 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Reality &#187; phish</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/regulatory-compliance/tag/phish/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/regulatory-compliance</link>
	<description>A SearchFinancialSecurity.com blog</description>
	<lastBuildDate>Wed, 06 Mar 2013 17:19:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Has PayPal lost its collective mind?</title>
		<link>http://itknowledgeexchange.techtarget.com/regulatory-compliance/has-paypal-lost-its-collective-mind/</link>
		<comments>http://itknowledgeexchange.techtarget.com/regulatory-compliance/has-paypal-lost-its-collective-mind/#comments</comments>
		<pubDate>Tue, 21 Aug 2012 14:21:42 +0000</pubDate>
		<dc:creator>David Schneier</dc:creator>
				<category><![CDATA[checking account]]></category>
		<category><![CDATA[checks]]></category>
		<category><![CDATA[credit]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[identify theft]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[NPPI]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[password theft]]></category>
		<category><![CDATA[phish]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[regulations]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/regulatory-compliance/?p=964</guid>
		<description><![CDATA[I&#8217;m not much of a shopper.  I decide what it is I need/want to buy, assess the market place to determine quality and price and once I have a generally strong sense for both make a decision and move forward.  My wife on the other hand loves the constant trolling, scouring and scouting of just [...]]]></description>
				<content:encoded><![CDATA[<p>I&#8217;m not much of a shopper.  I decide what it is I need/want to buy, assess the market place to determine quality and price and once I have a generally strong sense for both make a decision and move forward.  My wife on the other hand loves the constant trolling, scouring and scouting of just about any market and any product therein to find bargains, deals and steals.  So for her eBay has been among the happiest distractions ever.  She&#8217;s a bit of a night owl and after spending the first few decades of life being handcuffed by traditional store hours has found both eBay and the Internet to be the great equalizer.  And it&#8217;s difficult to think of eBay without also thinking of its most important business partner PayPal, an online payment processor that has for all intents and purposes revolutionalized the way we spend our money.</p>
<p>Our family has had a PayPal account almost since PayPal has offered them.  It&#8217;s remarkably convenient, it provides us great flexibility to shop online using a single payment source and I love that we&#8217;ve been able to change funding sources several times over the years.  It&#8217;s always conveyed a certain sense of security; I&#8217;ve just always felt safe using PayPal.  I&#8217;ve even gone so far as to suggest that at some point, if PayPal management grows things just right I could see a future state where paper currency and maybe even actual physical credit cards go away and are replaced by some version of their services.  When I discovered this past year that Home Depot already allows you to use PayPal to make in-store purchases I was convinced I was right.  Now I&#8217;m not so sure.</p>
<p>Over the past year or so I&#8217;ve been getting the occasional email ping from PayPal regarding our reaching a spending limit.  It&#8217;s a fairly high limit for most but considering that we&#8217;ve been using PayPal to make purchases going back nearly a decade maybe not as much.  But the message has been quite clear; if we didn&#8217;t verify our account before reaching this limit it would be &#8220; the maximum amount of money you can send or use for purchases before you need to become Verified&#8221;.   So how you become verified is quite simple &#8211; either give up your bank account information or apply for a privately owned credit card.  No, seriously, those are the only two options.</p>
<p>My first thought was that although I liked having the protective layer of a credit card product buffering my PayPal account from my actual money I was okay with providing bank account information.  It&#8217;s not like I don&#8217;t use that in other places to make payments and so there wouldn&#8217;t be any enhanced risk by doing so again.  I wasn&#8217;t going to apply for a PayPal-based credit card because I don&#8217;t want one or need one and I wasn&#8217;t looking for a new credit source anyway, I just wanted to continue using PayPal.  I clicked on the option to provide my bank account information and after the initial screen where they ask for the routing and account details and clicking on &#8220;Submit&#8221; I was presented with a screen that I still can&#8217;t believe exists.  Right there before my eyes was a screen from PayPal in which they ask me to provide my online banking user-id and password so they can verify a series of PayPal generated payments thus confirming my banking details.  Let me repeat that one more time; PayPal asked me to provide them with my online banking user-id and password.</p>
