Ransomware attacks are on the rise across all industries, with financial institutions being a favored target given the customer information and access to cash. But there are steps every bank can take to ward off this type of cyber risk — as well as phishing and DDoS threats — says Barbara Kissner, chief information security officer at Tassat, a global provider of financial technologies and products for digital payments, in today’s episode of “The Buzz.”
In this Bank Automation News podcast, Kissner also discusses the due diligence that banks and other financial institutions should perform to minimize cybersecurity threats while working with third-party vendors.
Subscribe to The Buzz Podcast on iTunes, Spotify, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Good day My name is Myra Thomas and I’m editor Bank Automation News. Recently I had the chance to speak with Barbara Kissner. She’s from tacit, there she was recently appointed as their chief information security officer working to oversee the company’s infrastructure technology and data security. tassets, a global provider of financial technologies and products for digital payments. The New York based FinTech company provides blockchain based technology solutions for digital payments and is delivered the first blockchain based digital payments platform approved by the NY DFS that’s transacted significant volume to date. Miss kiss, there’s a specialist in technology transformation, cybersecurity, risk management, organizational resilience and governance. And she brings over 25 years of experience to her role building and managing security programs for financial services firms. in that course of her career throughout her career, she has held multiple roles, including a VP and Chief Information Officer for Amalgamated Bank and SVP CIO and Chief Compliance Officer at International Fidelity Insurance Company. Miss Kissner has extensive extensive experience leading technology and digital transformation projects, managing cybersecurity programs for multinationals and delivering enterprise resiliency and discover disaster recovery strategies. And I want to thank her for joining us today. And we’ll jump right into our interview. And this interview is going to be concentrated on cybersecurity and financial institutions. And, Barbara, thank you very much for joining me. Let’s talk a little bit about social engineering, whether you’re talking about phishing, scareware, etc, every obviously all of that is on the rise, cyber attacks are rise. And I guess oftentimes, those result from human error by employees at banks. So what can banks do better as far as dealing with those sorts of situations human error? And how can they mitigate and deal with them once they arise?Barbara Kissner
So um, thank you, Myra, for inviting me to speak with you today. And that’s actually a very interesting topic. I think that it is important to know that no matter what you do in terms of your technology, infrastructure, there are always weaknesses in those chains. And the weaknesses very often is the human factor. And so it’s important for banks and financial organizations to continue to educate and promote security awareness. And that comes in many forms. It certainly comes in online training, it also comes in phishing campaigns. And it comes in security, awareness, messaging, and lunch and learns. And to be honest with you, you cannot do enough of this. Because no matter how many times you train people, there are always going to be somebody who’s very busy, gets an email and clicks on a link that they shouldn’t. So I think that it’s very important to consider the human factor as well as the technology infrastructure, because those things combined will keep these organizations secure. Unfortunately, if there is a breach, that’s a whole different topic, and we can certainly talk about that you have to have a very good disaster recovery and resiliency plan. And we can certainly get into more detail on that.Myra Thomas
How do you change people’s behaviors, though? You know, I think, you know, humans are unpredictable. And I think that’s why human error is one of those things that, you know, is really difficult to fight. Yeah. And, you know, what is their training process? You know, what, what does it consist of, to try to make people be more thoughtful about what they do online.Barbara Kissner
So one of the things, I think that’s important, the first factor is repetition, you have to keep repeating the same exercises, you have to change them up a little bit. But you have to have people make mistakes and learn from those mistakes in a safe environment. The other thing that’s important is when you’re doing the training is to make sure that people feel comfortable, and they have the ability to ask questions, even if they feel the questions might expose them as maybe not knowing so much. So you have to create a cultural environment in where people are open, and they feel comfortable about exchanging ideas and asking questions. Sure. And I think the third thing is you have to have very engaging training, you can’t have boring training, because people don’t just tap a button to get through it. You have to have training that hits home. So I do a lot of security training. I’m a member of a on the board of a college in the New York City area, and I do security training for them. And one of the things that’s important is to use examples from real life. You know, I got this note, what should I do? Should I click on it? I got a text and it looks like it’s from my bank should I should I click on it and help. They’re going to help me fix my suspicious activity and so forth. So I think those factors repetition, engaging culture and openness to explore and ask questions, and relevant training, I think are factors that might help to change behaviors.Myra Thomas
Sure. So you know, ransomware obviously, everyone’s watching the news, and there’s Seeing the recent ransomware attacks at variety institutions and corporations. You know, obviously banks must be particularly prone to it, though we don’t necessarily always hear about them in the news. What can banks ultimately do to fight something like ransomware? Is it possible,Barbara Kissner
