What's in a Name? .BANK Domain Rolls out for Greater Online Security, New Opportunities
Peggy Bresnick · ABA banking journal · 2015
CYBER attacks and data breaches continue to wreak financial havoc for organizations around the globe. The grim news is that online attacks are only going to become more numerous and more sophisticated in the future. Says Ponemon Institute in a recent research report, 2014: A Year of Mega Breaches, 2014 saw a series of mega security breaches and attacks that resulted in the exposure and theft of literally millions of customer and employee credit and debit card numbers and personal data. 2015 is predicted to be as bad or worse as more sensitive and confidential information and transactions are moved to the digital space and become vulnerable to attack, says the report. While organizations of all types and sizes are taking measures to stop data breaches, banks are working hard to shore up cyber defenses to minimize damage. Online fraud can injure a bank's brand and reputation, erode customer trust and threaten customer loyalty. The financial damage is potentially enormous; the costs of successfully detecting fraud and thwarting a wide and expanding array of cyber threats are rising. Financial institutions today know they must address security concerns proactively, rather than to simply address and react to issues after they occur. Unfortunately, with increasing customer use of the mobile and online channels, banks are finding it challenging to stay one step ahead of cyber criminals, who are becoming more and more sophisticated in their attacks. Criminals can create email communications that appear to have been sent by the recipients' financial institution, but they contain corrupt Web links that are designed to extract personal and financial information from the unwitting customer. Cyber criminals using IP addresses that are disguised as trustworthy sources trick victims into clicking links that will install malware on their machines and extract personal information. .BANK offers security, inspires trust Securing customer information is a priority for all organizations today, yet banks are finding it challenging to protect customers from online crooks who pose as legitimate financial institutions--and ultimately steal customers' account information. Within the next few months, however, banks will have new way to improve online security, proactively mitigate phishing and spoofing attacks while inspiring greater customer confidence and presenting new marketing and branding opportunities. ABA members and other verified members of the banking community can take advantage of .BANK, a new banking-specific top-level Internet domain with a variety of enhanced security controls. The new domain is offered by fTLD Registry Services LLC, Washington, D.C., an entity formed by the ABA, Financial Services Roundtable and other banks, insurance companies and financial services trade associations to apply for the .BANK and .INSURANCE domains and to operate them securely. fTLD now includes a Board of Directors that currently includes financial institutions and vendors operating in the banking space. Not merely a new domain, .BANK will offer the banking community and its customers a trusted, verified and easily-identifiable space on the Internet to conduct banking business. Banks that utilize the new domain will help prevent users from being redirected to fake bank websites. .BANK also will make it difficult for cyber criminals to be successful with spoofed emails, since banking customers will know to look for and trust communications from email addresses that include the specific domain. The .BANK domain also provides a high level of encryption designed to protect communications that banks and their customers sent through email, making it much more difficult to intercept, eavesdrop or manipulate those conversations. In the current environment, there's concern in the ability to trust that an email actually comes from a financial institution you're doing business with, says Doug Johnson, ABA's SVP, payments and cybersecurity policy. …