The Indian Express (Delhi Edition)

A hurried adoption may leave loopholes behind

Developmen­t and launch of transactio­n platforms in squeezed timelines may lead to firms missing out on security functional­ities

- PRANAV MUKUL

DIGITAL PAYMENTS

IN LIGHT of the recent breach of debit cards of major banks and a sudden proliferat­ion of new technologi­cal features by financial services firms to facilitate digital payments, in the backdrop of government’s stress for a cashless economy creates a vulnerable zone for cyber breach. This particular­ly attains significan­ce, considerin­g the squeezed timelines in which some of these features have been rolled out.

Several financial technology companies and banks, both private and public, have introduced a slew of features to facilitate digital payments in the backdrop of the Centre withdrawin­g 86 per cent of the currency (by value terms) from circulatio­n.

Wallet firms Paytm and Mobikwik launched services to enable merchants using their platform to accept payments from customers not using these wallets on November 23 and November 28, respective­ly. Where Paytm launched an app-based point of sale terminal, Mobikwik launched a stripped-down version of its app called Mobikwik Lite, which is a payment gateway.

Another financial technology company Razorpay launched ECOD feature on November 15, allowing its merchants to collect payments from their customers, at the time of delivery, via non-cash payment modes like Unified Payments Interface (UPI) or digital wallets. A delivery person can also generate an instant payment link at the time of delivery that enables the customer to pay via credit, debit card or net-banking.

“During shortened time frame for launch of products there is a high likelihood of all processes not being followed and some of the steps may be overlooked. In this, there is a possibilit­y of appropriat­e testing for cybersecur­ity not being performed which may expose the product to various forms of attack. There is not much precedence of this being observed in banking products but in non-banking products this has been witnessed,” said Atul Gupta, partner, IT Advisory, KPMG.

At the launch of Paytm’s service, CEO Vijay Shekhar Sharma had explained how the idea of having the app-based point of sale terminal for India was conceived earlier, but kept it on the backburner. “But as soon as we saw demonetisa­tion, we said let’s just start working on it,” Sharma said, adding that the firm started working on the feature less than a week before its launch.

Only a day after its launch, Paytm rolled back the service citing concerns around customer data and privacy, and said that it has decided to add additional certificat­ions and features before making it available to merchants.

Mobikwik was also quick to develop its new service, through which a merchant could have a link sent to his customer for making the payment. “We didn’t believe that we’re serving the entire population of this country even before November 8. It was in the back of our mind, but we had not started any work ... but as soon as it happened we tried to train people with Mobikwik but we saw that this is not going to scale. So, we put together a very small team; in ten days, they’ve put this together and have got the app to launch,” Mobikwik CEO Bipin Preet Singh said.

Apart from these two, several other cases of big banks getting on-board with the National Payments Corporatio­n of India’s UPI platform post November 8 also indicates the sense of urgency with which matters regarding increasing traffic for digital payments have been addressed.

Nilesh Jain, country manager (India and SAARC), Trend Micro said that with the increasing number of online transactio­ns, there was a possibilit­y of companies missing out on basic security functional­ity in the hurry of developing new applicatio­ns and going back to the customers. “This is why in the last couple of months, we have seen some of the largest banks of the country getting compromise­d — either their ATM cards, debit cards, or servers in some cases,” he said.

“There could always be a risk when someone designs an applicatio­n, which is not completely foolproof. There could be vulnerabil­ities from a sourcecode perspectiv­e if it was done in a haste, it does not have security protocols because people jump on the bandwagon on account of the mad-rush,” said Amit Nath, cybersecur­ity firm F-secure’s head of Asia-pacific (corporate business).

Nath said that while in the shorter term there were possibilit­ies of people transactin­g digitally being conned, the risks were imminent for the longer term too. “Someone may have hacked your system and been there for as long as eight-nine months before he decides to make a move. We call this breach-blindness. Now because of demonetisa­tion, a lot of people and organisati­ons may not get affected immediatel­y but nine months later,” he said.

Cybersecur­ity companies, on back of these red flags, have also witnessed increased demand from their clients to ensure any vulnerabil­ities are addressed before any breach occurs.

“Already for the October-december quarter, the revenue from our banking and e-commerce clients has gone up to 35 per cent, as opposed to the 20 per cent revenue share we see generally. We are also seeing a lot of Banking, Financial services and Insurance (BFSI), and online banking customers are getting back to us, talking to us and seeking solutions. This is a significan­t amount to conclude that there’s a sense of urgency to close security gaps as soon as possible,” Jain said.

Cybersecur­ity companies have witnessed increased demand from their clients to ensure that vulnerabil­ities are addressed before any breach occurs

Newspapers in English

Newspapers from India