CUInfoSecurity.com - Information Security News, Regulations, & Education

The Most Viewed Posts

The Public Eye

Harsh Words for Professional Infosec Certification

July 21, 2010 - Eric Chabrow

Eric Chabrow
Commission: Creating a Dangerously False Sense of Security...
-----------
The Fraud Blog

Pay-At-The-Pump Skimming - a Growing Threat

July 14, 2010 - Tracy Kitten

Tracy Kitten
Anytime universal keys or codes are the mainstays for access to terminals that accept payments, we're all asking for trouble....
-----------
The Fraud Blog

The Global AML Battle

July 1, 2010 - Tracy Kitten

Tracy Kitten
When it comes to money-laundering, the financial industry is fighting a losing battle....
-----------
The Public Eye

Jobs Aplenty for the IT Security Pro

July 8, 2010 - Eric Chabrow

Eric Chabrow
Infosec is among the most difficult positions to fill....
-----------
The Public Eye

Obama Urges Collaboration to Defend U.S. Cyber

July 14, 2010 - Eric Chabrow

Eric Chabrow
President Appears at 'Translucent' Event Hosted by Schmidt...
-----------
The Field Report

Strong Authentication - The Bank's Perspective

July 19, 2010 - Tom Field

Tom Field
One bank security officer weighs in on the debate over strong authentication - and what it really means....
-----------
Career Insights

Lessons Learned from BP Oil Spill

June 21, 2010 - Upasana Gupta

Upasana Gupta
Glaring errors surface in regards to BP's disaster response plan....
-----------
The Public Eye

IT Security Profession: Heal Thyself

July 22, 2010 - Eric Chabrow

Eric Chabrow
Cybersecurity Lessons to Be Learned from the Medicine Field...
-----------
The Expert's View

How to Spot Bulk Cash Smuggling

July 6, 2010 - Kevin Sullivan

Kevin Sullivan
As we know from dealing with major criminal enterprises, when one [money laundering] door closes, another one opens up....
-----------
The Field Report

Failures & Fraud: The Numbers Don't Lie

July 7, 2010 - Tom Field

Tom Field
Cumulatively, there have been far more breaches and failures this year than I'd believed....
-----------
The Fraud Blog

Are Mobile RDC Concerns Overblown?

July 9, 2010 - Tracy Kitten

Tracy Kitten
Mobile remote deposit capture is expected to explode, but does relying on an iPhone app pose security concerns?...
-----------
The Fraud Blog

BP Funds, Fraud Hit the Gulf Coast

July 21, 2010 - Tracy Kitten

Tracy Kitten
Fraud schemes are only going to multiply as the BP oil spill claims continue rolling in and funds continue flowing....
-----------
The Fraud Blog

Pay-At-The-Pump Skimming Saga Grows

July 28, 2010 - Tracy Kitten

Tracy Kitten
Pay-at-pump skimming jumps to forefront of financial security concerns....
-----------
The Field Report

On Breach Trends and Marketing Your Own Security

June 29, 2010 - Tom Field

Tom Field
It's the last week of June - half the year is over. Perfect time to take a look at data breach trends....
-----------
The Fraud Blog

Fighting Fraud: Device Behavior Can Thwart Hacks

July 16, 2010 - Tracy Kitten

Tracy Kitten
Forget about just knowing your customer; to fight fraud today, getting to know your device is just as important....
-----------
The Fraud Blog

ATM Scam: Another Case of Universal Access?

July 22, 2010 - Tracy Kitten

Tracy Kitten
I came across an ATM fraud incident this week that, for a change, did not involve card skimming....
-----------
The Agency Insider

Regulatory 'Reform' is Prelude to Next Crisis

July 15, 2010 - Linda McGlasson

Linda McGlasson
The banking regulatory reforms voted in by Congress will do little to stop the next financial crisis....
-----------
The Agency Insider

A Tale of Three Breach Reports

July 30, 2010 - Linda McGlasson

Linda McGlasson
This week a trio of reports came out on data breaches. I decided to take a look at these reports to compare commonalities and distinctions....
-----------
The Agency Insider

Mystery Shoppers: The Latest Fraud Scheme

January 25, 2010 - Linda McGlasson

Linda McGlasson
IC3's latest alert says "secret shopper" schemes are rampant....
-----------
The Agency Insider

Goldman Sachs Settlement Signals Start of Crackdown

July 22, 2010 - Linda McGlasson

Linda McGlasson
Last week's announcement that Wall Street giant Goldman Sachs agreed to pay $550 million to settle civil fraud charges came as no surprise....
-----------
The Agency Insider

How Many Strikes Before a Risky Employee is Out?

June 24, 2010 - Linda McGlasson

Linda McGlasson
There's no gray area when it comes to right, wrong side of security, privacy....
-----------
The Fraud Blog

Mobile Apps: Setting the Stage for P2P

July 13, 2010 - Tracy Kitten

Tracy Kitten
Mobile RDC is just the beginning, setting the stage for more diverse offerings, including peer-to-peer payments...
-----------
The Fraud Blog

World Cup Puts Card Fraud Into Play

June 16, 2010 - Tracy Kitten

Tracy Kitten
As eyes are now focused on South Africa for one of the world's largest sporting events, so are fraudsters - taking aim at tourists' credit and debit cards....
-----------
The Fraud Blog

Time for EMV in the U.S.

July 29, 2010 - Tracy Kitten

Tracy Kitten
Magnetic-stripe cards are quickly showing their age, and are increasingly giving the rest of the world a reason to point a finger of shame at the United States...
-----------
The Fraud Blog

The ATM Skimming Fight Against Eastern Europe

June 9, 2010 - Tracy Kitten

Tracy Kitten
Global ATM skimming attacks are becoming more common and sophisticated, and U.S. enforcement agencies are fighting a losing battle....
-----------
The Agency Insider

Heartland Heads to the Finish Line

July 27, 2010 - Linda McGlasson

Linda McGlasson
The one remaining hurdle for Heartland is located in a courtroom in Houston, Texas, where U.S. District Judge Lee Rosenthal presides over the last remaining class action suit....
-----------
Career Insights

How Do You Recover Your Reputation?

April 7, 2010 - Upasana Gupta

Upasana Gupta
Security professionals should learn to build and protect their online reputation....
-----------
The Public Eye

CISO Witnesses Hack Like No Other

March 3, 2010 - Eric Chabrow

Eric Chabrow
Hacking to gain competitive advantage....
-----------
The Field Report

2010: A Good Time to Start an Information Security Career

January 8, 2010 - Tom Field

Tom Field
With the global recession barely in the rearview mirror, you hear a lot of people saying one of two things: "I'm lucky to even have a job" or "This is a lousy time to be looking for work."...
-----------
The Agency Insider

Haitian Tragedy Inspires Fraudsters

January 14, 2010 - Linda McGlasson

Linda McGlasson
The call to aid the devastated country of Haiti came just hours after a 7.0 earthquake hit the impoverished Caribbean island on Tuesday.

Just as quickly as the tweets came in asking for donations, so too came the cyber criminals looking to divert funds from legitimate charities to their own pockets....

-----------
The Field Report

Notes from the Gartner Summit

June 25, 2010 - Tom Field

Tom Field
If I could sum up the major themes of the event in two words, they'd be these: Cloud computing....
-----------
The Field Report

Trends, Threats and Thought-Leaders

January 29, 2010 - Tom Field

Tom Field
I'm sorry, but weren't we just celebrating the holidays?

Unbelievable how fast the New Year has flown by already. It seems like we're all trying to get 12 months worth of work done in one....

-----------
The Field Report

More News You Can Use

June 11, 2010 - Tom Field

Tom Field
It's been a busy news week, and once again as I scan our sites I see stories that have relevant threads for anybody interested in information security, risk management or privacy....
-----------
The Public Eye

The Government's Infosec "Conspirators"

March 5, 2010 - Eric Chabrow

Eric Chabrow
Imagining a West Wing plot....
-----------
The Public Eye

Yes, Howard Schmidt Has the President's Ear

March 3, 2010 - Eric Chabrow

Eric Chabrow
Meeting in the Situation Room....
-----------
The Field Report

New Information Security Survey - Why it Matters

February 4, 2010 - Tom Field

Tom Field
I'm excited about today's launch of the 2010 Banking Information Security Today Survey, and you should be, too.

Think about it: Identity theft, fraud, regulatory compliance, vendor management, security awareness, risk management, privacy. These topics have no industry loyalty; they're common to all public and private organizations....

-----------
The Field Report

Mortgage Fraud: Farkas Wasn't the First

June 18, 2010 - Tom Field

Tom Field
Lost in the shuffle over the past week or so was disturbing news about a former bank executive who's in serious trouble over alleged misdeeds....
-----------
The Agency Insider

New Bill: Help a Terrorist, Lose Citizenship

May 14, 2010 - Linda McGlasson

Linda McGlasson
The stakes just got raised for detecting a terrorist among your banking customers....
-----------
The Public Eye

Politicization of Cybersecurity

February 19, 2010 - Eric Chabrow

Eric Chabrow
The real shock from Cyber ShockWave...
-----------
Career Insights

Call to Duty: Security Professionals Must Give Back to Communities

January 18, 2010 - John R. Rossi

John R. Rossi
I suggest you publish, speak, mentor, visit outside organizations, and offer to answer questions from the public....
-----------
The Agency Insider

Social Networking's 17 Golden Rules

February 9, 2010 - Linda McGlasson

Linda McGlasson
Dangers loom when a user frequents social nets via mobile phones....
-----------
The Public Eye

Kundra Encouraged by Private-Sector Cloud Efforts for Government

March 29, 2010 - Eric Chabrow

Eric Chabrow
Still, no massive .gov cloud deployment anytime soon....
-----------
The Public Eye

Declassified CNCI Summary: What's New?

March 3, 2010 - Eric Chabrow

Eric Chabrow
Few surprises in initiative's synopsis....
-----------
The Field Report

Security Stories You May Have Missed

June 4, 2010 - Tom Field

Tom Field
I want to call your attention to some of the information security stories you should be tracking....
-----------
The Public Eye

Internet Crime Losses More than Double

March 15, 2010 - Eric Chabrow

Eric Chabrow
FBI Report Shows Deteriorating Milieu...
-----------
The Agency Insider

Tippett's Top 10 Security Predictions

May 4, 2010 - Linda McGlasson

Linda McGlasson
By 2020, there will be better security protections and coordination to fight cybercrime....
-----------
The Agency Insider

The Problem with Passwords

February 3, 2010 - Linda McGlasson

Linda McGlasson
Passwords are the bane of my existence -- probably yours, too. In order to be a good, secure, computer and Internet user, ideally I should have a different password for every single application I use, website I register to, and place I visit on the Internet. I frequently have at least 10 to 15 different passwords and passphrases floating up in my head from one day to the next....
-----------
The Public Eye

Leading on Cybersecurity: The Administration Speaks

February 24, 2010 - Eric Chabrow

Eric Chabrow
RSA keynotes give the White House a platform....
-----------
Career Insights

The 'Need to Know' Has Got to Go

May 26, 2010 - Upasana Gupta

Upasana Gupta
The difficulty to get management to share security info....
-----------
The Expert's View

Mobile Devices: 10 Security Tips

June 2, 2010 - Terrell Herzig

Terrell Herzig
Don't wait until a breach occurs to develop a plan of action for securing portable devices that goes far beyond encrypting laptops....
-----------
The Agency Insider

FDIC Phishing Scam is an Object Lesson to us All

October 29, 2009 - Linda McGlasson

Linda McGlasson
Just how good are you at getting the word out on phishing attempts against your institution?

The FDIC's alert this week is a great example of what needs to be told to customers....

-----------
Industry Insights

The Case for a Digital Social Security Card

November 5, 2009 - Neville Pattinson

Neville Pattinson
Is it time for a Social Security card makeover?...
-----------
The Expert's View

One PC for Casual Surfing and Secure Banking

June 3, 2010 - Nikhil Deshpande

Nikhil Deshpande
If banks are truly going to help protect their customers, they need to offer solutions and options that are both safe and easy to use....
-----------
The Field Report

ACH Fraud by Any Other Name

May 27, 2010 - Tom Field

Tom Field
It seems like some industry groups no longer want us to use the term ACH fraud - they think it's a misnomer....
-----------
The Agency Insider

Ponzi Schemers Abound

June 1, 2010 - Linda McGlasson

Linda McGlasson
Ponzi schemes keep popping up all around the industry, as law enforcement continues to uncover more of these criminals' activities....
-----------
The Agency Insider

It's Phishing Season; Beware These Scams

February 18, 2010 - Linda McGlasson

Linda McGlasson
Spring is the season for the phishers to come and try to take advantage of to the unsuspecting public in the form of official-looking emails talking of tax refunds, as well as claims that the government has money waiting for them....
-----------
Industry Insights

Identity Self-Defense: The Power of PIV

January 15, 2010 - Neville Pattinson

Neville Pattinson
It is time to address the issue of protecting our identity and thanks to the federal government's implementation of PIV smart card credentials; we have a proven technology in place that could be leveraged for a much broader audience....
-----------
The Public Eye

Cybersecurity Lesson from Airline Sector

February 10, 2010 - Eric Chabrow

Eric Chabrow
Trusting those who operate crucial IT to do the right thing....
-----------
Secure Marketspace

60 Technology & Security Vendor Interviews in 400 Minutes

May 1, 2009 - Mike D'Agostino

Mike D'Agostino
That's roughly 6-7 minutes per interview. Add in 3-4 minutes for introductions, a 10-minute pre-interview, and 5 minutes to get to the next interview (who's counting?) - and you've got one busy week!

And so it was at the RSA Conference 2009 at the Moscone Center in San Francisco, an interview with a different security vendor every half-hour, on the half-hour, for 3-and-a-half days....

