New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Open banking innovation: A race between developers and cybercriminals

New York Tech Editorial Team by New York Tech Editorial Team
February 14, 2022
in Cybersecurity
0
Open banking innovation: A race between developers and cybercriminals
Share on FacebookShare on Twitter

In this interview with Help Net Security, Karl Mattson, CISO at Noname Security, explains the wide usage of open banking and how it can easily be exploited if adequate security measures are not implemented.

open banking

As open banking becomes widely used, it opens new possibilities for cybercriminals to plan their attacks. What is it that makes open banking so vulnerable?

Open banking initiatives, by design, empower communities of developers and FinTech companies to innovate and to satisfy new financial services’ needs. Open banking APIs handle everything from account status to fund transfers to pin changes and account services. Attackers able to gain access to these services will also gain access to these functionalities and sensitive customer data. Exposing sensitive customer, account and payment data requires a new level of precision to ensure the integrity of transactions and the safeguarding of data.

As the pace of open API development picks up, the security stakes are high. Even well-governed, highly secure companies face tremendous pressure to keep up with the pace of change and to match the API threats.

In addition, many companies adopt third-party API code shared by multiple customers and which may include vulnerabilities. Research indicates that third party API code presents significant opportunities for attackers to reusing attacks targeting third party code at multiple organizations.

On top of open banking driving API utilization, APIs have become a de facto standard in modern application development, with organizations often deploying thousands of APIs for a wide variety of purposes. Each connection point between these APIs represents a potential attack vector. Facing such a massively expanded attack surface, many organizations, and especially smaller ones, can struggle to secure them due to a lack of resources.

Why are APIs in open banking a common target for cybercriminals?

Cybercriminals will target APIs in open banking because of their ability to provide direct access to capital. Combined with the fact that the trend of API attacks as one of the most common and effective forms of cyberattack today means open banking APIs are at particular risk.

While the installation of API security precautions allows for the integration between banking apps and FinTech companies, these numerous touchpoints are also where cybercriminals look to exploit vulnerable code. Therefore, it should not come as a surprise that cybercriminals are empowered to target APIs open banking, because as we have recently seen, APIs are often left unsecured while the payoff for successfully hacking them is direct monetary gain.

What can financial services organizations do to make APIs more secure?

The first step is to gain a complete inventory of all the APIs, with data classification and configuration details to provide a holistic view of the environment. Today, one of the main challenges associated with securing APIs is that most organizations have thousands of APIs that they don’t know about – these are referred to as shadow or rogue APIs. Existing infrastructure, like API gateways and WAFs, don’t address API risks when they are not used. For high-risk open banking APIs, the margin of error is zero.

With a complete viewpoint on the posture and configuration of all APIs, organizations can prioritize their focus on highest risk exposure. This starts with identifying runtime anomalies, or attempted misuse observed in progress. APIs are well-suited for behavior analysis models to identify unique anomalies in each and every API.

Next, configuration and vulnerabilities should be identified upstream for quick resolution by network and application teams – firewall changes, API policy enforcement and other applied techniques to de-risk API exposure.

The final step is actively testing APIs to validate integrity before and after they are deployed to production, especially as the environment evolves through regular shipments of code or continuous integration/continuous delivery (CI/CD) deployments.

Can consumers trust open banking? What should they look out for?

Consumers benefit from open banking by opening a new universe of services and benefits for their financial needs. However, the consumer is at a distinct disadvantage with respect to knowing how to evaluate risks to their personal information. For example, a banking customer may have little insight or control over how these services are delivered on the backend by their financial institution.

As well, there are few data points for consumers to consider when evaluating whether a new FinTech service offering is truly secure. The average consumer is still largely dependent on quality oversight by financial industry regulators to be the gatekeepers of responsible risk management and data protections.

Can innovation actually set back the financial services industry security wise? How can it embrace innovation while ensuring security?

Open banking innovation is neither more or less secure than traditional models – but it does accelerate the pace of change considerably. Any changing environment may be prone to mistakes and human or technical error, even when the APIs themselves can be highly secured. Cybercriminals do take notice.

The surge in API growth has left security teams struggling to efficiently observe and adequately address the gaps. Rapid innovation is forcing developers to leave security by the wayside as they seek to deliver software at a faster pace. The need to keep up with innovation has become a race between developers and cybercriminals and is creating issues in itself.

Credit: Source link

Previous Post

Using mobile networks for cyber attacks as part of a warfare strategy

Next Post

Baringa and Retail Technology Show put focus on startup innovation — Retail Technology Innovation Hub

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Baringa and Retail Technology Show put focus on startup innovation — Retail Technology Innovation Hub

Baringa and Retail Technology Show put focus on startup innovation — Retail Technology Innovation Hub

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
PointFive Secures Spot on Redpoint’s InfraRed 100, Cementing Its Role in Cloud Infrastructure’s Next Era

PointFive Secures Spot on Redpoint’s InfraRed 100, Cementing Its Role in Cloud Infrastructure’s Next Era

June 12, 2025
Alisha Outridge: Redrawing the Future of Tech, Leadership & Learning

Alisha Outridge: Redrawing the Future of Tech, Leadership & Learning

June 11, 2025
New Funding Backs Unibeam’s SIM-Driven Fix for Broken Authentication Systems

New Funding Backs Unibeam’s SIM-Driven Fix for Broken Authentication Systems

June 9, 2025
New York City

Why Bite-Sized Learning is Booming in NYC’s Hustle Culture

June 4, 2025
Driving Innovation in Academic Technologies: Spotlight from ICTIS 2025

Driving Innovation in Academic Technologies: Spotlight from ICTIS 2025

June 4, 2025
Designer Paulina Raczkowska on UX, UI Design and the Power of Empathy in Product Design

Designer Paulina Raczkowska on UX, UI Design and the Power of Empathy in Product Design

June 2, 2025

Recommended

PointFive Secures Spot on Redpoint’s InfraRed 100, Cementing Its Role in Cloud Infrastructure’s Next Era

PointFive Secures Spot on Redpoint’s InfraRed 100, Cementing Its Role in Cloud Infrastructure’s Next Era

June 12, 2025
Alisha Outridge: Redrawing the Future of Tech, Leadership & Learning

Alisha Outridge: Redrawing the Future of Tech, Leadership & Learning

June 11, 2025
New Funding Backs Unibeam’s SIM-Driven Fix for Broken Authentication Systems

New Funding Backs Unibeam’s SIM-Driven Fix for Broken Authentication Systems

June 9, 2025
New York City

Why Bite-Sized Learning is Booming in NYC’s Hustle Culture

June 4, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech crypto cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media