Business Signatures Rapidly Deployed Fraud Monitoring Alternative to Multi-Factor Authentication Enables Financial Firms to Achieve FFIEC Compliance
| Industry Experts Agree "Anomaly Detection With Real-Time Customer Notifications" Is Consistent With FFIEC Guidance on Layered Security Approach |
Launching an easily deployed, no web application change approach to the problem of protecting risky transactions in online financial services, Business Signatures Corporation today announced that Anomaly Detection with Real-Time Customer Notifications solution, based on its Real-Time e-Fraud Detector(TM) and e-FraudMart(TM) products, has been deemed consistent with FFIEC guidance. This solution, also available through IBM Business Consulting Services, does not require an enrollment process and an "out of wallet question/answer challenge" authentication approach, which requires fundamental change in the online consumer experience resulting in potentially huge customer service related costs.
Recent coverage in Baseline Magazine points to some of the challenges and costs associated with alternative multi-factor authentication solutions. The full article titled, "Bank of America Seeks Anti-Fraud Anodyne," can be found at http://www.baselinemag.com/print_article2/0,1217,a=178262,00.asp.
Large and mid-size financial institutions concerned with overall costs and speed of FFIEC-related initiatives should confirm with their regulators that this approach will be sufficient to pass their FFIEC compliance-related audits in early 2007. The ease of installing this kind of solution "could make it more appealing to customers than harder-to-install products from vendors, such as RSA Security Inc.," according to an American Banker article published on June 15, 2006 titled, "Security Vendors Promote Fast Installation Capability."
The Anomaly Detection with Real-Time Customer Notifications solution could save financial institutions millions of dollars in annual customer service costs. It has the following important characteristics of a proven approach used in the credit card industry:
-- Identifies anomalies in online account access or behavior patterns in real time, based on examining Web traffic streams, sometimes referred to as server streams or server logs
-- Notifies the customer in real time using an outbound call or messaging, giving the customer the opportunity to approve or deny the suspicious pattern through an automated system
-- Provides offline reversal or suspension of suspicious transactions and can also support risk based authentication
-- Works with no web application change -- no web server plug-ins and no application server or database integration is required
"The Business Signatures anomaly detection approach enables banks to add security without the customer noticing an inhibiting change in their service; as opposed to, for example, adding a challenge question before transactions are allowed," said Peter Relan, chairman and CEO of Business Signatures. "Banks can also take additional precautions by adopting both an anomaly and authentication approach to ensure that even if consumers don't enroll in authentication, the financial institution is covered from a compliance and security perspective."
Financial Institutions choosing Anomaly Detection with Real-Time Customer Notifications will avoid the following problems encountered with basic challenge question-based authentication solutions:
-- Forcing customers to go through enrollment associated with shared secrets and challenge questions and answers
-- Dealing with the inevitable phishing attacks focused on stealing these shared secrets
-- Massive increase in call volume at customer service centers as customers look for help in enrollment and inadvertently type in incorrect answers to challenge questions
-- Large costs and risk associated with IT release cycles to integrate complex authentication software
"Indications from regulators are that the deadline of December 2006 is not a flexible one," Relan added. "However, we have received indication that our rapidly deployed, no web application change approach falls into the category of 'layered security or other controls' in the FFIEC guidance and is consistent with fulfilling this requirement."
A Business Signatures white paper, co-authored by a banking security expert and reviewed by analysts and experts in the context of FFIEC compliance, describes the value of the new anomaly detection approach. Please see the white paper, "Implications of FFIEC Guidance and Proposed Solutions," at http://www.businesssignatures.com/docs/ADCN.pdf.
Anomaly Detection with Real-Time Customer Notifications solution is based on the company's zero integration Real-Time e-Fraud Detector product, and is enhanced with real-time customer notifications using an approach proven in the credit card industry. Features include:
-- Simple GUI-based, customizable, e-Fraud Rule Library for detecting suspicious activity or unusual access to a customer account in real time, including unusual geo-location, behavior and transactional patterns
-- Multiple choices for real-time customer notifications, including e-mail, SMS, or automated outbound calling to inform a customer when suspicious activity or access is noticed
Pricing and Availability
Anomaly Detection with Real-Time Customer Notifications is available now. Pricing for the solution is offered according to Business Signatures' ground-breaking "no per user" fee annual subscription price. For more details, interested parties can call Business Signatures at 406-982-3432.
End-End Compliance and e-Fraud Prevention Solution
Deployed by top U.S. financial institutions, the Business Signatures e-Fraud Prevention Solution is an integrated product suite that provides the most advanced defense against online fraud available today. Businesses Signatures products are easy to deploy. They require no changes to Web application logic or complex data extraction from transactional systems:
-- Business Signatures Introduces Two Fast-Track Turnkey Solutions for FFIEC Compliance in Online Financial Services. (http://www.businesssignatures.com/company/press_releases/BusinessSignatures060706.htm) (Due to its length, this URL may need to be copied/pasted into your Internet browser's address field. Remove the extra space if one exists.)
-- Business Signatures Mutual 2 Factor Authenticator(TM) (M2FA) provides FFIEC-compliant front-door protection for websites. Priced on a low, annual flat fee basis. (http://businesssignatures.com/company/press_releases/BusinessSignatures013106.htm) (Due to its length, this URL may need to be copied/pasted into your Internet browser's address field. Remove the extra space if one exists.)
-- Business Signatures e-FraudMart(TM) is the first real-time fraud database for detecting and preempting fraud. Priced on an annual subscription fee. (http://www.businesssignatures.com/company/press_releases/BusinessSignatures032906.htm) (Due to its length, this URL may need to be copied/pasted into your Internet browser's address field. Remove the extra space if one exists.)
-- Business Signatures Real-Time e-Fraud Detector(TM) (RTFD) enables the industry's first capability of real-time monitoring and intervention of in-session fraudulent activity. Priced on an annual subscription basis. (http://businesssignatures.com/company/press_releases/BusinessSignatures102405.htm) (Due to its length, this URL may need to be copied/pasted into your Internet browser's address field. Remove the extra space if one exists.)
The integrated solution leverages the powerful Business Signatures data streams Intent Processor(TM) that provides real-time analysis of "fraudulent intent". The Business Signatures e-Fraud Prevention Solution is the subject of several patent applications for its unique depth of analysis.
Related News
"IBM Business Consulting Services Allies with Business Signatures to Offer Financial Industry Risk and Compliance Solutions" (http://businesssignatures.com/company/press_releases/BusinessSignatures020806.htm) (Due to its length, this URL may need to be copied/pasted into your Internet browser's address field. Remove the extra space if one exists.)
"Top US Financial Institutions Select Business Signatures Breakthrough Solution for Real Time E-Fraud Prevention" (http://businesssignatures.com/company/press_releases/BusinessSignatures012406.htm) (Due to its length, this URL may need to be copied/pasted into your Internet browser's address field. Remove the extra space if one exists.)
About Business Signatures
Business Signatures Corporation offers the e-Fraud Prevention Solution incorporating breakthrough "stream processing" technology to protect online customers and prevent fraud. Business Signatures products are the subjects of several patent applications for their real-time analytics-based approach to fighting fraud. Headquartered in Redwood Shores, California, Business Signatures is a private company. For more information, visit www.businesssignatures.com or call 650-622-3030.
Business Signatures Mutual 2 Factor Authenticator, Business Signatures Real-Time e-Fraud Detector, e-FraudMart and Intent Processor are trademarks of Business Signatures Corporation. All other products and brand names are trademarks of their respective owners.
