Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Interviews > SECURITY WITHIN THE FINANCIAL SECTOR
    Interviews

    SECURITY WITHIN THE FINANCIAL SECTOR

    SECURITY WITHIN THE FINANCIAL SECTOR

    Published by Gbaf News

    Posted on February 25, 2014

    Featured image for article about Interviews

    Global Banking & Finance Review recently spoke with Brian Spector, CEO, CertiVox about security within the financial sector, including the state of user security, common threats and organizations can be doing.

    How would you describe the state of user security within the financial and banking industry at the moment?

    “Organisations across all industry sectors are facing the increasing risk of data breaches and sustained assault from hacking collectives, and it seems that not a day goes by without another high profile data breach hitting the headlines. In recent weeks we have seen three South Korean banks fined for a data breach that affected up to 20 million customers, as well as the fallout for banks from the Target attack in the US. Obviously this is also prevalent across other sectors with high profile organisations like Yahoo!, Adobe and Tesco also falling victim to attacks in recent months, and as you would expect, the financial services industry is relatively one of the most secure.

    Brian Spector, CEO, CertiVox

    Brian Spector, CEO, CertiVox

    “However, we recently surveyed 2,000 UK consumers to look into their experiences of banking security, and found that of the 24 per cent of respondents who had online services hacked, 13 per cent of these successful attacks targeted banking services. With the important financial information concerned, this should make alarming reading for banks, particularly as the same research found that 25 per cent of respondents would terminate a service immediately if their account was compromised.

    “The finance and banking industry by its very nature must be aware of these increasing threats and regularly update its security accordingly. However, the additional security implemented by some are either not sufficient, or diminish the experience of their customers.”

    What are the most common threats encountered?

    “Recent research from Ponemon shows that the average annual cost of cyber crime varies by industry segment, with financial services, defence, and energy and utilities experiencing substantially higher cyber crime costs than organisations in retail, hospitality and consumer products.”

    “The problem is that as security gets more sophisticated so do the attacks themselves. It appears a recent high profile attack example could have been orchestrated based on initialisation through a malware-laced phishing email. Whatever the type of attack though, what is proven time and again is that username and password security systems are inherently weak, offering a wide range of attack vectors to criminals, along with a valuable harvest of private customer information.”

    Confidential data is a top concern. What products are available to increase security and help prevent data theft?

    “Security Intelligence systems such as two-factor authentication should start to be integrated across all industries in order to have some kind of real control on data breaches. Many companies do respond to these threats by adding layers of security, such as: additional security questions, Captcha codes, SMS based so called One-Time-Passwords or physical security devices in the case of banks. However, the problem with these measures is they often frustrate users in relation to the ease of use and experience in accessing services.

    “Data is the individual’s responsibility, but as service providers ‘volunteer’ to protect personal information it is by default their duty to safeguard the consumer data held.  This means organisations must begin to learn about the different technologies available like encryption, and using it to safeguard personal and sensitive data. There are several strong authentication technologies ready to step in and replace the traditional ID/ password combination, and organisations should really be focused on finding a higher  level of security that transcends user name and password, which is also cost effective and advanced, but also easy to use.

    “To establish trust and prevent these types of attacks, organisations need to look beyond username and password protection and even common two-step authentication and should urgently consider technologies that remove the username password altogether so that there is nothing to be stolen or compromised in the first place.”

    Explain to us how CertiVox’s M-Pin strong Authentication works and the benefits to both consumers and businesses it can offer?

    “M-Pin provides strong multi-factor authentication which is designed to replace the vulnerable username and password login system for digital services. Instead of username/password combinations, often the target of choice for hackers, M-Pin gives the end user a four digit PIN to enter for access to content and services. The M-Pin mobile client also alleviates concerns about accessing services from a PC not under a user’s control, by allowing login through the users’ smartphone.

    “M-Pin is based on strong elliptic curve cryptography and delivers multi-factor authentication for websites, enterprise and mobile applications, using HTML5 web apps, meaning no browser plug-ins or software is required. Authentication is performed between the M-Pin Client and the M-Pin Authentication Server using the M-Pin Protocol, a zero knowledge proof construct. The result is that the M-Pin server has just one leakproof cryptographic key, which if compromised or stolen reveals nothing about users in an enterprise or your web application. In addition, M-Pin operates on a principle of distributed trust, whereby the root key generators are split between CertiVox’s servers and those belonging to the client, meaning that any attack would have to compromise both of these systems to have any chance of being successful.”

    What have CertiVox got planned for 2014?

    “We can’t talk about the details at this stage but we have a lot going on in a variety of sectors, including financial services, in 2014. Expect to see product upgrades, high profile customers and a real step up in our drive to stop the slew of data breaches and establish real trust between consumers and organisations.”

