Showing posts with label online. Show all posts
Showing posts with label online. Show all posts

Wednesday, February 22, 2017

Security and Privacy


Banking on Good Security.  


Thinkstock.
The banking industry is responsible for safeguarding the most personal private information of our customers. Social Security Numbers, account numbers, credit card numbers, birthdates. You get the point!  We are held to the highest standard of security and privacy not only by our customers, but our regulators NCUA (National Credit Union Association). So it’s no wonder, when I apply for a Lowes’ credit card on a paper application in the store, I ask them where does the application go, is it filed in a drawer, who  has access to it. Most times I get funny looks when I ask these types of questions. I have been trained and programmed to always be thinking about security.  The reaction I get from people not of this mindset, is part problem with today’s consumers. The general public is not educated on how to protect their own personal information. So, as companies, we need to protect them – sometimes from themselves.

In a regulated environment, where we are audited on our privacy and security by the state, internal auditors and federal regulators, we hold ourselves to the absolute highest standards of privacy and security.   We are also responsible for training the employees and our customers on security.  We have dedicated a special section of our webpage to security and privacy content. Our employees receive annual security and privacy training and tested regularly.

Unfortunately, not all companies are committed to keeping their customer’s information safe. Case-in-point, TJX companies, and Heartland Data Breaches among the top data breaches.   According to Bloomberg.com, top “Data Breaches in the U.S.”, TJX back in 2007 resulted in a loss of 100 million dollars.

 Employee Guidance for Social Media - More than being "social"



Thinkstock
As employers, we have to set the expectations for our employees. When we created our company Facebook business account, I invited our employees to visit and like our page. We had many employees decline because they didn’t want our company, or other employees to see their personal Facebook accounts. Even though, they could change their privacy settings Coincidently, we were in the process of compiling a Social Media Policy for our employees. We have both an employee Social Media policy which includes Social Media Management. We provide guidelines for our employees which they agree to every year through policy review. These guidelines like those outlined by  National Relational Labor Board,  are approved and adopted within compliance guidelines for our industry. One of the interesting points made byte NLRB's guidance was the "Opinions are largely protected, even if they are factually incorrect" 

We are in the financial services industry. We have to exercise utmost security, regarding our buildings, security protocols and other information that could be used to perpetrate crimes against our business.  Federal Financial Institutions Examination Council (FFIEC) regulates topics like social media guidance for financial institutions. They provide us with the guidance of how we can conduct social media as financial institutions.  (Much, 2017)

  





 15 Social Media Security Tips, Siciliano, 2011
 

Quote of the Week: 


 

“Realize that you can become a victim at any time. Not a day goes by when we don’t hear about a new hack. With 55,000 new pieces of malware a day, security never sleeps”. -MacAfee (Siciliano, 2011)
Thinkstock