Independent Banker - August 2017 - 108
Nuts & Bolts
Advisors, agrees that the perception of
smaller institutions having less-capable
controls makes them a target because
cyberthieves believe it will make for a
faster, easier attack and a more likely
payoff. " They see it as a pretty straight
path to the money, " he says.
For community banks especially,
whose most valuable currency is their
customer trust, the potential damage
of being publicly outed as the victim of
a ransomware attack could have more
than just a fi nancial impact, including
" a tarnished reputation, the downtime
of operations, and loss of data, " Leet
points out. " Particular to the banking
industry, falling victim to a ransomware
attack would very likely have a
substantial impact on their regulatory
risk and scrutiny, especially in a case
where the bank wasn't adequately
prepared to withstand or recover from
the attack. The reputational concerns
can also be much more impactful on
community banks. "
Indeed, the Kaspersky research
found that small and medium-size
businesses were hit the hardest last
year, with 42 percent falling prey to a
ransomware attack in 2016. Of those
enterprises, one in three paid the
ransom, but one in fi ve never got their
fi les back, even if they paid. Similarly,
a study by IBM Security found that
as many as seven out of 10 businesses
overall pay to get their data back.
What's the plan?
For community banks, the biggest
challenge remains resource and
budget limitations, according to Leet.
" Community banks don't always
have the luxury of investing large
sums into IT and cybersecurity
controls, " he says. " Moreover, they
may not be able to lure or afford
knowledgeable cybersecurity or IT
personnel who can bolster their level
of cyber-resiliency. "
Ransom payment does not
guarantee data recovery, either. In
April 2016, the FBI put out a release
strongly recommending that victims
not pay the ransomware perpetrators.
" Paying a ransom doesn't guarantee
an organization that it will get its data
back, " FBI cyber division assistant
director James Trainor said in the
release. " We've seen cases where
organizations never got a decryption
key after having paid the ransom.
Paying a ransom not only emboldens
current cybercriminals to target
more organizations, it also offers an
incentive for other criminals to get
involved in this type of illegal activity.
And fi nally, by paying a ransom, an
organization might inadvertently be
funding other illicit activity associated
with criminals. "
Victims' willingness to pay these
ransoms is also increasing attackers'
demands, according to recent
64%
The percentage of ransomware
victims who
paid ransom in 2016
research from Symantec Security
Response, which found that 64 percent
of ransomware victims paid up.
Reevaluate your focus
Joshua Jacobs, president and cofounder
of Sawyers & Jacobs LLC
of Collierville, Tenn., says the issue
often comes down to community
banks having " an insuffi cient or misdirected
focus on cybersecurity. " For
example, Jacobs sees many smaller
banks paying fi rms to remotely run
a simple network vulnerability scan,
considering this adequate cybersecurity
testing.
" In working with one community
bank client recently that had passed
its regulatory exams with fl ying
colors and had penetration tests performed
for years, it became apparent
that the bank had not backed up
some of its critical network data in
years, " he says. " Should this bank
have been hit with a ransomware
attack before we uncovered this
vulnerability, there would have been
disastrous consequences. "
108 ICBA IndependentBanker August 2017
Since innovation always
outpaces regulation by at least
two years, community banks must
preempt government instruction
on cybersecurity. Jimmy Sawyers,
chairman and cofounder of Sawyers
& Jacobs LLC, recommends
instituting adequate cybersecurity
testing and regular IT audits.
" Having the right controls and
security measures in place is critical, "
he says, " but those controls and security
measures must be tested to verify
that they are working as designed. "
McGowan advises looking to the
FS-ISAC (Financial Services Information
Sharing and Analysis Center),
a global forum for sharing cyberintelligence
across banks, state and local
government agencies, law enforcement
and other trusted agencies. The
ISAC system recently implemented
a Critical Infrastructure Notifi cation
System (CINS) to allow these groups
to send security alerts to members
around the globe.
