Kevin Lee, VP of Digital Trust & Safety at Sift, and The Fraud Practice discuss the use of dynamic friction with account takeover risk screening, including strategies for applying this type of layered approach.

In this webinar, you’ll learn:

  • Three strategies and considerations for applying dynamic friction to the login event
  • The importance of communication between the ATO risk and transaction risk screening events
  • Maximizing user experience for users with low-to-moderate ATO risk at login
  • Understanding how to measure ATO risk exposure for your organization, and how much flexibility that allows with a dynamic approach to ATO

Watch the On-Demand Webinar

Close

Thanks for submitting!

close

Video Transcript

0:16
Hello everyone. Welcome to our webinar. It’s just a couple of minutes until we
0:20
get started. Uh but just wanted to say welcome and
0:24
thank you for joining us today. Provide an uh I will provide an update shortly
0:28
when we’re about to begin. Hello and welcome everyone.
1:19
It’s just now about the webinar start time, but I still see the number of
1:23
attendees steadily rising. So, I’m going to just wait another one minute or so
1:27
before we officially kick off. All right, we are now two minutes past
2:33
the hour. So, uh even though uh guests continue to to roll in, we’re going to
2:39
go ahead and get started. Um hi everybody, welcome. Thank you for
2:43
joining us today. Uh we’re going to kick off this this webinar. uh the title of
2:47
which is balanced atto risk strategies leveraging
2:52
dynamic friction and and I’m excited to discuss this topic today alongside
2:58
Kevin Lee and and Kevin I’m going to hand it over to you first to to
3:01
introduce yourself.
3:04
>> All right. Hey everybody. Thank you for joining us today. Really excited to talk
3:09
to you about something that’s quite near and dear to my heart and probably
3:12
something that you all have to deal with um on the daily at the moment. So, my
3:16
name is Kevin. I lead our trust and safety architect team here at SIFT. Uh,
3:20
basically what that means is we are the internal experts when it comes to
3:25
anything and everything risk, fraud, trust and safety related. Um, I’ve been
3:29
at SIFT for over six years now and prior to that led my own fraud, spam,
3:35
chargebacks, underwriting, collections, various fraud and abuse teams at
3:41
companies like Google and Facebook and Square. And essentially what I do now
3:44
and or really what my team does now is consult with a lot of our existing
3:49
clientele on if they are launching into a new country, maybe they have a new
3:53
form of payment coming out, new app coming out, what are some of the
3:57
potential gotcha or uh oh moments that they might want to be a little bit more
4:01
mindful of as they go down that particular endeavor. Um but pleasure to
4:05
be here. Looking forward to our discussion today.
4:09
>> Excellent. Thank Thank you, Kevin. I’m I’m looking forward to the discussion as
4:12
well. And you know, just one or two things before I introduce myself. I I I
4:17
forgot to mention as we are kicking off and and kind of introducing the webinar.
4:21
Just want to uh remind everyone that today’s webinar is being recorded. It
4:24
will be made available to everyone um whether you’re attending or just
4:28
registered but didn’t attend. And we we hope to get that recording out to
4:32
everybody by by tomorrow or the end of the week at the latest. And um there’s a
4:36
Q&A uh feature if if you have any questions. We’re going to hold off on
4:41
answering questions until the end. Um, but but we welcome questions to be
4:45
submitted throughout. So, just wanted to mention those those two things briefly.
4:49
Um, so my name is Justin McDonald. I’m a senior risk management consultant with
4:53
the fraud practice. I’ve I’ve been in the digital payments and and you know,
4:56
fraud and risk industry for about 12 years now. Uh, with the fraud practice,
5:01
I’ve I’ve worked with merchants, payment providers, and others active in this
5:05
space. uh primarily with a focus on designing and implementing fraud
5:09
prevention and risk management strategies. Uh I’ve also written some
5:13
white papers and uh I’ve led the development of the fraud practices
5:17
online training and professional certification programs and um definitely
5:22
excited to talk about this this topic today. You know, in the early years of
5:27
my career in this industry, it was really all about payment fraud and
5:30
chargebacks and and fraud. Fraud’s diversified so much. It’s it’s it’s you
5:34
know we have to talk about things like like ATL. Um so with that being said
5:38
>> is still there though.
5:40
>> Yeah. Abs. Yeah. It’s not going away. Not going away. Um but yeah, but that’s
5:45
that’s stuff about me. I’ll I’ll I’ll let Kevin kind of kick off the real
5:48
content of the webinar here.
5:50
>> All right. Um thanks Justin. And uh for those of you that are not familiar with
5:54
SIFT, uh we are a trust and safety platform that helps businesses protect
5:59
themselves and their consumers against various forms of abuse. So certainly
6:03
those credit card fraud that we mentioned today’s talk we’re going to be
6:06
talking a lot around account takeover uh content you think about spam and scams
6:11
and stuff like that um those are all things that many digital businesses have
6:15
to contend with um nowadays. So uh with regards to an agenda um really the big
6:22
things that we wanted to cover today are trends measurement we’ll talk about this
6:27
concept of dynamic friction and what the heck that actually means and how to
6:30
deploy it. um we’ll talk about different strategic approaches and then finally
6:35
some some predictions for for 2023 and I should say really one of the main goals
6:41
of this particular session my goal anyways in in our goal with Justin here
6:46
is to make sure that you at least get some actionable takeaways that you can
6:51
deploy to your business today, tomorrow, this quarter. I know a lot of us are in
6:55
this kind of Q1 or 2023 planning stage and so um we have a little bit of green
7:00
field to work with and so hopefully um after today’s talk you can take some of
7:05
these ideas and really start asking some questions and see where your company
7:09
stands with regards to some of these challenges.
