The financial sector
experience with information
sharing
Patrick Wynant
Manager Banking Operations
Febelfin




                             B-CCENTRE | 28 March 2012
AGENDA


1. Context
2. Interbank
3. External




               B-CCENTRE | 28 March 2012 | 2
Internetbanking in Belgium

 •   Simple, quick, comfort, cheap... > popular and growing
 •   Attractive target for cybercrime
 •   Risks: financial, reputation, continuity…
 •   Maintain trust in this distribution channel




                                                              3
Why should we (not) share information?
- Sharing of vulnerabilities is ‘not done’
- Can I trust the information receiver?
- What happens with my information?
…

+ understand better the potential vulnerabilities, threats & attacks
+ assess the impact of incidents
+ mitigate these threats and risks with (sector wide) measures
+ …save money

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
• Delicate balancing act
• Reciprocity - Win-win


                                                        B-CCENTRE | 28 March 2012   4
Internetbanking security information sharing in
Belgium
• Working Group:
 • banks + Isabel + NBB (supervisor) + FCCU
 • Recurrent + adhoc meetings + Task forces
• Forum of all banks: yearly + adhoc infosessions
• NDA - Disclosure classification: green/amber/red
• Alert communication channel:
 • Anonymous (filter) email to list of subscribers
 • Template with structured data on new/evolving threat
 • No personal data (compliance with privacy regulations)
• CERT.be
• Belgian Cybercrime Centre of Excellence for Training, Research &
  Education (B-CCENTRE)


                                                        B-CCENTRE | 28 March 2012   5
Financial cybercrime information sharing in
Europe
• WG IT Fraud in European Banking Federation
• ISSG Fraud Information Sharing Expert Group
  (CISEG) in European Payments Council (EPC)
• Financial Institutions - Information Sharing and
  Analysis Centre (FI-ISAC) - Europe




                                           B-CCENTRE | 28 March 2012   6
External information sharing
> New website (1/12/2011)

 www.safeinternetbanking.be
 www.internetbankierendoeikveilig.be
 www.labanqueparinternetentoutesecurite.be




                                             B-CCENTRE | 28 March 2012   |7
Internetbanking fraud statistics

• Internetbanking is very secure: # frauds / # sessions = 0,00002 %
• Re-imbursement (except if proven that payer has acted fraudulently)




                                                         B-CCENTRE | 28 March 2012   8
The fraudster at work

                  5 fraud vectors




                                    B-CCENTRE | 28 March 2012   |9
Security, an issue for my bank?

           Veiligheid, een zaak van mijn bank ?
           Wat de bank zoal doet om zowel internetbankieren als betalen via het internet
           zo veilig mogelijk te laten verlopen is terug te vinden onder de rubriek
           “veiligheid, een zaak van mijn bank”.




                                                                       B-CCENTRE | 28 March 2012   | 10
Security, also my business/concern?

           Veiligheid, ook mijn zaak ?
           De site zet bovendien alle tips op een rijtje waarmee de consument zelf kan
           bijdragen aan de veiligheid van zijn online transacties. Deze tips & tricks zijn
           terug te vinden onder de rubriek “veiligheid, ook mijn zaak”.




                                                                           B-CCENTRE | 28 March 2012   | 11
External information sharing > Press
 •      Febelfin press releases (‘malware’) :
         • 18 August 2011
         • 26 September 2011                       Le Soir,
 •      Press in January 2012                      19 augustus 2011
 •      Phishing 9 March 2012

                                                     Mon argent,
                                                4 november 2011




     La Libre Belgique,
      4 januari 2012




                                                Het Nieuwsblad,10 maart 2012
                                                                      B-CCENTRE | 28 March 2012   | 12
                De Tijd, 3 januari 2012

