SlideShare une entreprise Scribd logo
1  sur  12
Télécharger pour lire hors ligne
NEW THREATS FROM NEW
REGULATIONS COULD
IMPACT YOUR FIRM
CYBER
READY?
ARE YOU
FINANCIAL SERVICES
TECHNOLOGY ADVISORY
THE CHANGING
CYBER ATTACK
LANDSCAPE
Fake Banking Apps
Mobile Banking Malware
Ransomware
Mobile Trojans
Classical Trojans
Banking Malware
AND NOW
THERE’S PSD2…
Cyber attacks are on
the rise and becoming
more sophisticated
Copyright © 2017 Accenture. All rights reserved. 2
A new regulatory requirement
for banks operating within
the European Union (EU).
(revised/second payment service directive)
WHAT IT IS
Requires banks to open
application programming
interfaces (APIs) and allow all
payment service providers (PSPs)
to access customer information
and initiate transactions.
WHAT IT DOES
Copyright © 2017 Accenture. All rights reserved. 3
Increased
convenience and
ease-of-use for
customers
WHAT THIS
MEANS TO
YOUR FIRM
Increased opportunity
for “bad actors” to
commit cyber attacks
Copyright © 2017 Accenture. All rights reserved. 4
(revised/second payment service directive)
POTENTIAL NEW
RISKS FROM PSD2
Copyright © 2017 Accenture. All rights reserved. 5
The number of PSPs with criminal
intent could rise, further exacerbating
banking cyber security challenges
and increasing costs.
The number of fake multi-banking
apps could grow exponentially,
leading to customer identity theft
and data breaches.
MULTI-
BANKING
MALWARE
MORE
MALICIOUS
PSPS
POTENTIAL NEW
RISKS FROM PSD2
Copyright © 2017 Accenture. All rights reserved. 6
Cyber attacks against PSPs could
result in denials of service to banks,
arising from hacked PSP servers.
Failure by PSPs to appropriately
protect their security certificates
(e-Seals) could create opportunities
for cyber criminals to steal them
and access the bank’s APIs for
criminal intent.
STOLEN
CERTIFICATE
MISUSE
ATTACKS
AGAINST
PSPS
THINGS
YOU
SHOULD
DO!
Deeply embed security protection into APIs
through the following measures:
Do not allow your core
banking system to be
directly accessible
through the internet
THEN…
1 2 3Maintain a high
logging level
Restrict access to
APIs through validated
certificates (e-Seals)
Copyright © 2017 Accenture. All rights reserved. 7
FURTHER PROTECT
YOUR BANK
 Implementing screen scraping protections
 Closely monitoring PSP activity to detect
anomalies that point to fraud
 Strengthening security authentication to
discourage and curtail unauthorized payments
 Establishing a high level of protection against
Distributed Denial-of-Service (DDoS) attacks
 Strongly controlling access to certificate-
based APIs
 Locking out unauthorized banking software
Copyright © 2017 Accenture. All rights reserved. 8
HOW ACCENTURE
CAN HELP
Establishing new
open APIs as well
as the security
measures to protect
them can be a big
challenge. We help
banks prepare for
and respond to this
challenge by:
 Analyzing and assessing
current applications and
cyber defense capabilities
 Conducting readiness
checks against the new
API requirements
 Supporting the design
of new open APIs
 Developing new security
and cyber defense
capabilities and
mechanisms
 Integrating new cyber
defense mechanisms
and APIs into your
existing infrastructure
Copyright © 2017 Accenture. All rights reserved. 9
OR…
Accenture also offers
A partially outsourced and
cost-effective cyber defense
solution tailored to your needs.
AS A SERVICE
Copyright © 2017 Accenture. All rights reserved. 10
TO
LEARN
MORE,
CONTACT HOLGER
AHREND
Financial Services
Technology Advisory
holger.ahrend@accenture.com
CHRISTIAN
TÖLKES
Financial Services
Technology Advisory
christian.toelkes@accenture.com
Copyright © 2017 Accenture. All rights reserved. 11
ABOUT ACCENTURE
Accenture is a leading global professional
services company, providing a broad range of
services and solutions in strategy, consulting,
digital, technology and operations. Combining
unmatched experience and specialized skills
across more than 40 industries and all business
functions—underpinned by the world’s largest
delivery network—Accenture works at the
intersection of business and technology to help
clients improve their performance and create
sustainable value for their stakeholders. With
approximately 425,000 people serving clients
in more than 120 countries, Accenture drives
innovation to improve the way the world works
and lives. Visit us at www.accenture.com
DISCLAIMER
This presentation is intended for general informational purposes only and does not take into account the reader’s specific
circumstances, and may not reflect the most current developments. Accenture disclaims, to the fullest extent permitted
by applicable law, any and all liability for the accuracy and completeness of the information in this presentation and for
any acts or omissions made based on such information. Accenture does not provide legal, regulatory, audit, or tax
advice. Readers are responsible for obtaining such advice from their own legal counsel or other licensed professionals.
Copyright © 2017 Accenture
All rights reserved.
Accenture, its logo, and
High Performance Delivered
are trademarks of Accenture.