7:12
All right. So in preparation for this talk oftentimes something I do is just
7:19
look at what does the landscape look like? Um, and the the snapshots, the the
7:23
the screenshots and news articles I took here were all really from like the last
7:28
month or so. Um, I’d say the biggest one or the most relevant one for me that
7:32
came up was uh a report sent out by the Identity Theft Resource Center where the
7:38
number of data breaches um it’s not an all-time high. It’s about like 30 or 40
7:43
short from 2022, 2021 was actually the the all-time high here. Um but with
7:49
regards to the number of credentials that have been exposed and Twitter comes
7:54
to mind here. Um although the uh number of companies that reported it is
7:58
slightly less from the all-time low the number of consumers that are impacted it
8:03
impacted by it um actually grew substantially. Um, and one other I guess
8:09
interesting tidbit from that particular post was um, we found that companies
8:15
when they report these data breaches, they are reporting them, but they’re
8:19
actually being a little bit less transparent about the overall impact of
8:24
it. Part of that has to do with some regulations that may are kind of are
8:28
coming down from at least in the US. But I thought it was interesting where last
8:32
year or previous years companies were more transparent around what happened,
8:35
how it happened, number of users impacted and now at least for 2022
8:41
companies were a little bit more closed lipped about kind of what exactly they
8:45
disclose. And so, hey, once all that information
8:50
is out there, what actually happens with it? And so, and this kind of ties into
8:55
account takeover and also things like synthetic identities is it ends up for
9:00
sale on the dark web or um really what we’ve began to notice is I’ll call it a
9:06
democratization of fraud where you don’t have to go to some sketchy well you
9:10
still can go to some sketchy forums to find this stuff but whether it’s
9:13
Telegram or WhatsApp um all this information is pretty much readily
9:17
available. Um, and when I think about WhatsApp for example, this is actually a
9:23
screenshot um taken a few days ago uh where I feel like every day, every other
9:28
day I get invited to some glamorous Bitcoin discussion forum to to share
9:34
slash get my information fished. Um, so certainly consumers have to contend with
9:38
that. Um, I’ll also add that companies, let’s say like Google and and Apple have
9:44
become more privacy focused. So that makes me feel better. And so this middle
9:47
screenshot here is um if I haven’t used an app for a while, um my Pixel or
9:54
Android phone will proactively start removing some permissions, which I
9:58
appreciate as a consumer that’s a little bit more data conscious. Um and then
10:03
finally, I’d say companies have become better at identifying potential account
10:08
takeover. Um, so in this case here, it looks like we have um a post from
10:14
Snapchat saying, “Hey, looks like there’s some suspicious activity. Um,
10:19
please uh if this wasn’t you, please disregard. Um, this was you, you know,
10:23
go do A, B, and C.” Um, which is great from a company perspective that they’re
10:28
being a bit more proactive. What makes this particular uh shot a little bit
10:34
more tricky is and this was actually taken from a a friend of mine when uh
10:39
her Snapchat account was compromised. And one of the reasons why is this
10:44
particular screenshot is actually not from Snapchat. It was from the bad
10:48
actor, the fraudster posing as Snapchat where on the back end they were trying
10:52
to log into Snapchat. they trigger the 2FA that prompted um the kind of email
10:59
or the the the the message to go out and the hacker’s goal is that they will then
11:04
send the six six-digit code uh via this text to to the hacker. And so really
11:11
from a let’s say a strategy standpoint, we notice that uh bad actors are getting
11:18
a bit more sophisticated. you might call it spear fishing and things like that
11:22
and very targeted on kind of what they’re doing in this particular area.
11:27
So really all that stuff leads to our PII for sale and so here are some just
11:33
different areas that um fraudsters are selling either synthetic identities or
11:37
real identities. Um in some cases they’re using our tools not against us
11:43
but they’re using the same tools we’re using. So, uh, in in trying chatting
11:47
with different merchants, you might use different ID vendors like TLLLO comes to
11:51
mind or ideology or, um, other ones kind of listed here. Unfortunately, bad
11:56
actors have also been able to sign up for some of these services and then get
12:00
access so that they’re essentially building out their rolodex or building
12:03
out their profiles as well, which is another problem that we have to contend
12:07
with um, in this in this space.
12:11
>> Justin, anything to to add there?
12:12
>> Yeah, no, that that’s a big issue. One event, this is many years ago, but event
12:17
that comes to mind that that you reminded me of is when a major credit
12:20
bureau had a data breach where fraudsters were getting access to other
12:23
people’s credit reports. And why would you want that? Well, to get around these
12:28
KBAs and authentication checks that ask about, you know, who who an auto loan is
12:32
through or who a mortgage loan is through. And um you know it’s it’s
12:38
interesting to see the cooperation even among fraudsters across these these you
12:42
know chat platforms, social media platforms, how they share their
12:46
information. Um you know it kind of reminds you that you know hey this is
12:51
the opposition they’re actually you know well organized and and and
12:55
collaborative. Um it it really kind of underscores the need for that that level
13:00
of of communication and collaboration between industry stakeholders. Right.
13:05
Because you you the the other side’s doing that, right? We need to as well.
13:11
>> Yeah. Plus one to that. I like I uh somewhat endearingly call it organized
13:16
chaos where uh from a a fraudster perspective, they’re certainly
13:21
collaborating. Ah, sometimes the message falls flat or sometimes, you know, party
13:25
A tries to kind of do some bad stuff to party B. Um but in general that movement
13:30
is progressing nicely depending on how you want to measure it here. Um and they
13:35
are uh working together for a common goal which is basically exploiting our
13:40
our our businesses our customers etc. All right. Um kind of next topic here is
13:46
around calculating the cost of account takeover um and kind of measuring that
13:51
impact. So really the next few slides here just to kind of set the stage a bit
13:55
more. uh assuming like if you’re on the call today um either you have account
14:00
takeover or you kind of you’re preparing to deal with it in in some way shape or
14:04
form. And really to couch it a bit more want to at least say number one the
14:10
reports of account takeover we get and any business gets um is essentially the
14:15
the tip of the iceberg here. So certainly you have your your customers
14:18
that reported to customer service or call in or email in etc. Um but the
14:23
majority of account takeovers are unreported. And we see this um and I and
14:28
I saw this personally when I managed the the global spam ops team at Facebook
14:32
where many frauders would log in maybe they don’t change any information about
14:36
the account quite yet. But um we we counted that as an account compromise.
14:42
some businesses and I I often ask this to uh clients is do you measure do you
14:48
count an account takeover as someone accessing the account and then
14:52
transferring funds making a purchase or doing something that or if someone just
14:56
goes into the account takes a look around and exits does that still count
15:01
as uh or qualify as an account takeover but the gist here is that most account
15:06
takeovers are unreported because many consumers aren’t checking that app or
15:11
that thing every single day. Um and then in perpetuity here as account takeover
15:18
becomes more prevalent certainly uh that bad actor kind of uh action can permeate
15:24
throughout the industry and throughout kind of the ecosystem and especially if
15:27
you operate like a marketplace or an area where either consumers talk to
15:32
other consumers or some sort of peer-to-peer action going on that can
15:35
lead to a lot of kind of churn and things like that. And I’m thinking about
15:40
like a lot of dating apps or um marketplaces where you can can buy and
15:45
sell stuff. So with regards Oh, sorry, Justin, you
15:49
want to pop up?