so it is possible and ransomware takes two forms in a way. One is, there is a threat to corrupt data. And the other way is to take the data that they’ve stolen and expose it to the world on either the internet or the dark web. And I think each of those have different solutions. But the most important thing is prevention. Right, you have to have very good engineering, you have to very strong boundaries, you have to know an understand the traffic inbound and outbound from your organization. So it’s very important to have those tactics in place. The next thing that banks and really any organization needs is a very good disaster recovery and resiliency program. So for example, in your disaster recovery, Murray, you might be familiar with this, but Dr. There is, there are metrics, like a recovery point objective, which has to do with when you restore data. So a newer technique is to use snapshotting, which does picture of your data perhaps every 15 minutes or every half hour. So if heaven forbid, something happened, you would have the last most recent snapshot of data that might only be 15 minutes old. So for companies that are very highly transactional, that becomes critical in order to restore the data. If you have older recovery points, you might actually lose a day’s worth of data in trying to recover. So there’s a lot of technical techniques. And ultimately, it’s prevention. Now, if you do unfortunately, get your data encrypted, if you have a good resiliency, you have secure backups, you have these snapshots, company should be able to recover from that. But in the second situation that we discussed, which is where a company is threatening to expose data on the internet, or on the dark web, that’s really a horse of another color, because they’ve already exfiltrated the data, you can’t protect yourself anymore, right. And if you’re a bank, and you have a mother lode of personal information, it could be very, very damaging. And in those cases, sometimes you have no choice, you actually have to pay these guys. So I think the best course of action is very strong prevention, make sure you do very deep penetration tests, both externally and internally, have an external company perform those tests so that they are unbiased. Make sure that you are as secure as possible, and they are doing a very good resiliency.
Myra Thomas
So yeah, let’s get into the skinny of it, I guess, can you describe you know how a bank might fall prey to a DDoS attack, a DDoS attack. I know that to form a button that needed for coordinate DDoS attack. Hackers, employee devices previously compromised by malware hacking, I think AI can play a tool player, too. Maybe you could describe how this might happen at a bank.
Barbara Kissner
Sure. So first of all, a DDoS attack at a bank would most likely be aimed at their outward facing website. In other words, if you use a bank, and you use electronic banking, which where you log in, because the object of a DDoS account, excuse me, a DDoS attack is to prevent people from using the website to deny service, because it damages the reputation of the company. So I think it’s important to understand that the way that de deus attacks happen, there’s a couple of different ways one is dotnet, like you described. Another is there are very clever programmers that create simulated loads on websites. And sometimes people use that to actually stress test the website. So it’s not an unusual technique, but most people use it for the good. The bad guys, the hackers, what they do is they write programs that thing against these websites. And ultimately, they check the websites down. So when you have a botnet, what happens is that there are computers that are infected, and you most likely don’t even know it, and you can get infected by going to an infected website. One thing that people don’t realize is when you go to the Internet, and is all the flashing pictures and the different things, sometimes those contain malicious code, and you don’t realize that you can click on it and actually download a payload to your machine. And then what happens is that payload you become part of this family of computers, which could be 10s of 1000s. And that, that, that that software that you’ve downloaded without realizing it is controlling software, and it creates this enormous web have computers, which then take direction from a controlling organization or a controlling computer. So it sounds pretty scary and it is now the way that banks can protect themselves again. That is again, you have to very, very strong defense, you have to make sure that you do penetration testing and ensure that when your internal staff goes out to the internet, that you are monitoring their actions. And I don’t mean from an oversight perspective, but really understanding the traffic and have content management software installed so that you can block suspicious sites. And essentially, you really need a very strong set of controls in order to prevent against attacks like that. So I hope that answered your question.
Myra Thomas
No, it does. I mean, the thing I think, also was that we were finding that people are saying that they’re more instances of credential stuffing. And maybe you could explain to our listeners what that actually is. And you know, how banks can fight against it.
Barbara Kissner
So credential stuffing really is how many ways can I figure out my risk username and password so I can get into her bank account. And there are lots of programs that simulate this. So for example, if you use easy passwords, like if your password is Hello, that’s not going to be too good, right? So you need to have very strong passwords. But most banks that have established core platforms, those core platforms have internet banking, and they are usually very secure. I would say, for the newer banks that have digital only platforms. That’s where they have to spend a lot of time upfront engineering the security in so that they are websites protect against it, you can use things like CAPTCHA, which I’m sure you’ve seen, those are those odd looking codes, that ensures that there’s not a program running, where it’s not 50,000 times trying to figure out your password. So there are techniques like that, and I would recommend that all banks actually employ those to protect themselves against credential stuffing.