-----------
The Agency Insider

At the Crossroads with Banking Security

May 25, 2010 - Linda McGlasson

Linda McGlasson
In the wake of the PlainsCapital Bank settlement, we're all faced with the reality that the industry is at a crossroads of security....
-----------
The Public Eye

Schmidt to Announce Easing of CNCI Secrecy

March 2, 2010 - Eric Chabrow

Eric Chabrow
Portions of initiative to be declassified....
-----------
The Field Report

Customer Accountability: Where does it Start?

June 24, 2008 - Tom Field

Tom Field
On one hand, this step does show that the business has made a conscientious effort to plug a major security hole.

But on the other, can't you see that first lawsuit filed by a breached customer saying "Hey, you gave me this stuff and said my PC was safe ...?"...

-----------
The Agency Insider

Impressions from the PCI Community Meeting

September 28, 2009 - Linda McGlasson

Linda McGlasson
Notes and quotes from the Payment Card Industry's Security Standards Council community meeting in Las Vegas.....
-----------
The Public Eye

Howard Schmidt Achieves Rock-Star Status

March 1, 2010 - Eric Chabrow

Eric Chabrow
Cyber "Czar" headlines two RSA performances....
-----------
The Fraud Blog

EMV Abuzz in the U.S.

May 28, 2010 - Tracy Kitten

Tracy Kitten
The move to chip and PIN in the United States may be closer than we think. Witness: United Nations Federal Credit Union's announcement to push EMV to U.S. cardholders....
-----------
Information Technology Risk Management

Risk Management, Compliance and Industry Standards

January 29, 2009 - Sanjay Kalra

Sanjay Kalra
No matter where I turn, I can't seem to avoid reading about the Heartland data breach that was announced about a week ago. I have read everything from the incident being compared to the tainted Tylenol case dating back to 1982 or the more 'recent' case of TJX breach and just about everything in between....
-----------
The Expert's View

3 Steps to Protect Your IT from China-Like Attack

January 20, 2010 - Eric M. Fiterman

Eric M. Fiterman
Can your IP be the next target?...
-----------
The Expert's View

The Human Element - Our Greatest Exposure

January 13, 2010 - Philip Alexander

Philip Alexander
The most critical and often weakest link in ANY security program is the human element. This is true in data security, and as the events of Christmas day showed us, national security as well....
-----------
The Expert's View

The QSA's Perspective: PCI Compliance Risks Abound

March 22, 2010 - Peter Spier

Peter Spier
From a QSA's perspective, here is what is frequently lost from the PCI debate....
-----------
The Agency Insider

The 'P' in PCI Should Stand for People

September 25, 2009 - Linda McGlasson

Linda McGlasson
It's time to put the P back into PCI's focus -- the P standing for people, not payment....
-----------
The Business of Security

Tackling the Insider Threat

February 17, 2009 - Steve Katz

Steve Katz
Times are tough, and we all continue to hear about the heightened risk of the insider threat. Granted, unauthorized insider access to data has always been a concern. But the concern is increased now because of the tremendous changes that we are seeing in the economy....
-----------
The Agency Insider

The Security Professional's Wish List for 2010

January 5, 2010 - Linda McGlasson

Linda McGlasson
Now that the New Year is here and 2009 is behind us, here's a list of all the things that I think that infosec pros at financial institutions would like to receive in 2010...
-----------
The Agency Insider

'Blippy' Gives Green Light to Spear Phishers

January 29, 2010 - Linda McGlasson

Linda McGlasson
Blippy, a new social media data sharing site that is financial form of Twitter, has unleashed the unthinkable idea of publishing every single purchase for public consumption on the Internet....
-----------
The Field Report

Bank/Credit Union Failures - the Real Number

October 28, 2009 - Tom Field

Tom Field
So, how many banking institutions have failed in 2009?

If you pay attention to the popular news media, then your answer is 106. And you'd be partially right. That is the number of FDIC-insured banks to have failed this year - the most in any year since about two President Bushes ago....

-----------
The Public Eye

IT Decision Makers, IT Ignorance

April 22, 2010 - Eric Chabrow

Eric Chabrow
Third of IT leaders have no clue about cloud, virtualization....
-----------
The Field Report

The ABC's of ACH Fraud

May 6, 2010 - Tom Field

Tom Field
ACH fraud. We've been talking about it for nearly a year now....
-----------
Secure Marketspace

Predicting the Next Regulatory Challenge for Financial Institutions

December 26, 2008 - Mike D'Agostino

Mike D'Agostino
Wow - we've been part of quite a bit of quick decision-making recently. Financial institutions going out of business almost overnight, trillions of dollars being offered from the U.S. government in the blink of an eye, and the largest in the industry merging with and/or acquiring peer institutions within weeks....
-----------
Career Insights

Information Security ... and Ethics

April 13, 2010 - Upasana Gupta

Upasana Gupta
In information security, ethics can play havoc with a career....
-----------
Secure Marketspace

Obama's "Big Brother" Vision of IAM

June 10, 2009 - Mike D'Agostino

Mike D'Agostino
So, did anyone read about the President's Cybersecurity Action Plan? I'm assuming you've read through all 10 points. You didn't stop to ponder after the first few did you? I mean, you didn't happen to stop after number 8? The one about the incident response plan?...
-----------
The Public Eye

Storms Show Need for Telework Policy

February 16, 2010 - Eric Chabrow

Eric Chabrow
Navy CIO rushes home to D.C. from balmy clime...
-----------
The Public Eye

Does Melissa Hathaway Bank Online?

November 10, 2009 - Eric Chabrow

Eric Chabrow
Her comfort level with current tech dictates her choice....
-----------
The Field Report

What's Your Next Move? Take Our 2010 Career Trends Survey

October 1, 2009 - Tom Field

Tom Field
Risk management. Audit & compliance. Fraud, investigations and forensics.

What do these three topics have in common? They're the information security areas with the greatest potential for job growth, according to our new Information Security Today Career Trends Survey....

-----------
The Public Eye

Did Study Foresee Google Attack?

February 22, 2010 - Eric Chabrow

Eric Chabrow
Eerily similar methods described in two reports....
-----------
The Expert's View

4 Tips on Insider Threats

September 11, 2009 - Eric M. Fiterman

Eric M. Fiterman
The principle of security by obscurity holds true....
-----------
The Public Eye

Should Biometrics Replace Passwords?

September 16, 2009 - Eric Chabrow

Eric Chabrow
Avoiding use of username, password can protect identities....
-----------
The Expert's View

ID Theft Prevention: "I Lost My Purse ... Now What?"

December 29, 2009 - Upasana Gupta

Upasana Gupta
This is the last thing you'd want during the holiday season. I lost my purse at a local movie theater recently, and within a couple hours realized my loss. Nervously, I rushed to the customer service department, all the while hoping to get my grey tote bag handed safely from underneath the counter....
-----------
The Public Eye

Hardware: Cybersecurity's Soft Spot

October 23, 2009 - Eric Chabrow

Eric Chabrow
Don't ignore chips in safeguarding IT systems....
-----------
The Public Eye

Should Feds Withhold Funds to Compel IT Security?

April 27, 2010 - Eric Chabrow

Eric Chabrow
CISO suggests strong-arming cities to practice IT hygiene....
-----------
The Public Eye

Prime Time for Cybersecurity

November 9, 2009 - Eric Chabrow

Eric Chabrow
Weighing the impact on mass exposure to the infosec challenge....
-----------
The Public Eye

Infosec Among Hottest Professions in U.S.

November 3, 2009 - Eric Chabrow

Eric Chabrow
IT security jobs seen growing by 27% over 10 years....
-----------
Compliance Insight

Boards of Directors: How to Set the Tone at the Top for Security and Compliance

February 4, 2009 - David Schneier

David Schneier
We're barely out of January, and already this year has revealed itself as one to remember. Between the worsening conditions within the banking sector, the Heartland breach and a very noticeable shift in the regulatory climate, we're already hard pressed to pick this year's "Story of the Year." And somehow I suspect that this is only the beginning in more ways than just on the pages of the calendar....
-----------
The Public Eye

Community Colleges: Best Cybersecurity Training Grounds?

June 23, 2009 - Eric Chabrow

Eric Chabrow
On Capitol Hill, expert witnesses testify about the need to beef up graduate-level education, not only to train needed cybersecurity professionals, but prepare the PhDs and others needed to educate IT security specialists. But just outside the Beltway that encircles Washington, community colleges - hoping to tap millions of dollars President Obama promises to spend on strengthen federal government IT security - are instituting cybersecurity programs....
-----------
The Field Report

Early Predictions for 2010

December 4, 2009 - Tom Field

Tom Field
Tis the season, indeed.

As December starts, already I'm talking with thought-leaders about what the world of information security might look like in 2010....

-----------
The Agency Insider

New Rules for Social Networking

March 25, 2010 - Linda McGlasson

Linda McGlasson
Do you know what your employees are tweeting about or posting on their personal Facebook wall?...
-----------
The Agency Insider

Don't Make Gonzalez Another Famous Ex-Hacker

March 23, 2010 - Linda McGlasson

Linda McGlasson
What I'm hoping for is that no one steps up and makes this person famous for his criminal exploits....
-----------
The Agency Insider

Heartland One Year Later: What Have We Learned?

January 20, 2010 - Linda McGlasson

Linda McGlasson
I remember Jan. 20, 2009, as a date of historic significance. Not only did the country see the swearing in of the first African American U.S. President, but at the same time as the country's eyes were on Washington, D.C., there was another historic event happening....
-----------
The Agency Insider

Phishing Season is Here Again

May 12, 2010 - Linda McGlasson

Linda McGlasson
At the root of the ACH and wire fraud striking small businesses is the social engineering crime called phishing....
-----------
The Expert's View

BB&T Acquisition of Colonial: Ironic and Inexplicable

August 21, 2009 - William Black

William Black
The FDIC-assisted BB&T acquisition of Colonial is ironic and inexplicable. The acquisition means that federal regulators have allowed a bank, already "too big to fail," to continue to grow massively.

We should learn several lessons from the BB&T acquisition of Colonial:...

-----------
Compliance Insight

Regulatory Compliance: It's Not Enough to Plan; You Must Test

January 27, 2009 - David Schneier

David Schneier
When it comes to regulatory compliance and its intended purpose, I'm a believer. I genuinely believe that if a bank or credit union implements and supports all required controls essential to achieving compliance, they're the better for it, and their account holders can sleep better at night. What you might've missed in the last sentence is the size of the "if"; it's mighty big....
-----------
The Agency Insider

The Perfect Storm is Brewing

March 1, 2010 - Linda McGlasson

Linda McGlasson
There's a storm brewing on the horizon for the financial services industry, and it may be as devastating as "The Perfect Storm."...
-----------
Secure Marketspace

FinancialStability.gov - From Translucent to Transparent

February 11, 2009 - Mike D'Agostino

Mike D'Agostino
I remember when I was a child and my parents had a stand-alone shower stall. The walls and door were made of glass with a wavy contour, and they were frosted. Which means instead of being clear like a window, they added a pasty kind of blur to anything on the other side. Everyone has seen this before - you may have a shower like this; it does add a bit of privacy. From the on-looker, you can just about make out shapes and perhaps lighter and darker areas, however you never quite know what exactly is going on....
-----------
The Agency Insider

New Guide for Businesses to Defend Against Cyber Attacks

April 5, 2010 - Linda McGlasson

Linda McGlasson
A new action guide by ISA and ANSI gives businesses a framework to develop information security programs to protect from cyber attacks....
-----------
The Public Eye

Congress' Busy Infosec Agenda

October 29, 2009 - Eric Chabrow

Eric Chabrow
Next up: Data breach, data privacy bills....
-----------
Secure Marketspace

Multi-Factor Authentication ... or be Sued?

September 7, 2009 - Mike D'Agostino

Mike D'Agostino
The news story going around about the couple that was granted permission to sue their bank because of lackluster security measures interests me in a few different ways....
-----------
The Agency Insider

H1N1 Round Two: Are You Ready?

September 8, 2009 - Linda McGlasson

Linda McGlasson
As summer draws to an end, schools reopen and Labor Day arrives, there's something else that everyone is looking to return: the H1N1 flu virus. U.S. organizations handled the so-called swine flu virus spread in the spring, but now is the time to ask: Are you and your staff ready for its return?...
-----------
Compliance Insight

Heartland Breach Saps Resources, Time from Institutions

February 13, 2009 - David Schneier

David Schneier
Since the Heartland Payment Systems (HPY) data breach became "The Story," I've been trying to keep my distance from a blogging perspective, as it's being covered quite nicely elsewhere. Besides, I'm the regulatory compliance man in the field, and while this story certainly touches on related issues, it's off to the side of what I'm typically looking at.

This week that all changed....

-----------
The Public Eye

Sometimes, Stuff Happens

November 4, 2009 - Eric Chabrow

Eric Chabrow
Spaf, the infosec guru, is well prepared for laptop theft....
-----------
The Field Report

Are We Taking H1N1 Seriously?

October 27, 2009 - Tom Field

Tom Field
I rarely turn on TV news anymore (hey, I live in front of a computer screen!), but twice last week I found myself watching cable news shows, and here's what I saw:...
-----------
The Field Report

The Faces of Fraud 2010

April 2, 2010 - Tom Field

Tom Field
Payment cards, ACH, ATM - these are the forms of fraud that have made the biggest news so far in 2010. But there's another variation preying upon banking institutions, too....
-----------
The Field Report

Failed Banks and Credit Unions: The True Picture

November 20, 2009 - Tom Field

Tom Field
As of this moment, 124 banks and 29 credit unions have been closed, acquired or placed into conservatorship so far in 2009....
-----------
The Agency Insider

Dwelling House Failure: A Story of ACH Fraud

August 15, 2009 - Linda McGlasson

Linda McGlasson
The failure of Dwelling House Savings and Loan illustrates to me what smaller institutions are facing when it comes to securing their data....
-----------
The Public Eye

First CTO Suggest Cybersecurity Role for New CTO

April 24, 2009 - Eric Chabrow

Eric Chabrow
The first federal CTO thinks the new federal CTO also could serve as the federal cybersecurity czar.