Contenu connexe

Tendances

Cloud in the Boardroom
Cloud in the BoardroomCloud in the Boardroom
Cloud in the Boardroom
Accenture Operations
 

Tendances (20)

Digital Health Technology Vision 2017
Digital Health Technology Vision 2017Digital Health Technology Vision 2017
Digital Health Technology Vision 2017
 
Cloud in the Boardroom
Cloud in the BoardroomCloud in the Boardroom
Cloud in the Boardroom
 
The Digital Emperor Has No Clothes
The Digital Emperor Has No ClothesThe Digital Emperor Has No Clothes
The Digital Emperor Has No Clothes
 
Boost your AIQ: Transforming to an AI Business
Boost your AIQ: Transforming to an AI BusinessBoost your AIQ: Transforming to an AI Business
Boost your AIQ: Transforming to an AI Business
 
Stand Out or Stand Back
Stand Out or Stand BackStand Out or Stand Back
Stand Out or Stand Back
 
Trash The Rulebook
Trash The RulebookTrash The Rulebook
Trash The Rulebook
 
B2B Channel Partners: Can These Relationships be Saved?
B2B Channel Partners: Can These Relationships be Saved?B2B Channel Partners: Can These Relationships be Saved?
B2B Channel Partners: Can These Relationships be Saved?
 
Blockchain for Business Operations
Blockchain for Business OperationsBlockchain for Business Operations
Blockchain for Business Operations
 
Intelligent Automation - 3 Lessons Learned
Intelligent Automation - 3 Lessons LearnedIntelligent Automation - 3 Lessons Learned
Intelligent Automation - 3 Lessons Learned
 
Seeing Beyond the Loyalty Illusion in Italy: It’s Time you Invest More Wisely
Seeing Beyond the Loyalty Illusion in Italy: It’s Time you Invest More Wisely Seeing Beyond the Loyalty Illusion in Italy: It’s Time you Invest More Wisely
Seeing Beyond the Loyalty Illusion in Italy: It’s Time you Invest More Wisely
 
Accenture Technology Vision for Oracle 2014
Accenture Technology Vision for Oracle 2014Accenture Technology Vision for Oracle 2014
Accenture Technology Vision for Oracle 2014
 
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...
 
Leading in the New
Leading in the New Leading in the New
Leading in the New
 
Accelerate to a Frictionless Future in Rail and Transit
Accelerate to a Frictionless Future in Rail and TransitAccelerate to a Frictionless Future in Rail and Transit
Accelerate to a Frictionless Future in Rail and Transit
 
Digitally Enabled Grid 2017: Toward a more digital, distributed and resilient...
Digitally Enabled Grid 2017: Toward a more digital, distributed and resilient...Digitally Enabled Grid 2017: Toward a more digital, distributed and resilient...
Digitally Enabled Grid 2017: Toward a more digital, distributed and resilient...
 
