AIRLINK 70.65 Increased By ▲ 1.45 (2.1%)
BOP 4.95 Increased By ▲ 0.05 (1.02%)
CNERGY 4.26 No Change ▼ 0.00 (0%)
DFML 30.20 Decreased By ▼ -1.05 (-3.36%)
DGKC 79.48 Increased By ▲ 2.23 (2.89%)
FCCL 20.54 Increased By ▲ 0.54 (2.7%)
FFBL 34.90 Decreased By ▼ -0.10 (-0.29%)
FFL 9.18 Increased By ▲ 0.06 (0.66%)
GGL 9.85 Increased By ▲ 0.05 (0.51%)
HBL 113.19 Increased By ▲ 0.43 (0.38%)
HUBC 133.05 Increased By ▲ 0.01 (0.01%)
HUMNL 6.97 Increased By ▲ 0.02 (0.29%)
KEL 4.28 Increased By ▲ 0.05 (1.18%)
KOSM 4.32 Increased By ▲ 0.07 (1.65%)
MLCF 36.83 Increased By ▲ 0.23 (0.63%)
OGDC 133.20 Increased By ▲ 0.33 (0.25%)
PAEL 23.65 Increased By ▲ 1.01 (4.46%)
PIAA 24.67 Increased By ▲ 0.47 (1.94%)
PIBTL 6.45 Decreased By ▼ -0.01 (-0.15%)
PPL 117.15 Increased By ▲ 0.85 (0.73%)
PRL 26.19 Increased By ▲ 0.29 (1.12%)
PTC 13.15 Increased By ▲ 0.07 (0.54%)
SEARL 52.40 Increased By ▲ 0.40 (0.77%)
SNGP 68.25 Increased By ▲ 0.65 (0.96%)
SSGC 10.45 Decreased By ▼ -0.09 (-0.85%)
TELE 8.34 Increased By ▲ 0.06 (0.72%)
TPLP 11.09 Increased By ▲ 0.29 (2.69%)
TRG 58.79 Decreased By ▼ -0.50 (-0.84%)
UNITY 25.25 Increased By ▲ 0.12 (0.48%)
WTL 1.27 No Change ▼ 0.00 (0%)
BR100 7,424 Increased By 15 (0.2%)
BR30 24,191 Increased By 154.3 (0.64%)
KSE100 70,965 Increased By 298.2 (0.42%)
KSE30 23,267 Increased By 43 (0.19%)

KARACHI: Microsoft ended support for its Windows 7 embedded products earlier in the year, putting the operating systems at greater security risk and more vulnerable to viruses. All Windows 7 users have stopped receiving software updates since January 14, 2020, which include security updates. Following the end of support, questions have been raised on the security and compliance of the financial institutions, dealing with ATMs, around the world.

There have been concerns on how Pakistan's ATM infrastructure is now more exposed to security threats after expiration of Microsoft support on security-related updates. It is important to note that Pakistan's ATM footprint has expanded to over 15,600 machines across the country, with a little over 500 million transactions conducted in FY20 alone, that amounted to Rs6 trillion. Pakistan's ATM ecosystem is largely brick and mortar, with only a handful of specialized multipurpose ATMs. This usually means low cost and low maintenance hardware requirements. Replacing the existing operating system to ensure security compliance could be a costly affair for some, because the Microsoft recommends replacing existing computers with new ones for optimal results. In some cases, replacement with new computers might even be inevitable, as Windows 10 hardware requirements are significantly higher than those for Window 7. That said, those banks continuing with Windows 7 are not necessarily violating the best practice or the global benchmark Payment Card Industry Data Security Standard (PCI DSS). The relevant clause number 6.2 of the PCI DSS reads: "Protect all system components and software from known vulnerabilities by installing applicable vendor-supplied security patches. Install critical security patches within one month of release." From what it appears, in order to be PCI DSS compliant, all operating systems need to be upgraded from Windows 7 to Windows 10. But Microsoft still offers a window of opportunity to those who wish to continue with the existing operating system and/or are not ready yet to make the switch yet. Microsoft's Extended Security Update (ESU) programme is a last resort option for consumers who need to run Microsoft products past the end of support.

The ESU will be available for three years from the date of end of support, and most components last until January 2023. The customers are required to purchase the ESU updates to receive all security updates post the end of support. The ESU updates will not include design change requests, or new features. Given Pakistan's rather basic ATM infrastructure, any requirements beyond critical security update, may be considered additional. The central bank's compliance department would do well to ensure all banks have at least already opted for the ESU updates, if not the more-recommended switch to Windows 10.

Copyright Business Recorder, 2020

Comments

Comments are closed.