Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Banks To Force Customers To Foot the Bill For Fraud On Their Accounts
News & Analysis

Banks To Force Customers To Foot the Bill For Fraud On Their Accounts

ISB Editorial StaffBy ISB Editorial StaffMay 27, 2016Updated:May 27, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Banks could block customers from claiming money back if they are a victim of fraud and it is found they had substandard online security. Following this news, IT security experts from Lieberman Software, ESET, Imperva and AlienVault discuss whether this is a good idea.

Jonathan Sander, VP of Product Strategy at Lieberman Software:

JonathanBanks, just like other organisations trying to deliver online services, find themselves between a security rock and a competitive hard place. On one hand, there is a duty on the part of the bank to ensure security. That means forcing stronger passwords on users, having them use codes and computer identification to log in, and asking them to renew their credentials and connections regularly.

While all of this is best practice in security, it’s also a pain in the neck in the eyes of the uneducated online consumer.

On the other hand, banks are under competitive pressures like any other. If one bank makes things too hard on their users from a security perspective, they may decide to simply switch banks. This is doubly so for the younger, mobile, first generation of users that everyone is competing to capture.

When banks say they may ask users to take on some of the risk for using bad security practices, it seems they are saying that they want to split the tab for allowing people to be lazy. The banks won’t force good security on people – which they could – but they will instead say that choosing to opt out of good security is done so at your own, very grave, risk.

Mark James, Security Specialist at ESET:

mark-jamesI think it’s very important that the end user understands they are responsible for their own security. People still think it’s difficult or complicated to protect against fraud or cyber-attacks but the basics are very affordable and easy to implement. Making sure your operating system and applications are patched and on the latest versions along with a good regular updating internet security product would be considered as minimum requirements.

You should also be very mindful of the device you’re accessing any online banking with and ensure you always log out and never save passwords. Whenever there are big breaches or data found on the internet one of the biggest things that still amazes is the fact that users still do not use complex passwords. You really need to have at the very least a unique password for any financial login and ensure it contains enough unique characters to not be easily guessed, this could be a passphrase or even a few words added together with numbers, uppercase and special characters thrown in for good measures. You really are the first defence and can easily make things harder for the bad guys.

Amichai Shulman, CTO of Imperva:

amichai_shulmanWhen online banking started a few years ago, this was the standard practice. Banks would have their customers sign waivers that released the banks from any liability in the case of account takeovers or some online fraud. Previously credit card customers also had a hard time getting their money back if their credit card number got compromised. Business drivers and regulations forced banks and credit card issuers to remove the burden from end users and take responsibility for online security. If this hadn’t happened, we would not have witnessed the exponential growth of online commerce and online banking we are seeing today.

Javvad Malik, Security Advocate at AlienVault:

Javvad MalikOverall this is a bad idea, purely because the maturity in the market doesn’t exist. It will be difficult, if not impossible to agree what an acceptable baseline of security is. Will banks mandate which operating systems and browser versions are relevant? For example, will they block any visitors running windows XP? If that is the case, then the tables can very easily be turned if, in court, a customer asks a bank to demonstrate that all their systems involved in the online banking ecosystem meet the same level of base security controls. With many banks running legacy systems, it will be a difficult case to make – not to mention can potentially expose confidential information about the bank’s setup.

In the first instance, the banks would be better placed investing in better fraud detection and prevention controls on their own end. The systems should ideally be designed in a manner that even if a customer machine is compromised, it would be difficult for a fraudster to steal credentials.

Ongoing customer education is not to be discounted. Many people still fall victim to phishing or even telephone scams where fraudsters pose as the bank. The customers shouldn’t be victimised twice, once by the fraudster and second by the bank. Rather a collaborative approach is needed with more vulnerable customers perhaps given lower limits or limited functionality on their online banking in order to minimise the impact of fraud.

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}