What Was Banking Information Security Like in 2010?

188 views
•
October 31, 2011
by
RSAC Cybersecurity
YouTube video player
What Was Banking Information Security Like in 2010?

TL;DR

Banks faced a serious mismatch between prevalent fraud and their readiness to prevent it, especially for payment cards, ACH transfers, and ATMs. Respondents also expected another major third-party breach, expressed divided confidence in PCI DSS, showed notable support for end-to-end encryption, and anticipated that regulatory reform would bring tougher information security standards and greater accountability.

Transcript

Whenever you're ready, Tom. Good to go? Yeah. Hi, this is Tom Field, editorial director... Yeah, let's not go with the "this is." Sounds like I'm talking about a, an Android. Take two. Hi, I'm Tom Field, editorial director with Information Security Media Group. I'm here today to talk with you about the 2010 Banking Information Security Survey, whic... Read More

Key Insights

  • Fraud increased across financial institutions during 2009, with 62 tracked incidents involving banks and more than one-quarter involving insiders. The economic downturn coincided with more reported embezzlement and insider fraud as some individuals experienced worsening personal financial circumstances.
  • Credit and debit card fraud was the most commonly reported category, experienced by 72% of survey respondents during the previous year. ACH and ATM fraud also ranked highly, reflecting unauthorized business-account withdrawals and increased use of skimming devices on cash machines.
  • Preparedness lagged sharply behind fraud exposure, with only 28% of respondents saying they were best prepared to prevent credit and debit card fraud. Just 10% selected ACH fraud, and only 5% selected ATM fraud, despite the reported prevalence of these threats.
  • The Heartland Payment Systems breach exposed up to 130 million credit and debit cards and affected roughly 3,000 U.S. banks and credit unions. Those institutions had to reissue cards, monitor accounts, or take other measures in response to the compromise.
  • Third-party payment breaches remained an expected threat, with 84% of respondents considering another Heartland-type incident very likely or somewhat likely in 2010. This expectation was especially concerning because payment card fraud was widespread while prevention confidence remained comparatively low.
  • Confidence in PCI DSS was divided approximately down the middle among banking security executives. The Heartland incident fueled questions about whether compliance represented lasting security, how frequently it required renewal, and who should determine whether a payment organization truly complied.
  • End-to-end encryption received support from almost half of respondents as a preferred approach for securing payments. Chip and PIN also attracted substantial support, while enhanced PCI remained another option, showing that respondents wanted progress despite differing views about the best solution.
  • Regulatory reform was expected to affect information security directly, with 65% of respondents anticipating tougher standards and increased accountability. Only 12% expected little change, indicating that most participants connected broader banking reform with meaningful consequences for security executives.

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What fraud threats were banks experiencing in 2010?

Banking executives reported several major fraud threats based on their experiences during the preceding year. Credit and debit card fraud was the most common, affecting 72% of respondents. ACH and ATM fraud also ranked highly. The survey discussion highlighted unauthorized withdrawals from small and midsize business accounts, ATM skimming, insider fraud, and embezzlement as important concerns.

Q: How prepared were banks to prevent payment card fraud?

Banks reported a large gap between experiencing payment card fraud and feeling prepared to prevent it. Although 72% of respondents said they had experienced credit or debit card fraud during the prior year, only 28% identified it as the fraud category they were best prepared to prevent. The difference suggested that widespread exposure had not produced comparable confidence in preventive capabilities.

Q: Why was ACH fraud a concern for small businesses?

ACH fraud was a concern because hackers could gain access to the bank accounts of small and midsize businesses and initiate unauthorized withdrawals. The transcript describes funds being transferred to destinations including Ukraine and other distant locations. Despite this threat, only 10% of survey respondents said ACH fraud was the area they felt best prepared to prevent in 2010.

Q: What did the survey reveal about ATM fraud readiness?

The survey revealed very low confidence in preventing ATM fraud. Reports from 2009 included more skimming devices being placed on ATMs and more incidents in which funds were withdrawn from customer accounts. Yet only 5% of respondents identified ATM fraud as the category they were best prepared to prevent, demonstrating a pronounced readiness gap around this threat.

Q: How did the Heartland breach affect financial institutions?

The Heartland Payment Systems incident compromised up to 130 million credit and debit cards and affected roughly 3,000 banks and credit unions in the United States. Financial institutions had to respond by reissuing cards, monitoring accounts, or taking other protective steps. The breach also demonstrated why attackers valued payment processors, which could provide access to millions of cards at once.

Q: Why did the Heartland incident weaken confidence in PCI DSS?

The Heartland incident intensified debate about PCI DSS because payment processors could report that they had been judged compliant and still suffer a major breach. This raised questions about what compliance actually meant, whether it was a continuing condition or something requiring periodic renewal, and who should make compliance judgments. Survey respondents were consequently divided in their confidence in the standard.

Q: Which technologies did respondents prefer for securing payments?

Almost half of respondents supported end-to-end encryption as a preferred method for improving payment security. Chip and PIN also received substantial support, while enhanced PCI was another option presented in the survey. The mixed results showed no single consensus, but they did indicate a desire for payment-security improvements beyond relying on existing compliance claims alone.

Q: How was regulatory reform expected to affect information security?

Most respondents expected regulatory reform to have a meaningful information security impact. Specifically, 65% anticipated tougher standards and increased accountability for information security, while only 12% expected little change. These findings showed that banking and security executives did not view regulatory restructuring solely as a business issue. They expected direct consequences for security responsibilities and oversight.

Summary & Key Takeaways

  • The annual Banking Information Security Survey gathered responses from hundreds of banking and security executives about security, risk management, privacy, and business priorities. Its 2010 findings focused on fraud, payment protection, emerging technologies, and regulatory reform, while suggesting that banking concerns often translate to government, healthcare, retail, and other industries.

  • Fraud findings revealed a substantial gap between exposure and preparedness. Credit and debit card fraud had affected 72% of respondents, but only 28% felt best prepared to prevent it. Preparedness was even lower for ACH fraud at 10% and ATM fraud at 5%, despite their growing importance during 2009.

  • The Heartland breach intensified doubts about payment security and PCI DSS after up to 130 million cards and roughly 3,000 U.S. financial institutions were affected. Respondents favored further protection, particularly end-to-end encryption, while regulatory reform was expected by 65% to produce tougher information security standards and increased accountability.

  • Key Insights communication gap


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