Norm Lorentz served as the federal chief technology officer in 2002 and 2003, working within the White House Office of Management and Budget. In that job, Lorentz focused on developing the federal IT enterprise architecture, in which information security was a crucial component....

-----------
Secure Marketspace

Electronic Voting: The Ultimate Online Banking Application

March 19, 2009 - Mike D'Agostino

Mike D'Agostino
Every day I'm driving to or from work -- or even on the weekends - it seems like I hear about some new urgent priority that I must be aware of, whether it be the flailing economy, President Obama's directives, data breaches, or any number of other news-worthy items. But I love the news - so I don't mind!...
-----------
The Field Report

BAI Insights: The Growth of Mobile Banking

November 5, 2009 - Tom Field

Tom Field
Two of the words heard most frequently in discussions at the BAI Retail Delivery Conference & Expo: Mobile banking....
-----------
The Field Report

RSA Day One: It's All About Poe

April 21, 2009 - Tom Field

Tom Field
And so it begins ...

As this morning dawns on San Francisco, so begins the 2009 edition of the RSA Conference.

As anyone in information security can tell you, this is the Mardi Gras, the Super Bowl, the event in the industry. It's where security professionals from all walks of the public and private sectors come to discuss the major threats and solutions of the day....

-----------
Secure Marketspace

A World Without Payment Cards (and PCI Compliance)

September 24, 2009 - Mike D'Agostino

Mike D'Agostino
Credit and debit cards are everywhere. I use mine daily, and I suspect many functioning adults in the U.S. and beyond do as well. For me, convenience is a major factor in their use - instead of carrying around wads of cash, I can carry a single piece of plastic and use it to accomplish the same goal -- buy things. If I lose my wallet or worse, get robbed, I'm out a small piece of plastic instead of actual cash....
-----------
The Agency Insider

Risk Management is Now in Style

April 23, 2010 - Linda McGlasson

Linda McGlasson
A recent survey of public banking institutions shows that the number of public banking institutions with a chief risk officer nearly doubled in 2009....
-----------
The Agency Insider

Worm To Deliver April Fool's Day Surprise?

March 29, 2009 - Linda McGlasson

Linda McGlasson
This is something that used to really get me going as an information security practitioner. Someone would forward me (and everyone else they knew) an email that had the most dire of warnings - "EMAIL VIRUS WILL WIPE YOUR HARD DRIVE - Do not open !!!"...
-----------
The Expert's View

Data Security as a Business Case

October 8, 2009 - Philip Alexander

Philip Alexander
There is no such thing as the hack-proof computer.

Once we accept that reality, the next challenge is to acknowledge that a certain amount of IT risk is a part of conducting business. Risks also come in many different forms. I'm often asked which is worse -- regulatory, policy or compliance risk? I believe it may actually be reputational risk....

-----------
Information Technology Risk Management

An Open Letter to Heartland CEO Robert Carr

August 31, 2009 - Sanjay Kalra

Sanjay Kalra
It was nice of Tom Field and his team to let me be away for the last number of months as they held the fort and blogged on all sorts of matters from Bernie Madoff to FDIC issuing alerts regarding online fraud and BB&T's acquisition of Colonial Bank. It's even nicer to be back. Lots and lots of news on the technology risk management front to talk about....
-----------
The Agency Insider

Heartland's Lesson: How to Handle A Data Breach

February 10, 2009 - Linda McGlasson

Linda McGlasson
The fallout is still coming from the Heartland Payment Systems (HPY) data breach, and banks and credit unions are still dealing with the aftermath. At today's count there are more than 124 banks and credit unions affected by the breach, the number of cards affected topping 250,000.

The big question is: If your institution was hit with this kind of data breach that wasn't caused by your institution, would you be ready to respond?...

-----------
The Agency Insider

Anatomy of a Penetration Test

July 1, 2008 - Linda McGlasson

Linda McGlasson
I was talking the other day with a friend who works at an information security risk company. He shared with me the higher-level details of a physical penetration test on which he tagged along....
-----------
The Agency Insider

Vishing Spree Continues to Target Customers

April 26, 2010 - Linda McGlasson

Linda McGlasson
The signs aren't looking good if you're not prepared to handle vishing incidents against your customers....
-----------
The Field Report

My 7 Banking/Security Resolutions for 2010

January 4, 2010 - Tom Field

Tom Field
Here is my short list of banking/security resolutions for the New Year....
-----------
The Agency Insider

Heartland/Visa Settlement Raises Questions

January 12, 2010 - Linda McGlasson

Linda McGlasson
The $60 million settlement announced by Heartland Payment Systems and Visa on Friday didn't come without some provisions (translated: strings attached) for those institutions thinking about taking the settlement offer....
-----------
The Agency Insider

On Zeus, ATM Fraud and Foreclosures

April 19, 2010 - Linda McGlasson

Linda McGlasson
To start this week, I want to take a look at some of the numbers that caught my eye. Trojans, ATM fraudster plea and home foreclosure rates are some of the stories that should mean something to everyone....
-----------
The Field Report

Stupid Bank Robber Tricks

August 12, 2009 - Tom Field

Tom Field
Robberies, ATM heists, insider thefts - there are so many risks to employees, customers, funds and electronic data, and they're only heightened by economic conditions. Desperate times, desperate people. This is why we focus on physical security this month - to underscore how critical it is to a banking institution.

That said ... there really are some funny stories out there about attempted robberies!...

-----------
Career Insights

Developing Business Focus in Security Initiatives

January 11, 2010 - Kent Anderson

Security leaders are consistently told to "align security with the business." However, figuring how to do this successfully is often elusive....
-----------
Compliance Insight

FDIC: Now Hiring 1400 New Examiners

December 18, 2008 - David Schneier

David Schneier
The FDIC announced details regarding their recently approved 2009 operating budget. Not exactly your "stop the presses, hold all my calls" sort of thing, but it was worth my time to read through it....
-----------
The Field Report

Famous Last Words for a Failed Bank

March 16, 2010 - Tom Field

Tom Field
What a difference a year makes.

Almost exactly one year ago, I interviewed Charles Antonucci Sr., CEO of Park Avenue Bank. His institution was in the news because it withdrew its application for federal Troubled Asset Relief Plan (TARP) funds.

Last Friday, Park Avenue Bank was closed....

-----------
The Field Report

Fighting Fraud in the Re-Set Economy

April 16, 2010 - Tom Field

Tom Field
Just back from FICO World with insights and observations on the re-set economy....
-----------
The Fraud Blog

Remembering the Man Who Gave us the ATM

May 24, 2010 - Tracy Kitten

Tracy Kitten
Last Friday, the world put to rest the man who has been credited with the invention of the modern-day automated teller machine -- the ATM....
-----------
The Agency Insider

SEC Antics Serve as Policy Reminder

April 27, 2010 - Linda McGlasson

Linda McGlasson
So, while the financial industry tanked, the Securities and Exchange Commission's top staffers watched their fave x-rated videos?...
-----------
The Agency Insider

Mortgage Fraud: Education Key to Prevention

April 9, 2010 - Linda McGlasson

Linda McGlasson
The scenario is a familiar one: Desperate homeowners who are falling behind on mortgage payments want to find help. They find a scammer instead....
-----------
Secure Marketspace

How Google Will Save the Banking Industry (and the U.S. Economy)

October 21, 2008 - Mike D'Agostino

Mike D'Agostino
Yes, yes, we all know the economy is hanging by threads right now. Banks that have been around forever are closing around us, the largest financial institutions are faltering, the stock market is down and up and down and up again, the Treasury is pumping hundreds of billions of dollars into the economy, and we are all hanging on edge waiting for the next big news....
-----------
Information Technology Risk Management

Economic Crisis: Who Do We Blame Next?

October 9, 2008 - Sanjay Kalra

Sanjay Kalra
Two nights ago, I dozed off on the recliner while watching the second Presidential debate on CNN. I am quite sure the debate had an exciting and educated exchange of ideas and philosophy on where our country needs to go next (by nature, I am an optimist), but the exhaustion from the day's events just couldn't keep me awake....
-----------
The Field Report

My Favorite Interviews of 2009

December 31, 2009 - Tom Field

Tom Field
Earlier this week, I blogged on what have been the most popular interviews I've conducted in 2009 - and there have been a lot of them.

Today I'd like to talk about my favorite interviews of the year. And there have been a magnificent seven of those....

-----------
The Field Report

At the Heart of the Data Breach(es)

March 5, 2009 - Tom Field

Tom Field
OK, so how many payment processor data breaches are we talking about - one or two? That's been the big question we've been trying to sort out this week. And I'm not sure anyone knows definitively. If they do, they're not telling....
-----------
Information Technology Risk Management

State of Information Security: Educating Your Board

July 7, 2008 - Sanjay Kalra

Sanjay Kalra
The Section 501(B) of Gramm-Leach-Bliley Act clearly defines Board of Directors' responsibilities re: developing Information Security program for a financial services institution. It calls for significant board involvement in the creation and the oversight of the information security program.

Have you had this conversation with your board lately?...

-----------
Compliance Insight

Heartland: Where is the Outrage?

March 9, 2009 - David Schneier

David Schneier
How is it that Heartland doesn't remain front and center in the mainstream media?

I made the mistake of popping open a browser today and loading my preferred news website, and it was sort of like the ultimate one-two punch that hit me with concussive force....

-----------
Compliance Insight

Increased Regulatory Scrutiny: A Good Thing or Bad?

January 16, 2009 - David Schneier

David Schneier
Last week the NCUA announced the formation of the National Examination Team (NET) to "enhance the supervisory process in areas where economic conditions have adversely impacted federally insured credit unions." Or as I like to think of this move, the FDIC sneezes, and NCUA catches a cold....
-----------
The Field Report

RSA Day Two: It's About the Government, Stupid!

April 22, 2009 - Tom Field

Tom Field
Observations from day one of the RSA Conference.

Edgar Allan Poe might be the conference theme, but the topic everybody is talking about? Government.

From financial regulatory reform and compliance to the Obama Administration on cybersecurity, attendees and sponsors alike all are talking about the convergence of the U.S. federal government and information security....

-----------
The Field Report

Anti-Fraud: Customer Loyalty is King

April 15, 2010 - Tom Field

Tom Field
Reporting from the FICO World event in Miami, where many discussions are centered around fraud....
-----------
The Agency Insider

Heartland Breach: Déjà vu All Over Again

January 23, 2009 - Linda McGlasson

Linda McGlasson
While the dust is still settling and the forensic teams finish their investigations over at Heartland Payment Systems (HPY), and the line of banks and credit unions begin to form to jump onto the litigation bandwagon because their customers' card were hit in this latest data breach ... one thing jumps out at those of us who've been around for a while. This type of data breach has happened before at a payment processor....
-----------
Compliance Insight

Credit Unions Pay a Premium for Doing the Right Thing

March 2, 2009 - David Schneier

David Schneier
I was thinking after my last few Heartland-centric posts that I should probably get back to covering the basics of our practice and re-focus on all things regulatory. So I started skimming through my notes from recently completed fieldwork looking for ideas. The last few engagements happened to be with Credit Union clients, and the only thing that kept jumping off the pages at me was their struggles addressing the NCUA's actions to restore the National Credit Union Share Insurance Fund (NCUSIF) equity ratio to sufficient levels....
-----------
The Agency Insider

Insider Threat's New Twist: Fraud Via the Spreadsheet

March 9, 2009 - Linda McGlasson

Linda McGlasson
Most of us deal with the ubiquitous spreadsheet at least once a day in our daily work. Whether it is creating or updating reports for senior management or keeping track of equipment inventories - or the hundreds of other uses for spreadsheets - financial institutions depend on these workhorses to retain and create repositories of valuable data.

Without even considering the external threats that flaws in Microsoft Excel spreadsheets pose, including the yet unpatched zero day flaw Microsoft recently revealed in late February, the concern that many institutions may overlook is the potential for fraud perpetrated by employees....

-----------
The Expert's View

Heartland Data Breach: What is an SQL injection?

August 25, 2009 - Dan Grosu

Recent news about the Heartland Payment Systems data breach hints that SQL injection played a key part in the attack....
-----------
Compliance Insight

It's Time to Get Serious About PCI as a Regulation

February 20, 2009 - David Schneier

David Schneier
I had an interesting email from a colleague the other day. Turns out someone he knows had recommended that he read a post of mine from January in which I discuss the value (or lack thereof) of having controls in place that don't function. He wanted to let me know about the reach of BIS and let me know that our audience is aware, paying attention and apparently taking notes. But in trying to figure out which post was being referred to, I wound up taking an unintentional stroll down BIS Blog memory lane....
-----------
The Field Report

Trust on Trial

March 10, 2010 - Tom Field

Tom Field
Looking back on the week in SF, I'd say there were three words spoken constantly at RSA: Cloud, Computing ... and Trust....
-----------
The Agency Insider

Homeowner Beware: Mortgage Fraud Scams Abound

February 23, 2010 - Linda McGlasson

Linda McGlasson
It's been almost a year since the Financial Crimes Enforcement Network (FinCEN) issued its red flag advisory about foreclosure scams. Now it looks like the agency sees another spike in mortgage modification scams hitting the U.S....
-----------
The Expert's View

H1N1 Pandemic: What it Means to Banking Institutions

August 7, 2009 - Patricio Alfaro

Patricio Alfaro
The sudden emergence of H1N1 influenza has sent worldwide stress signals throughout the already burdened financial organizations. The potential effects of an unknown virus justify that concern....
-----------
The Agency Insider

The Battle of the Botnets

March 5, 2010 - Linda McGlasson

Linda McGlasson
The Mariposa "botnet" included PCs inside more than half of the Fortune 1000 companies and more than 40 major banks....
-----------
The Business of Security

Choosing the Right Staff

July 23, 2009 - Steve Katz

Steve Katz
If there's one thing I've learned about information security professionals, it's that they come in multiple flavors.

