Home > Financial Services Information Security Tips > Security Architecture Insider > How to protect your financial organization from malware
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY ARCHITECTURE INSIDER

How to protect your financial organization from malware


Brad Dinerman, Contributor
10.22.2008
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Financial institutions are targets for hacking due to the large amount of personal, sensitive data that are stored on their networks. You need to ensure that your systems are protected properly from outside and internal threats. Failure to do so can result in a systems breach, widespread negative publicity, the potential loss of customers and certainly the loss of your job. Malware is a major threat to financial services firms. Understanding what malware is and how it can land on your network is essential if you are going to properly protect against it.

Malware is any piece of software that is put onto your network without your consent and whose purpose is to harm your organization in some manner. The most well-known forms of malware include viruses, spyware and Trojans. Others include keystroke recorders ("keyloggers") and even custom software that an employee may have intentionally installed to mail sensitive data to his personal email address.

So what can you do to protect your financial organization from the threat of malware? The answers fall into two distinct categories: technical tools and policies.

More on integration
How to easily integrate managed email security services

Integrating firewalls into your financial enterprise systems

Technical tools
The technical tools are often the easiest to implement, since it's typically a matter of purchasing the right ones and implementing them. Examples include corporate-class antivirus and antispyware software that is installed not just on workstations, but also file and mail servers. Most modern firewalls have built-in antispyware and antivirus capabilities; they just need to be activated in order to do their job. Whichever you choose, it should be current, from a reputable vendor and installed by an individual or organization that truly knows the intricacies of the product. Never accept just the default settings, as they are usually inadequate for any business that values its data.

Email and Web browsing are two of the most typical mechanisms by which malware can be introduced into your network. For example, many email messages claim to come from a trusted source, such as Microsoft or your own financial institution, and will contain either hyperlinks to sites that try to collect your personal information, or attachments that the sender claims are needed to patch your computer. Similarly, websites will often try to deceive you into thinking that you have spyware and will contain a link for you to scan and clean your system, when the fact is that your system was already clean and the software that you will be downloading is the actual malware! This is where training is very important.

Along with the tools such as firewalls, antispyware and antivirus, it is critical to educate users about the threats and what they can do to mitigate them. To continue with the previous example regarding fake patches from Microsoft, users should be reminded over and over again that Microsoft and most other major vendors would never send these updates by email. Rather, they will provide a hyperlink for the user, or preferably the network administrator, to go to the vendor site to manually download the patches.

Policies
Procedural solutions to the malware threat are more difficult to manage and enforce. The weakest point in any organization is often the end-user, and as we all know, placing any restrictions on habits which might inconvenience the end-user can result in an unpleasant workplace. None the less, it is imperative to have these in place to protect your organization.

Two examples of policies include:

  • Acceptable Use Policy: This is a document that describes what rights employees have with regard to the usage of computer systems. The policy might state, for example, that employees are forbidden to browse gambling or pornographic sites while at work or from any company-owned computer. All employees should sign an Acceptable Use Policy when their employment first begins as well as at their annual performance review. To disregard the terms of the policy can be grounds for discipline or dismissal.
  • Remote Access Policy: This provides standards for methods and times that employees may connect to the corporate network from a remote location, including from home and/or mobile devices. Remote Access Policies can be enforced technically and are important to have in place as a safeguard against improperly transmitting confidential data to insecure sources.
  • Having policies alone will not protect a financial institution's network against malware. Rather, they will help to minimize the likelihood that malware will ever become a problem by educating end-users and placing potential consequences on their actions.

    About the author:
    Brad is a Microsoft MVP in Enterprise Security, one of less than forty worldwide to possess the award in this category. He is also a Microsoft Certified Systems Engineer (MCSE), a Certified SonicWall Security Administrator and a Certified 3Com IP Telephony Expert. He is the founder and president of the National Information Security Group, an active member of the FBI's Infragard program and a member of the Microsoft IT Advisory Council. He holds a Ph.D. in physics to help him determine how long it will take his monitor to be launched across the local highway.


    Rate this Tip
    To rate tips, you must be a member of SearchFinancialSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Security Architecture Insider
    How to secure data backup
    Too many encryption methods make secure communications difficult
    How to streamline role-based access control
    Five considerations for choosing network access control products
    Fighting fraud: Understanding technology and threats
    How to shift to centralized authentication and ease compliance
    Winning the war: Personal information protection
    Why financials must implement Web application security best practices
    Identity management for financial firms in turbulent times
    Identity management for financial firms in turbulent times

    Spam, phishing and social engineering attacks
    Judge rejects TD Ameritrade breach settlement
    FDIC warns of bogus emails
    Two Romanians suspected in phishing scheme extradited to U.S.
    Social engineering tests should make sense, not headlines
    Zeus Trojan hitting banking customers hard
    Five considerations for choosing network access control products
    Proposed expansion of top-level domains generates security concerns
    Online scammers exploit bank brands and consumers' financial woes
    BITS releases guide for implementing email authentication protocols
    Banks using Twitter need to proceed with caution, experts say

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts