WASHINGTON, D.C. – Testifying before the U.S. House Financial Services Committee at a hearing entitled “Fighting Fraud on the Front Lines: Challenges and Opportunities for Financial Institutions” today, Consumer Bankers Association (CBA) Fraud Management Committee Chair Patrick McDade reiterated the need for a whole-of-government approach to combat fraud and scams in order to better protect hardworking Americans.
Key excerpts from McDade’s oral testimony and responses to questions from the Committee are below.
On how banks are leading the way to combat fraud and scams, McDade said:
“CBA’s broad membership has long been raising the alarm about the rise in fraud and scams that are inflicting deep financial and emotional harm on American consumers and small businesses. Banks invest billions of dollars and millions of hours to combat fraudsters and scammers each year.”
On…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
