AIRLINK 72.13 Increased By ▲ 2.93 (4.23%)
BOP 5.04 Increased By ▲ 0.14 (2.86%)
CNERGY 4.32 Increased By ▲ 0.06 (1.41%)
DFML 31.40 Increased By ▲ 0.15 (0.48%)
DGKC 80.37 Increased By ▲ 3.12 (4.04%)
FCCL 21.03 Increased By ▲ 1.03 (5.15%)
FFBL 34.82 Decreased By ▼ -0.18 (-0.51%)
FFL 9.17 Increased By ▲ 0.05 (0.55%)
GGL 9.81 Increased By ▲ 0.01 (0.1%)
HBL 113.40 Increased By ▲ 0.64 (0.57%)
HUBC 134.20 Increased By ▲ 1.16 (0.87%)
HUMNL 7.02 Increased By ▲ 0.07 (1.01%)
KEL 4.35 Increased By ▲ 0.12 (2.84%)
KOSM 4.35 Increased By ▲ 0.10 (2.35%)
MLCF 37.20 Increased By ▲ 0.60 (1.64%)
OGDC 135.40 Increased By ▲ 2.53 (1.9%)
PAEL 23.69 Increased By ▲ 1.05 (4.64%)
PIAA 24.60 Increased By ▲ 0.40 (1.65%)
PIBTL 6.52 Increased By ▲ 0.06 (0.93%)
PPL 120.40 Increased By ▲ 4.10 (3.53%)
PRL 26.33 Increased By ▲ 0.43 (1.66%)
PTC 13.20 Increased By ▲ 0.12 (0.92%)
SEARL 52.40 Increased By ▲ 0.40 (0.77%)
SNGP 71.40 Increased By ▲ 3.80 (5.62%)
SSGC 10.60 Increased By ▲ 0.06 (0.57%)
TELE 8.40 Increased By ▲ 0.12 (1.45%)
TPLP 11.11 Increased By ▲ 0.31 (2.87%)
TRG 60.51 Increased By ▲ 1.22 (2.06%)
UNITY 25.21 Increased By ▲ 0.08 (0.32%)
WTL 1.27 No Change ▼ 0.00 (0%)
BR100 7,490 Increased By 81.2 (1.1%)
BR30 24,512 Increased By 475.5 (1.98%)
KSE100 71,504 Increased By 837.6 (1.19%)
KSE30 23,444 Increased By 220.2 (0.95%)

KARACHI: Microsoft ended support for its Windows 7 embedded products earlier in the year, putting the operating systems at greater security risk and more vulnerable to viruses. All Windows 7 users have stopped receiving software updates since January 14, 2020, which include security updates. Following the end of support, questions have been raised on the security and compliance of the financial institutions, dealing with ATMs, around the world.

There have been concerns on how Pakistan's ATM infrastructure is now more exposed to security threats after expiration of Microsoft support on security-related updates. It is important to note that Pakistan's ATM footprint has expanded to over 15,600 machines across the country, with a little over 500 million transactions conducted in FY20 alone, that amounted to Rs6 trillion. Pakistan's ATM ecosystem is largely brick and mortar, with only a handful of specialized multipurpose ATMs. This usually means low cost and low maintenance hardware requirements. Replacing the existing operating system to ensure security compliance could be a costly affair for some, because the Microsoft recommends replacing existing computers with new ones for optimal results. In some cases, replacement with new computers might even be inevitable, as Windows 10 hardware requirements are significantly higher than those for Window 7. That said, those banks continuing with Windows 7 are not necessarily violating the best practice or the global benchmark Payment Card Industry Data Security Standard (PCI DSS). The relevant clause number 6.2 of the PCI DSS reads: "Protect all system components and software from known vulnerabilities by installing applicable vendor-supplied security patches. Install critical security patches within one month of release." From what it appears, in order to be PCI DSS compliant, all operating systems need to be upgraded from Windows 7 to Windows 10. But Microsoft still offers a window of opportunity to those who wish to continue with the existing operating system and/or are not ready yet to make the switch yet. Microsoft's Extended Security Update (ESU) programme is a last resort option for consumers who need to run Microsoft products past the end of support.

The ESU will be available for three years from the date of end of support, and most components last until January 2023. The customers are required to purchase the ESU updates to receive all security updates post the end of support. The ESU updates will not include design change requests, or new features. Given Pakistan's rather basic ATM infrastructure, any requirements beyond critical security update, may be considered additional. The central bank's compliance department would do well to ensure all banks have at least already opted for the ESU updates, if not the more-recommended switch to Windows 10.

Copyright Business Recorder, 2020

Comments

Comments are closed.