Showing posts with label Cyber Security Of Banks In India. Show all posts
Showing posts with label Cyber Security Of Banks In India. Show all posts

Wednesday, January 4, 2012

Mobile Banking Cyber Security Is Required In India

Mobile banking in India is moving towards an acceptance level. However, till now very few people and institutions are comfortable in using mobile banking in India. Mobile banking in India is still not popular according to RBI. There are certain shortcomings of mobile banking in India that are still left unaddressed.

For instance, mobile governance in India is still not well established. M-governance in India is essential before mobile banking can be successfully implemented in India. We have no regulatory framework for m-governance in India. Even the proposed electronic delivery of services bill 2011 of India has failed to provide a mandatory legal framework for electronic delivery of services in India, including for mobile banking. In short, India is still not ready for m-governance and cloud computing especially in the absence of dedicated e-commerce laws in India.

Mobile banking in India is risky due to absence of mobile cyber security in India. Further, online banking system of India is not secure. In the absence of adequate cyber security safeguards, e-banking in India is not safe. The cyber security trends in India 2011 have also proved that Internet banking cyber security in India is in poor shape and it needs to be strengthened. Even data security, privacy and cyber security in Indian banking industry is not satisfactory.

Online banking risks in India are increasing and this is also shaking the confidence of customers in the same. Even RBI has acknowledged risks of e-banking in India. ATM frauds in India are increasing. In fact, Reserve Bank of India (RBI) has recently released the report of its working group on securing card present transaction that covers ATM security and credit card security issues as well. Internet banking risks in India cannot be effectively tackled till we have dedicated Internet banking laws in India.

Although an integrated banking law of India has been proposed yet it may take some years before it is actually enacted. In an interesting development, the RBI removed limits from mobile banking transactions limits in India. This is good for the development of mobile banking in India but is bad for the interests of mobile banking customers who have almost no safeguards against cyber crimes and technology assisted financial frauds happening in the mobile banking field.

The cyber law in India has prescribed cyber law due diligence for various stakeholders. Cyber due diligence for banks in India is just a part of the same. Cyber due diligence for Indian companies including banks operating in India is very stringent. However, Indian banks are not following the guidelines of RBI prescribing mandatory cyber security requirements for banks of India. Further, banks are also liable

Even on the policy front, mobile banking has received a bad response form Indian government. For instance, absence of effective encryption laws in India and non use of robust encryption in India has made the mobile security very weak in India. Instead of making the encryption requirements redundant and weak, India must concentrate upon further strengthening the same for better and secure mobile communications. Governments of most developed countries allow the usage of strong encryption standards ranging from 128 bits to 256 bits or more to ensure the security of sensitive information exchanged via Internet and other networks. However, India is still clinging to 40 bits encryption standards for the simple reason that intelligence and security agencies of India are not capable enough to break strong encryptions.

A weak mobile banking infrastructure would also affect other projects and schemes as well. For instance, recently the Securities and Exchange Board of India (SEBI) has declared about its intentions to introduce electronic initial public offer (E-IPO) in India. This is a good step but E-IPO cannot succeed in the absence of strong mobile banking and Internet banking infrastructure. Online payments mechanisms in India must also be suitable strengthened to make such proposals workable.

India must give these considerations some serious thoughts if it wishes to encash the benefits of technology. Otherwise, concepts like Internet banking and mobile banking are more nuisance than luxury in India.

Friday, June 3, 2011

ATM Frauds In India And Their Techno Legal Preventive Measures

ATM Frauds in India are increasing at an alarming rate. If we add to it the cases of Credit Card Frauds, Internet Banking Frauds and frauds committed using Phishing techniques, the numbers are really shocking.

It is not the case that Reserve Bank of India (RBI) is not aware of these cases nor is it the case that RBI is not doing anything in this regard. In fact, RBI has recently released the Report of its Working Group on Securing Card Present Transaction that covers ATM Security and Credit Card Security issues as well.

RBI has also recommended Cyber Security Due Diligence for Banks of India. However, despites these pro active steps, ATM Frauds are increasing in India. One chief reason for this growth is that Banks in India are not serious about Cyber Security and they are not following the Recommendations of RBI.

