Security
Skip to content

Security

Good practices and a secure cyberspace.

trade-hero
ONLINE BANKING SECURITY

Cybersecurity and rules for the secure use of CitiDirect

Regardless of the multi-level security measures applied by the bank, the user should be aware of the threats present on the internet. We remind you below of the rules for the secure use of CitiDirect®.

Login address for the CitiDirect system
  • Enter it manually in the browser's address bar or add it to "Favorites" – never search for the login page using an internet search engine.
  • Make sure you are on the correct portal page: in the browser window, a closed padlock must be visible in the address bar, indicating an encrypted connection, and the page address must begin with "https".
Login
  • Use the modern CitiDirect Mobile Token, which is assigned to a specific device, has strong verification protocols, time-based control mechanisms, and built-in security parameters. Combined with CitiDirect biometric authentication (fingerprints or facial recognition), it is a convenient and secure way to log in to CitiDirect.
  • Find out how to enable the CitiDirect Mobile Token for users: Activation Guide for System Administrators. The user can then easily activate their Mobile Token: Watch the ACTIVATION video, and log in to CitiDirect: Watch the LOGIN video.
Access rights and permissions in CitiDirect
  • The Administrator has the ability to manage user profiles, their permissions, and authentication tools (Mobile Token), and can temporarily block selected users in the system (e.g., for security purposes). This contributes to the security of funds and transactions.
  • To designate an Administrator, please submit the Activation Form
Smart payment verification

Citi® Payment Outlier Detection (CPOD) – an advanced analytical tool that helps identify transactions that differ significantly from previous trends:

  • compares current payments with payments made in the past,
  • helps identify transactions that deviate significantly from previous trends,
  • uses advanced machine learning algorithms that continuously adapt and evolve,
  • unusual cases are flagged for verification and approval or rejection by designated users before the payment is executed.

Citi Payment Outlier Detection is available through CitiDirect without any technological changes to the client's systems. To start using the tool, please contact your Advisor.

Beware of malicious software
  • The recipient's mail server verifies emails based on the sender's address. Please note that for emails from the CitiDirect system, this is always citidirectbe.notifications@citi.com, and for CitiManager – citicommercialcards.admin@citi.com. Citi Handlowy emails are always sent from the @citi.com domain.
  • Citi Handlowy uses SPF, DKIM, and DMARC email authentication mechanisms to increase email security. If your company's mail server is properly configured, a malicious email will not be delivered or will be routed to the spam folder.
  • Be careful with attachments: statements sent by us are encrypted, and notifications, i.e., balances, will always have masked details.

Best Practices in Digital Security for Online Banking

The most effective defense, called "layered defense," should be built using best practices applied across the industry, as well as by companies in the financial sector and law enforcement agencies.

Protection of systems
  • Ensure secure connectivity with third parties, using firewalls and encryption.
  • Restrict access to sensitive systems (e.g., online banking, management systems).
  • Proactively conduct fraud vulnerability assessments to identify weak points.
  • Use antivirus protection and anti-phishing tools, such as email filtering and suspicious link detection.
Transaction management
  • Restrict permissions for high-risk functions, such as transaction authorization or management of payment templates.
  • Establish permission limits and segregation of duties for high-value transactions (e.g., up to 9 authorization levels in CitiDirect).
  • Introduce controls over the sharing and modification of files and messages sent outside the company.
  • Remain vigilant, reviewing transaction details before sending it.
Access management
  • Never leave an active session unattended.
  • Log out at the end of each CitiDirect session.
  • Never share your login credentials or write down your PIN code.
  • Use strong passwords or multi-factor authentication, protecting your devices and business applications.
  • Set up multi-level authorization in CitiDirect.
Process management
  • Organize training on fraud awareness and business procedures.
  • Regularly update your business software and devices (e.g., operating system, browsers, Java, and Adobe Flash).
  • Make sure your organization's data is adequately protected.
  • Control employee access rights and review them periodically, especially in the case of sensitive or financial information.
  • Plan actions for a high-risk scenario.
Internal verification
  • Check account balances daily (including intraday).
  • Periodically verify information about suppliers and contractors.
  • Regularly review transaction reports and audit authorized users.
  • Use internal resources to prevent fraud and monitor suspicious payments.
  • Send notifications and reminders to employees about the steps to be taken in the event of actual or potential fraud.
CURRENT CYBER THREATS

biznes

Cookie Policy

Cookies are files that enable the storage of information or access to information already stored on the End User's telecommunications terminal device during or after a visit to websites, including transactional services.

Cookies used by the CitiDirect service do not store personal data; they are used, among other things, to remember User preferences or to secure websites.

Implemented ISO Standards

Citi Handlowy is among the leading financial institutions in the country in terms of implemented quality standards in the area of Information Security. The Bank holds the ISO 27001 certificate for information security, the ISO 22301 certificate for business continuity, and the ISO 20000 certificate for IT service management. Independent auditors have found our processes to be compliant with the highest international standards.

biznes
INCIDENT RESPONSE MODEL / PROCEDURE IN THE EVENT OF A SECURITY BREACH