- 23/02/2017
- Category: Commentaries
In the last two decades, the phenomenon of internet banking in Indonesia happens to be under scrutiny by many. This is largely driven by the fact that majority of banking institutions have provided customers with the ease of transaction via e-banking. E-banking innovations are materialized into several forms, namely mobile banking (including SMS banking service and application-based banking service) and Internet banking. The penetration of e-banking service has permeated to our daily activities, especially from our smartphones and computers. This innovation has helped the customer to acquire banking services and facilities in the easiest way possible. It has never been so easy that it could be accessed anywhere, anytime and by everyone.
The security and easiness of services for customers have always been prioritized by banks. Doing so enables banks to gain trust from their customers, such valuable assets for them. Maintaining trusts from customers can be acquired by banks when they also consider certain precautions. These things include:
1. Confidentially, where banks have to guarantee the privacy of customers’ personal information.
2. Integrity, where banks should not change customers’ identities before being approved by customers.
3. Authentication, where banks should be equipped with programs that ensure the security of customers’ data on their servers.
4. Non-repudiation, where customers’ consent/avowal to the transaction that has been made is not able to be changed by the banks.
5. Availability, where banks should ensure the complete service for their customers.
These precautions are so important in ensuring the security of all services provided by banks. Not ensuring this will make banks fragile to a security breach, which is very undesirable. Security attacks and crimes targeted to banks will also plummet the trust of customers, even in the worldwide scale. Banks would surely experience deprivation, in both material and non-material elements. More importantly, cyberattacks to banks may result in identity thefts that will implicate to greater crimes possibly committed by cybercriminals.
Crime in the world of banking can occur in every direction. There two kinds of attackers, active and passive attackers. Active attackers may breach banks’ security system and steal or modify any data obtained, including customers’ personal identity and private data. The security breach conducted by active attackers is highly possible to happen when customers access their accounts through mobile/internet banking in a public/shared network. Passive attackers, on the other hand, monitor the transaction conducted by customers in a specially designed system that looks friendly and trusted by customers. This can be seen from some fake sites which ask for customers’ bank information, like account numbers, ID, and passwords. These sites are sometimes indistinguishable from the real ones. Another example is when customers do any online transactions that ‘force’ them to fill in personal credit card/bank information.
Despite efforts from banks to safeguard their data, there are still several emphasis banks need to do, especially banks’ preventive approaches and customers’ awareness. The first thing banks can consider is improving their operational procedures, by checking it regularly like the early warning system mechanism. Secondly, banks can enforce safer account management system, not relying only on user ID and passwords. Thirdly, to specifically address issues of a security breach in a public/shared network, banks can implement the method of time out session every ten minutes of an unopen window. Above all, implementation of internet banking architecture with firewall protection is also needed to ensure the security of banks’ data further. Especially the ones related to customers’ personal and private data.
Amidst the strong winds on security breach and cybercrimes, collaborative and understanding approaches by both banks and customers are highly needed. By the time banks capacitate themselves further regarding security system and data management, customers also need to be aware of their behaviors in accessing accounts using risky channels, especially e-banking facilities. Customers can start safeguarding their accounts by, for example, frequently changing their passwords, as well as avoiding accessing accounts via e-banking facilities in a public/shared network. The most important thing to underline is that the innovation of e-banking has surely helped both banks and customers in bank services, and the mindset of benefits outweighing risks shall be there in the first place. Everything is there for the benefit of all.
References
Acharya, R.N., Kagan, A. and Rao Lingam, S. (2008). Online banking applications and community bank performance. International Journal of Bank Marketing, 26(6), page 418–439.
UK Essays. (2013). The History And Background Of Internet Banking Marketing Essay. [online]. Available at: https://www.ukessays.com/essays/marketing/the-history-and-background-of-internet-banking-marketing-essay.php?cref=1. [Accessed 21 February 2017].
Wijaya, Bambang Andi. (2012). Sistem Keamaanan Banking. [online]. Available at: http://andi-wb.blogspot.co.id/2010/02/sistem-keamanan-perbankan.html. [Accessed 21 February 2017]
Yap, K.B., Wong, D.H., Loh, C., and Bak, R. (2010). Offline and online banking – where to draw the line when building trust in e‐banking?. International Journal of Bank Marketing, 28(1), page 27–46.
Picture: pexels.com