Daily News logo Newsletter logo   Search News    

Best Practices for Online Banking Security

  Share This Story

There are two common misconceptions about online banking security which are holding financial institutions back from offering their customers the best services possible. This is according to Hilding Arrehed, Director Worldwide Professional Services at ActivIdentity®, and its parent company HID Global, trusted leader in solutions for the delivery of secure identity.

Arrehed comments: "Having had the pleasure to work with banks around the world to help them design and implement security solutions for their online banking systems, my colleagues and I have learned a few things about what to do to deliver secure yet user friendly solutions."

"For starters, as long as it makes customers feel secure and enables them to access more (preferably all) banking services online, it's okay to trade off a small amount of convenience in the user login experience."

Arrehed provides suggestions on how to use advanced security technologies of today to build an online banking system that offers strong security, whilst maintaining high convenience and access to as many services as you want to make available:

  1. At the time of log in, let customers choose which authentication method to use based on what they intend to use the service for. 

  2. Give customers the option to configure their own security levels.

  3. Let customers decide which type of device to connect from. 

  4. Integrate the online banking system and its security with your other operations to give customers a consistent sense of your approach to security. 

  5. Let customers use the same security credential as they use for online banking when they access other bank services. 

  6. Give customers good support the way they want it. Through FAQ on the website, online chat, telephone, email, face to face or by letter.

One typical misconception in online banking is that security begins and ends with securely authenticating account access.

"That's not the way I have learnt to look at it. The real risk for online banking customers is that someone steals money from their accounts. It therefore makes a lot of sense to focus more on ways to secure the actual money transfers than just the access to the service," continues Arrehed.

Based on his experience with successful online banks, Arrehed says banks have done just that and he shares a few recommendations they gave:

  1. Make it as easy as possible. Only ask for transaction signing when money is transferred to accounts other than the customers' own accounts and allow transactions to be batched.

  2. Use a secure but risk-appropriate technology to carry out the transaction signing. Smart cards, tokens, soft tokens and SMS text messages are all good ways to provide electronic transaction signing. 

  3. Make sure that it is clear to the user what is being electronically signed. This is to prevent the risk of man-in-the-middle attacks which is particularly important now given the recent attacks on trusted Certificate Authority providers and hacks of the session security protocol mechanisms (SSL/TLS) used by our web browsers. 

  4. Store the transaction data including the customer's electronic signature in a secure tamper-evident audit database for archiving purposes. It can be very useful to be able to prove that a money transfer was correctly carried out and approved many years after it happened.

Arrehed concludes: "Every bank obviously has its own advantages, challenges and security needs. Your security solution, including authentication and money transfer approval mechanisms, therefore needs to be specifically defined to meet those needs."

NOTES TO EDITORS           

About ActivIdentity
ActivIdentity, a global leader in identity assurance, enables customers to prove and establish trust in a person's identity when accessing resources on the network. The business's strong authentication and smart card solutions are relied upon by more agencies, including the U.S. Department of Defense, than any other provider, and has issued more than 100 million credentials to enterprise, government and commerce customers. ActivIdentity is headquartered in Silicon Valley, California. ActivIdentity is part of HID Global, an ASSA ABLOY Group brand. For more information, visit www.actividentity.com.

# # #

ActivIdentity is a registered trademark in the United States and/or other countries. All other trademarks are the property of their respective owners in the United States and/or other countries.

ActivIdentity Media Contact:
Mital Goel
Spreckley Partners Ltd.
T +44 (0) 207.388.9988
ActivIdentity@spreckley.co.uk



 
Support Wikipedia

NeswBlaze top writers

Find more stories recommended by Stumbleupon.

newsletter logo

What's Hot?
1 .Breaking News: Cannes Film Festival Awards 2012 - 71
2 .Supermodel Bar Refaeli Adorns the Cover of the 2009 Sports Illustrated Swimsuit Issue on Newsstands Today! - 69
3 .Waterless 'Air Cooler PLUS' Beats Summer's Heat Without Making Your Home Muggy - 37
4 .Round up of iPhone 5 Rumors From the Armenante Apple News Blog - 30
5 .Is It Coincidental We Have Another Missing Petite Blonde Coed, Mickey Shunick? - 26
6 .Calling All Military Supporters: a Supporter Needs Your Vote to Win a Grant - 29
7 .These 10 Comfortable Walking Shoes Are a Step in the Right Direction - 23
8 .Give a Great Valedictorian Speech - Joey Asher - 19
9 .Ethiopia Celebrates Downfall of the Derg Day - 22
10 .Very Young Girls Movie Review: Sex, Class and Ho Daddies - 22
Updated: 11:15 PDT     2834

NewsBlaze Editors

editors

NewsBlaze Writers

news writer images

Writers Wanted

Help NewsBlaze provide daily news, including top stories, Home and Garden, Technology, The Environment and more. NewsBlaze Writer

Follow NewsBlaze

NewsBlaze Social Media Logos NewsBlaze Facebook NewsBlaze LinkedIn NewsBlaze Twitter NewsBlaze YouTube NewsBlaze MySpace NewsBlaze Fan Page NewsBlaze StumbleUpon NewsBlaze Political Cartoons NewsBlaze Editorial Cartoons
NewsBlaze 
Copyright © 2004-2012 NewsBlaze LLC
Use of this website is subject to our Terms of Service and Privacy Policy  | DMCA Notice |         Press Room