Prof_Marcos A only

profilepzftoresc8h5
CHALLENGESFORENSURINGTHEDATASECURITYOFCOMMERCIALBANKS..pdf

CHALLENGES FOR ENSURING THE DATA SECURITY …

7

CHALLENGES FOR ENSURING THE DATA SECURITY OF COMMERCIAL BANKS

Prof. Bojidar Вojinov, РhD

Abstract: The introduction of new information and communication technology into banking has radically altered the essence and character of banking activity. Alongside the competitive advantages and the direct economic effect of the advent of high-tech innovation in the banking sector, credit institutions are facing a number of challenges, one of them being to ensure the security of their products and related information. The main objective of this research is to elucidate the nature, instances, and methods of managing data security in commercial banks. An emphasis is put on some sources of operational risk in commercial banks which have a direct impact on the potentially growing risk in terms of data security. The research also focuses on the role of bank management in governing that process, as well as the methods and mechanisms for reducing the occurrence of the risk related to information security.

Key words: banks, data security, information technology, distance banking, online banking.

JEL: G21.

Introduction The advent of new information and communication technology in

banking has gradually, yet radically altered the essence and character of banking activity. From a historical perspective, the adoption of innovative communication methods has helped reduce price differentials in geographically distant markets. In terms of organisation, technological innovations have contributed to the more efficient integration and communication between departments and to expanding the product range

technologies

Prof. Bojidar Вojinov, РhD

8 50 Years Department of Business Informatics

and distribution channels of retail banks. 1 Alongside the competitive

advantages and the direct economic effect of the advent of high-tech innovation in the banking sector, credit institutions are facing a number of challenges, one of them being to ensure the security of their products and related information

2 .

The main objective of this research is to elucidate the nature, instances, and methods of managing data security in commercial banks. Hence, the object of the research is data security of bank assets, while the subject focuses on available opportunities for efficiently managing that security.

* * * There is no generally accepted definition or uniform approach to the

essence and scope of data security in specialised literature 3 . Within a

1 See: Batiz-Lazo, B., Wood, D. Information technology innovations and

commercial banking: a review and appraisal from an historical perspective. Accounting and finance research unit, Manchester Business School, The University of Manchester, 2001, ISBN 0 7492 45476, p. 3.

2 Bank security is an instance of the commitment of banks to ensure the safe

storage and management of customers’ and banks’ assets and related data, as well as to guarantee the physical security and safety of clients and employees in bank offices. Specialised dictionaries define the term ‘security’ as the ‘physical security, internal audits, and prescribed procedures for ensuring the safety of customers and accounting records’ and ‘protection from attacks; confidentiality; warranty that deposited money will be paid back’. In economic literature, the term is generally approached as ‘creating an environment in which dangerous conditions or circumstances are absent or their possible consequences are reduced to such a level that they would not be detrimental to the smooth functioning of a bank, its property, or infrastructure, or prevent banks from achieving their goals’; and protection from hazards related to the conscious actions of individuals or legal entities and designed to cause damage to a bank. See: Shishmanov, K. Izpolzvaneto na savremennite informatsionni tehnologii v bankovoto

delo - predizvikatelstvo i realnost. // Finansova stabilizatsiya i ikonomicheski rastezh: Mezhdunarodna nauchno-prakticheska konferenciya, Svishtov, 2000, p. 121; Fitch, T. Dictionary of Banking terms. Barrons’s, 1997, p. 413; Dictionary of Banking and Finance. A&C Black Publishers Ltd, 2005, p. 319; Lavrushin, O. I. Bankovskii menedzhment. Moskva, Kronus, 2009, p. 519; Alaverdov, A.R. Organizaciya i

upravlenie bezopasnost’yu v kreditno-finansovyh organizatsiyah. Moskovskaya finansovo-promyshlennaya akademiya. Moskva, 2004, p. 6.

