Introducing The Blueprint, Sift’s new how-to series for fraud leaders who want practical guidance, not theory. Each session walks through a specific problem—from org design to benchmarking and revenue alignment—with clear steps, tradeoffs, and examples from real companies.

Fraud is no longer a siloed function. It’s a business-critical discipline at the intersection of security, revenue, and customer experience. As threats evolve, organizations must rethink team structure, ownership, and how trust is embedded into their infrastructure. During this session, industry experts will share lessons from building and scaling fraud organizations inside some of today’s most complex platforms.

Drawing on his experience establishing fraud programs at Square, Facebook, and Sift, Sift’s Field Chief Technology Officer Kevin Lee explains where to start, what has changed over the past decade, and how to align fraud with business outcomes. Hosted by Founder & CEO of AppSec Training Inc, Jerry Hoff, this conversation makes the case that trust is not a feature or KPI but infrastructure.

Featured Speakers

Kevin Lee (Field Chief Technology Officer at Sift)
Jerry Hoff (AppSec Training)

Watch Now

Close

Thanks for submitting!

close

Video Transcript

WEBVTT

1
00:00:00.000 –> 00:00:01.720
Jerry Hoff: Alright, well, I want to welcome…

2
00:00:02.740 –> 00:00:12.369
Jerry Hoff: Very good. Alright, I want to welcome everybody to The Blueprint, How to Build and Scale a Modern Fraud Organization, presented by SIFT.

3
00:00:12.370 –> 00:00:28.169
Jerry Hoff: I am really excited for this presentation. This is something that every digital business is wrestling with right now. How do you scale fraud prevention without slowing down growth? That’s… that’s the tricky, the tricky part here. We’ve got to make sure that we do just enough

4
00:00:28.170 –> 00:00:46.120
Jerry Hoff: that we don’t inhibit sales, but at the same time, we’ve got to stop this massive amount of fraud that is going on. So I am really excited about this. Before we dive into the topic, I’m going to do some quick introductions, so you know who you’re speaking to today. First of all, nice to meet everybody. My name is Jerry Hoff.

5
00:00:46.120 –> 00:01:01.060
Jerry Hoff: I’ve been in security for a very long time. I was head of security for Sony for many years, Sony Electronics, based in Tokyo. I was the global security architect at NTT, which is a Japanese telecommunications company.

6
00:01:01.060 –> 00:01:12.479
Jerry Hoff: And now I do a lot of teaching in application security, and I’m really excited to find out more about fraud. And I’m here with Kevin Lee. Kevin, if you could give us a quick introduction of yourself, please.

7
00:01:13.140 –> 00:01:21.200
Kevin: Of course. Hey, everybody. Great to meet y’all. My name is Kevin. I lead all of our professional services teams here at SIFT.

8
00:01:21.200 –> 00:01:24.459
Kevin: Essentially what that means, and I’ve been at SIFF for, gosh.

9
00:01:24.460 –> 00:01:47.049
Kevin: over 9 years now, and spent my career in fraud and trust and safety. But essentially what I get to do is meet with a lot of our clients to go over different fraud strategies, how to build different systems, tools, processes, all the things that I’m excited to talk to you about today, and kind of build out that fraud structure to make sure that they are built to scale, essentially.

10
00:01:47.050 –> 00:01:58.580
Kevin: Prior to joining SIFT, I managed and built my own, risk, fraud, various online abuse teams at companies like Google, Meta, and Square, and essentially what I get to do now

11
00:01:58.580 –> 00:02:13.840
Kevin: similar to Jerry, do a lot of teaching and education, and really analysis on how to future-proof a lot of these from a lot of different abuse factors with a lot of clients. So, great to be here today, and looking forward to the discussion.

12
00:02:14.850 –> 00:02:31.400
Jerry Hoff: Fantastic. Well, Kevin, you are… you’re definitely… your expertise is… is perfect for, you know, this talk, obviously, and for the world that we’re living in, and I really want to get into the broader fraud landscape. So, let’s talk about the fraud landscape for a moment.

