Small business risk being locked out of Bacs after security upgrade

Image

Next Monday, 13 June, risks being an unlucky date for around 1,000 small businesses, with Bacs warning they may be locked out of the payments system used to process salaries, supplier payments and collect Direct Debits because of failing to make important software upgrades

Currently, most secure internet sites are protected by Secure Hash Algorithm-1 SSL, or SHA–1 SSL, which was first introduced in 1996 and is now classified as vulnerable to cyber attacks.

The global internet community is now adopting the newer protocol SHA–256 SSL, which will be in universal use by the end of this year.

Bacs is making the change next week, before the final deadline, to avoid any last minute issues with payments when the existing SHA-1 certificates are switched off.

At the same time as this change is being made, Bacs will withdraw support for older connection protocols to ensure secure protection for the communications pipeline between the internet-based service access points, Bacstel-IP and the Payment Services Website, and the service user. After 13 June 2016, only TLS 1.1 and 1.2 will be supported.

The internet security updates directly affect all Bacs users whether they submit payment files directly or via a bureau and businesses must take action if they are to avoid being locked out of Bacs.

The payments system has been running a campaign for some months spelling out the new requirements, but says its research indicates around 1,000 smaller businesses have yet to take action.

Mike Hutchinson, Bacs’ director of scheme support and development, said: ‘We are really disappointed that a number of organisations have not acted on urgent communications about important changes they must make to their payment software. We have been telling them this for more than a year.

‘If you’re a small business, you should check now whether or not you have the right software and operating system in place to make important payments, like payroll as well as to settle invoices. If you work for a small business, ask your finance team if they’ve made these changes.’

Businesses which need to access Bacs via Bacstel-IP or the Payment Services Website to make or collect payments will need to have a compatible web browser, operating system, and – if used – a Bacs approved software solution that support these changes.

The browser on the computer used to access Bacs services must be able to support SHA-256 SSL certificates and TLS 1.1/1.2 by 13 June 2016, whether this is to submit directly or to collect reports. Direct submitters should talk to their Bacs approved software solutions provider to make sure software that can accommodate these changes is in place.

If companies collect their own reports from the Payment Services Website they will still need to have an up to date operating system and internet browser.  It is known that the operating systems most at risk are Windows 2000, Windows XP and Windows Vista. Indirect submitters should check their bureau is aware of the changes.

There are details about the move to the new security protocol on the Bacs website here

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

0
Be the first to vote

Rate this article

Related Articles
Subscribe