READER QUESTION No. 1
My IT person has said 2007 will be the year that true banking by cell phone is going to really take off. But I'm skeptical. Is this "the year", and if so, where do we need to be investing to leverage this?
Kishore Bayyapureddy, SVP & General Manager of ePayments
Fidelity National Information Services, Jacksonville, Fla.
We believe that this is the year mobile banking will begin to take off. We also believe you should focus your investment on Internet Banking and Bill Pay providers with mobile banking in their product roadmaps. Ideally, any mobile banking solution should be tightly integrated with Internet Banking and Bill Pay, which need to be tightly integrated with your host system. Users should feel confident that the information they get on their phone is secure and accurate at all times.
David McConney, EVP/General Manager, Credit Union Core Systems, Harland Financial Solutions, Atlanta
Many vendors are experimenting with various cell phone technologies to perform banking transactions and pay bills. SMS, or short message service, also known as text messaging; WAP, or wireless application protocol, typically used by wireless Web browsers; and proprietary downloadable applications, are among the most common technologies currently being explored. 2007 is likely the year that many companies will begin to introduce various applications within these technologies for consumers that are tech savvy and "on the go." If your credit union is considering any of these technologies, be sure to fully evaluate what is available on the market and what may be coming in the near future. When selecting the technology that addresses the features, functionality and security that match your credit unions' requirements, be sure to consider member demographics and their potential adoption of the application, your return on investment, taking into consideration staffing, hardware, software, additional security, etc., and the company and its stability in this an other cutting edge technologies.
It is likely that mobile banking will explode in the near future the way in which Internet banking did in the mid-90s.
Chris Barber, SVP/CIO, Western Corporate FCU
San Dimas, Calif.
My first reaction is "I already bank over the phone via my bank's 800 numbers and voice activation system. It's convenient and in widespread use." However, if the reference is to banking via blackberry or handheld, I don't see a strong demand for that in the U.S. anytime soon. PDA devices have too small of a screen for most people to use for things like banking. The websites would have to be specially crafted to render content for the PDA and then the user would have to trust both the device and the wireless link, which is a stretch. Many people still can't be convinced to bank via the web. Going to a very tiny screen over a wireless network is going to be a big leap of faith.
Terry Treadwell, director of market strategies,
Summit Information Systems, Corvallis, Ore.
This year is definitely the time to begin your mobile banking research processes-with more than 200 million U.S. wireless subscribers, wireless has surpassed land line use. It is not a question of "if" it should be considered but rather "when" to start deployment.
Unlike the early failed attempts at wireless banking-with low adoption, slow networks and clunky user interfaces-today's phones are more functional and networks more proficient.
Add to that the fact that more youthful consumers are adopting online banking and the recipe for success is there.
How quickly and what functionality you introduce depends upon the makeup and demand from your existing membership base. At a minimum you could start with easy to implement and relatively inexpensive eAlert, instant messaging, and text messaging functionality, with messages sent to a wireless device as many Summit clients are already doing. Also consider how your current web pages can be more acceptably displayed through these devices with perhaps a separate, simplified web page for wireless users.
Once you have gauged your memberships' acceptance of mobile technology, you can plan to incorporate some of the more complex data presentation types like balance inquiries, transfers, history, and bill payment down the road.
READER QUESTION No. 2
We've got our multifactor authentication solution in place, but have heard it remains vulnerable. Is this true and should we be exploring additional solutions?
John Edwards, President, XP Systems, Moorpark, Calif.
Security is a continuous process. For it to be successful, it must be proactive and evolving. Multi-factor authentication is not a new concept, nor does it represent a fundamental long-term solution to securing electronic delivery channels.
The focus right now in securing electronic channels is for financial institutions to implement measures and best practices that have been available for many years. For example, encryption of all data in transit from remote delivery points is a measure that can be implemented using standard off the shelf technology. What we are currently seeing is simply increased awareness and sensitivity to the most common threats and broader adoption of basic means of protection against these common threats.
To provide a more comprehensive means of securing these channels may require new solutions, technology, and a change in behavior-such as replacement of magnetic stripe based cards with smart (chip-based) cards or broader acceptance of biometric based methods of authentication. This continuous awareness of the latest security threats is the key to keeping your system, and your members, safe.
