<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>BankInfoSecurity.co.uk  RSS Syndication</title>
<link>http://www.bankinfosecurity.co.uk/rssFeeds.php?type=main</link>
<description>BankInfoSecurity.co.uk RSS News Feeds on bank information security news, regulations, blogs and education</description>
<pubDate>Mon, 28 May 2012 18:26:39 -0500</pubDate>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/bankinfosecurity/uk" /><feedburner:info uri="bankinfosecurity/uk" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
			<title>Attack Highlights Third-Party Risks</title>
			<link>http://www.bankinfosecurity.co.uk/attack-highlights-third-party-risks-a-4801</link>
			<guid>http://www.bankinfosecurity.co.uk/attack-highlights-third-party-risks-a-4801</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4801_artid_4801_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Hack of Online Billing Provider May Have Exposed 500,000 Cards&lt;/b&gt;&lt;br&gt;The hack of online billing provider WHMCS may have exposed 500,000 payment cards. Experts say the incident highlights the persistent risks third parties pose in cardholder data security.</description>
			</item>
			<item>
			<title>Insider Case Exposes Security Lapses</title>
			<link>http://www.bankinfosecurity.co.uk/insider-case-exposes-security-lapses-a-4798</link>
			<guid>http://www.bankinfosecurity.co.uk/insider-case-exposes-security-lapses-a-4798</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4798_artid_4798_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Bank Manager Pleads Guilty to Theft&lt;/b&gt;&lt;br&gt;A former PNC Bank manager has pleaded guilty to bank theft - a charge that could lead to 10 years in prison and a $250,000 fine. What common security flaws allow such insider schemes to flourish?</description>
			</item>
			<item>
			<title>Social Engineering: Mitigating Risks</title>
			<link>http://www.bankinfosecurity.co.uk/social-engineering-mitigating-risks-a-4795</link>
			<guid>http://www.bankinfosecurity.co.uk/social-engineering-mitigating-risks-a-4795</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4795_omurchu_liam_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Symantec Recommends Mix of Tech, Education&lt;/b&gt;&lt;br&gt;Why are socially engineered schemes causing so many headaches? Symantec's new Internet Security Threat Report shows attacks are growing. Here's a list of Symantec's recommendations to thwart risks.</description>
			</item>
			<item>
			<title>Anonymous Hacks Justice Dept. Database</title>
			<link>http://www.bankinfosecurity.co.uk/anonymous-hacks-justice-dept-database-a-4794</link>
			<guid>http://www.bankinfosecurity.co.uk/anonymous-hacks-justice-dept-database-a-4794</guid>
			<description>&lt;img src="http://docs.bankinfosecurity.com/files/images_articles/4794_anonymous_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Bureau of Justice Statistics Information Leaked&lt;/b&gt;&lt;br&gt;The hacktivist group Anonymous says it has stolen 1.76 GB of data from a United States Bureau of Justice Statistics server and posted it online for download. What's the rationale behind this latest attack?</description>
			</item>
			<item>
			<title>ENISA: Guidelines on Incident Reporting</title>
			<link>http://www.bankinfosecurity.co.uk/agency-releases/enisa-guidelines-on-incident-reporting-r-2611</link>
			<guid>http://www.bankinfosecurity.co.uk/agency-releases/enisa-guidelines-on-incident-reporting-r-2611</guid>
			<description>ENISA has issued guidelines to national telecom regulatory authorities about the implementation of Article 13a, in particular, the two types of incident reporting mentioned in Article 13a: the annual summary reporting of significant incidents to ENISA and the European Commission and ad hoc notification of incidents to other NRAs in case of cross-border incidents.</description>
			</item>
			<item>
			<title>ENISA: Technical Guidelines on Minimum Security Measures</title>
			<link>http://www.bankinfosecurity.co.uk/agency-releases/enisa-technical-guidelines-on-minimum-security-measures-r-2610</link>
			<guid>http://www.bankinfosecurity.co.uk/agency-releases/enisa-technical-guidelines-on-minimum-security-measures-r-2610</guid>
			<description>ENISA has issued guidance to national telecom regulatory authorities about the implementation of Article 13a, in particular about the security measures that providers of public communications networks must take to ensure security and integrity of these networks.</description>
			</item>
			<item>
