TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
IT Security

Online payment rules

by Mark Rowe

A test by an IT security product firm suggests that many users do not know (or know, but do not follow) basic security rules when making online payments or using online banking. For example, only half of users check if a website is authentic before entering their financial details, while almost a third consider it completely unnecessary to take any measures to protect their money online.

The test, online, included a number of potentially dangerous situations that users often encounter on the Internet, including online financial operations. Over 18,000 users completed the test.

Participants were asked to select one of four fictitious banking sites to enter their account details. Only half of the participants were able to recognise the truly secure site with an unmodified name (changes to an organisationโ€™s name are a common giveaway of phishing) and the https prefix indicating an encrypted connection. Moreover, five per cent of respondents selected sites with a misspelt address, which suggests they are potentially fake pages created to steal financial data from users.

Users were then asked what steps they would take before entering their financial data to make an online payment. Only 51 per cent of respondents said they verify the authenticity of a site. 21 per cent of those surveyed use a virtual keyboard to protect their passwords from interception by malware, while 20 per cent check their security solution is working properly to ensure the payment is secure from any outside interference.

Almost a third of users (29 per cent) said they would take no additional action because “the websites of big, well-known companies are sufficiently protected”. However, in most cases even a protected site cannot guarantee that cyber-criminals will not interfere in the payment process or that a device is not infected by a malicious program designed to steal money. Eleven per cent of respondents would use “incognito” mode to protect a payment, four per cent would resort to an anonymiser, and seven per cent of those surveyed would repeatedly enter and wipe the data “to confuse viruses”. Unfortunately, these actions do nothing to protect a userโ€™s financial information.

It turned out that some users were just as careless about protecting their payment details in the real world: 20 per cent see no problem in letting their bank card out of their sight when paying in a restaurant thereby giving fraudsters a chance to make a copy.

Kirill Slavin, Managing Director UK and Ireland, Kaspersky Lab, said: “These statistics emphasise what has long been perceived; which is that many users are not only endangering themselves and their money but also the banking systems they use. Rectifying issues caused by inexperienced users can consume considerable resources, and have a negative influence on a companyโ€™s reputation. Companies need to instill confidence in their users by reassuring them that they are doing everything possible to protect them from online fraud and this imposes a great deal of responsibility. This ultimately means the use of specialised security against online theft is becoming a necessity.”