Thursday, April 2, 2015

Human error cited as leading contributor to breaches, study shows

Human error accounts for 52 percent of the root cause of security breaches, according to a new study from CompTIA, which surveyed individuals from hundreds of companies in the U.S.

Image source: Article
“What is particularly troubling is that companies generally rate human error as a lower concern among other security issues [such as malware and hacking],” Seth Robinson, senior director of technology analysis with CompTIA.

Read the full article.

Wednesday, April 1, 2015

Bridging the Endpoint Security Gap

Current PC and Server security standards are no longer adequate to stop the latest generation of attackers. Despite your investments in security you are at greater risk than ever. You've spent a great deal of money and time building a multi-layer, defense-in-depth security strategy for your organization. But, is it enough?

Image source: Matrix White Paper
IT security vendors have acknowledged their inadequacy and are now pushing analytics – after an attack has been successful, learn about it faster than you do today. According to the latest Mandiant threat report, M-Trends 2015, based on their research the time from an organization’s earliest evidence of compromise to discovery of compromise in 2014 was 205 days. Further, only 31% of victim organizations discovered the breach internally while 69% were notified of the compromise by an external entity such as law enforcement.

Global uptake of biometrics expected to rise in 2015

ABI Research forecasts $3.1 billion global revenues in 2015 for biometrics in the consumer and enterprise sectors, with much of the growth coming from smartphone solutions.

Image source: EyeVerify
Rapid advances in the biometrics field will drive further smartphone hardware upgrades. Meanwhile, pioneering algorithm design and cloud computing services are transforming user authentication.

Are you using biometrics such as EyeVerify to protect mobile operations in your Credit Union?

Security firm reports vulnerabilities in 70 percent of mobile banking apps

People are becoming increasingly concerned about their security. They use two-step authentication, login alerts, and third-party security services to better protect their email and social media accounts.

Image source: Article
However, apparently we are all mistaken in that as many as 70 percent of the top 100 mobile banking apps on the Android operating system in the APAC region are vulnerable to security attacks and data leaks.

Think that because you are in North America that you're safe?

Thursday, March 26, 2015

Gmail Bill Pay a Bigger Threat to Banks than Google Wallet

Google's planned integration of bill pay and presentment with its immensely popular Gmail service could quickly scoop away one of the stickiest offerings of online banking sites.

Image source: Article
The product, reportedly called "Pony Express," would allow Gmail users to examine and pay emailed bills without navigating to another site.

Does your CU typically rely on emailed notifications to prompt customers to log into your own site, where you can sell upgrades and provide customer service?

Wednesday, March 25, 2015

Dangerous 'Vawtrak Banking Trojan' Harvesting Passwords Worldwide

Security researcher has discovered some new features in the most dangerous Vawtrak, aka Neverquest, malware that allow it to send and receive data through encrypted favicons distributed over the secured Tor network.

Image source: Article
Vawtrak is a sophisticated piece of malware in terms of supported features. It is capable of stealing financial information and executing transactions from the compromised computer remotely without leaving traces.

What protection measures do you have in place to protect your systems and your members?

Monday, March 23, 2015

Facebook marks its territory in mobile payment with peer-to-peer tool

Facebook announced this week that it's adding a new payment feature to its Messenger app.

Image source: Wired
The peer-to-peer payments service, which will roll out in the U.S. in a few months, allows desktop and mobile users to link their debit card information to Messenger and instantly send money to Facebook friends through the app.

What, if any, implications the service will have for your CU and your members?

Friday, March 20, 2015

Data Breaches Hit Half of America: Verizon Report

Almost half of all American consumers (45%) said data security breaches have compromised their personal payment information or that of a household member, according Verizon’s 2015 PCI Compliance Report.

Image source: Hubspot
Verizon Enterprise Solutions, a subsidiary of the communication firm, published the report March 12. It was the fourth year Verizon has published the report, which looks into how firms comply with the Payment Card Industry Data Security Standard.

Are you using firewalls, antivirus, and authenticated access portals to protect your systems and your clients?

