Showing posts with label Authorization. Show all posts
Showing posts with label Authorization. Show all posts

Thursday, January 5, 2012

Food for New Years Thought: The Future of Banking

Every consultant worth his salt is busy trying to write something prescient on the future business model for banks. GLG Research recently published a report calling out the following key parameters, with a focus on retail banking:
1. Peer-to-Peer (P2P) Lending: An advanced technology that eliminates middlemen and directly connects borrowers and lenders.

2. Prepaid General Purpose Reloadable (GPR) cards: In return for modest commissions, a global agency network of convenience stores and retailers are now enabling cards to be “loaded” with cash. When equipped with remote deposit check capture, direct deposit, bill payment and ancillary credit, savings and investment accounts, these cards make traditional bank branching redundant. eWallets such as those touted by ISIS, Google, Visa, Amex, Paypal and FaceCash are the offspring of GPR built on the same infrastructure; similar economics but a different, arguably more convenient, access device.

3. Social Media: Social media like Facebook and LinkedIn can offer insight into customer behavior that can be applied to enhance customer acquisition, retention, and even underwriting (http://www.freepatentsonline.com/20110112957.pdf).
Banks which are early movers in this area have a great opportunity to reverse the post-2007 profitability decline. Success, in my opinion, will depend on three things:
  • Getting it done quickly
  • Getting the customer experience right
  • Getting the risk management right
Those aims are, in many areas, conflicting. A balancing act is required. Wading too timidly into these areas might cause impatient "early adopter" customers to defect, or at least decrease their activity level. Making a big splash in these areas without consideration of risk factors invites the wrong kind of customers and is sure to balloon losses.

Critical to all three of these emerging trends are the "Three Risk-Management A's of Next-Generation Banking"
  1. Analytics: Collecting the necessary data about behavior as well as customer preferences to objectively understand and address behavior in a consolidated, risk-based, customer-centric manner 
  2. Authorization: Making an informed, risk-based decision about what the bank allows the customer to do
  3. Authentication: Making sure the transaction is being done by the customer, not a fraudster
Periodically on this blog, I will individually look at these trends, highlighting the risk implications for the future banking business model.


Tuesday, December 27, 2011

Employee Fraud Thanks to the Cloud

Peer-to-peer and cloud-based file sharing may have been designed by punk kids to get free music, but now some of those punk kids are punk employees of the world's financial institutions. They have not forgotten their craft, according to the Federal Trade Commission:

"when P2P file-sharing software is not configured properly, files not intended for sharing may be accessible to anyone on the P2P network. ... we found health-related information, financial records, and drivers’ license and social security numbers--the kind of information that could lead to identity theft."
 -- FTC Chairman Jon Leibowitz on the FTC's website.
A very small fraction may intentionally use these technologies to steal sensitive or private information about the institution or its clients, but a far larger number are unwittingly exposing this information to the open Internet.


Coverage also at the Washington Post.
Many of my clients block P2P clients and websites as well as related traffic on company-owned PCs within the institution's firewall. PCs on desks in offices are probably safe. But before you pat yourself on the back, though, make sure you're looking at all potential exposure points. Wherever there's a hole punched in your corporate firewall, there's a potential loss. Ask yourself two questions:
  1. Is the same level of protection and surveillance being placed on VPN, email, webmail, virtual web conferencing, mobile email, and all other devices which span across your firewall DMZ?
  2. Is your monitoring / blocking technology based solely on the sources and destinations of traffic (ex. "safe" and "prohibited" IPs) or does it also monitor content? Perfectly benign channels such as email or virtual web conferencing usually allow files to be transmitted outside the institution in order to facilitate essential communication and collaboration. Can you, without killing these valuable tools, control WHAT data is transmitted?
 If not ... time to make a little space on the roadmap for new controls.






Monday, June 13, 2011

The Convergence of Data, Identity, and Regulatory Risks

This blog started 2011 with a post arguing for the inclusion of financial crime as a type of risk:
"Financial Crime (including topics like Money Laundering, Identity Theft, Fraud, Unauthorized Access, and Data Theft) is the next frontier in the evolution of Risk Management." 1/3/2011
Halfway through the year, this has been borne out in the headlines. While no institution is immune, headlines this week have given one clear example of what I was talking about:
"Citibank has revealed that it detected a data breach last month that exposed fully 1% of all its North American credit card customers’ account details. Citi has about 21.2 million credit card customers in North America according to its annual report, implying that close to 210,000 accounts may have been hit." Andy Greenberg, Forbes Blog.
Only 11 months ago, the remnants of Countrywide Financial settled a class-action lawsuit by setting aside $56.5 million (not including court costs) to cover claims of anyone impacted by an alleged data breach of 2.5m identity records. They, like Citi, were particularly criticized for delaying disclosure. This presumably allowed them time to assess vulnerability, fortify security controls, and perhaps get their legal arguments in order. At the same time, their delay gave identity thieves extra time to use the stolen data to defraud Countrywide's unsuspecting customers.

