IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Public Teleconferences
Join CIO Executive Council members and participate in the following live one-hour teleconferences:

* Managing Change: Centralizing Your IT Organization
July 29

* Transforming IT Teams
September 16

* Global CIOs: How to Lead on the World Stage
September 18

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
 

What Banks Tell Online Customers About Their Security

Six months after the FFIEC's rules for strong authentication took effect, we test what the country's three biggest banks tell their customers about online security.

 

May 29, 2007CIO — By the end of 2006, U.S. banks were supposed to have implemented "strong authentication" for online banking—in other words, they needed to put something besides a user name and password in between any old Internet user and all the money in a customer's banking account.

The most obvious way to meet the guidance, issued by the U.S. Federal Financial Institutions Examination Council (FFIEC), would have been to issue one-time password devices or set up another form of two-factor authentication. But last summer, when I did a preliminary evaluation of security offerings at the country's largest banks, I was pretty unimpressed. (See Two-Factor Too Scarce at Consumer Banks.)

Since then, I've given up on getting a one-time-password device, and have accepted the fact that banks are instead moving toward what might diplomatically be called "creative" authentication. (See Strong Authentication: Success Factors.) Given that man-in-the-middle attacks can circumvent two-factor authentication, a combination of device authentication, additional security questions and extra fraud controls doesn't seem like a bad approach.

But, I wondered, almost six months past the FFIEC deadline, what are banks telling customers about online security? As the chief financial officer of Chateau Scalet—and as a working mother about to have baby No. 2—I wanted to know if any of them could offer me enough assurance that I would take the online banking plunge as a way to simplify my life. I decided it was time to update my research from last year.

I called the call centers at each of the top three banks, identified myself as a customer with a checking and savings account, and told them I was interested in online banking but concerned about security. The point, yes, was to see what type of security each bank had in place. More than that, however, I wanted to see how well each bank was able to communicate about security through its call center. After all, what good is good security if you can't explain it to your customers? Here's what I learned.

Loading...
 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Fuel the Responsive Enterprise Through Oracle Fusion Middleware

Balance Your Innovation and Efficiency Platforms for Competitive Advantage and Responsiveness

The Challenge of Network Access Control -- Is a Managed Service the Answer?

Strategic IT Financial Management - Achieve Higher Organizational Performance

Unified Communications: "More Than Just Talk"

A Closer Look at SaaS Purchasing Behaviors and Attitudes

31 Best Practices for the Service Desk

Enhancing Online Sales and Support

Putting Windows Server and Citrix to Work in the Enterprise

HP Puts Its Disaster-tolerant Capabilities to the Test

TDWI Research report clears confusion about automating data governance

Learn about the software-based VoIP solution from Microsoft

Microsoft System Center - Designed For Big

Reducing Data Center Costs with Data Deduplication: A TCO Analysis

Standalone Server vs. Open Source Toolkits

Oracle Real Application Testing with Oracle Database 11g

InfoWorld Test Center on Oracle Active Data Guard

Master Data Management: The Approach Determines the Results

The Power of Pervasive Business Intelligence

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

The Universal Wireless Client: Simplify mobility and reduce the cost of supporting mobile workers

Strategies for Asia-Pacific Expansion

Virtual Support Technology Delivers Quantifiable Gains in Productivity and Performance

Building Competitive Advantage with Next-Generation Wireless Infrastructure

Drive More Effective Business Processes with SOA

Reap the Benefits of Unified Communications

Controlling High Fraud Risk of International Transactions

Solving Online Credit Fraud Using Device Reputation

New research validates telepresence solutions.

How to Calculate the ROI of Remote Support

Implementing Knowledge Management

BPM Done Right: 15 Ways to Succeed Where Others have Failed

Extending the Enterprise Network Through Mobility

Speed, agility, flexibility - The HP BladeSystem c-Class

Cost-Effective Data Center 1U Server Solutions

Secure your virtual and physical environments with the same software

GET YOUR VoIP ONTM! Win 2 Years of Hosted VoIP from Cypress. $100,000 retail value. Enter today!

Storage Efficiency: The Key to Green Storage Operation

Oracle Database 11g: Real Application Testing & Manageability

InfoWorld Test Center on Oracle Real Application Testing

Oracle Database 11g: Advances in Compression, Real Application Testing and Data Guard

Getting Off on the Right Foot: Avoiding Common Master Data Management False Starts

Conquering Information Management Challenges

Renowned Engineering Institution Chooses AMD Processor-Based Servers

How to Manage the Mobile Work Environment

Extending PCI Compliance to the Mobile Workforce

Process Integration and Traceability through Requirements Management

Accelerating ITIL at the Service Desk

Building an Online Customer Experience Competency