One of the biggest challenges for digital businesses today is protecting a trusted user and preserving their ecosystem from fraud and hackers.
TeleSign’s account security platform is trusted by the world’s largest brands to prevent online fraud. Combining real-time data & analytics, phone verification and two-factor authentication, TeleSign helps customers secure billions of end-user accounts from compromise.
Using each consumer’s phone number is the optimal way to authenticate a global user base. Nearly 15 year ago TeleSign pioneered phone-based authentication services, and as we anticipated changes in hacker behavior, we introduced a new line of data products to fight back against the evolution of online fraud. Leveraging our proprietary insight into the volume of traffic around the world and the data captured by our products, we’ve developed the ability to predict potential fraud based on a variety of phone attributes, machine learning algorithms, data and behavioral patterns.
Today our expanded suite of products allow you to both preserve your ecosystem and your user base by detecting a suspicious user before account creation and identifying and blocking account takeover attacks before they occur.
In this whitepaper, we will provide an in-depth explanation of TeleSign’s security measures through a review of our Security Architecture and Information Security
TeleSign Security Architecture
The TeleSign REST API is the publicly-exposed programming interface to TeleSign’s web services. Requests to this web service are received via Transport Layer Security (TLS 1.2) connections. The API conforms to the REST Web service design model and, as such, Web services are treated as Domain Resources, and each one is accessed using its own unique URI.
Access to the TeleSign REST API is restricted by authenticating each call. To receive results for web service calls, customers must digitally sign their request message with valid credentials, which are provided by the TeleSign Customer Success team via a secure delivery channel.
TeleSign’s web services are colocated in Tier IV data centers located in the US, EU, and UK. All our data centers are SSAE 16 SOC 2 Type II compliant. These data centers are designed such that each data center is capable of handling 100 percent of our forecasted traffic for the year and are highly available individually, including fully redundant Internet access using disparate access providers. All data centers are inter-connected for replication purposes.
Customer traffic is distributed via geo-load balancing among these active data centers. All data centers are externally monitored by a third-party on a 24x7x365 basis. In the event of a disaster impacting one or more active data centers, TeleSign will shift traffic away from the impacted data centers within minutes as part of our Disaster Recovery (DR) process.
TeleSign regularly shifts traffic in conjunction with scheduled activities including deployment of new releases, hot fixes, applying security patches, controlled performance testing and operational events that impact a subset of active data centers i.e. this DR process is regularly tested and exercised.
The data center network architecture utilizes firewalls, intrusion prevention systems (IPS), load balancing farms and switching infrastructure — all of which are fully redundant with automated failover in the event of an individual component failure. Data center networks are segmented with all inter-segment traffic passing through a firewall cluster with only the ports necessary to support the traffic configured in the access lists. Access from the Internet into TeleSign’s designated perimeter network (“DMZ”) requires traffic to pass through router access lists, firewall access lists, IPS policies and the server’s local firewalls.
TeleSign’s architecture includes extensive use of virtual machines (VMs) distributed across physical servers for optimal load sharing and physical segregation of similar VMs performing the same role to avoid single points of failure. Each physical server has redundant network interface cards to access layer 2 switching and highly available storage area networking (SANs).
Databases are run in high-availability configuration (mirroring or clustering) and backed up at least daily. Customer transaction records in each active data center is moved to a centralized data warehouse every one to two minutes. This allows for two copies of DB transaction detail in disparate geographical locations within minutes of a transaction being processed. Tests of DB restores from backups are performed at least monthly. Full backups are copied / maintained in two separate data centers with data retention of 90 days.
TeleSign employs redundant well-known, industry-leading DNS providers to ensure high availability of DNS services. All network customer communication to/from TeleSign, as well as communication links to third party providers supporting TeleSign’s voice, SMS and data services, utilizes TLS encryption in-transit.
TeleSign supports whitelisting of customer traffic and third-party providers to limit access to/from TeleSign facilities/services.
Customers may access their account data through TeleSign’s customer portal – TelePortal (HTTPS only). Customers log in with their username and password to access the portal; credentials are provided via secure channels by TeleSign’s Customer Success team. In addition, two-factor authentication (2FA) is mandatory, and is available via multiple channels, including voice, SMS, mobile push or soft tokens.
