ALKHOBAR, 3 March — I have always been a big fan of automated banking systems. An ATM card has been in my wallet for 22 years. I was one of the few who understood early on that free personal banking for small customers would only continue if the service was automated to the max. That’s why my current experience with Saudi British Bank has been so disappointing. I will say that I left this bank once before. Some years ago I opened an account at SABB. After trying for a few months to deal with less than stellar service and a maze of rules and regulations, I simply gave up and went to another bank — the French. I was happy with the French, extremely happy, but somehow my company wasn’t. Last year I was notified that I’d have to have my paycheck deposited elsewhere, so I reactivated my account with SABB. Once again at this bank I have become mired in total frustration, with no end in sight.
Ever since I rejoined SABB I can’t get any of their automated banking services to work correctly. It’s not that I haven’t complained about it either — I have, again and again. I called their personnel at the telephone banking, SABB Direct, and informed them that there was something wrong with their system. I couldn’t access my account information. They informed me that there was nothing wrong. They could access it perfectly. I didn’t really care that they could access it. I was only interested in the fact that I couldn’t. The calls ended with them saying that they’d put in a report and then I’d never hear anything further.
In the midst of the whole mess, I tried to pay my telephone bill online. The SABBNET service gave me a confirmation number and showed the bill as paid. A few days later I checked back and found that the bill payment had mysteriously disappeared. I went to the SABB banking machine to pay the same telephone bill. I tried again and again but the machine wouldn’t allow me to pay it. Desperate to pay before my telephone was disconnected, I gave up on SABB and went across the street to the French banking machine. It took me about one minute to settle my STC bill there.
After the Eid holidays I called SABB Direct again and demanded to speak to a supervisor. I was transferred twice and finally a representative named Sami took the call. Instead of writing me off as an incompetent lunatic, he used a multiline technique to enable me to demonstrate to him that there was a problem. Then he said he was really, really sorry, and would work on a repair as fast as possible.
Financial institutions in the Kingdom keep wondering why people aren’t adopting online technology as fast as the banks had hoped. Well, I would venture to guess that a few experiences like mine put a damper on people’s enthusiasm. And I am not alone. I have been told tales of plenty of others who have had serious problems with automated banking services. Thank goodness I’m not abroad and desperate to use the service for a vital transaction as some have been.
I was amazed to learn that SABB records its customer service calls. Surprisingly, it records them without telling customers they are being recorded. I have been told that for legal reasons other banks are doing this too. In any case, since they have recordings of frustrated customers why aren’t they getting the message that people aren’t being served? I also can’t believe that those managers at the highest level in SABB don’t understand the concept of customer service. Perhaps somehow their ideas aren’t being translated to employees at lower levels.
I haven’t given up on automated banking. When it works it’s a great time saver. But this experience has reemphasized to me the importance of the human component in the proper management of information technology.
An essential part of automated banking is security. It took me several days to get a PIN code from SABB to use their Internet and telephone banking. I disliked the wait but if it was necessary for security reasons to wait, I would and did. I was glad to see any company being aggressive about online security. Internet and network security is a continuing problem in the Kingdom.
I remember when hackers started posting online the names of the Saudi networks and websites that they’d broken into or taken down. I thought such embarrassment would encourage companies to radically revamp their network security. All that happened was that businesses denied that they’d been hit. Sept. 11 should have been a real wake up call for everyone in the area of online security. Let me tell you about the progress made thus far. Saudi companies and ministries formed committees to investigate network security and they have been analyzing the situation — over and over again.
Meanwhile, back at the network and out in cyberspace, the criminals are getting more inventive.
