Skip to main content
Supervised by:
Dr. Naeem Ahmed
Case Study 6: Mobile Banking Security
1. ‫القحطاني‬ ‫جابر‬ ‫صالح‬ ‫محمد‬ 444812113
2. ‫اعظم‬ ‫محمد‬ ‫يوسف‬ ‫محمد‬ ‫أحمد‬ 444817166
3. ‫علي‬ ‫بن‬ ‫يحيى‬ ‫بن‬ ‫عبدالله‬
‫االحمري‬
443801944
4. ‫محمد‬ ‫بن‬ ‫عبدالله‬ ‫مشاري‬
‫الشمراني‬
443804017
Course name : IT Audit and Control Recommendations
Group G8
Introduction
 By understanding these risks, we can develop effective strategies to provide
recommendations for enhancing the platform's security posture.
 This report presents a comprehensive risk assessment of the bank's mobile banking
platform, conducted using the NIST SP 800-30 methodology. The assessment aims to
identify potential threats and vulnerabilities, evaluate existing security controls.
Objectives & Scope
 The primary objective of this assessment is to identify and prioritize risks
associated with the bank's mobile banking platform..
1. Objectives
The scope encompasses the mobile applications, backend servers, APIs, and
integration with core banking systems. The assessment focuses on
evaluating the security of data and transactions handled by the platform,
including account balances, fund transfers, and bill payments.
2. Scope
05
01
04 03
Mobile Applications
Available for Android and iOS devices, offering
account management, transaction execution,
and various financial services.
Backend Servers
Securely store customer data and process
transactions, integrating with core banking
systems for real-time updates.
Entegration with Core Banking
Systems
Enables seamless access to customer accounts
and financial information.
APIs
Facilitate communication between mobile applications and backend servers,
ensuring secure data exchange.
IT Infrastructure Overview
The bank's mobile banking platform consists of the following components:
In this case study, we have adopted the NIST SP 800-30 risk assessment methodology. This
approach provides a systematic framework for identifying, assessing, and mitigating risks in an
organization's IT environment. By employing this methodology, we can ensure a comprehensive
and structured analysis of the Mobile Banking Security.
risk assessment
preparation
threat
identification
vulnerability
identification
control
analysis
control
recommendations
likelihood
determination
impact analysis risk determination
The NIST SP 800-30 methodology involves a nine-step process that includes :
system
characterization
NIST SP 800-30 Methodology: A Systematic Risk Assessment
]
Potential Threat Identification
threats
 Malware
Targeting mobile devices to steal sensitive information,
such as login credentials and financial data.
 Phishing Attacks
Deceiving customers through emails, SMS
messages, or fake websites to reveal login
credentials or personal information.
 Man-in-the-Middle Attacks
Intercepting communication between mobile
devices and servers to steal data or manipulate
transactions.
 Unauthorized Access
Employees or insiders with access to systems or
data exploiting their privileges for malicious
purposes.
 Accidental Data Disclosure
Human error leading to unintentional data leaks or
breaches.
 Insecure Wi-Fi Networks
Exposing data to eavesdropping or interception
when using public or unsecured Wi-Fi networks.
 Data Loss or Corruption
Hardware or software failures, natural disasters, or
other events causing data loss or corruption.
 Social Engineering Attacks
Exploiting human vulnerabilities to gain access to
sensitive information or trick users into performing
actions that compromise security.
Potential Threat Identification
Mobile-Specific Threats
 Device Theft or Loss
Mobile devices being stolen or lost, potentially exposing sensitive
information stored on the device.
 Unsecured Mobile Apps
Downloading malicious apps or apps with security vulnerabilities that
could compromise data or device security.
 Jailbreaking or Rooting
Modifying mobile operating systems to bypass security restrictions,
increasing vulnerability to malware and other threats.
Potential Vulnerability Identification
1. Authentication and Authorization
 Weak Passwords : Users choosing weak or easily guessable passwords.
 Lack of Multi-factor Authentication : Reliance on single-factor authentication, making it easier for
attackers to gain access to accounts.
