Recent ECB/ EBA regulations how they will impact European banks in 2016

IBM Security
IBM SecurityIBM Security
Trusteer Positioning
ECB/EBA Recommendations for
Security of Internet Payments:
© 2015 IBM Corporation
Monday, December 07, 2015
Agenda
General information and milestones
– Things to note
The Guidelines
The layered security approach
How, why, and which IBM Security Trusteer product(s)?
Responding to the Specific Requirements
Summary / Next steps
2© 2015 IBM Corporation
Summary / Next steps
August 2015
Guidelines define
minimum requirements
2017 / 2018
Additional guidelines from
the EBA are expected once
the updated Payment
Services Directive (PSD2) is
published
Milestones and Recommendations
3© 2015 IBM Corporation
December 2014
EBA publishes the Final
Guidelines on Internet
Payments Security, based on
the European Forum on the
Security of Retail Payments
(SecuRe Pay)
minimum requirements
that have to be fulfilled
by PSPs under the PSD
published
Link to the Final Guidelines
Things to Note
The recommendations constitute a “living
document”
The recommendations are descriptive (vs.
prescriptive)
The bank may address recommended
solutions by other means
The recommendations constitute minimum
Regulations
4© 2015 IBM Corporation
The recommendations constitute minimum
expectations. It’s the responsibility of PSPs to
monitor and assess their particular risks,
develop their own detailed security policies and
implement adequate security measures that
are commensurate with the risks inherent in
the payment services provided.
Final guidelines on the Security Of Internet Payments
As per document issued in Dec 2014
R2
• Risk Assessment
R3
• Incident Monitoring and Reporting
R4
• Risk Control and Mitigation
R7
• Strong Customer Authentication
5© 2015 IBM Corporation
R7
• Strong Customer Authentication
R8
• Enrolment for, and provision of authentication, tools and/or software
delivered to the customer
R9
• Log-in attempts, session time out, validity of authentication
R10
• Transaction Monitoring
R12
• Customer Education and Communication
The Guiding Principles
Fraud prevention layers, listed in order of effectiveness
Device Security
• Ensuring the accessing device is secure and malware free
User Authentication
• Verify the authorized user and device with multifactor (tamper-proof) user
authentication
Transaction Monitoring
6© 2015 IBM Corporation
Transaction Monitoring
• Identify anomalous user behaviors and known fraud patterns
Network Analysis
• Correlate known fraud with other potentially fraudulent events
Customer Awareness and Education
• Ongoing customer education through continuous communication
Existing security controls
Do they impact your business?
7© 2015 IBM Corporation
Account &Transaction
Restrictions
Intrusive Controls
Increased Authentication
Challenges
IncreasedTransaction
Delays
Increased Investigation
Costs
DisruptiveValidation &
Verification
At a glance
ECB Recommendations mapped to Trusteer’s solutions (I)
Recommendation 2: Risk Assessment
KC 2.1 (Risk Assessment) Trusteer Cybercrime Intelligence
Recommendation 3: Incident monitoring and reporting
KC 3.1 (Reporting) Trusteer Cybercrime Intelligence
8© 2015 IBM Corporation
Recommendation 4: Risk Control and Mitigation
KC 4.2 (Phishing) Trusteer Rapport and Trusteer Pinpoint
BP 4.1 (Trojans)
Trusteer Rapport, Trusteer Pinpoint, Trusteer
Mobile Solutions (Mobile SDK, Secure Mobile
Browser)
AQ = Assessment Question
BP = Best Practice
KC = Key Consideration
At a glance
ECB Recommendations mapped to Trusteer’s solutions (II)
Recommendation 7: Strong customer authentication
AQ 7.0.1 (Use of 2+ elements for
authentication)
Trusteer Pinpoint and Trusteer Mobile SDK
AQ 7.0.4 (Protection of multi-
purpose devices)
Trusteer Mobile SDK; Trusteer Rapport;
Trusteer Pinpoint
9© 2015 IBM Corporation
AQ 7.0.8 (Protection of devices
where secrets are stored)
Trusteer Rapport and Trusteer Mobile SDK
AQ = Assessment Question
BP = Best Practice
KC = Key Consideration
At a glance
ECB Recommendations mapped to Trusteer’s solutions (III)
Recommendation 8: Enrolment for and provision of authentication tools and/or
software delivered to the customer
AQ 8.1.1 (Protection of payments
– safe and trusted environment)
Trusteer Rapport, Trusteer Pinpoint, and
Trusteer Mobile SDK
AQ 8.1.1 (Software delivered to
customers not under the bank’s
control)
Trusteer Rapport; Trusteer Pinpoint, and
Trusteer Mobile SDK
10© 2015 IBM Corporation
control)
Trusteer Mobile SDK
Recommendation 9: Log-in attempts, session time out, validity of authentication
KC 9.1, KC 9.2, KC 9.3
(Log-in attempts, session time out,
validity of authentication)
Trusteer Pinpoint
AQ = Assessment Question
BP = Best Practice
KC = Key Consideration
At a glance
ECB Recommendations mapped to Trusteer’s solutions (IV)
Recommendation 10: Transaction monitoring
Overview (Trx Monitoring purpose) Trusteer Pinpoint
KC 10.1 (Fraud prevention systems
should detect malware in the
session)
Trusteer Pinpoint
11© 2015 IBM Corporation
KC 10.4 (Trx Monitoring shouldn't
delay transactions)
All Trusteer's solutions work in real time,
providing actionable results while the user is
interacting with the site.
KC 10.5 (Blocks should be
maintained for as short time as
possible)
All Trusteer's solutions operate in real-time and
are highly deterministic, providing per-
transaction results avoiding blanket "blocking"
of users
AQ = Assessment Question
BP = Best Practice
KC = Key Consideration
At a glance
ECB Recommendations mapped to Trusteer’s solutions (V)
Recommendation 12: Customer education and communication
Overview (reassure customers of
the authenticity of the messages
received)
Trusteer Rapport and Mobile
12© 2015 IBM Corporation
AQ = Assessment Question
BP = Best Practice
KC = Key Consideration
Trusteer’s Solution Overview
© 2015 IBM Corporation
Online Banking
Malware attacks
against the website
Account
takeover
Detects malware
targeting OLB website
Trusteer Pinpoint
Malware Detection
Trusteer Pinpoint
Criminal Detection
• Detect fraud risk
• Identify cross
channel attacks
Holistic detection of fraud
based on malware history
and persistent device ID
Trusteer’s multi-layered fraud protections
R4, R7, R10
R4, R10 R4, R7, R9, R10
14© 2015 IBM Corporation
Phishing and
malware fraud
Phishing and
malware fraud
Phishing and
malware
Trusteer
Rapport
• Detects and removes malware
• Prevents future malware infections
• Alert phishing attacks
Trusteer
Mobile SDK / Browser
R2: Risk assessment, R4: Risk control and mitigation, R7: Strong customer authentication, R9: Log-in attempts, session time out, validity of
authentication, R10: Transaction monitoring, R12: Customer education and communication
R4, R7, R10, R12
Trusteer Pinpoint Criminal Detection
Product Highlights
Trusteer
Rapport
Trusteer Pinpoint
Malware Detection
Trusteer Pinpoint
Criminal Detection
Trusteer
Mobile
15© 2015 IBM Corporation
Correlates Device and Account Risk Factors to
conclusively detect account takeover attempts
Automated Criminal Device Detection feeds a Global
Criminal Device Database
Automated Fraud Rules Creation based on Real-time
threat and attack intelligence
Transaction Anomaly Detection
Trusteer Pinpoint Malware Detection
Product Highlights
Trusteer Pinpoint
Criminal Detection
Trusteer
Rapport
Trusteer Pinpoint
Malware Detection
Trusteer
Mobile
16© 2015 IBM Corporation
Clientless detection of live Man-in-the-Browser (MitB)
Malware
Real-time alerts of high risk devices
Updates automatically deployed without customer
interaction and no business interruption
Integrate data into existing systems and workflows
Trusteer Mobile Solutions
Product Highlights
Trusteer Pinpoint
Criminal Detection
Trusteer Pinpoint
Malware Detection
Trusteer
Rapport
Trusteer
Mobile
17© 2015 IBM Corporation
Captures Persistent Device ID and Device, User and
Session Risk Factors
Comprehensive Fraud Protection Across Bank Mobile
Apps and Mobile Web Access
Correlates Mobile-specific risk, Online Risk (malware and
phishing) and Global Criminal Devices DB to prevent
Cross-Channel Attacks
Trusteer Rapport
Product Highlights
Pinpoint Criminal
Detection
Pinpoint Malware
Detection
Trusteer
Mobile
Trusteer
Rapport
18© 2015 IBM Corporation
Compact Software Agent for PC and Mac – minimal
impact on the end-user’s machine
Transparently protects user credentials & website
interaction
Removes existing infections upon installation and alerts
user & security team of potential phishing sites &
credentials loss
Trusteer Solutions
And how they match the requirements
ECB/EBA Guidance How can IBM Security Trusteer help?
Risk Assessment
Risk Control and mitigation
Incident monitoring and reporting
Strong customer authentication
19© 2015 IBM Corporation
Enrolment for, and provision of,
authentication tools and/or software
delivered to the customer
Log-in attempts, session time out, validity
of authentication
Transaction monitoring
Customer education and communication
Summary
© 2015 IBM Corporation
Summary
Why IBM Security Trusteer
• 475+ leading global organizations put their TRUST in us
• Threat Intelligence gathered from more than 270 million endpoints
Helps prevent the ““““Root
Cause”””” of Fraud
Helps prevent the ““““Root
Cause”””” of Fraud 7/10
Top U.S.
Banks
9/10
Top U.K.
Banks
4/5
Top Canadian
Banks
21© 2015 IBM Corporation
Reduce
Operational Impact
Reduce
Operational Impact
Utilize Global
Malware Intelligence Service
Utilize Global
Malware Intelligence Service
Improve Your
Customer Experience
Improve Your
Customer Experience
Banks Banks Banks
Major
European
Banks
2/4
Top Japanese
Banks
Major
Latin American
Banks
Q&A
© 2015 IBM Corporation
Statement of Good Security Practices: IT system security involves protecting systems and information through prevention, detection and response to improper access from within and outside
your enterprise. Improper access can result in information being altered, destroyed, misappropriated or misused or can result in damage to or misuse of your systems, including for use in attacks
on others. No IT system or product should be considered completely secure and no single product, service or security measure can be completely effective in preventing improper use or access.
IBM systems, products and services are designed to be part of a lawful, comprehensive security approach, which will necessarily involve additional operational procedures, and may require other
systems, products or services to be most effective. IBM DOES NOT WARRANT THAT ANY SYSTEMS, PRODUCTS OR SERVICES ARE IMMUNE FROM, OR WILL MAKE YOUR ENTERPRISE
IMMUNE FROM, THE MALICIOUS OR ILLEGAL CONDUCT OF ANY PARTY.
THANK YOUwww.ibm.com/security
© Copyright IBM Corporation 2015. All rights reserved. The information contained in these materials is provided for informational purposes only, and is provided AS IS without warranty of any
kind, express or implied. IBM shall not be responsible for any damages arising out of the use of, or otherwise related to, these materials. Nothing contained in these materials is intended to, nor
shall have the effect of, creating any warranties or representations from IBM or its suppliers or licensors, or altering the terms and conditions of the applicable license agreement governing the use
of IBM software. References in these materials to IBM products, programs, or services do not imply that they will be available in all countries in which IBM operates. Product release dates and / or
capabilities referenced in these materials may change at any time at IBM’s sole discretion based on market opportunities or other factors, and are not intended to be a commitment to future product
or feature availability in any way. IBM, the IBM logo, and other IBM products and services are trademarks of the International Business Machines Corporation, in the United States, other countries
or both. Other company, product, or service names may be trademarks or service marks of others.
1 de 23

