Many PH banks have enhanced multi-level authentication vs cyberattacks – BSP

April 28, 2017 - 6:00 PM
The Bangko Sentral ng Pilipinas: FILE PHOTO FROM BWORLDONLINE

MANILA – A lot of Philippines-based banks have upgraded their multi-factor authentication (MFA) system to strengthen their capacity against cyberattacks, a ranking central bank official said.

Bangko Sentral ng Pilipinas (BSP) Deputy Governor Nestor Espenilla Jr. said on-site assessments are on-going to check banks’ MFA system, rules of which have been amended to prevent cyberattacks as banks migrate to the EMV technology.

He declined to give figures on BSP-supervised financial institutions (BSFIs) that are now compliant with MFA regulations, but said that “quite a number” of banks” have enhanced their systems “voluntarily as prudent business decision.”

MFA is required for transactions that are considered sensitive communications like enrollment in transactional electronic services or e-services, payments and fund transfers to third parties.

The central bank’s policy-making Monetary Board (MB) has amended regulations on MFAs and now require BSFIs to adopt the system for certain transactions starting September 30, 2017.

Espenilla told PNA that “by issuing a circular, we are now making that good practice a mandatory minimum standard.”

“This is a preemptive response to potential increase in card-not-present (CNP) fraud as cybercriminals try to look for other opportunities since card fraud has become harder due to EMV chip migration,” he said.

CNP fraud involves transactions done online such as airline ticket purchases, hotel bookings and utility bill payments.

EMV is a system developed by Europay, MasterCard and Visa. It uses a chip that is made part of the automated teller machine (ATM) card wherein which information about the ATM card holder is stored.

It has a more intricate technology and security features compared to the magnetic strip used currently in most ATM cards.

The BSP has mandated the full implementation of EMV-enabled ATMs by January 2017 but this has not been fully complied with.

Espenilla said the BSP is considering to set another deadline for this, citing that inability of banks to fully migrate to EMV technology is understandable given the volume of ATMs that have been issued to date.