<p>Has PayPal lost its collective mind?  Seriously, have they?</p>
<p>I was stunned, almost to the point where I couldn&#8217;t get coherent words to flow.  I immediately fired off an email to PayPal customer support asking them how they could do something so outrageous.  Within minutes I received an automatically generated reply which I always find insulting, as if though I&#8217;m not worth an actual intelligent and personal response.  It was a complete regurgitation of everything stated on their website and completely ignored the gist of my email.  I fired off a second email missive, this time way more specific.  Here&#8217;s what I wrote:</p>
<div><em>&#8220;How can you ask customers for their user-id and password for their online banking?  Surely this must be either a scam run by hackers and not a legitimate request by your company or a misunderstanding on my part.&#8221;</em></div>
<div></div>
<div>That was more than a week ago, they haven&#8217;t responded.</div>
<div></div>
<div>Let me just go right out there on that limb and state unequivocally that there is never any reasons whatsoever to share something as sensitive as your online banking user-id and password with anyone, ever!  PayPal needs to immediately revisit their business model and eliminate such an egregious requirement.  Seriously, what&#8217;s the point of doing what it is that I and my fellow practitioners do to make sure that PII and NPPI is being properly protected by financial institutions when one of the largest payment processors in the world is collecting the most sensitive of information?  They don&#8217;t need it, you shouldn&#8217;t be required to provide it and they should be forced to stop asking for it!  Shouldn&#8217;t this sort of thing be regulated by somebody?  Anybody?</div>
<div></div>
<div></div>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/regulatory-compliance/has-paypal-lost-its-collective-mind/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Vishing, Smishing and Phishing: No end in sight.</title>
		<link>http://itknowledgeexchange.techtarget.com/regulatory-compliance/vishing-smishing-and-phishing-no-end-in-sight/</link>
		<comments>http://itknowledgeexchange.techtarget.com/regulatory-compliance/vishing-smishing-and-phishing-no-end-in-sight/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 19:41:18 +0000</pubDate>
		<dc:creator>David Schneier</dc:creator>
				<category><![CDATA[assessment]]></category>
		<category><![CDATA[Audit]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[NCUA]]></category>
		<category><![CDATA[phish]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[red flags]]></category>
		<category><![CDATA[red flags identity theft]]></category>
		<category><![CDATA[regulatory]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[smish]]></category>
		<category><![CDATA[smishing]]></category>
		<category><![CDATA[vish]]></category>
		<category><![CDATA[vishing]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/regulatory-compliance/?p=828</guid>
		<description><![CDATA[This is something akin to my annual public service announcement (PSA) for anyone who has cash-on-hand, a bank account, an investment account or perhaps even a piggy bank:  As long as you have money there's someone out there right now scheming to try and take it away from you.]]></description>
				<content:encoded><![CDATA[<p>This is something akin to my annual public service announcement (PSA) for anyone who has cash-on-hand, a bank account, an investment account or perhaps even a piggy bank:  As long as you have money there&#8217;s someone out there right now scheming to try and take it away from you.</p>
<p>I&#8217;m having that kind of month right now where I&#8217;ve been learned of one scheme after another to separate people I know personally from their hard earned money.  And much to my chagrin, the schemers are enjoying some measure of success.</p>
<p>Last week I was regaled by a tale of how a senior citizen was stopped on her way to the bank to have a cashiers check drawn for $500.  She needed it because someone contacted her with an offer that was impossible to ignore or turn down.  If she paid for the modest bank fees for a large international wire transfer she could keep a small percentage as a &#8220;thank you&#8221; gift, a mere $2M (yeah, that&#8217;s two million).  The people who contacted her did so because she was recommended as a trusting resource who would be flexible and work with them.  And so the combination of the compliment and the chance to net a nifty seven-figure profit for a simple enough favor was just good enough to make her want to do it.  Fortunately she ran into a friend who happened to ask her where she was off to and when she answered honestly was more or less forcibly snapped back to reality.</p>