Recomendados

IBM Security AppExchange Spotlight: Threat Intelligence & Monitoring Microso... por
IBM Security AppExchange Spotlight: Threat Intelligence &  Monitoring Microso...IBM Security AppExchange Spotlight: Threat Intelligence &  Monitoring Microso...
IBM Security AppExchange Spotlight: Threat Intelligence & Monitoring Microso...IBM Security
1.9K visualizações37 slides
The Next Stage of Fraud Protection: IBM Security Trusteer Fraud Protection Suite por
The Next Stage of Fraud Protection: IBM Security Trusteer Fraud Protection SuiteThe Next Stage of Fraud Protection: IBM Security Trusteer Fraud Protection Suite
The Next Stage of Fraud Protection: IBM Security Trusteer Fraud Protection SuiteIBM Security
1.9K visualizações23 slides
QRadar & XGS: Stopping Attacks with a Click of the Mouse por
QRadar & XGS: Stopping Attacks with a Click of the MouseQRadar & XGS: Stopping Attacks with a Click of the Mouse
QRadar & XGS: Stopping Attacks with a Click of the MouseIBM Security
1.5K visualizações38 slides
Cloud security enforcer - Quick steps to avoid the blind spots of shadow it por
Cloud security enforcer - Quick steps to avoid the blind spots of shadow itCloud security enforcer - Quick steps to avoid the blind spots of shadow it
Cloud security enforcer - Quick steps to avoid the blind spots of shadow itIBM Security
745 visualizações25 slides
5 Ways to Get Even More from Your IBM Security QRadar Investment in 2016 por
5 Ways to Get Even More from Your IBM Security QRadar Investment in 20165 Ways to Get Even More from Your IBM Security QRadar Investment in 2016
5 Ways to Get Even More from Your IBM Security QRadar Investment in 2016IBM Security
9.3K visualizações40 slides
The ROI on Intrusion Prevention: Protecting Both Your Network & Investment por
The ROI on Intrusion Prevention: Protecting Both Your Network & InvestmentThe ROI on Intrusion Prevention: Protecting Both Your Network & Investment
The ROI on Intrusion Prevention: Protecting Both Your Network & InvestmentIBM Security
2.1K visualizações33 slides