15:50
>> Yeah, I was just going to kind of echo that point. It’s really important that
15:53
that you’re you know, what you see is the tip of the iceberg, you know, and um
15:58
the vast majority of ATO events are going to go unrecognized. You know, with
16:02
with um a transaction that’s fraudulent, you get that that charge back. you get
16:08
that notification atto I mean how do you identify that do you do you see like
16:13
churn you know just the many users are just going to leave and never come back
16:17
but never say anything to you about it so there’s definitely more more onus on
16:21
organizations to to be proactive in recognizing that it’s a problem it’s not
16:26
uh not as glaring of a problem most of the time
16:29
>> yeah that’s actually a great segue here when it oftentimes I work with like hey
16:33
how do you measure the cost of an account takeover um if we’re talking
16:38
traditional payment fraud where someone spins up a fake account, puts in a
16:41
stolen credit card, makes a $100 transaction, you get a $100 charge back.
16:45
Um maybe you have to spend some time disputing that chargeback or or dealing
16:49
with it. So there is some cost to that and I’ll kind of bucket that into the
16:52
short-term area. Um but when it comes to account takeover, the the toughest part
16:59
to measure here is around collateral damage. Um whether that’s damage to the
17:05
existing customer. So, if I’m the bad actor here, I compromise Justin’s
17:09
Coinbase account or something like that. Um, maybe Coinbase makes him whole at
17:14
the end of the day if I stole $1,000. Um, maybe they don’t and he churns. Uh,
17:20
maybe he doesn’t churn right away, but and plus not not all customers after
17:24
account compromise will churn. Uh but there certainly is a correlation where
17:29
if you measure it by like MPS score or um at at at at Facebook we used um uh
17:37
daily active users as the main kind of measurement here. We definitely saw a
17:41
drop off pre and post let’s say account compromise where the activity of that
17:46
user would go down post um atto even after you know we cleaned up the account
17:52
and gave it back to them. Some people just dropped off completely. uh most
17:56
people did come back in some way shape or form but their activity uh was
18:01
definitely diminished and so that’s one of the reasons why you know my team was
18:05
able to get funding and um kind of show like hey we need to address this
18:08
problem. The other area that um certainly your marketing team or your
18:13
bisops team will be more familiar with is around like customer acquisition cost
18:17
and things like that. So often times I tell fraud teams um to take a look those
18:22
metrics as well where and this is where it differentiates from kind of
18:27
traditional kind of uh stolen credit card fraud. there is a victim like
18:31
certainly your company is a victim but also your consumer or your customer um
18:36
is a victim as well and so monitoring the acquisition of these new customers
18:40
especially in today’s economy where it’s very much so about retention and
18:44
collecting new customers is is incredibly difficult. Um those are some
18:49
of the factors to look at when it comes to um calculating that overall cost uh
18:55
to the business. And something I didn’t mention at all here oh sorry go ahead
18:58
Justin. No, I I just didn’t want to get too far off that topic yet because your
19:02
example is a great example, but but something like Facebook is a really
19:05
sticky platform. Most of us on this call do not represent an organization that’s
19:09
going to have that stickiness that Facebook has with their user base. Um so
19:14
I would expect that turn to be even worse for for most most organizations.
19:19
>> Yeah, absolutely. Um and then one thing I didn’t call out here is around kind of
19:24
PR risks and things like that. That’s also difficult to measure for a lot of
19:28
companies. If you’re uh listed on a stock exchange or you’re a more
19:33
highprofile company, um having some of these whether they’re data breaches or
19:38
account takeovers um can be detrimental even if it’s just one one report.
19:46
All right. So, in terms of some um industry benchmarks, so these are things
19:50
that certainly my team tracks quite closely. Uh and we found some
19:54
interesting stats here. When it comes to account takeovers or attempted account
19:58
takeovers, we found that within our SIFT ecosystem, one in 300 login um is uh an
20:06
attempted rate when it comes to account takeover. And depending on the business,
20:10
one in 300 could be a lot, it could be a little um but it’s just a data point
20:14
that we found in that regard. Um and then the the next one is around um if
20:20
your company has some sort of like MFA or 2FA uh technology whether it’s like
20:25
SMS or inf notification or um uh email. Um the name of the game here is around
20:32
like certainly enabling the 99% of customers that are good but using this
20:37
particular tool relatively sparingly. Certainly it can be pushed back from
20:41
different product teams and growth teams like that. Um, but I’ve definitely seen
20:45
it used numerously um, successfully over and over at different companies um, when
20:51
it’s used appropriately. And then we’ll talk a little bit more about that in a
20:54
moment. Um, and really we want to make it as easy as possible for legitimate
20:59
users to successfully log in. So it’s not meant to kind of put up this brick
21:04
wall that even the account owner can’t get in or creating the barrier so high
21:08
that they can’t actually do uh, and engage on the platform. And so that’s
21:12
something to keep in mind as well when you’re factoring in like do I want to do
21:16
any take any action against account takeover like what are some strategies
21:19
to deploy. Um so I’ll leave it at that and um Justin to add there.
21:24
>> Yeah so it’s it’s extremely important to have these benchmarks or maybe your
21:28
organization calls them KPIs key performance indicators. Um and and to
21:33
your point Kevin you know it’s good to make external comparisons but there’s
21:37
going to be certain metrics that are that are much more organization
21:40
specific. So, is one of the 300 a low or a high number relative to any given
21:44
organization? Right? There’s a lot of different things to consider there. But,
21:49
you know what a question I often or or a concern I often hear about is, you know,
21:54
something like atto is difficult to measure. How do I know I’m measuring
21:58
this accurately? And another example would be like false positives, right?
22:03
Um, you know, it’s easy to measure chargebacks. Chargebacks come in. it’s
22:06
harder to measure when you um falsely decline a transaction that was
22:11
legitimate and and atto is more similar to that. Um and I guess just general
22:16
advice is that I would say is don’t get too hung up on whether you’re measuring
22:20
something perfectly. In many cases, it’s going to be an imperfect science. I
22:25
think what’s more important is is to just stay consistent in your methodology
22:29
of measuring these types of KPIs. That way you can identify fluctuations,
22:34
right? I’m doing better, I’m doing worse, or um those big short-term spikes
22:38
or or drops in certain activity or data. So, I guess, you know, generally, you
22:43
know, are we measuring this perfectly? Maybe not, but that’s okay as long as
22:47
we’re measuring it consistently because it’s more about recognizing change uh in
22:51
in many of these metrics.
