Banks urged to share data but warned over security

Experts voice concern over security of open API recommendations

Online banking details

Banks should open up data, including product and services information, to consumers in order for them to make more informed choices about services and value for money, a new report has urged. However, security industry figures have warned that any framework put in place must be secure.

In a report published by the Open Banking Working Group (OBWG), a new framework was unveiled that supports the use of open APIs in the banking sector with a number of measures put forwars on how to deliver them.

Advertisement - Article continues below

It said these APIs would be created so additional services could be built using bank and customer data. These would include open data about products and services as well as shared data about bank transactions that individuals or businesses can choose to share themselves through secure and controlled means.

It added that bank data, including information about banks' products and services, should be made available as open data so that services can be built allowing customers to get more out of their financial relationships.

"Banking as a service has long sat at the heart of our economy. In our digitally enabled world, the need to seamlessly and efficiently connect different economic agents who are buying and selling goods and services is critical," said Matt Hammerstein, co-chair of the OBWG and Barclays' head of client and customer experience for Personal and Corporate Banking. "The Open Banking Standard is a framework for making banking data work better: for customers; for businesses and; for the economy as a whole."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Fellow OBWG co-chair and ODI CEO Gavin Starks said the efforts of the OBWG and the Open Banking Standard "demonstrate the powerful result of leaders coming together to wrestle substantial challenges facing the banking sector."

"It will also set precedents across many sectors: a strong data infrastructure will be as important to the UK's economy today as roads have been to our success in the industrial economy for over a century."

The report said a minimum viable product for an Open Banking API based on open data is recommended to be launched towards the end of 2016, with personal customer transaction data included on a read-only basis starting at the beginning of 2017. The Open Banking Standard's full scope, including business, customer and transactional data, should be reached by 2019, according to the report.

However, Florian Malecki, international product marketing director at Dell Security, warned that if UK banks are to open up customer data to third parties, they must "follow a three-phase IT security process to ensure data are fully protected along their journey".

Advertisement - Article continues below

He said that banks must ensure that their partners' and their own networks have adequate network security protection before, during and after the data transfer.

"Both banks and third parties should anticipate an increase in data traffic and have next generation firewall technology in place which can ramp up network protection during particularly busy transfer periods," he said.

He added that banks should guarantee that customer data are sufficiently encrypted prior to sharing with third parties.

Lastly, he urged banks to ensure that both they and third parties have adequate identity and access management controls in place when receiving customer data to ensure they are viewed only by those who have a valid business reason to do so.

"If this measure is not followed, data could be viewed by unauthorised parties, resulting in failed audits or malicious or unintentional public disclosure of personal data that could impact the bank's reputation," said Malecki.

Featured Resources

Key considerations for implementing secure telework at scale

Identifying the security risks and advanced requirements of a remote workforce

Download now

The State of Salesforce 2020

Your guide to getting the most from Salesforce

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Rethink your cybersecurity strategy for the new world

5 steps to secure the enterprise and be fit for a flexible future

Download now
Advertisement
Advertisement

Recommended

Andrew Daniels joins Druva as CIO and CISO
Cloud

Andrew Daniels joins Druva as CIO and CISO

22 Jul 2020
University of California gets fleeced by hackers for $1.14 million
ransomware

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
Australia announces $1.35 billion investment in cyber security
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020
CSA and ISSA form cyber security partnership
cloud security

CSA and ISSA form cyber security partnership

30 Jun 2020

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

3 Aug 2020
How to use Chromecast without Wi-Fi
Mobile

How to use Chromecast without Wi-Fi

4 Aug 2020
Police use of facial recognition ruled unlawful in the UK
privacy

Police use of facial recognition ruled unlawful in the UK

11 Aug 2020