Mais conteúdo relacionado

Mais procurados

Valuing Data in the Age of Ransomware por
Valuing Data in the Age of Ransomware Valuing Data in the Age of Ransomware
Valuing Data in the Age of Ransomware IBM Security
703 visualizações28 slides
Borderless Breaches and Migrating Malware: How Cybercrime is Breaking Down Ba... por
Borderless Breaches and Migrating Malware: How Cybercrime is Breaking Down Ba...Borderless Breaches and Migrating Malware: How Cybercrime is Breaking Down Ba...
Borderless Breaches and Migrating Malware: How Cybercrime is Breaking Down Ba...IBM Security
1.1K visualizações20 slides
Don’t Drown in a Sea of Cyberthreats: Mitigate Attacks with IBM BigFix & QRadar por
Don’t Drown in a Sea of Cyberthreats: Mitigate Attacks with IBM BigFix & QRadarDon’t Drown in a Sea of Cyberthreats: Mitigate Attacks with IBM BigFix & QRadar
Don’t Drown in a Sea of Cyberthreats: Mitigate Attacks with IBM BigFix & QRadarIBM Security
4K visualizações25 slides
Compete To Win: Don’t Just Be Compliant – Be Secure! por
Compete To Win: Don’t Just Be Compliant – Be Secure!Compete To Win: Don’t Just Be Compliant – Be Secure!
Compete To Win: Don’t Just Be Compliant – Be Secure!IBM Security
1.1K visualizações32 slides
Outsmart Fraudsters: Give Customers Great User Experience While Keeping Fraud... por
Outsmart Fraudsters: Give Customers Great User Experience While Keeping Fraud...Outsmart Fraudsters: Give Customers Great User Experience While Keeping Fraud...
Outsmart Fraudsters: Give Customers Great User Experience While Keeping Fraud...IBM Security
672 visualizações32 slides
10 Security Essentials Every CxO Should Know por
10 Security Essentials Every CxO Should Know10 Security Essentials Every CxO Should Know
10 Security Essentials Every CxO Should KnowIBM Security
8.6K visualizações22 slides

Mais procurados(20)

Valuing Data in the Age of Ransomware por IBM Security
Valuing Data in the Age of Ransomware Valuing Data in the Age of Ransomware
Valuing Data in the Age of Ransomware
IBM Security703 visualizações
Borderless Breaches and Migrating Malware: How Cybercrime is Breaking Down Ba... por IBM Security
Borderless Breaches and Migrating Malware: How Cybercrime is Breaking Down Ba...Borderless Breaches and Migrating Malware: How Cybercrime is Breaking Down Ba...
Borderless Breaches and Migrating Malware: How Cybercrime is Breaking Down Ba...
IBM Security1.1K visualizações
Don’t Drown in a Sea of Cyberthreats: Mitigate Attacks with IBM BigFix & QRadar por IBM Security
Don’t Drown in a Sea of Cyberthreats: Mitigate Attacks with IBM BigFix & QRadarDon’t Drown in a Sea of Cyberthreats: Mitigate Attacks with IBM BigFix & QRadar
Don’t Drown in a Sea of Cyberthreats: Mitigate Attacks with IBM BigFix & QRadar
IBM Security4K visualizações
Compete To Win: Don’t Just Be Compliant – Be Secure! por IBM Security
Compete To Win: Don’t Just Be Compliant – Be Secure!Compete To Win: Don’t Just Be Compliant – Be Secure!
Compete To Win: Don’t Just Be Compliant – Be Secure!
IBM Security1.1K visualizações
Outsmart Fraudsters: Give Customers Great User Experience While Keeping Fraud... por IBM Security
Outsmart Fraudsters: Give Customers Great User Experience While Keeping Fraud...Outsmart Fraudsters: Give Customers Great User Experience While Keeping Fraud...
Outsmart Fraudsters: Give Customers Great User Experience While Keeping Fraud...
IBM Security672 visualizações
10 Security Essentials Every CxO Should Know por IBM Security
10 Security Essentials Every CxO Should Know10 Security Essentials Every CxO Should Know
10 Security Essentials Every CxO Should Know
IBM Security8.6K visualizações
Orchestrate Your Security Defenses; Protect Against Insider Threats por IBM Security
Orchestrate Your Security Defenses; Protect Against Insider Threats Orchestrate Your Security Defenses; Protect Against Insider Threats
Orchestrate Your Security Defenses; Protect Against Insider Threats
IBM Security1.2K visualizações
Infographic: Mobile is growing and so are security threats por IBM Security
Infographic: Mobile is growing and so are security threatsInfographic: Mobile is growing and so are security threats
Infographic: Mobile is growing and so are security threats
IBM Security4K visualizações
What’s the State of Your Endpoint Security? por IBM Security
What’s the State of Your    Endpoint Security?What’s the State of Your    Endpoint Security?
What’s the State of Your Endpoint Security?
IBM Security2.4K visualizações
Accelerating SOC Transformation with IBM Resilient and Carbon Black por IBM Security
Accelerating SOC Transformation with IBM Resilient and Carbon BlackAccelerating SOC Transformation with IBM Resilient and Carbon Black
Accelerating SOC Transformation with IBM Resilient and Carbon Black
IBM Security966 visualizações
Bridging the Gap between Privacy and Security: Using Technology to Manage Com... por IBM Security
Bridging the Gap between Privacy and Security: Using Technology to Manage Com...Bridging the Gap between Privacy and Security: Using Technology to Manage Com...
Bridging the Gap between Privacy and Security: Using Technology to Manage Com...
IBM Security941 visualizações
4 Ways to Build your Immunity to Cyberthreats por IBM Security
4 Ways to Build your Immunity to Cyberthreats4 Ways to Build your Immunity to Cyberthreats
4 Ways to Build your Immunity to Cyberthreats
IBM Security1.3K visualizações
Life on the Endpoint Edge: Winning the Battle Against Cyber Attacks por IBM Security
Life on the Endpoint Edge: Winning the Battle Against Cyber AttacksLife on the Endpoint Edge: Winning the Battle Against Cyber Attacks
Life on the Endpoint Edge: Winning the Battle Against Cyber Attacks
IBM Security3.7K visualizações
Tolly Report: Stopping Attacks You Can't See por IBM Security
Tolly Report: Stopping Attacks You Can't SeeTolly Report: Stopping Attacks You Can't See
Tolly Report: Stopping Attacks You Can't See
IBM Security942 visualizações
Cybersecurity in the Cognitive Era: Priming Your Digital Immune System por IBM Security
Cybersecurity in the Cognitive Era: Priming Your Digital Immune SystemCybersecurity in the Cognitive Era: Priming Your Digital Immune System
Cybersecurity in the Cognitive Era: Priming Your Digital Immune System
IBM Security1.1K visualizações
Are Cloud Apps the Invisible Man? por IBM Security
Are Cloud Apps the Invisible Man?Are Cloud Apps the Invisible Man?
Are Cloud Apps the Invisible Man?
IBM Security1.2K visualizações
Cutting Through the Software License Jungle: Stay Safe and Control Costs por IBM Security
Cutting Through the Software License Jungle: Stay Safe and Control CostsCutting Through the Software License Jungle: Stay Safe and Control Costs
Cutting Through the Software License Jungle: Stay Safe and Control Costs
IBM Security1.1K visualizações
Security Trends in the Retail Industry por IBM Security
Security Trends in the Retail IndustrySecurity Trends in the Retail Industry
Security Trends in the Retail Industry
IBM Security3.1K visualizações
Safeguard Healthcare Identities and Data with Identity Governance and Intelli... por IBM Security
Safeguard Healthcare Identities and Data with Identity Governance and Intelli...Safeguard Healthcare Identities and Data with Identity Governance and Intelli...
Safeguard Healthcare Identities and Data with Identity Governance and Intelli...
IBM Security1.3K visualizações
Malware on Smartphones and Tablets: The Inconvenient Truth por IBM Security
Malware on Smartphones and Tablets: The Inconvenient TruthMalware on Smartphones and Tablets: The Inconvenient Truth
Malware on Smartphones and Tablets: The Inconvenient Truth
IBM Security1.7K visualizações

