Hear from Rebecca Alter from Sift, Tom Voaden from BR-DGE, and Melisande Mual from The Paypers as they reveal insights into crafting a comprehensive fraud strategy for merchants.
- Tips for payment orchestration: Explore best practices, optimization, and key considerations in payment orchestration for seamless financial operations.
- Strategic fraud defense: Understand the surge in fraud and adopt a comprehensive trust and safety approach that accelerates business expansion.
- Secure smooth transactions: Discover strategies to safeguard against risks in network token adoption, from PSP compatibility challenges to vendor lock-in.
Watch the On-Demand Webinar
Video Transcript
0:01
So good morning or good afternoon and welcome to our webinar titled enhancing
0:06
fraud operations through network tokenization and payment orchestration.
0:11
My name is Melisand de mobile publisher of the papers and I’m delighted to be
0:15
the host of today’s webinar with our partners sift and bridge and thank you
0:20
so much for joining. It’s great to see so many of you tuning in today.
0:25
So what’s the story? Well, as the payment and commerce landscapes evolves
0:30
with each new card and currency, it’s it presents both higher returns, but also
0:35
unforeseen risks. And in 2023, businesses crappled with a significant
0:41
increase in fraud, including a 354%
0:45
surge in account takeovers. And this impact was felt across various
0:50
industries, notably travel, retail, and fintech, leading to substantial losses.
0:57
And to tackle these challenges, industry collaborations and partnerships have
1:02
become crucial. And in today’s session, we will explore how SIFT and bridge
1:06
collaborate to offer merchants a comprehensive fraud prevention strategy.
1:11
We will focus on two two key strategies to secure and scalable growth in
1:15
volatile and vulnerable markets. Network tokenization and payment orchestration.
1:22
But before introducing today’s speakers, I would like to start with some quick
1:26
notes regarding housekeeping. The discussion will take approximately 40
1:31
minutes and we will have 10 to 15 minutes for a Q&A at the end of the
1:35
discussion. So on the right side of your screen, you can see the chat panel which
1:39
includes a chat room and a Q&A widget. You can ask your questions at any time
1:46
throughout the discussions and please use the Q&A widget for that.
1:50
We will compile your questions and the speakers will take as many as possible
1:54
at the end of the discussion. And I also would like to draw your attention to the
1:59
handout session. The handout section, you can find a very insightful asset
2:04
over there. It’s the SIFT 23 Q3 ATO account takeover index report. So do
2:10
take a moment to download this. So today I’m joined by Rebecca Alter.
2:18
She’s trust and safety architect at SIFT and Tom Fodden, head of partnerships at
2:23
Bridge. So, hi Rebecca.
2:26
>> Hi, Tom.
2:29
>> Hi.
2:29
>> Hi. Great to see you. How are you today?
2:33
>> Oh, good.
2:36
>> Great. Um, Rebecca, could you tell the audience a bit more about yourself, like
2:42
your role and um, well, your career so far?
2:46
>> Yeah, happy to. So, as mentioned, my name is Rebecca. I am a trust and safety
2:51
architect here at SIFT. Um, what does that mean? That means that I help build
2:56
out um our product. I help um customers think strategically about how they can
3:01
build out their fraud program. Um, and I also help train our our various members
3:06
within our organization. Um, why am I equipped to do that? While previous tot
3:11
uh I’ve built various fraud preventions teams throughout several um different
3:16
fintexs so primarily um doing dispute management for Square now block um and
3:23
then I transitioned to a company called Gusto which specializes in payroll
3:27
across North America. And then lastly um I was at Stripe where I I was deep in
3:32
understanding um international payments and creating a better user experience
3:36
for all of our Stripe customers. Cool. Well, thank you, Rebecca. Um, Tom, could
3:42
you tell the audience a bit about yourself as well?
3:44
>> Yeah, sure. So, I’m head of partnerships at Bridge. Um, I come from a scheme
3:48
background. I think through many years working uh at a scheme, working with
3:54
merchants, enabling partners, acquirers. What I was able to identify was was the
3:58
real need for orchestration. Um, that really excited me. Um, and so few years
4:03
ago moved over to Bridge to to look after the partnership side. What are
4:06
partnerships at Bridge? Partnerships at Bridge are basically all of our
4:09
relationships with industry partners, gateways, acquire schemes, fraud tools,
4:13
payment methods. It’s really key to us, you know, as I’ll come on to, at one
4:18
level, excuse me, we’re an aggregator. Um, we’re nothing without our
4:23
partnerships. We need partners to, you know, to have on our platform to utilize
4:28
our technology. Um, and as I say, you know, we wouldn’t be able to serve our
4:32
end merchant customers without that.
4:34
>> Great. Thank you, Tom. Um, so yeah, I’m really looking forward to um to the
4:40
discussion and for the audience, thanks for tuning in, but also do engage with
4:45
our speakers. Rebecca and Tom would love to take your questions. So don’t be shy
4:49
and use the Q&A widget to send in your questions. So let’s kick off and um tell
4:55
the audience a little bit more about Sift and Bridge. Um so Rebecca, if you
5:01
could start to give a little bit of background on on Sift.
5:04
>> Yes, of course. So, Sift is a digital trust and safety platform. Um, what does
5:09
that mean? That means that we help our users protect um their payments and
5:13
their account loginins and their customer journey against nefarious um
5:17
transactions or actions on the account. Um, and we do that by um using our large
5:23
global data network to create advanced machine learning models as well as um
5:28
deploy different rule sets. And then of course um at the end of a transaction we
5:32
can also help you manage your chargebacks.
5:35
>> Brilliant. Thank you Rebecca.
5:39
>> Yeah. So we’re an orchestration platform. Um what that means is you know
5:43
as I say on one level we aggregate services. So we have a product suite and
5:47
one of those those products is bridge connect. What that is is is ultimately
5:51
that grouping of all of those those players that I mentioned. So gateways,
5:54
acquirers, fraud tools, payment methods and others. But then you know we’re not
5:59
just an aggregator. We are an orchestrator and what that means is
6:02
we’re then able to to work with merchants and partners to add logic,
6:06
create workflows, ultimately to to optimize payments um to make sure that
6:10
payments are are likely to be approved and ultimately so that the end consumers
6:15
have the best payment experience possible.
