AIRLINK 69.92 Increased By ▲ 4.72 (7.24%)
BOP 5.46 Decreased By ▼ -0.11 (-1.97%)
CNERGY 4.50 Decreased By ▼ -0.06 (-1.32%)
DFML 25.71 Increased By ▲ 1.19 (4.85%)
DGKC 69.85 Decreased By ▼ -0.11 (-0.16%)
FCCL 20.02 Decreased By ▼ -0.28 (-1.38%)
FFBL 30.69 Increased By ▲ 1.58 (5.43%)
FFL 9.75 Decreased By ▼ -0.08 (-0.81%)
GGL 10.12 Increased By ▲ 0.11 (1.1%)
HBL 114.90 Increased By ▲ 0.65 (0.57%)
HUBC 132.10 Increased By ▲ 3.00 (2.32%)
HUMNL 6.73 Increased By ▲ 0.02 (0.3%)
KEL 4.44 No Change ▼ 0.00 (0%)
KOSM 4.93 Increased By ▲ 0.04 (0.82%)
MLCF 36.45 Decreased By ▼ -0.55 (-1.49%)
OGDC 133.90 Increased By ▲ 1.60 (1.21%)
PAEL 22.50 Decreased By ▼ -0.04 (-0.18%)
PIAA 25.39 Decreased By ▼ -0.50 (-1.93%)
PIBTL 6.61 Increased By ▲ 0.01 (0.15%)
PPL 113.20 Increased By ▲ 0.35 (0.31%)
PRL 30.12 Increased By ▲ 0.71 (2.41%)
PTC 14.70 Decreased By ▼ -0.54 (-3.54%)
SEARL 57.55 Increased By ▲ 0.52 (0.91%)
SNGP 66.60 Increased By ▲ 0.15 (0.23%)
SSGC 10.99 Increased By ▲ 0.01 (0.09%)
TELE 8.77 Decreased By ▼ -0.03 (-0.34%)
TPLP 11.51 Decreased By ▼ -0.19 (-1.62%)
TRG 68.61 Decreased By ▼ -0.01 (-0.01%)
UNITY 23.47 Increased By ▲ 0.07 (0.3%)
WTL 1.34 Decreased By ▼ -0.04 (-2.9%)
BR100 7,394 Increased By 99.2 (1.36%)
BR30 24,121 Increased By 266.7 (1.12%)
KSE100 70,910 Increased By 619.8 (0.88%)
KSE30 23,377 Increased By 205.6 (0.89%)

KARACHI: Microsoft ended support for its Windows 7 embedded products earlier in the year, putting the operating systems at greater security risk and more vulnerable to viruses. All Windows 7 users have stopped receiving software updates since January 14, 2020, which include security updates. Following the end of support, questions have been raised on the security and compliance of the financial institutions, dealing with ATMs, around the world.

There have been concerns on how Pakistan's ATM infrastructure is now more exposed to security threats after expiration of Microsoft support on security-related updates. It is important to note that Pakistan's ATM footprint has expanded to over 15,600 machines across the country, with a little over 500 million transactions conducted in FY20 alone, that amounted to Rs6 trillion. Pakistan's ATM ecosystem is largely brick and mortar, with only a handful of specialized multipurpose ATMs. This usually means low cost and low maintenance hardware requirements. Replacing the existing operating system to ensure security compliance could be a costly affair for some, because the Microsoft recommends replacing existing computers with new ones for optimal results. In some cases, replacement with new computers might even be inevitable, as Windows 10 hardware requirements are significantly higher than those for Window 7. That said, those banks continuing with Windows 7 are not necessarily violating the best practice or the global benchmark Payment Card Industry Data Security Standard (PCI DSS). The relevant clause number 6.2 of the PCI DSS reads: "Protect all system components and software from known vulnerabilities by installing applicable vendor-supplied security patches. Install critical security patches within one month of release." From what it appears, in order to be PCI DSS compliant, all operating systems need to be upgraded from Windows 7 to Windows 10. But Microsoft still offers a window of opportunity to those who wish to continue with the existing operating system and/or are not ready yet to make the switch yet. Microsoft's Extended Security Update (ESU) programme is a last resort option for consumers who need to run Microsoft products past the end of support.

The ESU will be available for three years from the date of end of support, and most components last until January 2023. The customers are required to purchase the ESU updates to receive all security updates post the end of support. The ESU updates will not include design change requests, or new features. Given Pakistan's rather basic ATM infrastructure, any requirements beyond critical security update, may be considered additional. The central bank's compliance department would do well to ensure all banks have at least already opted for the ESU updates, if not the more-recommended switch to Windows 10.

Copyright Business Recorder, 2020

Comments

Comments are closed.