13
00:02:31.530 –> 00:02:48.949
Jerry Hoff: it’s very clear to me, when we were talking about this before, that it’s not… I think a lot of organizations see fraud as, like, one problem, but it’s really, like, a giant ecosystem. So you’ve got the fraud team, and you’ve got the global fraud economy, which is much bigger than I had realized.

14
00:02:48.950 –> 00:03:08.569
Jerry Hoff: Then you’ve got tool proliferation, all sorts of tools, and then you have siloed teams. So it’s very similar to maybe security, but fraud has this immediate impact in terms of financial. And I’ll just mention, this problem is so big, it’s not even in the billions anymore. It’s approaching the trillions.

15
00:03:08.570 –> 00:03:20.680
Jerry Hoff: Which is mind-blowing. So, Kevin, if you could walk us through the fraud landscape, please, and you know, tell us what the current state is in terms of the global fraud ecosystem.

16
00:03:21.250 –> 00:03:37.639
Kevin: Yeah, of course. And so this is actually an exercise I did with my Trust and Safety Architect team a while back, where we had a whiteboard, blank, and we wanted to discuss, hey, what are all the different vectors, or bad actors, and kind of areas that

17
00:03:37.690 –> 00:03:58.820
Kevin: a company can get exploited on. And here’s… this isn’t even the full list, here’s just what would fit on the screen here. And there’s two main halves to the, kind of, equation here. One is external side, so you can think of that as the global fraud economy, and then on the right-hand side is more internal things to deal with, in terms of tool proliferation, siloed teams.

18
00:03:58.820 –> 00:04:02.129
Kevin: And what was interesting here is, number one.

19
00:04:02.510 –> 00:04:12.019
Kevin: fraud teams have a lot to deal with. They’re kind of right at the center here, right? And a challenge that I often face throughout my career and, you know, building out different teams, is that

20
00:04:12.080 –> 00:04:13.980
Kevin: You’re the connective tissue.

21
00:04:13.980 –> 00:04:36.340
Kevin: Where you have these external threats, and, like, the purpose of a bad actor or a fraudster is to find the gaps in all these things, and boy, on this slide, there are a lot of gaps in terms of spaces, to proliferate bad activity. And so, that’s what you have to deal with from the external standpoint. And there might be some big ones, like payment-related or account takeover-related.

22
00:04:36.500 –> 00:04:53.800
Kevin: certainly content-related as well. And then, on the other side, you have internal things to deal with, with regards to data and teams. And the key word I’d say to remember from this particular slide is silos, and right now.

23
00:04:54.120 –> 00:05:08.900
Kevin: man, there’s a… there’s a tool for everything, or in anything, and sometimes you can have point solutions, sometimes you can have more holistic solutions. But the key thing where I see a lot of companies struggle with is, does that data talk to each other?

24
00:05:09.000 –> 00:05:10.470
Kevin: do those teams.

25
00:05:10.580 –> 00:05:20.060
Kevin: talk to each other. Do they have aligned incentives or aligned goals? Because when… not really if they don’t.

26
00:05:20.060 –> 00:05:38.900
Kevin: That’s where fraud seems to permeate more, when data or teams don’t talk to each other, and that’s really where bad things can happen, and it’s up to the fraud team. They’re kind of right in the middle here, where they have to be the eyes and ears and alert the teams, update the data, to reflect that bad activity. And so…

27
00:05:38.900 –> 00:05:48.869
Kevin: Certainly in… certainly in the last couple years, with more tools, certainly being available to the fraud fighters, but also to the fraud perpetrators.

28
00:05:48.970 –> 00:05:57.810
Kevin: whether it’s AI or other scaled attacks, they tend to be… they are proliferating as well, and so you do have a little bit of that arms race mentality.

29
00:05:59.310 –> 00:06:12.470
Jerry Hoff: Excellent. Kevin, can you talk a little bit about, you know, you have payment fraud up here, which is, when I think about fraud, my mind usually goes to, okay, well, it’s credit cards, it’s things like that, it’s fake credit cards, it’s chargebacks.

30
00:06:12.470 –> 00:06:21.590
Jerry Hoff: But you also have account takeover as one of those main branches and content abuse. Could you spend a minute or two kind of going through what is…

31
00:06:21.590 –> 00:06:28.830
Jerry Hoff: What are people doing? What are the bad guys doing in terms of taking over accounts? So it sounds like it’s well beyond just the transactions, right?