<p>Now to be honest with you I was stunned to learn that this scam ever works.  I&#8217;ve long advocated to friends and family that they should respond to electronic offers exactly the same way as if though they received it in the mail.  But while we throw out junk mail automatically we&#8217;ll read sometimes very cleverly worded emails because they look authentic.  But if you filter all electronic email through the same logic that has taught us to toss mass marketing materials you can cut out much of the clutter.  But what if that email finds someone who is perhaps a little lonely or a little desperate?  What if that email finds someone who is willing to roll the dice that just once what appears to be a scam might be the real thing?  I wouldn&#8217;t have thought it possible until last week but sometimes it works.  And when you think about it just a little bit more it&#8217;s the perfect scam.  Once a senior citizen falls prey to the trap and comes to realize they&#8217;ve been had many will keep it to themselves both because they&#8217;re embarrassed and as I&#8217;ve come to learn more recently, out of fear that they&#8217;ll be labeled as losing their facilities.  And while not all seniors are wealthy a sizable enough percentage have access to $500 easily enough.</p>
<p>Then this week a story was shared with me about how someones identify was stolen but with a twist.  They didn&#8217;t try and completely take over the identity but rather borrow it.  The man-in-the-middle attack worked as such: Person A routinely communicates with Person B via email and instant messenger because they&#8217;re on opposite sides of the world with a language barrier and about twelve hours separating them.  The electronic communications reduces the impact of the language barriers and allows them to keep in touch outside of the boundaries of a shared work day.  This has proven successful for both Person A and Person B for several years.  Recently Person B asked for special handling of a payment that while unusual within the designs of their business relationship was not otherwise out of the ordinary when dealing with others in the same country &#8211; Person A agreed to the request.  After several back-and-forth communications to arrange for the payment which spanned several days Person A sent an email asking Person B to confirm that they finally received the payment.  Person B responded by asking &#8220;what payment?&#8221;.</p>
<p>Someone had hacked into Person B&#8217;s account and was intercepting emails and instant messages and assuming that identity.  They still allowed most communications to pass through but successfully filtered out anything having to do with the payment from Person A.  So Person B had no idea there was something amiss and Person A saw very little outside of  normal communications.  But apparently that one time the hacker must have been off their game and not paying attention and so the two legitimate parties were made aware of the situation.  A long painful phone call ensued and some amateur detective work confirmed their suspicions.  And so a new version of phishing comes into play, one in which the scam is not so apparent or easy to detect.</p>
<p>That&#8217;s the thing, while there may be rules to how the scams are being run today those rules are ever changing.  You can&#8217;t simply look for one telltale sign that something is amiss because once a trend emerges the hackers change things up.  And while financial institutions and a multitude of agencies are always trying to educate the masses about the perils lurking about it seldom penetrates into peoples way of thinking.  The popular adage about suckers has never been truer only now there are two to the power of X ready to take them.  There are increasing measures available to counter attack some of these scams (e.g. Red Flags &#8211; Identity Theft) but by and large they go undetected or unreported.</p>
<p>So here&#8217;s the sum total of my PSA: If it seems too good to be true it is.  And if any financial dealing is presented where something is out of the ordinary apply the old audit mantra &#8211; trust but verify.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/regulatory-compliance/vishing-smishing-and-phishing-no-end-in-sight/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online identify theft: One victim&#8217;s story</title>
		<link>http://itknowledgeexchange.techtarget.com/regulatory-compliance/identify-theft-one-victims-story/</link>
		<comments>http://itknowledgeexchange.techtarget.com/regulatory-compliance/identify-theft-one-victims-story/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 14:24:58 +0000</pubDate>
		<dc:creator>David Schneier</dc:creator>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[id theft]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[password theft]]></category>
		<category><![CDATA[phish]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security awareness]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/regulatory-compliance/?p=329</guid>
