ALKHOBAR, 21 December 2002 — “Saudi banks have information security systems comparable to those of banks in Europe and the USA. The ComGuard statement that 95% of Saudi banks are unprotected from information piracy attacks is totally false, an act of sabotage and grounds for a libel action,” said Mirza Asrar Baig, CEO, Information Technology Matrix, one of the Kingdom’s leading information security total solution providers.
Baig was responding to a report carried in the Financial Times, based on a story in Al-Watan newspaper attributed to Amin Mahabliya, a senior consultant at ComGuard, a local IT company. According to Mahabliya, Saudi banks, which usually use the Unix/Linux operating system, apply traditional IT security systems, and thus, these banks are exposed to piracy attacks. International network security experts contacted by Arab News have asserted that the ComGuard statement is without merit.
The FT report has created a furor in the Kingdom. Baig said that the banks he has spoken with either never heard of ComGuard or assured him that they never participated in any security survey with ComGuard. Arab News has learned that at least one local bank has lodged an official complaint with the Saudi Arabian Monetary Agency (SAMA) based on evidence that Al-Watan never confirmed the veracity of ComGuard’s information which was provided by a local PR firm in a press release. ComGuard has a reputation among regional media outlets for regularly circulating press releases with sensational headlines and little substance, which are generally ignored.
By telephone to Dubai, Arab News contacted ComGuard’s regional sales director, Daniel Nufer. As Nufer was “out in the desert,” he refused to release a written statement on the comments by Mahabliya. He did say, however, that to his knowledge no survey of the Saudi banks had been done and that the comments came as a result of Mahabliya’s two to three years working in Saudi Arabia for ComGuard. Nufer believed that the statement on security problems in Unix/Linux systems was not specific to Saudi banks but could be applicable to some financial institutions globally. At this moment it is obvious that ComGuard has no hard evidence for their comments disparaging the Saudi banks.
The Kingdom’s ten commercial banks receive frequent security advisories from SAMA, the nation’s central banking authority. SAMA oversees all local banking activity, as well. Baig attended a BS7799 Information Security Conference in London in September 2002 during which he discovered that the IT security of Saudi banking networks is at the same level of banks in Europe and North America.
“I was not the only one from Saudi Arabia at the Information Security Conference,” said Baig. “Representatives from Saudi banks and SAMA were there, too. This year SAMA invited IT Matrix to organize an event at which international information security consultants gave presentations to all ten Saudi banks on BS7799 information security standards and how Saudi banks could achieve this certification. Local banks are now working to meet these international requirements. IT Matrix has become the local sponsor for the international digital security consultants “At Stake” and we have had @Stake’s European IT security consultants doing serious work with the Kingdom’s banks for the past year.”
@Stake’s digital security consultants have just left the Kingdom to spend the Winter holidays with their families. In London, Arab News caught up with Collin Gillingham, MD, @Stake and Andy Smith, @Stake’s senior security architect. Gillingham has visited banks in the Kingdom twice in the past year and Smith has spent the better part of 2002 in Saudi Arabia working with local banks on information security projects. During our telephone conversation, @Stake was unable to give specific details of these projects due to nondisclosure agreements signed with the Saudi banks, but they were able to provide general outlines of their consultancy which refute ComGuard’s statements.
“Saudi banks are very keen on achieving the highest level of information security,” said Gillingham. “As with all banks globally, security at Saudi financial institutions is the highest priority. Without information security there is no customer confidence. Saudi banks are working to constantly upgrade their information security systems and procedures. @Stake has already done work for several Saudi banks and we are in discussion with others for similar consultancies. Saudi banks are only interested in hiring the most reputable international consultants and it has never been brought to our attention by any client that ComGuard was competing against us on any project bid.”
Andy Smith, who has been physically at the banks in Riyadh for the past year gave some details of the work he has done.
“Over the past year myself and my team have completed multiple security related tasks at Saudi banks including penetration testing, risk assessments, and upgrading information policies and procedures,” Smith said. “Saudi financial institutions are spending millions to ensure that they have the best information security in place. Having worked within a number of Saudi banking institutions and SAMA, I can definitely state that they are being proactive in information security and looking after customer information. There is certainly no merit in ComGuard’s statement. Saudi Arabia’s banks and SAMA should be applauded for their strong and consistent attention towards enhancing information security.”