32
00:06:29.270 –> 00:06:46.349
Kevin: Yeah, so, there’s an old, like, advertising adage out there where it says, like, the answer to all your questions is money. And, I mean, from a fraud standpoint, they’re in… they’re running a business themselves, right? And I think about, let’s say, you know, my phone here.

33
00:06:47.400 –> 00:07:02.899
Kevin: How many apps does the average customer or average user, let’s say, have on their phone? I’d guess hundreds? Now, if you think about, of those hundreds of apps, how many of them have a credit card attached to it? Only a couple dozen.

34
00:07:03.080 –> 00:07:05.290
Kevin: And then how many of them

35
00:07:06.360 –> 00:07:14.429
Kevin: do you interact with as a consumer and post content? Probably a good chunk of them as well. And so when I think about account takeover in particular.

36
00:07:14.590 –> 00:07:19.750
Kevin: although of the… I think I have, like, 234 apps on my phone,

37
00:07:19.800 –> 00:07:24.840
Kevin: Of them, the vast, vast majority have an account attached to it.

38
00:07:24.840 –> 00:07:44.509
Kevin: And that can be monetized in some way, shape, or form, not specifically via a credit card. Like, there’s value intrinsically in that, so you can think about loyalty points, miles, you know, I’m… travel season’s starting to kick up again, so you can think about hotel points, airline miles, other things, that can all be monetized, and if

39
00:07:44.510 –> 00:07:46.320
Kevin: That account was taken over.

40
00:07:46.400 –> 00:07:58.440
Kevin: I would be quite unhappy as a consumer. I would then complain to the merchant or the business. And for the most part, they’re pretty good at making me whole, and saying, like, oh, sorry, you lost your

41
00:07:58.680 –> 00:08:06.890
Kevin: 100,000 miles, we’re gonna make you whole again. But that still is a form of digital currency to be mindful of, and it’s not free. And so.

42
00:08:06.890 –> 00:08:20.290
Kevin: That’s why account takeover can be particularly tricky, because not only do you have to make the customer right, like, there’s a bunch of cleanup work that has it involved as well, and so a lot of teams can struggle with that.

43
00:08:20.290 –> 00:08:26.999
Kevin: And then from the content side, man, this is… if you think about, like, misinformation,

44
00:08:27.300 –> 00:08:35.460
Kevin: people may bump, different ratings and reviews of a particular merchant. So, back in my Google Map days, we’d have

45
00:08:35.820 –> 00:08:54.400
Kevin: users out there that would try to, let’s say, pump up their business with a bunch of 5-star listings. They would, let’s say you’re competing with another coffee shop out there, and you try to put a bunch of one-star ratings there, and so there’s a lot of forms of content abuse that can be apparent. And you can think about things like

46
00:08:54.400 –> 00:08:56.369
Kevin: Misinformation, fake news.

47
00:08:56.380 –> 00:09:02.809
Kevin: Phishing and spam, those are all kind of in that content bucket as well that can be difficult to parse out.

48
00:09:04.260 –> 00:09:16.900
Jerry Hoff: Good stuff. This is a great slide. It really helps me visualize the problem, and then the idea that you’ve got the tools, the tools are not talking to each other, so even if you’re somehow registering some of the stuff, it’s not actually becoming actionable.

49
00:09:17.070 –> 00:09:27.009
Jerry Hoff: All right, really good. So now that we understand this kind of size and scope, let’s have a question for the folks. We got a lot of folks, attending today. So…

50
00:09:27.380 –> 00:09:35.819
Jerry Hoff: Hopefully, there should be something popping up on your screen, a poll question, and this is what we really want to know. And please, be honest, be honest,

51
00:09:36.060 –> 00:09:49.019
Jerry Hoff: how many types of abuse is your organization susceptible to, would you say? So, you can, you know, it’s probably different for every industry, but yeah, please go ahead and vote.