    Global Banking & Finance Review recently spoke with Brian Spector, CEO, CertiVox about security within the financial sector, including the state of user security, common threats and organizations can be doing.

    How would you describe the state of user security within the financial and banking industry at the moment?

    “Organisations across all industry sectors are facing the increasing risk of data breaches and sustained assault from hacking collectives, and it seems that not a day goes by without another high profile data breach hitting the headlines. In recent weeks we have seen three South Korean banks fined for a data breach that affected up to 20 million customers, as well as the fallout for banks from the Target attack in the US. Obviously this is also prevalent across other sectors with high profile organisations like Yahoo!, Adobe and Tesco also falling victim to attacks in recent months, and as you would expect, the financial services industry is relatively one of the most secure.

    Brian Spector, CEO, CertiVox

    Brian Spector, CEO, CertiVox

    “However, we recently surveyed 2,000 UK consumers to look into their experiences of banking security, and found that of the 24 per cent of respondents who had online services hacked, 13 per cent of these successful attacks targeted banking services. With the important financial information concerned, this should make alarming reading for banks, particularly as the same research found that 25 per cent of respondents would terminate a service immediately if their account was compromised.

    “The finance and banking industry by its very nature must be aware of these increasing threats and regularly update its security accordingly. However, the additional security implemented by some are either not sufficient, or diminish the experience of their customers.”

    What are the most common threats encountered?

    “Recent research from Ponemon shows that the average annual cost of cyber crime varies by industry segment, with financial services, defence, and energy and utilities experiencing substantially higher cyber crime costs than organisations in retail, hospitality and consumer products.”

    “The problem is that as security gets more sophisticated so do the attacks themselves. It appears a recent high profile attack example could have been orchestrated based on initialisation through a malware-laced phishing email. Whatever the type of attack though, what is proven time and again is that username and password security systems are inherently weak, offering a wide range of attack vectors to criminals, along with a valuable harvest of private customer information.”

    Confidential data is a top concern. What products are available to increase security and help prevent data theft?

    “Security Intelligence systems such as two-factor authentication should start to be integrated across all industries in order to have some kind of real control on data breaches. Many companies do respond to these threats by adding layers of security, such as: additional security questions, Captcha codes, SMS based so called One-Time-Passwords or physical security devices in the case of banks. However, the problem with these measures is they often frustrate users in relation to the ease of use and experience in accessing services.

    “Data is the individual’s responsibility, but as service providers ‘volunteer’ to protect personal information it is by default their duty to safeguard the consumer data held.  This means organisations must begin to learn about the different technologies available like encryption, and using it to safeguard personal and sensitive data. There are several strong authentication technologies ready to step in and replace the traditional ID/ password combination, and organisations should really be focused on finding a higher  level of security that transcends user name and password, which is also cost effective and advanced, but also easy to use.

    “To establish trust and prevent these types of attacks, organisations need to look beyond username and password protection and even common two-step authentication and should urgently consider technologies that remove the username password altogether so that there is nothing to be stolen or compromised in the first place.”

    Explain to us how CertiVox’s M-Pin strong Authentication works and the benefits to both consumers and businesses it can offer?

    “M-Pin provides strong multi-factor authentication which is designed to replace the vulnerable username and password login system for digital services. Instead of username/password combinations, often the target of choice for hackers, M-Pin gives the end user a four digit PIN to enter for access to content and services. The M-Pin mobile client also alleviates concerns about accessing services from a PC not under a user’s control, by allowing login through the users’ smartphone.

    “M-Pin is based on strong elliptic curve cryptography and delivers multi-factor authentication for websites, enterprise and mobile applications, using HTML5 web apps, meaning no browser plug-ins or software is required. Authentication is performed between the M-Pin Client and the M-Pin Authentication Server using the M-Pin Protocol, a zero knowledge proof construct. The result is that the M-Pin server has just one leakproof cryptographic key, which if compromised or stolen reveals nothing about users in an enterprise or your web application. In addition, M-Pin operates on a principle of distributed trust, whereby the root key generators are split between CertiVox’s servers and those belonging to the client, meaning that any attack would have to compromise both of these systems to have any chance of being successful.”

    What have CertiVox got planned for 2014?

    “We can’t talk about the details at this stage but we have a lot going on in a variety of sectors, including financial services, in 2014. Expect to see product upgrades, high profile customers and a real step up in our drive to stop the slew of data breaches and establish real trust between consumers and organisations.”

