Security - Making FransiPlus secure for you

Online Banking is a safe way to manage your money but you need to be on your guard against Internet fraudsters. Make sure you follow our advice to bank safely online:

Ignore emails claiming to be from Banque Saudi Fransi that ask for your Online Banking details. They ask you to follow a link to a site and enter your security details.

Scam emails have a link that opens a fake pop-up window over the real FransiPlus web site. DO NOT disclose any of your personal or security information in a pop-up. Always check the authenticity of the FransiPlus site by checking its security certificate, which you can do by double-clicking on the padlock symbol on your browser.
View example scam emails.

If you think you've received a fraudulent email that looks like it's from Banque Saudi Fransi, forward it to FransiPlusAdmin@alfransi.com.sa and then delete it from your email account.

For more information, or if you think you have given away your security details, call us on 800-124-0006.

Update your system and web browser
Download the latest manufacturers' security patches:
Windows and Internet Explorer | Apple Macs

To find out more about online security, check the following links:

Common Security Related Questions

§         Is FransiPlus Internet banking safe and secure for on-line banking?

§         I am behind a corporate firewall. Can I use FransiPlus Internet banking?

§         Which browsers and Operating Systems does FransiPlus support?

§         What if my computer crashes or the network goes down during a live FransiPlus session transaction?

§         I have forgotten my FransiPlus password - what should I do?

Registration Security

§         Secure Registration Process

§         What security details do I need to use for FransiPlus Internet banking?

§         Why do I have to enter the characters shown in the image on the first page of FransiPlus Online Registration and Forgot password?

How we maintain Security for FransiPlus

§         Secure Login

§         Secure Data Transmission

§         Automatic Logout

§         Fraud Prevention

§         Security Professionals

 

 

How you can improve your Security

§         Using online Banking securely

§         Checking FransiPlus’s security certificate

§         How can I keep my Internet banking password private and secure

§         Clearing your Browser Cache

How Attackers target YOU

§         Email scams

§         Fake Websites


Common Security Related Questions

Is FransiPlus Internet banking safe and secure for on-line banking?

Yes, Banque Saudi Fransi has implemented leading edge security mechanisms for FransiPlus including Firewalls, Intrusion Detection Systems and a industry Risk Management program in order to protect our systems against threats from the Internet. 

Banque Saudi Fransi security professionals are here to ensure that we provide you with a safe online banking service.  In addition to their expertise, we also contract independent security companies to conduct vulnerability assessments of FransiPlus on a regular basis.

I am behind a corporate firewall. Can I use FransiPlus Internet banking?

If conducting a secure Internet HTTP browsing is permitted in your company then you should have no problems in accessing FransiPlus. If still having problem, please call our customer service at 800-124-0006

Which Browsers and Operating Systems does FransiPlus support?

FransiPlus is currently available for Windows users running Internet Explorer 6.0 and above, and for Mac users who utilize Internet Explorer 6.0 for Mac.

What if my computer crashes or the network goes down during a live FransiPlus session transaction?

Requests received by FransiPlus would be processed. You can confirm this by contacting BSF Customer Service on 800-124-0006. If you are having difficulties with your Internet Service Provider, then you must contact them to see what is happening.

I have forgotten my FransiPlus password - what should I do?

You can use the Forgot Password link on the top left corner of FransiPlus homepage and follow the instructions. Contact our customer service on 800-124-0006 for any problem or inquiry


Registration Security

Secure Registration Process

To facilitate both a secure and convenient online registration to FransiPlus, you need to have an account with Banque Saudi Fransi (BSF) and provide your ATM card and PIN number information for verification purposes.  Entering your correct ATM card number and PIN represents the first stage in identification and authentication.  The second stage requires you to provide your corresponding BSF bank account number.  If all of this information is valid, then you can proceed with choosing a Subscriber ID and password, at which point access is granted.

What security details do I need to use for FransiPlus Internet banking?

Subscriber-ID: This is your unique identity on FransiPlus. When you register for the service we ask you to select this login ID for yourself. Subscribed-ID should be between 8 to 10 characters and has to be supplied each time you log into FransiPlus.

Password: This is a code of between 7 and 10 characters that can be a combination of alphabetic, numeric and special characters. You will be asked for it every time you log-on to FransiPlus internet banking.

Why do I have to enter the characters shown in the image on the first page of FransiPlus Online Registration and Forgot password?

The image’s characters are to tighten the security measures of online registration and forgot password processes within FransiPlus.

Saudi Arabian Monetary Authority (SAMA) Rules

As part of SAMA rules you are required to provide Banque Saudi Fransi with your original and valid “ID / IQ + Passport / CR” otherwise your account may be frozen. Please visit any Alfransi branch to avoid inconvenience to your account.


How we maintain Security for FransiPlus

Secure Login

To begin a session with FransiPlus, you must enter your Subscriber ID and password. To improve security and counter emerging risks Banque Saudi Fransi makes use of a virtual keyboard. This virtual keyboard defeats keyboard logging software which attackers may use to capture your Subscriber ID and password.

Using this virtual keyboard enter your Subscriber ID and password.

FransiPlus uses a lockout mechanism to deter unauthorized users from repeated Subscriber ID and password guessing attempts.  After five unsuccessful attempts, the system locks the Subscriber ID being attempted, requiring a phone call to BSF to re-authenticate you before reactivation.