52
00:09:49.670 –> 00:10:08.889
Jerry Hoff: I myself cannot vote, but I see that it popped up, so go ahead and do that, and then we’ll come back with the answers on that. But I would imagine for most organizations, Kevin, I’m just guessing here, it’s probably much more than meets the eye, right? The kind of obvious thought might be, well, it’s probably…

53
00:10:08.890 –> 00:10:15.460
Jerry Hoff: our credit card transactions, that might not be it. I mean, that might be it, but it’s probably much deeper like that that you already alluded to.

54
00:10:16.170 –> 00:10:23.789
Kevin: Yeah, so I think, and I’ll be interested to see the stats in a moment, but really, there are… I’ll call it.

55
00:10:23.890 –> 00:10:25.210
Kevin: active accounts.

56
00:10:25.220 –> 00:10:34.619
Kevin: And, or active vectors of fraud. And let’s say you mentioned credit cards, that’s the thing. That’s, like, the no-duh, like, of course we’re getting hit by it all the time.

57
00:10:34.620 –> 00:10:48.379
Kevin: What are the more subtle ones? Are… can be certainly content-related, or money laundering related. There’s these ancillary things that are often harder to attribute specific value to. Let’s take account takeovers, for example.

58
00:10:48.380 –> 00:10:50.270
Kevin: If an account

59
00:10:50.270 –> 00:11:08.959
Kevin: is compromised, and it’s accessed, and the bad actor… let’s say they don’t do anything yet. They just open the account, they’re able to maybe change the password if they wanted to, or update the billing instrument, or the credit card on file, and that’s all they do.

60
00:11:09.040 –> 00:11:14.169
Kevin: Does that count as a compromise, if there’s no extraction of value yet?

61
00:11:14.290 –> 00:11:22.770
Kevin: And so that can be difficult to work through. And actually, looking at the poll results that come up, looks like, well, over about half the group, 6+.

62
00:11:22.830 –> 00:11:40.149
Kevin: Which is not surprising. Hopefully not all of them are on fire at the moment, and maybe there’s only, you know, two or three that are actively being monitored for, and then it kind of ebbs and flows over time, where there may not be a bunch of account takeovers right now, but man, I can remember back to…

63
00:11:40.150 –> 00:11:55.020
Kevin: September, you know, 2025, and suddenly, hundreds of accounts of users were compromised, and then we had… it took a week or two to clean up, and so that’s typically the MO when it comes to those different, patterns.

64
00:11:56.090 –> 00:11:58.620
Jerry Hoff: Kevin, real quickly, since we’re looking at the results.

65
00:11:58.720 –> 00:12:16.010
Jerry Hoff: organizations that only have one or two, let’s assume that that is correct. Is it like, what, they’re just selling a digital product online, they don’t have accounts, so it’s very transactional, and that’s kind of the only vector? Like, I’m selling e-books, and the only thing I have to deal with is, you know, credit card fraud and chargebacks, something like that?

66
00:12:16.670 –> 00:12:37.379
Kevin: Exactly, so if you think about the surface area, how much can be exploited, if there’s only one path that end consumers can follow, then that’s only one area that can be exposed. Typically, when I think about a business, I look at all the buttons, whether it’s the sign up button, the purchase now button, the register for, you know, whatever promo button.

67
00:12:37.380 –> 00:12:45.600
Kevin: all those things have, of course, intrinsic value to the merchant here. Those also present areas that could potentially be exploited.

68
00:12:46.290 –> 00:12:59.009
Jerry Hoff: Interesting, interesting. Yeah, so we’ve got… looks like 3 and 4, and then somehow 5 isn’t very popular. It’s either 3 or 4 or 6, so… good stuff. All right, so now let’s get to the real meat and potatoes.

69
00:12:59.020 –> 00:13:14.680
Jerry Hoff: of the presentation, which is the new blueprint. And I do want to mention to all the folks, we have a lot of participants in here, so obviously this is a very important topic, but for those folks that are on, I want everybody to feel free to give us questions. So we’re here, we’ve got Kevin.

70
00:13:14.680 –> 00:13:20.299
Jerry Hoff: And so we can ask him all the questions that we want, so please feel free to put those questions into the

71
00:13:20.320 –> 00:13:38.160
Jerry Hoff: Q&A section, and then Keaton, who’s kind of running everything behind the scenes, will definitely call those out so that I can have Kevin answer those. So, Kevin, can you walk us through here the new blueprint? Essentially, this is a blueprint for the way that we need to be thinking about building our fraud detection program.