3 For further reading on issues related to general bank security, its varieties

and forms, see: Bojinov, B. Bankovata sigurnost – osnovni proyavleniya i aspekti. //

Narodnostopanski arhiv, No. 3, 2016.

CHALLENGES FOR ENSURING THE DATA SECURITY …

9

broader context, data security refers to all aspects of managing and preserving the integrity of the data processed by a particular entity, whatever the technical device used to store or process that data. Within the context of society computerization, the term ‘data security’ has acquired a narrower meaning to refer solely to the process of managing and ensuring the security of electronic data only. The scope of the concept has evolved, too, and from initially referring to the set of measures for protecting data from unauthorized access, nowadays it comprises the entire range of measures for preventing and dealing with problems in the operation of IT systems, alongside the measures adopted to protect information flows from unauthorized access or use.

At the same time, data security directly relates to the occurrence of operational risk in the banking sector

4 and is a direct consequence of

operational problems, organizational changes, lack of or inadequate procedures, no segregation of duties, insufficiently or inadequately trained staff, internal control violations, fraud or unpredicted events which may result in contingent losses, errors, delays in the fulfilment of tasks, IT system failures, fires and disasters which lead to the destruction of assets or data.

5

The most common sources of operational risk which affect data security relate to

6 :

 Staff (the human factor), and in particular: o Inadvertent and/or incompetent actions relating to lack of

adequate skills and knowledge; inadequate training; lack of awareness about performance standards; employed methods, tools, and procedures; negligence; technical errors; inadequate control, etc.;

o Deliberate actions related to unauthorized transacting; theft; forgery of data in the accounting system; forgery of financial and payment documents; theft of cash; hacking; breach of bank rules and procedures;

4 For further reading on issues related to bank risks, see: Bojinov, B.

Upravlenie na riskovete v targovskata banka. Obrazovanie i nauka, No. 58, Tsenov, Svishtov, 2013.

5 See: Dimitrova, T. Vatreshniyat odit – efektiven instrument na bankoviya

menidzhmant, Obrazovanie i nauka, No. 38, Tsenov, Svishtov, 2013, p. 87 6 See further: Trifonova, S. Upravlenie na operatsionniya risk na bankite.

Vatreshen oditor, No. 7, N 1, 2010.

Prof. Bojidar Вojinov, РhD

10 50 Years Department of Business Informatics

money laundering; insider trading, and other intentional acts for the purpose of personal gain;

o Poor planning and management of personnel – staff shortage and its replacement with insufficiently trained or qualified staff; sick leaves; staff turnover, etc.;

o Affecting customers’ interests through breach of bank secrecy; disclosure of personal and/or confidential information; damaging the interests of clients, etc.;

 Internal processes – breaches in prescribed rules, guidelines, processes, policies and control procedures; poor risk assessment and risk measurement in result of errors or omissions in applied models;

 Systems – problems in the IT systems which lead to a partial or complete interruption of bank operations. Those could be divided into:

o General systematic risks related to restricted access to systems and networks; inadequate procedures for data backup and recovery; anti-virus and malware protection policy; policy on restricting unauthorized access to the systems, etc.;

o Risks related to the software used, which may be due to system failures; errors in computation and/or reporting of operations and other programming errors in result of obsolete and/or inadequate technology; unauthorized access to customer data and accounts; data back-up problems, etc.;

o Risks related to the hardware, which refer mainly to using out-dated or poor quality computer systems; lack of crucial backup servers and hardware items; lack of backup and recovery systems; lack of emergency power systems, etc.

 External factors related to: o Force majeure – disasters, fires, vandalism, terrorist attacks,

etc.; o Deliberate third-party actions – robbery, fraud on behalf of

the bank, hacker attacks, illegal access to customer accounts, other deliberate actions;

o Risks related to service providers – providers of telephone services, power supply, telecommunications, outsourcing services, etc.

