• About Us
  • Privacy Policy
  • Terms & Conditions
  • Contact Us
  • Email Whitelisting
Wednesday, February 1, 2023
Invest Daily Pro
  • Top News
  • Economy
  • Forex
  • Investing
  • Stock
  • Politics
  • Editor’s Pick
No Result
View All Result
  • Top News
  • Economy
  • Forex
  • Investing
  • Stock
  • Politics
  • Editor’s Pick
No Result
View All Result
Invest Daily Pro
No Result
View All Result
Home Forex

Banks must enhance security controls for e-mail servers — BSP

by
October 11, 2022
in Forex
0
Banks must enhance security controls for e-mail servers — BSP
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter
BW FILE PHOTO

FINANCIAL INSTITUTIONS should adopt robust and layered security controls for their e-mail servers to prevent cyberattacks, the Bangko Sentral ng Pilipinas (BSP) said.

Memorandum No. M-2022-043 signed by BSP Deputy Governor Chuchi G. Fonacier said BSP-supervised financial institutions (BSFIs) should enhance their e-mail security controls as it has become a primary mode of communication in business operations.

“Given the central role of e-mail in digital communications, cyberthreats ranging from spam, phishing, ransomware and other malware attacks targeting e-mail platforms and communications continue to confront BSFIs,” the central bank said.

“To further enhance e-mail security, BSFIs should adopt, as warranted, the security controls and best practices in safeguarding both incoming and outgoing e-mails,” it added.

The BSP, in the memo, advised BSFIs to set up a Simple Mail Transfer Protocol (SMTP) authentication method for their mail servers. They should also use industry-accepted encryption standards and versions.

Financial institutions are also expected to enforce thresholds and rate-limit SMTP connections to prevent attacks on mail servers. 

To ensure that the Internet Protocol (IP) addresses of incoming e-mails are under a valid domain name, financial institutions should activate a Reverse Domain Name System. This would also cut down spam e-mails if BSFIs use reputation-based blacklists and local IP address filtering.

The central bank also advised institutions to allow anti-spam and anti-virus features to detect and block suspicious e-mails with malicious links and attachments.

Institutions are also encouraged to use layered security controls such as firewalls and intrusion prevention systems.

“(BSFIs should) activate Sender Policy Framework (SPF), Domain-based Message Authentication Reporting and Conformance (DMARC), and DKIM (DomainKeys Identified Mail) to prevent sender address spoofing,” the BSP said.

SPF refers to an e-mail authentication protocol used to stop phishing attacks. Likewise, DMARC provides domain-level protection of the e-mail channel.

These authentication protocols detect and prevent e-mail spoofing techniques used in phishing and other e-mail-based attacks.

Lastly, DKIM allows an organization to transmit a message in a way that mailbox providers can verify. This is to protect employees and customers from targeted cyberattacks.

“To thwart advanced threats and implement a defense-in-depth approach, BSFIs should integrate e-mail security solutions with enterprise fraud management systems, privilege access management, data leak protection, and mobile device management, among others,” the BSP said.

Aside from technical controls, financial institutions should also ensure ample user education and awareness on how to report and handle malicious e-mails.

BSFIs should also identify risks of malware infection, inspect e-mail header information, carefully scrutinize the content of the e-mail, and conduct regular phishing simulations or exercises, the BSP said.

Financial institutions likewise are expected to report any major e-mail-related cyber incidents or crimes to the central bank. They may also ask help from appropriate law enforcement agencies, especially for cases involving public safety and security. — Keisha B. Ta-asan

ShareTweetPin

Related Posts

Factory activity highest in 7 months
Forex

Factory activity highest in 7 months

February 1, 2023
Factory activity highest in 7 months
Forex

Factory activity highest in 7 months

February 1, 2023
PEZA approves P6.4-B investments in January
Forex

PEZA approves P6.4-B investments in January

February 1, 2023
PEZA approves P6.4-B investments in January
Forex

PEZA approves P6.4-B investments in January

February 1, 2023
Marcos to sign 7 bilateral deals during Japan trip
Forex

Marcos to sign 7 bilateral deals during Japan trip

February 1, 2023
Marcos to sign 7 bilateral deals during Japan trip
Forex

Marcos to sign 7 bilateral deals during Japan trip

February 1, 2023
Next Post
Virology institute a must as viruses with ‘pandemic potential’ found in PHL

Virology institute a must as viruses with ‘pandemic potential’ found in PHL

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Restore free rides on EDSA — congressman 

Restore free rides on EDSA — congressman 

September 18, 2022
Leading local merchants get boost during Shopee’s 9.9 sale event

Leading local merchants get boost during Shopee’s 9.9 sale event

September 14, 2022
How Dr. Ashok Bharucha is Helping Underserved Communities Gain Access to Quality Health Care

How Dr. Ashok Bharucha is Helping Underserved Communities Gain Access to Quality Health Care

March 14, 2022
Ruthless Rybakina rolls into Australian Open semifinals

Ruthless Rybakina rolls into Australian Open semifinals

January 24, 2023
BSP chief sees 2023 inflation back within target band

BSP chief sees 2023 inflation back within target band

July 29, 2022
Mariners rally from 7-run deficit to stun Blue Jays, clinch series

Mariners rally from 7-run deficit to stun Blue Jays, clinch series

October 9, 2022
Enter Your Information Below To Receive Free Trading Ideas, Latest News And Articles.






    Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!
    • About Us
    • Privacy Policy
    • Terms & Conditions
    • Contact Us
    • Email Whitelisting

    Copyright © 2022 InvestDailyPro. All Rights Reserved.

    Disclaimer: InvestDailyPro.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice.
    The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    No Result
    View All Result
    • About Us
    • Contact Us
    • Email Whitelisting
    • Home
    • Privacy Policy
    • Suspicious engagement
    • Terms & Conditions
    • Thank You

    Copyright © 2023 SmarterNewsNow. All Rights Reserved.