72
00:13:38.460 –> 00:13:40.079
Jerry Hoff: Kind of walk us through, if you could.

73
00:13:41.430 –> 00:13:50.410
Kevin: So really, when I think about when I was… I first got in the game, if you will, back in the, like, man, 2005 timeframe.

74
00:13:51.170 –> 00:13:59.100
Kevin: My job, my team’s job, was solely on charge racks, like, avoid losses, stop the losses, and that was a singular focus.

75
00:13:59.100 –> 00:14:18.980
Kevin: And that worked for a while, but as we got better, things began to change, and obviously the company matured, and our goals changed as well. And so when I look at businesses today, if I were to start from the ground up and, you know, build my own risk and fraud organization, tools, teams, processes, etc.

76
00:14:18.980 –> 00:14:20.770
Kevin: Number one.

77
00:14:21.400 –> 00:14:36.720
Kevin: balancing growth with security, like, yes, you want to protect against the downside, but to be honest, when you talk to your manager, or, you know, whether you roll up to the CRO, the CEO, the CTO, whoever it might be.

78
00:14:37.190 –> 00:14:39.090
Kevin: What resonates with them?

79
00:14:39.520 –> 00:14:51.899
Kevin: It may not be chargebacks, not gonna lie. It’s going to be more so around growth-oriented items, so things like acceptance rate, conversion rate. How do you balance that with your team? So that’s one area.

80
00:14:52.400 –> 00:15:07.580
Kevin: The second one is cross-functionally aligned. So, in that previous slide, we had… it kind of looked like a virus, right? Where you had the different siloed teams or tools, and so often, when either I’ve experienced it myself or, you know, working with different clients.

81
00:15:08.020 –> 00:15:17.640
Kevin: they don’t have the same objectives and key results, or the goals, on their team as they do with their sister team, and that’s…

82
00:15:17.640 –> 00:15:25.329
Kevin: a recipe for… not disaster, per se, it’s a recipe for inefficiency. And the reason why I say that is because

83
00:15:25.330 –> 00:15:42.179
Kevin: if you, you know, you want to go alone, you can go pretty far, or you can go kind of fast, but, like, if you want to get far, actually, you have to go together with a group, or in this case, different organizations. And so, in terms of what you’re building from a fraud perspective.

84
00:15:42.510 –> 00:15:51.390
Kevin: sometimes… especially with working with different organizations, they’ve got their own OKRs and own to-dos, and

85
00:15:51.640 –> 00:16:09.250
Kevin: fraud, risk, that might be the second thought, or the third thought. And so, if you’re not aligned there, it’ll be much more difficult to show your efficacy, or your, kind of ability to impact the business in a positive way. Case in point, when I was at Square.

86
00:16:09.350 –> 00:16:22.850
Kevin: the reason why that we were able to be successful from a risk standpoint is not because we said no to a bunch of people, it’s that we actually were able to say yes to a bunch of people. So a lot of the banks and credit card issuers and other PSPs out there

87
00:16:22.890 –> 00:16:30.679
Kevin: they were so risk-averse that they said, you know what? We can’t accept Jerry as a micro-merchant because we know nothing about him.

88
00:16:30.970 –> 00:16:32.750
Jerry Hoff: But when Square came along.

89
00:16:32.850 –> 00:16:52.259
Kevin: we actually had quite a robust kind of credit and underwriting scenario, and we said, hey, we actually, from a risk perspective, we want to say yes to Jerry, because… and by the way, he got rejected by, you know, PSP1, 2, and 3, and that enabled us to scale really quickly into this whole different category of folks.

90
00:16:53.380 –> 00:17:09.329
Kevin: The next bucket is around holistic, and when I think holistic there, it’s… it is different than cross-functional line, because that’s more of an internal mindset and scenario. Holistic is from the customer scenario, or the end-user scenario. What are we looking at, and

91
00:17:09.400 –> 00:17:22.089
Kevin: Admittedly, yes, most people are concerned with the transaction, because that’s really when you, can monetize it, or if we’re dealing with a digital wallet or a fintech company that has stored value, it’s the.

