Five Questions With: Nelson Teixeira

"I THINK we as consumers are becoming more knowledgeable and banks, in general, have done a great job of communicating the different schemes that are out there," said Nelson Teixeira, vice president of direct banking and e-commerce at Bank Newport. /

Online “phishing” scams have long been a problem for banks with an online presence. Fraudulent e-mails and Web sites that fool customers into revealing private information have cost them billions of dollars.
In recent years, banks have employed “dual-factor authentication,” and Bank Newport has gone about it in a different way. Nelson Teixeira, vice president of direct banking and e-commerce at Bank Newport, answered a few questions about it.

PBN: Can you explain dual-factor authentication? Who made it a requirement, and why?
TEIXEIRA:
Dual-factor authentication is a risk-management control necessary to authenticate the identity of retail and commercial customers accessing Internet-based financial services beyond single-factor authentication. Single-factor authentication is the process of accessing your account information using a User ID and password. That is what all banks used prior to the guidance that was released in October 2005 by the Federal Financial Institutions Examination Council (FFIEC), which required all financial institutions to achieve compliance with dual-factor authentication no later than year-end 2006.
The reason for the FFIEC guidance is that several studies were done to ascertain why there were so many fraud-related cases involving online banking. Account fraud and identity theft were frequently a result of single-factor authentication exploitation. Basically, customers were not safeguarding their information and banks did not have a better method to safeguard the system. Dual-factor authentication was the solution to be able to add another layer of authentication that would require financial institutions to protect the information to prevent fraud.

Seifert Systems Invests in Energy Efficiency to Strengthen Operations

For manufacturers, energy is more than just another operating expense. It plays a critical role…

Learn More

PBN: Is phishing a growing problem in the banking industry, or has dual-factor authentication put a damper on it?
TEIXEIRA:
It is a problem, but I think we as consumers are becoming more knowledgeable and banks, in general, have done a great job of communicating the different schemes that are out there. We continue to educate our customers when they open a new account or when they call our Direct Banking Center asking us about the security of our systems.
Dual-factor has helped the phishing problem because they now need another form of authentication. In our case, that other method is in the form of a digital certificate downloaded on their computer. I think we are well protected, but I cannot speak for other financial institutions or other methods of authentication. Dual-factor doesn’t protect customers from giving up information that may be private in nature; consumers can only protect against that by not sharing their private financial information when asked.

PBN: Have there been any reports of online phishing attacks on Bank Newport customers?
TEIXEIRA:
Yes, we did have a reported phishing attack last year, and we did not have exposure to any losses or fraud. Our security team does an excellent job of communicating these issues to our customers, and we regularly send out information in the form of letters and statement stuffers. We also have a notice on our Web site’s main page, so that all customers know that we will never ask them for sensitive information through e-mail or a phone call.

- Advertisement -

PBN: What ways have financial institutions chosen to meet the dual-factor requirements, and what way has Bank Newport approached it? Why?
TEIXEIRA:
I did extensive research on this topic and there are several methods that banks can protect customer information using dual-factor authentication. These methods include digital certificates, physical devices, such as smart cards, IP address location, one-time passwords, USB plug-ins or other types of tokens and biometric identification.
Bank Newport selected digital certificates as its preferred method of dual-factor authentication. We knew we had to achieve compliance, and all other methods seemed inconvenient to the customer. We wanted to ensure our customers achieved an exceptional customer experience when visiting our site. Our top priority was to make sure customer information was protected but to also make certain our customer’s needs were addressed.
Our customers initially had to go through a one-time registration process to register and then it asked the customer to download the digital certificate to their computer. Digital certificates are electronic documents. Computer users install them on their computers to verify their identity to that site. They are nearly impossible to forge because they are issued by official organizations called “certificate authorities.” We found that this new authentication method was a win-win for the bank and our customers. Once the certificate is installed, the customer does not need to do anything else other than put in their user identification and password. The process was seamless to the customer and their initial behavior continued.
Our customers who have multiple accounts at different institutions have complimented us on our solution and love the fact that once the certificate is installed, they continue banking the same way they always banked with us.

PBN: What if I am at a computer that does not have a certificate? Can I still access my accounts?
TEIXEIRA:
Yes, you would still be able to access your accounts. We also addressed the fact that if a customer were to use another computer, they could also download a digital certificate on that computer. If it were a public computer, then the system would require a question to be answered, something only the customer would know. A certificate is not required to be downloaded on each computer. It is up to the customer and if they do, then they will have a better experience on our site.

Bank Newport, founded in 1819, is a subsidiary of the Mutual Holding Co., OceanPoint Financial Partners MHC. The bank has 12 branches and $1 billion in assets. Additional information is available at www.BankNewport.com.

No posts to display