InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Your Bank’s Digital Side Door

Presented by

Ed Adams, CEO of Security Innovation

About this talk

A widely-used but little known technology has created a vulnerable “Side Door” to thousands of financial institutions in North America. This discovery started with a simple question: why does my bank require multi-factor authentication (MFA), but Quicken does not? This led to an exploration of the 20-year old Open Financial Exchange (OFX) protocol and the 3000+ North American banks that support it.  The conclusion:  80% of banks supporting OFX have no MFA support, putting consumers at risk by exposing login credentials.  This presentation provides a summary of our research. It also describes how organizations can assess and mitigate enterprise risk posed by OFX.  Topics include: · Open Financial Exchange (OFX) protocol — how it works and where it’s vulnerable  · Research findings —  OFX security vulnerabilities that create enterprise and consumer risk · Compliance implications - using a known vulnerable component creates headaches · Assessment techniques — commercial scanning tools don’t work with OFX. Learn how to assess this risk quickly ·Mitigation techniques — compensating controls that reduce exposure while using the OFX protocol
Bureau Veritas Cybersecurity

Bureau Veritas Cybersecurity

17510 subscribers90 talks
Bureau Veritas Cybersecurity is your expert partner in cybersecurity.
Bureau Veritas Cybersecurity is your expert partner in cybersecurity. We help organizations identify risks, strengthen defenses and comply with cybersecurity standards and regulations. Our services cover people, processes and technology, ranging from awareness training and social engineering to security advice, compliance and penetration testing. We operate across IT, OT and IoT environments, supporting both digital systems and connected products. With over 300 cybersecurity professionals worldwide, we combine deep technical expertise with a global presence. Bureau Veritas Cybersecurity is part of the Bureau Veritas Group, a global leader in testing, inspection and certification.
Related topics