Yet, increasingly today, you want people who can run security like a business, feel comfortable in maintaining a seat at the table and are willing to work with changing governance...

-----------
The Field Report

BAI Wrap: Industry Insights, the Road Ahead

November 6, 2009 - Tom Field

Tom Field
Just back from the BAI Retail Delivery Conference & Expo in Boston.

If I could boil down the event to just a couple of themes, they'd be......

-----------
The Agency Insider

'Tis the Season: Add Security to Holiday Greetings

November 27, 2009 - Linda McGlasson

Linda McGlasson
It's time to renew the security education effort because 'Tis the Season for Thieving....
-----------
The Field Report

RSA Wrap-Up: Annual Banking Survey Results Debut at Show

April 27, 2009 - Tom Field

Tom Field
I'd like to think we saved the best for last.

This past Friday, as the annual RSA Conference concluded, I presented the results of our annual Banking Information Security Today survey to a surprisingly packed house of banking/security leaders, regulators, consultants and vendors....

-----------
The Field Report

Hathaway Speech Lacks Substance

April 23, 2009 - Tom Field

Tom Field
She did a Geithner.

In making her first public appearance since delivering her long-awaited cybersecurity review to President Obama last week, Melissa Hathaway took to the stage at the RSA Conference in San Francisco on Wednesday. And she did exactly what Treasury Secretary Timothy Geithner was criticized for when he made his first public appearance to discuss how the Obama administration would tackle economic recovery....

-----------
The Agency Insider

Attack Update: Man-In-The-Browser, and Chat-In-The-Middle On Horizon For US Financial Institutions

September 18, 2009 - Linda McGlasson

Linda McGlasson
A recent conversation with a security researcher in Israel gave me a real feeling of dread. Toward the end of our talk, I asked Uri Rivner, head of new technologies, consumer identity protection, RSA Security, about what he sees on the horizon for online attacks against banking customers. What he told me wasn't good news....
-----------
The Field Report

Regulatory Reform: It's Time ... But is There Time?

February 11, 2010 - Tom Field

Tom Field
Can financial regulatory reform truly happen before the mid-term elections?...
-----------
The Field Report

Meet me at BAI in Boston

November 2, 2009 - Tom Field

Tom Field
Quick heads-up to those of you who will be in the Boston area this week: The BAI Retail Delivery Conference & Expo starts Tuesday at the Boston Convention & Exhibition Center. I'll be in attendance on Weds and Thurs, and I'd welcome the opportunity to meet you....
-----------
The Agency Insider

Heartland is Indeed the Big Deal

August 19, 2009 - Linda McGlasson

Linda McGlasson
Well, it is good to finally have a number to go along with the Heartland Payment Systems data breach, and even better that three hackers have been indicted for the crime. Albert Gonzalez, a 28- year-old identified as the lead hacker, faces up to 25 years in prison and a $250,000 fine if convicted....
-----------
Information Technology Risk Management

TJX Case Indictments: Lessons Learned

August 12, 2008 - Sanjay Kalra

Sanjay Kalra
The indictments of 11 individuals by the Department of Justice last week brought the TJX case and the other high-profile compromises of a number of retailers back into the limelight. I personally know a significant number of banking institutions that were victims of this crime.

These criminal activities perpetrated by these individuals had a great deal of impact on the banking institutions - a different impact, in some ways, than the actual incidents had on the retail outlets....

-----------
The Field Report

Survey Results Point to 2009 Hot Topic: Vendor Management

November 4, 2008 - Tom Field

Tom Field
Couple things I'd like to quickly bring to your attention.

First, have you checked out any of the new Bank Information Security Handbooks we introduced last week?

These electronic editions compile highlights of our content - articles, interviews, blog postings, agency alerts, etc. - in a unique format that gives you access to broad information resources from our ever-expanding content library. The goal is to put more information at your fingertips - help you make better-informed decisions. Humbly, I think we've succeeded....

-----------
The Field Report

Last Chance: Take the 2010 Banking Information Security Today Survey

February 19, 2010 - Tom Field

Tom Field
OK, so have you taken the 2010 Banking Information Security Today survey?...
-----------
The Agency Insider

The 'Dirty Dozen' Tax Schemes to Avoid

March 31, 2010 - Linda McGlasson

Linda McGlasson
Spring is here, and so is tax season. There are numerous scams and schemes that can fool anyone, including taxpayers....
-----------
The Agency Insider

Could This Senior Citizen 'Lottery Winner' Be A Customer Of Yours?

December 14, 2009 - Linda McGlasson

Linda McGlasson
I'm never surprised anymore when I talk to my contacts out in the "real world" of financial services and they tell me about the different types of fraud schemes they're uncovering....
-----------
The Field Report

New Identity Theft Red Flags Rule Survey Sheds Light on Compliance Efforts

June 26, 2008 - Tom Field

Tom Field
We've known for roughly six months now that the Identity Theft Red Flags Rule compliance deadline is Nov. 1, barely four months away. How close, then, are banking institutions to meeting that deadline?

That is the question of the summer, and the answer will be found in the results of our new Identity Theft Red Flags Rule Compliance Survey. The goal of this survey (which ends on Friday, June 27, hint, hint) is to take the pulse of the marketplace ......

-----------
The Field Report

Cybersecurity, Biometrics, the Pandemic and Other Hot Topics

May 5, 2009 - Tom Field

Tom Field
OK, back home and back in the office fulltime after a couple of weeks on the road to California for the RSA Conference and a bit of R&R. Some observations as I clear my desk ......
-----------
The Field Report

Social Media: You Can't Ignore, so Explore

November 10, 2009 - Tom Field

Tom Field
One of the recurring topics at last week's BAI Retail Delivery Conference & Expo -- in almost all recent conversations about the banking industry, in fact - was social media....
-----------
Information Technology Risk Management

The Rescue Plan: Bringing Confidence Back to the Credit Markets

October 14, 2008 - Sanjay Kalra

Sanjay Kalra
It seems like ages ago when I wrote about the credit markets being frozen and the major indices at stock markets around the world taking a nose-dive. It was actually last week. In terms of trading days, it was only two days ago. But something changed with the beginning of the new week....
-----------
The Field Report

Top 10 Stories of the Year

December 30, 2009 - Tom Field

Tom Field
This is always a fun exercise.

I spent some time today looking back over all the articles we published (so far) in 2009. And that number is 891, by the way - an average of just over 17 per week, or three-plus per weekday. But the number that concerned me most is 10 - what have been the top 10 most popular stories of the year?...

-----------
The Agency Insider

Last in the Hearts of Their Customers

February 12, 2010 - Linda McGlasson

Linda McGlasson
Forrester's annual Customer Advocacy ranking grades about 50 financial services firms in the U.S. by the percentage of each firm's customers who agree with the statement "My financial provider does what's best for me, not just its own bottom line."...
-----------
The Business of Security

Asking the Right Questions

May 21, 2009 - Steve Katz

Steve Katz
I moved to Citicorp in the mid-90s, and from the beginning we recognized that in order to be successful, information security had to have the support and buy-in from business and executive management....
-----------
Compliance Insight

OK, So You Detect a Red Flag. Now What?

October 31, 2008 - David Schneier

David Schneier
Hard to believe that November 1 is already upon us, bringing the onset of the Identity Theft Red Flags Rule compliance. We've been reading about and discussing it for so long that it almost seemed as if though it would always remain six months away, but even a watched regulation eventually transitions into effect. And so here we are with my kids eagerly anticipating Halloween candy and me anxiously waiting for the first formal examiner's review of a Red Flags program.

However, I'm in a better position to forecast how it's likely to go down. We've started seeing final draft versions of Red Flags programs from our clients, and combined with the availability of the agencies' related examination procedures I'm developing a perspective not previously possible....

-----------
The Agency Insider

Cybersecurity Awareness: Rules of the Virtual Road

October 15, 2009 - Linda McGlasson

Linda McGlasson
This month didn't slip out of my scope, but it's already October 15 -- halfway through Cybersecurity Awareness Month, designated for the last six years as the month when the public relation arms of security vendors, governors of states and other political types with predetermined agendas set forth to right a whole year of ignoring the need for strong information security awareness....
-----------
The Agency Insider

Pandemics of The Past and Lessons Learned

April 30, 2009 - Linda McGlasson

Linda McGlasson
I certainly wasn't around during the Spanish Flu pandemic of 1918-1919 - I vaguely remember the 1968 Asian Flu pandemic as a small child - but some of my relatives recall that health catastrophe of 88 years ago.

My 95-year-old great uncle remembers the 1919 school year as being abbreviated, cut short as a second round of infections that hit the central Indiana community where he and my maternal grandmother grew up....

-----------
The Field Report

Hard Times Don't Build Character; They Reveal it

December 23, 2008 - Tom Field

Tom Field
Pulling together some random notes here, heading into the holiday home stretch......
-----------
The Agency Insider

Phishing Plays us All for Phools

October 9, 2009 - Linda McGlasson

Linda McGlasson
It doesn't surprise me to hear that even top law enforcement officials don't bank online because they almost fell for a phisher's line of "Your bank account has been compromised, click here to reset your password..."...
-----------
The Agency Insider

Who's Breaking the Rules on Your Staff?

March 17, 2010 - Linda McGlasson

Linda McGlasson
A new poll shows that more than one in 10 U.S. employees says they've known they were violating policies put in place by their company's IT departments, but violated them anyway to get their work done....
-----------
Secure Marketspace

How Financial Institutions Can Leverage Modern Bank Heists

July 15, 2008 - Mike D'Agostino

Mike D'Agostino
Whenever family or friends or otherwise ask what I do or what kind of company I work for, I always take the opportunity to start off with a question: Do you know what "information security" is? I do not expect much, as I myself could not quite give a clear definition before working in the position I hold now. No one likes to admit they don't know something, so usually I get a pause, a sigh, a shoulder-shrug, and finally something along the lines of, "I kind of have a basic idea, but I can't really explain it."

If anyone gives an answer, it usually defines something technical - such as making sure your computer networks are secure so hackers can't in, or staying up to date with the latest patches for your anti-virus software. Afterwards I will explain that, yes, those things are indeed part of what makes up information security, but that there is so much more to it....

-----------
The Agency Insider

How - and When - to Deliver Bad News to Your Customers

April 8, 2010 - Linda McGlasson

Linda McGlasson
Think you know how you should communicate with your customer? What about when there is some suspicious activity on their account - how do you reach out to them? And when?...
-----------
The Field Report

Online Fraud: Who's Looking Out for Businesses?

August 27, 2009 - Tom Field

Tom Field
TJX. Hannaford. Heartland. Those are the names we all know, the famous fraud stories we all can recite by heart.

But who knows about Unique Industrial Product Co., a Sugar Land, Tex.-based company that lost $1.2 million to fraudsters this last April?...

-----------
Compliance Insight

Why Regulatory Compliance Works

October 7, 2008 - David Schneier

David Schneier
In discussing our current banking crisis with a colleague earlier this week, I was surprised by the level of cynicism he displayed towards the regulatory agencies and their efforts to govern the institutions they oversee. He's a practitioner like me, and I'd always thought of him as being of an equal mind on such matters. I was wrong....
-----------
The Field Report

Failed Banks: Better to Close than Receive?

December 21, 2009 - Tom Field

Tom Field
Did you catch the failed bank action this past Friday night? Among the 7 banks that were closed, there were some intriguing storylines....
-----------
Secure Marketspace

It's Not a Matter of Trust, It's a Matter of Honesty

April 24, 2009 - Mike D'Agostino

Mike D'Agostino
I'll admit that even though we're in the "age of digital," IPODS, Flip cams, and satellite radio, I still find some comfort in good ol' radio. I'm somewhat of a news junkie, and so naturally AM is my choice. Sure, I'll turn on the conservative guys for a few laughs every now and then, but most often I have the dial turned to Bloomberg. Because I listen on the way into work, and the way home, Tom Keene seemingly has a 24-hour presence. And I have no problems admitting I'm a big fan....
-----------
The Field Report

H1N1: What to Do When the Virus Strikes

November 16, 2009 - Tom Field

Tom Field
So, here's my story: Two weeks ago, the day before Halloween, one of my son's friends goes home from school with a fever, cough, nausea - all the early symptoms of the H1N1 virus, or swine flu....
-----------
The Agency Insider

Money Laundering Hits Home

July 24, 2009 - Linda McGlasson

Linda McGlasson
Driving to my office yesterday, I listened to the radio as an announcer read the news of an FBI sweep that saw politicians and religious leaders arrested. The first group I wasn't exactly surprised about, but religious leaders? Well, I was listening even more closely when the radio announcer then said there were four rabbis arrested and charged with money laundering....
-----------
The Agency Insider

In Time of Disaster, Beware the Con

April 14, 2010 - Linda McGlasson

Linda McGlasson
Disaster victims face an even more sinister threat that lurks in their neighborhoods -- scam artists looking to take advantage of them...
-----------
Information Technology Risk Management

Picking up the Pieces from 'Bloody Monday'

We Do, Indeed, 'Live in Interesting Times'
September 16, 2008 - Sanjay Kalra

Sanjay Kalra
It's Tuesday, and after the bloody Monday we just had, I thought I would work backwards and try to pick up some of the pieces from where we left off a couple of weeks ago.

Lehman Brothers, after being in the business for 158 years, is now to be referred to in the past tense. Yes, the biggest bankruptcy in history was filed yesterday, September 15, 2008. The day will go down in history for a couple of other reasons:...

-----------
The Field Report

'Confidence' is the Key Word in the Wake of Bank Closings

July 25, 2008 - Tom Field

Tom Field
Want a fun exercise?