TeleSign Information Security
TeleSign has established an information security management framework that is approved and endorsed by senior management. It describes the purpose, direction, principles and basic rules for how we maintain trust. This is accomplished by assessing risks and implementing administrative, technical and physical safeguards to protect the security, confidentiality, integrity and availability of TeleSign’s network, systems and data, including all of the information that we receive, store, process and transmit on behalf of our customers. TeleSign regularly reviews and updates security policies, provides security training, performs application and network security testing (including third-party penetration testing), monitors compliance with security policies as well as legal, regulatory and contractual requirements, and conducts internal and external risk assessments.
GLOBAL INFORMATION SECURITY POLICY (GISP)
TeleSign has an internal Global Information Security Policy (GISP) based on the ISO 27002:2013 standard for information security management. The GISP is reviewed and approved at least annually—based on the results of the annual Enterprise Risk Assessment (ERA), see “Compliance” section below—and are enforced by TeleSign’s Privacy and Security Office (PSO). All employees must consent to receiving, reading and complying with the GISP annually. In addition, the GISP applies to all vendors, subcontractors and relevant external parties via legal contracts with those entities. Violations, including a formal disciplinary process up to and including termination of employment or contract, and Exceptions are covered in the GISP. The GISP also includes a Mobile Device Policy and a Remote Access Policy.
The security and privacy of your data is of paramount importance here at TeleSign.
INFORMATION SECURITY ORGANIZATION
TeleSign has a dedicated and global PSO team, under the leadership of the Chief Information Security Officer (CISO), with documented roles and responsibilities. This team is committed to using a multi-disciplinary approach to protect the confidentiality, integrity and availability of information assets, including your data. PSO is accountable to senior management for creating and executing an Information Security Program that provides the security infrastructure necessary to protect information assets. This is done by:
- Establishing an information security architecture for standard security controls across TeleSign’s network;
- Defining organizational roles and responsibilities for information security;
- Monitoring and measuring the implementation of the GISP; and
- You have the right to object to or ask us to restrict the processing of your Personal Data.
- Developing and delivering a program to maintain information security awareness.
The PSO team will be your dedicated point of contact for information security matters. Please contact your Customer Success Manager for additional details.
HUMAN RESOURCE SECURITY
TeleSign leverages a Human Resources Information System to automate the sensitive process of onboarding incoming employees (e.g. background checks, security policy acknowledgement, NDAs) and offboarding departing employees (e.g. account deprovisioning). PSO works closely with HR to ensure that employees are consenting to the GISP and IPP, and attending information security training on an annual basis. New employees participate in mandatory security training and ongoing security awareness education. All employee access is promptly removed when an employee leaves the company.
TeleSign leverages Single Sign-On (SSO) and AAA systems (both are tied to Active Directory) for centralized management of user accounts for the majority of the infrastructure as well as cloud applications. These accounts are authenticated using strong, complex passwords including mandatory 2FA for SSO. TeleSign’s password policy includes complexity, history, expiration and lockout requirements.
Access is role-based and is limited only to systems and data required by users on a least-privileged and need-to-know basis. Access to Production systems and the network infrastructure (including firewalls), in particular, is tightly controlled and limited to a small number of administrators who must use separate accounts with elevated privileges and mandatory 2FA. Access is granted per approval by the system owner or manager and documented in the change management system. User accounts are reviewed quarterly and deprovisioned when no longer operationally required. Privileged and generic/service account access is tightly controlled and reviewed on a periodic basis. Service accounts are secured by very long and complex passwords and prohibited from performing interactive logons. Shared user accounts are prohibited.
Customer transaction data is housed in a shared environment in colocation facilities and classified as confidential data. This data is logically separated in TeleSign’s databases using a unique customer ID. Technical access controls and internal policies prohibit employees from arbitrarily accessing customer data. In order to protect customer privacy and security, only IT staff members have access to the environment where customer data is stored.
Any exceptions to baseline access permissions (e.g. temporary elevated privileges for a developer to perform a particular function) are documented using a change request ticket that is reviewed and approved by IT management prior to implementation.
