Security and Control
HSBC aims to provide you with a robust, reliable and secure online environment through the adoption of best-of-breed technologies, proven best practice IT policies and procedures, and the dedication of expert resources.
Drawing on our considerable experience as providers of secure electronic banking systems, we also operate a control and support structure designed to ensure that we address all aspects of the risks faced in providing transactional banking online.
SSL 128-bit encryption
SSL (Secure Sockets Layer) uses 128-bit encryption to provide a high level of security, and is the standard used by HSBC and most financial institutions. All data exchanged between HSBC and the User is encrypted to ensure privacy is maintained. This includes the initial establishment of a secure internet session with HSBC.
Security credentials and two-factor authentication
For HSBCnet, the minimum credentials required to log on and access the system are the Username, a memorable answer and password that are set by the User and are known only to them. For administrative activities and financial transactions, a User requires a smart card issued by HSBC that contains a unique personal digital certificate in association with a PIN. This adheres to the proven technique of two-factor authentication -to enter the system a User is required to provide something they know (password and PIN) and something they possess (the smart card).
Data confidentiality and integrity
HSBC employs security industry best practices to protect customer or personal data. Sensitive data such as your passwords are stored in encrypted databases using a hardware security module.
User access levels and control
HSBCnet provides two access levels for customer staff. The system is flexible enough to allow for segregation of administrative and transactional functions.
- Systems Administrators can perform general administrative tasks such as the setup and entitlement of Users to HSBCnet tools
- End Users have no access to administrative functions
- Either type of User can be allocated transactional functionality
HSBCnet allows your designated Systems Administrators to determine individual User access rights and entitlements, down to account level viewing, payment authorisation limits and the number of Users required to authorise a payment. This enables complete control of access and authorisation, while allowing payments to be processed efficiently.
Activity log tools
All transactional events and certain system administration functions are recorded in activity logs. Your Systems Administrators can view activity for all Users, while individual Users can view their own activity logs.