			<title>ENISA Launches Information Security Awareness Videos</title>
			<link>http://www.bankinfosecurity.co.uk/agency-releases/enisa-launches-information-security-awareness-videos-r-2598</link>
			<guid>http://www.bankinfosecurity.co.uk/agency-releases/enisa-launches-information-security-awareness-videos-r-2598</guid>
			<description>The European Network and Information Security Agency [ENISA] has launched information security awareness videos in 23 European languages.</description>
			</item>
			<item>
			<title>ENISA Launches Guide on Building Effective IT Security Public Private Partnerships</title>
			<link>http://www.bankinfosecurity.co.uk/agency-releases/enisa-launches-guide-on-building-effective-security-public-r-2567</link>
			<guid>http://www.bankinfosecurity.co.uk/agency-releases/enisa-launches-guide-on-building-effective-security-public-r-2567</guid>
			<description>The European Network and Information Security Agency has released a new guide on building effective IT security public private partnerships.</description>
			</item>
			<item>
			<title>Synovus Bank Eliminates Cybercrime - A Case Study</title>
			<link>http://www.bankinfosecurity.co.uk/webinars/synovus-bank-eliminates-cybercrime-case-study-w-277</link>
			<guid>http://www.bankinfosecurity.co.uk/webinars/synovus-bank-eliminates-cybercrime-case-study-w-277</guid>
			<description>Synovus Bank, one of the largest community banks in the southeast, offers Online Cash Management services to its commercial clients with a simple pledge: "The freedom to manage your cash position anytime, anywhere." After witnessing relentless cyber-attacks on the endpoints of end users, Synovus Bank knew that meeting this pledge required them to take action. The bank's Product Development team carefully selected an endpoint security solution that met their requirements:&lt;p&gt;&lt;ul&gt;
&lt;li&gt;Satisfying FFIEC Guidelines&lt;/li&gt;
&lt;li&gt;Low customer impact/Ease of installation&lt;/li&gt;
&lt;li&gt;Proven effective, quick to implement and easy to manage&lt;/li&gt;
&lt;li&gt;Complement the bank's two tier security architecture&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;
Hear how Synovus Bank proactively prevents fraud. Kevin Gibson, Director of Product Development at Synovus Bank, explains the challenges they faced, why Trusteer Rapport was the right fit, and its ease-of-deployment. He also discusses how Trusteer's layered security helps them protect against cybercrime, as well as Trusteer's role in enabling compliance with the latest FFIEC guidance. Trusteer's Director of Product Marketing, Oren Kedem will describe Trusteer's Cybercrime Prevention Architecture and how it stops online banking fraud.</description>
			</item>
			<item>
			<title>2012 Cloud Security Agenda: Expert Insights on Security and Privacy in the Cloud</title>
			<link>http://www.bankinfosecurity.co.uk/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</link>
			<guid>http://www.bankinfosecurity.co.uk/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</guid>
			<description>What are organizations' top cloud security concerns, and how are security leaders addressing these concerns through policy, technology and improved vendor management?
&lt;p&gt;&lt;p&gt;
This is the key question posed by the 2012 Cloud Security Survey.
&lt;p&gt;
No longer just an emerging technology practice, cloud computing today is embraced globally as a means of gaining efficient access to critical applications, processes and storage. It's now common for organizations to rely on cloud service providers for functions and business applications such as customer relationship management, messaging or storage via a public, private or hybrid cloud. Further, industry-specific cloud-based applications such as electronic health records or mobile banking and payment applications are emerging at an unprecedented pace.
&lt;p&gt;
But these engagements come with questions about risks:
&lt;ul&gt;
&lt;li&gt;What are your cloud service provider's security and privacy measures, and have they been audited?&lt;/li&gt;
&lt;li&gt;Where geographically is cloud data being stored, and how do operational practices comply with government, industry and organizational privacy regulations?&lt;/li&gt;
&lt;li&gt;How is a multi-tenant cloud environment managed, and in the event of system compromise - what will be the incident response escalation process?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
Yes, cloud computing is about efficiencies and new technologies, but it's also about security, privacy and an organization's reputation.