The Outcome-oriented High Tech Supply Chain Control Tower
The Outcome-oriented High Tech Supply Chain Control TowerThe Outcome-oriented High Tech Supply Chain Control Tower
The Outcome-oriented High Tech Supply Chain Control Tower
 
Smarter Investments, Outstanding Results: Resources Industries Digital Transf...
Smarter Investments, Outstanding Results: Resources Industries Digital Transf...Smarter Investments, Outstanding Results: Resources Industries Digital Transf...
Smarter Investments, Outstanding Results: Resources Industries Digital Transf...
 
Liquid Workforce - Tech Vision 2016 Trend 2
Liquid Workforce - Tech Vision 2016 Trend 2Liquid Workforce - Tech Vision 2016 Trend 2
Liquid Workforce - Tech Vision 2016 Trend 2
 
Why Software as a Service (SaaS) requires a new approach to Application Manag...
Why Software as a Service (SaaS) requires a new approach to Application Manag...Why Software as a Service (SaaS) requires a new approach to Application Manag...
Why Software as a Service (SaaS) requires a new approach to Application Manag...
 
Accenture Cloud Platform: Control, Manage and Govern the Enterprise Cloud
Accenture Cloud Platform: Control, Manage and Govern the Enterprise CloudAccenture Cloud Platform: Control, Manage and Govern the Enterprise Cloud
Accenture Cloud Platform: Control, Manage and Govern the Enterprise Cloud
 

En vedette

En vedette (13)

Accenture Nonprofit Citizen Survey
Accenture Nonprofit Citizen SurveyAccenture Nonprofit Citizen Survey
Accenture Nonprofit Citizen Survey
 
Accenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A ServiceAccenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A Service
 
Accenture Public Service Citizen Survey: Public Administration
Accenture Public Service Citizen Survey: Public AdministrationAccenture Public Service Citizen Survey: Public Administration
Accenture Public Service Citizen Survey: Public Administration
 
What people want: Accenture Public Service Citizen Survey - Wave 3
What people want: Accenture Public Service Citizen Survey - Wave 3What people want: Accenture Public Service Citizen Survey - Wave 3
What people want: Accenture Public Service Citizen Survey - Wave 3
 
Digital: The New Delivery Paradigm
Digital: The New Delivery ParadigmDigital: The New Delivery Paradigm
Digital: The New Delivery Paradigm
 
AR/VR/MR in Learning Primer v1.0 final
AR/VR/MR in Learning Primer v1.0 finalAR/VR/MR in Learning Primer v1.0 final
AR/VR/MR in Learning Primer v1.0 final
 
Augmented Reality (AR): Designing the Use Case
Augmented Reality (AR): Designing the Use CaseAugmented Reality (AR): Designing the Use Case
Augmented Reality (AR): Designing the Use Case
 
Utility digital benchmark review 2017 webinar slides
Utility digital benchmark review 2017   webinar slidesUtility digital benchmark review 2017   webinar slides
Utility digital benchmark review 2017 webinar slides
 
Drill Deeper Into Digital - 2017 Upstream Oil and Gas
Drill Deeper Into Digital - 2017 Upstream Oil and Gas Drill Deeper Into Digital - 2017 Upstream Oil and Gas
Drill Deeper Into Digital - 2017 Upstream Oil and Gas
 
Utilities Digital Data Driven Innovation
Utilities Digital Data Driven Innovation Utilities Digital Data Driven Innovation
Utilities Digital Data Driven Innovation
 
Digital Business - Accenture
Digital Business - AccentureDigital Business - Accenture
Digital Business - Accenture
 
Accenture DevOps: Delivering applications at the pace of business
Accenture DevOps: Delivering applications at the pace of businessAccenture DevOps: Delivering applications at the pace of business
Accenture DevOps: Delivering applications at the pace of business
 
AI and Machine Learning Demystified by Carol Smith at Midwest UX 2017
AI and Machine Learning Demystified by Carol Smith at Midwest UX 2017AI and Machine Learning Demystified by Carol Smith at Midwest UX 2017
AI and Machine Learning Demystified by Carol Smith at Midwest UX 2017
 

Similaire à Are You Ready for PSD2?