Tuesday, March 17, 2015

Cyber-Security Is Center Stage

Sen. Elizabeth Warren (D-Mass.) met with credit union executives following her general session address. The group discussed regulatory burden, cybersecurity and other key issues that concern credit unions.

Image source: Article
Cybersecurity emerged as the most prevalent theme, however, and every general address speaker covered the topic.

Do you share other CU executives' concern about cybersecurity?

Monday, March 16, 2015

Preparing for E-Discovery

One of the critical steps in managing litigation is properly handling electronically stored information, or “ESI.”

Image source: Article
The seismic shift to ESI is a significant challenge for businesses, but it doesn’t have to be overwhelming. Taking steps now to prepare for e-discovery will pay off in the future with significant savings in time and money. You can think about e-discovery in three stages: (1) prior to litigation; (2) anticipating litigation; and (3) during litigation.

Are you waiting until after you've been sued to think about e-discovery?

Friday, March 13, 2015

Hacking Update: Breach of Montana CU's Web Site Provides Vital Lesson

The recent hacking of a Montana credit union provides a stark lesson for CUs across the nation about the security of their web sites — namely that they aren't as secure as executives think.

Image source: Google Images
Last weekend, Southwest Montana Community FCU's web site was hacked by a group claiming to be the Islamic State (ISIS).

Read the full article>

MasterCard to Bring Biometric Security to Silicon Valley Credit Union

MasterCard is diving deeper into biometric security with a new credit union partnership, according to a Credit Union Times article by Roy Urrico. The company has teamed up with Silicon Valley’s First Tech Federal Credit Union.

Image source: Article
How the biometric technology will fit in with the rest of the security program is to be determined but MasterCard has confirmed that they will be exploring a multi-modal system employing face, fingerprint, and voice recognition.

Are you forward-thinking when it comes to biometric technologies?

Wednesday, March 11, 2015

The Best and Worst Credit Union Apps

Consumers want easy access to their funds and the ability to check balances on the go, make transfers in transit and deposit checks without heading into a local branch.

Image source: Article
Credit unions often get an unjust reputation as being behind the technological curve, but a 2014 analysis by Magnify Money shows 8 of the top 10 mobile banking apps were from credit unions.

Read the article to see which apps stand out from the rest. How do you stack up against the competition?

Tuesday, March 10, 2015

U.S. credit unions locked in cyber battle with their regulator

For Debbie Matz, the head regulator for 6,350 of the nation's credit unions, it's an easy answer: a cyber hacker sneaking in through a credit union vendor, cracking through to the larger U.S. financial system and wreaking havoc along the way.

Image source: Article
For years, Matz has warned about a general vulnerability of third-party vendors in U.S. financial markets, with little success.

Have you heeded the warnings?

Monday, March 9, 2015

XML Files Used to Distribute Dridex Banking Trojan

Cybercrooks have been leveraging malicious macros hidden inside XML files to distribute the Dridex financial malware, researchers have warned.

Image source: Article
It’s not uncommon for cybercriminals to use specially crafted Microsoft Office files that contain macros for malware distribution. However, attackers usually rely on Microsoft Word and Excel documents, not the XML (Extensible Markup Language) format.

Are you detecting these types of trojans?

Using Smart Phones to Improve Bank and Apple Pay Security

Recently, we've seen a lot of media coverage around Apple Pay being used for fraudulent activities by criminals with stolen identities and credit cards.

Image source: Article
Many of the articles highlight that fraud is stemming from a back door in the activation process called the “yellow path”. The yellow path is the process by which the bank can put the card activation on hold to do additional verifications.

Is your firm prepared to move beyond old fraud prevention technologies?
Post provided by:

Wednesday, March 4, 2015

How Same-Day ACH Transactions Will Affect Your Fraud Prevention Operations

by Damien Hugoo, Product Manager, Easy Solutions

The implementation of same-day Automated Clearing House (ACH) transactions has been getting a good amount of media attention lately. American Bankers Association (ABA) believes that widespread adoption of same-day ACH transactions represents a fundamental step to promote faster payments across the entire industry.

