Wednesday, August 29, 2012

How National Australia Bank Uses Cloud Computing to Cut Costs and Shrink Its Carbon Footprint

How much money, energy, and time get drained by your CU's current systems and processes?

Image source: freeaussiestock.com / CC BY 3.0
More and more financial institutions around the globe are finding that revising their energy policies and shifting toward "green IT" practices are key in optimizing resource management.

Spanning everything from IT to travel fleet, the energy reduction program adopted by the $782 billion-asset bank and Open Data Center Alliance member National Australia Bank (NAB) exemplifies the significant cost-savings and environmental benefits made possible by data virtualization through scalability, increased efficiency, and resource conservation.

Time for a data center overhaul for your CU? Read the BTN interview with NAB's Dennis McGee to learn about this large and complex institution's approach to green IT.

Monday, August 27, 2012

Convenience is Key for Bank Consumers: Report

When it comes to day-to-day banking, convenience is where it's at for your members, as found in a recent poll of 1,231 U.S. consumers conducted by Angus Reid Public Opinion in conjunction with TD Bank.

Image source: denn / CC BY-SA 2.0
This should come as no shock, especially in today's rapidly evolving technological world. The poll also found that online banking is the most frequent banking activity engaged in by consumers, with those surveyed reporting that they go online to manage their finances at an average of five times each month.

Also not surprisingly, "easy online banking" was the top response in terms of the most important factor for basic checking accounts.

What else is important to your members? Check out the results of the poll and hear it from them.

Friday, August 24, 2012

Zeus Variant Targets U.S. Accounts

The FBI has issued a warning to financial institutions about a new wave of ransomware which freezes and hijacks endpoint computer operating systems and attempts to extort funds from users while simultaneously working in the background to also rob their account data.

Image source: Article
Powered by the Zeus malware variant Citadel and the drive-by virus Reveton, these "targeted and convincing" attacks generate messages - often under the guise of the FBI - notifying users of their "illegal" Internet activity and demand that they pay fines in order to regain control of their computers. Meanwhile keyloggers are launched to steal online account credentials and other financial information.

Enhancing back-end fraud-prevention systems and processes so that malware is blocked from taking over your members' accounts even if their endpoints do become infected is critical, as is quick detection and removal.

The best defense, however, is educating your members. Given the lack of familiarity with ransom attacks, users in the U.S. have proven to be easy targets. Find out what both your CU and your members need to know.

Wednesday, August 22, 2012

Man-in-the-Mobile Attacks Target the Bank Accounts of Android Users

Android users in Portugal, Spain, the Netherlands, and Germany have been plagued by man-in-the-mobile (MITMO) attacks which enable cybercriminals to gain access to victims' banking data and make fraudulent transfers.

Image source: Photozou / CC BY 2.1
Powered by malwares such as Tatanga and SpyEye (SPITMO), these attacks start off as web injections via Windows users' PCs and come under the guise of notices from the victims' financial institutions instructing them to install a security application onto their mobile phones. If installed onto a device that runs on Google's operating system, the app gives the attacker access to all SMS traffic, including banking transaction authorization codes.

With Android devices accounting for most of the smartphone market in these countries, the Android platform is the obvious target and you must ask how many of your CU's members are also Android users. On the upside, there are preventative technologies out there, such as Guardtime's keyless data integrity validation service which shows when a MITMO attack has occurred and can help your CU intercept the attacker.

Learn more about how to spot these attacks.

Monday, August 20, 2012

Technology change agents make e-discovery better or worse

Change agents in technology, including social networking, cloud computing, and bringing your own devices to work, are changing how we do business and communicate, and impacts how organizations need to approach e-discovery.

Image source: imsmartin
With so much data and so many different data sources and destinations to keep track of, companies are struggling to keep up with security, forensics, and e-discovery.

Proper e-discovery is driven by proper forensics, which is fed by proper security management. These three functional turfs are converging at breakneck speed, and vendor offerings are starting to merge.

Read the full article to learn what the merging of these three trends means for your credit union.

A portion of this article reprinted with permission from ALM's Legal Technology News. Further duplication is prohibited.

Friday, August 17, 2012

Understanding the risks of different types of Mobile Banking transactions...

While leaving responsibility for personal mobile banking security solely in the hands of financial institutions is a poor strategy, your CU needs to do its part. Is yours?