Destaque

Pulse 2013 - How to run a successful BYOD initiative por
Pulse 2013 - How to run a successful BYOD initiativePulse 2013 - How to run a successful BYOD initiative
Pulse 2013 - How to run a successful BYOD initiativeChris Pepin
3.2K visualizações15 slides
Introducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat Prevention por
Introducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat PreventionIntroducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat Prevention
Introducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat PreventionIBM Security
4K visualizações21 slides
Best practices for mobile enterprise security and the importance of endpoint ... por
Best practices for mobile enterprise security and the importance of endpoint ...Best practices for mobile enterprise security and the importance of endpoint ...
Best practices for mobile enterprise security and the importance of endpoint ...Chris Pepin
5.4K visualizações33 slides
Pulse 2013 - Mobile strategy and user centered design, an IBM interactive primer por
Pulse 2013 - Mobile strategy and user centered design, an IBM interactive primerPulse 2013 - Mobile strategy and user centered design, an IBM interactive primer
Pulse 2013 - Mobile strategy and user centered design, an IBM interactive primerChris Pepin
6.4K visualizações37 slides
Close the Loop on Incident Response por
Close the Loop on Incident ResponseClose the Loop on Incident Response
Close the Loop on Incident ResponseIBM Security
2.6K visualizações1 slide
Retail Mobility, Productivity and Security por
Retail Mobility, Productivity and SecurityRetail Mobility, Productivity and Security
Retail Mobility, Productivity and SecurityIBM Security
1.4K visualizações1 slide

Destaque(13)

Pulse 2013 - How to run a successful BYOD initiative por Chris Pepin
Pulse 2013 - How to run a successful BYOD initiativePulse 2013 - How to run a successful BYOD initiative
Pulse 2013 - How to run a successful BYOD initiative
Chris Pepin3.2K visualizações
Introducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat Prevention por IBM Security
Introducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat PreventionIntroducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat Prevention
Introducing IBM Cloud Security Enforcer, CASB, IDaaS and Threat Prevention
IBM Security4K visualizações
Best practices for mobile enterprise security and the importance of endpoint ... por Chris Pepin
Best practices for mobile enterprise security and the importance of endpoint ...Best practices for mobile enterprise security and the importance of endpoint ...
Best practices for mobile enterprise security and the importance of endpoint ...
Chris Pepin5.4K visualizações
Pulse 2013 - Mobile strategy and user centered design, an IBM interactive primer por Chris Pepin
Pulse 2013 - Mobile strategy and user centered design, an IBM interactive primerPulse 2013 - Mobile strategy and user centered design, an IBM interactive primer
Pulse 2013 - Mobile strategy and user centered design, an IBM interactive primer
Chris Pepin6.4K visualizações
Close the Loop on Incident Response por IBM Security
Close the Loop on Incident ResponseClose the Loop on Incident Response
Close the Loop on Incident Response
IBM Security2.6K visualizações
Retail Mobility, Productivity and Security por IBM Security
Retail Mobility, Productivity and SecurityRetail Mobility, Productivity and Security
Retail Mobility, Productivity and Security
IBM Security1.4K visualizações
Some experiences from early-stage Australian startups por David Jones
Some experiences from early-stage Australian startupsSome experiences from early-stage Australian startups
Some experiences from early-stage Australian startups
David Jones705 visualizações
Security and Authentication at a Low Cost por Donald Malloy
Security and Authentication at a Low CostSecurity and Authentication at a Low Cost
Security and Authentication at a Low Cost
Donald Malloy961 visualizações
ThreatMetrix – Building Trust on the Internet por ThreatMetrix
ThreatMetrix – Building Trust on the InternetThreatMetrix – Building Trust on the Internet
ThreatMetrix – Building Trust on the Internet
ThreatMetrix1.2K visualizações
How to lead a large organization through agile transformation bodhi choudhuri por Bodhi Choudhuri
How to lead a large organization through agile transformation bodhi choudhuriHow to lead a large organization through agile transformation bodhi choudhuri
How to lead a large organization through agile transformation bodhi choudhuri
Bodhi Choudhuri453 visualizações
IBM Insight 2015 - Security Sessions Roadmap por IBM Security
IBM Insight 2015 - Security Sessions RoadmapIBM Insight 2015 - Security Sessions Roadmap
IBM Insight 2015 - Security Sessions Roadmap
IBM Security4.4K visualizações
Computación básica por deyipaola
Computación básicaComputación básica
Computación básica
deyipaola191 visualizações
ThreatMetrix ARRC 2016 presentation by Ted Egan por Ken Lam
ThreatMetrix ARRC 2016 presentation by Ted EganThreatMetrix ARRC 2016 presentation by Ted Egan
ThreatMetrix ARRC 2016 presentation by Ted Egan
Ken Lam643 visualizações

Similar a Recent ECB/ EBA regulations how they will impact European banks in 2016

IBM Security - 2015 - Client References Guide por
IBM Security - 2015 - Client References GuideIBM Security - 2015 - Client References Guide
IBM Security - 2015 - Client References GuideFrancisco González Jiménez
2.2K visualizações69 slides
3 Enablers of Successful Cyber Attacks and How to Thwart Them por
3 Enablers of Successful Cyber Attacks and How to Thwart Them3 Enablers of Successful Cyber Attacks and How to Thwart Them
3 Enablers of Successful Cyber Attacks and How to Thwart ThemIBM Security
1.4K visualizações18 slides
Combating Constantly Evolving Advanced Threats – Solution Architecture por
Combating Constantly Evolving Advanced Threats – Solution ArchitectureCombating Constantly Evolving Advanced Threats – Solution Architecture
Combating Constantly Evolving Advanced Threats – Solution ArchitectureIBM Sverige
1.6K visualizações10 slides
How to assess your Cybersecurity Vulnerability_.pptx por
How to assess your Cybersecurity Vulnerability_.pptxHow to assess your Cybersecurity Vulnerability_.pptx
How to assess your Cybersecurity Vulnerability_.pptxMetaorange
10 visualizações24 slides
How to assess your Cybersecurity Vulnerability_.pdf por
How to assess your Cybersecurity Vulnerability_.pdfHow to assess your Cybersecurity Vulnerability_.pdf
How to assess your Cybersecurity Vulnerability_.pdfMetaorange
9 visualizações24 slides
IBM BigFix: Closing the Endpoint Gap Between IT Ops and Security por
IBM BigFix: Closing the Endpoint Gap Between IT Ops and SecurityIBM BigFix: Closing the Endpoint Gap Between IT Ops and Security
IBM BigFix: Closing the Endpoint Gap Between IT Ops and SecurityIBM Security
6.6K visualizações26 slides

Similar a Recent ECB/ EBA regulations how they will impact European banks in 2016(20)

