Protect Your Personal Information Confidentiality Matters

Learn more about how you can pro­tect your­self and your busi­ness by fol­low­ing basic online secu­ri­ty practices.

ONLINE SECURITY GUIDELINES

  • Cre­ate a strong” pass­word with at least 8 char­ac­ters that includes a com­bi­na­tion of mixed case let­ters, num­bers, and spe­cial characters.
  • Change your pass­word frequently.
  • Nev­er share user­name and pass­word infor­ma­tion with third-par­ty providers.
  • Avoid using an auto­mat­ic login fea­ture that saves user­names and passwords.
  • Take advan­tage of trans­ac­tion lim­its. Estab­lish lim­its for mon­e­tary trans­ac­tions at mul­ti­ple lev­els: per trans­ac­tion, dai­ly, week­ly, or month­ly limits.
  • When you have com­plet­ed a trans­ac­tion, ensure you log off to close the con­nec­tion with the finan­cial orga­ni­za­tion’s computer.
  • Use sep­a­rate accounts for elec­tron­ic and paper trans­ac­tions to sim­pli­fy mon­i­tor­ing and track­ing any discrepancies.
  • Rec­on­cile by care­ful­ly mon­i­tor­ing account activ­i­ty and review­ing all trans­ac­tions ini­ti­at­ed on a dai­ly basis.
  • Use lim­its pro­vid­ed for mon­e­tary trans­ac­tions at mul­ti­ple lev­els: per trans­ac­tion, dai­ly, week­ly, or month­ly limits.
  • Review his­tor­i­cal and audit reports reg­u­lar­ly to con­firm trans­ac­tion activity.
  • Uti­lize avail­able alerts for funds trans­fer activity.
  • Do not open e‑mail from unknown sources. Be sus­pi­cious of e‑mails pur­port­ing to be from a finan­cial insti­tu­tion, gov­ern­ment depart­ment, or oth­er agency request­ing account infor­ma­tion, account ver­i­fi­ca­tion, or bank­ing access cre­den­tials such as user­names, pass­words, PIN codes, and sim­i­lar infor­ma­tion. Open­ing file attach­ments or click­ing on web links in sus­pi­cious e‑mails could expose your sys­tem to mali­cious code that could hijack your computer.
  • Nev­er respond to a sus­pi­cious e‑mail or click on any hyper­link embed­ded in a sus­pi­cious e‑mail. Call the pur­port­ed source if you are unsure who sent an email.
  • If an e‑mail claim­ing to be from your finan­cial orga­ni­za­tion seems sus­pi­cious, check­ing with your finan­cial orga­ni­za­tion may be appropriate.
  • Install anti-virus and spy­ware detec­tion soft­ware on all com­put­er sys­tems. Free soft­ware may not pro­vide pro­tec­tion against the lat­est threats com­pared with an indus­try stan­dard product.
  • Update all of your com­put­ers reg­u­lar­ly with the lat­est ver­sions and patch­es of both anti-virus and anti-spy­ware software.
  • Ensure com­put­ers are patched reg­u­lar­ly, par­tic­u­lar­ly oper­at­ing sys­tem and key appli­ca­tion with secu­ri­ty patches.
  • Install a ded­i­cat­ed, active­ly man­aged fire­wall, espe­cial­ly if using a broad­band or ded­i­cat­ed con­nec­tion to the Inter­net, such as DSL or cable. A fire­wall lim­its the poten­tial for unau­tho­rized access to your net­work and computers.
  • Check your set­tings and select, at least, a medi­um lev­el of secu­ri­ty for your browsers.
  • Clear the brows­er cache before start­ing an online bank­ing ses­sion in order to elim­i­nate copies of Web pages that have been stored on the hard dri­ve. How the cache is cleared depends on the brows­er and ver­sion you are using — this func­tion is gen­er­al­ly found in the browser’s pref­er­ences menu.
  • Change the wire­less net­work hard­ware (router /​access point) admin­is­tra­tive pass­word from the fac­to­ry default to a com­plex pass­word. Save the pass­word in a secure loca­tion as it will be need­ed to make future changes to the device.
  • Dis­able remote admin­is­tra­tion of the wire­less net­work hard­ware (router / access point).
  • If pos­si­ble, dis­able broad­cast­ing the net­work SSID.
  • If your device offers WPA encryp­tion, secure your wire­less net­work by enabling WPA encryp­tion of the wire­less net­work. If your device does not sup­port WPA encryp­tion, enable WEP encryption.
  • If only known com­put­ers will access the wire­less net­work, con­sid­er enabling MAC fil­ter­ing on the net­work hard­ware. Every com­put­er net­work card is assigned a unique MAC address. MAC fil­ter­ing will only allow com­put­ers with per­mit­ted MAC address­es access to the wire­less network.

