This higher reliance on the Web cannot come at the risk of exposing bank customers to violations of their privacy, identify theft, or other information security risks of online banking. So Bank of Alameda has put in place a secure infrastructure that can be managed by a small IT staff, one that leverages state of the art tools in automated remediation management to get the job done.
In 1998, when the big security push was the Year 2000 threat and the fear that computers would crawl to a halt at midnight on Dec. 31, 1999, federal bank regulators were looking closely to see that banks were ready.
“We thought we were OK because we had all brand-new equipment,” says Michael Roberts, chief information officer for the bank. “But they said that’s not enough, you had to test and then document everything.”
The bank did that, putting policies and procedures in place to meet the regulatory requirements. From that experience the bank concluded that a proactive security stance was the best approach.
“We decided to stay on the forefront of what was happening in security to protect the infrastructure that we had developed,” Roberts said.
Bank of Alameda has five branches that are all connected with a T-1 line. Backroom processing is outsourced to Fiserv, an information management provider for the financial services industry, with clients in 60 countries and 21,000 employees. The bank connects to Fiserv via a frame relay.
“A lot of what I do is vendor management,” says Roberts, who has one other person on his IT staff.
This was helpful, but, Robert says, “Once I knew what the vulnerability was, I had to go to each workstation to take care of it.” With branches in five locations, that was time-consuming.
So the bank searched and found the Hercules product from Citadel Security Software, which automates much of vulnerability remediation. Hercules is able to accept reports from Retina, and allow the security administrator to determine what action to take.
“We can pick and choose what to remediate,” says Roberts.
For example, if a software patch is required, the administrator can direct Hercules to go to the Microsoft site for the update, download it and apply it to each affected workstation.
“That’s a great time saver for us,” Roberts says.
The price of Hercules also was attractive when compared to other products priced from $20,000 to $30,000 that are doing similar work. Hercules is priced at $21 per device per year; the Bank of Alameda has 50 workstations and 11 servers.
The bank schedules remediation updates for times when users are not on their workstations, so there is little impact on productivity.
“We’ve been actively using it for six to eight months now, and everything is working great. It’s doing exactly what we want it to do,” Roberts says. The regulators are also pleased with the bank’s proactive stance toward information security. “It’s been a useful tool for us and would also be useful for other banks our size.”