Wednesday | 8 October, 2008
Computerworld
RSA Security CEO chats up anti-fraud services
Ellen Messmer (Network World) 27/06/2006 11:27:30

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    9 Paths to Higher Performance 10/12/2007 14:09:23

    When an organization brings together talented people in a creative, collaborative environment it fosters a culture of high performance, which in turn leads to superior business results
    Like high-achieving individuals, some organizations seem to have the Midas touch. Virtually every initiative they touch earns them gold and even those that fail never seem to cost them much of anything at all
  • +

    Process Trip 04/02/2008 13:07:03

    Why Maritz Travel revamped key business processes — and how business and IT came together to make it work
    When Rich Phillips became COO OF Maritz Travel about two and-a-half years ago, he sat down and took a hard look at the big industry picture
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

RSA Security late last year acquired privately-held Cyota, which offers online security and anti-fraud services to help financial institutions protect consumer accounts. Art Coviello, CEO of RSA Security, recently sat down with Network World's senior editor Ellen Messmer to discuss the Cyota acquisition and RSA's views on the future of authentication.

Cyota with its anti-fraud services for banks is a very different type of business than RSA Security has traditionally been in with its SecurID products for two-factor authentication and the BSAFE encryption tool kits. What made you think of acquiring Cyota?

We started 2005 flattish, and I was more than a little unhappy. I said to employees, if there's such a great market for authentication, we have to create it. We spent April to July figuring out strategy options that would call us to drive the market. We asked, what are the choices we need to give people? A different approach we noticed is risk-based analytics, especially on the consumer side. That was Cyota.

How does the Cyota analytics work?

At Cyota, they'll monitor consumer transactions based on several things: computer profile, browser and transaction behavior, to have servers in the bank looking at fraud monitoring. We're gathering data about legitimate users so when they come again, we'll know them.

So suppose the Cyota service for the bank spots what the risk-based analytics determine is a criminal trying to imitate a legitimate customer?

We work with the ISPs and shut them down. We do forensics and provide that to law enforcement. The fraudster gets pushed away and shut down. About 10 large banks, and now eTrade Financial, use Cyota to share information about fraud collaboratively as part of Cyota's eFraudnetwork.

Isn't this a lot different business than what RSA Security has been involved in up to now?

I don't think we're getting away from our roots. We're just getting more pragmatic.

Cyota is a start-up. Is it profitable yet? What does it cost to a financial enterprise to use Cyota?

Cyota is about to make money. As far as the fraud-based services, Cyota costs about US$1 to $2 per user per year.

The Cyota service is typically used to guard against fraud based on re-usable passwords. But RSA Security has long held that strong two-factor or encryption-based authentication provides much better security than re-usable passwords. How do you reconcile this somewhat contradictory viewpoint after advocating for so many years that people get away from re-usable passwords?

We have a passion for authentication. When it's something in between, Cyota will ask you for more information, such as identifying an image you picked out earlier.

On the topic of strong authentication and the RSA SecurID token for generating a one-time password, what's the status there?

The second major decision we made in addition to buying Cyota was to launch what we call "credentials everywhere." That means embedding the SecurID token in cell phones, memory sticks, Sandisk flash memory, RIM devices, the Motorola "Q" smartphone. We're developing sales and distribution relationships based on embedding the SecurID is these types of devices. Today, SecurID is available for the Palm and BlackBerry.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Revolutionising Back-up and Recovery

Rapid adoption of virtual server technology, and the challenges associated with the backup and recovery of ever-growing stores of information is causing a number of IT managers to reevaluate their data protection strategies. New backup and recovery methods which use data de-duplication technology to reduce capacity and network bandwidth requirements are being deployed to keep up with explosive data growth, shrinking backup windows, compliance initiatives and security concerns. Read on to find out more.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links