A Simplified Approach to Vendor Management

For those of you who are wanting to come into lightening-speed compliance with Section 164.308(b)(1) of the HIPAA Security Ruling, start telling your vendors that they need to revise their agreements to include the following.

The Anatomy of a CAT Attack

In order to understand the power of the three layers of security required by the June 2011 Supplement to the FFIEC’s 2005 Guidance on Authentication in an Internet Banking Environment, it is helpful to understand just how a corporate account takeover (CAT) attack works. Nowadays, criminals can purchase applications that are designed to attack American […]

What customers need to be told

According to the Federal Financial Institutions Examination Council’s (FFIEC), a financial institution’s customer awareness and educational efforts should address both retail and commercial account holders and, at a minimum, include the following elements: An explanation of protections provided and not provided to account holders relative to electronic funds transfers under Regulation E, and a related […]

Corporate Account Takeovers: Where Compliance Pays

As the “compliance burden” continues to rise, we may sometimes wonder whether information security regulations are worth the effort.  This is a story of how the FFIEC got it right. A Short History Lesson For many in banking, this story may appear to have started in June of 2011, when the FFIEC released what we […]

Qwerty Myths

Our friend, Joe Cychosz, found a great article connecting the past to the future. http://www.theatlantic.com/technology/archive/2013/05/the-lies-youve-been-told-about-the-origin-of-the-qwerty-keyboard/275537/

The Vulnerability Metrics: They are a Changin’!

The Common Vulnerability Scoring System, used by Cisco, Qualys, and Symantec since 2005, will be moving to its third iteration next year, aiming to make the rankings more objective and add more ratings to increase accuracy.

Bring Your Own What?

A five step process to control Portable Device Risk! Let’s start by summarizing the top half-dozen vulnerabilities that lead to that risk, and their corresponding controls: Lost or Stolen Devices.

Social Media Guidance Kit

Coming Soon! Sorry, we’re still reviewing the kit.  The guidance has a lot of detail, and we’re wanting to be sure we get it right. Social Media Guidance Kit Current estimated release date:  03/21/14 with the Indiana Banker’s Association Workshop. If you’d like to be informed when we have finished development, feel free to email […]