Thursday, July 10, 2014

Organizational Data Breach an Analysis



Businesses store vast amounts of information. A security breach occurs when an intruder, employee or outsider gets past an organization's security measures and policies to access the data. This sort of security breach could compromise the data and harm people. There are various state laws that require companies to notify people who could be affected by security breaches.

A data breach is the intentional or unintentional release of secure information to an untrusted environment. Other terms for this phenomenon include unintentional information disclosure, data leak and also data spill. Incidents range from concerted attack by black hats with the backing of organized crime or national governments to careless disposal of used computer equipment or data storage media.

Just to mention I would like to mention on the notion of a trusted environment is somewhat fluid. The departure of a trusted staff member with access to sensitive information can become a data breach if the staff member retains access to the data subsequent to termination of the trust relationship. In distributed systems, this can also occur with a breakdown in a web of trust.

Uncovering a security breach depends primarily on the method of discovery, as some methods inherently take longer than others. This also depends on the maturity of a security program implemented in an organization that directly reflects the ability of an organization to detect and respond to threats. It is important to remember that speed is not the only critical factor in incident response as execution of a well-conceived plan is equally critical while detecting and responding to breaches. Acting fast just for the sake of speed increases the risk of making mistakes, resulting in higher costs or needlessly extending the time necessary for full incident mitigation. Unfortunately, third parties discover data breaches much more frequently than victim organizations themselves.

Physical Security Breach
One form of breach is a physical security breach, wherein the intruder steals physical data, such as files or equipment that contains the data. Intruders could steal computers, particularly laptops, for this purpose. Businesses should monitor access to their property to cut down on such incidents and require employees to lock away their laptops when not in use.


Electronic Security Breach : Another form of breach is an electronic security breach, wherein the intruder gets into a business' systems to access sensitive data. The intruder gains such access by taking advantage of any weaknesses in the systems, such as inadequate firewall protection. This could also happen if the organization does not have adequate password protection for sensitive data. This sort of security breach is one reason businesses should perform constant security updates.
Data Capture Security Breach : Data capture, or skimming, is a practice whereby the intruder captures and records the data on a magnetic card stripe, such as on a credit card. This form of security breach helps the intruder produce copies of credit and debit cards. The intruder could either be an employee of a merchant who handles the customer's card, or it could be an external intruder. An external intruder could attach a device to card readers or ATM machines to skim information.
Business Response : Businesses should be wary of security breaches. Best practices for businesses to follow include having a policy in place to deal with any incidents of security breaches. They should identify what information has been compromised and decide who are the appropriate regulatory authorities to which they should report. Affected customers should also be notified.


Security and data breaches don’t favor one organization or industry over another and are taking place every day. Companies should consider the “how” of a breach as opposed to the “who” to evaluate their exposure to a similar event.

Retail operations remain a target to hackers due to the volume of information in their systems, including credit card information, confidential information for loyalty programs, and employee data. The victims of these attacks are an organization’s most valued assets: their employees and customers.

Until recently, many thought data risk was trivial compared to other threats such as theft, slip and falls, and workplace violence. But with data compromise occurring at much greater frequency, it’s one risk you don’t want to underestimate. Reputational harm stemming from a poorly managed data breach can be catastrophic.