92
00:17:22.099 –> 00:17:22.469
Jerry Hoff: the draw.

93
00:17:22.720 –> 00:17:30.989
Kevin: those things. But… one signal that I still to this day remember is when it came to

94
00:17:31.140 –> 00:17:33.959
Kevin: Finding fraud, or being an indicator of fraud.

95
00:17:34.260 –> 00:17:45.709
Kevin: one of the top signals that I would use internally was not how much they’re depositing or drawing or, you know, how they’re signing up. It was actually, are they,

96
00:17:45.910 –> 00:17:47.549
Kevin: He’s the end user?

97
00:17:47.720 –> 00:18:04.419
Kevin: do they subscribe to our newsletter? Now, that might sound like a weird thing, because obviously the marketing team cares about that metric of, like, hey, we have a million merchants, or a million customers on our platform. How many of them submit, how many of them open our newsletters? And what’s that open rate?

98
00:18:04.480 –> 00:18:08.709
Kevin: Very important to marketing. Seems like it wouldn’t matter to the risk team at all.

99
00:18:08.800 –> 00:18:12.279
Kevin: However, I won’t say, though, the…

100
00:18:12.610 –> 00:18:23.739
Kevin: If an end user opened up a newsletter, or actually engaged on the platform in that way, that was an excellent predictor of legitimacy, and so that was a signal that

101
00:18:23.780 –> 00:18:38.379
Kevin: Has nothing to do with the credit card, has nothing to do with… they’re trying to withdraw $10,000. If they actually opened up the marketing newsletter and engage with it, that was a very positive signal. And that’s what I mean about just being holistic from that perspective.

102
00:18:38.690 –> 00:18:44.189
Kevin: And the last column here is around board thinking, where so often.

103
00:18:44.350 –> 00:18:54.810
Kevin: And this ebbs and flows, where teams are in that reactive firefighting firefighting mode, and that is just…

104
00:18:55.730 –> 00:19:09.249
Kevin: all they’ve ever known, or that’s just the way that they were built, and that’s just how they operate. And when I look at more mature teams, as they go from, let’s say, the reactive mode to, ideally, you get into a maintaining mode.

105
00:19:09.250 –> 00:19:21.779
Kevin: an optimizing kind of scenario, and then you’re innovating, and that’s really where, kind of, the magic can happen with regards to forward thinking. Then you can begin to become more proactive, and I’ll say, instead of

106
00:19:21.840 –> 00:19:32.010
Kevin: reacting to a fire that’s more, like, instinctual. You can respond to something and get closer to, and Jerry, you might see this in the security world, getting closer to time zero, and what I mean by.

107
00:19:32.010 –> 00:19:32.390
Jerry Hoff: that.

108
00:19:32.390 –> 00:19:40.279
Kevin: is chargebacks and other things, they can be very lagging indicators, and 30 days later, 60 days later, if you’re learning at that point.

109
00:19:40.530 –> 00:19:58.259
Kevin: and then making changes, that’s a very reactionary motion and kind of instinct. What businesses are doing now, in kind of, becoming more insured and kind of part of this new blueprint, is what are the things that we can do closer to time zero at account creation or deposit.

110
00:19:58.260 –> 00:20:08.140
Kevin: to take action on that front. What systems or tools, processes, platforms do we need in place to be able to monitor at that point before, you know.

111
00:20:08.280 –> 00:20:10.019
Kevin: Shit hits the fan, essentially.

112
00:20:11.050 –> 00:20:13.950
Jerry Hoff: Yeah, this definitely has a lot of parallels with

113
00:20:13.970 –> 00:20:30.199
Jerry Hoff: With security in general. I mean, the balance between growth and security, it’s the same thing. If you put too many security controls, you could wind up losing customers, losing people, losing functionality, losing competitive advantage. But I like what you said. If you have your fraud detection

114
00:20:30.200 –> 00:20:35.460
Jerry Hoff: program dialed in correctly, it can be a competitive advantage.

115
00:20:35.460 –> 00:20:46.019
Jerry Hoff: Because you can, I guess, survive and live in situations where others cannot. That’s very interesting. And the cross-functionality, that makes sense to me. The holisticness.