More Related Content

PDF
Eestel atelier cartes 2013 - 2013-11-20
PPTX
Fintech Belgium Summit 2017 - Blockchain - KBC - by Koen Vingerhoets
PDF
Innovative Payment Solutions
PDF
BuyWay Payment Cards by Geert Roelants - FinTech Belgium Summit 2016
DOC
محاضرة للاستاذ مرعي العوامي حول القيادة الإدارية و أنواعها
PPTX
кднз№11
PPTX
Kredietverlening aan ondernemingen update februari 2014
PPTX
Kredietverlening aan ondernemingen juli 2013
Eestel atelier cartes 2013 - 2013-11-20
Fintech Belgium Summit 2017 - Blockchain - KBC - by Koen Vingerhoets
Innovative Payment Solutions
BuyWay Payment Cards by Geert Roelants - FinTech Belgium Summit 2016
محاضرة للاستاذ مرعي العوامي حول القيادة الإدارية و أنواعها
кднз№11
Kredietverlening aan ondernemingen update februari 2014
Kredietverlening aan ondernemingen juli 2013

Similar to Internetbanking security-info-sharing (20)

PDF
Security for Small Business
PPTX
Ib final project
PDF
Lecture 13 -_e-commmerce_e-banking_and_advanced_tech
PPT
Information Security – Review Of 2008 And 2009 97 2003
PDF
Insecure mag-33
PDF
Don zaal a 11.15 11.45 fccu
PDF
20120329 Cybercrime threats on e-world
PPT
Clifford wilke
PDF
INSECURE Magazine - 33
PPTX
Presentatie php benelux groep
PPT
Internet Banking Attacks (Karel Miko)
PDF
i-bank 2.0 & project "safebook" Lotusphere Orlando
PDF
20120613 e-banking fraud situation - BE law enforcement reaction
PPTX
INTERNET BANKING & SECURITY ANALYSIS
PPTX
Crimeware Fingerprinting Final
PDF
20130321 Cybercrime threats on e-commerce online shops
PPT
Ec2009 ch10 e commerce security
PDF
MOBES project
PDF
08 notable-security-incidents-in-the-finance-sector
PDF
08 notable-security-incidents-in-the-finance-sector
Security for Small Business
Ib final project
Lecture 13 -_e-commmerce_e-banking_and_advanced_tech
Information Security – Review Of 2008 And 2009 97 2003
Insecure mag-33
Don zaal a 11.15 11.45 fccu
20120329 Cybercrime threats on e-world
Clifford wilke
INSECURE Magazine - 33
Presentatie php benelux groep
Internet Banking Attacks (Karel Miko)
i-bank 2.0 & project "safebook" Lotusphere Orlando
20120613 e-banking fraud situation - BE law enforcement reaction
INTERNET BANKING & SECURITY ANALYSIS
Crimeware Fingerprinting Final
20130321 Cybercrime threats on e-commerce online shops
Ec2009 ch10 e commerce security
MOBES project
08 notable-security-incidents-in-the-finance-sector
08 notable-security-incidents-in-the-finance-sector
Ad

More from Febelfin (20)