Did you know that we have companies in Saudi Arabia still using firewall products developed by the Israelis? Even worse, there are thousands of Saudi companies that have installed neither anti-virus solutions nor firewalls on their machines. Many of those firms that do have anti-virus programs on their networks don’t upgrade them in a timely fashion. I checked around and found that for the recent Haj holiday most companies allowed their entire IT departments to go on leave. During that time several alerts came out for various security patches and upgrades. Some networks were used during the vacation without any of those patches or upgrades installed. In other cases, entire groups, including IT staff, went back to work last Tuesday. The inevitable happened. By last Monday morning I started getting notes that networks were down and urgent correspondence should be shifted to various free e-mail services. By Tuesday afternoon I’d received 16 such mails. There wasn’t a major bug on the loose, just the usual malicious stuff, but apparently combined with normal network problems and the lack of network maintenance, systems were sent crashing.
Since Sept. 11 governments in other countries have been working on the cyber security situation from many different angles. Money is being allocated in areas from biometrics to training. Here in Saudi Arabia we continue to lag behind. What is our problem?
“Security is an investment not an expense, but most managers look at IT security as a cost to them,” explained Andrew Smith, security consultant, @Stake (atstake.com). “They feel that they are paying money and so they want to see what’s the benefit in terms of physical, quantifiable return.”
Smith visited the Kingdom recently and he said that almost everywhere he went decision makers were still focusing on the bottom line in terms of cost for the appliances, software and expertise required to install and maintain network security.
“I had to repeatedly tell managers, ‘please take a different view’,” said Smith. “How much are your data, network and corporate image worth?”
Everyone in the network security business agrees that the Saudi market has yet to take the network security issue as seriously as it should. Some of the reluctance could be wrapped up in the fatalistic nature of some business people and the fact that there has been a limited amount of crime in the Kingdom. It took companies in Saudi Arabia a long time to understand the importance of insurance. Until recently physical security consisted of the most basic locks and metal grills. So perhaps it is natural that the Saudi business community should be struggling with the issue of cyber security.
“In Europe the Internet has been there a long time,” said Smith. “There’s been a linear learning curve. Now, Saudi Arabia is just starting to utilize the Internet. Unfortunately because the Kingdom is behind much of the developed world in adapting to the Internet culture, its learning curve must be much steeper just to keep up.”
Threats to networks continue to be both internal and external, and both have equal weight. Within the Kingdom, and globally, the use of Microsoft products is ubiquitous. Last week @Stake released a report showing that 70 percent of the security defects found in an analysis of its customers’ networks were the result of software design flaws and applications were the biggest security risk.
As the largest name in applications worldwide, this puts Microsoft Corp. on the hot seat. The company has acknowledged that enterprise customers simply do not download and install patches as they should. This is particularly critical for high-threat vulnerabilities. Microsoft would like to start automatically distributing patches to enterprise customers, but that would still leave installation at the customers’ discretion. According to @Stake, in the future customers might find that their software licenses require them to accept patches or their warranties will be void.
But not all security issues can be fixed with a patch. Internal issues will plague networks until properly installed security puts an end to abuse before it starts.
“Many companies are creating network utilization policies and this is an excellent idea,” said Smith. “But just because a policy is in place doesn’t mean all employees will welcome it. If a company has to fire a valuable employee because he went against their network policies and engaged in Internet misuse or network abuse it would be extremely unfortunate. Such an action is the same as if that employee was hit by a bus. He’s lost to the firm. Instead of depending on voluntary compliance, properly installed network security can easily enforce corporate policy. Security controls access both into, out of, and within a network.”
These days there are more and more Saudi companies implementing ERP solutions. Talk about B2B, CRM and e-government is increasing. Every business is connected to some sort of e-mail system and many have websites. Despite the growing reliance on networks and constant contact with the unknown out in cyberspace, most Saudi managers, even some IT managers, know little about network security. Just start to discuss security blueprints, ISO 17799 or Critical Component Failure Impact Analysis, and their eyes glaze over. Every network is only as strong as its weakest link. Ignorance at the decision-making level leading to a lack of timely decisions is resulting in massive and potentially crippling security vulnerabilities in Saudi networks.