Image source: Article
Initial reaction has been that same-day settlement will pinpoint fraud more rapidly and as a result, customers will be alerted quicker. While part of this is true, there is major work to be done to pinpoint fraud faster.

In terms of fraud operations, right now most banks processes have a 2-day timeframe to tell the Federal Reserve that they want to return the ACH debit. With Same-Day ACH, banks will be forced to reengineer their entire fraud program and compress all their current processes into the 2-hour window. Subsequently, all ACH fraud prevention processes will have to start to be automated for those transactions.

Is your credit union prepared for these changes?

For information about real-time transaction monitoring download this whitepaper: An Introduction to Transaction Anomaly Detection.

Post provided by:

Tuesday, March 3, 2015

Apple Pay a haven for 'rampant' credit card fraud, say experts

Apple and its banker pals may have inadvertently lowered the barrier to credit card fraud by adding pay-by-wave technology to iPhones, security experts fear.

Image source: Article
Payment cards can be added to Apple Pay by taking a photo of the card, and allowing a device to run optical character recognition over the image to fill out the long card number, expiry dates and other details. These numbers can be entered manually, so physical access to a card is not needed.

Are you an early adopter putting your members at risk?

Monday, March 2, 2015

Brian Panicko demos CellTrust SecureLine for Good

With the integration of CellTrust SecureLine for Good and Good Work, financial advisors, agents, analysts, brokers and wealth managers can seamlessly and securely access corporate email, make secure phone calls to business contacts, and send secure text messages all from their personal device.

Because the employees’ personal devices are equipped with a second mobile business number, business and personal communications are kept separate and private.

Go to www.celltrust.com/finserv-good-knox/ to learn more about CellTrust SecureLine for Good for financial services organizations. Alternatively, if you're ready, give the app a try.

Mobile Security By The Numbers

As ubiquity of mobility paired with the availability of cloud continues to drive major technological disruptions within just about every type of enterprise transacting business today, CIOs and CISOs are increasingly put on notice to incorporate mobile into their security plans or risk irrelevance.

Image source: Article
Over the past several months, numerous surveys and studies have done a good job offering up some statistical proof points about the scope of the mobile security dilemma.

Read the article to see a collection of salient stats, including:

Friday, February 27, 2015

Secure credit cards: Retailers are on board, banks and credit unions lag

Government and the private sector don't always see eye to eye, but we're working together on an issue of great importance to Californians and all Americans: making credit card purchases safer.

Image source: Wikipedia
One crucial sector of the business community, however, has yet to fully buy in.

Why is it credit unions continue to provide their customers with outdated, riskier technology?

Thursday, February 26, 2015

Three questions with a CU CEO on adapting to new technology

In October, the credit union had a soft opening of a new, innovative branch with only one employee. The branch features a computer touch screen table and wall, interactive loan consultation and an interactive teller machine (ITM) that video conferences in a remote representative.

Image source: Article
SEFCU President and CEO Michael Castellana said the credit union did not model the branch after any existing financial institutions.

Read the article to see how SEFCU is adapting to new technologies and read what is next for the credit union.

Tuesday, February 24, 2015

Windows? NO, Linux and Mac OS X Most Vulnerable Operating System In 2014

Apple’s operating system is considered to be the most secure operating system whether it’s Mac OS X for desktop computers or iOS for iPhones.

Image source: Article
But believe it or not, they are the most vulnerable operating system of year 2014. According to an analysis by the network and security solutions provider GFI, the top three most vulnerable operating system are: Apple’s Mac OS X, Apple iOS, and Linux kernel.

What operating system flavors are you using within your credit union?

Video Communication Isn't Just for Big Banks

The number of routine transactions conducted at community bank and credit union branches has gone down 10% annually over the past four years.

Image source: Article
Conversely, mobile traffic is skyrocketing with 50,000 customers downloading banks’/credit unions’ mobile apps each week and executing anywhere from 250 to 300 million online banking logins each month.

