News and Blog

Training banking operators: a cybersecurity strategy

miceli_hacker
Anti-Money Laundering and ComplianceBank of Italy - UIF - MEFCybersecurityNews

Training banking operators: a cybersecurity strategy

Edited by Giuseppe Miceli

The effects of the so-called digital divide also affect the banking world. The lack of computer literacy is a phenomenon that also affects employees, especially older ones, in the sector. This is a situation that is increasingly evident and cannot continue to be overlooked, especially when considering the rapid transformation—in terms of IT and digital—affecting banking services, even the most traditional ones. Almost all services require account registration, digital access, often conditioned by digital identity verification.

On the other hand, during this pandemic, the majority of account holders and users of banking services have had to opt for remote access to their bank, precisely because of the restrictions and limitations on mobility imposed by the anti-Covid-19 regulations. Everything suggests that even in the hoped-for post-pandemic phase, users will continue to favor the convenience of managing their current accounts via home banking, which also allows them to carry out transactions in real time and avoid unnecessary—and contagious—queues.

Thus, the IT knowledge gap continues to widen: on one hand, users who can benefit from financial education initiatives and who, out of necessity, increase their IT skills; on the other, old-school bankers who don't seem to be comfortable using new work tools.

Increase in online fraud in the banking sector

Alongside the natural need to rebalance the relationship between banks and users, there is the pathological emergence of online fraud targeting the banking sector, as if it were the most sought-after target.

This phenomenon also seems to have worsened in recent months, almost as if it were a side effect of Covid-19. Every day, we are bombarded with malicious emails, text messages, and communications that appear to come from our bank, only to realize—before or after the damage has occurred—that they are fake. This is called "spoofing," or false communications that aim to unlawfully obtain personal codes and data, such as passwords, credit card numbers, access codes, and anything else that could allow anonymous attackers to access an unsuspecting user's account and steal their funds.

Another type of fraud that occurs online is called “Smishing-Vishing,” a latest-generation variant of bank phishing that involves the illicit theft of sums ranging from a minimum of 300 to over 60.000 euros.

The "vishing" technique is particularly insidious and devious. The customer/victim is contacted by telephone by a fake bank clerk who, using deception and intriguing language, persuades them to provide the codes for their financial account. In many cases, this request is justified by convincing the customer that the code is necessary to allow the fake clerk to block illicit withdrawal attempts allegedly carried out by third parties. The result, in too many cases, is that the user trusts—mistakenly—and hands over their codes and credentials, falling victim to the scam.

Safety comes through training

Preventing and combating these online frauds is not solely the responsibility of the competent authorities. Bank operators play an equally crucial role, relying on training, as do users, who rely on information. The Italian Banking Association itself recently emphasized the need for adequate training for banking staff, through its President, Antonio Patuelli, and General Manager, Giovanni Sabatini.

ABI leaders are convinced that the significant investments banks are making in cybersecurity must be further enhanced by equally significant investments aimed at training personnel in a sector that is strategic for the national and international economy.

Training, therefore, as a compliance objective but also as a tool for informing customers/users, a combination that can lead to successful results in preventing and combating online fraud.

*Teacher at the Italian School of Anti-Money Laundering & Compliance – AML Compliance Specialist and OSINT Operator – formerly of the Guardia di Finanza

Select the fields to be shown. Others want to be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to Cart
  • Description
  • Content
  • Weight
  • Size
  • Product information
Click outside to hide the comparison bar
Compare