Image source: gadgetdude / CC BY 2.0
There are a number of different mobile banking techniques, and with each comes a specific set of security rationale. Both your CU and its members need to understand the various possible attack scenarios against mobile banking systems and what can be done to minimize risk.

Security controls built into smartphone operating systems are now thought to be stronger than those built into desktop computers; however mobile device malware threats are growing rapidly. Your members can easily undermine mobile banking security and thus actively monitoring the health of their devices can help them to protect their data.

Read the article and learn about the various types of mobile banking transactions and their associated risks.

Wednesday, August 15, 2012

Criminals push malware by 'losing' USB sticks in parking lots

Finders keepers...or so it seems that's what a cybercriminal was counting on in order to hack into DSM's corporate network.

Image source: Article
Employees of the Dutch branch of the multinational chemical company recently found several USB sticks on the ground in the company parking lot which appeared to be lost by their original owner. When DSM's IT department examined the sticks, they were found to be loaded with malware set to autorun on company computers and harvest employee login credentials.

Did a cybercriminal drop these infected USB sticks in the company parking lot in hopes that unsuspecting employees would find and use them?

Don't let cybercriminals outsmart your CU's personnel. Read the full article for more details.

Monday, August 13, 2012

Phishing the financial and banking seas

Thanks to the emergence of mobile devices, social networks, and new technologies such as Near Field Communications, the attack surface area against financial institutions has expanded at an explosive rate, providing cybercriminals more opportunities than ever to go "fishing" at your CU's expense.

Image source: Hitchster / CC BY 2.0
The top threats are payment card fraud, cheque fraud, phishing/vishing, account takeover, and third-party point-of-sale skimming, with about 80% of such incidents experienced by banking customers and an exponential escalation of malware attacks targeting financial transactions. Many large financial institutions are confident in their security measures and preparedness against the modern threat landscape, but recent history suggests otherwise.

Yet the painfully long list of increased security breaches within the past year is only the tip of the iceberg. As pointed out by U.S. Vice Admiral J. Mike McConnel (Rtd), "if you can just contaminate the data in one large bank, you could cause global banking to collapse."

Is your CU one of these overconfident institutions? Take a look at this Malta Independent report for a reality check...

Friday, August 10, 2012

Apple acquisition of AuthenTec fuels speculation on mobile payments debut

Does Apple's acquisition of fingerprint security firm AuthenTec mean that Apple is on its way into the mobile payments arena?

Image source: PDI
There is much anticipation that the next version of the iPhone will include mobile payment services, given that AuthenTec's fingerprint-scanning technology is used for authentication in mobile payment-processing - not to mention the fact that Apple competitors have already launched or are getting ready to launch mobile payment offerings.

Google Wallet has already been released, and Microsoft plans to roll out a wallet feature in its up-and-coming Windows Mobile 8 operating system towards the end of 2012. But with Microsoft, Apple, and Google "at loggerheads" and pushing their own agendas, will room have to be made for more than one type of mobile wallet?

See what Ovum Telecoms' principal analyst Tony Cripps suggests your CU can expect to transpire in the near future.

Thursday, August 9, 2012

RSA 2012 CYBERCRIME TRENDS REPORT: The Current State of Cybercrime and What to Expect in 2012

With 232 computers being infected by malware every minute, it doesn't seem like cybercrime slowing down. But is your CU's security program keeping up?

Image source: PDI
2011 brought new awareness to cybercrime worldwide, and in response, the RSA Anti-Fraud Command Center (AFCC) has issued an EMC-sponsored white paper with a list of the top six trends we can expect to see throughout 2012.

Not only are advanced threats increasing, but so is the sophistication level of attacks. As cybercriminals continue to find new ways to exploit stolen data, hactivism-related attacks meanwhile are also on the rise.

Download the RSA AFCC report and learn how your CU can better prepare for the new wave of threats.

Wednesday, August 8, 2012

Worldwide IT Outsourcing Services Spending To Surpass $251B In 2012: Gartner

A new Gartner report predicts that worldwide spending on outsourced IT services (ITO) will reach $251.7 billion in 2012, a 2.1 percent increase from the $246.6 billion spent on ITO in 2011.

Image source: Article
The cloud computing services market, which is part of the cloud-based infrastructure as a service (IaaS) segment, is the fastest-growing segment of ITO, with an estimated growth of 48.7 percent in 2012 to $5.0 billion, up from $3.4 billion in 2011. Meanwhile the application outsourcing (AO) segment is expected to reach $40.7 billion, a two-point increase from the $39.9 billion spent on AO in 2011, and data center outsourcing's (DCO) 34.5 percent representation of the entire ITO market in 2011 is expected to drop by one point in 2012.