Customers are sending a message: Did you get it?

Monday, February 23, 2015

7 Reasons Millennials Are Turning to Credit Unions Instead of Banks

Reason 4: Mobile banking is the new norm - millennials gravitate toward technology and apps that are on the same level as big banks, and found that credit unions are offering “just as many” online services and apps.

Image source: Article
Some Millennials prefer to do all their banking from their cellphones and some feel that banks are not on par with their offerings. Switching to a credit union two years ago meant that Chris Kummer, 33, an associate account executive in public relations in Seattle, could keep using his favorite three financial apps and maintain the personalized service.

Is your credit union keeping up with the millennials needs and desires? Be sure to read the whole article for the other 6 reasons.

Hiring Hackers to Find Software Bugs

When it comes to finding and fixing software bugs, companies have a variety of priorities.

Image source: Article
But whether it’s protecting credit card data or personally identifiable information, securing intellectual property, or preventing online gamers from cheating, one fact remains: finding and fixing security bugs is difficult and labor intensive.

This article looks at the risks and rewards of offering software bug bounties to hackers.

Friday, February 20, 2015

IT's top 3 cloud migration errors

The good news is that most companies are now moving to the cloud; the bad news is that many are doing it poorly

Image source: Flickr
Despite all the best-practice information out there, huge mistakes are still widely made.

Have you migrated to the cloud? Did you do so successfully?

Wednesday, February 18, 2015

An updated list of the merchants, cards and apps that accept Apple Pay

Nineteen new banks and credit unions now support Apple Pay.

Image source: Article
These include: Affinity Federal Credit Union, Cabela’s CLUB, Central Bank, Credit Union of Southern California, Farmers & Merchants Bank of Long Beach, First National Bank of Omaha, First Sentry Bank, FirstBank, Grow Financial Federal Credit Union, Ideal Credit Union, Morgan Stanley, Redwood Credit Union, State Department Federal Credit Union, Teachers Credit Union, Technology Credit Union, The Northern Trust Company, TIB-The Independent BankersBank, United Federal Credit Union, and Utah First Federal Credit Union.

Read the article to see some of the businesses already using Apple Pay.

Morgan Stanley leads 20 new bank and credit union additions for Apple Pay

Apple continues to expand the reach of its popular mobile payment system, with the Cupertino company rolling out support for cards from nearly two dozen additional financial institutions — including major investment bank Morgan Stanley — on Wednesday.

Image source: Article
The addition of Morgan Stanley may seem odd, given that the firm offers no retail banking services, but that is not the case. Investment banks like Morgan Stanley often offer exclusive credit cards to customers who use the bank's wealth management services.

Read the article to see some of the more than 700 banks and credit unions that have signed up to integrate Apple Pay.

Cloud security certifications: How important are they?

More and more certifications are being created around cloud security. Expert Sean Martin looks at some of the more prominent certifications and examines their value.

Image source: Article
If you are a CSO working for a company that leverages cloud technologies to run its business, what should you look for in a candidate to add to your staff?

Read the article to of see what some of the top certifications are for cloud security.

Credit unions set to take on banks with launch of debit cards

Eleven of the largest credit unions in Ireland are set to launch debit card services, allowing them to compete head-on with banks by offering full current accounts.

Image source: Article
The move is set to transform the services offered by credit unions, which have been concentrated on small loans and savings facilities up to now.

How does your CU stack up to those in Ireland?

Tuesday, February 17, 2015

SMBs Prep for EMV Shift: How Ready is Your Business?

There is a lot of work involved in implementing [EMV], and some banks have decided to go with a simpler more expedient roll-out, and are still meeting the minimum requirements of the card association while avoiding the time and overhead costs of issuing pins.

Image source: Article
Long Island City, NY-based UNFCU was an early adopter of EMV and one of the only credit card companies that issues chip cards.

Are you EMV ready?

Bank Hackers Steal Millions via Malware

In late 2013, an A.T.M. in Kiev started dispensing cash at seemingly random times of day. No one had put in a card or touched a button. However, the errant machine appears to be the least of the bank’s problems.