CHALLENGES FOR ENSURING THE DATA SECURITY …

11

A specific feature of bank activity is the confidentiality requirement in terms of borrowed and managed funds and their owners, which relates directly to the trust-based relationship between banks and their customers. This is also one of the reasons why banks are extremely reluctant to disclose their problems, including any incidents and security breaches in their information systems. Such information generally leaks out only after a financial crime has been detected, through independent specialised institutions, or when intruders themselves publicly announce their breakthrough.

7 We should note that according to statistics only 7 % of all

bank crime is committed using computer and IT technology. 8

Fig. 3 Frequency of occurrence of major risks related to bank fraud

9

7 Hakeri iztochili $71 mln. ot banka prez SWIFT.

http://technews.bg/article-90580.html (last access on 29.05.2016); Hakeri atakuvaha sayta na gradskata tsentralna banka. http://news.bnt.bg/bg/a/khakeri-atakuvakha-sayta-na-grtskata-tsentralna-banka (last access on 29.05.2016); Hakeri sa iztochvali sredstva ot blizo 100 banki po sveta. http://www.capital.bg/ biznes/kompanii/2015/02/16/2473701_hakeri_sa_iztochvali_sredstva_ot_blizo_100_ba nki_po/ (last access on 29.05.2016)

8 See: Zvezda, I. I. K voprosu o klassifikatsii sposobov mo-shennichestva v

bankovskoy sfere. // Izvestiya Tulyskogo gosudarstvennogo universiteta. Ekonomi- cheskie i yuridicheskie nauki, 2015, volume 3-2, 97-105, p. 99.

9 Deloitte - India Banking Fraud Survey - Edition II, 2015, p. 27.

Prof. Bojidar Вojinov, РhD

12 50 Years Department of Business Informatics

Major attacks on the data security of bank systems through theft, manipulation, or destruction of data are an attempt either to get rich quickly or to cover or commit another crime. These relate mainly to:

10

 ID related fraud committed to take over the accounts of third parties or to open accounts and acquire financial instruments through false identity. While the aim of the first type of crime is direct theft of cash, the second type of crime is generally part of a complex criminal scheme for committing commercial, financial, insurance, or tax fraud;

 Acquiring confidential information to engage in various espionage activities, in most cases to collect information about a business or a family partner, as well as to gain access to internal information which could be used for future enrichment;

 Exploiting existing bank infrastructure to commit financial and tax crime. In addition to financial, commercial, and tax fraud which involves the bank accounts of real and/or fictional persons and companies, organized crime also uses the bank system to conceal the true origin of funds acquired illegitimately and to facilitate their infiltration and integration into legal economy (a process known as ‘money laundering’

11 );

 Cybercrimes 12

are in most cases designed to steal funds, yet they may be committed to conceal evidence of other crime by destroying all

10 Adapted after: Lagazio, M., Sherif, N., Cushman, M. A multi-level Approach

to understanding the Impact of Cyber Crime on the Financial Sector. p.8. 11

The term ‘money laundering’, which is used as an umbrella term for legitimising ill-gotten gains, describes the practice of American mafia which used to filter in cash from gambling as earnings received from the laundromat business. Meyer Lansky, Al Capone’s financial advisor, is believed to have been the first person to exploit the bank system for legitimizing earnings from criminal business during the Prohibition in the Unites States. See: Storm, A. Establishing The Link Between Money Laundering And Tax Evasion. The Clute Institute International Academic Conference Munich, Germany 2014, p. 1; Alacer. Happy Birthday, Anti Money Laundering! http://www.alacergroup.com/happy-birthday-anti- money-laundering/ (last access 11.6.2016).

12 Specialised literature distinguishes among several categories of cyber crime:

traditional crime, hybrid cyber crime, true cyber crime, and cyber platform crime. Traditional cyber crime relates to exploiting cyberspace as providing more opportunity for crime (for example, traditional fraud, piracy, espionage, stalking, trading sexual material). Hybrid cyber crimes mainly relates to the activity of criminal groups which benefit from new opportunities provided by the Internet (such as ID theft, hacking, hactivism, illegal online trade). True cyber crime relies on the opportunities created purely by the Internet and is carried out entirely within the cyberspace (for example, spam, denial of service, illicit cyber sex). Cyber platform crimes (botnets, for instance) are committed to facilitate other types of crime, rather than to directly carry out criminal activity.