In spite of current business slowdowns, Gartner forecasts that the ITO market in the emerging Asia/Pacific region will represent the highest growth of all regions.

What impact will the evolving ITO market have on your CU? Read the article and get more insights from the Gartner research team.

Friday, August 3, 2012

Beyond Dropbox: Security is only part of the cloud's problem

Cloud computing = security breaches + data theft/loss + service disruptions...choose your vendors wisely!

Image source: TechNewsPedia
A bit discouraging for CUs seeking data management solutions. Yet this is the message we keep hearing over and over; it's no wonder that there are still a lot of businesses that aren't about to just dump their precious data into the cyber snake pit also known as the Cloud. The potential security breach that's now got cloud storage provider Dropbox in the hot seat again with its 50 million users is merely another addition to the never-ending list of wakeup calls about how precarious an environment the Cloud can be.

As this article points out, nailing down proper security is only half the battle. The other part of the equation for a safe cloud environment is availability. Cloud collaboration service provider ftopia's usage of Amazon S3 cloud infrastructure, for instance, mirrors data across multiple physical locations - critical for cloud storage, as it backs up the data and ensures that the service is always up and running.

On the security front, extra points go to ftopia for its self-validating data integrity feature powered by Guardtime which enables users to determine whether data has been compromised - something to think about in light of Dropbox's current situation.

Know what you're signing up for before you give up your data. Read networking technology analyst Dave Greenfield's take on reaching a higher level of confidence in cloud computing.

Thursday, August 2, 2012

Black Hat is Over, But SQL Injection Attacks Persist

Privacy Rights Clearinghouse reported that 312 million data records have been lost since 2005 and 83% of hacking-related data breaches were executed via SQL injection attacks.

Image source: imsmartin
In a period of six months, UK-based secure cloud hosting company FireHost reported a huge 69% jump in SQL injection attacks. It tracks these numbers based on the hundreds of thousands of total attacks it blocks on behalf of its cloud hosting clients.

Consider the stance from cloud hosting providers. If they can detect and block an attack against one website residing on their network, then they can collect this information over time, building knowledge that can be used to protect the entire hosted community.

For the most part, SQL injection attacks are automated and website owners may be blissfully unaware that their data could actively be at risk. Sites continue to lose customer data to digital thieves. Is your CU one of them? Read the article to learn more.

Monday, July 30, 2012

Visa's PCI compliance policy change: The end of the PCI assessment?

Does Visa's recent policy change on compliance assessments for the Payment Card Industry Data Security Standard (PCI DSS) mean the death of the PCI assessment?

Image source: Searunner
This change, which provides that merchants meeting certain criteria no longer need to undergo PCI assessments, may have many merchants and security professionals jumping at the idea of not having to fill out those lengthy annual self-assessment questionnaires (SAQs) anymore during the compliance validation process, but the PCI DSS program is here to stay and the SAQs probably are too.

The good news for merchants is that several movements on the rise may limit the number of merchants required to fill out the assessment forms and reduce the amount of time needed to complete them, including clearly defining the cardholder data environment, outsourcing credit-card processing, and using Europay, MasterCard, and Visa (EMV) "chip and PIN"-enabled terminals.

Read Mike Chapple's discussion on the PCI community's shift toward "a risk-based approach that reduces the burden on merchants not engaged in high-risk activities."

Friday, July 27, 2012

Square Expects New Financing and a Loftier Value

As on-the-go payment-processing technologies continue to gain popularity with merchants and consumers, the mobile payments market is becoming increasingly competitive, with more and more new innovations on the rise and more and more investors dropping large chunks of change into it.

Image source: Article
Rumor has it that mobile payments service provider Square is on the verge of bringing in yet another hefty round of funding – this one said to be roughly $200 million – which would give the start-up an implied valuation of $3.25 billion and would strengthen its posture against competitors such as Google, Intuit, and PayPal.

Best known for its square, “pint-size” credit card reader for smartphones, Square’s number of users doubled to roughly two million in the first half of 2012 and it is currently processing $6 billion in transactions a year. The company also rolled out its Square Register, an app for small businesses to use iPads as credit card registers, and Pay With Square, an app for consumers to open “tabs” with vendors for in-store shopping by linking in their credit card accounts.