PPTX
Governance van Febelfin
PPTX
Gouvernance de Febelfin
PPTX
Governance of Febelfin
PPTX
Oplichting via internet
PPTX
Safe internetbanking presentation European Cyber Security Month 30.09.2016
PPTX
Presentatie veilig internetbankieren @ OCMW Zwijndrecht
PPTX
Febelfin conférence de presse 12.03.2015
PPTX
Febelfin connect persconferentie 12.03.15
PPTX
Scholenroadshow Argenta - veilig internetbankieren - 6 maart 2015
PPTX
Kredietverlening aan ondernemingen update maart 2014
PPTX
Octroi de crédits aux entreprises mise à jour marspptx
PPTX
Octroi de crédits aux entreprises mise à jour février
PPTX
Kredietverlening aan ondernemingen update februari 2013 - copy
PPTX
Octroi de crédits aux entreprises mise à jour février
PPTX
Kredietverlening aan ondernemingen update februari 2014
PPTX
Octroi de crédits aux entreprises mise à jour février 2014
PDF
FA_presentation_NYEvent-28012014
PPTX
Octroi de crédits aux entreprises octobre
PPTX
Kredietverlening aan ondernemingen oktober 2013 - copy
PPTX
Kredietverlening aan ondernemingen augustus 2013
Governance van Febelfin
Gouvernance de Febelfin
Governance of Febelfin
Oplichting via internet
Safe internetbanking presentation European Cyber Security Month 30.09.2016
Presentatie veilig internetbankieren @ OCMW Zwijndrecht
Febelfin conférence de presse 12.03.2015
Febelfin connect persconferentie 12.03.15
Scholenroadshow Argenta - veilig internetbankieren - 6 maart 2015
Kredietverlening aan ondernemingen update maart 2014
Octroi de crédits aux entreprises mise à jour marspptx
Octroi de crédits aux entreprises mise à jour février
Kredietverlening aan ondernemingen update februari 2013 - copy
Octroi de crédits aux entreprises mise à jour février
Kredietverlening aan ondernemingen update februari 2014
Octroi de crédits aux entreprises mise à jour février 2014
FA_presentation_NYEvent-28012014
Octroi de crédits aux entreprises octobre
Kredietverlening aan ondernemingen oktober 2013 - copy
Kredietverlening aan ondernemingen augustus 2013
Ad

Recently uploaded (20)

PDF
Financial discipline for educational purpose
PPTX
Very useful ppt for your banking assignments Banking.pptx
PDF
Management Accounting Information for Decision-Making and Strategy Execution ...
PDF
NewBase 22 August 2025 Energy News issue - 1818 by Khaled Al Awadi_compresse...
PPTX
Risk Based Audit - Key to managhe the bussines & Creating the value
PDF
MPEDA Export License Apply Online for Seafood Export License in India.pdf
PDF
Lundin Gold Corporate Presentation August 2025
PDF
In July, the Business Activity Recovery Index Worsened Again - IER Survey
PPT
Conventional Financial Instruments 1.ppt
PPTX
Corporate Governance and Financial Decision-Making in Consumer Goods.pptx
PDF
2012_The dark side of valuation a jedi guide to valuing difficult to value co...
PPT
CompanionAsset_9780128146378_Chapter04.ppt
DOCX
Final. 150 minutes exercise agrumentative Essay
PDF
Fintech Regulatory Sandbox: Lessons Learned and Future Prospects
PPTX
ANALYZE MARKET DEMAND, MARKET SUPPLY AND MARKET.pptx
PPT
Project_finance_introduction in finance.ppt
PPTX
balanced_and_unbalanced_growth_theory_ppt.pptx
PDF
3CMT J.AFABLE Flexible-Learning ENTREPRENEURIAL MANAGEMENT.pdf
PDF
Best Accounting Outsourcing Companies in The USA
PPTX
Research Writing in Bioiinformatics.pptx
Financial discipline for educational purpose
Very useful ppt for your banking assignments Banking.pptx
Management Accounting Information for Decision-Making and Strategy Execution ...
NewBase 22 August 2025 Energy News issue - 1818 by Khaled Al Awadi_compresse...
Risk Based Audit - Key to managhe the bussines & Creating the value
MPEDA Export License Apply Online for Seafood Export License in India.pdf
Lundin Gold Corporate Presentation August 2025
In July, the Business Activity Recovery Index Worsened Again - IER Survey
Conventional Financial Instruments 1.ppt
Corporate Governance and Financial Decision-Making in Consumer Goods.pptx
2012_The dark side of valuation a jedi guide to valuing difficult to value co...
CompanionAsset_9780128146378_Chapter04.ppt
Final. 150 minutes exercise agrumentative Essay
Fintech Regulatory Sandbox: Lessons Learned and Future Prospects
ANALYZE MARKET DEMAND, MARKET SUPPLY AND MARKET.pptx
Project_finance_introduction in finance.ppt
balanced_and_unbalanced_growth_theory_ppt.pptx
3CMT J.AFABLE Flexible-Learning ENTREPRENEURIAL MANAGEMENT.pdf
Best Accounting Outsourcing Companies in The USA
Research Writing in Bioiinformatics.pptx