Go to Google News and type in "banks, confidence" - see what results you get.

These words are top-of-mind for all of us, of course, in the wake of the IndyMac Bank failure . Customer confidence is almost like the stock market - on a daily basis, we wonder whether it's up or down.

Even where I live, in southern New Hampshire, one of our community newspapers, Foster's Daily Democrat, came right out last week and asked its readers: 'How confident are you in your local bank?' Not sure that's a fair question, as the newspaper really didn't give its readers any context in which to frame their answers. But, still, in a resulting news story, NH banking leaders were quick to distance themselves from the turmoil caused by the subprime mortgage crisis....

-----------
The Agency Insider

Beware Internet Scams Old and New

March 18, 2010 - Linda McGlasson

Linda McGlasson
The release of the FBI's Internet Crime Complaint Center (IC3)annual report continues to reveal some seriously troubling numbers if you're on the side of the good guys....
-----------
Information Technology Risk Management

Banking Crisis Hits Home with Community Institutions

July 28, 2008 - Sanjay Kalra

Sanjay Kalra
It used to be a joke in the banking industry:

Question: How do you define a community bank?

Answer: When the CEO can walk out onto any street, be recognized and asked "What are you doing with my money?"

Suddenly, in the wake of recent bank closings, this old scenario leaps to mind, but now it's no joke....

-----------
The Field Report

BAI Retail Delivery Conference: Notes from the Floor

November 4, 2009 - Tom Field

Tom Field
Notes from the BAI Retail Delivery Conference & Expo in Boston ......
-----------
Compliance Insight

Vendor Management: One Size No Longer Fits All

August 8, 2008 - David Schneier

David Schneier
I'm out in the field this week conducting a series of services for one our clients. At the moment I'm heavily focused on completing a draft of a new vendor management program for them to implement. Although we have a standard methodology that's been used by the practice for several years, I've taken it upon myself to revise and update where applicable.

Based on what we've been seeing and hearing out in the field, the examiners aren't letting anyone phone this one in any more....

-----------
The Field Report

ID Theft Red Flags, Business Continuity, Vendor Management - Which is Your Biggest Regulatory Challenge?

July 10, 2008 - Tom Field

Tom Field
More ID Theft Red Flags Survey Resources Early this year, I caught up with Steve Katz, the dean of banking CSO's (see Stephen Katz on Top InfoSec Issues of 2008), and he had some interesting insights on the year's top challenges for banking institutions....
-----------
Information Technology Risk Management

WaMu is NoMore!

September 26, 2008 - Sanjay Kalra

Sanjay Kalra
To say that the last couple of weeks have been busy for the people in the news business will be a gross understatement. It was only a week-and-a-half ago that I was talking about the Bloody Monday and its impact on the employees and customers. Well, it's Friday and the last evening the Office of Thrift Supervision read the last rites to one of the country's largest banking institution - Washington Mutual. The bank ceased to exist....
-----------
The Field Report

PCI Just Lost a Friend

November 3, 2009 - Tom Field

Tom Field
I was stunned and saddened to learn of the sudden death of David Taylor, one of the most prominent thought-leaders on the Payment Card System Data Security Standard (PCI)....
-----------
The Field Report

Career Insights to Chew on

November 24, 2009 - Tom Field

Tom Field
OK, it's Tuesday before Thanksgiving, and we're all starting to think ahead to a long holiday weekend and then the quick windup to the Christmas/New Year's break. Hate to say it, but 2010 is all but here....
-----------
The Field Report

About Fraud - See You at FICO World

April 12, 2010 - Tom Field

Tom Field
Are we clear yet that fraud is so far the story of the year, and it comes in several dominant flavors?...
-----------
The Agency Insider

Why Comply With ID Theft Red Flags Rule? Let Us Count the Reasons

December 9, 2008 - Linda McGlasson

Linda McGlasson
When most financial professionals think of the recently enacted ID Theft Red Flags Rule, they shudder, then groan. You know the feeling of that regulatory burden on your shoulders. Another regulation to comply with; when will it stop?...
-----------
The Agency Insider

It's National Consumer Protection Week - Are You Prepared?

March 11, 2010 - Linda McGlasson

Linda McGlasson
Financial institutions should take this week, National Consumer Protection Week, and make every day one to protect their customers from the scammers, phishers, hackers, and downright evil doers who reside in the underbelly of society....
-----------
The Agency Insider

Countrywide and Solving the Insider Threat

August 20, 2008 - Linda McGlasson

Linda McGlasson
Maybe the Countrywide television ads that constantly run on cable news shows I watch on weekends will now tout, "Finance your mortgage with Countrywide, and have your identity stolen at the same time for mere pennies."

The recent arrest of a former Countrywide employee in the insider identity theft case, where an estimated 2 million mortgage loan customers at mortgage lender Countrywide were taken, is just chock full of "but for the grace of God" examples for other financial institutions....

-----------
Compliance Insight

Social Engineering: The Gorilla in the Room

August 26, 2008 - David Schneier

David Schneier
So, I'd started my weekly blog entry intending to discuss application security (I'm keenly interested in what the just-released BIS survey is going to reveal) when the following headline came across on my BIS RSS feed "Social Engineering Hits Brit Bank Head, Victim of Fraud."

You'll have to forgive me for being so easily distracted by this headline, but social engineering is a topic of immense interest for me these days....

-----------
The Field Report

Identity Theft Red Flags Rule: A Chance to Take a Stand

July 29, 2008 - Tom Field

Tom Field
I've told this story before about Michael Barrett, CISO of PayPal. When he joined the company, he asked how senior leaders were fighting the phishing problem.

"Technically, we don't have a phishing problem," he was told....

-----------
Secure Marketspace

Identity Theft Red Flags & What They Mean to Banking Customers

July 8, 2008 - Mike D'Agostino

Mike D'Agostino
More ID Theft Red Flags Survey Resources We are in the process of analyzing data from the Identity Theft Red Flags survey we recently administered - a survey that aims to gauge the current readiness of financial institutions as they move toward complying with new guidance from the banking agencies regarding their identity theft prevention programs. Many of the questions focus on how financial institutions are dedicating resources for this effort, what have been the most significant challenges moving toward compliance, and how their identity theft prevention programs are being managed. Two questions stand out to me though, and the responses are somewhat disappointing....
-----------
Secure Marketspace

Customer Innovation and the Art of Reaching Generation Y

Is Your Financial Institution Marketing to Today's Biggest Populace?
May 23, 2008 - Mike D'Agostino

Mike D'Agostino
Let's face it, the goal of any business is to make money -and grow a base of customers. So where does a banking institution find new customers?...
-----------
Information Technology Risk Management

Events of 2008 and What They Have Taught Us

January 2, 2009 - Sanjay Kalra

Sanjay Kalra
It's that time of the year when each one of us sits down and reflects on how the year that just past by went and develops our own lists of resolutions. Hopefully, there is some connection between these two - we decide on improving things that need to be improved. Looks like - based on this logic - we will have a long list for 2009....
-----------
The Field Report

Heartland: What We've Learned

January 28, 2009 - Tom Field

Tom Field
So, we were among the first to break the Heartland story when it first broke last Tuesday, and we've continued to follow it closely. After the initial media surge, where we saw news outlets and solutions providers tripping over one another to opine over what they think happened to Heartland and what it all means, here is what I believe we've learned so far from the case:...
-----------
The Agency Insider

Why Madoff's Mess Can't Ever Happen Again

June 30, 2009 - Linda McGlasson

Linda McGlasson
As I listened to Bernie Madoff get his prison sentence meted out to him by Judge Denny Chin, I felt some tinge of vindication. But not having been directly affected by the largest Ponzi scheme in history, I can't imagine what the more than 1,000 victims of his unprecedented crime felt at that same time....
-----------
The Field Report

Financial Fraud Task Force - Now What?

November 18, 2009 - Tom Field

Tom Field
OK, as of Tuesday's presidential executive order we now have a Financial Fraud Enforcement Task Force. So, now what?...
-----------
The Field Report

The 3 Biggest Stories No One is Discussing

December 9, 2009 - Tom Field

Tom Field
OK, it's year-end and everybody is thinking about the biggest this, biggest that of the year - of the decade, even. And we'll have our own lists, too, no worries. There's a lot to look back upon this year, and even more to look forward to in 2010.

But what are on my mind today are the big stories that no one seems to be talking about....

-----------
The Field Report

Catching up on the News: ACH and H1N1

September 23, 2009 - Tom Field

Tom Field
Catching up a bit on the news, as shared with me by various banking friends....
-----------
The Field Report

SafeCatch: a New Approach to Confronting Would-be Robbers

August 18, 2009 - Tom Field

Tom Field
Now here's an idea I like for thwarting bank robberies!...
-----------
The Field Report

Dumb Robberies: Signs of Troubling Times

January 6, 2009 - Tom Field

Tom Field
Stupid robbery attempts are always funny, but when they happen in your backyard, well, they're even funnier.

A few weeks back, near my home in New Hampshire, a would-be robber held up a local Citizens Bank branch, and he attempted to get away with an undisclosed amount of cash....

-----------
Compliance Insight

Safety, Soundness and Regulatory Compliance

November 7, 2008 - David Schneier

David Schneier
I'm traveling this week and figured I wouldn't have time to make my weekly blog entry while managing through a very full schedule. Writing these posts by itself is simple enough once you have a topic or idea to work with, but air travel, long car rides and fieldwork at multiple client sites don't allow much room for creative thinking. So it was with some degree of surprise that within the first 24 hours of my work week I encountered not one, not two, but three different items of interest that were worth sharing....
-----------
Secure Marketspace

Credit Crisis as a Segue to a New Financial Model

October 14, 2008 - Mike D'Agostino

Mike D'Agostino
I've heard many, many comments, analyses, opinions and otherwise regarding the current economic condition of the United States. I've heard that we should blame sub-prime mortgages. I've heard greedy CEOs are to blame. I've even heard that if we (the United States) had universal healthcare, we wouldn't be in this situation. Or that Harvard graduates are ultimately to blame. I, however, have been focusing on what "credit" means, and what its effects are on the economy.

When I applied for a mortgage a few years ago, I was offered something outrageous. I've always worked, and I think financially I am a stand-up citizen. However, if I were to use the full extent of the mortgage I was offered, I don't think I would have been able to pay it off under normal, reasonable terms. Even with the stronger market at the time....

-----------
The Field Report

Heartland: Why it Matters

February 5, 2009 - Tom Field

Tom Field
You can't get away from this story.

Since we first broke the news about the Heartland Payment Systems (HPY) data breach back on Jan. 21, this story has just dominated conversation in and about our industry.

On our site, the latest news updates and have proven enormously popular....

-----------
Information Technology Risk Management

Bank of Asia Experience Teaches us: Get Ahead of the News

September 29, 2008 - Sanjay Kalra

Sanjay Kalra
When I went to bed last night, Congressional leaders had just nailed down details of the $700 billion financial bailout.

As I left my house this morning, the President was addressing us about the plan and why we should embrace it.

By the time I got midway to work, Citigroup had acquired most of Wachovia's assets....

-----------
The Field Report

ID Theft Red Flags Compliance: What the Examination Guidelines Tell us

October 20, 2008 - Tom Field

Tom Field
OK, with less than two weeks to go, banking regulatory agencies are getting busy. Busier, I should say.

Last week saw both the OCC and FDIC release their approaches to the Identity Theft Red Flags Rule examination procedures.

No huge surprises here. But what's interesting is when you review the somewhat understated aspects of the guidelines....

-----------
The Agency Insider

Is 2009 The Year of The Phish?

November 18, 2009 - Linda McGlasson

Linda McGlasson
The FDIC, Department of Justice -- the list of targeted entities just keeps on growing. Is it time to name 2009 the Year of the Phish?...
-----------
The Field Report

Bank Failures: A Long, Quiet Weekend

October 14, 2009 - Tom Field

Tom Field
Of all things I was prepared for over the Columbus Day weekend - baseball playoffs, kids' activities, fall foliage - I wasn't prepared for this: A week without bank failures....
-----------
Compliance Insight

New Year's Resolution: Assess Your Risk

December 29, 2008 - David Schneier

David Schneier
Getting people on the phone this time of year can be quite a challenge. Between getting ready for the holidays, celebrating the holidays and trying to wrap up everything outstanding before year end there's simply a shortage of available time. And so as we work on building out the project schedule for the first quarter of 2009, I stress knowing that we have clients that have work that needs to get done, but who aren't ready to commit....
-----------
The Agency Insider

The Great Circle of Compliance - Be the Hunter or the Hunted

June 25, 2008 - Linda McGlasson

Linda McGlasson
Life on the Great Plains for many nomadic Indian tribes was built around the buffalo. The tribes followed the herds of great shaggy beasts across the rolling hills of tall grass, their entire lifecycle centered on the buffalo herd. Braves honed their lance and bow and arrow skills with hours of practice. A common target for the braves' bow and arrow practice was the white skull of a bull buffalo...
-----------
The Agency Insider

On Identity Theft and Breaking the Wrong Record

September 2, 2008 - Linda McGlasson

Linda McGlasson
Everyone was watching the Olympics this past month and saw lots of records being broken. But there is one record no one want to be included in -- the record number of 449 data breaches that have happened (and been made public) and recorded by the Identity Theft Resource Center.

Unfortunately for some unlucky players (and their customers) in the financial services industry, they're on this year's list....

-----------
Secure Marketspace

Customer Acquisition Challenges: Web 2.0 Could Hold the Keys

June 25, 2008 - Mike D'Agostino

Mike D'Agostino
By now we've all heard the buzz term "Web 2.0" - but how many of you truly grasp what it means?

For some time, even those entrenched in Internet marketing and technologies struggled to define the term (brings to mind "GRC"), and nowadays it seems more appropriate to describe web 2.0 by giving examples of specific websites. For example, MySpace.com is a web 2.0 website....

