Latest Comments
"Discontinuing the issuance of MD5 certs is a good first step, but the real problem is that the ..."
by Scott | Jan 6, 2009 3:13 PM
 
"My facebook profile has been hacked through one of these sites and they have changed my password ..."
by Ryan geen | Jan 3, 2009 3:51 PM
 
"http://impresser.com.au/category/security/ We need more websites like this. Security is an ..."
by Andrew Galdes | Dec 27, 2008 3:46 PM
 
"Um... what product were you really using???? documentation is supplied in printed form (aka a ..."
by Glen | Dec 23, 2008 12:11 PM
 
"maybe that is just why it is best to outsource your intranet solution to experts companies like ..."
by Pankaj | Dec 23, 2008 7:09 AM

No time for declarations of victory over compliance deadlines

  • Email a Friend
  • Print Page
No time for declarations of victory over compliance deadlines
By Arthur W.
Dec 5, 2006 9:00 AM
Tags: No | time | for | declarations | of | victory | over | compliance | deadlines
This is not Y2K and there are no permanent one-time fixes. Fraud is not going away: it morphs, and it will exist as long as customers have money that can be stolen with little risk of apprehension and prosecution.

Today's fraudsters have created an integrated supply chain of data thieves, data salesmen and account hijackers. They understand the strengths and weaknesses of risk management, have adopted continuous process improvement as their own perverse best practice and don't go back to legitimate jobs when they run up against strengthened security.

In light of this reality, proper anti-fraud management entails an actively managed mix of customer education, access restrictions, background monitoring and rapid response in order to extinguish threats and provide redress to actual victims. Security professionals know that this challenge is not met and disposed of by the purchase of a single point solution.

It demands a careful situational analysis, ongoing assessment of new risks, selection of the right tools and balance across a range of factors including customer experience, total cost of ownership and loss risk management.

The organisational structure itself must also adapt to take on a problem that is uniquely complex and disbursed. Internally, the various departments responsible for maintaining vigilance need to coordinate more adequately and work collectively to sell the program after compliance has been achieved or in the face of low loss levels.

In addition, better data sharing and reporting across channels will greatly enhance overall detection and prevention effectiveness. An ever-growing array of sophisticated tools is being used to "add locks to the front door," but institutions would do well to expand the security paradigm to include detecting and stopping the fraudsters when they do manage to get in.

Externally, cross-industry communication is still in its infancy, although we are encouraged by the growth of anti-fraud networks and industry efforts led by BITS, the FSTC and others.

Encouragingly, many of the financial institutions RSA has spoken to are executing on plans designed not just to meet, but to exceed the FFIEC's guidance and are also considering how to leverage this opportunity to improve their customers' trust in their brand and the remote channels.

As we move on into 2007, realism and perpetual vigilance remain key. This challenge will not be met and eliminated by the purchase of a single point solution. It demands a layered security approach and new organisational philosophies to eliminate current threats and prepare for emerging ones.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Risk Management Whitepapers