Keep security simple.
That's what online members told Technology Credit Union here, and the $1.2-billion credit union obliged when it launched website authentication at its Internet banking site in November.
"Members provided a lot of positive feedback and suggestions to make the implementation smoother," said Victor Smilgys, assistant vice president of e-commerce at Tech CU.
As a result, members aren't overwhelmed by options when they enroll online for the authentication platform, according to Smilgys.
Tech CU surveyed online members 10 days before deploying its customized version of the Site-to-User Authentication Module. Site-to-User, provided by Bedford, Mass.-based RSA Security, Inc., is designed to assure members that they are visiting a legitimate credit union site.
Although a few members asked if they could write their own challenge questions or upload their own personal image as part of the validation process, Tech CU said "no," deciding to go bare-bones, Smilgys continued.
"We want enrollment to be as simple and as quick as possible," he explained. "So members choose from our challenge questions instead of creating their own questions, and then we select a random image for each member."
After enrollment, members may change a personal image by choosing a new one from the credit union's image library, but they are not permitted to upload their own images, Smilgys said.
Tech CU's diverse membership also told the CU to simplify by providing challenge questions that aren't restricted to topics about the United States.
"Some of our members are from foreign countries, so we made the challenge questions direct and universal," Smilgys said.
For example, Tech CU removed the question "What was the name of the president of the United States the year you started college?" because one member deemed it too restrictive.
A simple authentication solution considers how the member will interact in the long-run, said Chris Young, general manager, Consumer Solutions Division, RSA Security.
"The key to making the Site-to-User solution easy-to-use over time is to ensure that, when members are asked to provide additional security information, they understand the purpose of that request," said Young.
"This produces a much more positive reaction to the solution, which in turn promotes better usage and so helps to make the security itself more effective," he continued.
The Silicon Valley-based credit union simplified the instructions for enrolling in the authentication platform as well, added Kathy Litman, vice president, marketing, at Tech CU.
"We cut down on the terminology we used in the instructions and made them clear and concise," she said.
Non-technical terminology is "easier to understand and is reassuring," agreed Young.
"We also enlarged and boldfaced the font for the instructions due to member requests," Litman added.
In addition, Tech CU added a confirmation page to conclude the enrollment process and remind members to remember their new passwords.
"The contact center was getting a lot of calls from members who had forgotten their new password after enrolling," Litman said.
Members also wanted to reset account passwords online, Smilgys said.
"Initially, for security purposes, we had members call our contact center or go to the branch to reset passwords," Smilgys explained. "But we later added that functionality online due to member demand."
The survey of more than 1,000 members came on the heels of an online tutorial showing them how to enroll in the authentication platform, and a test platform that was released to a portion of the membership.
Nearly 40% of the CU's 72,000 members banks online every month, Smilgys said.
More than one thousand credit unions use RSA Security through direct and indirect partnerships.
CUJ Resources
For info on this story:
* Technology CU www.techcu.com
* RSA Security www.rsasecurity.com











