A real and significant danger
With news of the $101 m heist at Bangladesh Bank making headlines around the world, both the global Financial Services sector and regulators will be watching events closely as they unfold. That the perpetrators were able to successfully bypass a complex multi-stage biometric verification process is itself cause for concern and could call into question the effectiveness of such authentication methods as criminals are adopting increasingly sophisticated means to circumvent them. Once the mainstay of solitary individuals and disaffected youth, "industrial hacking" is now a real and significant danger with backing from international organised crime and the stakes, as we have seen, are frighteningly high.
In the absence of solid evidence, one can still form a broad picture of the means by which the incident at Bangladesh Bank had occurred. Firstly, the encrypted and highly secure mechanism of SWIFT transfers between their dedicated terminals means that the likelihood of communications being intercepted or tampered en route can be ruled out. Secondly, that the recipient institution cannot initiate transactions from their end would exclude the possibility of any technical breach on that side. Given that the systems within Bangladesh Bank are themselves protected against external intrusion attempts by enterprise-grade firewall software, this leaves us with the unsettling conclusion that the crime is mostly likely to have occurred from within, prompting a line of investigation that is actively being pursued as we speak. While it would be unwise to draw further conclusions while the investigation is underway, the incident drives home the realities and challenges faced by the financial services industry as a whole.
Consulting firm Accenture, in their Global Risk Management Study of Investment Banking in 2015, revealed that 65 percent of Financial Services executives believed that cybercrime and IT risk would have an increased impact on their business in the next two years. Worryingly, it was also revealed that less than 10 percent of those institutions proactively ran inward-directed simulations of cyber-attacks or intentional failures to test the resilience of their systems against such events. Such a low level of cyber-threat awareness and preparedness combined with the astronomical sums of money involved makes members of the financial services industry prime targets for organised electronic crime on an unprecedented scale. It also demonstrates that cybercrime is a threat perceived by the entire global banking community and not Bangladesh alone.
A separate study by Accenture in conjunction with Ponemon Group, also in 2015, revealed that organisations at the forefront in the fight against cybercrime shared certain common traits. One of these was the appointment of a Chief Information Security Officer or CISO who would report directly to the CEO and board of directors to ensure that breaches of systems security were addressed at the top levels of organisations as a matter of top priority. It also noted that such firms were actively engaged in the on-going development of an overall IT security strategy along with clear definitions of security roles and responsibilities which were then communicated to employees at all levels. Four "Big Picture Principles" were identified: having a proactive stance, taking a broad view of risk management, a willingness to collaborate and, paying attention to the "human factor".
It is this last point, the "human factor" that is the most difficult for organisations to identify and control. The touch-points between humans and computers will always continue to be the weakest link in ensuring the integrity and security of any computer system and, unsurprisingly, an overwhelming majority of hacking incidents are attributed to human intervention in some form. This could be down to something as simple as accepting a prompt to install malicious software, browsing a compromised website or inserting an infected USB flash drive into a target machine. Such incidents often indicate a breakdown in internal control structures such as the appropriate segregation of duties or vetting of staff with access to critical systems. In the case of Bangladesh Bank, this is likely to be one of the key areas of focus for investigators and something that will be followed by stakeholders and the industry at large.
While it is easy to point out lapses that may or may not have occurred at Bangladesh Bank, it is important to note that the burden of responsibility for cybercrime is a shared one. Each and every party involved in the generation, handling and processing of financial data has a collective duty of care to ensure that only legitimate and verifiable transactions pass through the financial system. That is the main purpose of the comprehensive anti money-laundering awareness programmes that institutions require their staff to undertake on a regular basis. Importantly, this type of training is not restricted to front-office operatives alone, but applicable to all staff who are in contract with the physical or electronic trail of money throughout the lifetime of the transaction cycle. This implies that rather than a single point of failure, there may have been multiple issues relating to people and process in the organisations concerned that resulted in a significant number of fraudulent transactions passing through the system unchallenged.
It is because of this shared burden of care and responsibility that all institutions involved should make a joint effort to get to the bottom of the matter. While there may not have been a technical breach of systems within the Federal Reserve, there were perhaps issues around due diligence that need to be looked into to prevent further incidents such as this. That multiple sequential payments to different accounts from the reserve account of a sovereign nation would be made without being investigated is extremely worrying. Also, the fact that the $101m in question reputedly represents a subset of a much larger amount requested to be withdrawn at the same time - requests that were subsequently declined - demands that the Fed look into their evaluation criteria for the assessment and identification of fraudulent activity on their client accounts.
Being able to identify and isolate suspicious transactions, no matter how legitimate they may seem, is at the heart of the trust that both people and governments worldwide place in financial institutions whom they entrust to be custodians of their hard-earned money. Whether the end customer is an individual or a nation, banks have a duty to safeguard customer and transactional information as well as monitor activity on their customer accounts to identify and prevent unauthorised or criminal activity. For example, the next time you are abroad and your credit card gets declined for seemingly no reason, it is probably because banks are doing their job properly.
But customers are not the only ones to benefit from such preventive measures. The significant cost to financial institutions of implementing robust and effective systems security is overshadowed by the damage to reputation and monetary loss they could face in the event of a breakdown. The widely publicised ATM hacking operation involving three of Bangladesh's prominent retail banks that was foiled just weeks before the Bangladesh Bank incident is a point in case. Whatever the outcome of current investigations, these incidents call for a heightened awareness of the need to review and improve existing controls in order to retain the confidence of a disillusioned public in the financial system. In doing so, it should be remembered that effective cyber security begins at the top and it is only by driving down radical change in mind-set from the highest levels of the organisation that we can prevent a repeat occurrence of such events.
The writer is CEO and Principal Consultant at Indigo ICT, a Dhaka-based firm specialising in business technology.