" Banks need to get used to the idea
of sharing cyber-risk information, "
McGowan says. " There is no competitive
advantage to the bank next
door being attacked. "
Another important fi rst step is
simply to recognize that a ransomware
attack can happen to anyone.
Bjorklund encourages community
banks to be " realistic about the likelihood
of recovering data, " especially if
they are unwilling to pay the ransom.
" I don't see a lot of organizations
paying because you're just feeding
the beast, enabling the criminals, " he
says. Instead, he recommends banks
employ a defense-in-depth strategy,
using multiple layers of security to
protect their most vital information,
as well as frequent data backups and
employee training to spot potential
phishing scams.
" Cybersecurity is a neverending
battle, " Sawyers says, " but
an educated, engaged and aware
workforce is one of the best ways to
mitigate risk. "
Karen Epper Hoffman is a writer in
Washington state.
Independent Banker - August 2017
Table of Contents for the Digital Edition of Independent Banker - August 2017
Table of Contents
Independent Banker - August 2017 - Cover1
Independent Banker - August 2017 - Cover2
Independent Banker - August 2017 - Table of Contents
Independent Banker - August 2017 - 2
Independent Banker - August 2017 - 3
Independent Banker - August 2017 - 4
Independent Banker - August 2017 - 5
Independent Banker - August 2017 - 6
Independent Banker - August 2017 - 7
Independent Banker - August 2017 - 8
Independent Banker - August 2017 - 9
Independent Banker - August 2017 - 10
Independent Banker - August 2017 - 11
Independent Banker - August 2017 - 12
Independent Banker - August 2017 - 13
Independent Banker - August 2017 - 14
Independent Banker - August 2017 - 15
Independent Banker - August 2017 - 16
Independent Banker - August 2017 - 17
Independent Banker - August 2017 - 18
Independent Banker - August 2017 - 19
Independent Banker - August 2017 - 20
Independent Banker - August 2017 - 21
Independent Banker - August 2017 - 22
Independent Banker - August 2017 - 23
Independent Banker - August 2017 - 24
Independent Banker - August 2017 - 25
Independent Banker - August 2017 - 26
Independent Banker - August 2017 - 27
Independent Banker - August 2017 - 28
Independent Banker - August 2017 - 29
Independent Banker - August 2017 - 30
Independent Banker - August 2017 - 31
Independent Banker - August 2017 - 32
Independent Banker - August 2017 - 33
Independent Banker - August 2017 - 34
Independent Banker - August 2017 - 35
Independent Banker - August 2017 - 36
Independent Banker - August 2017 - 37
Independent Banker - August 2017 - 38
Independent Banker - August 2017 - 39
Independent Banker - August 2017 - 40
Independent Banker - August 2017 - 41
Independent Banker - August 2017 - 42
Independent Banker - August 2017 - 43
Independent Banker - August 2017 - 44
Independent Banker - August 2017 - 45
Independent Banker - August 2017 - 46
Independent Banker - August 2017 - 47
Independent Banker - August 2017 - 48
Independent Banker - August 2017 - 49
Independent Banker - August 2017 - 50
Independent Banker - August 2017 - 51
Independent Banker - August 2017 - 52
Independent Banker - August 2017 - 53
Independent Banker - August 2017 - 54
Independent Banker - August 2017 - 55
Independent Banker - August 2017 - 56
Independent Banker - August 2017 - 57
Independent Banker - August 2017 - 58
Independent Banker - August 2017 - 59
Independent Banker - August 2017 - 60
Independent Banker - August 2017 - 61
Independent Banker - August 2017 - 62
Independent Banker - August 2017 - 63
Independent Banker - August 2017 - 64
Independent Banker - August 2017 - 65
Independent Banker - August 2017 - 66