3 Enablers of Successful Cyber Attacks and How to Thwart Them por IBM Security
3 Enablers of Successful Cyber Attacks and How to Thwart Them3 Enablers of Successful Cyber Attacks and How to Thwart Them
3 Enablers of Successful Cyber Attacks and How to Thwart Them
IBM Security1.4K visualizações
Combating Constantly Evolving Advanced Threats – Solution Architecture por IBM Sverige
Combating Constantly Evolving Advanced Threats – Solution ArchitectureCombating Constantly Evolving Advanced Threats – Solution Architecture
Combating Constantly Evolving Advanced Threats – Solution Architecture
IBM Sverige1.6K visualizações
How to assess your Cybersecurity Vulnerability_.pptx por Metaorange
How to assess your Cybersecurity Vulnerability_.pptxHow to assess your Cybersecurity Vulnerability_.pptx
How to assess your Cybersecurity Vulnerability_.pptx
Metaorange10 visualizações
How to assess your Cybersecurity Vulnerability_.pdf por Metaorange
How to assess your Cybersecurity Vulnerability_.pdfHow to assess your Cybersecurity Vulnerability_.pdf
How to assess your Cybersecurity Vulnerability_.pdf
Metaorange9 visualizações
IBM BigFix: Closing the Endpoint Gap Between IT Ops and Security por IBM Security
IBM BigFix: Closing the Endpoint Gap Between IT Ops and SecurityIBM BigFix: Closing the Endpoint Gap Between IT Ops and Security
IBM BigFix: Closing the Endpoint Gap Between IT Ops and Security
IBM Security6.6K visualizações
Webinar-MSP+ Cyber Insurance Fina.pptx por ControlCase
Webinar-MSP+  Cyber Insurance Fina.pptxWebinar-MSP+  Cyber Insurance Fina.pptx
Webinar-MSP+ Cyber Insurance Fina.pptx
ControlCase69 visualizações
Convince your board - cyber attack prevention is better than cure por Dave James
Convince your board - cyber attack prevention is better than cureConvince your board - cyber attack prevention is better than cure
Convince your board - cyber attack prevention is better than cure
Dave James4.5K visualizações
Cyber crime in a Smart Phone & Social Media Obsessed World por John Palfreyman
Cyber crime in a Smart Phone & Social Media Obsessed WorldCyber crime in a Smart Phone & Social Media Obsessed World
Cyber crime in a Smart Phone & Social Media Obsessed World
John Palfreyman2.1K visualizações
Smart security solutions for SMBs por Jyothi Satyanathan
Smart security solutions for SMBsSmart security solutions for SMBs
Smart security solutions for SMBs
Jyothi Satyanathan953 visualizações
Securing Mobile Banking Apps - You Are Only as Strong as Your Weakest Link por IBM Security
Securing Mobile Banking Apps - You Are Only as Strong as Your Weakest LinkSecuring Mobile Banking Apps - You Are Only as Strong as Your Weakest Link
Securing Mobile Banking Apps - You Are Only as Strong as Your Weakest Link
IBM Security2.7K visualizações
Bordless Breaches and Migrating Malware por Sarah Freemantle
Bordless Breaches and Migrating MalwareBordless Breaches and Migrating Malware
Bordless Breaches and Migrating Malware
Sarah Freemantle229 visualizações
How to Raise Cyber Risk Awareness and Management to the C-Suite por SurfWatch Labs
How to Raise Cyber Risk Awareness and Management to the C-SuiteHow to Raise Cyber Risk Awareness and Management to the C-Suite
How to Raise Cyber Risk Awareness and Management to the C-Suite
SurfWatch Labs1.1K visualizações
Building a Next-Generation Security Operation Center Based on IBM QRadar and ... por IBM Security
Building a Next-Generation Security Operation Center Based on IBM QRadar and ...Building a Next-Generation Security Operation Center Based on IBM QRadar and ...
Building a Next-Generation Security Operation Center Based on IBM QRadar and ...
IBM Security20.9K visualizações
IBM Security Services Overview por Casey Lucas
IBM Security Services OverviewIBM Security Services Overview
IBM Security Services Overview
Casey Lucas2.5K visualizações
Mobile Payments: Protecting Apps and Data from Emerging Risks por IBM Security
Mobile Payments: Protecting Apps and Data from Emerging RisksMobile Payments: Protecting Apps and Data from Emerging Risks
Mobile Payments: Protecting Apps and Data from Emerging Risks
IBM Security1.4K visualizações

Mais de IBM Security

Automation: Embracing the Future of SecOps por
Automation: Embracing the Future of SecOpsAutomation: Embracing the Future of SecOps
Automation: Embracing the Future of SecOpsIBM Security
2K visualizações22 slides
Leaders & Laggards: The Latest Findings from the Ponemon Institute’s Study on... por
Leaders & Laggards: The Latest Findings from the Ponemon Institute’s Study on...Leaders & Laggards: The Latest Findings from the Ponemon Institute’s Study on...
Leaders & Laggards: The Latest Findings from the Ponemon Institute’s Study on...IBM Security
914 visualizações39 slides
Integrated Response with v32 of IBM Resilient por
Integrated Response with v32 of IBM ResilientIntegrated Response with v32 of IBM Resilient
Integrated Response with v32 of IBM ResilientIBM Security
1K visualizações21 slides
The Resilient End-of-Year Review: The Top Cyber Security Trends in 2018 and P... por
The Resilient End-of-Year Review: The Top Cyber Security Trends in 2018 and P...The Resilient End-of-Year Review: The Top Cyber Security Trends in 2018 and P...
The Resilient End-of-Year Review: The Top Cyber Security Trends in 2018 and P...IBM Security
775 visualizações12 slides
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated... por
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...IBM Security
742 visualizações18 slides
How to Build a Faster, Laser-Sharp SOC with Intelligent Orchestration por
How to Build a Faster, Laser-Sharp SOC with Intelligent OrchestrationHow to Build a Faster, Laser-Sharp SOC with Intelligent Orchestration
How to Build a Faster, Laser-Sharp SOC with Intelligent OrchestrationIBM Security
1.3K visualizações27 slides

Mais de IBM Security(20)

