Cyber Attacks On Banks Prompt New Regulatory Safeguards

 Janet Yellen, Chair of the Board of Governors of the US Federal Reserve System.

US regulators plan to require banks to adopt baseline safeguards to shield themselves from cyber-threats after a series of assaults cost the industry billions of dollars and shook consumer confidence, said people with knowledge of the matter.

The Federal Reserve is leading other agencies in crafting the protections, which would be minimum standards, said the people who asked not to be named because work on the measures isn’t public. The effort stems partly from a concern that as digital breaches become more frequent and aggressive, an attack could cripple the entire financial system.

The Fed is working with the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corp., said the people. Further details on the agencies’ plans couldn’t be determined, so it’s not clear whether costly efforts that lenders have already undertaken would put them in compliance with what regulators propose.

The industry has been stunned by recent computer muggings, including a February hack of Bangladesh’s central bank in which thieves made off with $81 million and the 2014 incursion of JPMorgan Chase & Co. that led to information on millions of customers being compromised. The attacks have spurred financial firms to try to fend off attacks by hiring thousands of employees to monitor threats and upgrading their technology.

The agencies’ first step would be to solicit public input on ideas for boosting banks’ defenses, which regulators would study before following up with a more formal proposal. The multistage rule process could stretch into next year.

In recent years, banking regulators’ public responses to hacks have mostly consisted of issuing guidance and industry alerts. But the escalating attacks have put pressure on them to do more, and a formal rule could give the government a greater ability to crack down on lenders it thinks aren’t doing enough to protect themselves. While the agencies years ago established information-security standards for banks, those measures were issued well before the modern threats emerged.

In JPMorgan’s 2015 annual report, Chief Operating Officer Matt Zames described the bank’s thousands of employees working from three global security-operations centers to protect the firm. He noted that every month they find more than 200 million malicious e-mails -- each the potential foothold for an attack on the bank.

‘Unconstrained Budget’

Bank of America Corp. finds it “very tough to keep ahead of those who would do us harm” even with the lender committing an “unconstrained budget” to securing information, Cathy Bessant, who runs operations and technology at the bank, said in an April interview with Bloomberg Television.

The danger of “potentially catastrophic” malware assaults was flagged recently by the panel of US regulators formed to deal with emerging risks to the financial system, the Financial Stability Oversight Council. 

Recently, the group called on financial regulators to set up a “common risk-based approach” for figuring out whether firms can block digital invaders, and that agencies remove hurdles that deter companies from talking to each other, the government and the public about how hackers are coming after them.

Last year, Congress passed legislation that lets companies share real-time data on hacking threats without opening themselves up to customer lawsuits.

The Fed itself got roped into this year’s audacious theft of millions of dollars from Bangladesh Bank, as the thieves reportedly transferred funds from that central bank’s account at the New York Federal Reserve after breaching the widely used messaging system run by the Society for Worldwide Interbank Financial Telecommunication, better known as Swift.

Top Issue

Swift connects members who are crucial to the global financial system, including central and commercial banks, money managers and Wall Street securities firms. The Bangladesh attack and other similar ones that have occurred recently relied on false messages routing money to the thieves’ accounts in what Swift has called a “wider and highly adaptive campaign targeting banks.”

While banking regulators are preparing new standards to address threats, the Commodity Futures Trading Commission has already proposed a cybersecurity measure requiring mandatory testing of safeguards at derivatives firms. CFTC Chairman Timothy Massad has said the agency’s work should be finished this year, adding that the risk posed by hackers is “the most important single issue we face in terms of financial market stability and integrity.”

Information- Management

 

« Cyber Threats & Nuclear Weapons
Quantum Computing: The US Airforce Needs Help »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

TenIntelligence

TenIntelligence

TenIntelligence provides due diligence, brand protection and fraud investigation services including digital forensics.

Parasoft

Parasoft

Parasoft is an independent software testing and software quality assurance tool and solution vendor.

Telos

Telos

Telos offers cybersecurity solutions and services that empower and protect the world’s most security-conscious enterprises.

Canadian Security Intelligence Service (CSIS)

Canadian Security Intelligence Service (CSIS)

CSIS collects and analyzes threat-related information concerning the security of Canada in areas including terrorism, espionage, WMD, cybersecurity and critical infrastructure protection.

One Identity

One Identity

One Identity delivers identity governance, access management, and privileged account management solutions that facilitate and secure your digital transformation.

Cyberwrite

Cyberwrite

Cyberwrite was founded to provide underwriters around the world a unique and innovative Cyber Underwriting platform.

Epati Information Technologies

Epati Information Technologies

ePati Information Technologies is a specialist in information technology and cyber security.

ISMS Accreditation Center (ISMS-AC)

ISMS Accreditation Center (ISMS-AC)

ISMS-AC is the national accreditation body for Japan. The directory of members provides details of organisations offering certification services for ISO 27001.

Cybersecurity Manufacturing Innovation Institute (CyManII)

Cybersecurity Manufacturing Innovation Institute (CyManII)

CyManII was established to create economically viable, pervasive, and inconspicuous cybersecurity in American manufacturing to secure the digital supply chain and energy automation.

AEWIN Technologies

AEWIN Technologies

AEWIN is professional in the fields of Network Appliance, Cyber Security, Server, Edge Computing and an ODM/OEM expert.

StrikeReady

StrikeReady

StrikeReady have developed CARA, an advanced technology solution that offers personalized and proactive assessment and remediation of future and current risk in real-time.

Harvey Nash

Harvey Nash

Harvey Nash is a leading global provider of talent and technology solutions.

MailChannels

MailChannels

MailChannels protects companies against malicious email threats. Used by 750+ hosting providers around the world.

Eqlipse Technologies

Eqlipse Technologies

Eqlipse Technologies provides products and high-end engineering solutions to customers in the Department of Defense and Intelligence Community.

Cynclair

Cynclair

Cybersecurity is a complex beast. And we're the beast-tamers. Our team thrives on deciphering the latest threats, building cutting-edge defenses, and making your digital world much safer.

Screwloose IT

Screwloose IT

Screwloose IT are a national provider of information technology services. We specialise in managed IT, cloud services, cyber security, website design and digital marketing for businesses of all sizes.