		<description><![CDATA[Because whether it be the result of a successful phishing attempt, poor judgement or sloppy controls (e.g. post-it notes under the keyboard/phone/stapler, etc.) the number one entry point used by hackers to gain access to sensitive information remains password sharing.]]></description>
				<content:encoded><![CDATA[<p>Last month I blogged about a phishing attempt that landed in my inbox.  The email account belonged to someone named Rebecca Keen who I had never heard of before (or so I believed at the time).  As I was finishing writing that post, I received a follow-up email from the same person indicating that all was well, that her account was hacked and asked that no one respond to the original phishing email.  As it turned out, Rebecca Keen was actually someone in my extended network, courtesy of a PTA email thread that I was part of.  Because she used Yahoo mail and went with their default settings, all of her outbound email addresses were added to her address book and so I was one of her contacts.</p>
<p>Ms. Keen was kind enough to share her story with me so that I in turn could share it with you.</p>
<p>Her bad day started with the most basic error in judgement: She responded to a Yahoo-branded email requesting that she confirm her account information or else her account would be closed.  She said that &#8220;despite my initial instincts, I fell for it.&#8221;  It&#8217;s not hard to understand why.  Like most parents with school-age children, she has too much going on, depends on email to keep things moving and if she is anything like my wife, is of a mind to address things as they arise; she was a perfect target for a hacker.</p>
<p>Ms. Keen first became aware that she was about to have a bad day when she received an early morning phone call from a friend indicating they&#8217;d received an email from her asking for help.  She attempted to sign on to her Yahoo account to see what was going on but the hackers had changed her password and she was locked out.  She explained what happened next:</p>
<p>&#8220;<em>I had to wait for Yahoo to open at 9:00am to resolve the issue and regain access to my account.  Yahoo was extremely helpful and we were able to take the account back quite easily.  The representative I spoke with knew to advise me to confirm if any of my personal information had been changed, which it had.  An alternate email address had been added by the hacker as a way to retain control of my account even after I had gotten back in.  And my understanding is this is how they would continue to log in and check to see if anyone was actually trying to send me money.  If I did not know to delete this alternate email, the hackers could continue to monitor the account and target anyone asking me where to send the money</em>.&#8221;</p>
<p>I asked her if anyone actually attempted to send money or respond favorably to the hacker&#8217;s phishing attempt and fortunately no one had.  While she did receive a few calls and/or emails trying to confirm if the request was legitimate, because as Ms. Keen explained, &#8220;<em>They did indeed want to help me if I really needed it,&#8221;</em> no one actually took further action.  Apparently the majority of people who received the phishing attempt knew it was a hoax and ignored it (score one for security awareness in the private sector).</p>
<p>Was there a lesson learned from all of this for Ms. Keen to share?</p>
<p>&#8220;<em>Do not respond to emails requesting personal account information, no matter how reputable they may seem,&#8221; </em>she said.  &#8221;<em>As Yahoo explained, they would never request that sort of account information from me (they already have it and there is no need for it to be confirmed).&#8221;</em></p>
<p>To which I would add that you could easily replace the Yahoo name with literally any reputable business with which you have an online account.  I would also recommend that you print Rebecca Keen&#8217;s advice and tape it to your monitors and keyboards at both work and home for all to see.  Because whether it be the result of a successful phishing attempt, poor judgment or sloppy controls (e.g. sticky notes under the keyboard/phone/stapler, etc.) the number one entry point used by hackers to gain access to sensitive information remains password sharing.</p>
<p>Check back here next week. I have an interesting (if not scary) story to share about how some financial institutions are (mis)managing regulatory requirements.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/regulatory-compliance/identify-theft-one-victims-story/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Something smells phishy</title>
		<link>http://itknowledgeexchange.techtarget.com/regulatory-compliance/something-smells-phishy/</link>
		<comments>http://itknowledgeexchange.techtarget.com/regulatory-compliance/something-smells-phishy/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 20:18:30 +0000</pubDate>
