Banking Exchange Magazine Logo

Cyber Crime Update: Meet today’s threats

Part 2: Specific digital threats—and defense tips

Part 2 of this two-part feature from a recent presentation by CSI's Steve Sanders has advice for banks anxious to curtail cyber risk. Part 2 of this two-part feature from a recent presentation by CSI's Steve Sanders has advice for banks anxious to curtail cyber risk.

Click to read Part 1, "Cyber Crime Update: 6 things to scare you"

Considered as a whole, the increasingly sophisticated and widely applied threats posed by cyber criminals is daunting. Steve Sanders, vice-president of internal audit, CSI, provides a rundown of specific avenues of attack banks may be susceptible to, and shares a number of tips as to what banks can do before they’re attacked.

“We have to be proactive. We have to be setting the stage. If we don’t do that we will forever be rocked back on our heels, feeling like we’re doing everything we can to keep our balance, wondering what the next attack will be,” Sanders says.

The first step is to have an understanding of the nature of specific attacks. The next step is to understand how vulnerable the organization is to them, and to prepare defenses. Sanders lists the following threats and tips.

Threats to beware of

Distributed denial of service—Charging just a few cents per computer, cybercriminals for hire can co-opt hundreds of thousands of computers without their legitimate owners knowing about it. Then these computers can be directed to send messages to a targeted website, effectively bringing it down.

“They can generate 150 gigabits per second of traffic. I don’t care who you are, you’re not ready for that,” Sanders says. “Can you imagine if your bank website didn’t work for three weeks?”

Malware—This is software cybercriminals surreptitiously install on target computers to do various misdeeds, such as steal confidential information or redirect assets. A lot of malware systems can be obtained very economically through the underground internet known as the “dark web.”

“The rate of return off of malware is 1,200%. That’s why the criminals are doing this,” says Sanders.

Advanced persistent threats—These generally combine malware and social engineering to place software into target systems that linger for long periods of time before their operators activate them to do their misdeeds. They lie dormant—sometimes for years—in order to evade detection systems, all the while collecting information.

Cloud breaches—Increasingly businesses contract with consumer-based cloud services to store confidential information, which can put them at risk. The cybercriminals target the cloud providers, either to swipe the confidential files or simply make them unavailable.

“If your cloud provider is not regulated they’re probably not putting into place the right solutions that you need, so you need to understand that. Ask good questions,” Sanders says.

Tips to counter the threats

Vendor management—“Do you have a robust vendor management program? The key word is robust,” says Sanders.

The main thing is to understand how mature the vendors are in the cyber security process, especially if they handle data or the bank’s infrastructure in any way.

Sanders says to download and embrace the FFIEC’s Appendix J to the IT Examination Handbook.

“That’s the No. 1 thing you need to be doing,” he says.

FFIEC cyber security portal—Bookmark this. It offers a wealth of statements, alerts, tools, and other resources regarding cyber security awareness and defense.

“It’s one of the best things they’ve put out in a long, long time,” Sanders says.

Cyber security assessment tool—Located at the FFIEC cyber security portal, it’s a crucial tool in which to assess a bank’s vulnerability to cybercrimes. It’s not an easy thing to complete, Sanders says, but it’s worth it.

John Ginovsky

John Ginovsky is a contributing editor of Banking Exchange and editor of the publication’s Tech Exchange e-newsletter. For more than two decades he’s written about the commercial banking industry, specializing in its technological side and how it relates to the actual business of banking. In addition to his weekly blogs—"Making Sense of It All"—he contributes fresh, original stories to each Tech Exchange issue based on personal interviews or exclusive contributed pieces. He previously was senior editor for Community Banker magazine (which merged into ABA Banking Journal) and for ABA Banking Journal and was managing editor and staff reporter for ABA’s Bankers News. Email him at [email protected]

back to top


About Us

Connect With Us


Webinar: From KYC to IDV

How three leading banks are utilizing cutting-edge
digital tools to onboard, win, and wow customers

Time/Date: June 23, 2021 11:00 a.m. ET

Digital adoption, already moving at warp speed, accelerated seven years into the future during the COVID-19 pandemic. As the number of bank branches continues to fall, with at least one study predicting all branches will disappear by 2034 (Fox Business) and foot traffic declining (Vox), today’s most innovative banks are charting a new, digital-first path to win over customers while increasing security, meeting KYC compliance requirements, and winning customers to drive revenue.

In this webinar, you’ll hear from John Baird, Founder & CEO of Vouched, Tyler Crawford, COO of Bankers Healthcare Group, Anand Sathiyamurthy, CPO of Flagstar Bank and Daniel Sheehan, Chairman & CEO of Professional Bank as they describe their vision for digital transformation and how customer expectations are changing to digital first. They’ll also explore how fostering an innovation mindset creates new ways to tackle complex KYC problems and allows them to quickly compete in new markets and win customers.


This webinar is brought to you by:
Vouched Logo