How Does the FDIC Assess Bank Cyber Fraud Risk?

106 views
•
November 1, 2011
by
RSAC Cybersecurity
YouTube video player
How Does the FDIC Assess Bank Cyber Fraud Risk?

TL;DR

Financial institutions should manage cyber fraud by identifying critical assets, assessing foreseeable threats and vulnerabilities, estimating potential costs, implementing key controls, and testing those controls. The FDIC supports this process by combining institutional reports, open-source intelligence, confidential examination data, interagency collaboration, and statistically sampled Suspicious Activity Reports to identify risks and guide examinations.

Transcript

Hi, I'm David Nelson with the FDIC Cyber Fraud and Financial Crimes section. FDIC insures the deposits of over eight thousand banks, and we directly examine and supervise more than four thousand nine hundred banks and their data centers, and also hundreds of independent technology service providers. As an FDIC cyber fraud specialist, I gather and a... Read More

Key Insights

  • Risk identification is the foundation of strong information technology security. Financial institutions are expected to base customer information security programs on risk assessments that connect important assets, foreseeable threats, vulnerabilities, potential costs, mitigating controls, and the results of control testing.
  • The FDIC's cyber fraud specialist analyzes hundreds of reports submitted by financial institutions each quarter. The resulting thirty-page report provides cyber fraud and other financial fraud statistics that help examiners focus examinations, train newer staff, and contribute to industry guidelines and regulations.
  • A complete risk assessment is a five-part process. It prioritizes assets and systems, identifies reasonable and foreseeable threats, evaluates vulnerabilities, estimates the institution's potential impact or cost, selects key mitigating controls, and requires those controls to be tested and audited.
  • Board oversight is part of the control process. Results from testing and auditing key security controls should be reported to the financial institution's board of directors at least annually, connecting operational security findings with institutional governance and accountability.
  • Threat intelligence is gathered from both public and confidential sources. Open-source inputs include reports from the Department of Homeland Security, SANS, US-CERT, and companies presenting at the RSA Conference, while confidential supervisory systems supply incident, network security, and examination information.
  • Working groups are necessary for exchanging and corroborating threat information. The FDIC participates with government agencies and law enforcement in groups such as the Cyber Fraud Working Group and Botnet Threat Focus Cell, and it also engages in public-private alliances such as the Anti-Phishing Working Group.
  • Suspicious Activity Report data requires cleaning and statistical analysis before it becomes useful. Financial institutions submit hundreds of thousands of reports each year, so the FDIC uses statistical sampling and releases its analysis only in aggregate and redacted form because the underlying information is confidential.
  • Bank-focused cyber fraud includes more than hacking and malicious software. The FDIC framework also covers identity theft, account takeover, credit and debit card fraud, counterfeit cards, wire and ACH fraud, and cyber-related check fraud involving stolen information or counterfeit checks.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How does the FDIC assess cyber fraud risk at financial institutions?

The FDIC combines hundreds of quarterly reports from financial institutions with open-source intelligence, confidential supervisory data, interagency information, and Suspicious Activity Reports. Analysts use these materials to identify assets at risk, threats, vulnerabilities, and estimated financial impact. The resulting report helps examination staff focus their reviews, train examiners, and contribute to industry guidelines and regulations.

Q: What steps should a bank follow when conducting a cybersecurity risk assessment?

A bank should first identify and prioritize its assets and systems. It should then identify reasonable and foreseeable threats and evaluate vulnerabilities to those threats. Next, it should estimate the potential impact or cost, select key controls to mitigate the risks, and test and audit those controls. The results should be reported to the board of directors at least annually.

Q: What information does the FDIC Cyber Fraud and Financial Crime Report contain?

The report is an extensive thirty-page analysis containing statistics about cyber fraud and other forms of financial fraud. It helps identify assets at risk, relevant threats and vulnerabilities, and the estimated impact or cost of fraudulent activity. FDIC examination staff use it to risk-focus examinations, train examiners, and help formulate industry guidelines and regulations.

Q: What sources does the FDIC use to analyze cyber fraud trends?

The FDIC uses open-source reports from the Department of Homeland Security, SANS, US-CERT, and companies that publish threat and daily intelligence reports. It also draws from confidential FDIC supervisory data, government and law-enforcement working groups, public-private alliances, and FinCEN Suspicious Activity Reports covering several categories of fraud and financial crime.

Q: Why does the FDIC participate in cyber fraud working groups?

The FDIC participates in working groups to exchange information, corroborate findings, and validate threat data. Its collaborations include government agencies and law enforcement through groups such as the Cyber Fraud Working Group and the Botnet Threat Focus Cell. Public-private alliances, including the Anti-Phishing Working Group, also provide opportunities to understand evolving threats affecting banks and payment systems.

Q: How does the FDIC analyze Suspicious Activity Report data?

The FDIC treats FinCEN Suspicious Activity Reports as a rich but unrefined source that must be cleaned before meaningful analysis. Because financial institutions file hundreds of thousands of SARs each year, the agency applies statistical sampling methods. The underlying data remains confidential, so findings are presented only in aggregate and redacted form rather than as identifiable individual reports.

Q: What types of activity count as cyber fraud for financial institutions?

The FDIC's bank-focused definition includes computer intrusions such as hacking, phishing, and malicious software. It also covers identity theft involving stolen personal information, account takeovers, credit and debit card fraud, counterfeit cards, wire transfer and ACH fraud, and check fraud. These categories reflect crimes affecting financial institutions and their payment systems.

Q: Why can check fraud be classified as cyber-related fraud?

Check fraud can be cyber-related because criminals may obtain personal and account information through identity theft, hacking, or account takeover. They can use that stolen information to open fraudulent bank accounts and commit check fraud. Counterfeit checks are also used extensively by online criminals in online auction fraud, secret shopper scams, and work-at-home scams.

Summary & Key Takeaways

  • The FDIC insures deposits at more than eight thousand banks and directly supervises more than four thousand nine hundred banks and their data centers, along with hundreds of independent technology service providers. Its cyber fraud analysis supports risk-focused examinations, examiner training, and the development of industry guidelines and regulations.

  • A financial institution's customer information security program should begin with a risk assessment. The process identifies and prioritizes assets, evaluates foreseeable threats and related vulnerabilities, estimates potential impact or cost, selects controls that mitigate the risks, and tests and audits those controls before reporting results to the board at least annually.

  • The FDIC develops its cyber fraud reporting from several sources, including open-source threat intelligence, confidential supervisory information, government and law-enforcement working groups, public-private alliances, and FinCEN Suspicious Activity Reports. Because institutions file hundreds of thousands of SARs each year, the agency uses statistical sampling and presents confidential findings only in aggregate, redacted form.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