Showing posts with label Steering Committees On Information Security By Banks In India. Show all posts
Showing posts with label Steering Committees On Information Security By Banks In India. Show all posts

Thursday, June 9, 2011

Citigroup Confirms Cyber Attack Upon Bank’s Network

Reserve Bank of India (RBI) has been stressing upon ensuring cyber security for banks in India. RBI has also constituted the working group on information security. As per the recommendations of the working group, RBI has directed that all banks would have to create a position of chief information officers (CIOs) as well as steering committees on information security at the board level at the earliest.

Meanwhile, RBI sought the inputs of various stakeholders upon the report of the working group. After analysing the public inputs, the final notification has been recently released by the RBI. The notification mandates complying with the recommendations of RBI in a time bound manner.

However, it seems the recommendations of the working group constituted by RBI have still not been implemented. A “progress report” must be sought from banks of India in this regard by RBI as soon as possible.

RBI has also made the appointment of chief of internal vigilance mandatory for banks in India. RBI has also prescribed cyber security due diligence for banks in India. In fact, cyber due diligence and banking due diligence could have prevented the recent Citibank fraud.

The truth is that banks and financial institutions in India are not serious at all regarding cyber due diligence, cyber crimes, financial frauds and cyber security. This is resulting in an increase in banking related cyber crimes and financial frauds.

As per the latest news, Citigroup Inc said computer hackers breached the bank's network and accessed data on hundreds of thousands of bank card holders in the latest of a string of cyber attacks on high-profile companies. Citigroup said about 1% of its card customers were affected by the breach, which had been discovered in May during routine monitoring. The names of customers, account numbers and contact information, including email addresses, were viewed during this cyber attack. However, other information such as birth dates, social security numbers, card expiration dates and card security codes (CVV) were not compromised.

Cyber attacks against banking and financial institutions are very common and frequent. They cannot be eliminated absolutely but efforts must be made to make them as less as possible. Banks and financial institutions of India must consider cyber security very seriously in the larger interest of their customers.

Saturday, May 21, 2011

CBI Director Stresses Upon Technology Awareness Among Bank Officers

Recently the third conference of chief vigilance officers (CVOs) of public sector banks and financial institutions was held at the new central bureau of investigation (CBI) headquarters building. The director of CBI Shri Amar Pratap Singh advised the CVOs of banks and financial institutions to adapt to changing technology and sensitise staff to new methods of frauds.

Delivering the Key Note Address, Director CBI Shri Amar Pratap Singh said that CBI’s role is to investigate the criminality in bank frauds and it does not interfere in cases of prudent commercial judgement, even if such decisions involve risks or have resulted in losses to banks.

The Director, CBI called upon banks to adapt to changing technology and to sensitise its officers to new methods of fraud which are of late, noticed in electronic payments, technology related payments like RTGS, Credit Cards, ATM, Cell Banking, Internet Banking etc. Director CBI said the Banking Sector has lost as much as Rs.1883 crore and Rs. 2017 crore during 2008-09 and 2009-2010 respectively. These include over 200 frauds of above Rs One crore during each year.

Shri A.P. Singh stated that banking officials are guiding Investigating Officers in scrutiny of financial statement, credit appraisal etc which has enhanced the professionalism of CBI, in detecting bank frauds.

The Conference discussed important issues such as Preventive Vigilance, E-Tendering/E-Procurement and Forensic Auditing. The services of bank officers are being utilised in various branches of CBI such as Bank Security and Fraud Cell, Economic Offences Unit and Anti Corruption Units in the CBI Headquarters as well as regions.

The call from CBI director came after G Gopalakrishna, the executive director of Reserve Bank of India (RBI) said that all Banks would have to create a position of Chief Information Officers (CIOs) as well as Steering Committees on Information Security at the Board Level at the earliest. The idea is to use information technology to the maximum possible extent while maintaining the cyber security of banks.

While RBI and CBI have done a great job yet banks and financial institutions in India are not taking these directions and recommendations seriously. Till now the directions of RBI to appoint CIOs and steering committee has not been followed by banks of India. Similarly, banks of India are also at fault for ignoring the cyber security requirements. The RBI has even said that mobile banking in India is not yet popular due to low adoption of technology by banks. Let us hope the banks and financial institutions would take cyber law, cyber crimes and cyber security issues seriously very soon.