CHALLENGES FOR ENSURING THE DATA SECURITY …

13

currently accessible or back-up data at a bank. Cyber terrorism and information warfare

13 , despite having different origins and objectives, pose

a serious threat to bank activity, too, since both aim to totally destroy data and IT infrastructure, to interrupt normal business processes, and to cause problems to banks, the financial system, and economy in general.

Fig. 4 Major impacts of data security problems upon bank institutions

14

The major type of damage suffered by banks due to breaches of

data security relate to: 15

See further: Lagazio, M., Sherif, N., Cushman, M. A multi-level approach to

understanding the impact of cyber crime on the financial sector. p. 7. 13

Kiberterorizam – zaplaha otvad virtualnoto prostranstvo. http://news.unabg.org/ kiberterorizam-zaplaha-otvad-virtualnoto-prostranstvo/ (last access 11.06.2016); Male, P. Zaplahata ot kiberterorizma pridobiva ochertaniya.

http://e-vestnik.bg/16797/zaplahata-ot-kiberterorizma-pridobiva-ochertaniya/ (last access 11.06.2016).

14 Deloitte - India Banking Fraud Survey - Edition II, 2015, p. 13.

15 Adapted and supplemented after: Lagazio, M., Sherif, N., Cushman, M. A multi-

level approach to understanding the impact of cyber crime on the financial sector. p. 11-12.

Претърпени действителни финасови загуби от кибератаката

Регулаторни рискове

Разходи за разследване и оценка на загубите и

щетите Накърняване на репутацията

Кражба или загуба на лична информация

Разрушаване на услугите

Кражба на IP,

вкл. и кражба на данни

Prof. Bojidar Вojinov, РhD

14 50 Years Department of Business Informatics

 Direct financial losses due to theft of funds held and managed by the commercial bank;

 Indirect financial losses due to regulatory fines, legal costs, recovery and clean-up costs, loss of customer trust and loyalty;

 Image costs which relate to the loss of public and customer trust due to the public disclosure of data security breaches and leakage of confidential information about bank transactions, customers, money laundering, involvement in criminal schemes, etc.

 Opportunity costs due to accidents with data security within a bank which, in addition to the two items above, also refer to the deteriorating competitiveness of a bank; shifts in internal and organisational priorities; reduced workload which affects operating profit, etc.;

 Defence costs which include costs for designing IT and communication infrastructure to prevent attacks and ensure the fault- tolerance of bank IT systems, as well as costs related to the deployment of organisational measures to increase data security and to improve the training and awareness of staff and customers in terms of newly emerging IT risks and their prevention.

Managers of commercial banks have a crucial role in the process of managing data security within the overall process of operational risks management.

16 Hence, the Board of Directors has the responsibility to

design and develop an operational framework for managing the risk related to data security; to determine the maximum tolerance of the institution to this type of risk; and to ensure adequate capital to secure the risk which the bank takes. The operational framework may be approached as a set of policies and strategies adopted by banks in the sphere of data security; the methods that banks employ to identify, assess and minimize risk, as well as their organizational structure, powers, and responsibilities in terms of risk management.

17

16

For further reading on issues related to the management of bank risks, see: Bojinov, B. Upravlenie na riskovete v targovskata banka. Obrazovanie i nauka, No.

58, Tsenov, Svishtov, 2013. 17

For further reading on issues related to bank policies, see: Bojinov, B.

Aktualni aspekti na bankovata politika. Obrazovanie i nauka, No. 50, Tsenov, Svishtov, 2013.

