Why do I need a Security Device?

A Security Device adds an extra layer of protection when banking online by generating a one-time code to help confirm it’s you or your staff approving transactions or making certain account changes.

Types of business Security Devices

SecurID® token

  • A physical device that generates one-time security codes
  • Required if you approve transactions over $200K per day
  • Ideal if you regularly have limited mobile coverage, or use a Corporate Online account.     

Westpac Protect™ SMS Code

  • Sends one-time security codes to a registered mobile
  • Suitable for businesses with a daily payment limit of $200K or less
  • Ideal if you have strong mobile coverage and prefer to receive security codes by SMS.

How-to guides

How to activate a SecurID® token

Before a SecurID® token can be used, it needs to be activated in Online Banking. Once activated, an Administrator needs to assign the token to the relevant user.

Step by step guide:

  1. Sign in to Online Banking from a desktop
  2. Select Services, then Security Settings 
  3. Select Authorise token
  4. Enter the 6-digit Token Number on the back of the token and select Authorise.

 

How to replace a lost, stolen or expired SecurID® token

You can order a new SecurID® token in Online Banking. If you already have a spare SecurID® token, you can reassign it to another user.

Step by step guide:

  1. Sign in to Online Banking from a desktop
  2. Hover over Administration, then select Security Devices
  3. Using the drop-down arrow next to each person’s name, select Replace SecurID token
  4. Select Send a new token
  5. Select the Reason for replacement and select Order token.

 

Please allow 3-5 business days for your SecurID® tokens to arrive. Once received, an Administrator needs to assign the token to the relevant user in Online Banking.
 

How to assign a SecurID® token

Before a SecurID® token can be used, an Administrator needs to assign it to an individual user in Online Banking.

Step by step guide:

  1. Sign in to Online Banking from a desktop
  2. Hover over Administration, then select User administration
  3. Using the drop-down arrow next to each user’s name, select Assign token
  4. Do you have a spare SecurID® token? 
  • Yes. Select Use a spare option, enter the serial number on the back, then select Assign token
  • No. Select Send a new token and it will be sent to your registered business address
     

Please allow 3-5 business days for your token to arrive.

 

How to reassign a SecurID® token

If a staff member leaves or no longer needs their SecurID® token, an Administrator can reassign that token to another user in Online Banking.

Step by step guide:

  1. Sign in to Online Banking from a desktop
  2. Hover over Administration, then select Security Devices
  3. Using the drop-down arrow next to each user’s name, select Reassign token
  4. Select Use a spare and enter the serial number on the back of the token
  5. Select Reassign token.

 

How to request spare SecurID® tokens

If you're an Administrator, you can order spare SecurID® tokens in Online Banking.

Step by step guide:

  1. Sign in to Online Banking from a desktop
  2. Hover over Administration, then select Security Devices
  3. Select Request spare tokens
  4. Enter the number of spare tokens you need, then select Submit Order.


Please allow 3-5 business days for your SecurID® tokens to arrive. Once received, an Administrator needs to assign the tokens to the relevant users in Online Banking.

 

 

You can order up to five spare SecurID® tokens a month in Online Banking. If you need more than five SecurID® tokens, please contact us. A fee may apply for additional tokens. Please refer to the Online Banking Terms & Conditions (PDF 627KB) for details.

How to switch to Westpac Protect™ SMS Code

If you or your staff have a daily payment limit of $200K or less, you may be able to switch from a SecurID® token to Westpac Protect™ SMS Code. This means security codes are sent by SMS instead of being generated on a physical token.


To switch an eligible user from a SecurID® token to Westpac Protect™ SMS Code:

  1. Sign in to Online Banking from a desktop
  2. Hover over Administration, then select Security Devices
  3. Using the drop-down arrow next to each authorised person’s name, select Switch to SMS Code
  4. Enter each person’s country and mobile number, then select Assign.

 

Once the switch is complete, the user will receive an SMS confirming they are registered for Westpac Protect™ SMS Code.

 

Note: Only Administrators can switch security devices. Not an Administrator? Find your Administrator in Online Banking by going to Service > Preferences > Profile access.

Frequently asked questions

A Security Device provides an additional safeguard against fraud. If you’re approving transactions higher than $5,000 in Online Banking, you’ll need a security code.

There are two security devices available to use in Online Banking:

  • Westpac Protect™ SMS Code uses your mobile phone to confirm certain transactions via text message when banking online
  • SecurID® token is a small, portable device that generates a digital security code, which you use to authorise transactions.

You and your staff can only have one active security device at any one time – either a SecurID® token or Westpac Protect™ SMS Code. You cannot have both.

You can return your old tokens to us to be recycled. Please mail to:

Reply Paid 
Westpac AAT
GPO Box 3433
Sydney NSW 2000

You may be able to receive Westpac Protect™ SMS Codes overseas if international roaming is activated and supported by your mobile provider. A short delay may occur due to international roaming limitations. If you have not updated your phone number to your international number, you can register your phone number in Online Banking however there are some countries that cannot be selected in Online Banking.

If you regularly travel overseas or have limited mobile coverage, a SecurID® token may be more suitable.

You can switch from an SMS code to a token at any time. If you don’t have a token, you can order a new token. If you already have a spare token, you can reassign an existing token to another staff member.