• ENEN
    • IT IT
    • ES ES
PARTNER LOGIN
  • ENEN
    • IT IT
    • ES ES

Auriga

  • COMPANY

    • About Us

    • Auriga History

    • Group

    • Our Values

    • Our Network

      • Partnerships

      • Certifications

      • Suppliers

    • CSR (ethical code)

      • CSR – Corporate Social Responsibility

  • BANKING

    • Overview

    • Needs

      • Channel Integration

      • Monitoring network

      • Marketing & Customer Relations

      • Accessibility of banking service

      • Corporate Banking

      • Banking Data Analysis

      • Branch of the Future

      • ATM network security

    • Products and Solutions

      • Shared Services

        • WinWebServer Architecture

        • Proactive Network Monitoring

        • One to One Marketing

      • ATM / Kiosks

        • WWS ATM

      • Internet / PC

        • WWS Digital Banking

      • Mobile Banking and Payments

        • WWS Mobile

      • Electronic payments

        • MyBank

      • Bank Marketing & Digital Signage

        • WWS One to One OMNIA

        • WWS Signage

        • WWS Perfect

        • WWS RSS Feed

        • WWS Simply Feed

      • Network Monitoring & Fraud Management

        • WWS Proactive Monitoring OMNIA

        • WWS Fraud Management System

        • WWS Simply Check

      • Call Centre

        • WWS Help Desk

      • Cash Handling

        • WWS Cash Handling

        • WWS Cash Management

      • Digital Invoicing and Document Management

        • WWS e-Invoicing

      • Branch

        • WWS Fill4Me and Bank4Me

        • WWS Greæter

        • WWS Customer Management

      • Business Analytics

        • WWS Business Analytics Management

        • WWS Asset Management

      • Cyber Security Platform

        • Lookwise Device Manager

  • NEWS & MEDIA

    • News

    • Press Release

    • Press Review

    • Blog

    • Videos

    • Infographics

  • RESOURCES

    • White Papers

    • Customer stories

    • Research

    • Brochures

  • CONTACT

    • Contact us

  • CAREERS

    • Work for Us

    • Online application

    • Job vacancies

Blog

  • Home
  • News & Media
  • Blog
  • What Self-Service Channel Needs for Better Cybersecurity in 2024
What Self-Service Channel Needs for Better Cybersecurity in 2024

What Self-Service Channel Needs for Better Cybersecurity in 2024

20 October 2023 / Blog

October is over and so is the month’s annual focus on putting cybersecurity to the top of everyone’s agendas. But obviously vigilance about cybersecurity shouldn’t let up once Halloween is over.

And this is especially the case for the financial institutions which are always in the cross hairs of cyber criminals and fraudsters.

The importance of avoiding cybersecurity complacency was underlined in 2023 for the sector when not just one but two new different kinds of ATM jackpotting scams emerged.

We wrote about the FiXs ATM malware attack in April. But there was another new jackpotting attack on ATMs reported in May. The second ATM attack combined shimming, which hides a thin hardware device in the ATM card reader to steal card data, and a relay attack, where an attacker intercepts and manipulates cash withdrawal communications. Unlike a skimming attack that fixes hardware on the outside the ATM, a shimmer is inserted inside the ATM terminal to read a victim’s card credentials, which are immediately transferred by Bluetooth to the fraudster’s mobile phone.

What is interesting is how the fraudster then does a network transfer to a second mobile phone that connects with another ATM compromised with skimmer hardware to complete theft of money.

How 2023 saw two new kinds of cyberattacks on ATMs shows how threats are always evolving and span more than just jackpotting but other even more sophisticated attacks like man in the middle exploits. Indeed, the majority of global ATM crime incidents involved digital fraud attacks (79%) compared to physical attacks like tearing out an ATM using a tractor (20%). (Source: Crisis and Crime Management Intelligence System – ATM Crime Trends – Q2 2023)

Banks and ATM operators need to keep a laser focus on securing their self-service banking channel especially as it is modernised and aligns with their omnichannel banking strategies.

SO, WHAT FUTURE STEPS SHOULD THE INDUSTRY BE CONSIDERING?

As in all areas of cybersecurity, intelligent automation and machine learning will be and is extremely useful in executing key tasks from detecting attacks to automating remediation and device security management on fleets of ATMs and ASSTs.

So, it is no surprise that artificial intelligence is being suggested as an important defence for the self-service banking channel. However, many ATM operators have found deploying current AI for behavioural analysis and detection and response has led to ATM malfunctions and outages. This also is related to how some banks and operators try to shoehorn general-purpose cybersecurity solutions into what is a specialised field.

When ATMs are considered as critical systems, there is still a lot to learn about where AI protection could be implemented on current and next generations of ATMs. Certainly, there will be more advanced  AI present in current and future generations of ATMs, and these could be another attack surface that needs defending.

ZERO TRUST APPROACH

What is going to of more fundamental benefit to banks and ATM operators will be how they have adopted a zero-trust strategy that ensures nothing is executed on an ATM or ASST unless it has been previously authorised.

