13.07.2015 Views

Driving Innovation in Security Technology Through ... - FST Media

Driving Innovation in Security Technology Through ... - FST Media

Driving Innovation in Security Technology Through ... - FST Media

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Driv<strong>in</strong>g</strong> <strong>Innovation</strong> <strong>in</strong> <strong>Security</strong> <strong>Technology</strong> <strong>Through</strong> Emerg<strong>in</strong>g Channels“How do I ensure thereis a secure transactionhappen<strong>in</strong>g? We don’thave an easy answer.”– Chris Smith, NAB“The question that ismost <strong>in</strong>terest<strong>in</strong>g hereis how do you keep acustomer secure, but atthe same time solve theissue of convenience?”– Cameron Owens,NAB4Chris Smith, NAB: I th<strong>in</strong>k a lot of what we dois the Wild West and so we create these apps. Iagree iOS is quite unique and a lot safer but I’vegot another audience, and who knows what they’redownload<strong>in</strong>g on that site.One of the issues we face is second mop up: howdo you authenticate? So you’re <strong>in</strong> that app, you’re<strong>in</strong> that experience, how do you get that? I agree it’sgood but I have a fundamental problem and thatis how do I ensure there is a secure transactionhappen<strong>in</strong>g? We don’t have an easy answer.Vic Mankotia, CA Technologies: There isadvanced authentication, there is authentication atthe log-<strong>in</strong> phase, risk-based authentication, thereis authentication with one-time password (OTP),there is SMS OTP, authentication on the web site,and aga<strong>in</strong> too much security will just hamperbus<strong>in</strong>ess. Five people will stab you with a spoonbecause you’re go<strong>in</strong>g to delay the speed of bus<strong>in</strong>essand you’ve got to move at the pace of the customer.Dave Williams, Bankwest: Com<strong>in</strong>g back toyour comment earlier about not be<strong>in</strong>g concernedabout the Qantas po<strong>in</strong>ts. Qantas actually hold quitea lot of <strong>in</strong>formation on you, as do many other sitesthat you register with, but they don’t have the samelevel of security that banks would have. So it’s notjust what security we can have, but how can weprotect ourselves aga<strong>in</strong>st non-f<strong>in</strong>ancial <strong>in</strong>stitutions’sites that collect credible, identifiable data.Paul Guardabascio, NAB: As an <strong>in</strong>dustry, thespeed of <strong>in</strong>novation and market competitive forcesare driv<strong>in</strong>g change. What do you see <strong>in</strong> terms ofcollaboration with the telcos and utility companiesand the bank<strong>in</strong>g sector? Who actually owns thecustomer?Vic Mankotia, CA Technologies: The telcostake no responsibility. The banks say, I provide youwith an application, it’s yours to use, but use it atyour own peril. The software security companiesare say<strong>in</strong>g, “Here’s a solution.” It works half thetime, it doesn’t work the other half of the time.And the hardware manufacturers are say<strong>in</strong>g, “Hey,what about Android, iOS 5, what about Galaxy?What about Symbian, BlackBerry Storm?”Soon it’s go<strong>in</strong>g to condense. It’s a four-horserace; soon it’s go<strong>in</strong>g to become a two-horse race.If you don’t look after your assets, nobody elsewill. Don’t expect there to be an ombudsman or acollaborative network of people who are go<strong>in</strong>g togo out and say, “I’ll do it for you.”Cameron Owens, NAB: The question that ismost <strong>in</strong>terest<strong>in</strong>g here is how do you keep a customersecure, but at the same time solve the issue ofconvenience? A lot of the solutions we have todayare token. There’s no especially convenient way tosolve the security issue. So that’s the <strong>in</strong>terest<strong>in</strong>gdilemma we have. Our customers are dragg<strong>in</strong>gus there, and we need to be there and we need tomake their life easier but also to protect them. Theyare obviously deal<strong>in</strong>g <strong>in</strong> large sums of money, butif the customer experience is so cumbersome, it’s amassive barrier.Naresh Vyas, Standard Chartered:Customer experience is important, otherwiseusability will be a problem.Vic Mankotia, CA Technologies: I’ll go backto your Square example. Last week <strong>in</strong> San FranciscoI was shocked when I saw how it worked. It was soconvenient that I used it 20 times dur<strong>in</strong>g the week.Naresh Vyas, Standard Chartered: Thishas completely changed the <strong>in</strong>dustry locally <strong>in</strong>the US. This is a device that you can plug <strong>in</strong>to theheadphone jack of either an iPhone or Android anddownload an app from different stores. It convertsa magnetic strip’s data <strong>in</strong>to an audio signal soit can plug right <strong>in</strong>to the audio jack. Once that isplugged <strong>in</strong>, I then have a POS device. I can swipean American Express card, Mastercard or Visa cardand put <strong>in</strong> the amount and charge it.You can have other features. You can take aphotograph of what you’re sell<strong>in</strong>g, the person willget an email receipt with an image of your house,and the location of where the transaction occurred,the amount.They give you this device for free. What it doesis turn anyone <strong>in</strong>to a merchant. You don’t needanyth<strong>in</strong>g special, you don’t need a merchantaccount. It was convenient but it also gave me theheeby jeebies, because I had no idea about thesecurity of this.Richard Farrell, ANZ: But you still used it,right?Naresh Vyas, Standard Chartered: But Istill used it.Vic Mankotia, CA Technologies: The secondproblem that many executives are talk<strong>in</strong>g about isemployees br<strong>in</strong>g<strong>in</strong>g <strong>in</strong> their own devices. Are yousee<strong>in</strong>g that happen often?Ber<strong>in</strong> Lautenbach, GE Capital: You surveypeople and a huge number actually don’t want tobr<strong>in</strong>g their own PC <strong>in</strong>. They’re not really <strong>in</strong>terested.Naresh Vyas, Standard Chartered: We’veissued standardised iPhones to employees. Wehave an eco-system with<strong>in</strong> the bank with securitycertificates for the devices. You have accessibility toimportant data remotely as opposed to hav<strong>in</strong>g to bephysically <strong>in</strong> the office.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!