Blog

The Only Fraud We’ve Seen in Online Banking….lately

Heath February 23rd, 2010 Comments

It seems like we say it at least every other week, “The only fraud we’ve seen for online banking has been compromises at commercial customer sites.” And is evidenced by two breaches of high profile banks out of Dallas over the past month.

Plains Capital Bank had a breach at one of their customer’s sites, resulting in over $800,000 being transferred out of the bank and they turned around and sued their customer. PCB may get all their money back, but who wants to pay those court fees, lose a customer and fight that PR battle?  In the other breach, the customer is suing Comerica and claiming that Comerica exposed them to phishing schemes. I’m anxious to see what happens in these cases and if banks and customers will turn lawsuits against each other over online banking breaches into a habit.

I mention these cases because they are the only ways that we have seen online banking accounts compromised over the past year or so, and it is becoming more prominent. Several of our clients have been breached by having their cash management customers credentials breached by either a keylogger, trojan, or rogue employee. I’d like to say that they can all be solved with a solid multi-factor authentication implementation, but the Bugat Trojan has found a way to circumvent Random Number Generating tokens.

There are still great risk mitigating ways to prevent your customer’s sites from being compromised including…

  • IP Restriction
  • USB Tokens and Random Number Tokens (it is better than nothing)
  • Text Message Codes or Callbacks
  • Customer Site Visits
  • Risk Assessing Customers
  • I believe this all goes to show banks that picking who you choose to do business with and properly training appropriate customer’s staff and cash management administrators can save bankers a lot of heartache.  And from having to sue their customer.

    • Print
    • Digg
    • Twitter
    • Facebook

    Webinars – Next Generation Compliance

    Brad February 12th, 2010 Comments

    Thanks to all that attending today’s webinar on ‘Next Generation Compliance’. We hope it was informative and enlightening. As promised, here is the video recording of today’s webinar. We’d love any feedback you could add on the topic today as well as other topics you’d like us to discuss more about. Feel free to mention those in the comments below. Have a great weekend everyone!

    For printable slides: Next Generation Compliance

    • Print
    • Digg
    • Twitter
    • Facebook

    RiskKey: Newly Designed Assessments Area

    Brad February 11th, 2010 Comments

    We just launched a new revamped assessment area for RiskKey that we think you’re really going to enjoy using. We care very much about an interface that is as simple to use as possible so you can focus on the work at hand.

    Why redesign it?

    RiskKey has continued to improve over the years to not only be a risk assessment tool that it started as but also one that now incorporates features like project management, files, and an audit system. With that, the risk assessment section needed to be retooled to better align with those sections and to allow for a better user experience for you. We really liked how the audit section has turned out so we decided to follow suit over in the assessments area as well. And voila…

    IT Compliance (demo) | Assessments - (Build 20091221151141)

    You can see that we moved to the two column layout to give a nice divider between the left side that focuses on titles and descriptors and the right column being about doing the work like threat analysis and safeguarding (but done in a super simple way).

    Link-tastic!

    We also wanted to make the information more available to you in the other areas that connect back to this assessments screen. So you are now able to click a link and get directly to the recommendations and the associated audit objectives in just one click. We love that.

    IT Compliance (demo) | Assessments - (Build 20091221151141)

    We’ve got more to coming soon but in the mean time…

    Send us your feedback!

    If you have any questions or feedback about RiskKey, please feel free to let us know through support [at] thegarlandgroup.net. You can also follow @thegarlandgroup on Twitter for status updates and news.

    • Print
    • Digg
    • Twitter
    • Facebook

    Future of Payments – Square

    Brad February 10th, 2010 Comments

    If you haven’t heard by now, there’s a new application being launched by Jack Dorsey, who originally founded Twitter, called Square. It’s an iPhone based payments app that allows credit card processing. Here’s a demo by Kevin Rose showing off the product. Enjoy.

    • Print
    • Digg
    • Twitter
    • Facebook