22:53
>> Yeah, certainly. Plus one to that. And just to add on a little bit more, um
22:59
certainly when it comes to false positives in traditional payment fraud,
23:02
like not the same topic for today. I can talk for a long time about that, but
23:08
when it comes to account takeovers, one thing I just want to like point out for
23:14
folks is when it comes to attempted, let’s say I’m attempting a $100
23:18
transaction with a new account, maybe it’s a stolen credit card, there’s
23:23
different routes to take and ultimately maybe it’s like approve or decline. When
23:27
it comes to account authentication, um this is of course with an existing
23:31
account, they have a username and password, etc. there are different
23:34
things that you can do not to stop a transaction and this kind of segus
23:39
nicely into the next area around dynamic friction where it doesn’t have to be a
23:46
all or nothing and so Jess and I will will chat a little bit more about that
23:49
as well and so switching gears a little bit around the the topic of dynamic
23:55
friction and so really what I’m want illustrate over the next few slides here
24:00
is around that user journey and the different not pressure points but events
24:07
that you can and should look at with regards to user experience. And so
24:13
really when it comes to let’s say an account already has a login, they they
24:17
come into the account, maybe they enable a $10 gift card or something, um they’re
24:22
coming from the same device, so you have good transaction history with them. Um
24:26
this is probably a good example of a triedand-rue uh customer. You’ll
24:30
probably want to enable like one-click checkout for them.
24:34
Then maybe let’s say they browse some listings and things like that. That’s
24:37
also pretty normal behavior on your platform. Um so again kind of the the
24:42
numbers here indicate um let’s say prob not not necessary probability of fraud
24:46
but riskiness. So the lower the score the less risky they are. Um but then
24:51
let’s say they kind of do something out of the norm. Uh whether it’s changing an
24:55
email address or a password. If you are uh a marketplace maybe they post
25:00
something that’s like within a totally different skew or like the average order
25:04
is 100 bucks but now they’re posting something for a thousand bucks. um
25:08
anything sort of like out of the norm. That’s really where you can deploy um
25:12
something called dynamic friction where you don’t necessarily have to go that AB
25:16
route where it’s like cancel or or authorize it. There are other tools in
25:20
your toolkit that you can potentially deploy whether it’s SMS verification,
25:24
biometric verification and things like that. And more and more across different
25:29
companies and different verticals across different geographies um I’m seeing more
25:34
businesses use this type of functionality because it allows them and
25:38
I’ll mention it later around optionality on what they can do to hedge their their
25:43
bet or their risk here against potentially kind of fraud uh customers
25:48
um with regards to account takeover but still enable um a legitimate transaction
25:53
to get going and get through. And so that kind of leads to this particular
25:58
slide around hey what can we do to make account defense or um part of the part
26:06
of the product where again we know that I mean 99 plus percent of the population
26:11
or the consumers on our platforms are legit and we have a vested interest to
26:17
make sure that they are able to go from point A to point B whatever that is as
26:21
easily as possible and what are the things that we can do to make that
26:24
happen but we also know that, hey, there’s some other things that we can
26:28
also do to limit their access or let’s say they want to change their bank
26:32
account or do something that’s somewhat anomalous for that user. Maybe it’s
26:36
normal for maybe some big whale customer that you might have, but if it’s for
26:41
this smaller customer or they’re doing something anomalous, what are some
26:44
things that you could do to limit access or maybe pop in a 2FA out there via
26:50
your, you know, method of choice? Um, but these are all options that you can
26:53
can and should at least explore. uh within your company and how that
26:57
potentially could be deployed. Um I’ll pause there a moment, but Justin,
27:00
anything else to add there?
27:02
>> Um no, I I really like the the visual um well here, but also on the last slide
27:06
and then the what you mentioned the the optionality, right? I I think that’s
27:10
really the the um the idea of kind of a dynamic approach is you’re leaving
27:14
options open and um you know, you’re you’re considering different things. You
27:18
know, it’s uh what I really liked about the the visual before is it it focused
27:23
on the journey, right? and taking kind of that examining the
27:26
interconnectedness, right, of of the whole path a user might might might be
27:31
on. And I don’t want to talk too much about it because that that’s kind of a
27:35
big focus of what I’m going to talk about next. Um, but but I definitely
27:39
appreciate that that visual right there and what that’s conveying and and and
27:42
the the focus on optionality that you mentioned as well.
27:48
>> Awesome. Well, with that said, wanted to shift gears a little bit more for Justin
27:52
around kind of different approaches that businesses um are using out there.