116
00:20:46.030 –> 00:20:58.060
Jerry Hoff: I guess that’s another part of having cross-functionality alignment. It makes a lot of sense, and then forward thinking, absolutely. We did have one question that came in, and the question is about, essentially.

117
00:20:58.250 –> 00:21:15.319
Jerry Hoff: the percentages, or I’ll read it. It says, hey, do you have a sense of industry data that sizes revenue impact of fraud versus the cost to run a fraud program? I.e, can you provide industry data comparing the cost of prevention in relation to the amount of revenue at risk?

118
00:21:15.730 –> 00:21:25.140
Kevin: Yeah, great question. So, maybe I’ll answer that in a few different flavor, then I’ll answer first with a story. So, in a previous role.

119
00:21:25.330 –> 00:21:31.379
Kevin: I had essentially a fraud budget, and let’s say it’s a million dollars a year, right? And within that fraud budget.

120
00:21:31.720 –> 00:21:37.789
Kevin: I was able to spend that on operations, so, like, just headcount. I was able to spend it on tools.

121
00:21:37.870 –> 00:21:41.089
Kevin: And I was able to spend it on fraud losses, essentially.

122
00:21:41.100 –> 00:21:58.579
Kevin: And where my mindset shifted that day is actually I was talking to the CFO at the time, and she’s… and I was… I went into that meeting, because, you know, you have one-on-ones, whatever. I was gonna say, hey, we are looking great. When it comes to the fraud losses, we’re in, you know, fantastic shape, and…

123
00:21:58.610 –> 00:22:10.839
Kevin: she said, Kevin, that’s great that those are, you know, trending down in a good way, but, you know, what’s our acceptance rate look like, and what’s our fraud budget? Because, let’s say we have

124
00:22:11.150 –> 00:22:28.730
Kevin: you know, 20 people on staff, and that’s obviously quite expensive. And so, really, where she challenged me, or changed my mindset, was to think about it not from just the losses perspective, it was around, what’s my fraud budget, where, let’s say it’s a million bucks total, then

125
00:22:28.890 –> 00:22:47.099
Kevin: let’s say I do spend, you know, $500K on headcount. That means I have another $500K to play with, with regards to tools and, frankly, losses. And so, we then shifted the conversation where I was coming in, quote-unquote, under budget. It’s like, oh, I’m on track to spend, invest, $800,000.

126
00:22:47.100 –> 00:22:51.890
Kevin: But that leaves $200,000 that I can play with. Maybe I actually do want to…

127
00:22:51.950 –> 00:22:54.860
Kevin: up my losses up to $200K here.

128
00:22:55.150 –> 00:23:02.330
Kevin: so I can tune my acceptance rate. And so, what I would ask the, you know, the person that asked that question would be.

129
00:23:02.740 –> 00:23:09.100
Kevin: When it comes to, like, straight… like, operating expenses.

130
00:23:09.410 –> 00:23:13.339
Kevin: The way that you measure those losses, you’re never gonna be…

131
00:23:13.460 –> 00:23:27.039
Kevin: 100% accurate. So, like, every order that you decline, it doesn’t actually mean that they’re fraud. There’s a high likelihood, right? Otherwise, we wouldn’t have declined it. You can measure those, but then play with different spectrums of… let’s say we’re only

132
00:23:27.180 –> 00:23:35.130
Kevin: 70% right. And so maybe of the $100,000 in losses that you quote-unquote prevented with those orders.

133
00:23:35.430 –> 00:23:52.320
Kevin: maybe don’t take credit for all 100K. What if we… what if we moved it down to $70K or 80K, and then you can begin to create that, kind of, different spectrums of investment or losses. Typically, and this is actually where it…

134
00:23:52.490 –> 00:23:57.040
Kevin: Came in play, especially if the economy is doing… is… is, kind of…

135
00:23:57.620 –> 00:23:59.560
Kevin: In a… in a rough spot, where…

136
00:23:59.670 –> 00:24:18.700
Kevin: at that point, I was on the… I was under the customer success org, and we were competing from, like, a support person versus a fraud analyst. Our fraud analysts, because we’re so numbers-oriented, we made so much more money, quote-unquote, back, and so, in that case, it was easier for us to retain that talent

137
00:24:18.910 –> 00:24:32.469
Kevin: over a support person, because I could tell the CFO, like, every person that we invest, we’re bringing back a million dollars in savings. So let’s say this person costs $100K, and they save a million.

