Sign in

Cooperative banks in Pune upgrade cyber security to meet RBI’s March 31 deadline

Banks have begun complying with guidelines laid down by the Reserve Bank of India to implement cyber security measures by March 31

Updated on: Feb 22, 2020, 16:15:59 IST
Hindustan Times, Pune | By
Share
Share via
  • facebook
  • twitter
  • linkedin
  • whatsapp
Copy link
  • copy link

Cooperative banks in Pune have started complying with Reserve Bank of India (RBI) guidelines to initiate cyber-security measures before the March 31 deadline, Vidyadhar Anaskar, president, Maharashtra Urban Cooperative Bank Federation has said.

In view of the Rs. 94 crore online theft at Cosmos bank two years ago, the Reserve Bank of India (RBI), on December 31, 2019, had issued guidelines to all urban cooperative banks to strengthen their cyber security. (Getty Images/iStockphoto)
In view of the Rs. 94 crore online theft at Cosmos bank two years ago, the Reserve Bank of India (RBI), on December 31, 2019, had issued guidelines to all urban cooperative banks to strengthen their cyber security. (Getty Images/iStockphoto)

In view of the Rs. 94 crore online theft at Cosmos bank two years ago, the Reserve Bank of India (RBI), on December 31, 2019, had issued guidelines to all urban cooperative banks to strengthen their cyber security.

This directive made it mandatory for the cooperative sector banks to comply with the guidelines ending March 31.

Anaskar said, “Most banks in Maharashtra are responding positively to the directives issued by the RBI. Our federation is also helping these banks to enhance their cyber security.”

Accordingly, the cyber crime department of the Pune police has also asked the banks to further boost their critical cyber security infrastructure and comply with the directions.

Any delay in compliance of the directives will result in strict action by the RBI and concerned agencies as the directives have been issued to protect the deposits of the bank customers, said cyber crime officials,

The RBI has suggested a four-step security structure to be put in place by the banks. The first being creation of basic cyber security infrastructure; second, the banks must take extra precaution and care of the account holders using net banking transactions.Third, there should be strict security arrangement for those banks engaged in high internet usage and ATM switch facilities and the fourth being those banks engaged in sharing data centres with other banks, must concentrate on strengthening their security.

The RBI does not give permission to conduct internet banking to those banks whose turnover is less than Rs 25 crore.

Police inspector Jayram Paigude of the cyber crime police station said, “The banks must immediately update their security so that online predators don’t target and siphon off the money. It is seen that cooperative banks don’t pay attention towards cyber security and hence, this is a very vital component of their security which must be addressed at the earliest. We have also issued directions to them. The cooperative banks must immediately comply with the RBI order.”

Preventing a hack attack

December 31, 2019: Directives issued by RBI

March 31, 2020: Deadline to comply with RBI guidelines

52: Number of cooperative banks in Pune district

Three levels for cyber security

Level 1: Basic cyber security

Level 2: Network management

Level 3: Establishing robust security to defend any online attack

RBIs four-step security structure

Step 1: Creation of basic cyber security infrastructure

Step 2: Extra precaution of account holders using net banking transactions

Step 3:Strict security arrangement for those banks engaged in high internet usage and ATM switch facilities

Step 4: Strengthening security of those banks sharing data centres with other banks

Things RBI wants UBCs to implement

-Implement bank specific email domains with anti-phishing and anti-malware, Domain-based Message Authentication, Reporting & Conformance (Dmarc) controls enforced at the email solution

-Document and apply baseline security requirements/configurations to all categories of devices (end-points/workstations, mobile devices, operating systems, databases, applications, network devices, security devices and security systems.), throughout the life cycle (from conception to deployment) and carry out reviews periodically.

-Periodically conduct Vulnerability Assessment/ Penetration Testing (VA/PT) of internet facing web/mobile applications, servers and network components throughout their life cycle (pre-implementation, post implementation and after changes.). VA of critical applications and those on DMZ shall be conducted at least once in every six months. PT shall be conducted at least once in a year.

Cosmos bank malware

-In an overnight attack on August 11, 2018, the Cosmos Bank had lost Rs 80,50,00,000 through 14,849 card transactions involving Visa and Rupay cards.

-The second attack was on August 13, 2018, when a transaction involving a swift code cost the bank over Rs 13,92,00,000.

18 people arrested in the case that is still under investigation

  • Yogesh Joshi
    ABOUT THE AUTHOR
    Yogesh Joshi

    Yogesh Joshi is Assistant Editor at Hindustan Times. He covers politics, security, development and human rights from Western Maharashtra.