Automation: Embracing the Future of SecOps por IBM Security
Automation: Embracing the Future of SecOpsAutomation: Embracing the Future of SecOps
Automation: Embracing the Future of SecOps
IBM Security2K visualizações
Leaders & Laggards: The Latest Findings from the Ponemon Institute’s Study on... por IBM Security
Leaders & Laggards: The Latest Findings from the Ponemon Institute’s Study on...Leaders & Laggards: The Latest Findings from the Ponemon Institute’s Study on...
Leaders & Laggards: The Latest Findings from the Ponemon Institute’s Study on...
IBM Security914 visualizações
Integrated Response with v32 of IBM Resilient por IBM Security
Integrated Response with v32 of IBM ResilientIntegrated Response with v32 of IBM Resilient
Integrated Response with v32 of IBM Resilient
IBM Security1K visualizações
The Resilient End-of-Year Review: The Top Cyber Security Trends in 2018 and P... por IBM Security
The Resilient End-of-Year Review: The Top Cyber Security Trends in 2018 and P...The Resilient End-of-Year Review: The Top Cyber Security Trends in 2018 and P...
The Resilient End-of-Year Review: The Top Cyber Security Trends in 2018 and P...
IBM Security775 visualizações
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated... por IBM Security
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...
IBM Security742 visualizações
How to Build a Faster, Laser-Sharp SOC with Intelligent Orchestration por IBM Security
How to Build a Faster, Laser-Sharp SOC with Intelligent OrchestrationHow to Build a Faster, Laser-Sharp SOC with Intelligent Orchestration
How to Build a Faster, Laser-Sharp SOC with Intelligent Orchestration
IBM Security1.3K visualizações
Are You Ready to Move Your IAM to the Cloud? por IBM Security
Are You Ready to Move Your IAM to the Cloud?Are You Ready to Move Your IAM to the Cloud?
Are You Ready to Move Your IAM to the Cloud?
IBM Security2K visualizações
Orchestrate Your Security Defenses to Optimize the Impact of Threat Intelligence por IBM Security
Orchestrate Your Security Defenses to Optimize the Impact of Threat IntelligenceOrchestrate Your Security Defenses to Optimize the Impact of Threat Intelligence
Orchestrate Your Security Defenses to Optimize the Impact of Threat Intelligence
IBM Security3.2K visualizações
Your Mainframe Environment is a Treasure Trove: Is Your Sensitive Data Protec... por IBM Security
Your Mainframe Environment is a Treasure Trove: Is Your Sensitive Data Protec...Your Mainframe Environment is a Treasure Trove: Is Your Sensitive Data Protec...
Your Mainframe Environment is a Treasure Trove: Is Your Sensitive Data Protec...
IBM Security1.1K visualizações
Meet the New IBM i2 QRadar Offense Investigator App and Start Threat Hunting ... por IBM Security
Meet the New IBM i2 QRadar Offense Investigator App and Start Threat Hunting ...Meet the New IBM i2 QRadar Offense Investigator App and Start Threat Hunting ...
Meet the New IBM i2 QRadar Offense Investigator App and Start Threat Hunting ...
IBM Security4.2K visualizações
Understanding the Impact of Today's Security Breaches: The 2017 Ponemon Cost ... por IBM Security
Understanding the Impact of Today's Security Breaches: The 2017 Ponemon Cost ...Understanding the Impact of Today's Security Breaches: The 2017 Ponemon Cost ...
Understanding the Impact of Today's Security Breaches: The 2017 Ponemon Cost ...
IBM Security3.6K visualizações
WannaCry Ransomware Attack: What to Do Now por IBM Security
WannaCry Ransomware Attack: What to Do NowWannaCry Ransomware Attack: What to Do Now
WannaCry Ransomware Attack: What to Do Now
IBM Security6.9K visualizações
How to Improve Threat Detection & Simplify Security Operations por IBM Security
How to Improve Threat Detection & Simplify Security OperationsHow to Improve Threat Detection & Simplify Security Operations
How to Improve Threat Detection & Simplify Security Operations
IBM Security1.9K visualizações
Mobile Vision 2020 por IBM Security
Mobile Vision 2020Mobile Vision 2020
Mobile Vision 2020
IBM Security1.5K visualizações
See How You Measure Up With MaaS360 Mobile Metrics por IBM Security
See How You Measure Up With MaaS360 Mobile MetricsSee How You Measure Up With MaaS360 Mobile Metrics
See How You Measure Up With MaaS360 Mobile Metrics
IBM Security1.2K visualizações
Nowhere to Hide: Expose Threats in Real-time with IBM QRadar Network Insights por IBM Security
Nowhere to Hide: Expose Threats in Real-time with IBM QRadar Network InsightsNowhere to Hide: Expose Threats in Real-time with IBM QRadar Network Insights
Nowhere to Hide: Expose Threats in Real-time with IBM QRadar Network Insights
IBM Security2.7K visualizações
Top 12 Cybersecurity Predictions for 2017 por IBM Security
Top 12 Cybersecurity Predictions for 2017Top 12 Cybersecurity Predictions for 2017
Top 12 Cybersecurity Predictions for 2017
IBM Security1.3K visualizações
Cybersecurity In The Cognitive Era: Priming Your Digital Immune System por IBM Security
Cybersecurity In The Cognitive Era: Priming Your Digital Immune SystemCybersecurity In The Cognitive Era: Priming Your Digital Immune System
Cybersecurity In The Cognitive Era: Priming Your Digital Immune System
IBM Security675 visualizações
Top 5 Things to Look for in an IPS Solution por IBM Security
Top 5 Things to Look for in an IPS SolutionTop 5 Things to Look for in an IPS Solution
Top 5 Things to Look for in an IPS Solution
IBM Security1.4K visualizações
Detect and Respond to Threats Better with IBM Security App Exchange Partners por IBM Security
Detect and Respond to Threats Better with IBM Security App Exchange PartnersDetect and Respond to Threats Better with IBM Security App Exchange Partners
Detect and Respond to Threats Better with IBM Security App Exchange Partners
IBM Security956 visualizações

Último

iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas... por
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...Bernd Ruecker
37 visualizações69 slides
Design Driven Network Assurance por
Design Driven Network AssuranceDesign Driven Network Assurance
Design Driven Network AssuranceNetwork Automation Forum
15 visualizações42 slides
Ransomware is Knocking your Door_Final.pdf por
Ransomware is Knocking your Door_Final.pdfRansomware is Knocking your Door_Final.pdf
Ransomware is Knocking your Door_Final.pdfSecurity Bootcamp
55 visualizações46 slides
Scaling Knowledge Graph Architectures with AI por
Scaling Knowledge Graph Architectures with AIScaling Knowledge Graph Architectures with AI
Scaling Knowledge Graph Architectures with AIEnterprise Knowledge
30 visualizações15 slides
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdf por
STKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdfSTKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdf
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdfDr. Jimmy Schwarzkopf
19 visualizações29 slides
SAP Automation Using Bar Code and FIORI.pdf por
SAP Automation Using Bar Code and FIORI.pdfSAP Automation Using Bar Code and FIORI.pdf
SAP Automation Using Bar Code and FIORI.pdfVirendra Rai, PMP
23 visualizações38 slides

Último(20)

iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas... por Bernd Ruecker
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...
Bernd Ruecker37 visualizações
Ransomware is Knocking your Door_Final.pdf por Security Bootcamp
Ransomware is Knocking your Door_Final.pdfRansomware is Knocking your Door_Final.pdf
Ransomware is Knocking your Door_Final.pdf
Security Bootcamp55 visualizações
Scaling Knowledge Graph Architectures with AI por Enterprise Knowledge
Scaling Knowledge Graph Architectures with AIScaling Knowledge Graph Architectures with AI
Scaling Knowledge Graph Architectures with AI
Enterprise Knowledge30 visualizações
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdf por Dr. Jimmy Schwarzkopf
STKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdfSTKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdf
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdf
Dr. Jimmy Schwarzkopf19 visualizações
SAP Automation Using Bar Code and FIORI.pdf por Virendra Rai, PMP
SAP Automation Using Bar Code and FIORI.pdfSAP Automation Using Bar Code and FIORI.pdf
SAP Automation Using Bar Code and FIORI.pdf
Virendra Rai, PMP23 visualizações
Mini-Track: AI and ML in Network Operations Applications por Network Automation Forum
Mini-Track: AI and ML in Network Operations ApplicationsMini-Track: AI and ML in Network Operations Applications
Mini-Track: AI and ML in Network Operations Applications
Network Automation Forum10 visualizações
Evolving the Network Automation Journey from Python to Platforms por Network Automation Forum
Evolving the Network Automation Journey from Python to PlatformsEvolving the Network Automation Journey from Python to Platforms
Evolving the Network Automation Journey from Python to Platforms
Network Automation Forum13 visualizações
Network Source of Truth and Infrastructure as Code revisited por Network Automation Forum
Network Source of Truth and Infrastructure as Code revisitedNetwork Source of Truth and Infrastructure as Code revisited
Network Source of Truth and Infrastructure as Code revisited
Network Automation Forum26 visualizações
6g - REPORT.pdf por Liveplex
6g - REPORT.pdf6g - REPORT.pdf
6g - REPORT.pdf
Liveplex10 visualizações
Uni Systems for Power Platform.pptx por Uni Systems S.M.S.A.
Uni Systems for Power Platform.pptxUni Systems for Power Platform.pptx
Uni Systems for Power Platform.pptx
Uni Systems S.M.S.A.56 visualizações
Future of AR - Facebook Presentation por ssuserb54b561
Future of AR - Facebook PresentationFuture of AR - Facebook Presentation
Future of AR - Facebook Presentation
ssuserb54b56114 visualizações
STPI OctaNE CoE Brochure.pdf por madhurjyapb
STPI OctaNE CoE Brochure.pdfSTPI OctaNE CoE Brochure.pdf
STPI OctaNE CoE Brochure.pdf
madhurjyapb14 visualizações
Kyo - Functional Scala 2023.pdf por Flavio W. Brasil
Kyo - Functional Scala 2023.pdfKyo - Functional Scala 2023.pdf
Kyo - Functional Scala 2023.pdf
Flavio W. Brasil368 visualizações
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ... por Jasper Oosterveld
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
Jasper Oosterveld18 visualizações
Igniting Next Level Productivity with AI-Infused Data Integration Workflows por Safe Software
Igniting Next Level Productivity with AI-Infused Data Integration Workflows Igniting Next Level Productivity with AI-Infused Data Integration Workflows
Igniting Next Level Productivity with AI-Infused Data Integration Workflows
Safe Software263 visualizações
NET Conf 2023 Recap por Lee Richardson
NET Conf 2023 RecapNET Conf 2023 Recap
NET Conf 2023 Recap
Lee Richardson10 visualizações
Microsoft Power Platform.pptx por Uni Systems S.M.S.A.
Microsoft Power Platform.pptxMicrosoft Power Platform.pptx
Microsoft Power Platform.pptx
Uni Systems S.M.S.A.53 visualizações
【USB韌體設計課程】精選講義節錄-USB的列舉過程_艾鍗學院 por IttrainingIttraining
【USB韌體設計課程】精選講義節錄-USB的列舉過程_艾鍗學院【USB韌體設計課程】精選講義節錄-USB的列舉過程_艾鍗學院
【USB韌體設計課程】精選講義節錄-USB的列舉過程_艾鍗學院
IttrainingIttraining52 visualizações

