Connect with us

Business

Why it’s risky for financial firms to rely on mobile device authentication

Source: Finance Derivative

Niall McConachie, regional director (UK & Ireland) at Yubico

Using mobile phones to sign into online services can offer people a sense of security and convenience. However, when their devices are damaged, lost, or stolen, they can quickly experience why relying on mobile authentication methods is not the best choice when it comes to protecting their online identities.

Despite this, many financial firms and institutions in the UK continue to encourage their customers and employees to use this form of digital authentication when accessing sensitive data. With cyber attacks being the most cited risk to the UK financial system, it is important that leaders understand the increased risks that they take on with continued use of ineffective authentication and poor cyber hygiene practices.

Limitations of mobile devices and passwords

Aside from being easily lost, stolen, or broken, the effectiveness of mobile-based authentication can be limited depending on the user’s location. For example, depending on where the mobile devices are being used, people may not have the reception needed to authenticate into an account. Additionally, they could be locked out of their accounts simply due to the device’s battery running out. However, even without these issues, mobile devices still pose considerable cybersecurity risks.

Indeed, findings from our recent State of Global Enterprise Authentication Survey, show that mobile SMS-based authentication (20 percent), push authenticator apps or mobile one-time passcodes (OTPs) (23 percent), and passwords (23 percent) are believed to be the most secure forms of digital authentication by UK respondents. As financial firms use these methods so often, it is understandable why customers and employees would come to this assumption. However, this is a misconception.

While any form of authentication is better than none, passwords and mobile-based authentication methods – including SMS verification, OTPs, and digital authentication apps – are all vulnerable to many modern cybersecurity threats. These include SIM swapping, phishing, password spraying, man-in-the-middle (MitM) attacks, and ransomware attacks which can all lead to possible data breaches, imposing serious consequences on UK financial organisations.

Improved cyber hygiene practices and training for employees

According to the survey, the primary ways that UK employees signed into their business accounts were with usernames and passwords (53 percent), mobile SMS-based authentication (24 percent), and push authenticator apps or mobile OTPs (19 percent),  indicating that UK employees are not choosing the best form of authentication methods. These practices leave their accounts easily compromised by bad actors. 

Additionally, it is important to note that no authentication solution can be fully effective in mitigating emerging cyber threats if used alongside poor cyber hygiene practices, which play a significant role in reducing an organisation’s cyber resiliency against external threats.

Overall, it appears that UK organisations are not properly enforcing best-practice cyber training amongst their internal staff. Findings show that only 42 percent of respondents are required to go through frequent cybersecurity training. The report also revealed significant lapses in employees’ cyber-hygiene practices. For instance, over the previous 12 months, UK respondents admitted to using a work-issued device for personal use (49 percent), allowing their work-issued device to be used by someone else (33 percent), not reporting a phishing attempt (31 percent), having an account reset due to lost or forgotten credentials (58 percent), and using a personal device for work (58 percent).

These poor habits should be concerning for finance firms because if an employee uses a personal device for work, bad actors can compromise that device and use it as a point of access to target their employer. As 73 percent of UK respondents claimed to have experienced a cyber attack in their personal lives within the previous 12 months – this and other similar scenarios are highly possible.

Moreso, the combination of weak authentication methods and poor digital habits make organisations especially vulnerable to cyber attacks which can directly target their customers, employees, and third party partners as well. Therefore, better cyber hygiene practices should be enforced on a regular basis to protect organisations fully and effectively from emerging threats.

Benefits of alternative authentication methods

For finance businesses looking for alternative methods, it is important to note that there are some forms of multi-factor authentication (MFA) and two-factor authentication (2FA) that are more robust than others. For example, some require users to authenticate with either a hardware security key or identity credential that is unique to the individual user like a fingerprint. With the help of FIDO protocols – globally recognised standards of public key cryptography techniques to deliver stronger authentication – stronger authentication methods like these provide users with a seamless experience when accessing their digital accounts by removing the need for passwords or mobile devices.

The National Cyber Security Centre (NCSC), recommends hardware-based security keys as a phishing-resistant solution against modern cyber attacks. In addition, a growing number of global companies and UK banks have implemented passwordless authentication. Apple, Barclays, Co-operative Bank, Google, HSBC, Microsoft, NatWest, Twitter, and the US Government are just a few reputable organisations which have opted for passwordless authentication.

