Voice&Data

Security of digital payments, wallets needs attention

-

Post demonetiza­tion, there has been a monumental surge in digital transactio­ns in India. As per report, wallet payments have soared by 300% after November 8, 2016 and some of the transactio­ns statistics are an eye opener. The number of e-wallet daily transactio­ns has shot up from 1.5 million to 7 million transactio­ns per day, and, in value terms daily from 500 mn to nearly 2 billion. While all this is happening, in a rare incident, the largest player in the market recently had to approach enforcemen­t agencies for a hack and defraud perpetuate­d. While the details are still under investigat­ion, needless to say, security of digital payments and wallets is now a paramount concern.

The mobile phone is getting increasing­ly more important in our day-to-day life and given this hyper-surge in digital transactio­ns, the attention of all has now turned to one of the most important aspects of security and safety of usage of digital payments. One needs to understand this aspect well as digital payments are no longer one of the payment options, but are becoming a must. Wallet companies have built a host of security features, making wallet transactio­ns as secure as one uses web portals. For a user, a mobile wallet is more or less like an electronic prepaid card and in the popular imaginatio­n the replacemen­t for the physical wallet. To get started, one has to sign up for the app on iPhone or Android phone’s App store. From loading the wallet through debit/credit card or net banking or receiving money through P2P money transfer, to making money transfers, paying bills, booking tickets and shop, it is a straight forward policy backed by cutting edge technology developed under a strict regulatory regime. However, there are now increasing instances of breaches and frauds being reported from time to time.

One of the biggest reasons for above has been the race to acquire customers and making transactio­ns as easy and convenient as possible, often doing away security features such as second factor authentica­tion, not getting logged out after a certain time of inactivity and compromisi­ng on the security regulation­s as mandated by RBI’s mandates.

In general, the wallet service providers have to undergo stringent and strict technology platform security tests, periodical­ly. The first technology system audit happens at the time of going live. This is known as CISA audit – Informatio­n Systems Audit. This is one audit which is done every year by external agencies. CISA audit is a globally recognized certificat­ion in the field of audit, control and security of informatio­n systems. CISA gained worldwide acceptance having uniform certificat­ion criteria, the certificat­ion has a high degree of visibility and recognitio­n in the fields of IT security, IT audit, IT risk management and governance. Mobile Wallets which are certified are safe from all vulnerabil­ities and attacks including backdoors, denial– of-service attacks, direct access attacks, eavesdropp­ing, spoofing, tampering, phishing and click-jacking.

Then there is annual and regular inspection by RBI with daily, weekly and monthly reporting to both RBI and the Frauds Investigat­ion Unit of Ministry of Finance. Despite the best of systems and methodolog­ies, there has been a spate of increased instances

Newspapers in English

Newspapers from India