Welcome Guest. | Log In | Register | Membership Benefits

Court Ruling Puts Security Burden On SMBs, Not Banks

Security experts cry foul in U.S. District Court ruling in $500,000 online bank account heist from construction firm

Jun 08, 2011 | 03:42 PM | 

By Ericka Chickowski, Contributing Writer

A recent ruling by a U.S. District Court of Maine magistrate in favor of a bank being sued by a construction company that had money stolen from its account by hackers highlights how vulnerable small to midsize business owners are to online fraud.

Unlike consumer bank accounts that come with fraud-reversal protection, businesses are left on the hook for fraudulent transfers -- a fact that many remain ignorant about, but of which hackers are well-aware, say security experts.

"They don't get the same kind of protection that an individual consumer gets, but they don't get much more attention than an individual consumer [from banks], so they are very vulnerable from that standpoint," says Terry Austin, CEO of Guardian Analytics. "And the criminals figured this out. A lot of the action a couple years ago was in retail banking, and we still see fraud there, but the big, really significant fraud attacks have been against the small-business community. There are hundreds of thousands of dollars, sometimes up to million-dollar attacks on these small businesses."

This is exactly what happened to PATCO Construction, which in 2009 saw $500,000 sliced away from its Oceans Bank commercial account after a malware attack made away with its authentication credentials -- including answers to challenge questions asked by the bank's authentication system. The bank helped PATCO recover a little less than half the sum, but the company was out $270,000 as a result of the attack.

Last year, PATCO sued Oceans Bank for that money, claiming the financial institution's authentication system was inadequate in protecting its customers from common hacking attacks. After the case made its way through the courts, on May 27 a magistrate ruled in favor of the bank. The magistrate claimed that the bank followed Federal Financial Institutions Examination Council (FFIEC) guidelines set in 2005 for multifactor authentication for online banking.

But many within the security industry disagree with the ruling and believe it sets a dangerous precedent that will justify banks to continue using weak alternative factors of authentication that are easily bypassed by automated malware today.

"I don’t believe this magistrate correctly interpreted the 2005 FFIEC authentication guidance," wrote Avivah Litan, a Gartner analyst who specializes in bank fraud and authentication matters. "Unfortunately, the 2005 FFIEC guidance referred to examples of relatively basic online theft techniques that were commonplace in 2004 and 2005. The cybercriminal of 2011 has long ago bypassed and surpassed those old techniques."

According to Litan and Austin, the ruling first and foremost should be a wake-up call to regulators to update old guidance on authentication that was developed in an age before the Zeus Trojan crimeware kit.

"I think that the FFIEC has been standing on the sidelines of this and not stepping in and updating their guidance and taking a firmer stand," Austin says. "I think they really have a lot to answer for here. I just don't think they're doing their part to respond to the problem."

But SMBs must also do their part to secure their machines. Often small-business owners assume that if they're ever hit by bank-stealing malware, the bank will reverse charges because this is what they are conditioned to believe due to their retail banking experiences. But banks rarely extend the same fraud reversal for business accounts as they do for consumer accounts. So SMBs at the very least need to start with the most basic principles of installing security software, establishing strong passwords,and limiting access to banking credentials across the organizations. Many experts also believe that small businesses should consider buying a dedicated machine solely for online banking.

"One thing I recommend to every small business is to not bank from a computer you use for anything else, period. Just don't do it," says Chet Wisiniewski, senior security adviser at Sophos. "Don't ever search the Web, don't go to Google, don't go to Facebook. Because of the Web risk, simply visiting an infected site puts you at risk. Do you really want to take that chance if you can buy the perfect banking netbook for $200? An alternative to that, too, is to use a live CD Linux distribution that's not writable."

Additionally, SMBs need to know to ask the right questions when they're looking for a bank, Austin says.

"These small businesses don't know how to ask their banks the right questions about their fraud policies," Austin says, explaining that companies need to ask about what their liability is in the event of an attack, what kind of authentication the bank uses, how the bank monitors activity to look for anomalous behavior, whether the bank utilizes risk-detection technology with behavioral analytics, and what the processes are when fraud is detected.

Ultimately, though, Austin believes it is up to the banks to start closing in on the vulnerabilities hounding their SMB customers. "I think even a business that does take precautions and does follow all of the proper procedures is still at very high risk," he says. "We have a level of sophistication in malware that is hitting even the most protected industry practitioners today. For a firm like a midsize $20 million business that's just trying to make a go of it, I just don't think they should be expected to bear the full burden of this."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



SMB Security Reports

report Small Businesses, Big Losses: How SMBs Can Fight Cybercrime
Small and midsize businesses are falling prey to cyberattacks that cost them sensitive data, productivity and corporate accounts cleaned out by sophisticated banking Trojans. SMBs are typically on the hook for these losses and lack effective means to prevent them. In this report, we explain what makes these threats so menacing, and share best practices to defend against them.

report Five Security Flaws, Five Security Fixes For Small And Midsize Companies
Take a sneak peek at data from the Dark Reading/InformationWeek 2011 Strategic Security Survey, with a focus on the five biggest problems faced by small and midmarket companies. You?ll get a look at key security practices and processes for managing the complexity of security; enforcing policies; assessing risk; preventing data breaches; and managing scarce IT resources.

report SMBs in the Crosshairs: Understanding the Threats, Defending the Business
Cybercriminals are not only exploiting small and midsize businesses -- they're targeting them. While thefts of hundreds of thousands or even millions of credit card numbers and personal information records make headlines, many small companies' accounts have been cleaned out. In this Dark Reading Tech Center report, we identify how SMBs are exploited, where their security fails and how they can shore up their defenses.

Other reports from the SMB Security Tech Center:




Featured Webcasts
Featured Whitepapers
Featured Reports