Recent ECB/ EBA regulations how they will impact European banks in 2016

  • 1. Trusteer Positioning ECB/EBA Recommendations for Security of Internet Payments: © 2015 IBM Corporation Monday, December 07, 2015
  • 2. Agenda General information and milestones – Things to note The Guidelines The layered security approach How, why, and which IBM Security Trusteer product(s)? Responding to the Specific Requirements Summary / Next steps 2© 2015 IBM Corporation Summary / Next steps
  • 3. August 2015 Guidelines define minimum requirements 2017 / 2018 Additional guidelines from the EBA are expected once the updated Payment Services Directive (PSD2) is published Milestones and Recommendations 3© 2015 IBM Corporation December 2014 EBA publishes the Final Guidelines on Internet Payments Security, based on the European Forum on the Security of Retail Payments (SecuRe Pay) minimum requirements that have to be fulfilled by PSPs under the PSD published Link to the Final Guidelines
  • 4. Things to Note The recommendations constitute a “living document” The recommendations are descriptive (vs. prescriptive) The bank may address recommended solutions by other means The recommendations constitute minimum Regulations 4© 2015 IBM Corporation The recommendations constitute minimum expectations. It’s the responsibility of PSPs to monitor and assess their particular risks, develop their own detailed security policies and implement adequate security measures that are commensurate with the risks inherent in the payment services provided.
  • 5. Final guidelines on the Security Of Internet Payments As per document issued in Dec 2014 R2 • Risk Assessment R3 • Incident Monitoring and Reporting R4 • Risk Control and Mitigation R7 • Strong Customer Authentication 5© 2015 IBM Corporation R7 • Strong Customer Authentication R8 • Enrolment for, and provision of authentication, tools and/or software delivered to the customer R9 • Log-in attempts, session time out, validity of authentication R10 • Transaction Monitoring R12 • Customer Education and Communication
  • 6. The Guiding Principles Fraud prevention layers, listed in order of effectiveness Device Security • Ensuring the accessing device is secure and malware free User Authentication • Verify the authorized user and device with multifactor (tamper-proof) user authentication Transaction Monitoring 6© 2015 IBM Corporation Transaction Monitoring • Identify anomalous user behaviors and known fraud patterns Network Analysis • Correlate known fraud with other potentially fraudulent events Customer Awareness and Education • Ongoing customer education through continuous communication
  • 7. Existing security controls Do they impact your business? 7© 2015 IBM Corporation Account &Transaction Restrictions Intrusive Controls Increased Authentication Challenges IncreasedTransaction Delays Increased Investigation Costs DisruptiveValidation & Verification
  • 8. At a glance ECB Recommendations mapped to Trusteer’s solutions (I) Recommendation 2: Risk Assessment KC 2.1 (Risk Assessment) Trusteer Cybercrime Intelligence Recommendation 3: Incident monitoring and reporting KC 3.1 (Reporting) Trusteer Cybercrime Intelligence 8© 2015 IBM Corporation Recommendation 4: Risk Control and Mitigation KC 4.2 (Phishing) Trusteer Rapport and Trusteer Pinpoint BP 4.1 (Trojans) Trusteer Rapport, Trusteer Pinpoint, Trusteer Mobile Solutions (Mobile SDK, Secure Mobile Browser) AQ = Assessment Question BP = Best Practice KC = Key Consideration
  • 9. At a glance ECB Recommendations mapped to Trusteer’s solutions (II) Recommendation 7: Strong customer authentication AQ 7.0.1 (Use of 2+ elements for authentication) Trusteer Pinpoint and Trusteer Mobile SDK AQ 7.0.4 (Protection of multi- purpose devices) Trusteer Mobile SDK; Trusteer Rapport; Trusteer Pinpoint 9© 2015 IBM Corporation AQ 7.0.8 (Protection of devices where secrets are stored) Trusteer Rapport and Trusteer Mobile SDK AQ = Assessment Question BP = Best Practice KC = Key Consideration
  • 10. At a glance ECB Recommendations mapped to Trusteer’s solutions (III) Recommendation 8: Enrolment for and provision of authentication tools and/or software delivered to the customer AQ 8.1.1 (Protection of payments – safe and trusted environment) Trusteer Rapport, Trusteer Pinpoint, and Trusteer Mobile SDK AQ 8.1.1 (Software delivered to customers not under the bank’s control) Trusteer Rapport; Trusteer Pinpoint, and Trusteer Mobile SDK 10© 2015 IBM Corporation control) Trusteer Mobile SDK Recommendation 9: Log-in attempts, session time out, validity of authentication KC 9.1, KC 9.2, KC 9.3 (Log-in attempts, session time out, validity of authentication) Trusteer Pinpoint AQ = Assessment Question BP = Best Practice KC = Key Consideration
  • 11. At a glance ECB Recommendations mapped to Trusteer’s solutions (IV) Recommendation 10: Transaction monitoring Overview (Trx Monitoring purpose) Trusteer Pinpoint KC 10.1 (Fraud prevention systems should detect malware in the session) Trusteer Pinpoint 11© 2015 IBM Corporation KC 10.4 (Trx Monitoring shouldn't delay transactions) All Trusteer's solutions work in real time, providing actionable results while the user is interacting with the site. KC 10.5 (Blocks should be maintained for as short time as possible) All Trusteer's solutions operate in real-time and are highly deterministic, providing per- transaction results avoiding blanket "blocking" of users AQ = Assessment Question BP = Best Practice KC = Key Consideration
  • 12. At a glance ECB Recommendations mapped to Trusteer’s solutions (V) Recommendation 12: Customer education and communication Overview (reassure customers of the authenticity of the messages received) Trusteer Rapport and Mobile 12© 2015 IBM Corporation AQ = Assessment Question BP = Best Practice KC = Key Consideration
  • 13. Trusteer’s Solution Overview © 2015 IBM Corporation
  • 14. Online Banking Malware attacks against the website Account takeover Detects malware targeting OLB website Trusteer Pinpoint Malware Detection Trusteer Pinpoint Criminal Detection • Detect fraud risk • Identify cross channel attacks Holistic detection of fraud based on malware history and persistent device ID Trusteer’s multi-layered fraud protections R4, R7, R10 R4, R10 R4, R7, R9, R10 14© 2015 IBM Corporation Phishing and malware fraud Phishing and malware fraud Phishing and malware Trusteer Rapport • Detects and removes malware • Prevents future malware infections • Alert phishing attacks Trusteer Mobile SDK / Browser R2: Risk assessment, R4: Risk control and mitigation, R7: Strong customer authentication, R9: Log-in attempts, session time out, validity of authentication, R10: Transaction monitoring, R12: Customer education and communication R4, R7, R10, R12
  • 15. Trusteer Pinpoint Criminal Detection Product Highlights Trusteer Rapport Trusteer Pinpoint Malware Detection Trusteer Pinpoint Criminal Detection Trusteer Mobile 15© 2015 IBM Corporation Correlates Device and Account Risk Factors to conclusively detect account takeover attempts Automated Criminal Device Detection feeds a Global Criminal Device Database Automated Fraud Rules Creation based on Real-time threat and attack intelligence Transaction Anomaly Detection
  • 16. Trusteer Pinpoint Malware Detection Product Highlights Trusteer Pinpoint Criminal Detection Trusteer Rapport Trusteer Pinpoint Malware Detection Trusteer Mobile 16© 2015 IBM Corporation Clientless detection of live Man-in-the-Browser (MitB) Malware Real-time alerts of high risk devices Updates automatically deployed without customer interaction and no business interruption Integrate data into existing systems and workflows
  • 17. Trusteer Mobile Solutions Product Highlights Trusteer Pinpoint Criminal Detection Trusteer Pinpoint Malware Detection Trusteer Rapport Trusteer Mobile 17© 2015 IBM Corporation Captures Persistent Device ID and Device, User and Session Risk Factors Comprehensive Fraud Protection Across Bank Mobile Apps and Mobile Web Access Correlates Mobile-specific risk, Online Risk (malware and phishing) and Global Criminal Devices DB to prevent Cross-Channel Attacks
  • 18. Trusteer Rapport Product Highlights Pinpoint Criminal Detection Pinpoint Malware Detection Trusteer Mobile Trusteer Rapport 18© 2015 IBM Corporation Compact Software Agent for PC and Mac – minimal impact on the end-user’s machine Transparently protects user credentials & website interaction Removes existing infections upon installation and alerts user & security team of potential phishing sites & credentials loss
  • 19. Trusteer Solutions And how they match the requirements ECB/EBA Guidance How can IBM Security Trusteer help? Risk Assessment Risk Control and mitigation Incident monitoring and reporting Strong customer authentication 19© 2015 IBM Corporation Enrolment for, and provision of, authentication tools and/or software delivered to the customer Log-in attempts, session time out, validity of authentication Transaction monitoring Customer education and communication
  • 20. Summary © 2015 IBM Corporation
  • 21. Summary Why IBM Security Trusteer • 475+ leading global organizations put their TRUST in us • Threat Intelligence gathered from more than 270 million endpoints Helps prevent the ““““Root Cause”””” of Fraud Helps prevent the ““““Root Cause”””” of Fraud 7/10 Top U.S. Banks 9/10 Top U.K. Banks 4/5 Top Canadian Banks 21© 2015 IBM Corporation Reduce Operational Impact Reduce Operational Impact Utilize Global Malware Intelligence Service Utilize Global Malware Intelligence Service Improve Your Customer Experience Improve Your Customer Experience Banks Banks Banks Major European Banks 2/4 Top Japanese Banks Major Latin American Banks
  • 22. Q&A © 2015 IBM Corporation
  • 23. Statement of Good Security Practices: IT system security involves protecting systems and information through prevention, detection and response to improper access from within and outside your enterprise. Improper access can result in information being altered, destroyed, misappropriated or misused or can result in damage to or misuse of your systems, including for use in attacks on others. No IT system or product should be considered completely secure and no single product, service or security measure can be completely effective in preventing improper use or access. IBM systems, products and services are designed to be part of a lawful, comprehensive security approach, which will necessarily involve additional operational procedures, and may require other systems, products or services to be most effective. IBM DOES NOT WARRANT THAT ANY SYSTEMS, PRODUCTS OR SERVICES ARE IMMUNE FROM, OR WILL MAKE YOUR ENTERPRISE IMMUNE FROM, THE MALICIOUS OR ILLEGAL CONDUCT OF ANY PARTY. THANK YOUwww.ibm.com/security © Copyright IBM Corporation 2015. All rights reserved. The information contained in these materials is provided for informational purposes only, and is provided AS IS without warranty of any kind, express or implied. IBM shall not be responsible for any damages arising out of the use of, or otherwise related to, these materials. Nothing contained in these materials is intended to, nor shall have the effect of, creating any warranties or representations from IBM or its suppliers or licensors, or altering the terms and conditions of the applicable license agreement governing the use of IBM software. References in these materials to IBM products, programs, or services do not imply that they will be available in all countries in which IBM operates. Product release dates and / or capabilities referenced in these materials may change at any time at IBM’s sole discretion based on market opportunities or other factors, and are not intended to be a commitment to future product or feature availability in any way. IBM, the IBM logo, and other IBM products and services are trademarks of the International Business Machines Corporation, in the United States, other countries or both. Other company, product, or service names may be trademarks or service marks of others.