Independent Banker - August 2017 - 67
Independent Banker - August 2017 - 68
Independent Banker - August 2017 - 69
Independent Banker - August 2017 - 70
Independent Banker - August 2017 - 71
Independent Banker - August 2017 - 72
Independent Banker - August 2017 - 73
Independent Banker - August 2017 - 74
Independent Banker - August 2017 - 75
Independent Banker - August 2017 - 76
Independent Banker - August 2017 - 77
Independent Banker - August 2017 - 78
Independent Banker - August 2017 - 79
Independent Banker - August 2017 - 80
Independent Banker - August 2017 - 81
Independent Banker - August 2017 - 82
Independent Banker - August 2017 - 83
Independent Banker - August 2017 - 84
Independent Banker - August 2017 - 85
Independent Banker - August 2017 - 86
Independent Banker - August 2017 - 87
Independent Banker - August 2017 - 88
Independent Banker - August 2017 - 89
Independent Banker - August 2017 - 90
Independent Banker - August 2017 - 91
Independent Banker - August 2017 - 92
Independent Banker - August 2017 - 93
Independent Banker - August 2017 - 94
Independent Banker - August 2017 - 95
Independent Banker - August 2017 - 96
Independent Banker - August 2017 - 97
Independent Banker - August 2017 - 98
Independent Banker - August 2017 - 99
Independent Banker - August 2017 - 100
Independent Banker - August 2017 - 101
Independent Banker - August 2017 - 102
Independent Banker - August 2017 - 103
Independent Banker - August 2017 - 104
Independent Banker - August 2017 - 105
Independent Banker - August 2017 - 106
Independent Banker - August 2017 - 107
Independent Banker - August 2017 - 108
Independent Banker - August 2017 - 109
Independent Banker - August 2017 - 110
Independent Banker - August 2017 - 111
Independent Banker - August 2017 - 112
Independent Banker - August 2017 - Cover3
Independent Banker - August 2017 - Cover4
https://www.nxtbook.com/mspc/independentbanker/january2025
https://www.nxtbook.com/mspc/independentbanker/december2024
https://www.nxtbook.com/mspc/independentbanker/november2024
https://www.nxtbook.com/mspc/independentbanker/october2024
https://www.nxtbook.com/mspc/independentbanker/september2024
https://www.nxtbook.com/mspc/independentbanker/august2024
https://www.nxtbook.com/mspc/independentbanker/july2024
https://www.nxtbook.com/mspc/independentbanker/june2024
https://www.nxtbook.com/mspc/independentbanker/may2024
https://www.nxtbook.com/mspc/independentbanker/april2024
https://www.nxtbook.com/mspc/independentbanker/march2024
https://www.nxtbook.com/mspc/independentbanker/february2024
https://www.nxtbook.com/mspc/independentbanker/january2024
https://www.nxtbook.com/mspc/independentbanker/december2023
https://www.nxtbook.com/mspc/independentbanker/november2023
https://www.nxtbook.com/mspc/independentbanker/october2023
https://www.nxtbook.com/mspc/independentbanker/september2023
https://www.nxtbook.com/mspc/independentbanker/august2023
https://www.nxtbook.com/mspc/independentbanker/july2023
https://www.nxtbook.com/mspc/independentbanker/june2023
https://www.nxtbook.com/mspc/independentbanker/may2023
https://www.nxtbook.com/mspc/independentbanker/april2023
https://www.nxtbook.com/mspc/independentbanker/march2023
https://www.nxtbook.com/mspc/independentbanker/february2023
https://www.nxtbook.com/mspc/independentbanker/january2023
https://www.nxtbook.com/mspc/independentbanker/december2022
https://www.nxtbook.com/mspc/independentbanker/november2022
https://www.nxtbook.com/mspc/independentbanker/october2022
https://www.nxtbook.com/mspc/independentbanker/september2022
https://www.nxtbook.com/mspc/independentbanker/august2022
https://www.nxtbook.com/mspc/independentbanker/july2022
