PROTECTING YOUR IDENTITY:
1
What to Know, What to Do
Britt Short
©2013 Raymond James & Associates, Inc., member New York Stock Exchange/SIPC. Raymond James® is a registered trademark of Raymond James Financial, Inc.
Information Security Topics
• Technology Threats
• Raymond James’ Safeguards
• Protecting Yourself
• Tips for Traveling
PROTECTING YOUR PERSONAL
INFORMATION
3
FINANCIAL SERVICES THREATS
5
7
What is it?
• Criminals seeking to obtain confidential information
• KYFF – Know Your Family & Friends
• Can occur via phone, email, or in person
• Social media makes the criminal’s job easy
This information is used to gain your trust
• Attacks are becoming much more realistic
9
Identifying Attempts
• Hoax messages often contain 3 recognizable parts: A hook - to catch your interest and get you to read
the message
A warning - about imminent danger if you do not react and respond
A request - to warn everyone you know about the danger
Phishing (Pronounced “Fishing”) - You receive an
email, which appears to be from a reputable company,
asking you to respond or go to a website and provide your personal information or credentials.
11
Technology Security
• Restricted physical access
• System Monitoring 24 / 7, 365 days
• Quarterly independent audits of technology
systems
• Latest technologies for firewalls and antivirus
• Limit and monitor employee access to systems
HOW DOES RAYMOND JAMES PROTECT
YOUR PERSONAL INFORMATION
Cyber Threat Center
• Real-time Monitoring
• Dedicated Intel Analysts
• Security Analytics - “Big Data” • Incident Command Center
• Partner Organizations
HOW DOES RAYMOND JAMES PROTECT
YOUR PERSONAL INFORMATION
13
Cyber Threat Center
• 30,000 Events recorded per second • 15 Phishing campaigns per week • 5 Wire fraud attempts per week • 87% of emails blocked by firewall
• Sharing critical authoritative information … world wide … instantly
• Launched in 1999 in response to “Presidential Directive 63” requiring public/private partnership • Coordination w/ Treasury, Comptroller of Currency,
Homeland Security (DHS), Secret Service, and the Financial Services Sector Coordinating Council
• Over 7,000 member firms worldwide
HOW DOES RAYMOND JAMES PROTECT
YOUR PERSONAL INFORMATION
15
Inbound Emails
• March 2014: Only 24 million (or 13%) of the 177
million emails that Raymond James received were allowed
Verify links on the
internet and in emails
• Don’t click on the unkown!
• HTTPS – Secure Connection
17
Change Passwords Regularly – Don’t Share!
Password Naming Conventions: “YEAR WORD XX”
PROTECTING YOURSELF
Account Password Raymond James 2015 Saf3ty RA Apple 2015 Saf3ty AP19
Use Strong Passwords - passwordmeter.com
What Not To Do
21
Encrypt Sensitive Documents
Password Protecting is not equivalent to encryption
PROTECTING YOURSELF
Slide 21
DW1 This slide is going to confuse them. We say password is not encryption yet the pic says it is. Maybe change it to password protect sensitive documents...
22
Handling of Documents
• Cross-shred sensitive documents
• Store in a secure place prior to shredding
• Opt out of mailing lists – OptOutPreScreen.com
Disposing of Electronics
• Properly destroy of hard drive
• Wipe your device
• Remove memory and SIM card
Mobile Banking Best Practices
• Utilize the devices lock function
• Physically secure the device
• Avoid auto-saving passwords
• Install updates quickly
• Do not access financial sites on
24
Skimmers
• Payment Card Skimmers • ATM Keypad Skimmers • Cash Register Skimmers
PROTECTING YOURSELF
Cyber attacks on businesses with fewer than 250
employees accounted for 31% of all reported attacks in 2012, compared with 18% in 2011.
26
Assumptions
• Assume all data sent over the Internet while abroad
may be monitored.
• Assume phone conversations (landline and cellular),
SMS messages, and instant messages are monitored.
• Assume electronic devices that leave your control may
be copied and the data residing on them may be compromised.
Recommendations
• Leave all unnecessary electronic devices behind
unless they are required.
• Do not connect any removable media devices (e.g.
thumb drive) to your computer.
• If possible, take electronic devices separate from
those you normally use or carry. This will minimize the amount of sensitive data stored on the devices.
28
Device Settings
• Disable Bluetooth
• Disable your laptops webcam
• Disable WiFi
• Ensure WiFi does not auto-connect
PROTECTING YOUR IDENTITY:
30
OVERVIEW
Identity protection:
• Protection from what?
• Warning signs of identity theft • How you can reduce your risk
32
Identity theft:
• Someone steals your personal information • Uses it without permission
• Can damage your finances, credit history and reputation
How do you know if your identity was stolen?
• Mistakes on accounts or your explanation of medical Benefits
• Regular bills go missing
• Calls from debt collectors for debts that aren’t yours • Notice from the IRS
• Calls or mail about accounts in your minor child’s name
WARNING SIGNS
34
HOW DOES IDENTITY THEFT HAPPEN?
Identity thieves will:
• Steal information from trash or from a business
• Trick you into revealing information • Take your wallet or purse
• Pretend to offer a job, loan, or apartment to get your information
Identity protection means treating your personal information with care.
Make it a habit.
• Like buckling your seatbelt, or • Locking your doors at night
36
Check for irregularities.
• Your right to a free credit report every 12 months • Stagger your requests so that you order one report
every four months
• To order, go to annualcreditreport.com or call 1-877-322-8228
Read your bank, credit and account statements, and explanation of medical benefits.
• Look for charges you didn’t make
• Be alert for bills that don’t arrive when you expect them
• Follow up if you get account statements you don’t expect
38
Respond quickly to notices from the Internal Revenue Service.
• If someone has used your Social Security number on a tax return, contact IRS’s Specialized Identity Theft
Protection Unit
Secure your Social Security Number.
• If someone asks for it, ask: Why do you need it? How will it be used?
How do you protect it?
40
Protect Your Personal Information.
• Keep your important papers secure • Be careful with your mail
• Shred sensitive documents
• Don’t overshare on social networking sites
Protect your computer.
• Lock up your laptop • Read privacy policies
42
• Act fast to limit the damage
• Take these steps immediately…
WHAT TO DO IF SOMEONE HAS STOLEN
YOUR IDENTITY
STEP 1: Place an initial fraud alert on your credit report STEP 2: Order your credit reports
STEP 3: Create an Identity Theft Report
STEP 4: File an identity theft complaint with the FTC
44
Your FTC Affidavit and police report
make an Identity Theft Report.
Physical Security
• Restricted access
• Guards on site 24 / 7
• Video surveillance
• Identification badges
HOW DOES RAYMOND JAMES PROTECT
YOUR PERSONAL INFORMATION
46
Employee Training
• Annual training on privacy, security, and ethics
• Policies and procedures for client data
protection
• New hires attend security-awareness training
• Privacy training annually to departments with
client information
HOW DOES RAYMOND JAMES PROTECT
YOUR PERSONAL INFORMATION
Business Continuity
• Dedicated employees certified in Disaster Recover
• Remote data center in low risk geographical
location
• Tabletop exercises throughout the year
• Operations centers in 3 states
HOW DOES RAYMOND JAMES PROTECT
YOUR PERSONAL INFORMATION
48