Financial institutions are required to regularly assess the authentication controls, security layers, and monitoring of Internet Banking to prepare for current threats and comply with FFIEC guidance.
Brian Petzold
Recent Posts
MFA Enrollment Mistakes
by Brian Petzold | Apr 8, 2022
Most financial institutions understand the importance of Multifactor Authentication (MFA) in keeping unauthorized parties from gaining access to user accounts. The volume of phishing attacks...
Is Your Risk Assessment Authentication & Access Ready?
by Brian Petzold | Jan 21, 2022
In August, the FFIEC released new guidance titled “Authentication and Access to Financial Institution Services and Systems”. Because the guidance replaces the previous “Authentication in an Internet...
Backups vs. Retention
by Brian Petzold | Nov 19, 2021
We often run into situations where different staff in an institution have different understandings of the goals and operations of their backup system. The IT department tends to think of backups as...
Tricky Phish Testing
by Brian Petzold | Oct 29, 2021
Phishing remains one of the top threats to organizations today. Every user regularly receives emails designed to trick them into clicking on a link, opening an attachment, or providing credentials...
Training Your Board
by Brian Petzold | Sep 24, 2021
Being on the board of a financial institution is not easy. Board members are expected to not only be knowledgeable about the operational and financial workings of the institution but also to...
Choosing a Cybersecurity Framework
by Brian Petzold | Aug 13, 2021
It is a good practice to identify a cybersecurity framework as part of an institution’s Information Security Program. A framework helps to identify gaps that might exist and leave the institution...
Breaking the SMS Habit
by Brian Petzold | Jun 25, 2021
Multifactor Authentication (MFA) is one of the most important controls to block account takeover fraud. There are many different forms of MFA available, and many banks support more than one method...
A Message to Vendors
by Brian Petzold | Jun 11, 2021
Today I am writing to those who wish to sell their products or services to a financial institution. If you work at a financial institution, feel free to pass this on to any prospective vendors to...
The Policy Labyrinth
by Brian Petzold | Apr 30, 2021
You started with an Information Security Policy that covered the basics. Then one day an auditor walked in and asked to see your Data Destruction Policy, so you wrote one. In the next exam,...