Square does have competition however, with so many other players out there also introducing new mobile payments products. Read up on the growing market for these technologies and see what’s working for Square.

Wednesday, July 25, 2012

Confidence in credit unions up, banks down

Credit unions once again take the lead over banks when it comes to trustworthiness in the public eye.

Image source: Geograph
According to the latest Chicago Booth/Kellogg School quarterly survey results, respondents’ confidence in credit unions rose to 63 percent, a few points up from the previous quarter’s 58 percent. Meanwhile the percentage of respondents who trust large banks dropped from 25 percent to 23 percent. In contrast, trust in small community banks got a more favorable 55 percent, up from 51 percent the previous quarter.

As a whole, trust in the overall financial system isn’t looking so good, down to only 21 percent of respondents stating that they do trust the system – the lowest result this category has seen since the March 2009 poll was taken as the global economic crisis steamrolled through the industry.

What else is on your members’ minds? Get more survey results from the article and see where people are putting their trust and what gives them cold feet.

Monday, July 23, 2012

Android app steals contactless credit card data

Better not let your members get too comfy with their contactless cards.

Image source: Article
paycardreader, the Android application capable of siphoning credit card data from contactless bank cards has been posted on Google Play Store by a German penetration tester.

The app, which skims card numbers, expiration dates, transaction data, and merchant IDs, was launched at Integralis Security World 12 in Germany while considered still unstable. Developer and senior consultant for Integralis Thomas Skora said the app was "only for technical demonstration" to show how data could be swiped from contactless cards, such as PayPass Mastercard and GeldKarte.

Not the first time contactless cards have been proven hackable by security researchers. And thankfully for all your CU's contactless card holders, paycardreader was available for download on Google Play Store and GitHub. Get the full story from SC Magazine.

Friday, July 20, 2012

Financial Regulators Address Cloud Security

In effort to help financial institutions address and understand the risk of cloud computing and avoid outsourcing haphazardly, the US Federal Financial Institutions Examination Council (FFIEC) has published Outsourced Cloud Computing.

Image source: Article
This resource document stresses the importance of due diligence when shopping cloud service providers. Vendors may be unaware of the regulatory requirements applicable to financial institutions, but the financial institutions are still responsible for the compliance and security of their records and therefore must make sure their providers meet risk-management, compliance, quality-of-service, and cost standards.

Focused on business continuity planning, regulatory and legal compliance, audits, information security, vendor management, and due diligence, this FFIEC resource is an excellent guide for outsourcing cloud services and hammering out your vendor contracts and service-level agreements.

Read the story in CloudTimes and take advantage of this invaluable resource for your CU.

Wednesday, July 18, 2012

How PDFs can infect your computer via Adobe Reader vulnerabilities [VIDEO]

Read at your own risk...

Image source: Article
Beware of PDFs booby-trapped by cybercriminals which can infect your computer and even potentially enable the attackers to gain access to your corporate network. These PDFs may be sent to victims via spam, or they may be planted on websites where they sit, waiting for unsuspecting visitors to click on them.

These booby-trapped PDFs exploit vulnerabilities in PDF-reading software such as Adobe Reader. The simple act of opening them can initiate automatic downloading of malicious code from the Internet and the decoy PDFs that are displayed cover up the malicious activity.

When was the last time you updated your applications like Adobe Reader with the latest security patches? Watch this video by Chet Wisniewski and see how hackers can leverage PDFs to pwn your computer.

Monday, July 16, 2012

Open source offense could be our best defense against cyberattacks

What corporate and member information does your CU have floating around in Cyberspace and how accessible is it to cybercriminals? Does your IT security team even know?

Image source: imsmartin
A growing IT challenge is how to properly protect an organization’s information systems and assets without draining the budget, but a strong defense doesn't have to be expensive. Don’t get caught up in all the media- and vendor-driven hype around cyberattacks, which caters to human interest over security basics and therefore can be misguiding, often scaring organizations into investing in security programs that might not even be appropriate for their circumstances.

Every organization is unique and so is every security product, so before spending time and money on any of them, your CU should first assess what data and processes it needs to protect and what their vulnerabilities are. Identifying any data that is publically accessible and figuring out how to safeguard it is a great place to start. Such data is readily available to attackers – no matter what security products your CU may be using.

Get the five tips for establishing a strong cyber-offence based on open source information presented by SANS Institute's Director of Research Alan Paller at the recent ISSA Los Angeles Security Summit.