-----------
The Field Report

Application Security - the Vendor Management Connection

September 8, 2008 - Tom Field

Tom Field
To me, this is one of the sleeper stories of the year.

The ID Theft Red Flags Rule, Business Continuity and Anti-Money Laundering have dominated the headlines - and banking/security priorities. But recent attention paid to Application Security has the potential to fuel one major fire drill in 2009....

-----------
The Field Report

FRB Action: A Sign of the Times

May 14, 2008 - Tom Field

Tom Field
In case you missed it - because it wasn't a huge headline anywhere - here's a bit of news about First Pryority Bank, a 108-year-old community bank based in Pryor, OK.

Well, first a bit of background. First Pryority was founded in 1900 by W.A. Graham,...

-----------
The Agency Insider

Is PCI the Humpty Dumpty of Information Security?

April 21, 2009 - Linda McGlasson

Linda McGlasson
As I reviewed the testimony from the other week's hearing on the Payment Card Industry Data Security Standard (PCI DSS) in Washington, D.C., a nursery rhyme popped into my head. While people called to testify about PCI and its effectiveness managed to dodge that all of the breached entities of the last few years were at one point PCI-compliant, but ended up non-compliant when they were broken into by hackers (this includes TJX, Hannaford, Heartland, RBS WorldPay) my thought was, "Is PCI the Humpty Dumpty of information security?"...
-----------
The Field Report

The Pandemic: What's it Really Mean?

August 4, 2009 - Tom Field

Tom Field
I've had this conversation a lot lately.

We'll be talking the news of the day, a colleague and me, and the topic of H1N1, or swine flu will arise....

-----------
The Field Report

Time to Start Thinking About the State of Banking Information Security 2009

July 17, 2008 - Tom Field

Tom Field
Talk about a harmonic convergence.

Just as the major banking regulatory agencies went before the Senate committee recently to deliver their "State of the Banking Industry" addresses, I was sitting back and starting to think about drafting the questions for our next State of Banking Information Security survey....

-----------
The Field Report

State of Banking Information Security Survey: Your Chance to Ask Questions, Get Answers

November 19, 2008 - Tom Field

Tom Field
As wild as the end of 2008 has been, I can't get my mind off 2009.

This is because I'm just now helping to put the finishing touches on our annual State of Banking Information Security survey, which helps us take the pulse of the banking/security community, so we can gauge the priorities for the year ahead.

Last year - the survey's first - we quickly determined that customer confidence was a huge topic for banking institutions, and see how that's played out this year....

-----------
The Field Report

Heartland: How This Disaster Exploded

January 22, 2009 - Tom Field

Tom Field
Let's talk about how a big disaster becomes an even bigger one.

On Tues., Jan. 20 - Inauguration Day - Heartland Payment Systems (HPY) President/CFO Robert Baldwin announced the company had been breached sometime in 2008.Heartland, which processes roughly 100 million transactions per month for 250,000 different businesses, says it discovered malware attached to its processing platform, and an undetermined number of consumers had their names and card numbers exposed to hackers....

-----------
The Field Report

Regulatory Reform: GAO Report Starts the Debate

January 9, 2009 - Tom Field

Tom Field
OK, for months now we've been saying (all right, I've been saying) that we all know regulatory reform is coming; it's just a matter of "what" and "when."

Well, "when" was Thursday, and "what" arrived in the form of a new report from the U.S. Government Accountability Office (GAO), proposing a new framework for the discussion of modernizing what it calls the "outdated U.S. financial regulatory system."

Let the debate begin......

-----------
The Agency Insider

GLBA and Security Avoidance Questions - Why Are We Not Surprised?

August 1, 2008 - Linda McGlasson

Linda McGlasson
Last month I wrote several articles on GLBA compliance, and I asked several people I know who are fluent in these issues what are some of the most common questions they face on GLBA as a security manager or assessor at the institutions they either work at or are assessing?...
-----------
The Field Report

Top 10 Interviews of 2009

December 28, 2009 - Tom Field

Tom Field
To satisfy my own curiosity, I just checked to see what were the 10 most popular podcasts of the year. Here's what I found:...
-----------
Information Technology Risk Management

Business Continuity: How Exactly Did We Get Here?

The Difference Between Regulation and Reality
May 15, 2008 - Sanjay Kalra

Sanjay Kalra
So, here's the million-dollar scenario I was presented with - "We have a well-documented BCP. The organization has never had any issues with this plan, mind you - we have never had to activate this plan since it was developed. I have just taken ownership of this function at the organization. Recently we had an audit and they noticed a number of findings with this plan."

Sadly speaking, I knew what was coming next. Here were the findings from the audit they recently went through....

-----------
The Field Report

The FTC and Red Flags: Another Extension - What Gives?

July 30, 2009 - Tom Field

Tom Field
This one was almost predictable.

We were just days away from Aug. 1, the date after which the Federal Trade Commission (FTC) would start enforcing compliance with the Identity Theft Red Flags Rule.

Then came the announcement from the FTC that it's going to extend the deadline. Again....

-----------
The Field Report

The Big Stories to End '09 with a Bang

September 4, 2009 - Tom Field

Tom Field
Sitting here on the cusp of the Labor Day weekend, and I'm thinking ahead to what I believe will be the big stories - of interest to us in banking/security, at least -- in the final quarter of 2009. Here, in no special order, are my top three......
-----------
The Field Report

All the News That's Fit to Tweet

ISMG Now Offers Updates Via Twitter
May 28, 2009 - Tom Field

Tom Field
It's "tweet" time! Information Security Media Group (ISMG) has just registered with Twitter.com to start providing regular updates to audience members who also are enjoying the tweet life.

OK, so I know some of you out there are still kinda dying to know, but don't dare to ask - what is Twitter?...

-----------
The Field Report

Summer Reading & Banking's Transition

July 14, 2009 - Tom Field

Tom Field
Looking for summer reading?

Just finished a new book, "Late Edition," by one of my favorite writers, Bob Greene. This is a touching, often funny memoir of Greene's days as a newspaper rookie in Columbus, Ohio in the 1960s....

-----------
Secure Marketspace

Did You Receive This Phishing Email?

September 17, 2008 - Mike D'Agostino

Mike D'Agostino
You know someone. Out of millions of Merrill Lynch customers, you should know at least one. Combine Bank of America's many more millions of banking customers, and you have to know someone. I know quite a few myself. All of these people are waiting to be absorbed into what is ultimately a new regime. This state of transition can and will be confusing for existing customers, and phishers and other social engineers will try to capitalize....
-----------
The Field Report

Podcasts: You Should Hear What You're Missing

October 29, 2009 - Tom Field

Tom Field
One of the pleasures of my job is that I get to talk to a lot of people. Bankers, regulators, analysts, security professionals. I enjoy the privilege of speaking to a broad range of thought-leaders and tapping into their insights into the challenges and opportunities of the world today.

And then, through the magic of podcasting, I get to share these conversations with you....

-----------
Compliance Insight

Business Continuity Part 2: Too Many Plans Contain 'Blind Spots'

July 11, 2008 - David Schneier

David Schneier
My recent post on Business Continuity Planning and its role in supporting institutions affected by the recent Midwest flooding generated more than its fair share of dialogue with my peers.

So much of what's required by regulation often presents itself as a documentation exercise and rarely transcends the theoretical domain into practical use. So, when it happens, when an institution needs to depend upon one of these documents to manage through the very situation it was intended to address, it's of great interest to the practitioner community....

-----------
The Agency Insider

The Golden Rule of Information Protection and ID Theft Red Flags Compliance

October 29, 2008 - Linda McGlasson

Linda McGlasson
As institutions look at their calendars and see that November 1 compliance deadline looming, it's time to realize that this isn't just another regulation. The ID Theft Red Flags Rule is about stopping identity theft from happening to your customers.

When I hear information security professionals say they're overwhelmed with the amount of work that is having to be done to comply with such regulatory requirements, I think of what my grandmother always used to tell us when we grandkids were squabbling over something or tormenting our siblings - "Treat others as you would like to be treated; that's the Golden Rule."...

-----------
The Field Report

It's 5 p.m. on a Friday. Do You Know How Many Banks Closed Today?

July 28, 2009 - Tom Field

Tom Field
It's become a Friday night ritual over the past year or so. Wait til 5 p.m., and then watch the clock to see how many after-hours bank failure notices come through from the FDIC or OCC....
-----------
The Agency Insider

Social Networking: What Don't You Want A Prospective Employer To Know?

June 25, 2009 - Linda McGlasson

Linda McGlasson
The power of social networking web sites can be measured by just looking at the number of hits (or visits) to a person's web page on such well-known sites as MySpace or Facebook.

The negative side web users should consider before placing information on such social networking sites include the connection one MySpace page owner had to last year's Eliot Spitzer scandal....

-----------
The Field Report

The FTC and Red Flags - Another Delay?

November 4, 2009 - Tom Field

Tom Field
Want to get an early jump on starting a pool for 2010?...
-----------
The Field Report

Today's the Deadline for Filing Heartland Fraud Claims - Now What?

May 19, 2009 - Tom Field

Tom Field
OK, so today's the day.

After two months of anxious anticipation, today is May 19, the deadline Visa set for financial institutions to file fraud claims related to the Heartland Payment Systems (HPY) data breach.

So...now what?...

-----------
The Agency Insider

It's Time to Get Loud - Banks Are Safe

December 16, 2008 - Linda McGlasson

Linda McGlasson
I have always admired the underdog, rooted for them, and cheered them when they beat unbeatable odds....
-----------
The Field Report

PCI: The Big Unanswered Question

August 10, 2009 - Tom Field

Tom Field
Each time we see a major data breach related to payment card data, the breached entity says 'Gee, well we were told we were PCI compliant - how could this happen?'...
-----------
The Field Report

Madoff: The Sentence Fits the Crime

June 29, 2009 - Tom Field

Tom Field
Can you imagine what the world will be like another 150 years from now, when Bernard Madoff's prison sentence expires?...
-----------
The Field Report

Don't Let Regulatory Reform be Derailed by Improved Economy

September 21, 2009 - Tom Field

Tom Field
Years ago, when I learned to drive and got my first cars, my approach to automobile maintenance was: If the "Check Engine" light came on, keep driving. Whatever the problem is, I'll drive out of it.

I see a disturbingly similar pattern now in the banking industry....

-----------
The Agency Insider

Consumers Come First With Obama's New Watchdog Agency

June 22, 2009 - Linda McGlasson

Linda McGlasson
The Obama financial regulatory reform plan includes a new watchdog agency to protect consumers from deceptive or dangerous mortgages, credit cards, and other risky financial products. It can't come at a better time....
-----------
The Field Report

Notes on Heartland, Madoff and AIG

March 18, 2009 - Tom Field

Tom Field
Clearing my desk and my head this morning...

Interesting nuance in the Heartland Payment Systems breach this week. Did you read the article about Visa and the security update it's presenting to its network of processors? In one part of this presentation, Visa discusses myths and facts about PCI DSS compliance, and one of the clarifications made is: "No compromised entity has been found to be PCI compliant at the time of the breach."...

-----------
Information Technology Risk Management

Bankers: Be Our Society's Security Leaders

June 30, 2008 - Sanjay Kalra

Sanjay Kalra
In the inner-circles of the banking sector, we hear often that the sector on the whole has to do more when it comes to information security - i.e., implementing controls for protecting the information they are entrusted with by their customers.

No doubt, the security controls from the 'green terminal' days are not a good fit for the Internet-enabled data centers! If we look back at the last 10 years (sorry, I know that's like 1869 in Internet years), the banking sector has made significant progress in instituting appropriate controls. Granted, at times this is due to the regulatory requirements - e.g., Thou shall strengthen authentication on Internet-enabled applications or Thou shall notify your customers when you suspect a breach. Nonetheless, speaking in broad terms - the progress has been made!

But that's not the point of today's discussion. Instead of worrying about the weaknesses, let's focus on some of the strengths of information security programs at financial services organizations....

-----------
Compliance Insight

The Rewards of Risk-Based Compliance

July 3, 2008 - David Schneier

David Schneier
Keeping abreast of what's going on in the regulatory compliance domain is something I need to do. It's sort of the life-blood of my career these days, as I spend most of my time either managing or executing audit and assessment activities predicated upon the various regs. Beyond wanting to be certain that my clients are getting the right work done at the right time, I also want to avoid doing the wrong work at anytime....
-----------
The Agency Insider

FDIC Makes First Move - TARP Fund Monitoring

January 15, 2009 - Linda McGlasson

Linda McGlasson
It was only a question of time before one of the regulators stepped forward to tell its banking institutions to monitor the use of their federal funds. The FDIC this week drew its own line in the sand when it comes to monitoring how the bailout money will be accounted for at its banks....
-----------
The Field Report

Which Comes First - the Banker or the Security Professional?

July 2, 2008 - Tom Field

Tom Field
Say, you need to hire your next CISO. Do you hire a security executive who can learn banking, or a banking executive who can pick up the necessary security skills?...
-----------
The Field Report

The Economy: What One Bank is Doing About it

October 2, 2008 - Tom Field

Tom Field
OK, you've heard enough from me of late about what banking institutions should say or do re: customer confidence and the crazy economic mess we're in.

Well, here's what one bank actually did about it....

-----------
The Field Report

Banking Leaders: We Want to Hear From You re: Confidence

October 16, 2008 - Tom Field

Tom Field
It's time to get real. Banking Confidence Survey

As we tackle this wild economy, which has deflated the market, toppled institutions, written history ... it's time to hear from real people to gain real insights on the events that are reshaping reality for us all.

Consider this my open call, then. Banking leaders: I'd like to speak to you and hear your thoughts - share them with our audience - on how you and your institution are responding to economic events and strengthening your own customers' confidence....