6:17
>> Okay, thank you Tom. And maybe if you don’t mind me asking, you say like
6:20
there’s an aggregator and there’s an orchestrator. So what is what is the the
6:24
key differentiator there? I think it’s it’s back to that point
6:28
that you know we we’ve built a almost a piece of middleware which sits between
6:33
enterprise level merchants and downstream payment providers. Um now to
6:38
facilitate the flow of transactions we need to be an aggregator ultimately
6:42
we’re an independent platform. We’re letting merchants um and partners
6:46
deliver that volume to where they want it to go to those downstream gateways
6:49
and acquirers utilizing thirdparty technologies such as fraud tools. But
6:53
the orchestration piece comes in in terms of how we make that more
6:56
intelligent. You know, it’s it’s how you utilize those connections. As I say, add
7:00
in those workflows and hopefully that ends in a in a better result for
7:03
everybody.
7:04
>> Very clear. Thank you, Tom. Um, so let’s start uh talking a little bit more about
7:08
fraud and what SIFT is seeing in uh in their network. Um so the agenda for
7:15
today as I mentioned we start talking about fraud the escalating fraud demands
7:20
and how it asks basically for a comprehensive solution. We’ll talk about
7:24
payment orchestration best practices optimization and critical considerations
7:29
and we will address strategies to navigate the risks of network token
7:32
adoption and the incomparability with certain PSPs and and vendor lockin. Um,
7:39
so Rebecca, um,
7:45
>> yeah, I’m happy
7:48
>> I’m so sorry. This is Oh,
7:52
>> that’s okay. I’m happy to to jump in here. Um so as we kind of mentioned um
7:58
at the beginning here, what we’re seeing um at SIFT in particular over the last
8:03
two quarters is just a massive surge in account takeovers across our businesses.
8:08
Um so we’ve actually seen a 354% year-over-year increase in account
8:14
takeovers across um the SIFT global network and that’s on the back of um the
8:19
previous year having 121% increase. So what this means is that more and more uh
8:26
fraudulent actors are having access to individuals information and they’re
8:30
finding it it’s actually easier to take over account than to create a synthetic
8:35
identity or to um hack it or well they are hacking through ATOs but to create a
8:41
synthetic identity um it’s just easier to access somebody’s already good
8:45
account. Um in particular we’ve seen a really stark increase in fintech and
8:49
food and beverage. So in fintech in particular, there is an 808% rise in
8:54
account takeovers. I think this is um on the backs of cryptocurrencies and just
8:59
new technologies that are entering the the marketplace. Um people oftentimes
9:04
ask me why did you see a rise in food and beverage? Uh my best guess here is
9:08
that you know food and beverage is a necessity and so we’ll always see
9:12
individuals willing to um enter or into engage to getting different food items
9:19
for free. I also think there’s a bit of thought like, you know, well, what does
9:23
it matter if I get a um a hamburger for free, for example? It’s okay. It’s not
9:28
going to harm anybody there. So, we see people more willing to engage in this
9:31
this type of activity when it comes to food and beverage. Um, but why does this
9:34
matter so much to businesses and and I think this stat is one of the most ones
9:39
that I found the most intriguing is that 79% of consumers told Sift that they
9:44
would go ahead and leave a brand if their account had been compromised. So
9:47
business spend so much time and energy building trust, acquiring that customer,
9:52
and then if their account’s taken over, they’re going to leave. And so that’s a
9:54
huge cost to your business and a huge cost to churn. So it’s really important
9:57
that you as a business protect your customers account so they can continue
10:02
to have a positive experiences with you and your brand as they go ahead and shop
10:05
online. Um,
10:08
>> so so Rebecca, this is what you’re seeing in in your network, which is
10:11
pretty substantial.
10:13
>> That’s correct.
10:14
>> Yeah. So let’s ask the audience like whether they have experienced account
10:18
takeover. Um so if we can launch the poll question here.
10:24
Yeah. So we would like to know have you or your organization experienced an
10:28
account takeover problem? It’s either your account or have you as
10:33
an organization offering accounts because the numbers you just mentioned
10:38
are substantial and also the the search in
10:42
this growth. Seems like a lot of our um
10:47
participants here have also experienced an account takeover. So yeah.
10:53
>> Awesome.
10:55
>> Well, that
10:56
>> let’s have a look. Let’s have a look at the uh the audience what they’re
11:01
>> Oh, wow. Wow. Lucky for for the audience members here.
11:07
>> Okay, let’s move on. Um, awesome. And then also to I always
11:15
think it’s good to level set here. So how big is the problem that we’re
11:18
talking about? Um, so we think about payment fraud as a global industry. And
11:22
actually if you were to take the aggregate loss of fraud across global
11:27
companies, it would reach a 48 billion dollar uh industry which would make rank
11:33
it and revenues um one of the top uh revenue generating businesses in the
11:38
world which I always find quite um outstanding when you see this number
11:42
against the likes of you know an alphabet or a Birkshar halfway just to
11:47
um see there is a real industry here and it’s not just an individual actor it’s a
11:52
group of people that are working together um that are highly connected
11:55
and highly skilled um trying to gain funds here because there is real money
11:59
to be had in this industry. Um and not only is there real money but
12:05
there again like I said the fraud ecosystem is really well connected. Um
12:09
so it’s not just one type of fraud. I know I mentioned talking about account
12:13
takeovers at the beginning but there’s also payment fraud, content abuse and
12:17
different types of things that they can do within each of those vectors as well.
12:20
So, it’s a well-connected system and they’re all working together. Maybe
12:23
they’re getting PII from one website, they’re getting credit card data from
12:27
another website, and then they’re committing the crime on a third website,
12:29
but they’re all working together and it’s the same actors with the same
12:32
information. And not only are they wellconed, but also, as I mentioned,
12:37
it’s becoming more and more complex. So, consumers want to have ease of use and
12:41
they want to have flexibility in their spending, and brands want to give that
12:45
to them. But what does that mean for you and your fraud teams? It means that you
12:48
are fighting against more and more types of abuse. So, crypto scams, buy now pay
12:53
later, car testing, the dark web, refund abuse, currency conversion, promo abuse.
