Secure Use of Electronic Banking Services. George Chou Hong Kong Monetary Authority Dec 2013



Similar documents
電 子 銀 行 風 險 - 認 證 與 核 實. Fraud Risk Management The Past and the Future 欺 詐 風 險 管 理 - 過 去 與 未 來

Supervisory Policy Manual

Country Club Bank- Intro to Mobile Banking- Android & iphone Apps

Business Internet Banking / Cash Management Fraud Prevention Best Practices

Business ebanking Fraud Prevention Best Practices

Protecting against Mobile Attacks

MCBDirect Corporate Logging on using a Soft Token

Business Online Banking Quick Users Guide

Best Practices Guide to Electronic Banking

ONLINE BANKING SECURITY TIPS FOR OUR BUSINESS CLIENTS

CBI s Corporate Internet Banking Inquiry Services gives you the ability to view account details and transactions anytime, anywhere.

The Hang Seng Mobile Payment - FAQs

Retail/Consumer Client. Internet Banking Awareness and Education Program

Personal Online Banking & Bill Pay. Guide to Getting Started

Tips for Banking Online Safely

Identity Theft Protection

Business Mobile Banking

Business Online Banking & Bill Pay Guide to Getting Started

How To Protect Yourself Online

Cyber Security, Fraud and Corporate Account Takeovers LBA Bank Counsel Conference December 2014

Practice Good Enterprise Security Management. Presented by Laurence CHAN, MTR Corporation Limited

Spring Hill State Bank Mobile Banking FAQs

Hong Kong Information Security Outlook 2015 香 港 資 訊 保 安 展 望

U.S. Cellular Mobile Data Security. User Guide Version 00.01

Phishing Scams Security Update Best Practices for General User

Deter, Detect, Defend

Protecting your Data, Devices, and Digital Life in a BYOD World: A Security Primer GLENDA ROTVOLD AND SANDY BRAATHEN NBEA APRIL 2, 2015

Understanding It s Me 247 Security. A Guide for our Credit Union Clients and Owners

Legislative Council Panel on Information Technology and Broadcasting. Information Security

Step 1. Step 2. Open your browser and go to and you will be presented a logon screen show below.

Remote Deposit Quick Start Guide

Security aspects of e-tailing. Chapter 7

Contents. 4 Welcome to ATBOnline Business. 5 How to Use This Guide

Cyber Security. Securing Your Mobile and Online Banking Transactions

Information Security Threat Trends

It is in PDF format. It has similar layout of a paper cheque with the display of a standardized e-cheque logo on the face of e-cheque

Electronic Cheque (e-cheque) E-Brochure

Bring Your Own Device (BYOD) & Customer Data Protection Are You Ready?

F G F O A A N N U A L C O N F E R E N C E

Safe Practices for Online Banking

What are the common online dangers?

Your security is our priority

General tips for increasing the security of using First Investment Bank's internet banking

NQ Mobile Security Frequently Asked Questions (FAQs) for Android

Online Security Information. Tips for staying safe online

Secure Your Mobile Workplace

Enhanced Security for Online Banking

Introduction. PCI DSS Overview

COMMONWEALTH OF PENNSYLVANIA DEPARTMENT S OF PUBLIC WELFARE, INSURANCE AND AGING

Course: Information Security Management in e-governance. Day 1. Session 5: Securing Data and Operating systems

Galveston College Wireless Network Users Setup Guide Version 1.0

FAQs about Cyberbanking Mobile Phone. Q1: What services are available via Cyberbanking Mobile Phone?

Bitrix Software Security. Powerful content management with advanced security features

Mobile Devices: Know the RISKS. Take the STEPS. PROTECT AND SECURE Health Information.

Security Guide. for electronic transactions. UniBank is a division of Teachers Mutual Bank Limited

Stop Identity Theft. with Transparent Two-Factor Authentication. e-lock Corporation Sdn Bhd

Online Banking Customer Awareness and Education Program

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training - Session One

Security Guidelines and Best Practices for Retail Online and Business Online

Best Practices For Department Server and Enterprise System Checklist

Enterprise Mobility Management Migration Migrating from Legacy EMM to an epo Managed EMM Environment. Paul Luetje Enterprise Solutions Architect

July, 2014 Page 1 of 7

Cyber Self Assessment

1. What you need to know about these conditions of use

PROTECT YOUR COMPUTER AND YOUR PRIVACY!

Frequently Asked Questions

Online Cash Management Security: Beyond the User Login

Infocomm Sec rity is incomplete without U Be aware,

Frequently Asked Questions For Investors

Online Services User Guide

Self-Service Portal Registering, downloading & activating a soft token

Agenda. Cyber Security: Potential Threats Impacting Organizations 1/6/2015. January 10, 2015 Scott Petree

Marlon R Clarke, Ph. D., CISSP, CISM Director Network Operations and Services, NSU

Chapter 15: Computer and Network Security

MOBILE BANKING. Why should I use Mobile Banking?

A QUICK AND EASY GUIDE TO CITY NATIONAL BUSINESS ONLINE

Reference Guidelines On Best Practices To Support E-Banking Service Security

Electronic Fraud Awareness Advisory

Why is a strong password important?