Customers and staff should not be solely responsible for adjusting their own cybersecurity practices. It is also up to organisations to enhance their digital security by implementing phishing-resistant passwordless solutions. Whether using biometric identifiers or hardware security keys, these solutions are more effective and user-friendly than conventional authentication methods. They also offer robust authentication across multiple devices and accounts, reducing the number of times a user needs to sign in. However, most importantly, implementing business-wide passwordless solutions helps to reinforce an organisation’s security posture and significantly decreases the risk of emerging attacks.

Mobile-based authentication, OTPs, and passwords are some of the most widely used authentication methods but are not the most secure. As the finance sector continues to prioritise passwordless authentication, this will likely change customers’ and employees’ perceptions of what secure authentication truly is. Ultimately, providing users with the most secure authentication possible should be a top priority. With it, financial firms can experience the long-term benefits of improved data security, better user experience, and considerable ROI.



982/750 word minimum

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business

Time is running out: NHS and their digital evolution journey

By Nej Gakenyi, CEO and Founder of GRM Digital

Many businesses have embarked on their digital evolution journey, transforming their technology offerings to upgrade their digital services in an effective and user-friendly way. Whilst this might be very successful for smaller and newer businesses, but for large corporations with long-standing legacy infrastructure, what does this mean? Recently the UK government pledged £6bn of new funding for the NHS, and the impact this funding and investment could have if executed properly, could revolutionise the UK public healthcare sector.

The NHS has always been a leader in terms of technology for medical purposes but where it has fallen down is in the streamlining of patient data, information and needs, which can lead to a breakdown in trust and the faith that the healthcare system is not a robust one. Therefore, the primary objective of additional funding must be to implement advanced data and digital technologies, to improve the digital health of the NHS and the overall health of the UK population, as well as revitalise both management efficiency and working practices.

Providing digital care

Digitalisation falls into two categories when it comes to the NHS – digitising traditionally ‘physical’ services like offering remote appointments and keeping electronic paper records, and a greater reliance on more innovative approaches driven by advances in technology. It is common knowledge that electronic services differ in GP practices across the country; and to have a drastically good or bad experience which is solely dependent on a geographical lottery contradicts the very purpose of offering an overarching healthcare provision to society at large.

By streamlining services and investing in proper infrastructure, a level playing field can be created which is vital when it comes to patients accessing both the care they need and their own personal history of appointments, GP interactions, diagnoses and medications. Through this approach, the NHS focus on creating world-leading care, provision of that care and potentially see waiting lists decrease due to the effective diagnosis and management enabled by slick and efficient technology.

This is especially important when looking at personalisedhealth support and developing a system that enables patients to receive care wherever they are and helps them monitor and manage long-term health conditions independently. This, alongside ensuring that technology and data collection supports improvements in both individual and population-level patient care, can only serve to streamline NHS efforts and create positive outcomes for both the patient and workforce.

Revolutionising patient experiences

A robust level of trust is critical to guaranteeing the success of any business or provision. If technology fails, so does the faith the customer or consumer has in the technology being designed to improve outcomes for them. An individual will always have some semblance of responsibility and ownership over their lives, well-being and health. Still, all of these key pillars can only stand strong when there is infrastructure in place to help drive positive results. Whilst there may be risks of excluding some groups of individuals with a digital-first approach, technology solutions can empower people to take control of their healthcare enabling the patient and NHS to work together. Tandem efforts between humans and technology

Technology must work in tandem with a workforce for it to be effective. This means the NHS workforce must be digitally savvy and have patient-centred care at the front and centre of all operations. Alongside any digital transformation the NHS adopts to improve patient outcomes, comes the need to assess current and future capability and capacity challenges, and build a workforce with the right skills to help shape an NHS that is fit for purpose.

This is just the beginning. With more invtesement and funding being allocated for the NHS this is the starting point, but for NHS decision-makers to ensure real benefits for patients, more still needs to be done. Effective digital evolution holds the key. Once the NHS has fully harnessed the poer of new and evolving technologies to change patient experiences throught the UK, with consistent communication and care, this will set the UK apart and will mark the NHS has a diriving example for accessible, digital healthcare.

Continue Reading

Business

Driving Business Transformation Through AI Adoption – A Roadmap for 2024

Author: Edward Funnekotter, Chief Architect and AI Officer at Solace

From the development of new products and services, to the establishment of competitive advantages, Artificial intelligence (AI) can fundamentally reshape business operations across industries. However, each organisation is unique and as such navigating the complexities of AI, while applying the technology in an efficient and effective way, can be a challenge.

