In honor of National Cybersecurity Awareness Month, we interviewed our Chief Information Officer, Faizel Dakri, about cyberattacks and cybersecurity in an effort to help inform you on ways to keep your personal information safe and secure.
Faizel has worked in the information technology industry for over 30 years, and the banking industry for the last 7 years. We feel it is crucial to hear from someone with extensive experience, in both industries, for tips on cybersecurity in banking.
In this three-part series, we’ll take a closer look at cybersecurity from a few different angles. In part one of this series, Faizel will discuss the basics of cybersecurity. Part two will dive deeper to look at general tips and practices to protect yourself from cyberattacks. We will end the series with a discussion on what to do if you are a victim of a cyberattack.
Cybersecurity — An Introduction
With technology becoming an increasingly indispensable part of our daily routines, attackers have many more opportunities to wreak havoc. Mobile phones, tablets, PCs, and smartwatches have become integral to our lives, accompanying us everywhere we go, acting as gatekeepers to our private and public information. Unfortunately, as our dependency on these technologies increases, so does their attractiveness to cybercriminals. In this blog post, we’ll answer some basic cybersecurity questions and define the term, as well as discuss cybersecurity’s relevance in the current environment.

What is cybersecurity?
In broad terms, cybersecurity is everything we do to protect against unauthorized access to data. This can include installing anti-virus software, enabling firewalls, training against social engineering, properly disposing of confidential information, and more.
How significant is cybersecurity in the banking industry?
It would be an understatement to say that banks take cybersecurity seriously. Financial institutions are entrusted to protect not only money but also personal and confidential information. That trust is earned by the length banks take to protect that information. In addition to the common cybersecurity protections, banks typically go further by employing procedural and policy controls to help protect against unauthorized transactions. However, cybersecurity is no less significant at home than at work, or at the bank. We are all carriers of information that criminals find valuable, making all of us attractive targets.
What effect did the recent pandemic have on cybersecurity? Is there a particular time of year when cybersecurity attacks occur most often?
The ongoing global pandemic brought on by the coronavirus was just another event that criminals used to dupe unsuspecting people into clicking links, visiting websites, or opening attachments designed to steal sensitive information. With most of the world working from home, and no longer working within the confines of a secured corporate network, cybercriminals were able to increase their points of attack. We saw an uptick in the number of phishing emails being delivered, attacks of video teleconferencing, and attacks on home networks.
Although these are all challenges brought on by the recent pandemic, they are not necessarily anything new or unexpected. Cybercriminals are always looking for opportunities to attack, whether seasonal, political, shopping-related, or a natural disaster. You may see an increase in phishing or attacks during holiday months, as more people are doing their shopping online; a political event, such as an election, might provide an opportunity to send out phishing emails.
What are some common cybersecurity threats/scams that target people?
You’ve probably seen movies where a hacker actively tries to break into a computer system from halfway around the world. Although this can happen, there are many less sensational means that hackers and criminals use to access your information.
Probably the most common method is social engineering – gaining or taking advantage of someone’s trust to gain access. Typically, this is done through unwanted phishing emails or even text messages or voicemail. Whatever the manner, the goal is the same: to entice an unsuspecting person into doing something that an attacker can take advantage of. For example, sending an email with a link to some ransomware or spyware that will give attackers control of your computer; including a link to a bogus website that mimics an official website in the hopes that you might enter your password for the attacker to capture.
Social engineering scams are not limited to emails, however. Another social engineering scam involves posing as technical support in the hopes that you might grant an attacker access to your system to ‘diagnose’ your computer problems.
One of the most effective ways to thwart cyberattacks is by using multi-factor authentication (MFA); we’ll discuss this topic in a later post, keeping in mind that we are also seeing attacks against MFA systems. Again, these are social attacks where an attacker might call or send a text asking that you verify your login information by visiting a website; unbeknownst to the victim is the fact that the attacker is secretly hosting a fake website that looks like the real one and is waiting to capture your MFA code when you enter it.
Stay tuned for Part two of this Expert Series on cybersecurity.
BANKING MADE EASY
- Ⓒ Wallis Bank, All rights reserved.
-
Equal Housing Lender
- Privacy Notice Disclosures