World View

Differences You Can Bank On

Observations on the differences between US and European banks

By Paul Raines

March 01, 2007CSO

I may be living in Europe now, but I still keep a practiced eye on the news coming out of the States.

Last fall, between Britney's divorce and the midterm elections, I couldn't help but notice a little newsbyte that several American online trading companies had been hacked. Yikes! Luckily, when I logged on to my accounts held with U.S. financial institutions, I found that my balances had not mysteriously vanished down a cyberdrain, but the episode did give me pause. The fact is, I've found stark differences in the practices at my American and European banks, and all evidence points to Europe being much more security-conscious.

I first noticed this with the different password requirements by American and British subsidiaries of the same bank. When I lived in the United States, this bank—which shall remain unnamed—allowed me to establish any eight-character password for online banking. If I wanted, I could use my cat's nickname as my password.

However, when I later did business with the bank's subsidiary in the United Kingdom, the password was chosen for me and sent to my home address. This password was also eight characters long, but it was an incomprehensible amalgam of special characters, numbers and letters in both upper- and lowercase.

The result, of course, is that I knew I would never remember it. I tore out the password and tucked it inside my wallet. Yes, Mother, I know I'm not supposed to do that. But let's be honest. If given the choice between doing this and forgetting the difficult password, calling the help desk, being put on hold for 30 minutes, and then requesting a new password only to be told that you'll receive it in five working days, which would you choose? Besides, isn't a strong password tucked in my wallet better than the password "kitty"?

Anyway, I happened to be friends with the global head of information security at this bank, so I rang him up to ask about the difference. He explained that the bank's American and British subsidiaries are run under the philosophy of "each tub on its own bottom." They made and implemented their own security models for online banking based upon the "cultural and regulatory differences" in the regions.

It seems the American subsidiary is more attuned to customer friendliness, while the U.K. subsidiary is more attuned to security.

Another big difference is in the use of stored-value cards. Here, I bank with an internationally known Dutch bank. When I first set up my account, I was given a smart card that functions the same as a debit card in the States but with added functionality: A chip on the smart card can be used to store electronic money. The idea is that you can transfer funds from your checking account to the chip, then use that money for small transactions such as paying for parking, purchasing train tickets and making incidental purchases at stores. The advantage from a security standpoint is that the parking meter, ticket machine or what have you doesn't have to authenticate you back to the bank; it's enough that you're holding the card. The disadvantage is that if you lose the card, you also lose the stored money—but I solve that by not keeping more than 20 euros on the card.

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

IS/IT Project Mgt. Credentials From Villanova - 100% Online

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Data Protection: Challenges for the Traveling User

Key strategies for C-level executives and security staff

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage

Configuration Assessment: Choosing the Right Solution

Revolutionizing Endpoint Security with a Single Agent

Envision Identity-Based Access Control for the Datacenter

Rolling the dice with your security? Take the Self-Assessment Test now

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

Digital Identity Protection and Data Security Get Personal

The Case for Business Software Assurance ~ Securing Your Applications

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era