It is suggested that commercial online banking customers perform risk assessments and controls evaluations periodically to help identify potential threats and to determine the strength of their controls. This can be done as follows:
• Identify possible risks in the online banking environment.
• Educate your employees on the risks.
• Create and maintain proper user account controls.
• Review all transactions.
• Install and maintain proper antivirus/security software on all systems/networks that access
online banking.
Alternative Risk Control Mechanisms
Customers may also implement additional control mechanisms to help alleviate their risk. Some
examples are as follows:
Passwords:
• Avoid using personal information.
• Create a unique password for online banking that you don’t use elsewhere.
• Do not use the password auto-save feature on your browser.
• Do not share your passwords or write them down.
• Change your password periodically.
• The Bank will NEVER ask for your password.
Personal Computers:
• Always sign out or log off.
• Update software frequently and keep systems current.
• Virus software, “definitions’ should be updated daily.
• Install and activate a personal firewall.
• Install and run most recent version of Antivirus software.
• Keep your operating system (OS) current.
• Activate the automatic update feature.
• Set your browser’s security level to the default setting or higher.
General Best Practices
• Keep your personal information private and secure.
• Check your account balance regularly.
• Do not access your account from a public location.
• If you suspect suspicious activity, take swift action.
• Be skeptical of e-mail messages, for example from someone unlikely to send an email such as
the IRS.
• Do not open the suspicious emails and do not click on the links, should this happen, stop work
and have a diagnostics performed immediately.
ID Theft Tips
• Shred receipts, statements, expired cards, and similar documents.
• Review statements promptly and carefully.
• Be positive of the identity of anyone before you divulge personal information, only if you initiate the contract.
• Periodically check your credit report.
Websites:
• Check your credit report.
• Pay using credit cards.
• Shred bank account, credit card, physician and other statements with personal information.
• Never click on suspicious links
• Only give sensitive information to websites using encryption, verified though the web address
“https:// (the “s” is for secure).
• Use social media wisely and don’t reveal too much.
Mobile Devices:
• Use passcodes.
• Avoid storing sensitive information.
• Keep software up-to-date.
• Install remote wipe if the device is lost or stolen it can be cleared off.
Using ATM’s safely:
• Protect your ATM card and PIN, if lost report as soon as possible.
• Choose a PIN different from your address, telephone #, and birthdate.
• Be aware of people and your surroundings.
• Put away your card and cash.
• Skimming – observe the card reader; if it appears damaged don’t use it.