12:59
I mean, the list can go on and on. All the different ways in which your um
13:03
businesses can be susceptible to this type of fraud. Um, so how do you block
13:07
this? Right? So, we know this is going on. We know it’s complex. We know it’s a
13:11
big problem, but how do you prevent fraud for your business, especially at
13:15
scale? Right? So I think I hear where I talk to a lot of different people that
13:20
um you know they started their program off the spreadsheet but how do we get
13:23
beyond the spreadsheet and to build a more scalable solution uh for
13:26
individuals. So we describe it to how to win at
13:31
scale. So there’s these five pillars that we really think make the bedrock of
13:35
a winning fraud program. Um so the base foundation the base layer here is high
13:40
volume uh digestible data. So there’s so much data that is available to various
13:46
websites and to sift um based upon their customers journey and how they’re
13:50
interacting with the internet, where they’re navigating to, how they’re
13:54
coming to your site, what time of day they’re getting to your sign up flow,
13:57
what information they’re putting in your signup flow, how they’re putting their
14:00
information in your signup flow, for example. I know copying and pasting or
14:03
or doing it at speak a good example. So there’s all this really rich data that
14:08
we can gather um that gets us to be able to profile or to understand that end
14:12
user to make sure that we can um guess their intention on your website. Is
14:16
their intention going to be a good intention to be a positive experience or
14:20
or maybe they’re trying to take advantage of you. Um and then also not
14:25
only before your website and the signup flow, there’s also so much valuable and
14:29
rich data while they’re on your website. So you can get browser information, you
14:33
can get behavioral biometrics. Um, one of the things I like to say is uh, you
14:38
know, fraudulent actors rarely spend time in your help center. So if you see
14:41
a lot of, um, good users really navigating those help center page and
14:44
really being confused. It’s like, okay, they’re doing something weird, they
14:47
might be testing the site, right, or just wanting to know how it works as
14:50
opposed to taking advantage of it. So that’s an example I like to share with
14:53
people. That’s a good thing where, you know, you want to map out your good
14:56
users flows and also your bad users flow. And there’s so many pieces of
14:59
information. Um, and then what we do here at SIFT or what you could do as
15:03
well is create your own machine learning model where you take all of that rich
15:07
data and you put it into um this machine learning model that really captures um
15:12
the identity. So again, I mentioned maybe someone’s giving you an email
15:16
address or a birth date at your signup flow. Um, their behavior, so how they’re
15:20
navigating on your website. I think transaction history is so important. So
15:24
you know what’s the velocity? What’s their normal spin patterns? there’s so
15:28
much that you can extrapolate just just on those transactions levels and then
15:32
also the similarities. So is this usual experience for them? Um is this not
15:36
usual experience for them? So do they normally never log in with a tour
15:40
browser and all of a sudden there’s an account and they’re using your tour
15:43
browser to buy a $1,000 you know item when they normally only b pay between
15:50
100 and 500 normally. So we can take all of that at scale, right? And um either
15:54
approve transactions immediately or reject transactions um or cue
15:58
transactions up for varying users reviews or the typical patterns here
16:02
that we see. Um machine learning is an amazing
16:06
powerful tool and it really enables your business to move at scale. But just
16:10
having grown my own fraud teams, I I do think there is definitely uh room for
16:15
workflows and rules automation. I find uh various rules triggered especially in
16:20
the middle of a fraud attack to be really important. So um when you’re in
16:23
the active fraud attack, time is of the essence. So it’s really important to
16:27
just stop the bleeding when it occurs. So maybe that’s a really simplistic rule
16:30
that you don’t want to have all the time. But hey, my company is under a car
16:34
testing attack. I actually want to block all transactions from this specific IP
16:38
for a limited number of time. and you can deploy those tools automatically and
16:42
in that the time you can stop the bleeding or you can work with your
16:45
engineering and your product teams um and your strategy teams to build out
16:49
your longerterm solutions and to get those embedded into your product um and
16:52
then you can remove those rule sets um once you’ve mitigated that actual issue.
16:57
Um, so I do find that there’s really strong value in these workflows, in
17:01
these roles and automations. As I mentioned previously, sometimes you
17:06
might be unsure of a transaction. Uh, you might be looking for some manual
17:11
review. And so you want to give your your analysts or the the individuals
17:15
that are working uh the the right tools and then also you want to give that
17:20
model um feedback so the model can understand new fraud trends you’re
17:24
seeing on your platform and also can again to understand those good
17:27
transactions or the the good flow so you can reduce your false positive rate. Um
17:31
and it’s really important for your users that you give them the tools to what I
17:35
always say is you want to um make your tools so that your uh employees are able
17:41
to uh make uh information calls for spending time gathering information. So
17:46
I see a lot of setups where people have to click in multiple locations. They
17:49
have to go around to different call actions and all that adds time and and
17:53
it doesn’t give them the benefit of just having all that information in front of
17:56
them so that they can make the best decision possible. And then also the
18:00
ability to take action, especially the ability to take action in bulk. So, as
18:03
we know, fraudulent actors like to work. They are well connected. And so,
18:06
sometimes we’ll see these large fraud rings and you’ll need to take down lots
18:10
of varying um sites at the same time. And so, it’s good to be able to take
18:13
action and to take action and bolt. Um and the last part here is how do you
18:18
know that this is successful? Right? So, I’m doing all these things, but what are
18:21
my key measures of success? And so, you know, I think that really depends upon
18:25
what part of your fraud program you’re monitoring. Are you monitoring um your
18:28
false positive rate or your customer experience? Are you monitoring your
18:31
loss? So, you want to look at your chargeback rate or your refund abuse?
18:35
Are you um and then also what type of fraud are you monitoring? So, making
18:40
sure that you’re having like the right metrics at the right time. I think um
18:43
metrics are so important to informing you and regular real time monitoring of
18:47
these programs is also so important so that you know again I think speed of of
18:51
the essence when it comes to measuring fraud. So real time monitoring, lots of
18:56
um individualized metrics so you can really get to the root of the problems
18:59
are are super important here.
19:02
>> Thank you um Rebecca for these great insights and um I would like to take uh
19:08
to basically give over to uh Tom uh who will talk about the orchestration role
19:14
in enhancing your fraud operations. Um so Tom, over to you.