To unlock the transformational potential of AI in 2024 and integrate it into business operations in a seamless and productive way, organisations should seek to follow these five essential steps:

  • Prioritise Data Quality and Quantity

Usefulness of AI models is directly correlated to the quantity and quality of the data used to train them, necessitating effective integration solutions and strong data governance practices. Organisations should seek to implement tools that provide a wealth of clean, accessible and high-quality data that can power quality AI.

Equally, AI systems cannot be effective if an organisation has data silos. These impede the ability for AI to digest meaningful data, and then provide the insights that are needed to drive business transformation. Breaking down data silos needs to be a business priority – with investment in effective data management, and an application of effective data integration solutions.

  • Develop your own unique AI platform

The development of AI applications can be a laborious process, impacting the value that businesses are gaining from them in the immediate term. This can be expedited by platform engineering, which modernises enterprise software delivery to facilitate digital transformation, optimising developer experience and accelerating the ability to deliver customer value for product teams. The use of platform engineering offers developers pre-configured tools, pre-built components and automated infrastructure management, freeing them up to tackle their main objective; building innovative AI solutions faster.

While the development of AI applications that can help streamline infrastructure, automate tasks, and provide pre-built components for developers is the end goal, it’s only possible if the ability to design and develop is there in the first place. Gartner’s prediction that Platform Engineering will come of age in 2024 is a particularly promising update.

  • Put business objectives at the heart of AI adoption – can AI deliver?

Any significant business change needs to be managed strategically, and with a clear indication of the aims and benefits they will bring. While a degree of experimentation is always necessary to drive business growth, these shouldn’t be at the expense of operational efficiency.

Before onboarding AI technologies, look internally at the key challenges that your business is facing and question “how can AI help to address this?” You may wish to enhance the customer experience, streamline internal processes or use AI systems to optimise internal decision-making. Be sure the application of AI is going to help, not hinder you on this journey

Also remember that AI remains in its infancy, and cannot be relied upon as a silver bullet for all operational challenges. Aim to build a sufficient base knowledge of AI capabilities today, and ensure these are contextualised within your own business requirements. This ensures that AI investments aren’t made prematurely, providing an unnecessary cost.

  1. Don’t be limited by legacy systems

Owing to the complex mix of legacy and/or siloed systems that organisations employ, they may be restricted in their ability to use real-time and AI-driven operations to drive business value. For example, IDC found that only 12% of organisations connect customer data across departments.

Amidst the ‘AI data rush’ there will be a greater need for event-driven integration, however, only an enterprise architecture pattern will ensure new and legacy systems are able to work in tandem. Without this, organisations will be prevented from offering seamless, real-time digital experiences, linking events across departments, locations, on-premises systems, IoT devices, in a cloud or even multi-cloud environment.

  • Leverage real-time technology

Keeping up with the real-time demands of AI can pose a challenge for legacy data architectures used by many organisations. Event mesh technology – an approach to distributed networks that enable real-time data sharing and processing – is a proven way of reducing these issues. By applying event-driven architecture (EDA), organisations can unlock the potential of real-time AI, with automated actions and informed decision making using relevant insights and automated actions.

By applying AI in this way, businesses can offer stronger, more personalised experiences – including the delivery of specialised offers, real-time recommendations and tailored support based on customer requirements. An example of this is in predictive maintenance, in which AI is able to analyse and anticipate future problems or business-critical failures, ahead of them affecting operations, and dedicate the correct resources to fix the issue, immediately. By implementing EDA as a ‘central nervous system’ for your data, not only is real-time AI possible, but adding new AI agents becomes significantly easier.

Ultimately, AI adoption needs to be strategic, avoiding chasing trends and focusing instead on how and where the technology can deliver true business value. Following the steps above, organisations can ensure they are leveraging the full transformative benefit of AI and driving business efficiency and growth in a data driven era.

AI can be a highly effective tool. However, its success is dependent on how it is being applied by organisations, strategically,  to meet clearly defined and specific business goals.

Continue Reading

Auto

Preparing for the Surge: Meeting the MCS Requirements of Electric Trucks

John Granby, Director of eTruck & Van, EO Charging and Erik Kanerva, Sales Director at Kempower

Auto electrification is moving at a rapid pace, with electric vehicles (EVs) going from a passion project for early technology adopters to the mainstream – especially when you consider the need to electrify consumer and commercial vehicles ahead of the government’s 2035 Zero Emission Vehicle mandate.

Electrification is also starting to play a vital role in public policy and commercial plans, leading to vehicle availability and a variety of improvements and increasing interest among commercial fleets’ prospective customers. As a result, all of the main car and van manufacturers have a respectable EV offering, and the eBus industry is well on its way to proposing a similarly credible offering for citizens.