Image source: Article
The scope of this attack on more than 100 banks and other financial institutions in 30 nations could make it one of the largest bank thefts ever — and one conducted without the usual signs of robbery.

No bank has come forward acknowledging the theft. Is your firm one of them?

Monday, February 16, 2015

Banking Trojan Dyreza sends 30,000 malicious emails in one day

A massive spam wave is installing banking Trojan Dyreza on tens of thousands of computers to steal sensitive financial data from unsuspecting customers.

Image source: Flickr
30,000 malicious emails were sent in just one day from spam servers in the UK, France, Turkey, US and Russia.

Read the article to learn more about server-side polymorphism.

App Economy Demands "Security-First"

Protection is still the main driver for security, but organizations understand the application economy demands a new view and approach to security.

Image source: Article
Key findings include the following: mobility matters, the desire to innovate quickly, new attitudes adopted, and increase in security investment.

Read the article to access additional details uncovered by the research.

Thursday, February 12, 2015

A Credit Union Cyberattack Defense Manual

With the ever increasing risks that are associated with cyberattacks, companies across industries are realizing the importance of having a cybersecurity team.

Image source: Article
Cyber criminals are becoming more sophisticated, and they are able to hack into the biggest financial institutions across the globe, like JP Morgan Chase and HSBC. Any small dropping of the guard can result in catastrophic theft of customer financial records, business data and syphoning of a large amount of funds.

Have you dropped your guard?

Tuesday, February 10, 2015

The Day Memory Scraping Malware Lost

Every organization today is, or should be, concerned about the spread of dangerous malware being launched in targeted attacks. An example of a recent trend is the aggressive use of memory scraping malware by cyber-criminals against any organization that accepts credit cards – this incudes retail, healthcare, financial services, governmental entities and others. The headlines reflect the scale of the issue – every week there are new headlines of record setting data loss and credit card data theft in organizations of all sizes.

Image source: Wikipedia
The issue that causes the most concern about these damaging attacks is that each of these breached organizations had invested a great deal of money and effort to put in place and support a multi-layered in-depth security solution. In addition, they were in certified compliance with standards like PCI DSS, HIPAA, GLBA and other regulations. Doubt has surfaced for many organizations who are now wondering “If these large sophisticated companies that take security seriously were breached, how can I be safe?”

Monday, February 9, 2015

Networking Your Way to a Datacenter in the Cloud

As the dream of the fully virtualized data center comes closer to reality, the race is on to integrate SDN into the cloud stack.

Image source: Wikipedia
According to U.K. researcher Companies and Markets, an expanding cloud is expected to spur the growth of network fabric topologies as top organizations look to build key functions like continuous data availability, application flexibility and rapid architecture deployment.

What is your firm's place in the SDN cloud race?

Friday, February 6, 2015

Study: Cloud, Mobile Computing to Drive Financial Services Security Market Growth

Research and Markets has forecast the global market for cybersecurity offerings within the banking, financial services and insurance sector to yield a 13.14 percent compound annual growth rate through 2019.

Image source: Article
The increasing use of cloud security and mobile platforms is projected to drive the BFSI cybersecurity market’s growth over the next four years, the research firm said.

Does your firm use any of the firms profiled in the report? (BAE Systems, Booz Allen Hamilton, Computer Sciences Corp., FireEye, IBM and Symantec)

Mobile fraud hits enterprises in the pocket to tune of $240m, report finds

New survey data from mobile identity provider TeleSign has found that enterprises have lost up to $240m (£157.3m) a year because of mobile e-commerce fraud.

Image source: Article
The study, conducted by J. Gold Associates and sponsored by TeleSign and RSA, EMC’s security division, found average revenue loss due to mobile fraud was $92.3m per year (£60.54m).

Is your firm one of the many companies not prepared – or just not bothered – about potential repercussions with respect to the state of mobile security?