19:19
>> Fantastic. Thank you. Um, so I’m going to talk through a little bit about
19:22
Bridge, who we are, um, a high level our product set, and then hone in on to both
19:27
network tokenization and also how we work, um, to combine that with with
19:31
fraud tools such as SIFT. Um, so just a little bit of background
19:35
on Bridge first. Um, so who are we? You’ve probably been been around less
19:40
time than uh than Sift. So some of you may not know us. Um, we are a UK based
19:45
um, orchestration platform operating globally. Um we’ve been around since
19:50
about 2018. Um and really what we’re targeting is enterprise level merchants.
19:56
Um and also as I say working very closely with partners. What we’ve built
20:00
is is ultimately a piece of infrastructure which is formed by the
20:04
five products that that you see on screen. Um so it’s all the way from
20:07
integrate which is how you connect into our platform through to the insights
20:11
that we provide and the optimization that I spoke about. Today we’re really
20:15
gonna just hone in on the the vault piece which is our network tokenization
20:19
engine and then the connect piece which is our aggregation as I say and the uh
20:24
the connect piece is is where SIFT sits within our platform as well.
20:31
>> So just stepping back a little bit um some of you may be familiar with network
20:35
tokenization it’s certainly become you know similar to orchestration and has
20:39
become a buzzword in the industry. Um what is network tokenization? Network
20:44
tokenization is a EMV code so a scheme level initiative which ultimately aims
20:50
to replace PAN to replace the the 16digit card numbers with a new digital
20:55
identifier. There’s a whole host of reasons that
20:58
that this is being driven into the market. I’ll come on to to some of the
21:01
benefits shortly. Um but the key thing is is that a network token is unique um
21:08
not only unique to the card but it’s also unique to the merchant or device
21:11
and that builds a whole new layer of security in and around the transactions
21:15
which is why it’s being push pushed so widely in the industry
21:19
in terms of how how we’ve worked with that um as bridge we have ultimately
21:24
built an independent network token engine what I mean by that is we’ve
21:29
connected directly with the schemes um so multiple schemes and we’re constantly
21:33
broadening that list of schemes that we’re working with as well as as they um
21:37
kind of broaden their enablement globally. Um and what that means is that
21:41
we can offer merchants, we can offer platforms, we can offer payment partners
21:45
the ability to access network tokens from the schemes via our um via our
21:50
platform and that’s via the one single API connection which can also be used to
21:55
off to access our wider product suite some of those other products um that
21:58
were on screen a second ago. But also if you want it to be it can be just to
22:02
access the network tokenization piece. We really recognize that you know the
22:06
industry is moving fast but it’s very hard especially for large merchants who
22:10
may have limited development resource to be able to keep up with initiatives like
22:13
this but equally they’re getting pushed to. So we believe that our solution can
22:17
really really help drive that forward um and do it very quickly and easily with a
22:21
lot less technical work needed on the merchant or the or the partner side as
22:25
well. One of the questions we often get is
22:29
what is the difference between kind of gateway token, the tokens that merchants
22:33
have probably been familiar with for a while and network tokenization. Um, as I
22:38
say, the real key difference is where the token is is generated from. So
22:42
network tokenization is generated at the scheme. That means that it’s the schemes
22:46
working with the issuers who are supplying the tokens. Um, the schemes
22:50
also have a have a vault where they’re they’re doing that kind of swapping out
22:53
in the transaction flow. Whereas when we look at gateway token and even
22:57
orchestration token um as a standalone without network token where that’s being
23:02
done is is right at the kind of front of the transaction flow. So the typical
23:06
journey is you know a customer is shopping online um the transaction goes
23:11
to the gateway and the gateway um may give the merchant a token that’s unique
23:15
to the gateway but it’s not a token that can be then sent downstream through the
23:20
acquirer through the processor through the scheme to the issuer. What that
23:23
means from a security perspective is that there’s a PAN kind of going through
23:27
that flow. Um, a PAN obviously which inter which if intercepted can be used
23:32
elsewhere. Um, and therefore it’s it’s much less secure. Um, as I say with the
23:37
the network token that’s secure. It’s a it’s a unique token which goes all the
23:42
way through to the scheme where it’s then swapped out between the scheme and
23:45
the issuer for for a credential that the issuer can recognize. And not only that,
23:49
it’s also unique to that merchant or that device.
23:54
every single transaction um that is network tokenized has a unique
23:57
cryptogram as well as well which enables a number of features but also again
24:01
builds upon that security. So what we have built is um connectivity into those
24:07
schemes and therefore that means that at a a gateway or an orchestration level we
24:12
can provide a network token to merchants and ultimately that can then be rooted
24:16
you know via multiple PSPs it can be stored it reduces PCI risk and that
24:22
downstream kind of intercept risk as well amongst other things
24:28
>> just in terms of the wider benefits of network token um there’s some really
24:33
kind solid statistics about what this actually means from a kind of customer
24:37
perspective, from a merchant perspective. Um, and this is what makes
24:40
it really worthwhile to consider moving towards network tokenization. So, Visa’s
24:45
own statistics that they publish typically show a 2 to 7% elevation in
24:49
authorization rate. We on our side having enabled this with a with a number
24:53
of merchants and partners see that. Sometimes that is the case, sometimes
24:57
it’s smaller. Um however when you know we’re working with merchants of an
25:01
enterprise scale even a 1.5% increase is a massive difference in terms of the
25:07
amount of um authorization volume that is able to go through that might not
25:11
have done before. Alongside that you know they’re getting this reduction in
25:15
fraud that I spoke about spoke about all those different layers of security which
25:19
combine together and ultimately um they result in that reduction in fraud.
