How to Safeguard Your Business and Your Customers

Growth of the Internet in Banking

According to Forrester Research, an expected 130 million people will be using remote banking services in Europe by 2007. This trend has been welcomed by the banks and financial service providers, who can keep branch costs low and at the same time, reap the benefits of increased transaction frequency. The customers, on the other hand, are afforded greater freedom, and more immediate control over their finances.

Password Overload – the Drive for Stronger Authentication

The rapid growth in Internet banking has been paralleled with an equally rapid and alarming rise in card-not-present (CNP) fraud. Historically, banks have relied on the use of passwords to enable remote access to banking applications. However, highly sophisticated fraudulent techniques have evolved beyond the capabilities of traditional password based security measures. With sophisticated spyware software, phishing attacks and key-logging all threatening the online security of banks and their customers, it is becoming apparent that one-factor authentication systems, a staple of the financial services industry for the past few years, are no longer sufficiently secure.

Recent statistics from APACS, the UK Payments Association, show that in 2004, the UK banking industry lost £12m to online banking fraud alone. In the same year, the total cost of card related fraud was a staggering £504.8m. Of this, CNP had increased by 24 per cent to £150.8m, and continues to be the biggest single fraud category. These losses are being compounded by the increasing customer reluctance to use online financial services which they deem to be unsafe or unsecure. It is therefore imperative for banks to upgrade their current password-based authentication solutions to stronger, two-factor authentication.

The Role of EMV in Online Security

Many banks across the world are gearing up for the shift to chip-based EMV payment cards. The deadlines for the fraud liability shift to the retailer have been set by Visa, Mastercard and JCB, as 2005 in Europe and 2006 in Asia. Failure to migrate to EMV by these deadlines will mean retailers will have responsibility for certain types of fraud. The banking and financial services industry has invested a great deal in educating customers and adapting their systems for EMV migration. Banks can leverage this significant investment if they recognise the potential of customers using their chip cards not simply for secure payments, but also as a means of authenticating themselves during e-banking and other card-not-present transactions.

With many customers saying that they would welcome stronger online security, banks can turn the situation around in their favour and provide their customers with devices to enable secure online access. This in turn will increase the amount of business banks can do online, lowering branch costs and encouraging an increase in the number of banking transactions.

Current Authentication Solutions

There are a number of different security solutions currently available; ranging from tokens, to smart card readers, or devices that generate one-time passwords (OTP).

Pocket-sized EMV-compliant smart card readers incorporating a challenge/response capability appear to offer the most promising long-term answer to online authentication problems – at least in European and Middle Eastern markets. Not only do the readers leverage the considerable investment by the banking industry in EMV chip card migration, they can also be extended in scope to cover other forms of CNP fraud.

There are a range of solutions on the market to foil spyware programs and prevent phishing attacks. Some of these incorporate a challenge-response capability, enabling banks to securely authenticate online customers through strong, two-factor authentication.

While security experts are in agreement that two-factor authentication is essential, the perceived challenge is how to implement the solutions, while keeping time and deployment costs low.

Banks are Accelerating their Interest in Safeguards for Customers

Some of the European banks currently introducing smart cards, in place of credit and debit cards with magnetic stripes, are already taking advantage of the intrinsic cryptographic power of the chip to add another layer of security.

In May 2005, the national bank of Slovenia, Banka Koper, began roll-out of the country’s first e-banking and e-commerce programme, with a smart card-based authentication solution modelled on the MasterCard Chip Authentication Programme (CAP). Xiring supplied Banka Koper with more than 10,000 Xi-Sign 4000 smart card readers, branded Banka Koper that are being issued to the bank’s retail customers for use in conjunction with their EMV bank cards, to offer the highest levels of user authentication for accessing banking services online.

This roll-out comes at a time when most European banks are working on projects to improve the security of their on-line services. In Northern Europe in particular, banks are moving away from token-based solutions, towards smart-card based programs (e.g. ABN Amro, Rabobank), because they are cheaper and easier to deploy.

The Future of Authentication

Many countries are now recognising the benefits of moving towards a smart-card based authentication. As the January 2005 deadline for EMV migration in Europe has now passed, and the compliance deadline for regions including the Middle East, Africa and Asia-Pacific is less then five months away in January 2006, banks are recognising the considerable leverage on investment of deploying solutions that rely on EMV.

Major players in the retail banking sector are already putting research and development into strong, authentication solutions. MasterCard, together with a major UK bank recently conducted a pilot of portable EMV card readers, including XIiring’s Xi-Sign range, as a means to authenticate customers who access banking services online. In addition, APACS has indicated that it began work in May 2005 to establish a UK standard for physical online transaction authentication. The forecast from APACS is that within six to nine months, this new online security system is expected to be fully implemented within certain retail banking sectors.

Roll out of strong, two-factor authentication is not limited to the banking and financial services industry. Xiring has worked closely with the Aquitaine Cancerology Network in France on the implementation of an authentication solution, based on the CPS card, to enable health care professionals to secure remote access to confidential medical files. The deployment has been very successful, and roll-out of similar schemes looks set to become the standard across France, setting an example to the rest of Europe, and the world.

Retailers would also be wise to take heed of the two-factor authentication solutions available and install the systems on their sites, enabling them to process card transactions online and via call centres securely. Last year, online theft during card purchases accounted for £117m of the UK’s card-not-present fraud, and of this, the retailers themselves bore the greatest loss.

Whitepapers & Resources

2021 Transaction Banking Services Survey
Banking

2021 Transaction Banking Services Survey

5y
CGI Transaction Banking Survey 2020

CGI Transaction Banking Survey 2020

6y
TIS Sanction Screening Survey Report
Payments

TIS Sanction Screening Survey Report

7y
Enhancing your strategic position: Digitalization in Treasury
Payments

Enhancing your strategic position: Digitalization in Treasury

7y
Netting: An Immersive Guide to Global Reconciliation

Netting: An Immersive Guide to Global Reconciliation

8y