Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

Friday, April 24, 2020

Children are at risk of net addiction: Survey

Children and young people could be at a higher risk of internet addiction, gaming addiction and exposure to adult contents, according to a survey.
They could also be at a higher risk of online sexual abuse and exploitation, the ‘Survey on Changed Online Behaviour During Covid-19 Lock down in Nepal,’ conducted by ChildSafeNet reads.
Although the government banned pornographic sites in Nepal, more than 41 per cent respondents, including children and young people said they had visited such sites, the survey result reads, recommending addressing issues like this. “Detailed and thematic researches are required to develop in-depth knowledgebase to address the issue of online safety of children and young people during and after the lock down period.”
They surf youtube most of the time and facebook seconds the most searched sites, according to the survey that has also recommended conducting cyber safety awareness sessions for children, young people and parents through online and virtual awareness activities through social media and video conferencing sessions. “Video conferencing workshops on 'Parenting in the Digital Age' can help to equip parents with knowledge and skills to keep children and young people safe online,” it recommends, adding that the workshops will help to provide guidance to parents on reducing their own screen time, learn about cyber safety and lead by example to protect children and young people from online harms. “Educate children, young people and parents on the positive use of the internet and provide them information on sites and apps suitable for children.”
It also recommends to inform about useful and suitable sites according to their age and requirements. Asking to develop simple and easy cyber safety resources in Nepali and local languages for dissemination through online media, including, but not limited to social media, it has also suggested to operate a dedicated online helpline to provide tips, advice and support to people who experience online harms or at risk; refer to support services - police, psychologists, lawyers, social workers. “Strengthen law enforcement to report online abuses and make reporting accessible throughout the country.”
ChildSafeNet – a non-governmental organisation, established with a mission to make the digital technology safer for children and young people – also recommends advocating for more financial and technical resources from the government, ICT companies and other duty-bearers to make the internet safer for children, young people and everyone.
According to the president of ChildSafeNet Anil Raghuvanshi, the ‘Survey on Changed Online Behaviour During Covid-19 Lockdown in Nepal’, was conducted in all provinces of the country using online Google forms, distributed through social media platforms. The survey, self-administered by respondents started on April 17, 2020 till April 21, 2020. The survey was conducted with young children, young people and adults. Since the behaviour of adults may affect children in many ways, the survey also collected information on adults' online behaviour. “A total of 1,228 respondents – some 648 male, 576 and 4 other – had participated in the survey.
Due to the Covid-19 pandemic, the government imposed a country-wide lockdown in Nepal from March 24, 2020. As a result, schools, colleges and offices are closed, and people are staying at home spending a longer time using internet, which has increased the risk of online abuse and exploitation, particularly to children and young people as child online groomers and online sex predators may contact them for abuse and exploitation.
According to Nepal Telecommunications Authority (NTA), some 72.16 per cent people have access to broadband internet and 55.30 per cent use mobile broadband internet. Facebook is the most used social media platform in Nepal with 11 million active, it reads, adding that the number of Facebook users, particularly among young age groups declined globally and in Nepal. “However, the number of Facebook users increased by 600,000 from November 2019 to April 2020.”

Tuesday, September 10, 2019

Security audit of BFIs mandatory

The central bank has asked the banks and financial institutions to implement precautionary measures to minimise the possible threat on their cyber security infrastructure.
The central bank has made it mandatory for the banks and financial institutions (BFIs) to conduct an audit of their information and technology (IT) system regularly after the recent ATM hacking exposed significant security vulnerabilities in the banking system. Almost two weeks ago, the Chinese hackers withdrew millions through ATMs of different banks through malware attack.
Issuing a three-point directive to bank and financial institutions (BFIs) to address and manage internal and external risks in use of information technology (IT) today, the central bank has also instructed BFIs to carry out regular monitoring and reporting of their systems and share information of any incident or attack to the respective agencies.
Stating that there have been attempts to infiltrate the systems of banks and financial institutions from unauthorised people or places by placing fake order or correspondences, the central bank directed BFIs to regularly audit their IT system and promptly address the IT and security flaws that are detected. It has also directed BFIs to adopt best international practices in the IT and security system at their respective firms. The central bank has also directed the BFIs to prepare preventive, detective and responsive IT security strategies and implement them as soon as possible.
The central bank has also asked to take necessary measures to minimise external risks such as spam, phishing and spoofing, among others that could result in the loss and theft of data. “The BFIs must standardise technologies related to perimeter defence, access control, encryption, anti-virus and firewall to cope up with possible risks regarding cyber attack, malware virus and ransomware at BFI’s website, mobile applications, authenticated social networks and the entire information and technology system,” the directive reads, adding that the BFIs should also raise awareness among office bearers on IT and security issues.
Malware – a type of software – is used to infiltrate and damage the entire network system. Likewise, ransomware variants encrypt the files on the affected computer making the files inaccessible to the concerned authority. The hackers mainly use the software to block access to a computer system or computer files until a sum of money is paid.
The central bank's directives to take precautionary moves comes in the wake of recent ATM heist in Kathmandu, where a group of hackers has stolen over Rs 18.9 million by hacking the payment switch of Nepal Electronic Payment System (NEPS) through use of cloned debit and credit cards of 17 member banks of the NEPS that use Visa system, according to preliminary findings of the central bank. “Likewise, Rs 1.05 million Indian Currency (IC) was stolen in India from six commercial banks of Nepal on the same day, according to the findings.
Earlier today, the central bank also summoned chief executive officers of banks and financial institutions to discuss about security measures to check cyber attack or threats to their IT system. During the meeting, central bank Governor Dr Chiranjibi Nepal instructed the chief executives to keep vigil over their systems, particularly during the festive season as the banks and financial institutions will have longer holidays in those days.
The central bank has also lowered the maximum limit for cash withdrawal using debit card from last Thursday as part of security measures, though the hackers will anyway use malware to withdraw any amount as they did last Saturday.