Five myths you can’t afford to believe
1. Data theft is not a problem for me — my company is too small. Data privacy is a concern for organizations of any size. Rogue employees, data thieves, and unscrupulous business associates are looking for opportunities to take advantage of any weakness or mistake. Additionally, human error by negligent or careless staff account for a surprising number of data breaches around the country.
2. We can afford to self-insure the risk. As the economy continues to recover, companies are still closely watching discretionary spending, including certain lines of insurance coverage.
Many organizations wrongly believe that if something happens to their data, they can afford to cover the costs. According to a recent Ponemon Institute study, the average cost for a small breach of 1,000 records could easily exceed $200,000 — a sum that many companies cannot easily absorb.
Remember, the majority of funds to respond to a breach need to be liquid. Breach vendors typically look for payment before or at the time service is rendered, and payment for postage is required when the letter is mailed, not 30 days later.
3. Coverage is expensive and hard to get. This perception was true five years ago but is not true today. Competition, claims experience and a larger pool of buyers have made network security and privacy liability coverage more cost-effective and easier to obtain.
Even with the recent proliferation of retail breaches, the market remains relatively stable. Some carriers, however, are more cautious when reviewing risks with a large volume of credit card data.
4. Our general liability policy will cover us. General-liability insurance covers bodily injury and property damage as well as advertising injury and personal injury. The courts have consistently stated that data are not property because they are intangible. The perils associated with advertising injury and personal injury are very specific.
While a properly worded lawsuit could trigger coverage, the main expenses from a data-privacy event are the breach response- and notification-related costs. There is little chance of these costs being covered under a general-liability policy.
5. We have vendors who handle our sensitive information and credit card transactions; if they have a breach, it’s their problem not ours. This is not generally true. The data owner — the person or entity collecting the data — is ultimately responsible for what happens to that data.
Thus, a breach at a trusted business vendor could still lead to your obligation to provide notification and a decision whether to offer credit monitoring. Your contracts may require indemnification by your vendor, but if the breach is large enough, indemnification might not be enough to cover the costs or your vendor could file for bankruptcy.
More importantly, do you want critical correspondence to customers and/or employees handled by someone other than you?

A few steps toward peace of mind

It is essential for organizations to adopt policies and procedures addressing information security, along with a concrete, comprehensive plan for incident response. Consider these questions to create “peace of mind”:
  • Plan — What will you do if a potential issue is identified?
  • Educate — Have you adequately educated your employees about their responsibility to protect private information?
  • Access –Have you implemented standard procedures for access to and use of private data? Is access to data limited to a “need-to-know” basis?
  • Contracts — Do you have procedures for managing your contracts with third parties? Do they address indemnification and insurance?
  • Encrypt — Do you follow encryption standards? Do you restrict and/or encrypt data that is stored on mobile devices, including thumb drives and backup tapes? What about data at rest?
  • Online Do you have a written policy regarding the dissemination of personal information on public and social media sites?
  • Financial impact — Do you have adequate reserves or an appropriate insurance policy to manage the financial impact of a breach?
  • Monitor — How often do you monitor networks, websites and databases to detect potential issues?
Readiness is the crucial step. Organizations can’t afford to figure things out after a breach occurs. It’s much more cost-effective to have a ready-to-use incident-response plan, an on-call forensics expert and a privacy attorney on retainer. Then, when a potential issue is identified, your organization can act to mitigate the effects of a breach, deter any potential litigation and respond to inquiries from regulators.
Employers should also look for insurance partners who can help them identify financial risks and develop customized solutions to better protect their organization.
As larger organizations adopt security awareness campaigns due to requirements of various compliance regimes, training is often conducted only once a year. Organizations will be able to learn about potential security incidents faster only if their employees are well-equipped to recognize that something is amiss and react accordingly. And this will only be possible if, apart from stringent security policies, regular updates and refresher courses are in place.