25:25
So from a merchant perspective, you’ve kind of got the the perfect the perfect
25:29
size of both worlds. We often have merchants coming to us from an
25:32
orchestration perspective saying, you know, we just want to improve
25:35
authorization rates. Now, sometimes when you do that and you use an orchestrator
25:38
or a rooting engine to do that, you you run the risk of actually increasing your
25:42
fraud, increasing your chargebacks. Um, so there’s a balance you need to strike
25:45
there. We believe that network tokenization really helps to build that
25:48
balance because actually what it’s doing is increasing authorization but it’s
25:52
doing it in a really secure way which is powered by you know the biggest payment
25:56
companies in the world the card schemes in terms of other benefits that that um
26:02
merchants and partners will see through network token the digital card updater
26:05
is a really key piece. So, some of you may be familiar with the kind of scheme
26:09
account updated product. Um, which ultimately mean that if I lose my card
26:14
or my card is stolen or or I just come to the expiry date of my card, what
26:19
happens is the merchant will receive a kind of update push um which says Tom’s
26:24
got a new card, but you don’t need to do anything because the credential you’ve
26:27
got will still work. Um, ultimately that’s what network token is enabling.
26:31
So because what’s being held by the merchant or by by bridge is a is a um is
26:36
a network token. It’s not a PAN ultimately then in the background the
26:40
PAN that is linked to that token can in effect be um updated as and when those
26:46
um incidents occur again then when we think about authorization rate what that
26:50
means is if I’m a subscription merchant and I’m regularly charging every month
26:55
um I may not have been told by by Tom that his card has been lost or stolen.
27:00
However, he doesn’t actually need to tell me anymore because that network
27:02
token credential I have on file will automatically link to that new PAN that
27:06
his his issuer has given him. So, it’s a really nice way of kind of keeping that
27:10
that customer retained from a from an end consumer perspective. It means I
27:15
don’t have to do anything when I lose my card, which is fantastic because, you
27:19
know, that’s that’s a pain that we probably all have to go through from
27:21
time to time when we get a new card, having to update all of those those
27:24
different merchants to remember who they are. Outside of that, we’re we’re
27:28
enabling one-click checkout in certain cases. Um, so no need to resubmit CVV in
27:33
future transactions. So, where that card’s on file, what that means is I can
27:37
just go in and I can just click pay without having to go through the pain of
27:40
finding my card and finding that CVV. Um, which then when you combine that
27:45
with, you know, kind of remembered form fields for for cards is a really nice
27:48
customer experience. It’s not available in all all scenarios. There’s kind of
27:52
rules around where when it can be used and when it can’t. Um but where it can
27:56
again it’s just creating that more seamless checkout.
28:00
>> The flip side of this is as well that you know the schemes are pushing towards
28:04
network token and for good reason. All of those things I just spoke about lead
28:08
to more security, more authorization and a better customer experience. um they’re
28:13
doing that in some ways with a carrot, but the other way is also with a stick,
28:16
which is to create a new fee structure in certain parts of the world, which
28:20
ultimately mean you may pay more for a transaction if it’s not network token or
28:24
it’s not authorized with 3DS, for example. Now, you know, the ultimate
28:29
customer journey is hopefully they don’t have to step up to 3DS every time. So
28:32
really, what you’d like to be doing is is enabling network token, avoiding that
28:36
fee change, and again giving the customer the best experience. So you may
28:40
start to see more of that on an acquirer level, those fee changes coming through.
28:44
Enabling network token now will ultimately lead to being able to avoid
28:48
those new charges. Final thing, and it’s it’s a fairly minor point, but actually
28:52
we’ve seen that it does really build trust, especially in certain
28:55
demographics, is the ability to return card art and check out. So using our
28:58
hosted payments hosted payments page, for example, what we’re able to pull
29:02
through is an accurate picture of your bank card. Um, so whatever issuer it is,
29:07
it will have their logo on it. it will look familiar and therefore you you will
29:11
feel like you can trust that merchant more especially if it’s the first time
29:14
you’re using them. We’ve really seen that build up kind of um trust as I say
29:18
especially in certain demographics and certain types of businesses. Um and
29:22
again that leads to more customer conversion which is only a good thing.
29:26
>> Great. And maybe just a brief note for the audience audience we’ve received
29:30
some great questions but uh don’t hesitate please feel free to send in
29:34
more for uh Rebecca and for Tom. Thank you.
29:38
Great.
29:41
>> So in terms of our our partnership with SIP and and how that works with our
29:43
platform and I’ll come on to how this all combines together in a second. Um
29:47
but as I say we have our bridge connect product and what that is is ultimately
29:50
our our aggregation. It’s our marketplace in effect. So what we’re
29:53
trying to build is a global marketplace of of payments providers. Meaning that
29:57
as a as an end merchant, what you can do is use the one single integration into
30:01
our platform, access all of these different types of entities um and then
30:06
as I say start to build intelligent workflows within that. So we’ve got a
30:10
we’ve got a um connectivity into um a large number of gateways, a large number
30:15
of acquirers, and over 200 payment methods alongside a number of fraud
30:19
tools. and then our direct connectivity into scheme products for things like
30:22
installments, tokenization and click to pay as well.
30:28
>> So how does this all all sit together? Um ultimately we believe that the
30:33
combination of network tokenization combined with the the um kind of market
30:38
leading offering from SIF’s fraud um capabilities combined with our
30:43
decision-making engine actually can lead to the kind of most optimized and secure
30:47
payment stack that there is. So through the one integration into bridge, what
30:51
you get is you get that access into the tokenization where it’s available. Um
30:55
where it’s not available, we have a logic that just says, you know, this
30:59
part of the world isn’t ready yet. Therefore, continue using a different
31:02
type of tokenization. Um we can call out to SIFT’s fraud capability before you
31:07
hit your your gateways and downstream payment offerings. And what that means
31:11
is got a token credential, got a load of data being collected by bridge going to
31:15
SIFT, coming back with a result, and we can ultimately then work with you to
31:19
decide the best place to send that transaction where it’s most likely to be
31:23
approved. But also not forgetting that, you know, we don’t want to risk
31:27
increased fraud, increased chargebacks, all of those kind of things.
31:31
Doing these connectivity these connections through bridge ultimately
31:34
means that you can do it without kind of um affecting and impacting negatively
31:39
your existing downstream connections. We’re an independent platform.
31:43
Therefore, we’ll ultimately continue to deliver the connectivity that you have
31:46
today. We just want to continue to work with you to to enhance that.