		<dc:creator>David Schneier</dc:creator>
				<category><![CDATA[email]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[phish]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[scammer]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[theft]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/regulatory-compliance/?p=305</guid>
		<description><![CDATA[P.T. Barnum was often credited with having said that "There's a sucker born every minute" and apparently online there are somewhere between two and too many scammers waiting to take 'em.]]></description>
				<content:encoded><![CDATA[<p>I received an email from Rebecca Keen this morning asking for help.  You see, Rebecca took an unexpected trip to the UK and while there lost her wallet and all of her financial resources and was hoping I could help.  She asked if I could float her a temporary loan of $1,540 so she could settle her hotel bill and make it back home safely.  It turns out that all of her other possible avenues for assistance have failed her and I&#8217;m something of a last resort.</p>
<p>Of course I don&#8217;t know anyone by the name Rebecca Keen and knew instantly that it was a phishing scam. It&#8217;s not the email by itself that made this a blog-worthy item.  What made Rebecca&#8217;s email this week&#8217;s topic was the reaction of someone close to me and their attitude about how to handle it.</p>
<p>At the risk of embarrassing anyone, I won&#8217;t go into specifics as to who the person is, but when I told them about the email as a way of educating them on how to identify and manage phishing attempts, they asked me how I knew it wasn&#8217;t legitimate.  Beyond the obvious fact that I don&#8217;t know now and have never known anyone by that name I&#8217;m not sure what else I&#8217;d need as proof this was a scam.</p>
<p>Here was the ensuing exchange:</p>
<p>&#8220;That may be true but what if they sent you the email by accident?  What if they misspelled the email address?&#8221;</p>
<p>To which I replied, &#8220;Still not my problem and I won&#8217;t respond because that establishes a dialogue which will only encourage the person further.&#8221;</p>
<p>&#8220;But shouldn&#8217;t you at least let the person know they reached the wrong person,&#8221; I was asked with a tinge of real concern.</p>
<p>&#8220;If I reply, that will send the message that they reached the right person. They&#8217;ll think I care, which will only open me up to additional pressures from the scammer&#8221;.</p>
<p>&#8220;People are so mistrusting these days.  I&#8217;d at least want to make sure this wasn&#8217;t someone who needed my help&#8221;.</p>
<p>And therein lies the problem: Despite this being a very obvious phishing attempt, it was only obvious to me. Despite the endless stories about people being exploited and robbed by an endless array of online and email scams, there are still people who respond favorably to these sort of things because of their basic decency. The person to whom I was talking wasn&#8217;t lacking in intelligence and isn&#8217;t typically naive, but when presented with these situations uses a different set of rules.</p>
<p>To make matters worse, the email from Rebecca Keen was properly formatted without spelling errors and actually looked like something I might receive from a legitimate source.  As a matter of fact, it presented itself so well that I actually opened it, which is a step further along than these things usually get.  But of course I knew instantly that it was just the latest example of how people are using the Internet to try and steal money.  And while the scam was obvious to me, there is at least one person I know who might actually have taken action upon receiving something similar.</p>
<p>You know what occurred to me today?  The reason that scammers continue to send out phishing emails is because they still generate the desired results.  Despite the endless marketing campaigns by a wide range of financial institutions to educate online users, there are still a large enough number of people who are victims waiting to happen.   And as long as even one person responds favorably to a phishing campaign, it&#8217;s considered a success.</p>
<p>I&#8217;m thinking that as a former New Yawker I should create a program for the FDIC based on my experiences growing up in New York City.</p>
<ul>
<li>Do not engage in any dialogue with anyone you don&#8217;t know about money in an unusual or inappropriate setting e.g. street corners, subway platforms, etc.</li>
<li>If someone is selling something, offering to buy something or trying to distract you somehow when in an unusual or inappropriate setting (e.g. stopping you on the street, walking up to your table at a restaurant, etc.) immediately disengage and continue on your way or return to what you were doing without allowing the conversation to develop and/or continue.</li>