Tuesday, June 17, 2014

Mobile Banking growth an Analysis



As mobile device technology evolves from being device driven to consumer driven, we are witnessing a corresponding shift in the consumer’s outlook towards the usage of mobile devices.
In the earlier days, the consumer would feel overawed by the impact of technology and could be easily satisfied with the simple promise of convenience. Today’s consumer, exposed to unprecedented levels of information and awareness, is becoming more and more demanding by the day. The average mobile device user is not swayed by the bundle of services being offered on his device; he now expects service providers to push the envelope continuously, leading to the age of consumer led innovation. The evolution of mobile device technology and the consumer’s expectations has had a significant impact on the banking industry.
With non-banking players venturing into the realm of mobile payments, wallets etc. The consumer is spoilt for choices. However, with the mobile payments industry still in a state of flux, ambiguities remain in terms of regulations, cross-border transactions, and most significantly, ownership of the customer. To survive the onslaught of non-traditional competitors, banks need to ramp up their capabilities to service the connected and aware consumer.
This blog studied the current trends in the mobile banking sector, placing emphasis on the disruptive innovations that are altering the global banking landscape
Over the years, mobile communications technology has evolved from being device-driven to user centric. In the past, the customer’s usage of a mobile communication device was restricted by the device’s capabilities. However, with the evolution in technology, the device no longer dictates the user experience. Instead, it is the other way round; the user’s expectations now drive the device’s capabilities. Increasing computing power, scalability of operations and the increasing interaction between the device and the user have led to innovations such as voice-activated assistants, mobile handsets with built in projectors, wireless battery chargers etc., which are continuously redefining the way we use mobile devices. The past decade or so, we have witnessed the evolution from physical identity cards and passbooks to virtual methods of establishing identity such as secret questions on telebanking, pin codes, barcodes, QR codes etc.
 As technology advances further, mobile devices will play a significant role in multi-factor authentication and authorization. Identity will be sensor driven in the age of robotics, cloud and predictive analytics. Face and voice recognition using biometric technology will enable mobile devices to replace the traditional modes of establishing identity.
Emerging technologies such as Near Field Communication (NFC), which is in vogue these days for making contactless payments, can also be used to enable devices to act as electronic identity documents. Since the technology supports encryption, it is more secure than Radio Frequency Identification (RFID) systems. Unique identity can be further extended to manage access in the form of common access devices, a concept that is already being applied for getting tickets or boarding passes at airports. Innovative applications of NFC technology include car locking mechanisms, tagging of pets, parking meters etc.
The emerging trends of Bring Your Own Device (BYOD) technology, virtual thin clients, and cloud-based network management can be applied to enable authentication even when a local network server does not manage the device.
As wearable’s become more and more prevalent, users will be able to carry their identity with them at all times. As mobile technology becomes more and more affordable and accessible, a mobile device will gradually become an extension of one’s self.

The delivery of a mobile banking service to a consumer in Indian context involves the participation of four primary players; A Bank, Mobile Network Operator (MNO), a Mobile Banking Technology Vendor and the consumer. 
In most instances the mobile banking vendor has been the pioneer in shaping industry adoption and lobbying the other two principle stakeholders on the value of extending the banking franchise to mobile.  The early pioneers of mobile transacting go back around 10 years. These initial visionaries have persisted in lobbying the banking industry over this time with little success, and where implemented, little consumer adoption. However the consumer mobile market has matured and the various stakeholders (banks and MNOs) seem to have taken an interest and realised the potential value of the high penetration in mobile phones amongst their respective customer bases. This is seen through the recurrent press coverage around new launches and new global initiatives to leverage this channel in banking. 
This is also clear when looking at the number of known, deemed successful, implementations in the world. The bank typically has a multi-channel approach to delivering transactional services to its customer base. Its channels include the traditional bricks and mortar branch, ATMs, POS and the internet. These channels have gone a long way in servicing the retail banks in delivering financial transaction volumes and assisting in extending the banks reach to its customers. 
Mobile banking represents a more cost efficient channel for the banks, allowing them to charge less for transactions, and permitting the consumer to have immediate access to information related to their bank accounts. These factors should translate into more transactions more often.
The bank’s mobile banking options include:
  • Leveraging the MNO bearer channel and infrastructure to extend its payments franchise to mobile facilities as a channel
  • Leveraging the MNO brand, distribution network, and extended customer base to target new market segments
  • Allowing a MNO to use the bank’s financial license and/or infrastructure to become a bank.

The Mobile Network Operator (MNO) provides the mobile phone and the ability to use the mobile phone for providing banking services to the consumer. The global mobile phone market is becoming more competitive, with reducing prices, increasing customer churn, and reduction in profits. The highly competitive mobile environment is also reflected in the number of mergers and acquisitions seen in the global market and therefore the sheer size of some of the MNO multinationals. 
The MNO is increasingly focused on innovation in order to offer higher value to its customer base in an attempt to reduce customer churn, as well as a focus on new ways of generating revenue, even from sources not core to their current business.
Mobile software solution vendor has its roots in
  • Developing applications or platforms to service its own commerce needs
  • Developing applications as foresight to a future with the mobile phone as a banking channel   