&lt;p&gt;
The 2012 Cloud Security Survey was crafted with assistance from leading experts in cloud computing, security and privacy, with a mission to:
&lt;ul&gt;
&lt;li&gt;Chart the latest cloud trends, including types of cloud implementations most common by industry and region;&lt;/li&gt;
&lt;li&gt;Gauge organizations' top cloud security concerns, from vendor security to data governance and breach preparedness;&lt;/li&gt;
&lt;li&gt;Predict the top areas of investment for organizations most concerned about cloud security.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
This webinar will draw upon survey results and expert insight from a special roundtable panel to discuss:
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Top Security Concerns&lt;/b&gt; - Are organizations more concerned about where their data is stored, or whether a malicious insider might be a threat to it?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Success Factors&lt;/b&gt; - On a scale with cost savings and availability of services, how does security now rank among elements critical to a successful cloud computing implementation?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Protective Measures&lt;/b&gt; - What are some of the practices organizations are employing, from instituting more stringent contracts to enforcing third-party audits and even participating in mock security exercises with cloud service providers?&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>2012 Faces of Fraud Survey: Complying with the FFIEC Guidance</title>
			<link>http://www.bankinfosecurity.co.uk/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</link>
			<guid>http://www.bankinfosecurity.co.uk/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</guid>
			<description>A follow-up to ISMG's 2011 Faces of Fraud Survey, this webinar looks not only at the latest fraud trends and how institutions are fighting back, but also at their progress in putting together layered security controls in conformance with the FFIEC Authentication Guidance.
&lt;p&gt;
&lt;p&gt;
Given the persistence of fraud threats and the demands of the FFIEC Authentication Guidance, the 2012 Faces of Fraud Survey is crafted with assistance from leading experts in fraud detection and prevention, with a mission to: 
&lt;ul&gt;
&lt;li&gt;Chart the latest fraud trends, including account takeover, skimming and payment card breaches;&lt;/li&gt;
&lt;li&gt;Gauge institutions' preparedness to conform to the FFIEC Authentication Guidance, including where they are prioritizing their efforts;&lt;/li&gt;
&lt;li&gt;Predict the top areas of focus for 2012, from real-time fraud monitoring tools to new layered security controls.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>BYOD: Manage the Risks and Opportunities</title>
			<link>http://www.bankinfosecurity.co.uk/webinars/byod-manage-risks-opportunities-w-266</link>
			<guid>http://www.bankinfosecurity.co.uk/webinars/byod-manage-risks-opportunities-w-266</guid>
			<description>From home computers and laptops to cellphones and PDAs, employees have always lobbied to introduce consumer technologies in the workplace.
&lt;p&gt;
&lt;p&gt;
But with the advent of smart phones, tablets, portable storage and a variety of laptops - powerful computing devices that often rely on unsecured wireless networks - the push today is even greater. Example: Intel, the global computer technologies manufacturer, reports that connected mobile devices grew from 10,000 to 30,000 over the first 10 months of 2011. And by 2014, Intel expects 70% of its employees to use personal devices for some aspect of their job.
&lt;p&gt;
So, it's no longer a question of whether to allow employees to use their own devices - no corporate policy can stem the tide of consumerization. The questions now are about:
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Inventory&lt;/b&gt; - How do you properly account for all of the consumer devices introduced by your employees? Know how to lock down your corporate wireless networks and desktop computers, so you'll also know when employees are trying to access corporate resources via connecting new devices.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Security&lt;/b&gt; - How do you protect your systems and data from unauthorized access - and in the event of lost or stolen devices? From identification to proper authentication, appropriate access control, data storage and detecting un-authorized activities - all controls implemented by an organization on 'corporate-owned' resources over the last decade can potentially be rendered useless on an employee-owned device. Learn the importance of each control and the implementation challenges in a large-scale environment.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Privacy&lt;/b&gt; - The controls you place on an employee-owned device could potentially compromise the individual's privacy (knowing which sites they visit, or whom they e-mail in their off-hours, for instance). How do you achieve the right balance to protect the enterprise's security and the employee's privacy?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Compliance&lt;/b&gt; - Certain international regulations and standards spell out standards for how data is collected and stored, as well as how it must be made available for legal requests. Are you prepared to address these and other top-level compliance issues when it comes to employees storing enterprise data on their own devices? Learn how to weigh the risks and benefits.