27:58
>> Great. No, thank you, Kevin. Um so, yeah, I’m going to continue the
28:02
discussion around applying uh dynamic friction, those different approaches. Um
28:06
and again, from the login event through across the user journey and just just
28:10
some kind of general strategies and ideas around around how to take this
28:14
approach, how to think about this approach. Um, you know, I think uh most
28:20
discussions around fraud and risk management come down to to balance. So,
28:25
we’re referring to this now as is flow and friction, right? Flow versus
28:29
friction. Um, you know, it’s it’s not that hard to design a risk management
28:34
strategy that’s that’s, you know, nearly zero fraud, but you know, what’s what’s
28:38
the downside, right? How what are what are we paying in in in vendor and
28:42
operational costs? Uh how much friction are we applying? How many good users are
28:46
we turning away? So what’s really difficult is finding that right mix of
28:50
of friction and flow. Um you know use being you know performing more
28:57
stringent risk management checks when when you need more scrutiny but then
29:01
also letting things flow when they are lower risk and there’s no
29:05
one-sizefits-all approach. Um different organizations have different risk
29:09
appetites. um there’s different risk exposures and then even within one
29:14
organization every user every transaction every login
29:18
event is different um so really the only way to manage this is with an adaptive
29:25
dynamic and layered approach so I’m going to talk about three different
29:29
strategies here and and as I talk about the first one I’m going
29:34
to have to kind of lay a little bit of of of kind of groundwork for framing
29:37
this discussion so you this concept of dynamic friction. I think actually a lot
29:43
of people are already familiar with this from a a transaction risk screening
29:48
standpoint. And you can think of this as the different paths you might route an
29:52
order or a transaction on, right? You have your what I call like the fast
29:56
track, right? Low risk, low friction. You have kind of the more scrutiny,
30:00
higher scrutiny, higher risk, higher friction path. Um, but I would actually
30:05
argue that this dynamic friction approach works even better for the login
30:11
event for atto risk because your list of outcomes isn’t as narrow, right? Those
30:18
transaction paths, transaction risk screening paths ultimately lead to
30:22
accept, decline, review, right? But but what we’re gonna really talk about next
30:28
is a different way of looking at you know
30:32
what level of account access ultimately are you given an are you giving an
30:36
enduser and and you can get creative with that right you can reduce friction
30:42
but maybe restrict the account capabilities and then apply friction
30:47
before you allow access to to certain things right like like a page where you
30:52
could see some some PII I some personally identifiable information. So
30:57
I think to really think about this and to explain this I have to start with
31:00
this concept of um what I’ll call atto risk exposure right what is the risk
31:06
exposure to account takeover that your specific organization faces and and what
31:11
this really refers to is how much damage can someone do if they get unauthorized
31:16
access to an account. So for example, financial institutions
31:21
um you know any type of like like trading or or platform any anywhere in
31:25
like that kind of you know related to personal finances that’s really high ATO
31:30
risk exposure right you don’t want anybody having access to to to your bank
31:34
accounts investment accounts crypto accounts what about with merchants you
31:38
know this this varies widely um you know how easy is it to use stored payment
31:44
credentials what type of PII can someone see once they’re logged into an account?
31:50
What kind of account changes can they make? So there there there’s more
31:53
variables into what influences that risk exposure, that overall
31:59
atto risk exposures. But I think what’s a useful exercise is is for everyone to
32:05
think about what are the various things someone does t the t what the typical
32:11
user does or what someone feasibly could do once they are logged into an account.
32:17
and you could start like bucketing those different activities or those actions
32:21
based on the level of risk associated with each.
32:26
So, you know, logging into an account and and and browsing, right, is is very
32:31
different than um actually, you know, let me change my password, let me change
32:35
my my shipping address, let me add new payment cards, maybe I’m just testing,
32:41
maybe I’m, you know, taking over an account just to to card test. um or you
32:46
know using a stored payment credential for a new transaction, right? So so
32:50
think about these different things that someone is going to do or could do when
32:55
they’re logged in and then determine what um you know walls or or potential
33:01
friction events you might want to present at any point in time. And then
33:05
you can get really creative with what you allow an account um or user to do
33:12
and when they can do it relative to your level of confidence that the end user is
33:18
actually is the real account holder, right? Not not someone committing atto
33:22
fraud. So I think everyone here knows just because someone logs in with the
33:28
correct password on the first try, right? That doesn’t guarantee it’s not
33:32
atto. Um so what else can you look at right has that email and password
33:36
combination been com uh compromised somewhere else in in you know recent
33:41
history um you know is that login event coming from a an odd IP address you know
33:47
so these are things that mean elevated risk they don’t necessarily guarantee
33:52
atto right so uh maybe you know if you’re a financial institution you see
33:57
one of those things you’re probably presenting you know extra you know um
34:02
you know extra friction, stronger authentication right off the bat, and
34:05
you should. But if if if you’re a merchant, um or you’re, you know, your
34:09
ATO risk exposure is low, then you can really get more creative and say, “Okay,
34:14
um let’s just say you have an ATO risk
34:17
score, for example, right? And it’s somewhere in the low, middle, you know,
34:20
moderate risk range. We’ll let you log in, but maybe we won’t let you do we’re
34:26
not going to give you the keys. We’re not going to give you full account
34:29
access. And if you then attempt to do something that’s a higher risk exposure,
34:35
then we’re going to present that stronger authentication friction type
34:40
event. Right? So go back to those buckets or categories of activities that
34:46
an account might partake in, right? Um what are the varying levels of atto risk
34:52
exposure with with each of those different types of activities? And then
34:56
you can say, okay, well, if um an ATO risk score is low, they have full
35:01
access. If if a ATO risk score is very high, uh maybe we’re going to require
35:06
strong authentication right off the bat. If it’s somewhere in the middle, here’s
35:10
a a list of activities we can allow. Here’s a list of activities that that
35:15
they need to then do something else, right? We’re going to apply that
35:19
friction to be sure it’s the the true uh account holder. And I’m speaking about
35:26
things at a at a kind of a a broad level here. Um because this is going to look
35:30
so different across different types of organizations. And in many cases, it’s
35:34
kind of more of a mindset of of thinking outside of the box and have and allowing
35:39
that flexibility, right? Um what actions are are lowrisk enough to allow someone
35:44
to complete even though we have this inclination of atto risk. Right? Now, if
35:49
if you’re a bank, it’s it’s nothing, right? you know, login’s like all or
35:53
nothing, right? But but there’s many organizations that that have that, let’s
35:58
just call it creative flexibility and what you’re going to allow someone to do
36:01
before you, you know, you really um start compromising the user experience
36:06
to confirm their identity. And um I kind of have a list of those
36:13
potential trigger events that you could organize under those those buckets of
36:17
ATO risk here on this slide. Um, the second strategy, um, I’ll move
36:24
to next, unless there’s anything you want to, uh, chime in on at any time,
36:27
Kevin, please, please do.
36:30
>> Um, no, keep going. I have some thoughts. I’ll share.