Auriga’s Lookwise Device Manager (LDM) applies a Zero Trust approach, as well as utilising the knowledge of the network infrastructure, and the attacker’s tactics and techniques. It provides the most comprehensive layered protection model for ATMs, ASSTs, and other critical devices at all stages of the attack lifecycle, ensuring full availability of services for customers.

Robust network security policies are considered essential, and currently, there are solutions with a higher degree of protection than network firewalls, such as application firewalls, which not only control communications but also regulate which processes can engage in them. Furthermore, more advanced solutions like microsegmentation are more secure and advisable, as they employ secured channels with controlled certificates for each connection, even though they come with a higher deployment and maintenance cost.

Banks and other ATM operators are increasingly applying zero trust strategies. Indeed, we are seeing ATMs properly classed as a fixed-purpose operational technology critical device. This is creating the potential for ATM protection that reduces the attack surface on the self-service channel and its key operational processes, transforming its weaknesses into strengths.

To learn more about how cybersecurity for self-service banking is evolving, please check out our LDM resources.

    
  • Tweet
  • News
  • Press Release
  • Press Review
  • Blog
  • Videos
  • Infographics

DO YOU WANT INSIGHTS FROM THE WORLD’S BANKING INDUSTRY?

JOIN THE AURIGA COMMUNITY TO BE ALWAYS UPDATED ON:

News on software solutions

Invitations to industry events

Customer stories

Reports

Market research

...and much more!

LET'S CONNECT
CONTACT

HEADQUARTER - BARI
Via Don Luigi Guanella, 17
70124 Bari - Italy

TEL: +39.080.5692111

info@aurigaspa.com

Milan office
Rome office
Brussels office
London office
Madrid office
Mexico City office

BUSINESS CONTACTS
Niccolo Garzelli - Auriga - Footer

Niccolò Garzelli Milan office
niccolo.garzelli@aurigaspa.com

MARK ALDRED London office
mark.aldred@aurigaspa.com

brendan-thorpe-contacts

BRENDAN THORPE London office
brendan.thorpe@aurigaspa.com

Stefano Cipollone Milan office
stefano.cipollone@aurigaspa.com

MARTIN ESPINELMexico City office
martin.espinel@aurigaspa.com

lukasz-feluch

ŁUKASZ FELUCHVarsaw office
lukasz.feluch@aurigaspa.com

RUDY DE WOLFBrussels office
rudolf.dewolf@aurigaspa.com

angel arenillas

ÁNGEL ARENILLAS YUSTEMadrid office
angel.arenillas@aurigaspa.com

Kelum-Dissanayake-Auriga-Footer

Kelum Dissanayakekelum.dissanayake@aurigaspa.com

EXPLORE
  • About Us
  • WinWebServer
  • Blog
  • White Papers
  • Research
LATEST NEWS
  • Hybrid-Branch-Digital-and-Physical-Blog-ENG-Auriga

    The Hybrid Branch: Blending Digital and Physical Banking

    14/04/2025
  • Access to cash

    Maintaining ATMs and Access to Cash: a Worldwide Issue

    14/04/2025
  • service-delivery-manager-job-vacancies-auriga

    Service Delivery Manager – Brussels (Belgium)

    09/04/2025

Connect with us

SUBSCRIBE TO THE NEWSLETTER

Join the Auriga community

Let's connect

Auriga Spa - Copyright © 2025 - All rights reserved | Legal Notice | Privacy Policy | Whistleblowing Policy | Social Media Policy
P.I. 05566820725 - Capital € 1.196.055 i.v. - R.E.A. 426675

TOP
Gestisci Consenso

We, and third party websites you may interact with via our site, use cookies to collect site usage data and improve your experience, this includes permanent and profiling cookies. By clicking ‘Accept’ you agree to allow cookies, however you can disable this through your browser settings at anytime. If you opt to totally or partial disable cookies, this might compromise some features on the website. For more information on our cookie policy, go to the Legal Notice page.

Functional Always active
L'archiviazione tecnica o l'accesso sono strettamente necessari al fine legittimo di consentire l'uso di un servizio specifico esplicitamente richiesto dall'abbonato o dall'utente, o al solo scopo di effettuare la trasmissione di una comunicazione su una rete di comunicazione elettronica.
Preferenze
L'archiviazione tecnica o l'accesso sono necessari per lo scopo legittimo di memorizzare le preferenze che non sono richieste dall'abbonato o dall'utente.
Statistiche
L'archiviazione tecnica o l'accesso che viene utilizzato esclusivamente per scopi statistici. L'archiviazione tecnica o l'accesso che viene utilizzato esclusivamente per scopi statistici anonimi. Senza un mandato di comparizione, una conformità volontaria da parte del vostro Fornitore di Servizi Internet, o ulteriori registrazioni da parte di terzi, le informazioni memorizzate o recuperate per questo scopo da sole non possono di solito essere utilizzate per l'identificazione.
Marketing
L'archiviazione tecnica o l'accesso sono necessari per creare profili di utenti per inviare pubblicità, o per tracciare l'utente su un sito web o su diversi siti web per scopi di marketing simili.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}