<li>And if at any time your instincts tell you that something is wrong, amiss, out of place or odd err on the side of caution and do everything and anything to remove yourself from that situation.</li>
</ul>
<p>P.T. Barnum was often credited with having said that &#8220;There&#8217;s a sucker born every minute&#8221; and apparently online there are somewhere between two and too many scammers waiting to take &#8216;em.</p>
<p>P.S. As I was about to publish this post I received an email update from Rebecca Keen letting me know that someone temporarily stole her email account and that there&#8217;s no emergency whatsoever.   Glad to hear it but I still have no clue who she is.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/regulatory-compliance/something-smells-phishy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How security aware is your organization?</title>
		<link>http://itknowledgeexchange.techtarget.com/regulatory-compliance/how-security-aware-is-your-organization/</link>
		<comments>http://itknowledgeexchange.techtarget.com/regulatory-compliance/how-security-aware-is-your-organization/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 03:57:03 +0000</pubDate>
		<dc:creator>David Schneier</dc:creator>
				<category><![CDATA[Audit]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[NCUA]]></category>
		<category><![CDATA[phish]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security testing]]></category>
		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/regulatory-compliance/?p=270</guid>
		<description><![CDATA[It's February 2010, do you know when was the last time your organization conducted a social engineering exercise?]]></description>
				<content:encoded><![CDATA[<p>Consider this post to be something of a (banking) community service announcement.</p>
<p>It&#8217;s February 2010, do you know when the last time was that your organization conducted a social engineering exercise?</p>
<p>I come across instances almost all of the time where financial institutions have obvious issues with regards to their staff and how they handle sensitive information.  I almost always find non-public personal information (NPPI) left unsecured on desktops, in printer/fax queues and displayed on computer monitors.  I can recall at least a half-dozen instances during the past year where I personally witnessed person-to-person exchanges where proper protocol was not followed in handling situations that are now supposed to be governed by the <a href="http://searchfinancialsecurity.techtarget.com/sDefinition/0,,sid185_gci1374703,00.html" target="_blank">Red Flags rule</a>.</p>
<p>It&#8217;s not hard to understand why these things happen; it involves human nature and that&#8217;s a wild card element that can&#8217;t be easily managed or controlled.  People are busy, people are inherently trusting and in their haste to help a customer or get their work completed, they lower their guard.  But it&#8217;s in those moments when good judgement is pushed to the side that an institution is most vulnerable.</p>
<p>A password is shared, a sensitive document is left exposed or a file loaded with account information is carted off on a USB storage device.  Ultimately, how it happens is never really the big story though, at least not for those impacted by the breach.  For the affected, it&#8217;s all about the damage, both potential and realized, that they&#8217;re confronted with.  And of course it then also becomes about the tarnished reputation of the institution connected to the breach.</p>
<p>Do something about it.</p>
<p>Schedule a social engineering exercise; it&#8217;s easy, it&#8217;s affordable and it works.  It tests the effectiveness of your security awareness program(s), illuminates what&#8217;s working and what&#8217;s broken, and allows you to adjust your training accordingly.  And you can vary the angles taken from year to year.  Start by seeing what happens when someone places calls to your staff trying to get them to share sensitive information.  Follow that up by doing the same with emails.  When you conduct your next internal vulnerability assessment, have the project include having the testing resources access secured facilities.  You can also mix in dumpster diving (a favorite of mine), fax phishing and eavesdropping (don&#8217;t laugh, it&#8217;s a great way to skim NPPI and impossible to trace).</p>
<p>The results will prove to be revealing &#8211; both good and bad &#8211; and will serve as remarkably effective fodder for your next round of training.  And the testing itself becomes an important tool because once people are aware that these tests are occurring, they begin to pay greater attention to their action. No one want to be tagged as being on the wrong side of the testing &#8211; trust me on this, I&#8217;ve seen this dynamic in play and it&#8217;s real.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/regulatory-compliance/how-security-aware-is-your-organization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