ONLINE ACCESS ONLINE ACCESS FAQS FAQS

Wireless Network Best Practices for General User

Online security. Defeating cybercriminals. Protecting online banking clients in a rapidly evolving online environment. The threat.

Multi-Factor Authentication (FMA) A new security feature for Home Banking. Frequently Asked Questions 8/17/2006

Web Plus Security Features and Recommendations

Transcription:

Secure Use of Electronic Banking Services George Chou Hong Kong Monetary Authority Dec 2013

Agenda Recent Development of Internet Banking in Hong Kong Regulatory Requirements on Internet Banking Supervisory Approach Public Education by the HKMA Security Tips for Internet Banking Users

Recent Development of Internet Banking in Hong Kong

Recent Development of Internet Banking in Hong Kong * As of June 2013

Recent Development of Internet Banking in Hong Kong * As of June 2013

Recent Development of Internet Banking in Hong Kong Growth of Internet Banking Accounts Number of Internet Banking Accounts 8.4 8.5 PIB (million) BIB (thousand) 6.2 7.0 7.7 765 798 5.7 658 4.9 573 3.3 3.8 401 477 307 234 162 End 2005 End 2006 End 2007 End 2008 End 2009 End 2010 End 2011 End 2012 Mid 2013

Recent Development of Internet Banking in Hong Kong High mobile service subscription penetration rate in Hong Kong 250% 200% 150% 100% 50% 0% 233.2% as of July 2013 (around 2.3 mobile service subscription per person) (Source: Office of the Communications Authority (OFCA) in HK Key Communications Statistics) Mobile service subscription versus population of HK (%)

Recent Development of Internet Banking in Hong Kong Mobile Banking in Hong Kong (as of June 2013) Personal Mobile Banking 16 banks 7,600,000 accounts Business Mobile Banking 10 banks 590,000 accounts

Recent Development of Internet Banking in Hong Kong NFC Mobile Payment Contactless payment in point-of-sale terminals Currently offered by a number of banks in Hong Kong Other possible functions E-coupons Transaction history enquiry

Recent Development of Internet Banking in Hong Kong Electronic Bill Presentment and Payment (e-bill) system

Regulatory Requirements on Internet Banking

Regulatory Requirements on Internet Banking HKMA aims to create a safe and sound environment for electronic banking development in Hong Kong without standing in the way of progress Independent assessment before launch of new Internet banking service or major enhancement to the existing Internet banking service

Regulatory Requirements on Internet Banking Two-factor authentication for high-risk transactions Unregistered third party fund transfer Online registration of third party account for fund transfer Bill payment to high-risk merchant categories (e.g. credit cards, telebet service) Increase of Internet banking daily transaction limit Online change of sensitive personal information

Regulatory Requirements on Internet Banking Two-factor authentication Why we need two-factor authentication? User ID and password alone no longer sufficient cases reported where user IDs and passwords were stolen through phishing, fake website, virus, Trojan, etc What is two-factor authentication?

Regulatory Requirements on Internet Banking Major types of two-factor authentication Digital Certificate Security Token-based OTP SMS-based OTP Security Token

Regulatory Requirements on Internet Banking Controls over fund transfers Default transaction limit set the default transaction limit to zero when a new Internet banking account is first activated Increase of transaction limit customers can increase the transaction limit through secure channels (e.g. at branches or by post) Reset transaction limits for inactive customers - reset the transaction limit to zero if such a facility has not been used for a prolonged period (e.g. 1 year)

Regulatory Requirements on Internet Banking Protection of one-time password (OTP) and customer alerts Validity of OTP shorten the expiration of OTP (e.g. within 100 seconds) used for authenticating online high-risk transactions SMS OTP message prominently display transaction details (e.g. type of transaction, partial payee account number and transaction amount) before the OTP within the SMS OTP message SMS notification include transaction details in the SMS message notifying customers of the execution of high-risk transactions

Supervisory Approach

Supervisory Approach International co-operation Independent compliance assessment Continuous monitoring and examinations Awareness & training Policies & guidance Foundation

Public Education by the HKMA

Public Education by the HKMA Press release on fake bank websites / phishing emails InSight articles on emerging threats Online learning on the HKMA website Cooperation campaign with the Police, OGCIO and HKCERT Radio broadcast

Security Tips for Internet Banking Users

Security Tips for Internet Banking Users Apply security patches for your OS and applications regularly Install anti-virus, anti-spyware and personal firewall with up-to-date definition applied NEVER access your Internet banking website from a public computer (e.g. in a cyber cafe) Always log off after using Internet banking service

Security Tips for Internet Banking Users Mobile security Lock your mobile device when not in use Install mobile security software if available Install the official mobile banking app from reputable sources (e.g. Apple App Store or Google Play) Do NOT access banking services with jail broken / rooted devices Avoid accessing banking services through public Wi-Fi network

Security Tips for Internet Banking Users Do NOT access bank websites through hyperlinks embedded in e-mails internet search engines suspicious pop-up windows Banks in Hong Kong will NOT send e-mails to customers with embedded links to the transactional websites NEVER ask customers for sensitive information (e.g. logon passwords or one-time passwords)

Security Tips for Internet Banking Users Beware of unusual log-on process and notify your bank if you encountered Unusual pop-up screen Abnormally slow computer response Unexpected steps or information required for log-on