• Reconcile and review all banking transactions on a daily basis.
  • Initiate wire transfer payments only under dual control, with a transaction originator
    and a separate transaction authorizer.
  • Use tokens for all online transactions to provide an additional layer of authentication.

 
 

Computer systems best practices (including but not limited to):
  • If possible, carry out all online banking activities from a stand-alone, hardened and completely locked down computer system from which e-mail and Web browsing (beyond the secure online banking site) is not possible.
  • Be suspicious of e-mails purporting to be from a financial institution, government department or other agency requesting account information, account verification or banking access credentials such as usernames, passwords, PIN codes and similar information.
  • Opening file attachments or clicking on web links in suspicious emails could expose the
    system to malicious code that could hijack your computer.
  • Install a dedicated, actively managed firewall, especially if they have a broadband or dedicated connection to the Internet, such as DSL or cable. A firewall limits the potential for unauthorized access to a network and computers.
  • Limit administrative rights on users’ workstations to help prevent the inadvertent downloading of malware or other viruses.
  • Install commercial anti-virus and desktop firewall software on all computer systems.
  • Free software may not provide protection against the latest threats compared with an industry standard product.
  • Ensure virus protection and security software are updated regularly.
  • Ensure computers are updated regularly particularly the operating system and key applications with security updates. It may be possible to sign up for automatic updates for the operating system and many applications.
  • Consider installing spyware detection programs.
  • Recommend clearing the browser cache before starting an Online Banking session in order to eliminate copies of web pages that have been stored on the hard drive. How the cache is cleared will depend on the browser and version. This function is generally found in the browser’s preferences menu.

 
 

Online Best Practices (including but not limited to):
  • Train staff with access to online accounts on best practices to be used online.
  • Create a strong password with at least 10 characters that include a combination of mixed case letters, numbers and special characters and change that password regularly.
  • Prohibit the use of “shared” user names and passwords for online banking systems.
  • Use a different password for each website that is accessed.
  • Never share username and password information for Online Services with third-party providers.
  • Verify use of a secure session (https not http) in the browser for all online banking.
  • Avoid using an automatic login features that save usernames and passwords for online banking.
  • Never leave a computer unattended while using any online banking or investing service.
  • Never access bank, brokerage or other financial services information at Internet cafes, public libraries, etc. Unauthorized software may have been installed to trap account number and sign on information leaving you vulnerable to possible fraud.