36:33
>> I’m on a roll. Um, okay. So, um, the second strategy, um,
36:40
first is kind of saying, okay, why don’t I bucket different, um, you know, events
36:44
and then figure out when I need to apply friction, when I don’t. Another way of
36:48
thinking about this is are what are things we can do as an organization to
36:53
limit our ATO risk exposure once somebody’s logged in. And um again
36:59
thinking about kind of the the the previous set of considerations these
37:03
could be things you do across the board or these these could be um maybe think
37:07
of it as different account views right um someone who logs in with moderate ATO
37:12
risk we’re going to restrict what they’re able to see. Um, so there’s two
37:17
primary areas where you could kind of focus focus this. First would be uh
37:23
limiting information around account details. So think about where that’s
37:27
displayed. Um, typically anywhere where you would edit information about your
37:32
account, where you would update your email, change your password, um, add a
37:36
new payment card, uh, view existing payment credentials and the associated
37:42
billing address, right? where do you have PII uh displayed and kept? Um and
37:49
and you know in what cases can we obiscate
37:53
it, right? And and I would say as much as possible. Um and then I think the
37:57
other like kind of set of considerations is how easy is it for somebody to use a
38:03
stored payment credential, right? How much of that payment credential is
38:07
shown? Um, you know, I think pretty much the standard is to always require the
38:12
CVB and and actually check it, right? Are you also requiring an expiration
38:16
date? And I think sometimes we have to remember it’s easy for us to forget in
38:21
this industry. Um, because I think most of us tend to to take security best
38:26
practices, but our typical user does not. And I’ve seen some funny things
38:31
where for example uh you have the ability to add multiple stored payment
38:37
cards to your user account and you can name that card whatever you want. Um so
38:42
you know what it is, right? And the idea is it’s like oh this is my uh business
38:46
Visa, this is my um you know joint um master card, right? Um I’ I’ve seen
38:53
people put in full 16digit credit card numbers, right? So so they they know
38:57
exactly what card they’re referencing. um for them that’s okay, right? But if
39:01
someone takes over their account then that that information is right there for
39:05
them. So um you know what are those ways? What are the ways as an
39:10
organization you you can perform perform an ATO risk exposure
39:16
audit, right? What are those things that that
39:21
will will cause damage right to a to a a user um you know brand risk if if
39:27
there’s account takeover and and what what of these things can I where can I
39:31
reduce that exposure do I reduce that across the board or do I provide those
39:36
different account views um restricting information available based on atto risk
39:44
and uh the third strategy and actually let Let let you chime in here, Kevin.
39:48
Before I go to the third strategy,
39:50
>> just real quick, one other thing I’d add here is um people should not discount
39:55
the passive notification functionality that we many businesses deploy and we I
40:01
I’m a high proponent of and a a case in point example of this would be for
40:06
Netflix or for Google like if it detects a new login, you might get that push
40:11
notification says, “Hi, we we noticed a new login. If this is you, do nothing.
40:16
if this wasn’t you, you know, do something.
40:19
Even if that user is presumably, you know, attempting to make a transaction,
40:24
I as a consumer can say that I I like getting those notifications. And
40:29
granted, hey, we’re in the fraud space here, so I I like being kind of uh up
40:33
toate on the the status of my account, but in general, we run different like
40:37
sentiment surveys on this as well. Um and it can vary across industry like
40:41
certainly for like um banking and other fintech organizations like consumers are
40:45
like really thankful to get these alerts. E-commerce still thankful but
40:49
not quite as much. Um but it doesn’t mean you are blocking the transaction
40:54
and not allowing the consumer to do what they want to do. You’re simply
40:58
passively giving them the option to to say something is wrong if something is
41:02
wrong. And I’ve seen that been used as an incredibly good ground truth signal
41:07
to identify essentially at prevalence within the system. Um, and I I’ve
41:13
definitely rolled this out with a uh e-commerce marketplace where they
41:17
thought they had let’s say 300 account takeovers a week. It was actually closer
41:21
to 1,000 a week uh because they got 300 um notifications or like you know on the
41:28
if we’re we’re investigators, right? So, we’ll we’ll go into the account and
41:31
maybe we don’t have that SMS kind of uh feature, but we’ll say like, oh, someone
41:35
logged in from usually they log in from San Francisco. Today, they’re logging in
41:39
from Mexico City. Is that account takeover or are they just traveling? And
41:43
so, sometimes there’s that gray area of like, we don’t really know. But if
41:47
you’re able to leverage like SMS or other notifications, you get that
41:50
consumer ground truth relatively instantly. And that’s a really really
41:54
powerful signal to help identify or scope the the size of that issue. But
41:59
I’ll pause there just I know we’re a little bit short on time so I’ll let
42:02
Justin go through um point three.
42:04
>> No, that that was such that’s such an excellent point and I I’m I’m with you.
42:07
I agree. I sign up for all of those alerts myself, right? If it’s even if I
42:11
have to opt into it, I opt into it. I want to know all those alerts. Um maybe
42:15
not true for everybody, but I think that what was really valuable what you said
42:20
is how those alerts can close the feedback loop, right? Like is something
42:25
atto? Is it not? Right. it it provides that immediate feedback back to you
42:29
where you can um basically have that affirmation um this was not an ATO event
42:33
it was or this was and um that that provides so much more visibility. So, I
42:39
think that that’s really just a brilliant point that you made around
42:42
that aspect especially.
42:45
>> And actually, real quick, um that actually gets to a question. Actually,
42:48
no, I’ll take it back. We’ll answer Pam’s question in a moment, but she does
42:51
have a question on TFA, but please go ahead, Justin.
42:54
>> Okay. Yeah. And um I’ll go through the the rest of of uh this here to be sure
42:58
we do get to those questions because se several uh really good questions came in
43:01
and we’re going to try to get to all of them. Um okay, so the third strategy and
43:06
I’ll go through this quickly. This is actually related to a a slide that Kevin
43:10
that you showed that I said I really like this kind of that view and and this
43:12
is kind of just the idea of a holistic approach to risk management across the
43:16
unit uh user journey across all events. Um and the reason this is so important
43:21
is is um compounding risk signals, right? It’s one thing if if someone uses
43:27
a stored payment card to ship to a new address, right? It could be a gift, a
43:32
birthday gift, right, for a friend. It’s another if that follows um inclinations
43:38
or risk of atto at login, right? Like like each of those risk events in a
43:44
vacuum only gives you so much. If you look at the collection and the the
43:49
compounding effect of multiple signals where they have those interactions,
43:53
that’s extremely valuable. um for organizations that have a um a
43:59
modelingbased architecture, right? Like a modelbased
44:02
fraud score, a lot of those compounding risk factors are already taken into
44:05
account. Um you do want to be sure though that it’s it’s it’s going back in
44:10
time, right? It’s not just compounding risk factors at the transaction event,
44:13
it’s going back through through to the login event. Um a more rules-based
44:18
approach like that has to be a a compound logic rule, right? Okay, so
44:22
there’s a rule up on, you know, a new shipping a different shipping address,
44:25
but then there’s a different rule on also another risk signal that compounds
44:29
that. So just just keep keeping in mind the interaction of multiple risk
44:34
signals. And when risk signals A and B happen at the same time, there’s that
44:39
multiplier effect. Um, so that really does often require looking across the
44:45
whole journey. Okay. And I do want to leave time for
44:49
questions. So I think the last thing we were going to talk about was um
44:52
predictions in this industry um going forward.