    Related Posts
    iFAST Global Bank Emerges as a New Strong Player in UK Business Banking Space – Q&A with Steve Chu
    iFAST Global Bank Emerges as a New Strong Player in UK Business Banking Space – Q&A with Steve Chu
    Building Trust in Private Banking: A Conversation with Jonathan Hass
    Building Trust in Private Banking: A Conversation with Jonathan Hass
    Lumana: How AI Is transforming video surveillance in banking
    Lumana: How AI Is transforming video surveillance in banking
    Marco Santos Reflects on His First Year as GFT’s Global CEO and Charts the Company’s AI-Driven Future
    Marco Santos Reflects on His First Year as GFT’s Global CEO and Charts the Company’s AI-Driven Future
    Shadow AI in banking: What financial institutions must know now
    Shadow AI in banking: What financial institutions must know now
    How to Future-Proof Products in a Fast-Moving Tech Landscape—Q&A With Sri Phani Teja Perumalla
    How to Future-Proof Products in a Fast-Moving Tech Landscape—Q&A With Sri Phani Teja Perumalla
    Bank Earnings: Q&A with Daniela Sabin Hathorn of Capital.com
    Bank Earnings: Q&A with Daniela Sabin Hathorn of Capital.com
    Negotiation as an EBITDA Engine: Alex Adamo on Turning Deals into Strategic Assets
    Negotiation as an EBITDA Engine: Alex Adamo on Turning Deals into Strategic Assets
    Branded Residences and the Rise of Destination Investments: A New Asset Class for Global Capital
    Branded Residences and the Rise of Destination Investments: A New Asset Class for Global Capital
    Banca Mifel and Finacle: A Partnership Powering Mexico’s Digital Banking Future
    Banca Mifel and Finacle: A Partnership Powering Mexico’s Digital Banking Future
    Broadstreet Global: How a Greenville-based Private Equity Firm is Scaling Southern Hospitality with Iconic Hotel Brands
    Broadstreet Global: How a Greenville-based Private Equity Firm is Scaling Southern Hospitality with Iconic Hotel Brands
    How eClerx's Fayetteville Center of Excellence Taps into Veteran Talent: Q&A with John Flowers
    How eClerx's Fayetteville Center of Excellence Taps into Veteran Talent: Q&A with John Flowers

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Interviews

    Explore more articles in the Interviews category

    Banking on Experience in a Rising India: How Standard Chartered is Redefining Wealth for the Affluent

    Banking on Experience in a Rising India: How Standard Chartered is Redefining Wealth for the Affluent

    Trading your way forward with the new Maybank Trade SG app – Interview with Alexander Thorhauge, Head of Retail Business, Maybank Securities Singapore

    Trading your way forward with the new Maybank Trade SG app – Interview with Alexander Thorhauge, Head of Retail Business, Maybank Securities Singapore

    Securing Energy Certainty: A Financial Playbook for the Volatile Decade Ahead

    Securing Energy Certainty: A Financial Playbook for the Volatile Decade Ahead

    Building Intelligence at Scale: Inside Ant International’s Vision for Inclusive Finance

    Building Intelligence at Scale: Inside Ant International’s Vision for Inclusive Finance

    Inside the 2025 Finance and Accounting Talent Crisis: Q&A with Personiv’s Matt Wood

    Inside the 2025 Finance and Accounting Talent Crisis: Q&A with Personiv’s Matt Wood

    One Woman’s Vision in Turning Career Highs and Lows Into a New Kind of Leadership

    One Woman’s Vision in Turning Career Highs and Lows Into a New Kind of Leadership

    Asia’s Evolving Scam Defense: Regional Divergence, Rising Prevention, and the Path Toward Collective Security

    Asia’s Evolving Scam Defense: Regional Divergence, Rising Prevention, and the Path Toward Collective Security

    Why the finance sector needs to adopt a smarter approach to Product Lifecycle Governance

    Why the finance sector needs to adopt a smarter approach to Product Lifecycle Governance

    Dr. Adil Quraish Shares A Transformational Journey Through Diverse Fields

    Dr. Adil Quraish Shares A Transformational Journey Through Diverse Fields

    Investor and Strategic Advisor Dr. Adil Quraish Highlights the Importance of Professional Adaptability

    Investor and Strategic Advisor Dr. Adil Quraish Highlights the Importance of Professional Adaptability

    Expert Explains How DeFi Fits the Wealth Management Philosophy

    Expert Explains How DeFi Fits the Wealth Management Philosophy

    Rewarding Relationships: How Merlion Global Is Redefining Loyalty in Online Trading

    Rewarding Relationships: How Merlion Global Is Redefining Loyalty in Online Trading

    View All Interviews Posts
    Previous Interviews PostQ&A WITH PRAVIN KOTHARI, FOUNDER AND CEO OF CIPHERCLOUD
    Next Interviews PostTHE INNOVATION LABORATORY