-----------
Compliance Insight

ID Theft Red Flags Compliance Will Impact Examinations for Years to Come

August 19, 2008 - David Schneier

David Schneier
The OTS released their examination procedures this past week for the looming ID Theft Red Flags requirements due to go into effect in 75 days (not that I'm counting). In discussing this both with members of our management team and fellow practitioners, I'm finding that there's a decided split as to what the impact is going to be for the financial institutions needing to comply....
-----------
Compliance Insight

Phishing Season Has Been Extended - Beware!

December 11, 2008 - David Schneier

David Schneier
I've heard that timing is the key to comedy; it may well be true for information security as well.

Late last week I'd sent an email to the BIS (BankInfoSecurity.com) team suggesting that they consider publishing a piece about phishing. I've been getting clobbered with a wide-range of phishing emails over the past few weeks and thought it was noteworthy. It's not that I've been completely immune from receiving these in the past, but I've never had this many pass through my inbox in so short a period of time....

-----------
The Field Report

Springtime - When the Government's Fancy Turns to ... Regulatory Reform?

June 4, 2009 - Tom Field

Tom Field
OK, so healthcare reform is in the headlines today. Can financial services regulatory reform be far behind?...
-----------
Compliance Insight

Regulatory Compliance: It's the Size of the Risk that Matters Most

October 24, 2008 - David Schneier

David Schneier
It's interesting how with everything going on in our industry this year, between the credit crisis, bank mergers, bank closings and emerging regulatory compliance requirements (and on and on and on), that we haven't had time to discuss much else. However, work continues out in the trenches, money is still moving into and out of a dizzying array of accounts and investment products, exams are occurring and (for what I suspect is the vast majority of our industry) life goes on.

So, when I was having a conversation with the Managing Partner of my firm and touching on some of the more noteworthy details from the myriad meetings and activities that occurred during the week, there was one topic that surfaced a few times and it had nothing to do with current events....

-----------
Compliance Insight

Application Security: Exactly What Can Your Users Access?

June 5, 2008 - David Schneier

David Schneier
The OCC recently issued a bulletin (2008-16) in which it targets application security and the need for banking institutions to properly address application security "whether internally developed, vendor-acquired, or contracted for." I for one am relieved....
-----------
The Field Report

A Tale of Two Defendants: Where's the Justice?

January 13, 2009 - Tom Field

Tom Field
An alleged bank robber gets away with nothing, and he's in jail awaiting trial. Not that I'd argue otherwise. Meanwhile, Madoff defrauds investors of billions, quite literally ruins businesses and lives ... and he hasn't even lost access to his premium movie channels....
-----------
Compliance Insight

Four Tips for a Successful (and Secure) 2009

January 8, 2009 - David Schneier

David Schneier
I'm experiencing the New Year's phenomenon. That's what I call the very early part of each year when I struggle writing the correct date on things like checks, forms and the many other documents that require it....
-----------
The Field Report

President's Cybersecurity Report Acknowledges Our Work

July 6, 2009 - Tom Field

Tom Field
To be filed under the category of "One small step, one giant leap ..."

It's just come to my attention that when President Obama revealed his administration's cybersecurity policy at the end of May, the document's introduction featured a prominent reference to an article published on our sites in February of this year....

-----------
Compliance Insight

Vendor Management: Services are Invisible - Until They Don't Work

June 25, 2008 - David Schneier

David Schneier
I started scoping out my next blog entry with PCI in mind (and how it will likely find its way into the community-bank/credit union space in a few years) and was blind-sided by one of my favorite nits to pick recently: the risks presented by poorly managed third-party vendor relationships....
-----------
The Agency Insider

Painting the Town Red with Regulations

February 26, 2009 - Linda McGlasson

Linda McGlasson
Spring time in Washington D.C. used to be marked by the pink and white splashes of color of the cherry trees that line the Potomac and the Tidal basin.

Now I suspect this spring (or possibly even sooner) we're going to see some color of a different kind in D.C. - the color red....

-----------
The Field Report

GM Bankruptcy: What it Means to Banking, Security and Business

June 1, 2009 - Tom Field

Tom Field
So, General Motors files for bankruptcy today. Whoever thought such an event would unfold in our lifetimes - that the U.S. leader in one of the top industries of the 20th century would sputter into the 21st and end up broken down beside the road, like a car whose owner neglected to heed the "Check engine" light?...
-----------
The Agency Insider

A Breach to Remember - What Banks Have in Common with Titanic

July 14, 2008 - Linda McGlasson

Linda McGlasson
Just the other night, I was watching the 1958 classic movie about the sinking of the Titanic. You know, the one that told the straight story before Leonardo DiCaprio and Kate Winslet's steamy romantic version?...
-----------
The Field Report

Beyond Wachovia and WaMu: Time to Get Back to Business

September 29, 2008 - Tom Field

Tom Field
It's all anyone wants to talk about.

In the wake of Washington Mutual's historic failure last week and the Wachovia takeover today, all anyone wants to discuss is the enormity of these events what they mean to the banking industry....

-----------
The Agency Insider

Mr. President, What Are You Going To Do About Our Present State of Cyber Insecurity?

November 5, 2008 - Linda McGlasson

Linda McGlasson
Standing in line to vote yesterday evening at my local middle school, I thought there were a lot of things that the 44th President will have to fix: the economy, the country, the federal government, the out of whack federal budget. Whew! That's a lot, just on a national scale; we're not even talking global problems that need fixing.

But there has been for our industry (financial services and information security in particular) a really big hanging chad question since Bush took office back in 2001....

-----------
Compliance Insight

IndyMac Proves the System Works

July 22, 2008 - David Schneier

David Schneier
One of the tricks of my trade is to see the forest for the trees. Which is to say that with what our practice encounters during fieldwork, what we hear from the regulatory agencies and what we read/hear about in the news, we need to correlate and figure out what it all means. We then need to apply that toward the services we deliver and help our clients keep up with the expectations of examiners. And it never stops -- never!...
-----------
The Field Report

Welcome to Our New Blogs!

June 25, 2008 - Tom Field

Tom Field
Finally, it's your turn to have your say.

Since first joining Information Security Media Group late last summer, one of my primary goals has been to debut a blog for BankInfoSecurity.com and CUinfoSecurity.com.

Today, proudly, I'm able to announce the launch of not just one blog, but five - with more to come in the months ahead - all of which you can subscribe to, ensuring you always stay on top of the latest, hottest conversations....

-----------
The Agency Insider

Foreclosure: Sometimes Risk Management Truly is a Matter of Life or Death

October 8, 2008 - Linda McGlasson

Linda McGlasson
The sad scenario plays out on the news on a regular basis these days. A homeowner facing foreclosure is barricaded inside their home as law enforcement comes to serve the papers. Shots ring out, and officers rush in to find the wounded homeowner.

What happened last Friday with Addie Polk of Akron, Ohio, a 90-year-old homeowner who shot herself when the sheriff's deputies came to serve her papers from a mortgage sold to her by Countrywide, now makes her a symbol of the nation's home mortgage crisis....

-----------
The Agency Insider

Mortgage Fraud: Dirty Little Secrets

July 13, 2009 - Linda McGlasson

Linda McGlasson
The FBI recently announced it had 2400 mortgage fraud investigations ongoing - nearly double from the year before....
-----------
Secure Marketspace

ID Theft Red Flags: The Only Compliance Initiative Your Customers Care About

August 29, 2008 - Mike D'Agostino

Mike D'Agostino
GLBA who? Bank Secrecy what? Insider Threat?...is that something mob-related?

Your customers may not even know your institution is examined for security compliance by the banking regulatory agencies, and so most likely will have never even heard about the ID Theft Red Flags Rule and the impending November 1 compliance date. That being said, the resulting preparedness by financial institutions to adhere to the Red Flags Rule and strengthen their position against identity thieves will hopefully have a resounding effect on said customers.

I'm convinced that if you asked the majority of people how their bank operates -- more specifically, how their bank operates in a "secure" manner -- they would be clueless. I have no caveats saying the general public has no concept of how their private information is kept private, and the steps financial institutions go through to secure their sensitive data. Some would tell me that the general public doesn't have to know, they shouldn't care how it is done, just that it ("security") is getting done and everything is being done to keep their sensitive data private. I think I would agree, however there is one ultimate security concern that consumers have. I'll explain below......

-----------
The Agency Insider

A Tale of Two Breaches

August 24, 2009 - Linda McGlasson

Linda McGlasson
I got a call recently from a friend of mine (let's call her Sally) who is a fraud expert in the financial services industry. She had just heard from her bank, US Bank, asking if she'd been to Orlando recently. She responded no, she hadn't (It is never a good thing when your bank asks if you've been somewhere you haven't been)....
-----------
The Field Report

2008 Election Results: 4 Questions that Impact the Banking Industry

November 5, 2008 - Tom Field

Tom Field
At least one question has been answered.

With the election of Barack Obama as the next U.S. President, we know who our nation's leader will be for the next four years. And with Democrats picking up additional seats as the majority party in both the House and Senate, we have a sense that Obama is going to have some congressional support for the change he's promised.

The real question is: What kind of change are we talking about for the banking industry?...

-----------
The Agency Insider

Passwords: Prying Eyes are All Atwitter

July 17, 2009 - Linda McGlasson

Linda McGlasson
Passwords - they are the bane of information security pros everywhere, and they're back in the headlines again....
-----------
Information Technology Risk Management

Information Security: Are You Prepared to Answer Your Customers' Questions?

June 25, 2008 - Sanjay Kalra

Sanjay Kalra
There is a chance that I will be disowned by many friends in the banking sector after they read what I am about to say below. It's a risk, but it's kind of, sort of, maybe...worth taking it.

So, here it is - a question that has been on my mind since the very first time I saw my bank's name in the press, citing some sketchy details about a system compromise....

-----------
The Field Report

Customer Confidence: Overblown or Understated?

August 18, 2008 - Tom Field

Tom Field
To me, it was a given.

In the wake of recent news of IndyMac and other bank failures, it seemed safe to say that U.S. banking institutions were dealing with a bit of a crisis of confidence. I mean, I didn't imagine that line of anxious customers outside IndyMac, did I?

But then I got a recent note from a community bank CEO, who had a decidedly different perspective....

-----------
Secure Marketspace

Ouch! What If This Was Your Institution?

July 30, 2008 - Mike D'Agostino

Mike D'Agostino

I was in shock, I could not believe such a headline made front page news on Digg.com. I didn't think anyone would believe me; I had to take a screenshot! OK, OK, I may be exaggerating a bit - however I can say that as much as I visit Digg.com, rarely do I see something that has implications to banking and information security make the front page. Perhaps a very topical story on phishing will make it, but it's rare to see a headline about identity theft with a particular bank being named - albeit a very large bank.

What's that you say? What is Digg.com again? As I stated earlier, technically I would say Digg.com is a social media website, falling into the realm of "web 2.0". More specifically, any person can submit any web page (in essence a headline and short description), and then other users can digg (vote for) the web page. The more diggs/votes the web page gets, the closer the listing moves to the front page. On very, very rare occasions, a web page will become so popular it makes it to the front page of Digg.com, and millions of people will see it....

-----------
The Field Report

A Taxing Time for Troubled Banks

April 15, 2009 - Tom Field

Tom Field
OK, so it's April 15, and everyone's mind turns to taxes and filing returns.

Me? I'm thinking of the pace of failed banking institutions we've seen so far this year - and wondering just how much we're taxing the FDIC's insurance fund....

-----------
The Field Report

Disaster Recovery: Don't Be Caught Without Backup

July 20, 2009 - Tom Field

Tom Field
Imagine the scene: You awaken to start your workday, boot up your PC, and suddenly two of your most mission-critical software applications are unavailable....
-----------
The Field Report

Too-Easy Authentication?

August 4, 2008 - Tom Field

Tom Field
At first, I thought my bank was pretty sharp.

About a year ago, when I logged in to do some routine internet banking - check balances, transfer some funds - I was met by a new security page that wanted to better protect my assets....

-----------
The Agency Insider

Risk Management: Your Role Model is on Main Street, not Wall Street

September 30, 2008 - Linda McGlasson

Linda McGlasson
It used to be the mantra - "Bigger is Better" was the one thing that made sense when it came to risk management models. Goldman Sachs and Morgan Stanley's conversion into bank holding companies, allowing them to buy other retail banks and more readily borrow money from the Federal Reserve Bank, means that long-chanted mantra no longer rings true....
-----------
The Field Report

Help Us Help You Get a Handle on Heartland

February 13, 2009 - Tom Field

Tom Field
The numbers are staggering as we try to get a handle on exactly how many institutions, cards and customers have been affected by the Heartland breach.

One single institution's report of the number of cards compromised by the Heartland Payment Systems (HPY) data breach - 10,000....

-----------
Compliance Insight

What It Will Take to Fix Our Economy

December 5, 2008 - David Schneier

David Schneier
I just concluded a strange twenty-four hour period as relates to current events.

It started on Monday evening, when I read an Associated Press story online about how the Bush administration ignored the developing problems in the financial markets....

-----------
Compliance Insight

Crystal Ball: How Will Lending be Regulated a Year from Now?

September 18, 2008 - David Schneier

David Schneier
I was presenting at a credit union conference this week, where the session before mine covered current economic conditions. The timing was perfect in a macabre sort of way, as the 24 hours prior were filled with news about the Merrill Lynch rescue and Lehman Brothers collapse. As part of the Q&A phase, a prediction was made that the subprime debacle would lead to new regulations governing lending. I was surprised that the reaction in the room was mostly that of heads quietly nodding in agreement....
-----------
The Agency Insider

Train Conductor Chuck Pushed Throttle on IndyMac

July 18, 2008 - Linda McGlasson

Linda McGlasson
Some U.S. senators don't just want to make the news, they want to be front and center in the headlines. Charles Schumer, U.S. Senator from New York, is the latest headline maker.