ATM Frauds happen when someone leaves his/her credit card unattended in a vehicle or changing room or allows anyone else to use the card or looses the card that is misused by others or discloses the Personal Identification Number (PIN) to others, etc. These mistakes allow the offender to withdraw money by using the stolen information. Fraudsters are using special devices, skimmers, duplicate ATMs, etc to withdraw money from ATMs. Sometimes such frauds are an insider job with the collusion of the employees of the company issuing those cards. However, misuse of the disclosed PIN for withdrawing money is the most common techniques used for committing ATM Frauds.

ATM Frauds can be prevented if we take some basic level precautions. For instance, never leave your credit card unattended in a vehicle or changing room, never allow anyone else to use your card, always retain sales/charge slips to compare with the amount specified on the billing statement, do not disclose your PIN to anyone, etc.

The Technology can also be used to minimise cases of ATM Frauds in India. The technological mechanisms like Designated time, Microchip technology, Biometric tokens, Enhanced security, ATM Monitoring, Customised softwares, Customer motivation, Alerts, etc can be used to minimise and prevent ATM frauds in India.

Another reason for growth of technology related crimes and ATM Frauds in India is absence of “Deterrent Law” in this regard. The Information Technology Act, 2000 (IT Act 2000) is the sole Cyber Law of India. After the Information Technology Amendment Act, 2008 (IT Act 2008) almost all the Cyber Crimes in India have been made “Bailable” Now Cyber Criminals can commit almost all Cyber Crimes, ATM Frauds, Credit Card Frauds, Internet Banking Frauds in India without any fear. It is high time to repeal the Cyber Law of India as soon as possible and enact Strong and Effective Laws in this regard.

The IT Act, 2000 does not contain any specific provisions regarding ATM Frauds and Credit Card Frauds and the traditional law of IPC, 1860 also cannot be relied solely and independently to tackle this problem. We need a better law for this purpose and Perry4Law and Perry4Law Techno Legal Base (PTLB) have already provided their Suggestions and Recommendations in this regard and other ICT related matters to the Government of India, Department of Information Technology, Department of Science and Technology, Prime Minister’s Office, etc from time to time.

Till we have suitable and apt laws, we must apply existing laws in a purposive and updating manner. However, ATM frauds can be tackled by using Techno Legal Methods alone and neither Legal nor Technical Measures is sufficient in itself.

Report Of The RBI Working Group On Securing Card Present Transaction

The Reserve Bank of India (RBI) is taking cyber security of banking industry very seriously. RBI has been stressing that banks in India are required to ensure cyber due diligence and cyber security due diligence. However, the banks in India have still not done the needful in this regard even though the first quarterly report in this regard is due on 30th June, 2011.

RBI has now taken another significant step in this regard. RBI today placed on its website the Report of the Working Group on Securing Card Present Transaction. Comments of the Report may be emailed or forwarded by June 30, 2011 to the Chief General Manager, Department of Payment and Settlement System, Reserve Bank of India, Central Office, Mumbai-400001.

Card Present Transactions (at PoS and ATMs) constitute major proportion of card based transactions in the country. Currently, transactions using cards at PoS do not require additional authentication in majority of cards. Further most of the cards used in India, presently used magnetic stripe technology. Taking into account vulnerabilities involved, and to increase customer confidence may countries led by European Union have moved to Chip and Pin technology.

The RBI constituted a Working Group consisting of banks and card companies in March 2011 to look into all the related issues implementing the security of card transactions in India and suggesting a road map for migration. The Working Group submitted its report on June 2, 2011.

The Working Group arrived at the final recommendations based on the following critical factors:

(1) Putting in place a series of measures to strengthen the Payments infrastructure and ecosystem in the country,

(2) The need for a hybrid approach – the evolving nature of UIDAI, varying international and domestic trends. (Ed-The use of UID has been not approved till the suitability of same is well established).

(3) The need for a PIN (to ensure Lost and Stolen fraud is minimized) over and above protecting for skimming (Counterfeit). The choice of PIN though would be at the discretion of the Issuer.