31:52
I think we have a a poll at this point that we we’d like to
31:55
>> Yeah. Because we would love to ask the audience a question about uh network
31:59
tokens. Um, we would like to know and maybe we can launch the poll here. What
32:04
do you see as the biggest barrier to entry for your business to enable
32:09
network tokens? Is that the technology resource? Is that prioritization?
32:13
There’s just so much to be done. Is it dependence on PSP readiness or is it
32:18
just a complex payment stack? So, I was wondering Tom, what do you see most in
32:24
your network as biggest barriers? Yeah, I think we see um it’s always that
32:31
prioritization piece, you know. Um merchants just want payments to work for
32:35
them. Um rightfully so, right? They want to concentrate on what they’re they’re
32:39
good at, which is and and what the core of their business is, which is, you
32:42
know, selling goods, serving customers, that kind of thing. Um ultimately, they
32:47
want to work with partners where it just works smoothly. And I think the the
32:51
thing is is that there’s a mixed readiness in the market in terms of the
32:54
PSP side. Some are ready, some aren’t. And as a merchant, that’s a really hard
32:58
landscape to navigate if you know you’re able to network tokens by some of your
33:02
providers but not by the others. Um that’s something we’re seeing. And then
33:06
from the merchant side, just being able to prioritize development of it amongst
33:09
the thousand other projects that they’re looking to do is always is always tricky
33:13
with every initiative um especially ones like this which is quite a major
33:16
overhaul of the way that you work with payments. A
33:19
>> great thanks Tom. But let’s see what the audience sees as the the biggest
33:23
barriers. Maybe we can launch the results here.
33:26
So it’s the technology resource 18% prioritization 29 dependence on PSP
33:33
readiness almost 40% it’s more than I anticipated and a complex payment tech
33:37
14. So so how does this resonate with you Tom?
33:41
>> I think that’s good because hopefully that that kind of reiterates what I was
33:44
just saying about the PSP readiness piece. Um outside of that you know these
33:48
are all things that we’re hearing. Um it’s all kind of linked in a way. you
33:52
know, some merchants are more reliant on PSPs than others. Um, and that’s fine.
33:56
It typically comes down to the, you know, the size of your team and um, how
34:00
payment sits within your business. I guess again what what we see is that
34:04
merchants, you know, they want to do tokenization because of all those things
34:08
we spoke about. Again, it’s it’s is there a reliance on a third party in
34:11
terms of a PSP? Usually yes. Um, and then also from their side, how do they
34:16
get that kind of prioritized in terms of tech resource and the cost of that? you
34:20
know, any project that uses resource is is a cost to the business. Um, making
34:24
that case um, internally can sometimes be challenging when compared against
34:28
other things.
34:30
>> Great. Thank you, John.
34:32
>> No worries. So, in terms of of how we see mitigation against that and why we
34:37
believe that the product we built does mitigate against some of that. Um,
34:40
firstly, it’s important to reemphasize we have direct connectivity into the
34:43
schemes. We’re not doing it utilizing any other third party. Um
34:48
outside of that, you know, some of the PSPs are um utilizing network token, but
34:54
they’re doing it that in a way which which locks you in to just using them
34:58
for that network token. What we’re trying to do is is disagregate the
35:02
network token from that downstream PSPs, just as we’re trying to disagregate your
35:06
fraud solution from the downstream PSPs. So ultimately, you can utilize those
35:11
services, but you can still have that core payment volume going via whatever
35:14
route you want. And if you want to change that regularly, you can change it
35:17
regularly. Um, on the flip side of that, as I say, if one of your PSPs isn’t
35:21
ready, we may still be able to send a network token down that stream. If we
35:26
can’t, we have a logic which just says, okay, you want the transaction to go by
35:29
XY Z PSP, we’ll swap that out for a PAN in that case. So, it’s the ability to be
35:34
able to use that routting and split that volume, manage a global payment stack
35:38
without reliance on PSP readiness for network token and building your own
35:42
logic to to kind of match that.
35:46
>> Outside of that, um it’s the ability to then combine it with other products we
35:50
have, for example, our BIN lookup and the rooting capability there. What you
35:54
can start to do is build up a really um kind of clever intelligent payment
35:58
strategy, reducing fraud, increasing authorization rates, and doing that with
36:02
a party like Bridge is independent of it. So, we’ll work with you to serve
36:06
what you want to achieve. Um, and hopefully we’ll we’ll enable that
36:09
through our technology stack as well.
36:19
>> Perfect. I think over to Rebecca.
36:21
>> Yeah. And so the benefits of partnering with companies like Sift and Bridge that
36:25
have these um integrations already uh together is that um one it’s efficient
36:32
for you and your business from a resourcing standpoint. So you don’t have
36:35
to do those expensive R&D resources to build out the implementation um stage.
36:41
And two, I think when you’re thinking about protecting your business, the um
36:45
from fraud in particular, I think the more data and information that you have
36:48
available to a company like SIFT or Bridge, the better. Um and so not only
36:54
will you get the rich data set that Zift offers from our global data network, but
36:58
you’ll also get the pieces um of information uh from Bridge as well here.
37:04
I think that’s really important. I think, you know, a lot of our platform
37:08
um capability is enabling that single view of data. What we’re able to do is
37:12
is to combine that single view of data, send some of that through to SIFT to
37:17
allow, you know, greater consideration in terms of the the fraud response
37:20
they’ll get. Um and then ultimately, as I say, leverage their rules engine, but
37:24
also combine that with our rules engine to start doing some really intelligent
37:28
stuff.
37:31
>> Great. Well, thank you so much Rebecca and Tom uh for your insights into your
37:36
partnership and also how merchants can leverage basically both uh network
37:41
tokenization and SIFT’s AI powered decisioning engine um to create this
37:46
more secure and seamless payment experience for for merchants and
37:50
consumers. Um what I would like to do now uh is basically go through the Q&A
37:55
session. We have some great questions from the audience and as I mentioned
37:58
before do send in more. we will have some time to address all your questions.