CHALLENGES FOR ENSURING THE DATA SECURITY …

15

The role of senior bank management in this process relates to establishing the prerequisites for the efficient introduction and implementation of the policies, strategies, and procedures which the Board has prescribed and approved for managing the risk related to data security, as well as its direct responsibilities in terms of general management, assessment and monitoring of the overall process and the implementation of corrective actions in case of identified deficiencies and omissions, or changes in the internal and/or external environment.

Some of the measures adopted to increase data security also relate to the recruitment and training of bank officers; upgrading the hardware and software products which banks use; as well as the implementation of efficient internal control policies.

Fig. 5. Principle technology for ensuring data security at commercial banks

18

18

See: Tyutyunnik, A. V., Turbanov A.V. Bankovskoe delo. Finansii i statis-

tika, Moskva, 2005, p. 458.

Бизнес процеси

ОБЩА ПОЛИТИКА ПО ИНФОРМАЦИОННА БЕЗОПАСНОСТ

Очаквани рискове и заплахи

Използвани технологии

Концепция за информационна безопасност

Модел за защита и възстановяване на информацията

Определяне на технически средства за защита и възстановяване на информацията

Изработване на правила за информационна безопасност при работа с информационните

системи на банковите служителите и на потребителите (банковите клиенти)

Мониторинг Инсталиране и експлоатация

на техническите средства

Анализ на безопасността при експлоатацията на информационните системи

Възстановяване на системите и отстраняване на щетите

Prof. Bojidar Вojinov, РhD

16 50 Years Department of Business Informatics

The operational management of the risk related to data security is usually the responsibility of specialised information security units which may report directly to IT departments or to Risk Management Committees. Direct supervision on the activity of bank employees by their line managers in terms of compliance with established rules and procedures for internal control is, of course, an important condition for reducing the risk of internal bank fraud and omissions. Inasmuch as the risk related to data security belongs to the category of the so called ‘pure risks’, i.e. it may only incur losses, the major approaches related to its management refer to:

 Risk aversion – this approach is only applicable to certain aspects of the risk which banks are able to avoid (for example, by refusing to provide remote banking);

 Risk taking by providing reserves which may be statutory (for example, in compliance with Ordinance No. 8 of the Bulgarian National Bank) or voluntary;

 Risk transferring to third parties, including through insurance, hiring outside providers of IT services, and any other applicable methods;

 Risk minimization through assessment; adequate procedures for process management, reporting, and efficient internal control; recruitment, training and qualification of bank employees;

 Risk diversification (only applicable to certain aspects of operational risk, mainly related to systems and software) by introducing mechanisms to back up exploited technological, technical, and communication solutions; outside providers of services; alternative methods for providing services, etc.

The fast rate of development of IT and communication technology and the advent of hi-tech innovations in all spheres of human life force banks to identify adequate tools for the operational management and minimization of risks related to their data security. Some of the latest approaches in this aspect include the deployment of multi-factor authentication; geo-location; device recognition; cross channels to monitor and analyse user behaviour, etc.

19

19

ACI Univercal Payment. Fighting online fraud: an industry perspective. volume 3, 2014, p. 5-6.

CHALLENGES FOR ENSURING THE DATA SECURITY …

17

Fig. 6. Major aspects of improving data security with remote banking

20

Multi-factor authentication relates to the deployment of a multi-step

process for unique user identification in which, in addition to standard user names and passwords, various devices and methods are used alongside some private information provided by bank clients during the account opening phase (such as their favourite football team, the brand of their first car, their pets, etc.) so that they could be uniquely recognized by banks’ automated IT systems. As for the devices and equipment which banks employ for user authentication, in most cases these are tokens which generate random numbers; USB devices containing login credentials or other unique information; notifications delivered as text messages (including about sending a single confirmation code).

20

See:Vizgunov, A., Vizgunov, Ar. Uroven’ zashtishtennosti ot nesanktsio-

norovannogo dostupa kak klyuchevoy pokazatel’ kachestva sistemy distantsionnogo bankovskogo obsluzhivaniya. Informatsionnye tehnologii v biznese, Biznes-informa- tika, No.2 (12), 2010, p. 39.