(4) Important to ensure that both offline and online PINs are accepted by the EDC machines so that interoperability is ensured.

(5) Open, reloadable prepaid cards to be treated as “debit” equivalent as far as group recommendations as concerned.

(6) Differentiated implementation timelines for debit and credit cards.

(7) EMV Cards for international travelers to be prioritized

(8) Minimize throw-away costs and technology efforts for all stakeholders.

(9) Evaluation of UIDAI’s Aadhaar rollout as a strong alternative for domestic transactions 18 months from now based on:

(a) Aadhaar enrollment statistics for the existing cardholder base

(b) Proof of Aadhaar working as a second factor through pilots and roll outs

(c) Readiness of UIDAI to work with ATM, POS and device manufacturers to ensure ubiquity of biometric authentication both for existing machines and new deployments

(d) End to end transaction time including biometric authentication to comply with global standards for authentication

(e) Legal framework to be in place for ensuring non-repudiation of biometric authenticated transactions.

(f) Procedural guidelines and engagement model for banks to work with UIDAI for authentication, validation process in case of dispute through logs etc. to be put in place.
(g) UIDAI’s readiness to work with banks, associations and technology partners to make the payments ecosystem ready for a well tested, industry grade solution 18 months from now

(h) Evaluate the risk of being a “single point of failure”.

Perry4Law and Perry4Law Techno Legal Base (PTLB) welcome this initiative of RBI and congratulate the working group for coming out with good guidelines.

Cyber Security Due Diligence For Banks In India

Reserve Bank of India (RBI) has recently constituted the Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds (Working Group). The Working Group submitted its report in the recent past upon which public inputs were invited. After analysing the public inputs, the final draft has been recently released and notified by the RBI.

This “notification” has set a specific timeline for implementation of the final recommendations of working Group. While not all these recommendations are mandatory some of them are and banks of India must comply with the same till October 31, 2011. These mandatory recommendations pertain to policies and procedures which do not require extensive investment.

RBI has also directed that all banks would have to create a position of chief information officers (CIOs) as well as steering committees on information security at the board level at the earliest. This direction was provided through the information technology vision document for 2011-17 (IT Vision 2011-17) and the recent notification of the draft report.

Now the October 31, 2011 deadline may include the setting up of the ICT strategy steering committee, cyber risk management committee and the ICT steering committee as well as designation of CIOs. The notification also suggests a quarterly review process and the first calendar quarter after the issue of the guideline falls on 30th June 2011.

The board of directors must comply with the recommendations of Working Group before the quarterly report would be analysed by RBI. The constitution of steering committee and appointment of CIOs must be put on records so that RBI may analyse the same.

RBI has also been taking non compliance of its recommendations seriously. Recently, RBI imposed penalty upon 19 commercial banks for non compliance of prescribed standards. Similar dedication is also required regarding the recommendations issued by RBI for ensuring cyber security infrastructure by Indian banks.

Further, RBI has also directed banks to seek information from their directors on any adverse strictures passed by financial sector regulators against them. This means if directors of banks are negligent in meeting various due diligence requirements, statutory obligations, cyber law and cyber security requirements, etc and any stricture is passed against them in this regard that would have to be reported. Non compliance of the recommendations of Working Group may result in passing of such stricture against the directors. It is in their own interest to comply with the recommendations of RBI as soon as possible.

Perry4Law and Perry4Law Techno Legal Base (PTLB) have been analysing these issues for long and they have been providing their suggestions in this regard. We believe that RBI must play a more pro active role in analysing whether its policies and recommendations are duly complied with. It seems the recommendations of the Working Group constituted by RBI have still not been implemented. A “Progress Report” must be sought from Banks of India in this regard by RBI as soon as possible.

Further, banks and financial institutions that are interested in complying with the cyber due diligence requirements under the cyber law of India, under the recommendations of RBI and working group or in any other case, may contact us in this regard. In any case banks must consider the recommendations of RBI very seriously in the larger interest of banks in general and their customers in particular.

Thursday, June 2, 2011

RBI Working Group On Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds

Reserve Bank of India (RBI) has been streamlining the Financial and Banking Sector of India. It is very apparent if we look at the recent Policy Decisions made by RBI from time to time. Although all of these Policy Decisions are good yet one aspect that requires a special mention is the constitution of RBI Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds (Working Group).