An FBI rec­om­mend­ed best prac­tice is to sug­gest that com­pa­ny users ded­i­cate a PC sole­ly for finan­cial trans­ac­tions, such as Wire Trans­fers and instruc­tions and ACH Trans­fer and instruc­tions (e.g., no web brows­ing, emails, or social media).

Com­pa­nies should pro­vide con­tin­u­ous com­mu­ni­ca­tion and edu­ca­tion to employ­ees using online bank­ing sys­tems. Pro­vid­ing enhanced secu­ri­ty aware­ness train­ing will help ensure employ­ees under­stand the secu­ri­ty risks relat­ed to their duties.

Com­pa­nies should also con­sid­er­ing adopt­ing advanced secu­ri­ty mea­sures by work­ing with con­sul­tants or ded­i­cat­ed IT staff; and also uti­lize resources pro­vid­ed by trade orga­ni­za­tions and agen­cies that spe­cial­ize in help­ing small businesses.

  • Use pre-noti­fi­ca­tion trans­ac­tions to ver­i­fy that account num­bers with­in your ACH pay­ments are correct.
  • Use lim­its for mon­e­tary trans­ac­tions at mul­ti­ple lev­els: per trans­ac­tion, dai­ly, week­ly, or month­ly limits.
  • Use Tokens to ensure authen­ti­ca­tion and dual control.
  • Review trans­ac­tion report­ing reg­u­lar­ly to con­firm trans­ac­tion activity.
  • Uti­lize avail­able alerts for ACH activity.
  • Use lim­its pro­vid­ed for mon­e­tary trans­ac­tions at mul­ti­ple lev­els: per trans­ac­tion, dai­ly, week­ly, or month­ly limits.
  • Use Tokens to ensure authen­ti­ca­tion and dual control.
  • Review his­tor­i­cal and audit reports reg­u­lar­ly to con­firm trans­ac­tion activity.
  • Uti­lize avail­able alerts for wire trans­fer activity.
  • Lim­it admin­is­tra­tive rights on users’ work­sta­tions to help pre­vent the inad­ver­tent down­load­ing of mal­ware or oth­er viruses.
  • Ded­i­cate and lim­it the num­ber of com­put­ers used to com­plete online bank­ing trans­ac­tions; do not allow Inter­net brows­ing or e‑mail exchange and ensure these com­put­ers are equipped with lat­est ver­sions and patch­es of both antivirus and anti-spy­ware software.
  • Delete online user IDs as part of the exit pro­ce­dure when employ­ees leave your company.
  • Assign dual sys­tem admin­is­tra­tors for online cash man­age­ment ser­vices and ensure users are adher­ing to dual con­trol procedures.
  • Use mul­ti­ple approvals for mon­e­tary trans­ac­tions and require sep­a­rate entry and approval users.
  • Estab­lish trans­ac­tion dol­lar lim­its for employ­ees who ini­ti­ate and approve online pay­ments such as ACH batch­es, wire trans­fers, and account transfers.

To learn more about online secu­ri­ty, please call us at 866.604.2006 or vis­it a branch.