Banking Business Review
Security
Anonymous User | Login

Majority Of Private Banking Websites Potentially Vulnerable To Attacks: MyPrivateBanking

Published: 04-Mar-2010

MyPrivateBanking, an independent platform for information and networking for wealthy private clients across the world, has released a new survey report on the protection of the personal data of private banks and wealth managers on their public websites.

The research surveyed 195 websites in the 17 important banking markets and found that 61% of the banks do not offer secure web messaging. Almost as high, at 59%, is the proportion that do not give privacy warnings to users of their website about sending unprotected e-mails to recipients at the bank.

Overall the research showed that online communication is of increasing importance to private banks and wealth managers and offered by the vast majority of the providers. Of the surveyed banks only 10% offer telephone numbers as the sole means of contact, while 35% offer e-mail contacts, 31.3% have a contact form and 23% offer both means of online contact.

For assessing the level of privacy, MyPrivateBanking research looked at the two major means to transmit messages via the public (not password protected) website of a bank. First, it was checked whether the bank offers encrypted messaging via the secure HTTPS (Hyper Text Transfer Protocol Secure). Without HTTPS, a message that is transmitted via a website can be easily intercepted.

Second, whether in the case of contact e-mail addresses, published on the website, the bank explicitly warns their website users about the risks of e-mail transmission. This could be done in an explicit privacy policy on the website or directly, on the contact page of the bank.

In total 54.4% of banks offered a web-based contact form for users of their public website. However, looking on the websites of these banks, research has noticed that more than 60% did not use the secure HTTPS protocol. Even more private bank websites (58.5%) offered one or multiple e-mail addresses to send messages to recipients at the bank. Of these, only a minority of 41.2% made a statement to users about the risk involved in sending simple e-mails. The majority of banks (58.8%) did not give any warning to website users not even in the privacy policy on their website.

MyPrivateBanking Research recommends that more than ever banks need to focus very carefully on their online privacy reputation as this is an important asset for building trusting client relationships. Consequently private banks and wealth managers should make privacy protection on the web a high priority item for the management and offer HTTPS-protected contact forms and explicit data security warnings on all relevant pages of the website.

Steffen Binder, research director of MyPrivateBanking, said: “Thousands of private banking clients have suffered recently from the disclosure of sensitive personal data. Many clients have become concerned about confidentiality and privacy protection, making it all the more surprising that in reality the majority of private banking and wealth management websites are insecure and potentially subject to eavesdropping attacks that can let intruders gain access to sensitive information.”

Christian Nolterieke, managing director of MyPrivateBanking, said: “Users have to be aware that the internet is an un-policed open space and avoid sending information via regular e-mail or through web contact forms, except those that are HTTPS protected. By explicitly pointing out the security features of their websites banks will make it easier for users to develop trust and lower the hurdle for online contact.”

Mail sent successfully

Tell your friend about this article


Please enter a valid email address

Please enter your name

Please enter the mail body


Your Name: *
Your Email: *
Friend's Email: *
Email Body: *
 

Suppliers To This Sector

Browse A-Z

# A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Cryptomathic

Security Solutions for Businesses ...

Agnitio

Voice Biometrics for Enterprise Security ...

VASCO

Strong Authentication and e-Signature, Specialising in Online Accounts, Identities and Transactions ...

Crossing-Tech™

Banking Application Integration and Urbanisation ...

Todos AB

Security for eBanking and eCommerce ...

All Media Banking

Solution Development ...

White Papers

Browse A-Z

# A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

The Benefits Of Automation For The Front Office

The increase in ultra high net worth families around the world — especially in the emergin ...

Performance Attribution: Identifying the Sources of Investment Performance

Knowing what makes your investment decisions successful (or not so successful) is a powerf ...

A Best Practice Guide to Family Office Technology

The increase in ultra high net worth families around the world — especially in the emergin ...

The Antidote to Information Overload

In recent years the industry has struggled with a massive influx of investment information ...

Tower Group Report: Global Exchange Consolidation

This 12-page TowerGroup report analyses the rapidly consolidating exchange market, examine ...

How Financial Firms Can Improve Business Integration Capabilities and Increase Straight-Through Processing Efficiency

This paper identifies some of the more common issues and challenges such as security and t ...

Related Companies

No items to display

Suppliers Product News

VASCO Data Security and MoadBus Partnering to Deliver Digital Signature for Mobile Banking and Mobile Cash Solutions

VASCO Data Security International Inc (Nasdaq: VDSI), a leading software security company specialising in authentication products, and MoadBus, a software products and services provider to the international financial sector, have announced they have joined forces to deliver digital signature on mobile banking and mobile cash solutions to joint customers.

KBC Securities Secures Bolero Customers with VASCO's DIGIPASS 270

VASCO Data Security International Inc (Nasdaq: VDSI), a leading software security company specialising in authentication, and KBC Securities, the largest brokerage company in Belgium, have announced that KBC Securities is using DIGIPASS® 270 to secure its Bolero customers. The introduction of DIGIPASS for Bolero customers coincides with the launch of the new Bolero website.

VASCO Data Security and MoadBus are Partnering to Deliver Digital Signature for Mobile Banking and Mobile Cash Solutions

VASCO Data Security International Inc (Nasdaq: VDSI), a leading software security company specialising in authentication products, and MoadBus, a software products and services provider to the international financial sector, have announces that they have joined forces to deliver digital signature on mobile banking and mobile cash solutions to joint customers.

HSBC Bank Brazil Provides Full Integration Between Electronic Channels with m-Banking and VASCO DIGIPASS for Mobile

VASCO Data Security International Inc (Nasdaq: VDSI), a leading software security company specialising in authentication products, enabled HSBC Bank Brazil to roll out fully integrated m-banking services for its retail customer base thanks to VASCO's DIGIPASS for Mobile.

Banking Application Landscape Evolution

How to succeed by making the most out of the opportunities while mitigating risks and delivering quick wins to the business?

Todos Brings Trust and Usability to Mobile Authentication

Transaction verification goes mobile as Todos AB updates onMobile for Java MIDP mobiles, launches onMobile for iPhone™ and iPod Touch™ and announces application for the Android platform.

Free Newsletter Sign-up

Sign up, and we will send you a free Hang Seng Bank Limited - Financial and Strategic Analysis Review from GlobalData worth $750

Please enter a valid email address