Most ATMs will remain on Windows XP after Microsoft pulls plug on OS support
Less than 40% of U.S.'s 425,000 ATM systems will have migrated off Windows XP
Computerworld - More than six out of 10 ATM machines in the country will be running on an obsolete operating system when Microsoft pulls the plug on Windows XP support on April 8, raising serious security and compliance issues for the systems' operators.
According to the ATM Industry Association (ATMIA), about 38% of the nearly 425,000 ATMs in the U.S. that are powered by Windows XP will have migrated off the OS by next month's deadline.
Operators of the remaining quarter million or more machines will have an increasingly hard time supporting their systems and ensuring sufficient software security after that date.
The Payment Card Industry Security Standards Council (PCI SSC), which is responsible for overseeing security standards in the payments industry, has already noted that ATMs still on Windows XP after April 8 will need to have certain compensating controls in place to be considered PCI compliant. The PCI SSC estimates that Windows XP powers 95% of ATMs in the world.
"The vast majority [of ATM operators] are aware of the deadline," said David Tente, executive director USA of the ATMIA.
Many operators have already moved or are in the process of moving their systems to Windows 7, which is the next available Windows upgrade for ATM systems, Tente said. But for a majority, the cost and time involved in upgrading their systems to a new OS is a huge challenge, he said.
Several financial institutions have worked out, and at great cost, arrangements with Microsoft to keep Windows support available for a while longer, he said.
In many cases, upgrading an ATM's operating system involves physical access to the machine and about one hour's worth of labor. Not all ATMs will be ready to migrate to Windows 7 and may need hardware upgrades as well, Tente said.
According to Tente, independent operators run about half the ATMs in the U.S., while large financial networks operate the rest. A "fair number" of installed ATMs are powered by Windows CE and embedded versions of Windows XP, which are not affected by the April 8 deadline, he said.
Microsoft has said that it will cease support for Windows XP after April 8. After that date, the company will stop providing security updates or technical support for Windows XP, an operating system that still has a huge installed base around the world.
Microsoft has pointedly stated that PCs running Windows XP after the end-of-support date should not be considered protected and has urged users of the operating system to move to a newer version as soon as possible.
According to Tente, it's possible that malicious hackers are waiting until after April 8 to attack ATMs and other systems running Windows XP. But just because a system remains on Windows XP after that date does not automatically make it more vulnerable.
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Jyske Bank extends brand message to more than one million visitors a month
- IBM WebSphere Portal software helps bank offer a clearly differentiated digital experience
- The Big Data Opportunity for HR and Finance
- If CEOs, CFOs, CIOs, and CHROs want to drive their businesses forward, they will need to quickly recognize the enormous value of big...
- SANS: Next-Generation Datacenters = Next-Generation Security
- This whitepaper takes a look at some new technology that may allow security teams to implement more flexible and capable protection models in...
- SANS: Protecting Virtual Endpoints with McAfee Server Security Suite Essentials
- SANS review of McAfees Server Security Suite Essentials that address some of the emerging challenges of securing virtual platforms and cloud environments.
- Safeguarding the Next-Generation Data Center
- Use of virtual and cloud servers has exploded. Unfortunately, security often lags behind. McAfee recommends looking at innovative solutions in order to erect... All Financial IT White Papers
- Is SQL Server AlwaysOn really as powerful? Tips and Tricks from the field With the introduction of AlwaysOn, Windows Clustering Services is now more critical than ever.
- What Does it Take to Deliver a Superior Customer Experience? The Two Top-Rated Online Retailers, B&H Photo and Crutchfield Electronics, Share Their Secrets Discuss practical CX tools and service methods such as contact center agents and the use of realtime speech analytics to help contact center...
- Keep Servers Up and Running and Attackers in the Dark An SSL/TLS handshake requires at least 10 times more processing power on a server than on the client. SSL renegotiation attacks can readily...
- On Demand: Mastering the Art of Mobile Content Management Mobile device usage in the enterprise has skyrocketed, and it continues to escalate. IT must answer to users who demand access to their...
- DevOps with PureApplication System: Reduce cost and speed delivery with an integrated IBM Cloud solution Join this webcast to hear what ING Netherlands has been able to achieve while deploying DevOps tools from IBM Rational. An ING executive...
- All Financial IT Webcasts