Heavy-duty vehicle electrification has progressed slowly, but the pace has picked up over the last year, with several of the major truck manufacturers testing completely electric heavy trucks that are now near-ready to enter the general market.

This is a critical shift in the move towards net zero, given that heavy commercial vehicles account for around 25% of CO2 emissions from road transport emissions in the EU and approximately 6% of the region’s overall emissions. It’s a similar situation in the US, where medium and heavy-duty trucks account for around 29% of total road transport emissions or approximately 7% of the country’s total but make up fewer than 5% of all vehicles on the road.

Having clear goals and objectives in place for fleet electrification will be vital to ensuring the transport sector is on track. For example, Scania’s goal is that 50% of all vehicles it sells annually by 2030 will be electric. Despite Scania being the slowest into the market with battery electric vehicles, other vehicle manufacturers are following the same target, with Volvo Trucks setting itself a target for 50% fully electric vehicles by 2030 and the same with Renault, for example.

Meeting this ambitious goal will require the appropriate charging infrastructure in place so customers have the confidence to invest in the large-scale electrification of their fleets. That is one of the reasons why charging system manufacturer Kempower expects the commercial vehicle DC charging market in Europe and North America to have a 37% compound annual growth rate until 2030.

Trucks require substantial battery packs to provide a similar range as traditional engines, and having the right infrastructure in place to keep them regularly charged is certainly a key factor to consider when electrifying truck fleets. According to the European Automobile Manufacturers’ Association (ACEA), trucks will require up to 279,000 charging outlets by 2030, with 84% located in fleet hubs. By 2030, buses will require up to 56,000 charging outlets, with fleet hubs accounting for 92% of the total.

The Charging Interface Initiative (CharIN) is a global organisation that has been working on a standard for the rapid charging of trucks for several years. CharIN developed the Megawatt Charging System (MCS) concept, which serves as the foundation for the ISO and IEC standards which govern the design, installation, and operation of truck fast charging infrastructures.

The MCS is intended to standardise the quick delivery of enormous amounts of charging power to vehicles and provide stronger communication, which minimises downtime caused by unsuccessful charging events.

Customers who drive commercial vehicles follow particular driving habits. By taking advantage of the required break time from the hours-of-service restrictions governing their drivers, customers can travel further each day thanks to the increased charge rate that MCS offers. Better electrification of commercial cars is made possible by legislation that mandates that drivers take rest breaks. As a result, shorter charging durations to accommodate these breaks are beneficial.

The MCS will operate at up to 3,000A and 1,25 KV at its final development stage, delivering up to 3,75 MW of power when charging. With the backing of a significant segment of the industry, MCS is founded on an international consensus on technical standards. An internationally recognised standard is essential to promote harmonised solutions that reduce costs and boost interoperability without sacrificing safety and uptime.

Trucks on the highway are a key focus of the MCS, not only depot pricing. Large truck units operating long-haul routes and some smaller rigid trucks operating cross-border short-haul deliveries—such as logistics organisations operating deliveries between the United Kingdom and continental Europe—pay particular attention to this issue.

Most MCS charging occurs while drivers take breaks from their routes, but some depots may have a single MCS charger on site to do a flash charge if a truck needs to be turned around quickly. In order to balance this unit’s demand against other chargers on site, load management is crucial because it will require a power supply of at least 1 MW+.

Fleet operators should look to consider incorporating MCS into their whole charging ecosystem and solutions, regardless of whether they are thinking about how electrification will affect their fleet of vehicles on the road or how their depots will operate.

Adopting cutting-edge energy management technology solutions will enable effective fleet electrification, particularly at depots. Investing in effective load management technologies will be critical to maximising existing grid infrastructure capacity while decreasing the need for additional investments in generation or distribution capacity.

Investing in and deploying effective energy management technologies is the key to a smoother, more efficient shift for commercial fleet operators. They are critical in lowering energy expenses, both economically and environmentally.

Energy management solutions for charging electric fleets will also help maximise existing grid capacity, reducing the need to invest in new generation or distribution capacity. This will be an essential factor for fleet managers to consider as eTruck fleets expand and other commercial vehicle fleets, such as buses, increase demands on infrastructure.

With unprecedented energy and investment going into electrification, 2024 looks to be a pivotal year for picking up the momentum of progress around MCS in the logistics sector. If done right, it will create a shift of optimism in the market to accelerate the electrification of commercial fleets and promises to positively impact other sectors, such as marine and aviation, contributing significantly to reducing carbon emissions.

Continue Reading

Copyright © 2021 Futures Parity.