These roots have developed into business models that enabled Maximus as application service provision (ASP) and packaged licensing of technology. In other words one can either pay for the use of the technology to a on a per transaction basis or license the system for use by internal operations.
Mobile software solution vendor as a mobile banking play an integral part in the delivery of mobile banking to the customer. The business model the mobile banking system vendor & technology provider we have the ability to do mobile banking, for a Bank, through a MNO, to a consumer.
In crux of the matter, mobile Banking solution facilitates the integration of the bank system with that of the MNO bearer channel, and provides the mobile banking platform or the mobile banking application, that enables the consumer to bank using their mobile phone.
Mobile banking is seen to be an extension of the existing payment infrastructure of a bank to mobile phones as a channel for the leveraging of the mobile network and its reach, to deliver banking services to consumers. The mobile banking infrastructure thus sits in a similar technical environment to the banks ATMs, POS, branch and internet banking service offerings. 
A bank’s core banking system, the system that houses the consumer’s account and related transaction management and history, would require a means to translate banking instructions, received from consumers, through one of the bank channels such as ATMs or the internet, into a format that the core banking system can process. This translation is normally performed by an EFT channel switch. The EFT channel switch would switch transactions from the channel to the appropriate area within the core banking system.   



A generic architecture depiction for Mobile banking solution
The mobile banking channel can be delivered to the consumer through two bearer or application environments. 
Client-side applications are applications that reside on the consumers SIM card or on their actual mobile phone device. Client-side technologies include, .Net, J2ME, etc. Server-side applications are developed on a server away from the consumer mobile phone or SIM card. Server-side technologies include USSD2, IVR, SSMS and WAP.
The bank would only need to select one of these bearer channels, or bearer channel strategies, for implementation. However, in some markets it would be wise to implement more than one bearer channel in order to manage consumer take up and the risk associated with non-take up of a specific technology. The selected bearer channel does not have an effect on where the mobile banking platform should sit.
The extension of the payment franchise to mobile can be as simple as a bank channel enablement or as complex as a complete bank system implementation depending on what infrastructure already exists, and that which can be re-used as part of the implementation
Let’s have close look at multi-layered mobile architecture 


Selecting the right technology for your market will, firstly, require some work to understand the market’s technology environment. Some key elements are:
  • Who is your target market and which mobile devices do they have?
  • What kind of user experience and value proposition would be sufficient/appropriate in servicing your target market?
  • What are the bearer channel costs related to this transaction and is it affordable to your target market? 
  • Does your target market have access to the bearer channel?
  • Are you able to get the application onto your consumer’s phone or handset without requiring the consumer to have an in-depth knowledge of the technology?
  • Is the bearer channel selected secure enough for the risk profile of the customer you are targeting? Is it secure enough to protect the bank from any reputation risk if security is breached? Are there sufficient means to manage the risk around the bearer channel chosen?  
  • Does the channel comply with any financial processing rules and regulations relating to: the method of processing; authentication of the customer; transfer of data; and levels of encryption, yet still deliver on the business requirement?  
A bank with a single market segment that a certain bearer technology suits in regard to access; cost; and device and SIM dependency, should implement this single bearer channel and focus its efforts on consumer education and increasing usage.   
In a more complex market segment, or an unknown market environment, a multi-bearer strategy may suit. In this way you mitigate the risk of one technology not being taken up by the consumer. There are good examples of focused as well as spread bearer technology strategies.
Mobile banking is moving up on the adoption curve, which is evident in the number of implementations known in the world and the level of interest and discussion around the technology and its implementation.  It is also evident in the number of technology providers emerging in the mobile banking space.
There are several choices when considering how to implement mobile banking. These choices include whether or not to develop the technology within the bank, use a shared infrastructure, or purchase the enabling technology from one of many vendors. 
The choices also include various mobile bearer channels, suited to differing market segments and differing capabilities of consumers handsets. Each of the bearer channels has unique requirements in provisioning and securing applications, transactions and consumer data.
The selected implementation option including bearer channel, vendor and value proposition, should be driven by consumer adoption of the technology, technical capability of the handsets in the target market, affordability of the bearer channel, and the consumers ease of accessing the service.