RSA Security late last year acquired privately held Cyota, which offers online security and anti-fraud services to help financial institutions protect consumer accounts. CEO Art Coviello recently sat down with Ellen Messmer to discuss the Cyota acquisition and RSA's views on the future of authentication. With its anti-fraud services for banks, Cyota is a very different type of business than RSA Security traditionally has been in with its SecurID products for two-factor authentication and the BSAFE encryption toolkits.
What made you think of acquiring Cyota?
We started 2005 flattish, and I was more than a little unhappy. I said to employees, if there's such a great market for authentication, we have to create it. We spent April to July figuring out strategy options that would call us to drive the market. We asked, 'What are the choices we need to give people?' A different approach we noticed is risk-based analytics, especially on the consumer side. That was Cyota.
How do the Cyota analytics work?
At Cyota, they'll monitor consumer transactions based on several things: computer profile, browser and transaction behavior, to have servers in the bank looking at fraud monitoring. We're gathering data about legitimate users so when they come again, we'll know them.
So suppose the Cyota bank service spots what the risk-based analytics determine is a criminal trying to imitate a legitimate customer?
We work with the ISPs and shut them down. We do forensics and provide that to law enforcement. The fraudster gets pushed away and shut down. About 10 large banks, and now eTrade Financial, use Cyota to share information about fraud collaboratively as part of Cyota's eFraudnetwork.
Isn't this a lot different business than what RSA Security has been involved in up to now?
I don't think we're getting away from our roots. We're just getting more pragmatic.
Cyota is a start-up. Is it profitable yet? What does it cost to a financial enterprise to use Cyota?
Cyota is about to make money. As far as the fraud-based services, Cyota costs about US$1 to $2 per user, per year.
The Cyota service is typically used to guard against fraud based on reusable passwords. But RSA has long held that strong two-factor or encryption-based authentication provides better security than reusable passwords. How do you reconcile this somewhat contradictory viewpoint after advocating for so many years that people get away from reusable passwords?
We have a passion for authentication. When it's something in between, Cyota will ask you for more information, such as identifying an image you picked out earlier.
On the topic of strong authentication and the RSA SecurID token for generating a one-time password, what's the status there?
The second major decision we made in addition to buying Cyota was to launch what we call 'credentials everywhere.' That means embedding the SecurID token in cell phones, memory sticks, SanDisk flash memory, [Research in Motion] devices, the Motorola Q smart-phone. We're developing sales and distribution relationships based on embedding the SecurID in these types of devices. Today, SecurID is available for the Palm and BlackBerry.
ScrumMaster offers tips on how to play in a winning dev team
How spyware nearly sent a teacher to prison
Open source identity: Asterisk founder and Digium CEO Mark Spencer
Fighting e-waste one mobile phone at a time
MIT's JoAnne Yates on information overload, 'CrackBerry' addicts and the 'always online' life
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 2008-12-02 09:56:00+11
The state of Middleware
Middleware delivers unprecedented visibility and control over your business by making timely information available to decision makers. Organisations are using Middleware to leverage their existing IT investments, while optimizing their IT and business operations, securing their infrastructure and driving compliance. Read on to discover how Middleware can help you increase your businesses profitability.












