Philippine Daily Inquirer

BANKS URGED TO BEEF UP SYSTEMS TO COMBAT CYBER ATTACKS

- —BENO. DEVERA

Citing rising concerns on phishing and cyber attacks targeting bank customers and personnel, the Bangko Sentral ng Pilipinas ordered financial institutio­ns to beef up their defenses. Phishing is the attempt to get sensitive informatio­n such as usernames, passwords and credit card details by pretending to be a trustworth­y entity in an electronic communicat­ion like e-mail.

“In response to the growing concerns on cyber attacks involving fraudulent e-mails and websites aimed at customers and employees of financial institutio­ns, BSP-supervised financial institutio­ns are advised to sustain resilience efforts and continue to perform rigorous risk assessment­s of their current technology environmen­t,” Deputy Governor Nestor Espenilla Jr. said in Memorandum No. M-2017-017 issued onMay10.

In addition to implementi­ng risk-based authentica­tion methods for customer accounts, it said BSPsupervi­sed financial institutio­ns should also ensure adequate access control measures were in place for systems that support the provision of electronic products and services such as authentica­tion servers, applicatio­n servers, domain name system (DNS), including domain registry services, regardless of whether these were managed internally or by a third-party service provider. For outsourced systems, it said BSP-supervised financial institutio­ns, as part of their outsourcin­g risk management framework, should have a sufficient level of assurance that the service provider was maintainin­g robust security controls.

Also, stronger authentica­tion methods other than the use of passwords should be adopted for high-risk/sensitive systems that are managed by privileged users such as network and system administra­tors,” Espenilla added.

BSP-supervised financial institutio­ns should also be mindful of domain hijacking, whereby attackers modify a financial institutio­n’s domain name records to redirect users to unauthoriz­ed websites. In such cases, additional security measures such as registry lock feature for top-level domain should be adopted,” according to Espenilla, referring to multi-factor authentica­tion (MFA).

Newspapers in English

Newspapers from Philippines