TeleSign maintains an inventory of all technology assets and physically protects them from theft or loss. Unauthorized hardware is prohibited from the network and enforced using a Network Access Control (NAC) system. Procedures are in place for asset decommissioning, including secure destruction of data from electronic media. The usage of removable media (e.g. USB drives) is prohibited and enforced by technical means.
An Acceptable Use Policy governs usage of all assets, and includes a clean desk policy, PIN requirement and lockscreen timeout for mobile devices, and screensavers for workstations.
TeleSign has a Mobile Device Policy that addresses BYOD. Personally-owned devices are not allowed on the secure network, and this is enforced by the NAC. TeleSign has an information classification policy, which categorizes data into three categories: Sensitive, Confidential and Public. This categorization takes into account the value, sensitivity and criticality of the data. Procedures are in place to address best practices for handling the storage and transmission of each of the three categories of data (e.g. Sensitive/Confidential data must be encrypted when transmitted over the Internet). Guidelines are also available for the labeling of Sensitive/Confidential data.
Customer data is considered Confidential data, and is retained for 90 days for operational troubleshooting and billing purposes. Ninety days is the minimum required for TeleSign to operate its business and service platform effectively.
TeleSign encrypts all customer transactions to our APIs via the Internet with TLS 1.2, as well as customer access to our management console, TelePortal. Advanced Encryption Standard (AES) and Secure Hash Algorithm 2 (SHA-2) are the most widely-used encryption and hashing algorithms within TeleSign.
For services requiring third-party requests (e.g. SMS delivery), the requests are sent over TLS to ensure encryption of data in transit. Mobile devices (laptops, mobile phones, tablets, etc.) are encrypted. Encryption is also in use for remote access to the TeleSign network, as well as company Wi-Fi.
COMMUNICATIONS & OPERATIONS SECURITY
TeleSign secures its network using the “defense in depth” approach. Our network security and monitoring techniques are designed to provide multiple layers of protection and defense. The perimeter – including all office locations and data centers – is protected by enterprise-grade, next-generation stateful packet inspection firewalls and intrusion prevention systems. This strictly limits inbound access to specific source and port numbers, confines the destination to a DMZ and must be supported by approved business justification. Outbound access from the Production environment is also limited by restrictive egress filtering firewall rules, i.e., Web access from servers is blocked. Internal network segmentation is used to further isolate sensitive production resources (e.g. sensitive databases from the rest of the production network).
In addition, firewalls/IPS have application-level (Layer 7) controls and anti-malware as well as URL filtering capabilities and are implemented in a high-availability configuration. Firewalls and IPS strictly control traffic between the Internet-facing DMZ, the Production network and the Office network. Firewall rules are reviewed on a periodic basis and any changes are controlled via a change management process. In addition to anti-virus and malicious code detection software with automated updates on all systems, host-based firewalls and application whitelisting software are also in-use on production servers. Connectivity within the WAN is encrypted, providing for redundancy between data centers. Remote access into TeleSign’s network is strongly authenticated (i.e. two- factor) and encrypted using VPN technology. Access privileges are restricted based on their role. Company Wi-Fi networks are secured using WPA2 Enterprise with 802.1x authentication.
TeleSign identifies and mitigates risks via regular network and application security testing and auditing by both dedicated internal security teams and third-party security specialists.
Vulnerabilities – including hardware, operating system, software (third-party included) and applications – are patched in a timely manner (30 days for Critical, 45 days for High, 90 Days for Medium) based on weekly external vulnerability scans against the perimeter and weekly internal vulnerability scans on all internal nodes. Patching is automated via multiple patch management systems for the various hardware/software configuration. TeleSign also engages external vendors to perform security code reviews on all our applications and APIs on an annual basis, and penetration testing of our external-facing networks bi-annually.
Critical vulnerabilities that are identified to be imminent impactful on public-facing assets – where the risk and exploitability is much higher – are remediated within 48 hours of the release of the patch by the vendor.