38:03
Um so the first question is for um Rebecca when you were talking about all
38:09
these fraud trends and increases that you’ve seen in in account in account
38:13
takeover. Is there a given country that has most fraud? Is there one country
38:18
that really you know basically spikes? Um there’s not a specific country uh but
38:24
we do see spikes of fraud regionally. Um so I’ll say Eastern Europe is a larger
38:30
spike of fraud. Um western Africa and then uh in the southern part of China is
38:35
where we’ll see uh increases in fraud as well. I’ll also say while these are
38:40
global trends um what I’ve seen in my own experience is that specific
38:44
countries fraud may depend upon your product and where you’re developing or
38:48
where you’re building and what that product or that tool might be
38:53
susceptible to. So sometimes you’ll see country spikes um in development phases
38:58
that are not aligned with global trends just because of maybe something that
39:01
you’ve built internally or there’s an exploit that somebody’s been available
39:05
to. I think country information is powerful. I also think it’s really
39:08
understanding your own product and how it can be be manipulated in specific
39:12
geographic regions.
39:14
>> Great. And what is driving this search and account takeover?
39:18
Well, what we are seeing right now, I think um there is lots of fishing
39:23
schemes. Um and then also what we’ve seen is like the increase in generative
39:27
AI is making it more easy for uh users or fraudsters to have the tools and the
39:34
technology to gain information and access. Um and then the other trend that
39:40
we’ve seen is we’re calling it the democratization of fraud. So, we’re
39:43
seeing a lot of individuals engage um with people in forums like Telegram or
39:49
Discord and give over their credentials to have someone else do the fraud on
39:54
their behalf. And so, we’re finding that people are more willing to have someone
39:58
else commit the fraud. Um, and they’re just getting things what they think as a
40:02
discount and that fraudulent actor is working to get that stuff for free and
40:05
taking um a cut from that person that’s engaging with them. And we’re seeing
40:09
that happen more and more especially in younger demographics who are being
40:13
targeted in these things like on Tik Tok and Instagram and social media. So it’s
40:17
been an interesting trend over the last few years.
40:19
>> Yeah. Thanks Rebecca. Question for you Tom. Um it’s a question I get you I I’m
40:25
sure you get pretty often. It’s about uh the question is like the uh ask he he
40:32
understands or she the benefits of bridge and payment orchestration but it
40:36
will be a single point of failure in the end right is that’s basically the
40:40
question so um
40:41
>> yeah so we obviously get this a lot um obviously you know we’re talking about
40:46
sitting in front of a merchants’s entire payment stack um now we talk about that
40:51
we don’t always do it sometimes we we slot in alongside other providers you
40:55
know ultimately we don’t mind we’ve built modular set of products that can
40:58
actually be used independently. So take the network token piece, you know,
41:02
that’s not going to disrupt any of your connections into your PSPs if you don’t
41:06
want it to. We can also actually sit at different stages in your payment stack.
41:10
So we’re not precious about being the front end if you don’t want us to be. We
41:13
can sit, you know, kind of further embedded. Um, we see ourselves as a very
41:17
flexible piece of infrastructure, which I think helps with that. Um in terms of
41:22
uh you know if we are to sit in front of everything the reassurance we can give
41:25
is we’re multiloud multilocation we have very strict kind of failover protocols
41:31
in place that uh you know if one of our cloud providers go down we can fall back
41:34
to a different one the same in terms of the location side of things as well. Um
41:38
touchwood you know a very strong uptime on our side. We we’ve not seen any
41:42
instances so far, but we’ve built the platform to deal with merchants who are
41:46
putting through a lot of volume and are putting through a lot of volume at the
41:49
moment. Um, so we’re kind of standing ready for, you know, the day when one of
41:53
the downstream providers um goes down, we have everything in place to to deal
41:57
with that in a in a way that will not affect the merchants payment flow.
42:01
>> Okay, brilliant, Tom. So uh another question is does the merchants have to
42:07
have a contract with each acquirer and um payment methods? Um if not how does
42:13
the end payment provider fulfill its money laundering requirements and KYC?
42:19
>> Yeah. So just to break this into two. So in terms of network token um there’s
42:23
obviously no contract needed. You just contract with bridge for that. We’re
42:26
providing that service ourselves directly with the schemes. Um, outside
42:30
of that, we’re an independ independent piece of software. So, ultimately, we’re
42:34
just enabling you to fulfill your payment obligations downstream. So, you
42:38
have those agreements in place with your different payment providers. If you use
42:42
us to access Syft, you have a direct relationship with SIFT. So, you get all
42:45
the benefits of working with them directly. You can still go in and use
42:48
their dashboards and their tools and all that kind of good stuff. We are just
42:51
helping you solve that technical enablement side of things.
42:55
So it’s purely for the deployment in a way basically to make that process
42:59
easier.
43:00
>> Exactly. Yeah. It’s it’s about modernizing the technology taking you
43:04
know taking on a lot of that development work on our side maintaining those
43:06
connections but in terms of the commercial relationships and I think
43:09
this person’s also interested in kind of AML KYC side of things. You know we’re
43:14
not touching flow of funds that’s all happening with your acquiring banks and
43:17
the payment methods and you still manage stack in the same way as you would
43:19
before.
43:20
>> Yeah. Brilliant. Tom another question. Um we see uh we see a more of the
43:27
acquirers and gateways providers also talk about offering their own network
43:31
tokenization tools. Uh for instance that’s what Ajan talked about at their
43:35
investor day uh weeks ago. So how do merchants choose what route to take?
43:42
>> Yeah. Yeah, and I’ve got to be careful what I say here, but um you know, some
43:45
of those pro some of these providers um potentially one mentioned in the
43:48
question are offering network tokenization in a way which is specific
43:52
to them. Now, that’s fine if you just want to be with one provider and and
43:56
you’re not thinking about building a wider payment stack, but what you’re
43:59
doing is ultimately committing that to them. Now, merchants who use bridge um
44:03
typically have a secondary provider for resilience purposes at the very least.
44:07
And what what that means is if you use network token through us, it’s not
44:10
specific to one provider. If your PSP falls over, we can still use that
44:14
network token and send it to a different one. So, it’s about taking control,
44:18
having a more direct connection disagregated from your downstream
44:21
payment providers into into the schemes for that network tokenization service,
44:26
therefore reducing reliance and giving you more control and freedom if you want
44:29
to change your PSP setup in future. So, um Tom, if a card holder purchases
44:36
at multiple bridge merchants, you know, merchants that work with with you guys,
44:41
um they use this the same token for each merchants um for the each the stores
44:47
card holder data or does it ask the scheme for a token for each merchants?