DCIC - Company Profile_Rev2
DCIC - Company Profile_Rev2DCIC - Company Profile_Rev2
DCIC - Company Profile_Rev2
Dexter Cecilia
 

Similaire à Are You Ready for PSD2? (20)

Convince your board - cyber attack prevention is better than cure
Convince your board - cyber attack prevention is better than cureConvince your board - cyber attack prevention is better than cure
Convince your board - cyber attack prevention is better than cure
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Security in the App Economy: How to Ride the Wave Without Wiping Out!
Security in the App Economy: How to Ride the Wave Without Wiping Out!Security in the App Economy: How to Ride the Wave Without Wiping Out!
Security in the App Economy: How to Ride the Wave Without Wiping Out!
 
Aensis Cyber_Sec 2017
Aensis Cyber_Sec 2017Aensis Cyber_Sec 2017
Aensis Cyber_Sec 2017
 
Cyber security infotech pvt ltd
Cyber security infotech pvt ltdCyber security infotech pvt ltd
Cyber security infotech pvt ltd
 
Software as-a-service: Strategic Background
Software as-a-service: Strategic BackgroundSoftware as-a-service: Strategic Background
Software as-a-service: Strategic Background
 
eCare Presentation ORL Alex2
eCare Presentation ORL Alex2eCare Presentation ORL Alex2
eCare Presentation ORL Alex2
 
APIdays Singapore 2019 - Embrace transformation through FinTech collaboration...
APIdays Singapore 2019 - Embrace transformation through FinTech collaboration...APIdays Singapore 2019 - Embrace transformation through FinTech collaboration...
APIdays Singapore 2019 - Embrace transformation through FinTech collaboration...
 
2017 Cost Of Cyber Crime Study | Insights On The Security Investments That Ma...
2017 Cost Of Cyber Crime Study | Insights On The Security Investments That Ma...2017 Cost Of Cyber Crime Study | Insights On The Security Investments That Ma...
2017 Cost Of Cyber Crime Study | Insights On The Security Investments That Ma...
 
Financial services rely on APIs
Financial services rely on APIsFinancial services rely on APIs
Financial services rely on APIs
 
neXt Curve reThink: What Meltdown & Spectre Mean for IoT Past, Present & Future?
neXt Curve reThink: What Meltdown & Spectre Mean for IoT Past, Present & Future?neXt Curve reThink: What Meltdown & Spectre Mean for IoT Past, Present & Future?
neXt Curve reThink: What Meltdown & Spectre Mean for IoT Past, Present & Future?
 
DCIC - Company Profile_Rev2
DCIC - Company Profile_Rev2DCIC - Company Profile_Rev2
DCIC - Company Profile_Rev2
 
Cyber security
Cyber securityCyber security
Cyber security
 
Cyber security
Cyber securityCyber security
Cyber security
 
IT solution
IT solutionIT solution
IT solution
 
How Financial Institutions Can Deliver Seamless Customer Digital Engagements
How Financial Institutions Can Deliver Seamless Customer Digital EngagementsHow Financial Institutions Can Deliver Seamless Customer Digital Engagements
How Financial Institutions Can Deliver Seamless Customer Digital Engagements
 
La Seguridad en la Economía de las Aplicaciones
La Seguridad en la Economía de las AplicacionesLa Seguridad en la Economía de las Aplicaciones
La Seguridad en la Economía de las Aplicaciones
 
How to build a highly secure fin tech application
How to build a highly secure fin tech applicationHow to build a highly secure fin tech application
How to build a highly secure fin tech application
 
ABD207 building a banking utility leveraging aws to fight financial crime and...
ABD207 building a banking utility leveraging aws to fight financial crime and...ABD207 building a banking utility leveraging aws to fight financial crime and...
ABD207 building a banking utility leveraging aws to fight financial crime and...
 