Chuck Schumer's letters in late June to banking agencies inquiring about the stability and strength of IndyMac bank -- prior to the bank's takeover on July 11 by the FDIC - were pointed to as a contributing factor to the bank's failure....

-----------
The Field Report

In the Wake of WaMu: What to Tell Your Customers After the Largest Bank Failure in History

September 26, 2008 - Tom Field

Tom Field
This time the news was so big it couldn't even wait til Friday.

Up to this point, as you know, whenever the FDIC has closed a bank this year, it's waited til after markets have closed for the week - let things settle over the weekend, and then the failed bank can reopen under its new flag on Monday.

But Washington Mutual is different. When a 119-year-old bank fails - the largest such failure in history - it happens on its own schedule, and frankly all the old rules go out the window....

-----------
The Field Report

The New Rules for Banking Leaders: Appearance is Everything

April 9, 2009 - Tom Field

Tom Field
OK, so here's a reaction I never expected.

We've talked a lot about the banking crisis over the past year - the differences between Wall Street and Main Street, and how all financial institutions are impacted in one way or another by fallout from the industry's "3 B's," Bailouts, Bernie and Bonuses....

-----------
The Field Report

From the Inbox: Boo to Citi Bailout

December 2, 2008 - Tom Field

Tom Field
I'm excited about the news we're announcing today re: opening access to all of the articles on our site.

With more people able to view our stories w/o first having to register or log in, that will enable more opportunities for folks to comment on our stories, which then fuels one of my favorite parts of this job: Reader response....

-----------
Compliance Insight

Outing the Shortcomings in Outsourcing

June 10, 2008 - David Schneier

David Schneier
With all due respect to the pugilist fan base still out there, the FDIC used a classic left-right combo this past week aimed squarely at the jaw of the third-party service provider community.

First Sheila C. Bair, the Chairman of the FDIC, touched on emerging guidance regarding third-party service providers in...

-----------
The Agency Insider

When is a Customer Too Much of a Security Risk?

May 14, 2008 - Linda McGlasson

Linda McGlasson
It's not always easy to decide to stop doing business with a person or entity. In fact, it might be a decision that many bankers aren't willing to face. However, when an institution sees a growing amount of fraud losses on a customer's online banking account due to their negligence,...
-----------
Compliance Insight

Cyber Monday Guide: Tips for Safer Shopping

November 28, 2008 - David Schneier

David Schneier
Last night I spent nearly three hours helping out a friend who had called in desperation because the PC was running slow and "weird things" were happening. You might not know it based upon what I do for a living these days, but there was a time and place when I was a genuine "techie" -- a real hands-on PC-guru kind of guy who could take a machine apart, put it back together and reinstall every piece of software from the BIOS on up. Despite my best attempts to leave that in the past, I find it difficult to reject friends and family when they come looking for help. And with the ever improving remote control capabilities available these days and the broadband connectivity, I can't even claim it's inconvenient. So shortly after getting the house settled down, I established a remote session and went to work....
-----------
The Agency Insider

Security Enforcement: The Threat of a Pop Quiz Works Every Time

July 9, 2008 - Linda McGlasson

Linda McGlasson
Remember when you were in school and you hadn't read the chapter like your American history teacher had instructed your class to do on Friday afternoon right before the last bell? It was springtime; who was paying attention to their school work? Who thought there might be a pop quiz on Monday afternoon?

Now, here is a related story for all of you information security professionals out there who think you don't have to "study chapter 14."...

-----------
Secure Marketspace

A Love Affair with the FDIC Press Release

September 26, 2008 - Mike D'Agostino

Mike D'Agostino
I'll admit it, I've become an FDIC press release junkie. The past few weeks, nay, the past year, have given me a steady supply of news to keep my binge going. From bank closings to statements on conservatorships, this affair has been nothing short of spectacular....
-----------
The Field Report

And Now for Another Data Breach

February 24, 2009 - Tom Field

Tom Field
I read the news today, oh, boy.

About another credit card processor that supposedly has been breached, exposing consumers and cards to potential fraud.

This news comes almost a month exactly after Heartland Payment Systems (HPY) went public with news of its data breach sometime in 2008....

-----------
Compliance Insight

Smaller Institutions Make the Community Connection

October 15, 2008 - David Schneier

David Schneier
Like most of our readership I've been so caught up in the drama of our current economic crisis that I've thought of little else. But just the other day I participated in a management discussion in which I was asked what the practice has been hearing in the field. Are our clients consumed or distracted by what's going on, are they making changes to strategy, marketing plans, product offerings, etc? I was caught a little off guard by the question because most of what I had to offer on the subject of our economy was based on my own research and opinions. And so I replied that I needed time to think about it and would have a better answer in a few days. Turns out I had a better answer in a few minutes....
-----------
Compliance Insight

Business Continuity III: Republic Bank Gets it Right

July 16, 2008 - David Schneier

David Schneier
I no sooner finished my most recent post on Business Continuity Planning, and we (BIS) published the transcript of a podcast conducted with Roger Batsel CISO Interviews: Roger Batsel, Republic Bank, on Business Continuity/Disaster Recovery), SVP, Managing Director of Information Systems at Republic Bank, Louisville, KY about.... Business Continuity Planning.

It was a great read and illuminated many of the very same points I typically cover when working with clients on BCP....

-----------
The Agency Insider

Security Budget Battle: Arm Yourself with These Questions

April 2, 2009 - Linda McGlasson

Linda McGlasson
It is an age old question: Who really is in charge of security? A look back into history, one can see the origination of the word "password" and how it came from the guard at the gate of a city or castle, who upon approached, would say "Halt, who goes there?"...
-----------
The Agency Insider

Smart Bankers Avoid Mortgage Fraud

September 12, 2008 - Linda McGlasson

Linda McGlasson
I can't say enough about the mud slinging and finger pointing being done during the continuing mortgage crisis. It is getting ugly out there. Even the government-sponsored enterprises Fannie Mae and Freddie Mac are now under the watchful conservatorship eye of the federal regulators, as the mortgage foreclosures top 1.2 million this year. Clearly, there is another growing cancer in the industry - mortgage fraud....
-----------
The Agency Insider

Hunting Season Opens on Cyber Criminals

October 22, 2008 - Linda McGlasson

Linda McGlasson
I just have to chuckle sometimes when I read headlines like the one that appeared recently - 'Dark Market' Takedown: Exclusive Cyber Club for Crooks Exposed.

It seems that the FBI is getting pretty clever at "blending" into the cyber criminal world. A tip of the hat goes to Shawn Henry, the FBI Cyber Division Assistant Director, and his team for turning the tables on this group of cyber criminals....

-----------
The Agency Insider

Do You Know Where Your Backup Tape is Today?

May 28, 2008 - Linda McGlasson

Linda McGlasson
The public service announcement used to appear on television screens every night, it seemed, when I was growing up. The announcer would speak in a deep voice, "IT'S 10 p.m., do YOU know where YOUR CHILDREN ARE?" Looking around, my parents would sigh a deep breath of relief, knowing that we children were either in our beds already, or fast asleep on the couch next to them....
-----------
The Agency Insider

Presidential Politics: 'Passwordgate' More Distressing Than Troopergate

September 19, 2008 - Linda McGlasson

Linda McGlasson
I have issues with weak passwords and easy to guess answers for challenge questions on password resets. This was Sarah Palin's (Republican vice presidential candidate)apparent problem with her personal Yahoo! email account. It only took a Google search and some thought on a young hacker's part to find out the challenge question to her email account password reset. Now I'm also adding that Palin isn't the only executive who is known to use such simple passwords or easy to find answers to challenge questions....
-----------
The Agency Insider

Madoff Got the Goldmine, We Got The Shaft

December 19, 2008 - Linda McGlasson

Linda McGlasson
Say the words $50 billion. Sort of rolls off your tongue. I'd be really upset if my family, firm or investment company had invested money with Bernard Madoff's alleged Ponzi scheme. It is shaping up to be one of the biggest investment frauds ever....
-----------
The Agency Insider

Foreclosure Rescue Scams: Educate Your Customers

June 8, 2009 - Linda McGlasson

Linda McGlasson
Driving home every day along the New Jersey highways, I often see the signs offering "Save Your Home from Foreclosure" with a toll free number to call for more information.

It is the sign of the times. Foreclosure rescue scams are on the rise, along with mortgage fraud....

-----------
Compliance Insight

It's Easier to Comply Than Explain Why You Haven't

July 31, 2008 - David Schneier

David Schneier
During my formative years, I developed a tendency to spend considerable time trying to figure out ways to circumvent the myriad systems teenagers and young adults are confronted with. So much of what was expected of me just didn't make sense, and I didn't want to simply go-along-to-get-along. My father would often observe my actions and comment that if I'd spent the time doing what I was supposed to, it would likely take less time than I was spending on my avoidance strategies....
-----------
The Agency Insider

Top Internet Scams for You - and Your Customers - to Avoid

April 13, 2009 - Linda McGlasson

Linda McGlasson
Among the layoffs, companies downsizing, slashing budgets and falling stock prices, there is one area of the economy that appears to be flourishing - crime via the Internet.

The Internet Crime Compliant Center (IC3) says that reports of Internet-based crime jumped 33 percent in 2008, according to the group that monitors web-based fraud....

-----------
The Field Report

The Market is Vulnerable - and so is Your Institution

September 30, 2008 - Tom Field

Tom Field
And so the hits just keep on coming.

Just when you think you've seen the biggest bank failure in modern times in IndyMac, WaMu comes along and tops them all.

Just when you think you've seen the blackest of Black Mondays in your lifetime, a darker day dawns, and the stock market reels from a record plunge of 777 points....

-----------
Compliance Insight

Sheila Bair is My Choice to be Treasury Secretary

November 18, 2008 - David Schneier

David Schneier
I was watching CNN this morning, and one of the stories they covered was that of President-elect Obama's selecting his cabinet. In a poll taken regarding this topic, 41% of respondents identified the Secretary of the Treasury as the most important position to be filled; Secretary of State was a distant second at 25%. Think about that for a moment ...

It really shouldn't come as any great surprise, as polls like this one often reflect what's occupying everyone's mind, and these days it's all about the economy....

-----------
Information Technology Risk Management

Assessing Application Security Risk Assessment

May 29, 2008 - Sanjay Kalra

Sanjay Kalra
Earlier this month, the Comptroller of the Currency issued a bulletin (OCC 2008-16) outlining the importance of application security in an institution's Information Security program. For the folks who have been in the banking industry and are responsible for information security at their institutions, there was nothing new in this bulletin....
-----------
The Field Report

Let's Focus on What We Can Control: Security

November 25, 2008 - Tom Field

Tom Field
There's so much we can't control today. The global economy, the fickle stock market, rampant layoffs, decisions being made in Washington, D.C. All these elements affect us, but there's little to nothing we can do to influence them.

Helpless feeling, no?

That's why this week, in advance of the Thanksgiving holiday, we're prepared a news package focusing on some things you can control - what I'm calling The 5 Essentials of Banking Security in Tough Times....

-----------
The Field Report

Bernard Madoff: Time to Fit the Crime? Hardly

March 12, 2009 - Tom Field

Tom Field
So, today's the day.

When Bernard Madoff appears in court this morning, presumably to plead guilty to at least a portion of the fraud he committed in his $50 billion Ponzi scheme, the world will be watching....

-----------
The Agency Insider

The Twelve Days of Breachmas

December 24, 2008 - Linda McGlasson

Linda McGlasson
Sitting down at your desk wondering how you're going to get your info sec budget through the next finance meeting unscathed and still manage to meet all of your department's regulatory requirements? Well, I can assure you, you're not alone....
-----------
The Field Report

Who'll Bail out the Bailout?

November 12, 2008 - Tom Field

Tom Field
OK, so first came the subprime mortgage debacle, and it was bad.

Then came the global credit crunch, and it was worse. Reading the economic tea leaves, the feds in October swept in with a $700 billion economic relief package designed to bail out some of the nation's troubled financial institutions. So, then we saw:...

-----------
Information Technology Risk Management

Perfect Storm or Perfect Opportunity?

July 21, 2008 - Sanjay Kalra

Sanjay Kalra
So, is there anyone who hasn't heard about the lines outside IndyMac's offices this past week?

Since the previous weekend, the discussions over the barbecues and around the water-coolers have ranged from "How come we didn't see it coming?" to "Who's next?" and "How big is the FDIC's chest to take on these hits?" I don't know the answers to most of these ... all right, let me be honest - I don't know the answers to ANY of these questions....

-----------
The Field Report

Banking Information Security Today - Take Our Annual Survey

March 27, 2009 - Tom Field

Tom Field
Angry about the Heartland data breach?

Anxious because you have an upcoming regulatory exam?

Frustrated by the effects of the global recession, and wondering when the heck we're going to climb out of it?...

-----------
Compliance Insight

Business Continuity/Disaster Recovery Part I: The Aftermath of Natural Disaster

June 27, 2008 - David Schneier

David Schneier
Last fall I was conducting a risk assessment, and one of the people I interviewed shared his experience of having survived Hurricane Katrina in a previous job. His company's infrastructure had been located on the third floor of the building they occupied, and so as a result, when the water levels started rising, they avoided a complete loss. He regaled me with his tales of being lowered from a helicopter onto the roof, grabbing what amounted to the company's network infrastructure and having to rebuild at a remote location about 30 miles outside of the flood zone....
-----------
Compliance Insight

PCI Compliance: Time for Banking Institutions to Pay Attention

June 25, 2008 - David Schneier

David Schneier
Regulatory compliance rules my work day. It's the driving force behind my practice and the primary reason our clients become our clients; we're very good at understanding what needs to be done and then helping make sure that it does. So it's always an interesting conundrum when I'm asked by a client what PCI is, and do they need to worry about it.

Well, PCI (aka, the Payment Card Industry Data Security Standard) equals compliance, compliance equals opportunity, opportunity equals revenue, and revenue is good -- particularly when working for a professional services firm....