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Policy&lt;/b&gt; - Beyond making employees aware of your policy, how do you enforce it? Awareness is key - make sure employees understand your policies around device usage, access, software licensing and other critical issues. But you also need to articulate specific areas of non-compliance and then monitor appropriately for violations subject to disciplinary action, including termination.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Opportunity&lt;/b&gt; - Beyond securing devices, BYOD is an opportunity to improve data and access security in the enterprise, web, mobile, and SaaS applications. The opportunity is for organizations to still have strong security and authentication, but in a way that is "outsourced" to the device owner for all of their applications. This outsourcing can save the company IT budget, as well as reduce help desk support.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
In this session, mobile security experts will discuss these topics and more, sharing insights on how today's leading-edge organizations are embracing BYOD as a means of improving employee productivity and creating new business value.</description>
			</item>
			<item>
			<title>Why Boards of Directors Don't Get It</title>
			<link>http://www.bankinfosecurity.co.uk/interviews/boards-directors-dont-get-it-i-1569</link>
			<guid>http://www.bankinfosecurity.co.uk/interviews/boards-directors-dont-get-it-i-1569</guid>
			<description>IT risk management, cyber insurance, privacy - these are hot topics for security leaders, but not for their boards of directors. Why do senior executives still fail to see IT risks as business risks?</description>
			</item>
			<item>
			<title>How to Respond to Hacktivism</title>
			<link>http://www.bankinfosecurity.co.uk/interviews/how-to-respond-to-hacktivism-i-1568</link>
			<guid>http://www.bankinfosecurity.co.uk/interviews/how-to-respond-to-hacktivism-i-1568</guid>
			<description>Hacktivist attacks will increase, and researcher Gregory Nowak says organizations can take proactive steps to reduce exposure and protect brand reputation. Why, then, are many organizations failing?</description>
			</item>
			<item>
			<title>4 Security Priorities for Banks</title>
			<link>http://www.bankinfosecurity.co.uk/interviews/4-security-priorities-for-banks-i-1566</link>
			<guid>http://www.bankinfosecurity.co.uk/interviews/4-security-priorities-for-banks-i-1566</guid>
			<description>From mobile and the cloud to DDoS attacks and risks surrounding big data, what should banks and credit unions do now to mitigate exposure? Gartner's Anton Chuvakin offers his top recommendations.</description>
			</item>
			<item>
			<title>Understanding 'Big Data'</title>
			<link>http://www.bankinfosecurity.co.uk/interviews/understanding-big-data-i-1563</link>
			<guid>http://www.bankinfosecurity.co.uk/interviews/understanding-big-data-i-1563</guid>
			<description>Banks have a lot of data, but how well is it integrated? How much are institutions gleaning from the data they house? State Street Corp's chief scientist says financial services could be doing more.</description>
			</item>
			<item>
			<title>Fighting Hackers With Public Relations</title>
			<link>http://www.bankinfosecurity.co.uk/blogs/fighting-hackers-public-relations-p-1278</link>
			<guid>http://www.bankinfosecurity.co.uk/blogs/fighting-hackers-public-relations-p-1278</guid>
			<description>&lt;b&gt;Understanding Hacktivists' Goals is Key to Thwarting Attacks&lt;/b&gt;&lt;br /&gt;By understanding the motivations behind hacktivism, companies can learn why good public relations can play an important role in thwarting attacks or minimizing their impact.</description>
			</item>
			<item>
			<title>Global: A Lack of Breach Transparency</title>
			<link>http://www.bankinfosecurity.co.uk/blogs/global-lack-breach-transparency-p-1275</link>
			<guid>http://www.bankinfosecurity.co.uk/blogs/global-lack-breach-transparency-p-1275</guid>
			<description>&lt;b&gt;Processor Promised Updates, But We've Heard Little&lt;/b&gt;&lt;br /&gt;Global Payments has been less than forthcoming with information about its data breach. How could this lack of transparency hurt the processor, and what's the lesson for others?</description>
			</item>
			<item>
			<title>The Business Case for Continuity Planning</title>
			<link>http://www.bankinfosecurity.co.uk/blogs/business-case-for-continuity-planning-p-1272</link>
			<guid>http://www.bankinfosecurity.co.uk/blogs/business-case-for-continuity-planning-p-1272</guid>
			<description>&lt;b&gt;Small, Mid-Size Enterprises Especially Need to Develop Strategy&lt;/b&gt;&lt;br /&gt;Why do so many small and mid-sized enterprises continue to believe that business continuity planning is just for the big guys? And how do we go about convincing them otherwise? Here are some tips.</description>
			</item>
			<item>
			<title>Big Data for Fraud Prevention?</title>
			<link>http://www.bankinfosecurity.co.uk/blogs/big-data-for-fraud-prevention-p-1270</link>
			<guid>http://www.bankinfosecurity.co.uk/blogs/big-data-for-fraud-prevention-p-1270</guid>
			<description>&lt;b&gt;Tracking Customers, Not Accounts, Could Reduce Fraud&lt;/b&gt;&lt;br /&gt;Do banks and credit unions use all the data they collect? One credit reporting bureau says they could be doing more with their data to track and prevent fraud.</description>
			</item></channel></rss>

