Special offer

FFIEC Mandates “System Of Layered Security” to Combat Fraud

Reblogger Olympus Executive Realty Inc.
Real Estate Agent with Olympus Executive Realty INC. SL3227108

Special thanks to Robert Siciliano

on updates on all the latest security issues that can affect us.

This is a re-blog, thanks Robert on all your

wealth of knowledge on these matters.

Original content by Robert Siciliano

For any cave-dwelling, living-under-a-rock, head-in-the-sand, naïve, under-informed members of society who aren’t paying attention, we have serious cyber-security issues on our hands.

Black hat hackers, who break into networks to steal for financial gain, are wreaking havoc on banks, retailers, online gaming websites, and social media. Black hats cost these companies and their clients billions of dollars every year. They are using stolen usernames and passwords to transfer money through wire transfers, Automated Clearing House (ACH) and through billing fraud.

The Federal Financial Institutions Examination Council (FFIEC) has repeatedly implored that come January 2012, any lagging financial institutions will be required to significantly upgrade their security protocol. Since any existing form of authentication can be compromised, the FFIEC recommends that financial institutions should institute systems of “layered security.”

Previous FFIEC recommendations discussed authentication, suggesting that the security issue takes place when a user logs in. But in fact, not all the danger occurs at login. Other website integration points are vulnerable to security issues, particularly at the point when money is transferred.

According to the FFIEC’s recent update:

“Fraudsters use keyloggers to steal the logon ID, password, and challenge question answers of financial institution customers. This information alone or in conjunction with stolen browser cookies loaded on the fraudster’s PC may enable the fraudster to log into the customer’s account and transfer funds to accounts controlled by the fraudster, usually through wire or ACH transactions.”

One of the FFIEC’s recommendations for financial institutions involves complex device identification. iovation, an Oregon-based security firm, goes a step further offering Device Reputation, which builds on complex device identification with real-time risk assessments, the history of fraud on groups of devices, and their relationships with other devices and accounts which exposes fraudsters working together to steal from online businesses.

Smart financial institutions aren’t just complying with the FFIEC’s security recommendations, but are going beyond by incorporating device reputation into their layered security approach.

Robert Siciliano, personal security and identity theft expert contributor to iovation, discusses another databreach on Good Morning America. (Disclosures)

Posted by
 
 
Olympus Executive Realty INC.
Home of Top Producers
100% Commission Real Estate Brokerage
16903 Lakeside Dr Suite 6
Montverde, FL 34756
407-469-2000
OlympusExecutiveRealty.com
Monday-Thursday 10 am -3 pm
Closed: Friday, Saturday & Sunday & All Bank Holidays
 
 
 
Providing REALTORS with a first-class education, we present "Breakfast At Bella Collina with Olympus Executive Realty"  i-branding fundamentals.