Banking on Good Security.
 |
| Thinkstock. |
The banking industry is
responsible for safeguarding the most personal private information of our
customers. Social Security Numbers, account numbers, credit card numbers,
birthdates. You get the point! We are
held to the highest standard of security and privacy not only by our customers,
but our regulators NCUA (National Credit
Union Association). So it’s no wonder, when I apply for a Lowes’ credit card on a
paper application in the store, I ask them where does the application go, is it
filed in a drawer, who has access to it.
Most times I get funny looks when I ask these types of questions. I have been trained
and programmed to always be thinking about security. The reaction I get from people not of this
mindset, is part problem with today’s consumers. The general public is not educated
on how to protect their own personal information. So, as companies, we need to
protect them – sometimes from themselves.
In a regulated
environment, where we are audited on our privacy and security by the state,
internal auditors and federal regulators, we hold ourselves to the absolute
highest standards of privacy and security. We are also responsible for training the
employees and our customers on security.
We have dedicated a special section of our webpage to security and
privacy content. Our employees receive annual security and privacy training and
tested regularly.
Unfortunately,
not all companies are committed to keeping their customer’s information safe.
Case-in-point, TJX companies, and Heartland Data Breaches among the top data
breaches. According to Bloomberg.com,
top “Data Breaches in the U.S.”, TJX back in 2007 resulted in a loss of 100
million dollars.
Employee Guidance for Social Media - More than being "social"
 |
| Thinkstock |
As employers, we
have to set the expectations for our employees. When we created our company
Facebook business account, I invited our employees to visit and like our page.
We had many employees decline because they didn’t want our company, or other employees to
see their personal Facebook accounts. Even though, they could change their privacy
settings. Coincidently, we were in the
process of compiling a Social Media Policy for our employees. We have both an
employee Social Media policy which includes Social Media Management. We provide guidelines
for our employees which they agree to every year through policy review. These
guidelines like those outlined by National Relational Labor Board, are approved and adopted within compliance
guidelines for our industry. One of the interesting points made byte NLRB's guidance was the "Opinions are largely protected, even if they are factually incorrect"
We are in the financial services industry. We have to exercise
utmost security, regarding our buildings, security protocols and other
information that could be used to perpetrate crimes against our business. Federal
Financial Institutions Examination Council (FFIEC) regulates topics like
social media guidance for financial institutions. They provide us with the
guidance of how we can conduct social media as financial institutions. (Much, 2017)
15 Social Media Security Tips, Siciliano, 2011
Mintz, L. C. (2012, February 1). http://www.natlawreview.com/article/nrlb-report-employers-social-media-policies-must-be-narrow-must-not-restrict-right.
Retrieved from National Law Review: http://www.natlawreview.com
Quote of the Week:
“Realize that you can become a victim at any time. Not a day goes by when we don’t hear about a new hack. With 55,000 new pieces of malware a day, security never sleeps”. -MacAfee (Siciliano, 2011)
 |
| Thinkstock |