Основни направления на развитие на системите за информационна

безопасност на отдалеченото банкиране

Детайлизация на изискванията за гарантиране на безопасността

при работа със системата

Технологични решения

Мерки

от организационен характер

Усъвършенстване на документацията за

работа със системата

Информиране на клиентите за

нововъзникващите заплахи

Уточняване на процедурата за проверка на спорни документи

Технологии предотвратяващи достъпа до системата на неупълномощени лица

Технологии позволяващи откриване на измамни операции в системата

SMS информиране на клиенти (за влизане в система,

извършване на операции и др.)

Възможност за преглеждане на информация за предишни

влизания в системата

Автоматизиран контрол на подозрителни документи

Използване на апаратни решения за

криптозащита

Използване на виртуална клавиатура за въвеждане

на парола

Използване на еднократни пароли за

вход в системата

Изпращане на пароли чрез SMS

Използване на токън устройство за

генериране на парола

Ограничаване на достъп до системата чрез

контрол на IP/ MAC адрес

Предоставяне на банковите клиенти

антивирусен софтуер

Използване на списък от пароли на

скейтч-карта

Prof. Bojidar Вojinov, РhD

18 50 Years Department of Business Informatics

Banks have recently started using the MAC addresses of their customers’ devices (computers, tablets, telephones) and geo-location services (through IP addresses or GPS) to assess the potential risk of conducted transactions and to request further information for the unique identification of ordering parties in transactions. Furthermore, automated expert systems are increasingly introduced by banks to analyse consumer behaviour (for example, the usual time they log in, their typical actions, the typical amount, frequency, direction and means of payment, the devices they use) and thus detect any irregularities (the so called ‘red flags’) which indicate a potential fraud attempt, including through identity theft.

Over the last years, banks have started integrating ‘disaster recovery plans’ into their data security management policies. Those plans include measures for identifying and designing alternative mechanisms and channels to resume their services in case they are interrupted (through back-up equipment, technology, communication links, emergency power systems, etc.); designing backup systems ensuring quick recovery of data archives at minimum or no loss of data (building clusters, applying virtualization systems, real time data duplication, high backup frequency to ensure minimum loss of data) and creating Disaster Recovery centres including by using external providers or cloud services.

Conclusion Globalisation and digitization processes have been altering

slowly, yet irreversibly all aspects of contemporary society. While providing new opportunities and facilities, these processes also pose new risks and challenges, hence the growing importance of data and data security in the new digital environment. The only available solution for commercial banks is to adapt to and evolve in the new circumstances, which requires digitization and automation of existing processes; exploitation of new distribution channels to offer bank products and services; as well as creating new products and services. Hence, data security risk management has become a new key aspect of bank risk management and the overall management of bank establishments.

CHALLENGES FOR ENSURING THE DATA SECURITY …

19

References 1. ACI Univercal Payment. Fighting online fraud: an industry

perspective. volume 3, 2014. 2. Alaverdov, A. R. Organizaciya i upravlenie bezopasnost’yu v

kreditno-finansovyh organizatsiyah. Moskovskaya finansovo- akademiya. Moskva, 2004.

3. Batiz-Lazo, B., Wood, D. Information technology innovations and commercial banking: a review and appraisal from an historical perspe- ctive. Accounting and finance research unit, Manchester Business School, The University of Manchester, 2001.

