Cisco Confidential 1 © 2010 Cisco and/or its affiliates. All rights reserved. Security in Banking Emmanuel van de Geer Senior Architect Governance, Risk, Compliance and Security Standard Chartered Bank
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2 2 © 2010 Cisco and/or its affiliates. All rights reserved. What are we covering
Cisco Confidential 3 © 2010 Cisco and/or its affiliates. All rights reserved. Criminals want to steal from Banks Banks succeed because customers trust them with their money Suttons Law “That’s where the money is”
Cisco Confidential 4 © 2010 Cisco and/or its affiliates. All rights reserved. Customers need to know that Banks are safe and secure This isn’t just to do with Information Security. It’s about how a Bank is run. Here For Good Standard Chartered Bank
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential © 2010 Cisco and/or its affiliates. All rights reserved. This is one reason why Information Security in Banks is different from other industries Information Security isn’t a technology problem, it is a business asset.
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential © 2010 Cisco and/or its affiliates. All rights reserved. Another reason why information security is different in Banking: Follow the Money
Cisco Confidential 7 © 2010 Cisco and/or its affiliates. All rights reserved. How Banks Work & Why Risk Is Important
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8 8 © 2010 Cisco and/or its affiliates. All rights reserved.
Cisco Confidential 9 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9 9 © 2010 Cisco and/or its affiliates. All rights reserved.
Cisco Confidential 10 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10 Cisco Confidential 10 © 2010 Cisco and/or its affiliates. All rights reserved.
Cisco Confidential 11
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12 Cisco Confidential 12 Cisco Confidential 12 © 2010 Cisco and/or its affiliates. All rights reserved. Risk management and information security are factors that determine how competitive and successful a Bank is.
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13 Cisco Confidential 13 Cisco Confidential 13 © 2010 Cisco and/or its affiliates. All rights reserved. In the Banking industry, security isn’t just about the technology, rather, it is integrated with Risk Management, Compliance and Fraud. This combined space is called GRC
Cisco Confidential 14 © 2010 Cisco and/or its affiliates. All rights reserved. In 2000, online fraud was unheard of. Now it costs banks 60M in the USA alone.
Cisco Confidential 15 © 2010 Cisco and/or its affiliates. All rights reserved. & what a career in security can mean for you.
Cisco Confidential 16 © 2010 Cisco and/or its affiliates. All rights reserved. Today, I design systems that prevent and detect everything from hackers to money laundering.
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18 Cisco Confidential 18 Cisco Confidential 18 © 2010 Cisco and/or its affiliates. All rights reserved. As the threats of theft and fraud have increased, so has the role of Information Security professionals.
Cisco Confidential 19 © 2010 Cisco and/or its affiliates. All rights reserved. Online Fraud The Insider Threat Cards and Transactions Denial of ServiceData Leakage Trading Fraud Payments Processing Information Theft
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20 Motivation: who is it and why do they do it? Geopolitical - Government affiliated - NGO - Militant Hacktivism – Crowd Sourced - Anonymous - LulzSec - Occupy Extortion/financial gain - Criminals Targets: what do they target Asia (MY, KR, TW, CH) US Gov Israel, Palestine Banks in Brazil CIA Bank of America
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21
Cisco Confidential 22 © 2010 Cisco and/or its affiliates. All rights reserved. Zeus and SpyEye
Cisco Confidential 23 © 2010 Cisco and/or its affiliates. All rights reserved.
Cisco Confidential 24 © 2010 Cisco and/or its affiliates. All rights reserved. But how bad is it?
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 30
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 31
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 32
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 33
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 34 Cisco Confidential 34 Cisco Confidential 34 © 2010 Cisco and/or its affiliates. All rights reserved. Recap Information in Banking: -People Steal Money, Money lives in Banks. -People Trust Banks & Reputation is key. -Fraud and Risk impact Bank profitability. Information Security is a business problem for Banks.
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 35 Cisco Confidential 35 Cisco Confidential 35 © 2010 Cisco and/or its affiliates. All rights reserved. Recap Online Fraud - Steadily increasing - Some way to go compared to other fraud activity Prediction: -Mobile Security will get worse -The end of SMS OTP