The Working Group submitted its report in the recent past upon which public inputs were invited. After analysing the public inputs, the final draft has been recently released and notified by the RBI.

RBI has also directed that all banks would have to create a position of Chief Information Officers (CIOs) as well as Steering Committees on Information Security at the board level at the earliest. This direction was provided through the Information Technology Vision Document for 2011-17 (IT Vision 2011-17) and the recent notification of the draft report. This document has suggested many technological as well as legal reforms for banking sector of India.

Although the direction to have CIOs and Steering Committee is very clear yet till now banks in India has failed to comply with this direction. RBI said that the banks need to ensure implementation of basic IT organisational framework and put in place policies and procedures which do not require extensive budgetary support, infrastructural or technology changes, by October 31, 2011. The rest of the guidelines need to be implemented within period of one year unless a longer time-frame is indicated.

Banks in India need to formulate a Cyber Security Policy as soon as possible. Cyber Security Policy is an issue that is very important for Banks of India. With the growing use of Internet Banking, ATM machines, Credit and Debit Cards, Online Banking, etc, Banks of India must also upgrade their Cyber Security Infrastructure and establish a Cyber Security Policy.

Banks and Financial Institutions must regularly engage in “Forensics Audit” and “Incidence response”. Presently, Banks and Financial Institutions engage in these “Essential Exercises” when something fraudulent or wrong have already taken place. If Banks and Financial Institutions conduct regular Cyber Due Diligence then incidences like Citibank Fraud Case could be minimised.

Perry4Law and Perry4Law Techno Legal Base (PTLB) have been analysing these issues for long and they have been providing their suggestions in this regard. We believe that RBI must play a more pro active role in analysing whether its Policies and Recommendations are duly complied with. It seems the Recommendations of the Working Group constituted by RBI have still not been implemented. A “Progress Report” must be sought from Banks of India in this regard by RBI as soon as possible.

Tuesday, May 24, 2011

RBI Mandates Information Giving Of Strictures Passed Against Directors

Reserve Bank of India (RBI) has been streamlining the management of banking and financial institutions of India. It has taken many pro active steps in this regard. From prescribing a more stringent cyber due diligence policy for banks to mandating a requirement to appoint chief information officers (CIOs) and steering committee at the board level, RBI has taken many reformative steps.

In fact, cyber due diligence and banking due diligence could have prevented the recent Citibank fraud. The truth is that banks and financial institutions in India are not serious at all regarding cyber due diligence, cyber crimes, financial frauds and cyber security. Till now RBI’s guidelines on steering committee and CIOs have not been fulfilled by banks of India. Even RBI has recently imposed non compliance penalty upon 19 banks of India in another case.

However, despite all these actions, the higher management of banks have not been persuaded to take due diligence seriously. Now RBI has decided to change this position and it has asked banks to seek information from their directors on any adverse strictures passed by financial sector regulators against them.

This means if directors of banks are negligent in meeting various due diligence requirements, statutory obligations, cyber law and cyber security requirements, etc and any stricture is passed against them in this regard that would have to be reported.

RBI has also partially modified the format of “Declaration and Undertaking” prescribed for the purpose of conducting due diligence to determine the “fit and proper” status of directors. Banks should get information whether the director at any time come to the adverse notice of a regulator such as the Securities and Exchange Board of India (SEBI) and the Insurance and Regulatory Development Authority (IRDA) .

Henceforth, banks should obtain declaration and undertaking from existing directors and also persons to be appointed or elected as director. It is not necessary for a candidate to mention about orders and findings by regulators which have been later on reversed or set aside in toto. But they would have to make a mention of the same, in case the reversal and setting aside is on technical reasons like limitation or lack of jurisdiction and not on merit. If the order (of the regulator) is temporarily stayed and the appellate or court proceedings are pending, the same also should be mentioned, RBI added.

This is a good step in the right direction by RBI. This would bring not only discipline among the higher management but would also ensure statutory and due diligence compliances on their behalf.