Security Tips
What have we done to protect you?
•   
With the use of 128bit Secure Socket Layer (SSL) encryption, we ensure the security of your data during transmission.
•    Our system will monitor each login attempt. If there are several consecutive login attempts with incorrect password,the online service
will be suspended immediately.
•    We will not ask for customers' account number, password or any personal information via emails.
•    Our web servers are protected by firewall systems to prevent unauthorized access.
•    CCB Online Enterprise Banking Services provide one-time password (OTP) as one of your two-factor authentication tools for
further verification when you need to conduct high-risk online transactions.
•    You should not leave your Security Device unattended to avoid unauthorized use of such device by third party to conduct
online transaction.
What can you do to protect yourself?
Password Protection
Password function is the key to your CCB Online Enterprise Banking Services. It is important for you to safeguard your Customer
Number, User Name, and Password. Please seriously consider the following suggestions:
•    Destroy the original printed copy of your Password
•    Change your initial password when you first access Online Banking Service.
•    Change your Password regularly
•    Use a combination of numbers, upper and lower case letters for your Password
•    Avoid using a number or name that is likely to or can easily be guessed by others, for example birthday, ID number or telephone numbers
•    Avoid to use the same Password for different web service accounts and systems
•    Never read out your Password over the phone
•    Never disclose your Password to anyone, including staff at CCB
•    Never write down or record any Customer Number, User Name, and Password without disguising it
•    Never include/send your Customer Number, User Name, and Password within an email message
•    Ensure that no one is watching you while you key in your Customer Number, User Name, and Password

Security Device (token) Protection
• Keep your Security Device (token) in a safe and secure place.
• Do not leave your Security Device (token) unattended.
• Do not allow anyone to take the possession or control of your Security Device (token).
 
Fraudulent Website
Fraudsters may send spoof emails pretending to be from China Construction Bank. Most of these emails appear to
come from the true source of the bank.

Recipients of these emails will be requested to input their personal information such as their username, password, credit card number, etc
through these emails.

Fraudsters through these emails may instruct the reader to visit the fraudulent websites via hyperlinks embedded in these emails and request
users to input their personal and account information.

Please be reminded that the bank will NEVER ask customers to provide confidential data via emails, so do not respond to any suspicious emails
that request for such information or click on an embedded hyperlink contained therein.
How to prevent?
•    Make sure you are connected to the bank's official versions respectively before login or keying in any confidential data
•    Do not access the website directly through hyperlinks embedded in e-mails. You should type directly on the browser's address bar or access via a bookmark
•    Verify the server certificate of our website (the locked padlock symbol at the bottom right hand corner of the browser)
•    Update your anti-virus software and change your login password regularly
Spyware
Spyware is a computer software that monitors what users do with their computer and collects information of the computer users without the
users' knowledge or consent. This software often comes from unseen components of "free download programs or applications".

The software will transmit the collected information to an unauthorized organization and more seriously, it can try to record what a user types in
order to attempt to intercept passwords or credit card numbers.
How to prevent?
•    Do not use public computers or mobile devices to logon to CCB Online Enterprise Banking Services.
•    Do not download any programs or software onto your computer from suspicious sources
•    Install anti-virus and/or anti-spyware software programs in your computer and always run the programs before downloading programs or
•    software or opening emails Regularly update your anti-virus and/or anti-spyware software programs and change your password
Unauthorized Access
In order to protect your computer and its contents and to stop unauthorized access to your computer, you should:
•    Install anti-virus/anti-spyware software programs, a personal firewall, and security patches on your computer
•    Install and regularly update anti-virus/anti-spyware software programs and security patches
•    Run the anti-virus/anti-spyware software programs before downloading programs or software or opening emails
Other Preventive Actions
Useful Security Tips to help you enjoy CCB Online Enterprise Banking Services.:
•    Remember to logout after you have completed your online activities
•    Do not use shared computers to access your CCB Online Enterprise Banking Services.
•    Do not leave your computer and/or mobile unattended when you are accessing your web service account
•    Check the date and time of your last visit to the Company’s official website every time after you have logged in
•    Review the transfer limit for non-registered third party account and lower it if necessary
•    Be alert of the SMS notification sent to you after each funds transfer to non-registered account via Online Banking( For CCB Asia and HongKong Branch only)
•    Never install uncertain applications provided by any third party
•    Review regularly and follow security tips published by the authorities


© China Construction Bank. All rights reserved.