 Insecure Session Management : Weak session management allowing attackers to hijack user sessions.
2. Data Security
 Insufficient Data Encryption : Data not being encrypted in transit or at rest, making it vulnerable
to interception or theft.
 Insecure Data Storage : Sensitive data being stored in insecure locations or formats, increasing
the risk of unauthorized access.
 Lack of Data Backup and Recovery : Inadequate data backup and recovery procedures, making
it difficult to recover from data loss or corruption.
3. Mobile App Security
 Insecure Code : Mobile apps containing vulnerabilities that could be exploited by attackers.* **
 Lack of Input Validation : Insufficient input validation allowing attackers to inject malicious code or
manipulate data.
 Insecure Communication Channels : Mobile apps communicating over insecure channels, exposing
data to interception.
Control Analysis
Existing Controls
 Multi-factor Authentication : Enhances login security by requiring multiple verification steps.
 Data Encryption : Protects sensitive information in transit and at rest using strong encryption
algorithms.
 Secure Communication Protocols : Ensures data security during transmission by utilizing protocols
like HTTPS.
 Mobile Device Management : Enables remote device management, including device wiping and
security policy enforcement.
 Security Testing and Code Review : Identifies and addresses vulnerabilities in mobile applications and
backend systems.
 Compliance with Mobile Security Standards: Adheres to industry best practices and regulations,
such as OWASP Mobile Top 10.
Control Gaps
 Limited Security Awareness Training : Employees may not be adequately trained on mobile security best
practices, increasing the risk of social engineering attacks or accidental data breaches.
 Infrequent Security Assessments and Penetration Testing : Vulnerabilities may not be identified
promptly, leaving the system exposed to attacks.
 Lack of Robust Data Backup and Recovery Procedures : Data loss or corruption could have severe
consequences if adequate backups and recovery mechanisms are not in place.
Likelihood Determination
Assessing the Odds: Evaluating the Likelihood of Security Threats
High-Likelihood Threats:
 Malware : Mobile devices are increasingly targeted by malware, making this a high-likelihood threat.*
 Phishing Attacks : The prevalence of phishing campaigns and the success rate of social engineering
tactics make this a significant risk.
 Insecure Wi-Fi Networks : Public Wi-Fi networks are often unsecured, making them vulnerable to
eavesdropping and data interception.
Medium-Likelihood Threats
 Man-in-the-Middle Attacks : While technically challenging, these attacks can be successful if attackers
have access to the network infrastructure.
 Social Engineering Attacks : Human vulnerabilities can be exploited through various social
engineering techniques, making this a moderate threat.
 Data Loss or Corruption : Hardware or software failures, natural disasters, or human error can lead to
data loss or corruption.
Likelihood Determination
Assessing the Odds: Evaluating the Likelihood of Security Threats
Low-Likelihood Threats
 Zero-Day Exploits : Exploiting previously unknown vulnerabilities requires sophisticated attackers
and specific targeting, making this a low-likelihood threat.
 Physical Attacks : Physical attacks on data centers or mobile devices are less common but can
have severe consequences.
Likelihood Determination
Assessing the Odds: Evaluating the Likelihood of Security Threats
Industry Trends:
 Overview:
Healthcare organizations face increasing threats such as targeted ransomware attacks, supply chain
compromises, and vulnerabilities in connected medical devices.
 Reports and Studies
Cite recent reports from reputable sources highlighting the evolving threat landscape and the
importance of proactive cybersecurity measures.
Threat Intelligence:
 Sources:
Utilize threat intelligence from information sharing platforms like the Health Information Sharing and
Analysis Center (H-ISAC) and collaborate with trusted cybersecurity vendors.
 Specific Threats Targeting Healthcare:
Recent examples include targeted ransomware attacks on hospitals, data breaches through
vulnerable third-party vendors, and phishing campaigns impersonating healthcare professionals.
Justification Rating
Threat Name
Mobile devices are increasingly targeted by malware, and the bank's mobile app
is a potential target due to its popularity and access to sensitive data
| .
High Malware
Weak password practices increase the risk of unauthorized access, but security
awareness training and access control improvements can mitigate this
vulnerability
.
High Phishing Attacks
Public Wi-Fi networks are often unsecured, making them vulnerable to
eavesdropping and data interception
.
High Insecure Wi-Fi Networks
Human vulnerabilities can be exploited through various social engineering
techniques, making this a moderate threat
.
Medium Social Engineering Attacks
Hardware or software failures, natural disasters, or human error can lead to data
loss or corruption
.
Medium Data Loss or Corruption
Exploiting previously unknown vulnerabilities requires sophisticated attackers
and specific targeting, making this a low-likelihood threat
.
Law Zero-Day Exploits
Physical attacks on data centers or mobile devices are less common but can Law Physical Attacks
Likelihood Assessment
:
Impact Analysis
Examining the Potential Impact of Security Breaches
Financial Losses
 Fraudulent transactions: Attackers could gain access to customer accounts and make
unauthorized transactions, leading to financial losses for both customers and the bank.
 Data breaches: Stolen customer data, such as credit card numbers or social security numbers,
could be sold on the dark web or used for identity theft, resulting in financial losses for customers
and reputational damage for the bank.
 Regulatory fines: Failure to comply with data security regulations could lead to hefty fines and
penalties.
Operational Disruptions
 Denial-of-service attacks could disrupt the availability of the mobile banking platform, preventing
customers from accessing their accounts and conducting transactions.
 System outages caused by security incidents could lead to operational disruptions and financial
losses.
Impact Analysis
Examining the Potential Impact of Security Breaches
Reputational Damage
 Data breaches and security incidents can damage the bank's reputation, leading to loss of customer
trust and negative publicity.
 Negative media coverage and social media backlash can further amplify the reputational damage.
 Loss of customer trust can lead to decreased customer loyalty and reduced business opportunities.
Legal Liabilities
 Data breaches and security incidents could lead to lawsuits from customers claiming damages due to
identity theft or financial losses.
 Failure to comply with data security regulations could also result in legal action.
Impact Severity
 The severity of the impact will depend on the nature of the security breach, the amount of data
compromised, and the number of customers affected.
 A large-scale data breach involving sensitive customer information could have a devastating impact
on the bank's reputation, finances, and operations.
Risk-level Determination & Risk Mitigation
Malware
Risk ID: 01 Probability: 90% Impact: high
Description
:
Mobile devices are increasingly targeted by malware, which
could steal sensitive customer information and financial data
.
Mitigation
:
Implement strong access controls, multi-factor authentication,
and regular user access reviews. Encrypt sensitive patient
data and monitor access logs for any suspicious activity
.
Phishing Attacks
Risk ID: 02 Probability: 85% Impact: high
Description
:
Phishing campaigns are prevalent, and customers may be
tricked into revealing login credentials or personal information
.
Mitigation
:
Implement regular data backups and establish a robust disaster
recovery plan. Ensure proper storage and backup procedures to
minimize the risk of data loss or damage
.
Physical Attacks
Risk ID: 03 Probability: 20% Impact: Low
Description
:
Physical attacks on data centers or mobile devices are less
common but can have severe consequences
.
Mitigation
:
Implement physical security measures to protect data centers
and mobile devices, and conduct regular security
assessments
Risk-level Determination & Risk Mitigation
Insecure Wi-Fi Networks
Risk ID: 04 Probability: 90% Impact: high
Description
:
While technically challenging, these attacks can be successful
if attackers have access to the network infrastructure
.
Mitigation
:
Implement secure communication protocols (HTTPS) and use
certificate pinning to prevent man-in-the-middle attacks
Man-in-the-Middle Attacks
Risk ID: 05 Probability: 85% Impact: high
Description
:
Phishing campaigns are prevalent, and customers may be
tricked into revealing login credentials or personal
information
.
Mitigation
:
Implement regular data backups and establish a robust
disaster recovery plan. Ensure proper storage and backup
procedures to minimize the risk of data loss or damage
.
Social Engineering Attacks
Risk ID: 06 Probability: 60% Impact: Medium
Description
:
Human vulnerabilities can be exploited through various social
engineering techniques
.
Mitigation
:
Implement secure communication protocols (HTTPS) and use
certificate pinning to prevent man-in-the-middle attacks
Data Loss or Corruption
Risk ID: 07 Probability: 40% Impact: Medium
Description
:
Hardware or software failures, natural disasters, or human
error can lead to data loss or corruption
.
Mitigation
:
Implement robust data backup and recovery procedures, and
conduct regular data integrity checks
.
Risk Mitigation
1. Unauthorized Access to Patient Data
Recommendations
Control Recommendations
 Implement strong password policies, including minimum length requirements, complexity rules, and
regular password changes.
 Enforce multi-factor authentication for all customer accounts, using a combination of knowledge-based
factors (passwords), possession-based factors (tokens), and inherence-based factors (biometrics).
 Implement adaptive authentication, which adjusts authentication requirements based on risk factors,
such as device type, location, and transaction value.*
 Implement session management controls, such as timeouts and inactivity detection, to prevent
unauthorized access to accounts.
1. Authentication and Authorization
Based on the risk assessment findings, the following control recommendations are provided to
enhance the security of the bank's mobile banking platform:
 Encrypt all sensitive data in transit and at rest using strong encryption algorithms and key
management practices.
 Implement data loss prevention (DLP) solutions to prevent unauthorized data exfiltration.
 Regularly back up critical data and test recovery procedures to ensure data availability in the
event of a disaster.
2. Data Security:
Recommendations
 Conduct thorough security testing of mobile apps before deployment, including static code
analysis, dynamic analysis, and penetration testing.
 Implement secure coding practices to prevent common vulnerabilities, such as SQL injection
and cross-site scripting.
 Validate all user inputs to prevent malicious code injection and data manipulation.
 Use secure communication channels for all data transmission between mobile apps and
backend servers.
3. Mobile App Security
Recommendations
Critical Thinking
Thinking Critically About Risks and Stakeholder Impacts
Risks and Stakeholder Impacts:
 Consider the potential impact of security breaches on different stakeholders, including customers,
employees, shareholders, and regulators.
 Analyze the root causes of security risks and identify opportunities for systemic improvements.
 Evaluate the cost-benefit analysis of implementing security controls, considering the potential financial
losses from security breaches.
 Stay informed about emerging threats and vulnerabilities, and adapt security controls accordingly.
Critical Thinking Questions:
 What are the most critical assets that need to be protected?
 What are the most likely attack vectors that could be exploited?
 What are the potential consequences of a successful attack?
 What are the most effective controls that can be implemented to mitigate risks?
 How can security controls be implemented in a way that balances security and usability?
The mobile banking platform faces significant security risks that could have severe consequences
for the bank and its customers. By implementing the recommended controls and adopting a
proactive approach to risk management, the bank can significantly enhance the security of its
mobile banking platform and protect its assets, reputation, and customer trust.
Conclusion
Key Points:
 A comprehensive risk assessment is essential for identifying and prioritizing security risks.
 Implementing strong security controls and adopting a proactive approach to risk
management are crucial for protecting mobile banking platforms.
 Critical thinking and stakeholder analysis are essential for making informed decisions about
security investments.
 Continuous monitoring and adaptation are necessary to stay ahead of evolving threats and
vulnerabilities.
Refeneces
1) National Institute of Standards and Technology (NIST). (2012). Guide for conducting risk assessments.
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
2) Open Web Application Security Project (OWASP). (2023). OWASP Mobile Top 10.
https://owasp.org/www-project-mobile-top-10/
3) SANS Institute. (n.d.). Mobile Security Resources. https://www.sans.org/security-resources/mobile-
security
4) Verizon. (2023). 2023 Data Breach Investigations Report.
https://www.verizon.com/business/resources/reports/dbir/
Thank You