Secure Data Transmission

From the beginning to the end of the FransiPlus session, all information that flows between your computer and BSF is protected by 128-bit strength Secure Sockets Layer (SSL) encryption.  FransiPlus is installed with a VeriSign Digital Certificate, which provides unbreakable protection between your Web browser and BSF servers.

Automatic Logout

To provide additional protection, a timeout feature is in effect whilst using FransiPlus, in case you walk away from your computer and forget to log-out. This feature automatically logs you out of your session after a period of inactivity. Re-establishing and authenticating your credentials for your online session helps to reduce unauthorized access to your accounts.  You should always use the log-out button to finish your online banking session.

Fraud Prevention

If you suspect a fraud please report the matter immediately to our customer support on our toll free number 800-124-0006. BSF customer support will take the appropriate action in case the transaction in question was performed within the past 2 months.

The following guidelines will help you how to monitor your account logons & transactions:

Detecting Possible Unauthorized Logons

The best way to stay informed about your activities within FransiPlus is to view the last logon date and time.  The last logon date and time is displayed in the top left-hand corner of the screen and indicates when we recorded you last accessing FransiPlus.  If you do not remember accessing FransiPlus at this time, then please report the matter immediately to us.

You can also review the activities performed during your last logon session by selecting the ‘Session History’ option.  If you notice any activities that you believe you have not performed then please contact us immediately.

Detecting Possible Unauthorized Transactions

Regularly check your online balance and transaction history and report any irregularities.  In addition to the ‘Last Ten FransiPlus Transactions’ , the best way to stay informed about your account is to ensure that your online records match your hardcopy BSF account statement.

FransiPlus provides email notifications, SMS messages, and online statement capabilities to assist you in monitoring your account activity.  Be aware of the activities in your account and contact us immediately to report any discrepancies.

Saudi Arabia’s Leading Security Team

Banque Saudi Fransi has a dedicated security department who ensure FransiPlus maintains the highest level of security possible.
How you can improve your Security

Using online banking securely

Take these steps when you're using Online Banking to keep your account information safe.

§         When you log-in to FransiPlus, double-click the padlock symbol at the bottom of your browser to ensure the site certificate belongs to FransiPlus. This will ensure you're not being duped into entering your details on a 'fake' site. How to check the site certificate.

§         Keep your operating system (eg Windows XP) and web browser (eg Internet Explorer) up to date. Flaws are sometimes found in these products and the publishers will issues 'patches' to correct the problem. Visit the following site to ensure you have the latest updates: Microsoft

§         Use a personal firewall and anti-virus software to prevent unauthorized access and viruses being downloaded onto your PC when you're on the Internet.

§         Keep your personal details secret. Never write down or reveal your Subscriber ID or Password.

§         Be wary of emails especially if they prompt you to visit FransiPlus by clicking on a link in the email. You can check the authenticity of the site by reviewing the certificate as detailed above. If you're in any doubt about the source of an email, it's best to delete it without opening it.


§         Check your accounts regularly. Look for transactions you don't remember making or recognize. If in doubt, note the details and report it to the helpdesk immediately on 800-124-0006

§         Always log-out after using FransiPlus by selecting the log-out button and never leave your PC unattended while you're logged in to the service.

§         We automatically instruct most browsers not to store your personal information in the cache (memory). As this may be affected by the type of browser you use, always clear the cache yourself.

 

 

 

 

 

 

 

 

Checking FransiPlus’s security certificate

How to check a site certificate

 

1. Double-click on the padlock in your browser window.

2. A dialogue box opens. Click on the 'Details' tab at the top.

3. Select the entry marked 'Subject'.

4. The entry marked 'CN' should be secure.fransiplus.com.

 

 

How to check the security certificate is valid:

 

After double-clicking the padlock (as above):

1. Click on the tab that says 'certification path' in the dialogue box.

2. Select secure.fransiplus.com in the certification path dialogue box.

3. Verify that it says 'This certificate is OK' in the certificate status dialogue box.

 

 

How can I keep my Internet banking password private and secure

You can better protect your Internet banking password by adopting the following guidelines:

§         Always try and use an alphanumeric password (consisting of letters and numbers).

§         Never choose a password same as your Subscriber-ID.

§         Choose a password, which is easy for you to remember but difficult for others to guess.

§         Keep changing your password frequently

§         Do not share your password with anyone.

§         Do not write down your password, just memorize it.

Clearing your Browser Cache

Although we instruct your PC web browser not to cache any of your personal details, there are some cases, which can include irregular browser types, versions and different platforms, where some web pages may be temporarily stored in your browser’s memory. 

To safeguard against this, we recommend that you always use the FransiPlus menu options and buttons to navigate the web site, always use the logout button once you have finished the FransiPlus session and close the browser window to clear the web page history stored in memory.

 


How Attackers target YOU

Email scams

Be wary of emails especially if they prompt you to visit FransiPlus by clicking on a link in the email. You can check the authenticity of the site by reviewing the certificate as detailed above. If you're in any doubt about the source of an email, it's best to delete it without opening it.

These emails may say they are security alerts from Banque Saudi Fransi, or mails about the status of your account. Banque Saudi Fransi will never contact you by email to ask you questions related to your account so don’t be tricked by these emails.

Fake Websites

Thieves may try to trick you to visit bogus websites which may look similar to FransiPlus. The only purpose of these sites is to fool you to entering your FransiPlus ID and password. Don’t be fooled by these sites and only ever visit the real FransiPlus site by checking the websites certificate as detailed in reviewing the certificate.