LoansPQ: A Loan Origination System by MeridianLink
LoansPQ: A Loan Origination System by MeridianLinkLoansPQ: A Loan Origination System by MeridianLink
LoansPQ: A Loan Origination System by MeridianLink
 

Plus de accenture

Plus de accenture (20)

The Industrialist: Trends & Innovations - January 2024
The Industrialist: Trends & Innovations - January 2024The Industrialist: Trends & Innovations - January 2024
The Industrialist: Trends & Innovations - January 2024
 
The Industrialist: Trends & Innovations - September 2023
The Industrialist: Trends & Innovations - September 2023The Industrialist: Trends & Innovations - September 2023
The Industrialist: Trends & Innovations - September 2023
 
Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education
 
The Industrialist: Trends & Innovations - July 2023
The Industrialist: Trends & Innovations - July 2023The Industrialist: Trends & Innovations - July 2023
The Industrialist: Trends & Innovations - July 2023
 
Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education
 
Engineering Services: con gli ingegneri per creare valore sostenibile
Engineering Services: con gli ingegneri per creare valore sostenibileEngineering Services: con gli ingegneri per creare valore sostenibile
Engineering Services: con gli ingegneri per creare valore sostenibile
 
Digital Euro: Implications for the Financial System
Digital Euro: Implications for the Financial SystemDigital Euro: Implications for the Financial System
Digital Euro: Implications for the Financial System
 
More deals, less money: the Black founder funding journey
More deals, less money: the Black founder funding journeyMore deals, less money: the Black founder funding journey
More deals, less money: the Black founder funding journey
 
The Industrialist: Trends & Innovations - June 2023
The Industrialist: Trends & Innovations - June 2023The Industrialist: Trends & Innovations - June 2023
The Industrialist: Trends & Innovations - June 2023
 
Reinventing Enterprise Operations
Reinventing Enterprise OperationsReinventing Enterprise Operations
Reinventing Enterprise Operations
 
Semiconductor Gender Parity Study
Semiconductor Gender Parity StudySemiconductor Gender Parity Study
Semiconductor Gender Parity Study
 
The Industrialist: Trends & Innovations - March 2023
The Industrialist: Trends & Innovations - March 2023The Industrialist: Trends & Innovations - March 2023
The Industrialist: Trends & Innovations - March 2023
 
Nonprofit reinvention in a time of unprecedented change
 Nonprofit reinvention in a time of unprecedented change Nonprofit reinvention in a time of unprecedented change
Nonprofit reinvention in a time of unprecedented change
 
Free to be 100% me
Free to be 100% meFree to be 100% me
Free to be 100% me
 
The Industrialist: Trends & Innovations - February 2023
The Industrialist: Trends & Innovations - February 2023The Industrialist: Trends & Innovations - February 2023
The Industrialist: Trends & Innovations - February 2023
 
Mundo gamer e a oportunidade de entrada pela abordagem do movimento
Mundo gamer e a oportunidade de entrada pela abordagem do movimentoMundo gamer e a oportunidade de entrada pela abordagem do movimento
Mundo gamer e a oportunidade de entrada pela abordagem do movimento
 
Pathways to Profitability for the Communications Industry
Pathways to Profitability for the Communications IndustryPathways to Profitability for the Communications Industry
Pathways to Profitability for the Communications Industry
 
The Industrialist: Trends & Innovations - January 2023
The Industrialist: Trends & Innovations - January 2023The Industrialist: Trends & Innovations - January 2023
The Industrialist: Trends & Innovations - January 2023
 
Reimagining the Agenda | Accenture
Reimagining the Agenda | AccentureReimagining the Agenda | Accenture
Reimagining the Agenda | Accenture
 
Climate Leadership Eleventh Hour | Accenture
Climate Leadership Eleventh Hour | AccentureClimate Leadership Eleventh Hour | Accenture
Climate Leadership Eleventh Hour | Accenture
 

Dernier

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Dernier (20)

Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 

Are You Ready for PSD2?