Myra Thomas
Now, you know, in talking to bank leaders, I find out that, you know, they could have multitude of fintechs vendors that they’re dealing with. And in the automation process, whether you’re looking to automate, you know, internal functions are they’re looking to automate, you know, something that involves client customer experience. And, you know, I would imagine that picking between the various fintechs and vendors is a complicated process. And so obviously, you’re looking at money, of course, but and whether or not the product they can deliver is good. But at the same time, you know, the issue is ultimately security and the vulnerabilities and the risks that happen when you deal with a vendor. You know, it, you know, how, how should say you worked at a financial institution? How would you, how do you pick a vendor, you know, how do you better police them, you know, so that when you expose your customers, you know, to this vendor it, you know, it there’s there’s that risk that exists?
Barbara Kissner
Sure, I think that’s a very good question. Because the the marketplace is proliferating with tons and tons of vendors. So financial institutions, in particular, they should be using certain guidelines to pick these vendors who one thing they should be looking to see that the vendor has something called a sock report, which stands for service organization controls. And that is a standard report that will let you know if there’s any kind of infractions or anything that doesn’t look right. And they that usually is done by a third party who attests to the controls within the organization. Another thing that I would recommend is when you sign a contract with a vendor that you put an audit clause in, meaning that the financial institution can actually audit the vendor depends on the size of the vendor, some will let you do that some won’t. Some will provide you with reports. Another thing that I do is I look at the Internet, I check for different you know, there’s different kinds of trends, there’s different complaints, there’s different issues with these vendors, make sure that the vendor is in good standing, that they have good financial background, that they’re not going to fall apart, because you don’t want a vendor who doesn’t have any money and ended up selling out to somebody that doesn’t have really good standards. So I would say you have to apply the same rule that you do internally to your external partners, you have to apply the same types of security Procedures and Standards, when In addition, look for supporting documents like the soccer core. And again, I would look to see if they under an NDA will provide penetration testing, or anything that will give you a sense of what how secure the environment is at the vendor.
Myra Thomas
It’s a complicated process. Because if you think about it, you know, you might have a core provider, you know, who’s doing one thing for an organization, and then you’re layering on a variety of different other platforms on top of that, yes, that seems very complicated to manage for
Barbara Kissner
a bank. You know, it’s the way of the world though. So I think if you’re in you’re in and you just have to understand that word, providers don’t provide everything. There are many layered products. And I think you have to check each of them individually and then make sure they play together harmoniously in your environment so that you don’t have issues with counting of outline technologies that don’t mesh properly. But I just I think that’s just the way of the world, I think people usually take a layered approach and they have a number of different products and they will have to be secure. And they will have to play well together in the same environment.
Myra Thomas
I get the sense to there’s a lot of mystery when you talk to bankers about, you know, technology deployment and automation, implementation and whether or not they decide to build or buy, and whether or not they can actually figure out the return on the actual investment, whether they do it in house or not, you know, what do you see when you talk to banks? How do they make these decisions on build versus buy?
Barbara Kissner
So you know what, that’s interesting, Myra? It’s a good question. I think it’s very individual. And it depends on the bank’s DNA. Some banks have very large development environments, and they might have a bias towards developing in house, a lot of the smaller and medium sized banks don’t have large development steps, and they can’t undertake development, particularly if you think about in the world today. There’s so much security engineering that has to go into developing products, that really requires quite a bit of effort. So their bias might be actually to outsource. But I do think that it is individual, I think it’s what the fit for purpose is, for example, if you want a product that does customer relationship management, the chances are there’s a lot of good products in the market, it doesn’t make sense to actually spend the resources building one when there’s so many great things to choose from, but if there are very specific business cases or use cases within the bank, they might have to have to actually develop it in house.
Myra Thomas
So, I mean, in looking at dealing with banks, often the sense that you get is there a better internal reporting structure that could happen because I often see that it is siloed on one side security on another, you know, how can banks better manage internally, you know, the security risks that exist for them, you know, so
Barbara Kissner
so a lot of banks have adopted an enterprise risk management strategy, and that is an overarching risk, kind of an a risk platform that the bank will, will adopt in which everybody participates. So there are members from all different departments, including security and technology. And I think if you have an overarching approach to risk, even if the reporting is siloed, if you’re if everybody’s looking at risk together from the same lens, I think you have a much better chance of capturing the weaknesses, understanding the strengths and building the appetite for the bank on on what risks it’s willing to accept or mitigate or transfer. Well, Barbara, I
Myra Thomas
will stop it there. I really do appreciate your time. Thanks very much. That wraps up this episode of the buzz. Thanks for listening. And please let us know how we’re doing at Bank automation news calm and of course on Twitter and LinkedIn. Thanks very much.