4. Bojinov, B. Aktualni aspekti na bankovata politika. Obrazo- vanie i nauka, No. 50, Tsenov, Svishtov, 2013.

5. Bojinov, B. Bankovata sigurnost – osnovni proyavleniya i aspekti. Narodnostopanski arhiv, No. 3, 2016.

6. Bojinov, B. Upravlenie na riskovete v targovskata banka. Obra- zovanie i nauka, No. 58, Tsenov, Svishtov, 2013.

7. Deloitte - India Banking Fraud Survey - Edition II, 2015. 8. Dictionary of Banking and Finance. A&C Black Publishers Ltd,

2005. 9. Financial Fraud Action UK. News release 10. Fitch, T. Dictionary of Banking terms. Barrons’s, 1997. 11. Dimitrova, T. Vatreshniyat odit – efektiven instrument na banko-

viya menidzhmant, Obrazovanie i nauka, No. 38, Tsenov, Svishtov, 2013. 12. Lagazio, M., Sherif, N., Cushman, M. A multi-level Approach

to understanding the Impact of Cyber Crime on the Financial Sector. 13. Lavrushin, O. I. Bankovskii menedzhment. Moskva, Kronus, 2009. 14. Shishmanov, K. Izpolzvaneto na savremennite informa-

tsionni tehnologii v bankovoto delo – predizvikatelstvo i realnost. // Finan- sova stabilizatsiya i ikonomicheski rastezh: Mezhdunarodna nauchno- prakticheska konferenciya, Svishtov, 2000, p. 119-122.

15. Shishmanov, K. Riskovete pri izpolzvaneto na internet ban- kiraneto i otgovornostta na potrebitelite. // Finansite i stopanskata otchet- nost – sastoyanie, tendencii, perspektivi : Yubileyna mezhdunarodna nauchnoprakticheska konferenciya, Conference proceedings , V. 1, Svishtov , 2013, p. 79-84.

Prof. Bojidar Вojinov, РhD

20 50 Years Department of Business Informatics

16. Storm, A. Establishing The Link Between Money Laundering And Tax Evasion. The Clute Institute International Academic Conference Munich, Germany 2014.

17. Trifonova, S. Upravlenie na operacionniya risk na bankite. // Vatreshen oditor, No. 7, N 1, 2010.

18. Tyutyunnik , A. V., Turbanov A. V. Bankovskoe delo. Finansii i statistika, Moskva, 2005.

19. Vizgunov, A., Vizgunov, Ar. Uroven’ zashtishtennosti ot ne- sanktsionorovannogo dostupa kak klyuchevoy pokazatel’ kachestva sistemy distantsionnogo bankovskogo obsluzhivaniya. Informatsionnye tehnologii v biznese, Biznes-informatika, No.2 (12), 2010.

20. Zvezda, I. I. K voprosu o klassifikatsii sposobov mo-shen- nichestva v bankovskoy sfere. // Izvestiya Tulyskogo gosudarst-vennogo universiteta. Ekonomicheskie i yuridicheskie nauki, 2015, volume 3-2, 97-105.

Internet Sources

21. Alacer. Happy Birthday, Anti Money Laundering! http://www.alacergroup.com/happy-birthday-anti-money-laundering/ (last access 11.06.2016).

22. Hakeri atakuvaha sayta na gradskata tsentralna banka. http://news.bnt.bg/bg/a/khakeri-atakuvakha-sayta-na-grtskata-tsentralna- banka (last access 29.05.2016).

23. Hakeri iztochili $71 mln. ot banka prez SWIFT. http://technews.bg/article-90580.html (last access 29.05.2016).

24. Hakeri sa iztochvali sredstva ot blizo 100 banki po sveta. http://www.capital.bg/biznes/kompanii/2015/02/16/2473701_hakeri_sa_izto chvali_sredstva_ot_blizo_100_banki_po/ (last access 29.05. 2016).

25. Kiberterorizam – zaplaha otvad virtualnoto prostranstvo. http://news.unabg.org/kiberterorizam-zaplaha-otvad-virtualnoto-prostrans- tvo (last access 11.06.2016).

26. Male, P. Zaplahata ot kiberterorizma pridobiva ochertaniya. http://e-vestnik.bg/16797/zaplahata-ot-kiberterorizma-pridobiva-ocherta- niya/ (last access 11.06.2016).

Copyright of Business Management / Biznes Upravlenie is the property of D.A.Tsenov Academy of Economics and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.