44:56
Um yeah Kevin, you want to go first?
44:58
>> Uh sure. So I mean I’ll take a bit of a contrarian uh piece here and I’ve spent
45:06
years and years kind of working through this and dealing with myself at at
45:10
different companies and also consulting with many many others here. And I mean
45:16
even when we opened up this this uh talk we talked about um headlines of like
45:20
data breaches and number of accounts exposed and all these things and yes
45:24
that’s absolutely true and I think it’s going to get worse but to be honest when
45:29
it comes to getting change at the company level um where I’ve seen it work
45:35
equally well maybe somewhat unjustly well is pro providing those that
45:40
anecdotal evidence of this is where we like effed up or this is where like like
45:47
shit’s hitting the fan and it’s that one user story, that one PR story if it gets
45:52
to that point, but or if there’s let’s say an exec has their account
45:57
compromised and like your team has to deal with it, right? Those are some of
46:02
the things that can affect change and that’s kind of like a squeaky wheel
46:05
approach. So, I’m not saying it’s the best for everyone, but I have seen it
46:09
used effectively where there’s like the the the big data sets out there in terms
46:14
of like 65% of consumers reuse the same password over and over again. In some to
46:20
some cases, I feel like we get numb to that. Where it gets a little bit more
46:24
personal, frankly, is if someone within the company has their account
46:27
compromised or um there’s yeah, some exec that has to deal with it or passes
46:32
it to you to deal with. Um those are some opportunities to elicit change.
46:37
They might be painful opportunities, but I have seen it work out well um to
46:41
elicit that that type of change.
46:45
>> Uh that it’s I I agree and it’s it’s um a really valid point. You know,
46:49
typically from a from a consulting perspective, you know, most
46:55
a lot of things are reactionary instead of proactive, right? Un unfortunately.
46:58
And there is some emotional event, some big event, hopefully it’s not a PR
47:01
event, right? that that that that’s what enacts action and gets change. Um but un
47:08
you know unfortunately that’s the case that it’s if you can’t take a proactive
47:13
approach it’s better than being reactive though. Um all right my my prediction um
47:19
I try to avoid cliches but I mean I don’t think there’s escaping it here. Um
47:22
it’s probably going to get worse before it gets better right when you think
47:24
about atto activity it keeps ramping up. Um, as I mentioned before, fraud’s
47:29
diversifying and atto the point that you mentioned, um, Kevin, uh, with, um, you
47:37
know, reusing passwords, right? Atto kind of is been this path of least
47:40
resistance, but I think if you take a longer term view, um, maybe
47:44
optimistically a medium-term view, there’s some really encouraging
47:48
developments on the horizon. I think even consumers know reusing passwords is
47:53
not secure, but that doesn’t stop them, right? So I think the real potential uh
48:00
for improvement here is around passwordless authentication.
48:04
Um now I really do have to kind of present this with a grain of salt. So I
48:08
mentioned you know I’ve been in this industry for over 10 years. Uh the phto
48:11
alliance formed 10 years ago in 2013 and the phto uh alliance their their goal is
48:18
reduce the over reliance on static passwords. So this has been a known
48:21
problem for a decade and I don’t know how much progress have we really made
48:24
right. Um but what changed recently right Apple’s pass key and u it was
48:31
actually Apple, Google and Microsoft they all committed to expanding support
48:36
uh for passwordless authentication. So um I think one thing we’ve all learned
48:41
in this this industry is there’s no silver bullet but this is definitely a
48:44
meaningful step in the right direction. So I think I think that’s encouraging
48:48
news. And um you know just real quickly um in the
48:53
interest of time I’m going to keep this one really short and I don’t want to get
48:55
too technical but what about NFTTS for um uh identity right um I would just
49:03
encourage anyone who’s interested in that to look at this look up the concept
49:06
of a soulbound token um and I don’t want to talk too much
49:10
about it because it’s too technical and we’re running out of time but um it who
49:15
knows if that’ll come into fruition but it’s it’s interesting it’s very
49:18
interesting. Justin, soul bound NFT. That sounds um
49:23
I’m gonna do some more reading on that one. That sounds something like out of a
49:26
Marvel pick, but I’ll I’ll leave it at that.
49:30
>> It’s It’s interesting. Yeah, Soulbound tokens. It’s a Ethereum based NFT. Um
49:36
okay. Um there was some excellent questions. Um,
49:43
so this question, um, uh, this person asks,
49:48
“Big question at our company right now. Should we allow our users to opt out of
49:53
2FA, two-factor authentication?”
49:56
>> Awesome. I don’t actually get asked this question as much, but um, I’ll give you
50:00
a kind of a a two or three-prongong answer here. Um, so it sounds like it’s
50:05
already mandatory, and I know companies like Airbnb for the longest time, they
50:08
didn’t make it mandatory. Certainly for hosts they made it mandatory. I think as
50:12
even as guests they now make it mandatory. Um but it’s wonderful to have
50:16
this type of discussion uh within kind of the company walls here. My thought
50:21
process there is that yes, you should give and in the true meaning of
50:27
optionality like you should give consumers or your customers here the
50:30
ability to opt out if they want to unless it’s you know you’re dealing with
50:34
like high stakes um uh transactions and things like that. But I will try maybe
50:43
shifted the conversation a little bit to more like gamification where like if you
50:47
opt out of 2FA then do you lose some access or some right and to flip it
50:52
another way and this is more to promote uh more 2FA uh or opt into 2FA. Um, I
50:58
definitely did it uh when I was at Google where like if you practice good
51:03
password hygiene or if you sign up for 2FA you get let’s say more Gmail storage
51:08
or you get um additional credits in AB and C. So it’s something relatively
51:12
lightweight for for the company and it actually promotes in some cases more
51:16
stickiness by the consumer but they there’s a give to get model here where
51:20
it’s like fine I will sign up for 2FA even as as a consumer maybe I’m not a
51:24
fan of it but if I get whatever coupon or functionality or access to this or
51:29
that then I’ll I’ll do it and so that can be a win-win for both the consumer
51:33
and the company and your your team. Um so thanks Pam for that question.