Countrywide's negotiated settlement puts the average hard-dollar cost of losing an identity record at $22. Many analysts estimate that the all-in number is four times as much once you factor in the soft costs such as reputation damage, lost business, and cost of additional controls. As a result, the rule of thumb I and many of my clients use to size up the cost of a data breach is $100 per identity. That makes Citi's breach quite costly!

In fact, Citi's latest incident comes atop a tide of recent compromises at a number of global firms, including a particularly disturbing breach of the "gold standard" RSA SecurID tokens which are used by many firms as an enhanced security measure for things like sensitive network access and large-dollar online banking transactions.

To pretend that these events "won't happen here" or "are black swans" and thus don't need to be factored into the price of doing business is as negligent as saying that mortgages never go underwater. Blithe assumptions like these are precisely why big, smart firms end up in catastrophe.

Finstitutions need to view financial crimes including data theft, identity theft, and fraud as risks which:
  • are intrinsic to their business, just like credit and market risks
  • are not outlier events, but rather are inevitable (and growing more frequent)
  • must be mitigated, monitored, and controlled
That's lesson one of 2011.

Today, 47 states have data privacy laws. It's the Internet, people! State-by-state laws don't make sense in this context. The good news is that, without a doubt, legislators and regulators alike have noticed these headlines and have stepped up their efforts to develop additional regulatory requirements to address the issue.

The Forbes blog goes on to say:
"The White House’s proposed cybersecurity policy outlined last month would include a mandatory federal breach disclosure law, and another bill proposed by Senator Patrick Leahy would similarly make concealing a data breach a federal crime."
These legislative proposals are atop upcoming FDIC regulations and FFIEC standards on authentication which will likely contain provisions addressing:
  • More frequent risk assessments focusing on authentication and related controls at least every 12 months and prior to implementing new electronic financial services
  • More robust controls as the risk level of transactions increases.
  • Layered security to detect and effectively respond to suspicious or anomalous activity both at initial login access and at initiation of online transaction
  • Multi-factor authentication, well beyond simple device identification and easily answered challenge questions
  • Increased customer education and awareness
Therefore, lesson two of 2011 is that regulatory compliance is another risk which should be incorporated into every FI's risk management framework, policy, and practice.

Thursday, January 20, 2011

The World is Flat for Fraud

This blog entry describes a very common fraud pattern in which criminals, using the internet, can very easily and cheaply collaborate globally to reach halfway around the world ... and right into your customers' pockets.

If you're a Fraud Prevention Exec at a financial institution (FI), this story should sound like a thousand others you hear every day from your investigative staff. If it isn't, you might want to have a look at your defenses.

If you're NOT a bank Fraud Prevention Exec, this blog post is for you! As I discussed in a recent blog post, risk management must comprehensively address all types of risk, including identity theft, unauthorized access, and financial fraud. Read the story below and ask yourself whether your FI is addressing this holistically as a risk to the enterprise.

  1. A teenage hacker in Alabama (or Shenzhen China, for that matter) downloads the code for a Zeus, URLzone, or Champi trojan virus. He experiments and figures out how to secretly place it on a computer via email.
  2. He brags online about his feat, and soon is contacted by a more seasoned fraudster, who buys the virus for $100. The teenager is ecstatic! Party on!
  3. The fraudster sends it out to 1,000 random email addresses from an anonymous account. The virus takes hold on several hundred computers. It is structured to avoid most common virus scans.
  4. The fraudster then places an ad online offering to sell access to the infected computers (yes, there are Craigslist-like sites just for criminals) for about $30 to $300 for one month. He knows he has broken some laws, but feels his exposure is limited.
  5. A criminal in Eastern Europe buys access, allowing him to activate the trojan and receive the victims' balances, account numbers, usernames, passwords, pins, identifying info, and even secret questions.
  6. The criminal uses this real customer info to set up a series of "mule" accounts at FIs he knows are vulnerable. The real customer doesn't even know these accounts exist.
  7. The criminal then uses all the usernames and passwords he has gathered to set up funds transfers from the unsuspecting customer accounts to his mule accounts. He knows to do it quietly over a period of time in order to stay under everyone's radars. He probably knows, from anecdotes of other criminals (yes, there are fraudster blogs and chatrooms), exactly what patterns or thresholds the FI is looking for.
  8. The criminal opens anonymous or mule offshore accounts in countries with weak laws Anti-Money Laundering and Know-Your-Customer laws so he doesn't have to provide any of his own identifying info.
  9. The criminal places an add on Monster.com or Craigslist for a "work-from-home payroll analyst" who can naively move money for him without raising any alarms.
  10. He hires a person in the US who, based on the criminal's legitimate-looking instructions, transfers money from the mule accounts to offshore accounts over a period of weeks. By the time the "payroll analyst" realizes they're not getting paid for their work, it's too late. The criminal is gone and his tracks are covered. Once FIs and police investigate the fraud, the "payroll analyst" looks like the prime suspect.
  11. Meanwhile, the criminal launders the funds through a series of transfers, checks, debit card transactions, bill pays, and stored value card purchases. Once the money is clean, he puts it right in his pocket and takes a 6-month vacation with YOUR paycheck.