  • 1. NEW THREATS FROM NEW REGULATIONS COULD IMPACT YOUR FIRM CYBER READY? ARE YOU FINANCIAL SERVICES TECHNOLOGY ADVISORY
  • 2. THE CHANGING CYBER ATTACK LANDSCAPE Fake Banking Apps Mobile Banking Malware Ransomware Mobile Trojans Classical Trojans Banking Malware AND NOW THERE’S PSD2… Cyber attacks are on the rise and becoming more sophisticated Copyright © 2017 Accenture. All rights reserved. 2
  • 3. A new regulatory requirement for banks operating within the European Union (EU). (revised/second payment service directive) WHAT IT IS Requires banks to open application programming interfaces (APIs) and allow all payment service providers (PSPs) to access customer information and initiate transactions. WHAT IT DOES Copyright © 2017 Accenture. All rights reserved. 3
  • 4. Increased convenience and ease-of-use for customers WHAT THIS MEANS TO YOUR FIRM Increased opportunity for “bad actors” to commit cyber attacks Copyright © 2017 Accenture. All rights reserved. 4 (revised/second payment service directive)
  • 5. POTENTIAL NEW RISKS FROM PSD2 Copyright © 2017 Accenture. All rights reserved. 5 The number of PSPs with criminal intent could rise, further exacerbating banking cyber security challenges and increasing costs. The number of fake multi-banking apps could grow exponentially, leading to customer identity theft and data breaches. MULTI- BANKING MALWARE MORE MALICIOUS PSPS
  • 6. POTENTIAL NEW RISKS FROM PSD2 Copyright © 2017 Accenture. All rights reserved. 6 Cyber attacks against PSPs could result in denials of service to banks, arising from hacked PSP servers. Failure by PSPs to appropriately protect their security certificates (e-Seals) could create opportunities for cyber criminals to steal them and access the bank’s APIs for criminal intent. STOLEN CERTIFICATE MISUSE ATTACKS AGAINST PSPS
  • 7. THINGS YOU SHOULD DO! Deeply embed security protection into APIs through the following measures: Do not allow your core banking system to be directly accessible through the internet THEN… 1 2 3Maintain a high logging level Restrict access to APIs through validated certificates (e-Seals) Copyright © 2017 Accenture. All rights reserved. 7
  • 8. FURTHER PROTECT YOUR BANK  Implementing screen scraping protections  Closely monitoring PSP activity to detect anomalies that point to fraud  Strengthening security authentication to discourage and curtail unauthorized payments  Establishing a high level of protection against Distributed Denial-of-Service (DDoS) attacks  Strongly controlling access to certificate- based APIs  Locking out unauthorized banking software Copyright © 2017 Accenture. All rights reserved. 8
  • 9. HOW ACCENTURE CAN HELP Establishing new open APIs as well as the security measures to protect them can be a big challenge. We help banks prepare for and respond to this challenge by:  Analyzing and assessing current applications and cyber defense capabilities  Conducting readiness checks against the new API requirements  Supporting the design of new open APIs  Developing new security and cyber defense capabilities and mechanisms  Integrating new cyber defense mechanisms and APIs into your existing infrastructure Copyright © 2017 Accenture. All rights reserved. 9
  • 10. OR… Accenture also offers A partially outsourced and cost-effective cyber defense solution tailored to your needs. AS A SERVICE Copyright © 2017 Accenture. All rights reserved. 10
  • 11. TO LEARN MORE, CONTACT HOLGER AHREND Financial Services Technology Advisory holger.ahrend@accenture.com CHRISTIAN TÖLKES Financial Services Technology Advisory christian.toelkes@accenture.com Copyright © 2017 Accenture. All rights reserved. 11
  • 12. ABOUT ACCENTURE Accenture is a leading global professional services company, providing a broad range of services and solutions in strategy, consulting, digital, technology and operations. Combining unmatched experience and specialized skills across more than 40 industries and all business functions—underpinned by the world’s largest delivery network—Accenture works at the intersection of business and technology to help clients improve their performance and create sustainable value for their stakeholders. With approximately 425,000 people serving clients in more than 120 countries, Accenture drives innovation to improve the way the world works and lives. Visit us at www.accenture.com DISCLAIMER This presentation is intended for general informational purposes only and does not take into account the reader’s specific circumstances, and may not reflect the most current developments. Accenture disclaims, to the fullest extent permitted by applicable law, any and all liability for the accuracy and completeness of the information in this presentation and for any acts or omissions made based on such information. Accenture does not provide legal, regulatory, audit, or tax advice. Readers are responsible for obtaining such advice from their own legal counsel or other licensed professionals. Copyright © 2017 Accenture All rights reserved. Accenture, its logo, and High Performance Delivered are trademarks of Accenture.