Contributor

Bank complacency still exists

Opinion
Oct 20, 20082 mins

One of the problems that financial institutions exhibit over and over is indulging in faulty risk calculations. Say for instance that you had 600,000 online banking clients and 3 of them succumbed to a phishing attack. That would be a .0005 percent problem.  It would not be worth investing any money in combating phishing attacks since the projected cost of instituting strong authentication would be much higher than just writing off the cost of reimbursing victims of fraud.  

Sarkozy and supermodel Bruni

Bank of America did not work there would be no more phishing attacks.

But the risk calculation would miss the bigger picture. As soon as a successful phishing attack is carried out there is a criminal hacker somewhere who has just had a huge influx in fresh capital, maybe several thousand dollars.  So, they launch another phishing attack. Soon your bank’s brand becomes associated with “target”.   After all, if phishing attacks against

news from France:

Now look at today’s

The French government was forced to admit that no one was safe from internet fraud yesterday after it emerged that thieves had managed to hack into President Nicolas Sarkozy’s personal bank account and siphon off cash.

This statement sums up the complacency that most financial institutions have when it comes to attacks against individual account holders:

“[This] proves the system of internet checking [of bank accounts] is not infallible,” Chatel said. “These cases are sufficiently rare that we haven’t had to really organise ourselves, but [they are] sufficiently serious for us to reflect on how to improve the system.”

            -Luc Chatel, Secretary of State for Consumer Affairs

Good idea. A reflection is needed.  Better to over invest in security. Continued banking complacency will only fuel the rise of cyber crime by providing the funding cyber criminals need to continue their activity.  If classical risk management techniques cannot handle the idea of an enemy who is actively pursuing the bank then perhaps they can assign some risk to prominent public figures having their accounts stolen and the subsequent bad publicity for the bank.

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author