Siam Thanat Hack Co., Ltd.

Bank of Thailand Guidance for Mitigating ATM Malware Risk

A source-based guide to the Bank of Thailand letter RorPorTor.ForSor.(03) Wor. 1180/2559, dated 26 September 2016, on mitigating ATM malware risk. Addressed to commercial banks and specialized financial institutions, it covers physical controls, Core PCs, operating systems, network devices, cash loading, reconciliation, SDMS, and anomaly alerting.

Document scope and the timelines stated in the letter

The BOT describes ATMs as a key electronic-financial-transaction channel and cites a growing malware threat, directing institutions to strengthen both short- and long-term measures.

Thai infographic explaining: Document scope and the timelines stated in the letter
Visual guide: Document scope and the timelines stated in the letter
  • The letter set a six-month completion target for short-term measures and a two-year target for long-term measures, measured from its 2016 issue date.
  • Compliance and internal-audit functions were expected to participate in governance and assessment, with an assessment result and improvement plan submitted within 60 days as stated in the letter.
  • This page summarizes a 2016 source. It is not a determination of an institution's current obligations; check the latest BOT requirements and organization-specific obligations.

Short-term measures: physical condition, Core PC, and onsite equipment

The short-term measures connect site inspection with reducing unauthorized access to or modification of the Core PC and communications equipment.

Thai infographic explaining: Short-term measures: physical condition, Core PC, and onsite equipment
Visual guide: Short-term measures: physical condition, Core PC, and onsite equipment
  • Inspect ATM condition, communications equipment and cables, installation areas, lighting, and CCTV regularly, using a checklist so inspections remain repeatable.
  • Control the storage and issue of ATM-cabinet and communications-equipment keys; replace default BIOS, Core PC, and network-device passwords with unique values and protect them appropriately.
  • Disable automatic BIOS updates, close or restrict external-device connection paths, and configure booting from the primary hard disk only as stated in the letter.
  • Restrict execution to approved applications, review user access, disable unneeded programs and services, enable a firewall, retain Security/Event Logs, and review Core PC hardening.

Network devices, cash loading, and reconciliation

The letter connects technical safeguards with operational controls so communications and cash-handling activity have accountable owners and auditable records.

Thai infographic explaining: Network devices, cash loading, and reconciliation
Visual guide: Network devices, cash loading, and reconciliation
  • Replace router defaults, limit access by operational need, rotate passwords as appropriate, close unused ports and services, harden the device, and retain Security/Event Logs.
  • Review ATM cash-loading procedures against internal controls, including segregation of duties, dual control, and regular independent supervisory review.
  • Review and improve ATM cash reconciliation so cash-volume discrepancies can be detected promptly.

Long-term measures: network, SDMS, encryption, and alerting

The long-term measures extend individual-machine controls into network design, software management, authentication, encryption, and event monitoring across operations.

Thai infographic explaining: Long-term measures: network, SDMS, encryption, and alerting
Visual guide: Long-term measures: network, SDMS, encryption, and alerting
  • Maintain secure key-management processes and staff-review standards; use pairing authentication between cash dispenser and Core PC where feasible, and encrypt hard-disk data with full-disk encryption.
  • Separate the ATM network from other internal networks; control connections between ATMs, SDMS, and ATM Host with access control lists; verify SDMS-to-ATM communications; and encrypt the communications path with secure key management.
  • Scan and remove detected malware and maintain anti-virus/anti-malware on SDMS; replace defaults, restrict access, harden the system, and retain adequate Security/Event Logs.
  • Alert on physical, logical, and network anomalies including cabinet opening/tampering, unusual device or software installation, and unplanned reboot; limit Master-program access, scan it for malware before installation, and review staff activity periodically.

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofBOT letter RorPorTor.ForSor.(03) Wor. 1180/2559: Guidelines for mitigating ATM malware risk

BOT letter RorPorTor.ForSor.(03) Wor. 1180/2559: Guidelines for mitigating ATM malware risk

By Bank of Thailand

Open document (PDF) Source