The most vulnerable aspect of a bank’s security is the people — employees and customers — or so the story goes. But four security experts came together to discuss the issue and opinions differed. For example, can you still call humans the weak link when banks fail to use the best technology?
This means education is an important aspect of mitigating risk, but it’s easier to educate employees than consumers. Matt Riley, group president of ProfitStars, a Jack Henry company, works with financial institutions on security, compliance, and disaster recovery. He noted that phishing is alive and well as an attack vector, though there has been a slight drop recently in ransomware but uptick in cryptocurrency mining via a backdoor. But the main issue remains phishing. “Employees always click on the link,” he said. “Hackers aren’t attacking the technology, they’re attacking the people.”
To combat this, Riley recommends banks employ threat intelligence monitoring tools, internal or external. “You need more robust systems to determine what is normal traffic and what is an anomaly.” Tracking employee usage patterns can help stop problems in their tracks when anomalies arise, he said.
More Channels, More Problems
Social engineering is also a threat in customer service channels. Jim Rumph, senior systems manager at the accounting and advisory firm Porter Keadle Moore, said, “Usually the bad guys are trying to exploit customer service agents who are trying to provide good service.” Education, in this case, means recognizing likely threats and red flags, but balancing that with good service, and not rejecting actual customers. Add to this challenge that customer service channels have proliferated wildly with the rise of social media.
Sherif Samy, senior vice president of the mobile app security firm Entersekt, addressed the security weaknesses on the consumer side. “Phishing attacks and man-in-the-middle attacks are possible because we’re still using passwords and SMS,” he said. “We’re still sending sensitive information through non-secure channels. So, on the one hand, the customer is the weakest link, but on the other hand, we’re not using the best technology.” The best technology would include out-of-band channels — for example, secure messaging within a mobile app, rather than a text message that could be coming from anyone, anywhere.
Samy also pointed to the synthetic identity problem, which is large and growing. In this scenario, a fraudster will assemble a fake identity using several real components, an address from here, a social security from there, and attempt to open an account or obtain credit.
Mickey Goldwasser, vice president of marketing for the payment company Payrailz, said that for banks to assess the landscape, threats must be divided into categories, such as prevention, notifications, controlling or limiting account access, internal fraud, and audit trails. Pattern-finding software can check all these areas, and all of them in concert is required for a proper security environment. But the customer experience must be kept top of mind, Goldwasser warned. “Customers don’t like friction,” he said.
Samy countered that there is such a thing as “healthy friction,” and that banks are reliant on third parties such as handset manufacturers for security, which put the total experience outside the banks’ control.
Are Chatbots More Secure Than Human Employees?
It’s still not known how susceptible chatbots will be to social engineering, let alone attacks from other bots. Riley from ProfitStars said that his group has started to integrate with the Amazon Echo and recently had a meeting with some larger FI clients to discuss the Echo and Google Home. “I think we’re still early in it,” he said. “Certainly risks are posed with Amazon and Google when you have data being passed into the cloud — where is it being stored? It’s baby steps for now. We’re just looking at getting your balance, not paying bills for now.”
Samy agreed: “It’s always baby steps. With biometrics, you only have one, you can’t reset it.” With biometrics, you need a second factor as well. “It can’t be voice alone,” Samy said. He also stressed that customer consent is extremely important for all new authentication methods.
Goldwasser said Payrailz envisions being able to use Alexa to do payments, but it has to be more than your voice, there will be other ways to secure the device as voice assistant get more powerful. Rumph added that new products always bring new risks.
“It was the same with the ATM,” he said. “The new products may end up being much safer, we just don’t know yet.”
As for what will eventually be needed to keep customers secure whatever they do online, it may be a unified digital identity.
“Consumers have a government ID, banking ID, healthcare ID, many other IDs,” Samy said. “You wouldn’t use your healthcare ID to do a banking transaction or vice versa. We need some combination of these things to make one ID. This is where other countries are going. Canada did that.”
Banks will have an important role to play in this process, whenever it takes place.






