2012

Open source offense could be our best defense against cyberattacks

What corporate and member information does your CU have floating around in Cyberspace and how accessible is it to cybercriminals? Does your IT security team even know?

Image source: imsmartin
A growing IT challenge is how to properly protect an organization’s information systems and assets without draining the budget, but a strong defense doesn't have to be expensive. Don’t get caught up in all the media- and vendor-driven hype around cyberattacks, which caters to human interest over security basics and therefore can be misguiding, often scaring organizations into investing in security programs that might not even be appropriate for their circumstances.

Every organization is unique and so is every security product, so before spending time and money on any of them, your CU should first assess what data and processes it needs to protect and what their vulnerabilities are. Identifying any data that is publically accessible and figuring out how to safeguard it is a great place to start. Such data is readily available to attackers – no matter what security products your CU may be using.

Get the five tips for establishing a strong cyber-offence based on open source information presented by SANS Institute's Director of Research Alan Paller at the recent ISSA Los Angeles Security Summit.

Friday, July 13, 2012

Researchers Find Serious Flaws in Popular Point-of-Sale System

VeriFone Systems' widely used Artema Hybrid point-of-sale system has been found by Security Research Labs in Germany to have several serious vulnerabilities which enable attackers to alter transactions, steal card data, and perform other malicious activity.

Image source: Nik Hewitt
The series of weaknesses discovered within some of the terminals gives attackers pathways into the system both remotely and via local interface. The bigger issue however is what an attacker can do after gaining access to the system. The most serious attack scenario would involve the attacker not only stealing data from a payment card, but modifying the transaction itself as well by changing the amount charged to the card.

VeriFone is currently investigating the situtation to determine the appropriate countermeasures and will release an update when further information is available. Read the details of the report in the Threatpost article.

Wednesday, July 11, 2012

BYOD is a user-driven movement, not a secure mobile device strategy

As phenomenal as the “bring your own device” (BYOD) movement may be, it sure is complicating things for IT security planning.

Image source: imsmartin
Whether people are bringing their own mobile devices into the workplace in order to access corporate resources or simply to check their social networks, the movement is unstoppable. Recent reports from sources such as Gartner and Cisco forecast 90% of businesses supporting corporate applications on mobile devices by 2014, and a 3.47 average number of devices per person by 2015, expected to increase to 6.58 devices per person by 2020.

That’s a lot of personal devices for your credit union to manage. What to do?

The basic options are: block ALL devices not provisioned, block NO devices at all, or control access for SOME devices, granting or blocking access to resources based on need and risk. Addressing this question alone, however, is not enough, as the real challenge still remains: secure mobility. Even more important than managing device access to your network is controlling what these devices can do while they have access.

What’s your strategy? Is it working? Learn more about combining "mobile device management" (MDM) with "mobile application management" (MAM) and stay on top of BYOD.

Friday, July 6, 2012

5 Enterpriseworthy Cloud Storage Services

Cloud storage and file sharing services have been emerging at an impressive clip over the past few years.

Image source: Fotopedia
What if you want a secure business solution for your virtual office?

One solution for cloud storage and document management on the list is Ftopia, which allows you to configure a file structure and create branded, secure, tamper-evident, virtual rooms that can be shared with colleagues or clients.

Sit back and relax and let the article take you on a tour of the best cloud storage services for small to midsize businesses such as your own Credit Union. The list contains: Box, Carbonite, Egnyte HybridCloud, Ftopia, and SugarSync.

Thursday, July 5, 2012

Federal appeal court raps bank over shoddy online security

A U.S. construction company may stand a greater chance of recovering some of the US$345,000 it lost in fraudulent wire transfers that it blames on poor online banking practices of its bank.

Image source: Flickr
Fraudsters made six wire transfers using the Automated Clearing House (ACH) transfer system amounting to more than $588,000 in May 2009. About $243,000 was recovered.

The court found that Ocean Bank was not monitoring its transactions for fraud nor notifying customers before a suspicious transaction was allowed to proceed, both capabilities that it did possess with its security system.

Pay me now or pay me later...Are you doing enough to protect your members and your CU? Read the full article to see what could have been done to alter the outcome.

Monday, July 2, 2012

App Development: Been There Done That

The age of the Internet has created a sense of urgency in the world. There is a strong want for instant gratification.

Image source: Article
People expect news, status updates from friends and feedback on anything and everything instantly. So why should it be any different for mobile Apps?

When creating your own apps, be mindful of the following pitfalls described in this article.

Read the full article to see if your apps are up to snuff.