OldNational Security & Fraud Prevention Guide
Business banking security is more critical than ever. OldNational provides multiple layers of protection, but effective fraud prevention requires both technology and sound operational practices. This guide covers all security features available on the platform and best practices for keeping your business accounts safe.
Table of Contents
- Security Layers Overview
- Check Positive Pay
- ACH Positive Pay
- ACH Debit Block
- Secure Browser Protection
- Dual Control Workflows
- Multi-Factor Authentication
- Cybersecurity Best Practices
- Incident Response
Security Layers Overview
OldNational employs a defense-in-depth strategy with multiple independent security layers:
| Layer | Purpose | Where Configured |
|---|---|---|
| Secure Browser | Malware & phishing protection | Workstation install |
| Hardware Token | Physical authentication factor | Enrollment |
| Multi-Factor Auth | Verify user identity at login | Admin / User settings |
| Dual Control | Require two persons for payments | Admin permissions |
| Positive Pay | Verify checks & ACH before posting | Treasury Management |
| ACH Debit Block | Block unauthorized ACH debits | Treasury Management |
| Audit Trail | Log all user activity | Automatic |
| User Permissions | Limit access per user | Admin settings |
Check Positive Pay
Check Positive Pay is a fraud prevention tool that allows business clients to monitor checks posted to their accounts and make the decision to pay or return any check. It works by comparing checks presented for payment against an issued check file provided by the company.
How It Works
- Your company uploads an issued check file to OldNational (check number, amount, date, payee).
- When a check is presented for payment, the system compares it against your issued file.
- If the check matches an issued item, it is paid automatically.
- If the check does not match (different amount, unknown check number, or stale date), it is flagged as an exception.
- You review exceptions and decide to pay or return each item before the daily cut-off.
Benefits
- Detects counterfeit and altered checks before funds leave your account
- Reduces check fraud losses to near zero
- Provides daily review of all presented checks
- Automated matching reduces manual reconciliation
ACH Positive Pay
ACH Positive Pay (also called ACH Filter or ACH Authorization) applies similar fraud prevention logic to incoming ACH transactions:
How It Works
- You define rules for authorized ACH debits: approved originators (by ACH Company ID), maximum amounts, and effective dates.
- When an incoming ACH debit arrives, the system checks it against your rules.
- Matches are processed automatically.
- Non-matches become exceptions for your review.
- You decide to pay or return each exception.
Rule Types
- Originator whitelist: Only allow ACH debits from specific Company IDs.
- Amount limits: Set maximum dollar amounts per transaction or per originator.
- Date ranges: Limit transactions to specific date windows.
- Single transaction vs. recurring: Differentiate between one-time and recurring debits.
ACH Debit Block
ACH Debit Block is the most restrictive ACH fraud prevention tool — it blocks all incoming ACH debit transactions from posting to your account.
When to Use ACH Block
- Accounts that should never receive ACH debits (e.g., payroll accounts)
- Accounts with a history of unauthorized ACH transactions
- As an emergency measure when fraud is suspected
ACH Block with Whitelist
Some configurations allow you to block all ACH debits except those from a pre-approved list of originators. This provides maximum security while still allowing legitimate transactions from known vendors.
Secure Browser Protection
The ONPointe Secure Browser provides an additional layer of protection against malware attacks, particularly:
- Man-in-the-Browser attacks: Malware that intercepts browser sessions to modify transactions.
- Keyloggers: Software that captures keystrokes including passwords.
- Session hijacking: Theft of session tokens by malicious code.
- Phishing redirects: Forcing the browser to navigate to fake banking sites.
The secure browser creates a protected environment that isolates the banking session from the rest of the operating system, making it significantly harder for malware to interfere with transactions.
Dual Control Workflows
Dual control (maker-checker) is one of the most effective fraud prevention mechanisms:
How Dual Control Works
- Maker (Creator): One user creates the payment or file.
- Checker (Approver): A different user reviews and approves or rejects the payment.
- The maker and checker must be different individuals — you cannot approve your own transactions.
- Approval limits can be tiered: higher-value transactions may require multiple approvers.
Recommended Dual Control Configuration
| Transaction Type | Dual Control | Approval Limit |
|---|---|---|
| ACH Origination | Required | Per user, by role |
| Wire Transfers | Required | Per user, by role |
| Account Transfers | Recommended | Per user, by role |
| Payee Additions | Recommended | Admin approval |
| Template Creation | Optional | Admin approval |
Multi-Factor Authentication
MFA is mandatory for all OldNational logins. Best practices for MFA:
- Use authenticator apps over SMS when available — they are more resistant to SIM-swapping attacks.
- Keep contact information current — outdated phone numbers or emails can lock you out.
- Never share MFA codes with anyone, including IT staff or bank representatives.
- Report lost tokens immediately to your administrator for deactivation.
- Hardware tokens provide the highest security level for organizations that need it.
Cybersecurity Best Practices
Workstation Security
- Keep the ONPointe Secure Browser updated to the latest version.
- Install reputable antivirus/anti-malware software and keep definitions current.
- Apply operating system patches promptly.
- Use a dedicated workstation for banking — avoid browsing unrelated sites on the same machine.
- Lock your screen when stepping away from your desk.
Email Security
- Be suspicious of emails requesting banking credentials or MFA codes.
- Verify wire transfer instructions received via email by calling a known phone number (not the one in the email).
- Do not click links in unsolicited emails claiming to be from your bank.
- Implement email authentication protocols (SPF, DKIM, DMARC) for your domain.
Business Email Compromise (BEC) Prevention
- Establish out-of-band verification for any change to payment instructions.
- Train employees to recognize BEC phishing attempts.
- Use dual control for all wire transfers — BEC attacks often try to bypass this.
- Set up alerts for changes to payee banking details.
Incident Response
If you suspect fraud or a security breach:
- Immediately contact Treasury Management support through the official bank website.
- Stop all pending payments that may be fraudulent.
- Change passwords for all affected users.
- Deactivate compromised users in the admin panel.
- Review audit logs for unauthorized transactions or setting changes.
- Document the incident including timestamps, affected accounts, and amounts.
- File reports with law enforcement if fraud is confirmed.