Tuesday, September 3, 2019

Central bank mulls stricter security policy

The central bank is mulling to introduce stricter cybersecurity policy as the Saturday’s hacking on various ATMs in Kathmandu have exposed significant security vulnerabilities in the Nepali banking system.
The central bank is amending its cyber security directive making banks and financial institutions (BFIs) adopt sophisticated technology to prevent the sporadic cyber and malware attacks in the banking system. Some Chinese nationals stole millions from ATMs of different banks few days ago also due to poor IT security among BFIs to cope with cyber and malware attacks, which is not the first time in Nepal.
The central bank will introduce a few provisions for BFIs related to cyber security as soon as the investigation on Saturday’s banking heist concludes, the central bank said, adding that the BFIs should be aware of such cyber attacks and adopt sophisticated technologies.
The central bank has also formed a probe committee led by head of Department of Payment System at the Nepal Rastra Bank (NRB) Bam Bahadur Mishra to investigate the ATM Freud. “The committee will prepare its preliminary report by midnight today and submit it to the central bank by tomorrow,” he said, adding that the Chinese hackers have withdrawn substantial amount of money from those ATM boths. The central bank has, however, earlier said that the the BFIs have notified the regulator that the hackers have withdrawn Rs 16.87 million in Nepali currency from ATM cards of different banks and Rs 10.5 million Indian Currency (IC) from ATM booths in India through the use of Nepali ATM cards.
The Nepali ATM cards are used in India also.
The Police claimed that it has recovered around Rs 12.63 million from the five Chinese nationals and suspected rest of the cash looted from Nepal have been carried away by absconders.
“But the details of the heist and the amount withdrawn by hackers will be available only after the digital forensic test, which will take more than a week,” Mishra added.
The hackers, according to Police, used electronic cards of at least six banks – NIC Asia, Siddhartha, Janata, Global IME, Prabhu and Sunrise – and used them at ATMs of three banks – Nabil, Nepal Investment and Nepal SBI – to illegally withdraw the money frpm ATM booths as the BFIs failed to conduct periodic security audits, comply with the latest technology and invest adequately in digital security.
Police has arrested a Chinese citizen Zhu Lianang on Saturday night from a Nabil Bank ATM booth in Durbar Marg, while attempting to withdraw cash. Zhu named four other Chinese nationals, who were involved in stealing cash from ATMs by using cloned debit cards to breach processing systems.
Although the central bank has made it mandatory for banks to conduct information security audits, many banks have not been allocating an adequate budget for a proper audit.
Despite banks making record profits year after year, the BFIs are blamed for not investment in digital security. In the last fiscal year, commercial banks made a net profit of over Rs 60 billion, with almost all of them posting net profits of more than Rs 1 billion each, according to the central bank.
Although most banks have transitioned to debit and credit cards with microchips, there are still a few banks that still use magnetic strips in their cards, which poses a vulnerability. Banks fail to follow security protocols for Swift and governance risk compliance systems for the Nepal Electronic Payment Systems (NEPS) – a local interface that allows transactions of money deposited in one bank using cards issued by other member banks – which should also have management oversight and an independent audit system.
Nepali BFIs currently use different types of software including Finacle, Temenos T24 and different editions of Pumori Plus.