Protecting Your Systems from Intruders and "In-Truders"

Steve Cocheo · ABA banking journal · 2000

old saw says better the devil you know, than the one you don't but when it comes to a community bank's computer systems, it's the person you know who could represent the greater threat. Over the course of this year federal regulators have been warning banks about guarding against computer system intrusions, such as in the Comptroller's Bulletin 2000-14. In light of recent headlines, such as the news this fall of the Microsoft break-in, where hackers stole electronic blueprints for yet-to-be-released software products, bankers would naturally be most concerned about threats from without. But must take care not to ignore threats from within. The big challenge, overall, for the community bank is access, according to Robert W. Leuchs, information systems case manager in the Boston Regional Office of FDIC's Division of Supervision. As more and more community banks adopt fully transactional websites, said Leuchs, they open up their systems to the entire world. However, Leuchs told bankers at an ABA gathering earlier this year, that hackers are the number-two threat to community bank systems. first level of threat that community banks face comes from insiders: employees and the employees of vendors and contractors. Bank employment used to be a longterm matter, Leuchs noted, but with the full-employment economy encouraging mobility, particularly among skilled computer workers, that is coming to be a thing of the past, even among community banks. When employees stayed for decades, there was trust and a history behind that, he said, and that used to be enough. However, Leuchs continued, I'm not sure in the future that that level of trust is going to be enough to protect you. Employees of the bank and outside providers will come and go, and will carry with them knowledge both of a bank's systems and the chinks in the bank's defenses. It will be critical to have controls in place to guard against this becoming a problem. Leuchs suggested some quick-and-dirty steps banks can take to begin to address this threat. (1) A key area to examine is passwords. Amazingly, Leuchs said, some banks fail to change the default passwords that are built into commonly used software systems as come off the shelf. Anyone who has been around the data processing business for a while knows these and ought to be changed immediately so unauthorized staffers can't go exploring. Windows NT, out of the box, has an extremely unsophisticated security system, Leuchs said. Similarly, he said, generic logins commonly used to avoid forgetting passwords should be avoided. It's the system's version of not using your name or your birthday as the PIN for your ATM card. There are other helpful steps to follow. For example, some system users, to avoid forgetting their password, simply switch back and forth between two alternatives whenever are required to make a password change. Sooner or later both choices will become known. Leuchs suggests requiring consecutive changes before permitting a repeat. Actually, ten isn't a good number, but at least it's a start, Leuchs noted. Users should be required to come up with passwords of at least eight alpha and numeric characters, in order to make it harder to luck into the right combinations through simple guesswork or trial-and-error. And no more than three attempts to log into a system should be permitted before the user is forced to ask for a manual resetting. This strikes a balance between innocent typos and repeated guesses by the unauthorized. A bank would do well, said Leuchs, to reexamine how widely critical system information and passwords are distributed within the organization. …

Read the paper · More papers on PaperTik