Deciphering Multifactor Authentication: Strategies for Banks
Multifactor authentication (MFA) is the talk of the town. The Federal Financial Institutions Examination Council’s (FFIEC’s) guidance has presented financial institutions with a major dilemma – how to effectively deploy and manage one or more electronic banking authentication solutions for multiple customer segments. At first glance, this may seem like a simple project. However, this initiative requires far more than a glance. It is a multi-dimensional effort and a major decision for financial institutions.
Interestingly, the talk has focused on retail online banking due to the sheer volume of customers this would affect. Additionally, retail considerations have thrown banks a curve – certain types of multifactor authentication can damage the customer experience. However, it is important to note that the guidance affects not only retail online banking but all forms of electronic banking across all customer segments. What type of impact does this all have on small businesses? What are banks going to provide to midsize and large corporate clients? Banks have to firm up their decision-making for all customer segments. They need to move forward with effective solutions that will satisfy the FFIEC, preserve the user experience, and provide an additional level of security.
Banks scrambled to put appropriate measures in place to mitigate the risk of electronic banking. Although banks have had since October 2005 to begin working on a response to the FFIEC guidance, many are stuck in a rut and did not meet the end of 2006 deadline. Why did this happen? How can they effectively plan solutions that will satisfy the requirements of retail customers, small businesses, and corporate customers?
In August 2006, Celent published the report, ‘North American Bank Priorities: Convention or Innovation?’ The report examines and analyzes – through the eyes of bank CIOs – bank IT and business priorities. Given the large emphasis placed on IT security, specific questions were directed at banks regarding their security practices. Not surprisingly, when asked to list their top three IT security priorities, 50% of banks mentioned MFA as their top priority. One would assume that such banks would be on top of the situation. Alas, priorities do not always translate into actions, and banks are often slow to respond to evolving marketplaces.
This lack of action is further witnessed when examining actual and planned solution deployment. As of August 2006, only 7% of banks had rolled out MFA solutions geared at small business online customers. This figure was expected to rise to 25% by the end of 2006. Corporate online banking/cash management fared far better with 50% of banks ready with an actual solution. There is, however, a reason that the figures for corporate users are higher than those of small business. Many banks have been supplying devices, such as tokens to corporate cash management users, for some time (used primarily as a form of authentication upon the release of a wire transfer). Given that the infrastructure and interfaces are in place already within the application, it is relatively straightforward for banks to adapt this to the login process. But the fact is that some banks are stuck in the planning and/or decision-making process.
Why has the FFIEC guidance thrown banks into a state of confusion? Why are banks so hesitant about deploying MFA? There are numerous reasons why banks were not able to meet the end of year 2006 deadline and they extend beyond being unable to properly segment their customer base and determine future banking requirements:
Whether they like it or not, banks must overcome their reluctance and see the bigger picture. A single username and 10-year-old password just doesn’t cut it anymore, nor should they. Banks have to accept that now is the time to implement multifactor authentication for all forms of electronic banking across all customer segments. MFA is an investment in customer protection and a cost of doing business for banks.
The overwhelming majority of financial institutions have a varied client base spanning retail, small business, midsize and large corporate clients. Although banks do tend to lean one way or another, they are conscious of being able to accommodate all client types. Additionally, banks that are weak or not focused on a particular segment may want to attack new markets or improve their offering over time. Thus it would be shortsighted, for example, for retail focused banks to select an MFA solution specifically for retail clients and automatically assume that it would serve all customer segments. The same can be said for a wholesale-focused bank that has been using technology tokens for some time and wants to apply them to all parts of its operation, including retail.
There may be a ‘catch-all’ solution, but it requires the bank to start from the ground up and put aside their bias based on what they currently have in place. In fact, certain banks will be able to find a catch-all solution to serve their needs once they go through a detailed risk assessment and vendor evaluation process. The key is not to get hung up on what is already in place at the bank; those trusty tokens, for example, may not be the best long-term solution for the client. The best place to start is at the bottom – knowing who your customers are. Banks need to define customer segments and decide what bucket customers belong in. For instance, how is a small business client defined by the bank?
Banks need to be methodical when selecting an MFA solution. They are presently attempting to determine their present and future MFA requirements before they understand who their customers are and what they require. Unfortunately, due to time constraints, absence of advanced analytical tools, and a lack of dedicated small business banking platforms, most banks are treating MFA as a stand-alone project and are not following an order.
Banks must pay careful attention to the segments they are defining and take care to focus on future banking and customer requirements when selecting an MFA solution. A focus on expendability and flexibility is paramount. The security challenges faced by banks today will not be the challenges they meet tomorrow. Banks cannot predict the future, but they will have to anticipate it by having the flexibility to grow and expand their security requirements as challenges evolve.
Numerous permutations and combinations of MFA options exist. It is important to note that banks will most likely and should choose more than one of the MFA options available to them. Banks will want to employ a layered MFA approach. This will allow the bank to devise a comprehensive MFA program that can meet a wide variety of needs. For example, a bank may choose a mutual authentication solution for all customer segments in which the client pre-selects an image and a familiar phrase. This solution may also analyze the user’s computer for certain items (e.g. IP address, location) to recognize the person logging in. In addition, the bank may choose to distribute tokens to business clients who are conducting large-value transactions.
Some banks may also choose to take advantage of a risk-based monitoring solution in order to track user behavior and patterns and throw out challenge questions in the event that the system detects an anomaly. MFA choices will vary depending on transactional risk, mix of banking platforms, disturbance threshold, and the existing use of a particular technology (e.g. tokens).
Once options are chosen, banks have to work on selling the concept to its client base. This is key to adoption and acceptance. Banks will need to promote MFA at industry conferences, launch contests and promotions, offer solutions free of charge, and work on overall customer education.