Thursday, February 5, 2015

Cuba Fertile Ground for Credit Unions

If Dan Mica had his way, he would be on a flight to Cuba tomorrow to help establish the nation’s first credit unions and boost the financial wellbeing of the country’s 11 million citizens. But Mica, a former U.S. Congressman from Florida, former president/CEO of CUNA and current president of consulting firm The DMA Group, knows that such a process isn’t simple.

Image source: Article
A business-to-business connection between the U.S. and Cuba of any kind will have been a long time coming.

Is there a way to partner with another Credit Union based in Cuba?

Wednesday, February 4, 2015

iPhone Security Could Improve at NCUA: OIG Audit

The NCUA’s Inspector General recommended ways the agency could improve its security policies and controls regarding agency-issued mobile devices, such as iPhones, to enhance the protection of its data and resources.

Image source: Article
The NCUA had been issuing agency-owned iPhones to employees and contractors since April 2012, which could access the agency’s exchange server.

Do you agree with IG's recommendation that the NCUA supplement or enhance its existing mobile device security policies, controls and configuration settings by addressing the security measures, such as passcode guidance or controls, unauthorized applications, container-based encryption, bluetooth controls and QR codes?

Friday, January 30, 2015

North American bank IT spending climbs as firms invest in external services

Banks in North America are ramping up IT spending on retail banking services and digital channels this year, with total IT spend expected to reach $64.8 billion by 2016. The figures represent a 4.5% increase this year, as financial institutions increasingly turn to external software provider and specialists to bolster their abilities.

Image source: Article
IT security is expected to prove quite a struggle for banks in the coming years, as banks are effectively locked in an endless battle with fraudsters.

Where will your spending be focused in 2015?

Data Breaches Affect Credit Unions More Compared to Large Banks

The breach of data at retailers like Staples, Target and Home Depot have a crippling effect on the member services of the credit unions, namely as the expense of ensuring the privacy of customers post breaches is the responsibility of non-profit financial institutions. As one example, the Desert School Credit Union, in 2013, was forced to reissue about 40,000 credit and ATM cards after a data breach.

Image source: Article
CUNA, which claims to represent almost 90 percent of total US credit unions numbering almost 6,700, has plans to push the issue to the Congress and also seek the legislation to protect the values of members. The Dodd-Frank legislation also impacts the credit unions.

What is your position on this legislation?

Thursday, January 29, 2015

Spike in Fake ID Schemes Confounds Banks' Fraud Filters

Identity fraud, especially so-called synthetic schemes that use completely or partly made-up identities, is on the rise and hitting banks hard. Using new techniques, hackers can stitch digital data together and sell it on the black market as a fully emulated debit card that allows an individual to walk up to an ATM, enter the PIN and withdraw cash.

Image source: Article
It is hard to measure the frequency of synthetic ID fraud, in large part because "there’s no self-reporting victim," notes Richard Parry, a consultant and a former security executive at JPMorgan Chase, Citigroup, and Visa.

Credit unions have an obligation to "know their customer". What is your firm doing to identify and combat identity theft and fraud for your members?

Wednesday, January 28, 2015

'Masquerading': New Wire Fraud Scheme

A new impersonation scheme is taking aim at business executives to perpetuate ACH and wire fraud, says Bank of the West's David Pollino, who explains steps institutions should take now to protect their customers.

Image source: Article
Once inside and posing as company executives, the criminals could send e-mails to the bank to request wire transfers from the business's account to a bogus account.

Is your firm susceptible to this attack?

Monday, January 26, 2015

Heartbleed Alert: Vulnerability Persists

The Heartbleed bug remains present on about 250,000 servers and other systems that connect to the Internet. Multiple security experts say that while they don't have the means to independently verify them, the continuing prevalence of Heartbleed bugs in systems does not surprise them.

Image source: Article
Heartbleed was fixed with OpenSSL version 1.0.1g, which was released on April 7, 2014, after which many enterprises went into furious patching mode, beginning with their OpenSSL-using Apache servers.

Have you addressed the Heartbleed bug yet?