Home > Financial Services Information Security Tips > Security Architecture Insider > How to protect your financial organization from malware
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY ARCHITECTURE INSIDER

How to protect your financial organization from malware


Brad Dinerman, Contributor
10.22.2008
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Financial institutions are targets for hacking due to the large amount of personal, sensitive data that are stored on their networks. You need to ensure that your systems are protected properly from outside and internal threats. Failure to do so can result in a systems breach, widespread negative publicity, the potential loss of customers and certainly the loss of your job. Malware is a major threat to financial services firms. Understanding what malware is and how it can land on your network is essential if you are going to properly protect against it.

Malware is any piece of software that is put onto your network without your consent and whose purpose is to harm your organization in some manner. The most well-known forms of malware include viruses, spyware and Trojans. Others include keystroke recorders ("keyloggers") and even custom software that an employee may have intentionally installed to mail sensitive data to his personal email address.

So what can you do to protect your financial organization from the threat of malware? The answers fall into two distinct categories: technical tools and policies.

Technical tools
The technical tools are often the easiest to implement, since it's typically a matter of purchasing the right ones and implementing them. Examples include corporate-class antivirus and antispyware software that is installed not just on workstations, but also file and mail servers. Most modern firewalls have built-in antispyware and antivirus capabilities; they just need to be activated in order to do their job. Whichever you choose, it should be current, from a reputable vendor and installed by an individual or organization that truly knows the intricacies of the product. Never accept just the default settings, as they are usually inadequate for any business that values its data.

Email and Web browsing are two of the most typical mechanisms by which malware can be introduced into your network. For examp


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Architecture Insider
Winning the war: Personal information protection
Why financials must implement Web application security best practices
Identity management for financial firms in turbulent times
Identity management for financial firms in turbulent times
How to use data loss prevention tools to stop data exfiltration
Security questions to ask SaaS vendors when outsourcing services
Book chapter: Remote deposit capture risks
How to communicate the value of security controls for online transactions
How to perform a network device audit
Emerging themes in identity access management

Spam, phishing and social engineering
Online scammers exploit bank brands and consumers' financial woes
BITS releases guide for implementing email authentication protocols
Banks using Twitter need to proceed with caution, experts say
Financial fraud affects consumer bank behavior, Gartner finds
Symantec researchers warn of banking Trojan
Phishing attack uses pop-up message on bank sites
Phishing, malware to strain banks in 2009
Study of banking malware analyzes underground economy
Financial firms fight cyberthreats, brace for difficult year
ING hopes to cut phishing attacks with encryption software

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


le, many email messages claim to come from a trusted source, such as Microsoft or your own financial institution, and will contain either hyperlinks to sites that try to collect your personal information, or attachments that the sender claims are needed to patch your computer. Similarly, websites will often try to deceive you into thinking that you have spyware and will contain a link for you to scan and clean your system, when the fact is that your system was already clean and the software that you will be downloading is the actual malware! This is where training is very important.

Along with the tools such as firewalls, antispyware and antivirus, it is critical to educate users about the threats and what they can do to mitigate them. To continue with the previous example regarding fake patches from Microsoft, users should be reminded over and over again that Microsoft and most other major vendors would never send these updates by email. Rather, they will provide a hyperlink for the user, or preferably the network administrator, to go to the vendor site to manually download the patches.

Policies
Procedural solutions to the malware threat are more difficult to manage and enforce. The weakest point in any organization is often the end-user, and as we all know, placing any restrictions on habits which might inconvenience the end-user can result in an unpleasant workplace. None the less, it is imperative to have these in place to protect your organization.

Two examples of policies include:

  • Acceptable Use Policy: This is a document that describes what rights employees have with regard to the usage of computer systems. The policy might state, for example, that employees are forbidden to browse gambling or pornographic sites while at work or from any company-owned computer. All employees should sign an Acceptable Use Policy when their employment first begins as well as at their annual performance review. To disregard the terms of the policy can be grounds for discipline or dismissal.
  • Remote Access Policy: This provides standards for methods and times that employees may connect to the corporate network from a remote location, including from home and/or mobile devices. Remote Access Policies can be enforced technically and are important to have in place as a safeguard against improperly transmitting confidential data to insecure sources.
  • Having policies alone will not protect a financial institution's network against malware. Rather, they will help to minimize the likelihood that malware will ever become a problem by educating end-users and placing potential consequences on their actions.

    About the author:
    Brad is a Microsoft MVP in Enterprise Security, one of less than forty worldwide to possess the award in this category. He is also a Microsoft Certified Systems Engineer (MCSE), a Certified SonicWall Security Administrator and a Certified 3Com IP Telephony Expert. He is the founder and president of the National Information Security Group, an active member of the FBI's Infragard program and a member of the Microsoft IT Advisory Council. He holds a Ph.D. in physics to help him determine how long it will take his monitor to be launched across the local highway.


    Rate this Tip
    To rate tips, you must be a member of SearchFinancialSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts