PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Bots Deployed With Access Privileges Might Come Back And Bite You

By Tim Sloane
July 24, 2017
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on LinkedIn
business documents on office table with smart phone and digital tablet and graph business diagram and man working in the background

business documents on office table with smart phone and digital tablet and graph business diagram and man working in the background

 This blog in Finextra by Matt Middleton-Leal of CyberArk explains how helper Bots deployed in the enterprise to replace IT staff for some tasks, such as rebooting servers, can represent a significant threat to overall enterprise security:

“One of the ways in which the banks are streamlining processes is by adopting “bots”; applications which can perform pre-defined tasks faster, cheaper and more accurately than humans can. So, where an IT admin may be called on to regain operations, or resolve service, a bot could complete the same task automatically. It’s no surprise that IT tasks which were typically outsourced overseas – such as re-booting a server or allocating resources – are coming back to the UK in the form of bots to speed up response times and ensure resource goes towards higher value activities.

How bots could lead to breaches

Just like any human IT admin, however, the robots being used to complete these tasks need privileged accounts. These are valid credentials used to gain access to systems, providing elevated, non-restrictive access to the underlying platform that non-privileged user accounts don’t have access to.

Banks racing to introduce bots, without properly considering how to secure them, will open the institution up to new types of risks. If these privileged accounts were compromised, the attacker could move laterally through the bank’s infrastructure until they find the information (or funds!) they are looking for.”

Clearly credentials stored in Bots that are distributed across the enterprise would represent a growing security threat and a new attack vector for criminals. That said, as long as every Bot is implemented in a secure environment that risk can be managed. To lower the risk even further, perhaps Bot to Server communications can be further secured with cryptographic keys that are linked to specific IP addresses on the internal network, which would lower the chance that credentials are released into the wild or that commands sent from external locations would be obeyed.

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

Read the full story here 

0
SHARES
0
VIEWS
Share on LinkedIn
Tags: BankingCustomerCustomer RetentionFraud Risk and Analytics

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    bots fraud, bank security in data sharing, J.P. Morgan fraud protection TSYS, 3D Secure 2.0

    The Evolution of 3D Secure Puts it at the Center of Fraud Prevention

    September 18, 2026
    fraud detection signals

    Why Fraudsters Look Trustworthy and Good Customers Look Suspicious

    September 17, 2026
    Fraud Monitoring, Nacha ACH Rules, Same Day ACH

    10 Years Running, Same Day ACH Continues to Break New Ground

    September 16, 2026
    stablecoin infrastructure

    To Unlock Stablecoins’ Potential, Infrastructure Gaps Must Be Resolved

    September 15, 2026
    Latin America payment orchestration

    Navigating Latin America’s Complex Payment Ecosystem

    September 14, 2026
    upi biometric

    Beyond Authentication: Rethinking Digital Identity Security

    September 11, 2026
    Fraud Monitoring, Nacha ACH Rules, Same Day ACH

    Nacha’s Upcoming Rules Refresh Is All About Improving Clarity

    September 10, 2026
    instant payments for financial institutions

    Why Haven’t More Financial Institutions Adopted Instant Payments?

    September 9, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result