44:52
>> Yeah. So, so we are in effect kind of working on an on behalf of model. So, we
44:56
on board every single merchant with the with the scheme themselves. So it’s not,
45:00
you know, it’s not bridge acting as a merchant. Um, so you will be registered
45:04
as a merchant with the scheme or or your merchants will be registered with the
45:08
scheme. Um, and what that therefore means is, you know, a customer for each
45:12
merchant will have a unique token. Tokens by nature are so good because
45:16
they’re unique to a merchant or a device. So in this case, you know, we
45:20
want it to be unique to that merchant. So therefore, the token can’t be used at
45:24
other merchant sites.
45:27
>> Yeah. Question for Rebecca. Um Rebecca with with u account takeover searching
45:33
and and so many you know new challenges also ahead of us like what’s the best
45:38
way to gain resources within your organization to help teams effectively
45:43
to stop fraud and I I know you’ve been in that situation yourself
45:47
>> so how did you do that? Yeah, I think we all hopefully all have been there,
45:52
right? How do you get how do you get the things you want built? Um I think Tom
45:55
mentioned this as well. Prioritization uh comes into that and what I think
45:59
about is how do you effectively prioritize? Well, again, you use data.
46:03
So that’s why I think reporting is so important. So you can tell your story to
46:08
um upper management through data by demonstrating the importance of this
46:13
issue um either from a financial standpoint or from a brand standpoint or
46:17
from a trust and loyalty standpoint. Um the other thing I like to think through
46:22
and actually uh a colleague of mine told me this advice and and I think it’s
46:26
really good. Um when I was asking her you know probably early days of Gusto I
46:30
was like should I build or should I buy what should I do? um I need to build,
46:35
you know, my own fraud system. And she said, you know, I do think after years
46:38
of doing this, I think, uh if you can buy and the the tool is sufficient, then
46:43
you should buy because you’re going to get way more resources from that vendor
46:46
than you are going to be internally where you’re going to spend so much of
46:49
your time internally advocating for tools for resources. But if you you can
46:54
get the budget to buy, then it’s much easier to to manipulate vendors to do
46:58
things for you than uh some of your own internal resources so they can focus on
47:02
the product. Um and uh you know I I I keep that with me. Um I think that was
47:09
like good advice just from her years of experience and too she wanted to
47:11
minimize how much she uh she actually gets to negotiate.
47:15
>> Great. Thank you Rebecca. Um the question is for Tom. Uh I mean you serve
47:20
different different merchants, different type of customers. Uh what benefits do
47:24
they value most and do you see differences um uh per sort of vertical
47:30
of type of merchants that you serve?
47:33
>> Yeah, it’s really interesting. So so on the direct to merchant side for us where
47:36
we’re we’re directly servicing merchants, we’re typically working
47:39
across travel and transit which is where our heritage is as a company. We’re also
47:43
working in retail and and digital e-commerce. Um and then finally we we
47:48
service some gambling merchants as well. The kind of range of needs across all of
47:52
those varies so much. Um I would say that in the travel sector we’re doing a
47:56
lot of that modernization piece. A lot of travel merchants for example have
48:01
legacy relationships with with acquirers um and they might corporate bank with
48:05
them as well. However, they’re not necessarily getting that technology kind
48:08
of uplift that they’re looking for. As again consumer expectations change, how
48:12
do I launch new payment methods? How do I have a have a nice front end?
48:16
>> Outside of that, you take something like a a gambling or a digital goods
48:20
subscription merchant. They typically have a much um better round well-rounded
48:24
kind of well-forged payment strategy um in terms of you know they might have a
48:28
large payment team with dedicated developers against that. A lot of what
48:32
we’re doing is enabling these these kind of um new services such aworked
48:36
tokenization helping them again control a really complex payment stack of maybe
48:41
10 PSPs utilizing a fraud tool like SIFT outside of that. um whilst also
48:46
potentially leveraging tools from their gateways creating complex workflows. Um
48:51
so I think it’s that ability to to really start to do bespoke stuff with
48:56
your your different payment options and do that in a way as I say that’s
48:59
independent so you’re kind of not getting tied in network organization the
49:02
benefits speak for themselves but I think you know what we see is for those
49:06
cardon file merchants where they’ve got a lot of customers credentials stored on
49:09
file they do see a real terms authorization increase and that’s the
49:13
key benefit for them. you know, you can’t you can’t really complain about
49:17
getting more transactions authorized. Um, and that’s what ultimately this is
49:20
enabling.
49:21
>> Yeah, especially in in in recurring transactions. It’s like a must have.
49:27
Definitely. There’s one last question. Um, does network token interact with
49:31
other products as well. Eg there’s so many payment methods, wallets for
49:35
instance, or other issuer products?
49:38
>> Yeah. So, the short answer is some of them, yes. Um, so we can do some clever
49:42
stuff with network tokens and and other payment offerings, largely wallets that
49:46
have card based elements. We’ve also gone live with, for example, Visa
49:50
installments. We did a press vis press release a couple of weeks ago
49:55
in the UK on that. Um, outside of that, we’re going live with scheme click to
49:59
pay. These solutions are all able to utilize um network tokenization in the
50:05
background. Ultimately, that means that you get all the benefits of these other
50:08
solutions, but you also get all the benefits of network token. Um, so it’s
50:12
really the kind of backbone for a lot of these wallets products and a lot of
50:16
other things that the schemes are doing. We’re aiming to be a hub for that so
50:19
that we can enable it all um kind of at pace for merchants and payment partners
50:24
as well.
50:25
>> Brilliant. Well, thank you so much Rebecca and Tom for taking all your all
50:29
the questions and also thanks for the audience uh for engaging with Rebecca
50:34
and Tom and to ask for more clarification on certain topics. I
50:38
really appreciate it. Um I think it’s for most of us it’s time for dinner or
50:42
at least prepare for dinner. Um so for now uh what we’ll do we’ll send you a
50:47
link to this webcast shortly. we will get back to questions that we did not
50:51
have time to include and I just wish you a very lovely rest of the day. So, thank
50:57
you so much. See you see you next time.