Internetbanking security-info-sharing

  • 1. The financial sector experience with information sharing Patrick Wynant Manager Banking Operations Febelfin B-CCENTRE | 28 March 2012
  • 2. AGENDA 1. Context 2. Interbank 3. External B-CCENTRE | 28 March 2012 | 2
  • 3. Internetbanking in Belgium • Simple, quick, comfort, cheap... > popular and growing • Attractive target for cybercrime • Risks: financial, reputation, continuity… • Maintain trust in this distribution channel 3
  • 4. Why should we (not) share information? - Sharing of vulnerabilities is ‘not done’ - Can I trust the information receiver? - What happens with my information? … + understand better the potential vulnerabilities, threats & attacks + assess the impact of incidents + mitigate these threats and risks with (sector wide) measures + …save money >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> • Delicate balancing act • Reciprocity - Win-win B-CCENTRE | 28 March 2012 4
  • 5. Internetbanking security information sharing in Belgium • Working Group: • banks + Isabel + NBB (supervisor) + FCCU • Recurrent + adhoc meetings + Task forces • Forum of all banks: yearly + adhoc infosessions • NDA - Disclosure classification: green/amber/red • Alert communication channel: • Anonymous (filter) email to list of subscribers • Template with structured data on new/evolving threat • No personal data (compliance with privacy regulations) • CERT.be • Belgian Cybercrime Centre of Excellence for Training, Research & Education (B-CCENTRE) B-CCENTRE | 28 March 2012 5
  • 6. Financial cybercrime information sharing in Europe • WG IT Fraud in European Banking Federation • ISSG Fraud Information Sharing Expert Group (CISEG) in European Payments Council (EPC) • Financial Institutions - Information Sharing and Analysis Centre (FI-ISAC) - Europe B-CCENTRE | 28 March 2012 6
  • 7. External information sharing > New website (1/12/2011) www.safeinternetbanking.be www.internetbankierendoeikveilig.be www.labanqueparinternetentoutesecurite.be B-CCENTRE | 28 March 2012 |7
  • 8. Internetbanking fraud statistics • Internetbanking is very secure: # frauds / # sessions = 0,00002 % • Re-imbursement (except if proven that payer has acted fraudulently) B-CCENTRE | 28 March 2012 8
  • 9. The fraudster at work 5 fraud vectors B-CCENTRE | 28 March 2012 |9
  • 10. Security, an issue for my bank? Veiligheid, een zaak van mijn bank ? Wat de bank zoal doet om zowel internetbankieren als betalen via het internet zo veilig mogelijk te laten verlopen is terug te vinden onder de rubriek “veiligheid, een zaak van mijn bank”. B-CCENTRE | 28 March 2012 | 10
  • 11. Security, also my business/concern? Veiligheid, ook mijn zaak ? De site zet bovendien alle tips op een rijtje waarmee de consument zelf kan bijdragen aan de veiligheid van zijn online transacties. Deze tips & tricks zijn terug te vinden onder de rubriek “veiligheid, ook mijn zaak”. B-CCENTRE | 28 March 2012 | 11
  • 12. External information sharing > Press • Febelfin press releases (‘malware’) : • 18 August 2011 • 26 September 2011 Le Soir, • Press in January 2012 19 augustus 2011 • Phishing 9 March 2012 Mon argent, 4 november 2011 La Libre Belgique, 4 januari 2012 Het Nieuwsblad,10 maart 2012 B-CCENTRE | 28 March 2012 | 12 De Tijd, 3 januari 2012