FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

Protect Your Homepage from “Man-in-the-Middle” Attacks

Melanie FriedrichsbyMelanie Friedrichs
October 19, 2012
in Risk & Security
Reading Time: 2 mins read
0
Share on Facebook

Most financial institutions invest a large portion of their security budgets to protect their software-as-a-service (SaaS) applications. They correctly perceive that many cybercriminals look for opportunities where software vendors call, send, or receive valuable data from the institution, and try to make that process as secure as possible. That said they often totally miss the boat on a very different, but sometimes equally juicy target; their own homepages. Institutional homepages play a critical role in directing traffic, and are a major target for cybercriminals. Yet, many financial institutions spend little to no resources protecting their homepages with adequate security controls. So, what does this type of crime look and why is it important to protect your homepage?

Well, imagine that you’re a tourist driving in your brand new Mercedes Benz CL in downtown Manhattan, not certain of your destination. When you reach an intersection, you encounter a police officer directing traffic in the middle of the road. The officer asks you to take a detour. After driving for a few minutes, you hit a construction blockade, and suddenly a man with a gun comes up to the driver’s window from behind your car and forces you out. In the car, you have an unencrypted laptop containing sensitive customer information that is worth millions of dollars on the black market. As the criminal drives away with your car and your customer information, you realize that the police officer at the intersection was a criminal in disguise. You were duped. Game over!

Likewise, a bank or credit union’s homepage can be compromised and modified to redirect unsuspecting customers to an identical site that collected usernames, passwords, and security questions. The hacker can then use those credentials to log into the legitimate site and access bank account numbers, credit card histories, and other sensitive (and valuable) information. This type of attack is called a “man-in-the-middle attack.”

Insufficient security investment for protecting your homepage can leave your institution vulnerable to a massive short-term hit to your bottom line and even worse long-term damage to your institution’s credibility. At minimum, your homepage should have the following controls:

  • An intrusion prevention system (IPS) where attacks are detected and responded to in real-time
  • A firewall
  • Host-based logging and monitoring
  • Hardened web server according to best practices; see http://cisecurity.org/

Protecting your homepage is just as important as protecting your SaaS applications. If you’re a bank or credit union, make sure your IT team is thinking about homepage security too!

Original Post: http://blog.andera.com/posts/2012/october/why-protecting-your-homepage-is-no-laughing-matter.aspx

Tags: cybercrimeFinancial ServicesSecurity
Previous Post

Investor Participation in the Home-Buying Market

Next Post

PayPal Regains Top Spot as Most Downloaded App

Related Posts

Flagright logo
Risk & Security

UniCredit Poland rolling out Flagright financial crime compliance platform

August 14, 2026
Cisco logo on a wall of lights
Risk & Security

Cisco clients spend more on security to prepare for Mythos, quantum

August 13, 2026
digital globe surrounded by interconnected data streams
Risk & Security

FIs cannot rely solely on legacy systems for cybersecurity

August 12, 2026
Next Post

PayPal Regains Top Spot as Most Downloaded App

Please login to join discussion

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

FinAi Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

Connect

twitter linkedin podcast podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account