AAA logging – including login attempts, access to services and executed activities – is enabled and synchronized to UTC to assist in the identification or investigation of security incidents and/or breaches and monitored for log correlation and alerting purposes. Public-facing systems are subject to penetration testing by an approved third-party provider on a regular (bi-annual) basis.
Backup procedures are in place and periodically tested.
SYSTEM ACQUISITION, DEVELOPMENT AND MAINTENANCE
TeleSign’s systems are hardened using documented procedures to disable all unnecessary services before applications are installed on them. All changes to computer systems are subject to the change management process and procedures to ensure changes are adequately reviewed, approved and tracked.
A well-established SDLC process is in place for the development of TeleSign applications, focusing on secure coding standards and guidelines such as OWASP and CWE Top 25 to ensure our products provide the highest level of security to our customers. Information security and privacy controls are built-in to the SDLC process as checkpoints, e.g. network/application-level vulnerability scans as well as static code analysis are performed on all applications prior to production roll-out. Development platforms are logically segregated from the QA/Staging and Production platforms. All Production changes are handled by IT staff, not developers.
In addition, we employ an independent third-party to perform code reviews on all our applications, including public-facing websites and mobile applications.
TeleSign assesses all Third-Party Providers (e.g. external vendors, suppliers, consultants, service providers and individuals) that provide goods and services before they are allowed access to Sensitive and Confidential data. The assessment of the Third-Party Provider information security (based on the ISO 27002:2013 security domains) and privacy controls is conducted by PSO. The process includes the Third-Party Provider signing a Data Processing Agreement (DPA) with TeleSign for compliance with the GDPR, and completing a Vendor Self-Assessment (VSA) questionnaire. Once the assessment is complete, the Third-Party Provider will enter into a contract with TeleSign, which is reviewed and approved by our Legal Department. The contract obligates the Third-Party Provider to adhere to TeleSign’s information security and privacy policies/standards.
TeleSign is contractually obligated to report security incidents involving customer data to the affected customers, as well as to relevant authorities to comply with legal and regulatory requirements, in the earliest possible timeframe. Employees are regularly reminded via security training and awareness to report all security incidents without delay.
TeleSign has an Incident Response Plan (IRP) covering the six phases of the incident response process for each of the five incident categories and types. The phases are: detection and identification, analysis, containment, recovery, closure and post-mortem. The categories are: unacceptable use/policy violation, lost/stolen asset, malicious code, denial of service and unauthorized access. Procedural checklists are available for each of the five categories based on priority level (high, medium or low) covering all six phases.
TeleSign has office locations in the US and Europe. The TeleSign PSO Team is responsible for enforcing physical security policy and overseeing the security of the offices. Physical access to office locations is restricted to authorized TeleSign personnel via a badge access system. Visitors and guests are required to sign-in using a visitor registration system which maintains access logs in the cloud for 12 months.
TeleSign has colocation facilities (“data centers”) in the US and EU. Physical access to colocation facilities where data-processing systems reside is restricted to personnel authorized by TeleSign, as required to perform their job function. Only the VP of Global Operations and his/her designees are authorized to explicitly approve and grant access to these colocation facilities.
All such requests for access, including justification, are recorded in TeleSign’s internal issue tracking system and similarly approved. Once approval is received, a member of the Global Operations team will contact the colocation facility to request access by providing the requestor’s name and identification number (e.g. driver’s license number). The colocation facility will record that information in their own system and provide the approved TeleSign personnel with badge access and, if possible, biometric scan access upon his/her next visits to the colocation facility. Once access is granted to approved individuals, the colocation facility is responsible for restricting access to authorized individuals only.
Visitors and guests are prohibited from accessing these secure colocation facilities.
TeleSign employs various independent third parties to perform an ISO 27002-based Enterprise Risk Assessment (ERA) across the entire network on an annual basis to measure our compliance with the ISO-based standard as well as the GISP. The results of the ERA are used to build a Security Roadmap that encompasses security projects tied to each of the ERA’s findings as part of the remediation process. High-level details of the roadmap can be shared upon request.
If you have any questions regarding TeleSign’s Security Architecture and/or Information Security, please contact TeleSign Support or your Customer Success Manager and your inquiry will be routed to the Privacy and Security Office (PSO) for a prompt response.