51:39
people respond to incentives. That that’s I never even really thought about
51:42
that, but that’s a great idea, right? Incentivize it in some way. I mean, you
51:45
know, we prefer to if they I requested I opt in for it, but that’s not the case
51:50
for everybody. Um there’s not really a whole lot I can have to add to that and
51:53
um I want to try to get to a couple more questions and I’m just going to go
51:56
through these in order. And let me say that um I think we’re going to reach out
52:01
to you personally if we do not get to your question here. Um we we will reach
52:05
out after the webinar to answer your question. And I’m I’m going to I think
52:08
just go in the order in which we receive them for answering live. Um so the next
52:12
question was what is the best practice treatment option when we detect
52:16
potential out of pattern uh behavioral patterns but there is no payment
52:21
initiation or action done by the perpetrator? Essentially when do you
52:26
take action? um keeping in mind um there’s going to be you know a lot of
52:31
false positives and and you know you don’t have the you know it’s it’s an
52:35
operational strain to investigate every single one of these types of of alerts
52:39
if it’s not associated with a payment event and um I can speak to that a
52:43
little bit first and then invite you to chime in also Kevin um yeah you know I
52:47
kind of go back to those uh different events and triggers that are associated
52:51
with different levels of atto risk exposure um you So I I would I would
52:58
eliminate focus on just the payment event because
53:02
someone could be scraping PII as well, right? So there’s definitely real
53:07
concern here. But I also understand that you you know we all have limited time,
53:12
limited staff, limited resources. We need to focus our efforts. um if if
53:17
there’s any way to to see even though there’s no payment action or initiation
53:23
that type of event are is someone visiting the account details page right
53:28
I think trying to change a password trying to change an email address
53:31
typically to lock out the real account holder um that’s that’s that’s a real
53:37
event right someone making a payment um or initiating a transaction that’s a
53:41
real event that you’re probably going to have a trigger on but there’s other
53:44
things people could do you could something to be weary of. Now, the
53:47
question of how do I allocate my resources and determine what’s more
53:51
important. You know, that’s that’s tricky. Um there’s a lot of
53:54
organizational specific considerations there. Um but I guess I would say um
53:59
don’t narrow your scope too tightly either, right? There there’s a lot
54:02
beyond the payment event that’s still has the potential to to be a serious
54:07
issue, serious brand risk, um you know, some some news story in the future.
54:15
Thanks, Chester. And the only thing I’ll add to that is um what is the severity
54:19
of a false positive for the business? And and I and I say that because um if
54:26
you count a false positive as you send out a passive notification then and and
54:31
the person says yes, this was me. Is it that severe? Some companies maybe
54:36
it’s like out of the question that’s like very harmful. Some you like no
54:40
that’s okay. Like our consumers are okay with it. We’ve done some sentiment
54:43
analysis around like they actually enjoy getting these these these prompts and
54:46
these notifications. Um, and so it’s something it it can vary company by
54:51
company a little bit. One thing I I’ll highly recommend is doing some AB
54:55
testing if you have the capability where you don’t want to roll 2FA out overnight
55:01
to 100% of the population. Like I wouldn’t I I just wouldn’t recommend it.
55:04
It’s going to take some time. Um but to do it in a controlled fashion where
55:09
internally you might have those naysayers like I want to avoid false
55:12
positive at all costs but okay give me or give my team some flexibility here to
55:18
validate some of these issues. We know that there’s this kind of pain coming or
55:23
we we hear consumers talking about getting um compromised. So we got to do
55:28
something and so let’s experiment with it. Put it into a more controlled
55:32
setting. Again, we’re not going kind of boil the ocean approach here. Not yet,
55:35
anyways. But let’s run it with a subset of the population, see what we gather,
55:41
and then make some more educated decisions after that within our own
55:45
ecosystem. Hopefully, that makes sense.
55:49
>> It does. Makes sense to me. Um, all right. Um, we’re running out of
55:53
time, but maybe we’ll squeeze one more in. And, um, I’m kind of doing this
55:57
again, first come, first serve. Um but if uh again we’ll we’ll uh someone will
56:02
reach out to you with with an answer to your question because there are several
56:05
more that I’m not getting I’m not able to get to. Um the question is we
56:09
currently integrate email change as an update account event and have not seen
56:13
scores jump higher uh in I guess in response to that event. Is there a
56:18
better um integration than update account that would specifically detect
56:23
email change um that could potentially change the
56:26
score?
56:28
>> Um so I can take that one on and whether it’s I mean using SIT or you have an
56:32
internal engine or or something else here that’s a common thing when it comes
56:36
to ML versus rules like I’m actually a proponent of both.
56:41
had to build these systems from the ground up for a number of companies and
56:46
not one strategy wins in terms of like I’m only using rules or I’m only using
56:51
ML. Um so what I’d say there is definitely deploy um a rule like if if
56:58
there is uh and and test it of course in terms of the efficacy where if it’s
57:03
password change or email change um and you want to force a review or force um
57:09
an SMS notification or something um you can hardcode that rule. Hopefully, it’s
57:13
easy enough to to to implement at your company, but make the change so you
57:18
actually get that feedback. QA it of course to make sure like you know what
57:22
are we seeing here and then adjust uh accordingly. Um and then over time like
57:28
ML models may take some time to learn but at least if you want to really focus
57:32
in on that subset of the population, make it a thing for a short amount of
57:37
time for a limited sub subset of the population. gather that data and
57:41
hopefully the system allows you to quickly uh either put that rule in, take
57:45
that rule out, augment it as you wish and then the scores as you and you know
57:49
as you find good and bad accounts should address adjust accordingly.
57:56
>> Great. Excellent. Um a lot of really good questions. Um you know the the the
58:02
three that we addressed were were submitted in the first 30 minutes of the
58:05
webinar. Um, but like I said, we’ll we will reach out to the the remaining um
58:10
question askers as long as it wasn’t anonymous. Um, and a recording of the
58:16
webinar will be provided um very shortly uh tomorrow. Um, we’re going to try for
58:21
tomorrow, Friday at the latest. Uh, you’ll receive a link to where you can
58:25
view the video uh for this webinar. Um, Kevin, thank you so much. I I think we
58:31
we we covered a lot of ground and and and talked about some really interesting
58:34
topics and uh definitely enjoyed uh co- co-presenting this in uh webinar with
58:39
you.
58:40
>> Um and we like to thank everybody thank everybody for attending.
58:46
>> All right, thanks everyone. Um look for the video soon. Bye.