Terry Treadwell, Summit Information Systems
The key is finding your credit union's happy medium between security, user friendliness and expense. The misconception is to believe that one single security solution such as multi-factor authentication will cover all possible online fraud scenarios. Hopefully, you have conducted a thorough security risk assessment and developed security policies and procedures to control these risks while clarifying acceptable levels of risk you are willing to assume. The success of any particular security strategy depends on your overall corporate policies, procedures, training and awareness. Security requires a comprehensive approach that not only correctly identifies members and safeguards their transactions, but also incorporates the necessary internal business process controls as well. For Summit, we work closely with our clients to understand this and provide the most appropriate solutions.
The FFIEC regulations issued in 2005 mandated that "financial institutions should implement multi-factor authentication, layered security, or other controls reasonably calculated to mitigate those risks." Alternative authentication solutions such as tokens and biometric identification are possibilities, although expensive. Several large banks and online brokers provide a layered approach including tokens in addition to multi-factor authentication. In the end, your decision requires a comprehensive analysis of what technology will best suite your needs given your risk levels.
Chris Barber, WesCorp
The answer to this question depends on the solution you put in place and your tolerance for risk. Authentication systems perform one primary function: to properly verify the identity of the requestor. There are different types of systems that provide different levels of authentication. Generally, this means something you know (e.g., a password), something you have (e.g., a physical token), or something you are (e.g., biometric fingerprint.) Are those basic forms of authentication open to attack? Sure, passwords can be stolen, tokens can be stolen, and fingerprints can be lifted - visit YouTube and search for "mythbusters biometric" for proof.
This is why it is important to track more information and tie it to a risk assessment. For example: perhaps the person has the right password or even the right token, but are they logging in from China? If so you might want to prompt them for even more information since that falls outside of their "normal" usage pattern. You are now making more intelligent authorization decisions (what the user can access) based on both authentication and risk. Perhaps you only allow read-only access if they don't pass all of your validation checks. That's up to each institution to decide the best fit and how much risk they want to take.
David McConney, Harland Financial Solutions
Keeping up with security measures and technologies is a constant game of cat and mouse. Ensuring your credit union is as unattractive as possible to fraudsters and preventing the mistakes of well-intentioned staff, while also looking at ways to ensure security measures are in place and kept current, requires continual diligence.
A good place to begin is to leverage the often overlooked existing security features already available within many applications. Educating members and staff about social engineering, including "phishing" and "pharming" and educating members about security precautions when online or when using checks and card products can help reduce or even prevent an increase in fraudulent activity.
Credit unions can install an incident reporting and tracking program to help discover and address specific vulnerabilities. Since no security solution today is bullet proof; and the best solutions only make it a little harder for the fraudsters to infiltrate your credit union and target your members, education is the key. It is extremely important that online security measures be heavily marketed to both staff and members.
Kishore Bayyapureddy, Fidelity National Information Services
Without knowing the specifics of your current solution, we will focus our answer on the criteria that we used to select our multi-factor authentication solution to eliminate vulnerability. The following is part of the scorecard we used in the selection of our current solution:
MUST HAVE
2nd Factor of Authentication Something the user has or is
Two-Way Authentication Presents a shared secret
Supplemental Authentication Use of challenge questions
Out-of-Brand Authentication Confirmation via phone or e-mail
IP Address & Geo-Location Verifies IP address and location
Backend Fraud Prevention Suspicious transaction detection
Cost Effective Capital, resources and recurring
OPTIONAL
One-Time Password Cards Non-hardware-based tokens
Client-Side Certificates Secure communication both ways
Secure Password Client ATM-like secure password interface
AVOID
User-Installed Software Requires software to be installed
Hardware Tokens Requires physical device
Additionally, we looked for:
* Easy to use (designed for consumer market); automated self-enrollment; low false-positives/false-negatives; automated single use/new computer handling; let customers use it anywhere; be easily managed by CU/bank' addresses known and evolving threats, and low risk.