https://www.nxtbook.com/mspc/independentbanker/june2022
https://www.nxtbook.com/mspc/independentbanker/may2022
https://www.nxtbook.com/mspc/independentbanker/april2022
https://www.nxtbook.com/mspc/independentbanker/march2022
https://www.nxtbook.com/mspc/independentbanker/february2022
https://www.nxtbook.com/mspc/independentbanker/january2022
https://www.nxtbook.com/mspc/independentbanker/december2021
https://www.nxtbook.com/mspc/independentbanker/november2021
https://www.nxtbook.com/mspc/independentbanker/october2021
https://www.nxtbook.com/mspc/independentbanker/september2021
https://www.nxtbook.com/mspc/independentbanker/august2021
https://www.nxtbook.com/mspc/independentbanker/july2021
https://www.nxtbook.com/mspc/independentbanker/june2021
https://www.nxtbook.com/mspc/independentbanker/may2021
https://www.nxtbook.com/mspc/independentbanker/april2021
https://www.nxtbook.com/mspc/independentbanker/march2021
https://www.nxtbook.com/mspc/independentbanker/february2021
https://www.nxtbook.com/mspc/independentbanker/january2021
https://www.nxtbook.com/mspc/independentbanker/december2020
https://www.nxtbook.com/mspc/independentbanker/november2020
https://www.nxtbook.com/mspc/independentbanker/october2020
https://www.nxtbook.com/mspc/independentbanker/september2020
https://www.nxtbook.com/mspc/independentbanker/august2020
https://www.nxtbook.com/mspc/independentbanker/july2020
https://www.nxtbook.com/mspc/independentbanker/june2020
https://www.nxtbook.com/mspc/independentbanker/may2020
https://www.nxtbook.com/mspc/independentbanker/april2020
https://www.nxtbook.com/mspc/independentbanker/march2020
https://www.nxtbook.com/mspc/independentbanker/february2020
https://www.nxtbook.com/mspc/independentbanker/january2020
https://www.nxtbook.com/mspc/independentbanker/december2019
https://www.nxtbook.com/mspc/independentbanker/november2019
https://www.nxtbook.com/mspc/independentbanker/october2019
https://www.nxtbook.com/mspc/independentbanker/september2019
https://www.nxtbook.com/mspc/independentbanker/august2019
https://www.nxtbook.com/mspc/independentbanker/july2019
https://www.nxtbook.com/mspc/independentbanker/june2019
https://www.nxtbook.com/mspc/independentbanker/may2019
https://www.nxtbook.com/mspc/independentbanker/april2019
https://www.nxtbook.com/mspc/independentbanker/march2019
https://www.nxtbook.com/mspc/independentbanker/february2019
https://www.nxtbook.com/mspc/independentbanker/january2019
https://www.nxtbook.com/mspc/independentbanker/december2018
https://www.nxtbook.com/mspc/independentbanker/november2018
https://www.nxtbook.com/mspc/independentbanker/october2018
https://www.nxtbook.com/mspc/independentbanker/september2018
https://www.nxtbook.com/mspc/independentbanker/august2018
https://www.nxtbook.com/mspc/independentbanker/july2018
https://www.nxtbook.com/mspc/independentbanker/june2018
https://www.nxtbook.com/mspc/independentbanker/may2018
https://www.nxtbook.com/mspc/independentbanker/april2018
https://www.nxtbook.com/mspc/independentbanker/march2018
https://www.nxtbook.com/mspc/independentbanker/february2018
https://www.nxtbook.com/mspc/independentbanker/january2018
https://www.nxtbook.com/mspc/independentbanker/december2017
https://www.nxtbook.com/mspc/independentbanker/november2017
https://www.nxtbook.com/mspc/independentbanker/october2017
https://www.nxtbook.com/mspc/independentbanker/september2017
https://www.nxtbook.com/mspc/independentbanker/august2017
https://www.nxtbook.com/mspc/independentbanker/july2017
https://www.nxtbook.com/mspc/independentbanker/june2017
https://www.nxtbook.com/mspc/independentbanker/may2017
https://www.nxtbook.com/mspc/independentbanker/april2017
https://www.nxtbookmedia.com