https://www.engineeringnews.co.za

Bt Helps Global Financial Industry Keep Data Secure With New Ethical Hacking Service

16th September 2015

  

Font size: - +

This article has been supplied as a media statement and is not written by Creamer Media. It may be available only for a limited time on this website.

Crest  (0.10 MB)

Company Announcement - BT today announced the global launch of “BT Assure Ethical Hacking for Finance”, a new security service designed to test the exposure of financial services organisations to cyber-attacks. The wealth of valuable and sensitive personal data held by financial organisations, such as retail and investor banks and insurance companies, makes them among the most attractive targets for malicious hackers and cyber-criminals. This risk has intensified in recent years as more and more retail financial services move online and electronic trading is one the rise.

Assure Ethical Hacking for Finance uses mature methodologies that mimic those of "black hats" or malicious attackers to provide a range of tests targeted at the various entry points to a bank’s IT systems as well as perceived “weak points” of an organisation. These include phishing scams, mobile devices and hardware from laptops to printers, internal and external networks, databases and complex enterprise resource planning systems. BT not only tests and verifies systems that can access the network but also checks for risks of human failure, for example by using social engineering to test how employees apply the policies in place. The new service draws on the ethical hacking expertise gained by working closely with large financial institutions in the U.S. for nearly two decades.

Within the confines of strict rules of engagement, BT's ethical hackers have been able to perform database dumps of tens of thousands of social security and credit card numbers; intercept and modify mobile cheque deposit data; reverse engineer proprietary encryption streams; generate enormous, valid gift cards with payment details from other test accounts; create admin accounts by having an employee simply open an email; escape remote access sessions and get shell access to systems, including subsequent establishment of tunnels into the company; transfer funds between unauthorized test accounts or harvest complete account data for all users by attacking machine-to-machine communications. The ultimate objective is to identify vulnerabilities that would impact an organisation’s primary business processes and thus its brand and reputation.

The new Assure ‘Ethical Hacking for Finance’ will enable BT to use CREST www.crest-approved.org certified Simulated Targeted Attack and Response services to help financial services firms to develop the most robust security solutions, ensuring sensitive customer data remains secure. BT was in 2014 one of the first companies in the world accredited by CREST to provide STAR services. Working alongside the Bank of England (BoE), UK Government and industry, CREST developed the STAR framework to deliver controlled bespoke, intelligence-led cyber security testing. STAR incorporates advanced penetration testing and threat intelligence services to more accurately replicate cyber security threats to critical assets.

Mark Hughes, president of BT Security, said: “The prospect of accessing confidential financial information is a powerful lure for hackers so few companies attract as much online criminal attention as banks. Apart from direct financial loss, a serious hack could lead to irreparable reputational damage. While much of the concern focuses on retail-banking activities, the threat is just as important for investment banks or for wholesale, where banks provide services like currency conversion and large trade transactions for major corporate customers. We encourage all financial institutions to put themselves through a rigorous series of cyber-security simulations, whereby our ethical hacking consultants push the cyber defences of financial institutions to the limit.”

BT has a strong, award-winning, global team of security specialists, including ethical hacking consultants, who provide a standardised method to test systems by imitating hacker attacks, reporting identified vulnerabilities and providing clear remediation steps that customers can use to quickly patch applications and affected systems.

Edited by Creamer Media Reporter

Comments

Showroom

Goodwin Submersible Pumps Africa (Pty) Ltd
Goodwin Submersible Pumps Africa (Pty) Ltd

Goodwin Submersible Pumps Africa is sole distributors for Goodwin electrically driven, submersible, abrasion resistance slurry pumps.

VISIT SHOWROOM 
Condra Cranes
Condra Cranes

ISO-certified Condra manufactures overhead cranes, portal cranes, cantilever cranes and crane components: hoists, drives, end-carriages, brakes and...

VISIT SHOWROOM 

Latest Multimedia

sponsored by

Option 1 (equivalent of R125 a month):

Receive a weekly copy of Creamer Media's Engineering News & Mining Weekly magazine
(print copy for those in South Africa and e-magazine for those outside of South Africa)
Receive daily email newsletters
Access to full search results
Access archive of magazine back copies
Access to Projects in Progress
Access to ONE Research Report of your choice in PDF format

Option 2 (equivalent of R375 a month):

All benefits from Option 1
PLUS
Access to Creamer Media's Research Channel Africa for ALL Research Reports, in PDF format, on various industrial and mining sectors including Electricity; Water; Energy Transition; Hydrogen; Roads, Rail and Ports; Coal; Gold; Platinum; Battery Metals; etc.

Already a subscriber?

Forgotten your password?

MAGAZINE & ONLINE

SUBSCRIBE

RESEARCH CHANNEL AFRICA

SUBSCRIBE

CORPORATE PACKAGES

CLICK FOR A QUOTATION







sq:1.469 1.52s - 158pq - 2rq
Subscribe Now