Guidance on Management of Risks associated with Fraudulent E-mails or Websites
Beruexo SerurReL Ne prurelNns OFFICE OF THE DEPUry GOVERNOR SUPERVISION AND EXAMINATION SECTOR MEMORANDUM NO. M-2015. 025 To : ALt BSP-SUPERV|SED FtNANC|AL tNST|TUT|ONS Subject : GUIDANCE ON MANAGEMENT OF RISKS ASSOCIATED WITH FRAUDUTENT E.MAIIS OR WEBSITES Phishing attacks and fraud perpetrated via other vectors continue to be a primary concern affecting the financial services industry. The steady increase in the number of incidents as reported by banks mostly involves unauthorized intra or interbank fund transfer facilitated via phishing e-mails received by clients. since the clients are the direct target of said attacks, failure to address such concern may result to diminished trust and confidence of the public in the financial system, particularly the use of online banking products and services. Moreover, while incidents of this nature remain a small percentage of the total cybercrime losses of the industry, the cyber threat landscape continues to evolve with more sophisticated versions of these attacks, such as pharming and spear phishing, not far in the horizon. BSp-Supervised Financial Institutions (BsFls) are therefore enjoined to adopt appropriate risk management practices to adequately prevent, detect and proactively manage fraudulent e-mails or websites. A. RETEVANT PROVISIONS AND GUIDETINES BSFI's are reminded that, as specified in Section 4.t.tL Website information and maintenance under Appendix 75f and e-59f of the Manual of Regulations for Banks (MoRB) and Manual of Regulations for Non-Bank Financial Institutions (M9RNBFI), respectively, "The BSFI should manoge the risk associated with froudulent emoils or websites which are designed to trick its customers into revealing private detoils such os account numbers or e-services passwords.,, To manage the risks associated with fraudulent e-mails or websites, BSFIs should, ata minimum, observe the folloryilH controls as required by the regulations: o Dynamic consumer Since phishing and its more sophisticated versions are awareness program mostly external attacks and normally beyond the control of the BSFI's security measures, the key defense lies in an effective, dynamic and well-designed consumer awareness program, which should be regularly reviewed/evaluated by senior managementa. Further, BSFIs should educate their clients on: o "the risks of usina online a Section 4.3.3 Consumer Awareness of Appendix 75f and e-59f of the MORB and MORNBFI.
subscribe to such services. Ongoing educotion must be avoiloble to roise the security oworeness of customers to protect their systems and online transoctions (Annex A of Appendix 75f and Q-59f of the MORB and MORNBFI)"; "woys to ensure thot they ore communicoting with the official website and that they will not be required to occess the BSF(s tronsactional e-services portal through hyperlinks embedded in e-mails unless the website is validated by legitimote digital certificate (section 4.t.LL of Appendix 75f and Q-59f of the MORB and MORNBFI)."; and, "security meosures thot must be put in place to uphold their interests in the online environment (Annex A of Appendix 75f and Q-59f of the MORB and MORNBFI).' Expectations on the electronic services consumer awareness program are further summarized in Annex C of Appendix 75f and Q-59f of MORB and MORNBFI. o Confirmations and BSFIs are expected to implement additional authentication identity checks to and authorization controls for sensitive transactions or significant transactions activities, such as (al "enrollment in a new on-line service, or activities large fund transfers, occount maintenonce chonges, or suspicious account activity" (Subsection 4.1.6 Application security of Appendix 75f and Q-59f) and (b) "when customer requests o chonge in his account informotion or other contoct detoils" (Subsection 4.2.t. Administration of E-Services Accounts of Appendix 75f and Q-59f). Strengthened As successful cyber-attacks via fraudulent e-mails or infrastructure and websites usually manifest in suspicious online transactions security monitoring; or unusual activities, BSFIs should put in place strong and, monitoring mechanisms and processes to detect and respond to potential breaches in a timely manner. Subsection 4.L.7 lnfrastructure and security monitoring of Appendix 75f and Q-59f has highlighted features of an effective infrastructure and system monitoring process: o Sound monitoring system oA sound monitoring - system should include oudit features that can ossist in the detection of fraud, money laundering, compromised passwords or other unauthorized octivities"; o Response -"The BSFI's monitoring staff should be promptly alerted by its monitoring mechanism if suspicious online transfers and unusual activities are initioted. ln these csses, the BSFI should, os soon as practicoble, check with the account holders of these
transactions or activities"; ond, o Consumer notification - "Considerotion should also be given to notifying personal customers immediately through an alternative automoted chonnel (such as messoges sent to mobile phones or e-moil accounts of customers) of online tronsfers mode to unregistered third porties, online transfers exceeding certoin amount limits, or detected unusual activities related to their accounts." a For more proactive approach, BSFIs should have mechanisms in place to monitor the external environment (e.g. surveillance of the existence of similar- lookingfraudulent websites) and take appropriate action when necessary. BSFIs have the option to avail the services of an external service provider if they do not have the expertise or capability to adequately manage external risks. o Appropriate As part of consumer protection, BSFIs should also authentication implement "a mechanism to authenticote officialwebsite to techniques. protect customers from spoofed or foked websites. (Annex A of Appendix 75f and Q-59f: Online Internet Financial Services)". Dependent on the extent of services made available to client and its risk assessment, the BSFI should determine what authentication techniques to adopt to provide protection against cyber-attacks. Given the evolving nature of the attacks and extensive potential damage of a successful widespread attack against the financial services sector, BSFIs are enjoined to proactively assess and institute resilience in their existing networks, security controls and customer awareness initiatives to preserve trust and confidence on the financial environment. B. REPORTINGREQUIREMENT Incidents on fraudulent e-mails or websites perpetrated via phishing, pharming and other evolving forms of attacks involving the BSFts or their clients should be reported to the BsP as prescribed under section xL77.g and 4L77Q.8/4t965.8/4L93P.8/4196N.8 of the MORB and the MORNBFI. For information and guidance. [tr-r-q--a-( \FsroR A. qsPENlL Deputy Governo LlJune 2Ot5
More in BSP Memoranda
- Consolidated Report of Deposit Liabilities by Size of Account(BSP Memoranda)
- Unsecured Subordinated Debt (USD)(BSP Memoranda)
- MB Resolution No. 1012.A dated 28 June 2012- Placement of the Rural Bank of Naguilian (La Union), Inc. under Receivership(BSP Memoranda No. M-2012-029)
- Phishing and Other Similar Social Engineering Attacks(BSP Memoranda No. M-2020-090)
- Public Advisory on ATM Transaction Security(BSP Memoranda No. M04112006)
- Final list of accredited Corporate Governance Seminar providers(BSP Memoranda)
- Extension of the Campaign Period for the "Tulong Barya para sa Eskwela" Coin Recirculation Project(BSP Memoranda No. M-2006-013)
- Rural Bank Strengthening Program(BSP Memoranda No. M-2022-024)
Want an analysis of this document?
Ask ASG Legal AI to summarize it, compare it with other rulings, or explain how it applies to your situation — it researches from this same library.