138
00:24:32.690 –> 00:24:34.380
Kevin: That’s a 10x ROI.

139
00:24:34.450 –> 00:24:36.780
Jerry Hoff: How does that compare to a support person?

140
00:24:37.080 –> 00:24:56.240
Jerry Hoff: Yeah, that’s… that’s something that, you know, unfortunately, in the infosec, it’s very hard to quantify, but in fraud detection, I think you’ve got good quantification. So I do have one more… one more question for the audience. What stage of fraud maturity is your organization currently in? So, now that we’ve kind of talked about that maturity

141
00:24:56.680 –> 00:25:09.419
Jerry Hoff: model, if you will, are you in unaware, reacting, maintaining, optimizing, or innovating? So we only have about 3 minutes left, three and a half minutes left, but there was another question that came up.

142
00:25:09.420 –> 00:25:20.279
Jerry Hoff: We’ll deal with this while we’re waiting for the rest of that poll, but if you compare the best teams that are effectively managing their fraud and revenue loss exposure to lower performing teams.

143
00:25:20.280 –> 00:25:29.919
Jerry Hoff: What are some of the best practices that you can see in the data? So, in other words, you look at the best teams, you look at the mid-teams, what can the mid-teams implement to become much more effective?

144
00:25:30.950 –> 00:25:32.439
Kevin: So maybe… well, actually.

145
00:25:32.660 –> 00:25:45.469
Kevin: That’s a great segue into… so maybe, Jerry, let’s flip to the next slide, and there’s three, kind of, areas that I would count and kind of look at, and then we can go back to the, the poll question. Number one is, it’s not just

146
00:25:45.470 –> 00:25:56.119
Kevin: about building processes, or just, like, those mid-teams out there, what can they do to kind of up-level to that A side? It’s…

147
00:25:56.120 –> 00:26:13.709
Kevin: of course, building out the policies and procedures, but making sure those platforms are actually connected, and they’re actually talking to each other. So, whether it’s the teams talking to each other, whether it’s the data talking to each other, making sure that is connected to create a positive feedback loop, and so, which I’ll talk a little bit more about in a moment.

148
00:26:13.990 –> 00:26:29.789
Kevin: The second one is around what are the right metrics to measure? Now, in the… we have the common metrics, whether it’s fraud loss rate, charge-back rate, manual review rate, false positive rate, kind of those things. If those are, you know, key to your business, like, absolutely.

149
00:26:29.790 –> 00:26:41.029
Kevin: have measurement in place, and whether you use Looker or Tableau or whatever BI tool you have out there, what I encourage you to have is a really strong pulse

150
00:26:41.030 –> 00:26:53.289
Kevin: even every day, like, I don’t think you need it by hour or anything, but every day, every week. Understand what are the right metrics for your team, and what matters not just to, let’s say, your boss, but what

151
00:26:53.920 –> 00:27:10.700
Kevin: what measure… what metrics measure to your sister teams, and how does the work that you do impact them? And if you can create a scenario where the work that you do impacts your sister team in a positive way, thus creating kind of like that win-win scenario, really great things are going to happen.

152
00:27:10.800 –> 00:27:14.430
Kevin: And the last thing I’ll mention is around that feedback loop, where…

153
00:27:14.770 –> 00:27:18.450
Kevin: I kind of break it down into… draining…

154
00:27:18.650 –> 00:27:26.689
Kevin: Like, quality, training, and policy. And you might create the best policy ever, but if you don’t give it proper training.

155
00:27:26.980 –> 00:27:31.009
Kevin: it’s not gonna work. You can have a great policy, great training.

156
00:27:31.010 –> 00:27:51.499
Kevin: But let’s say the quality is poor, as in the analysts or whoever is reviewing it, they’re just not adhering to the, this… the quality of, like, what needs to be done, that’s gonna break down there as well. And so, creating those feedback loops, certainly within your team, but also cross-functionally, also tends to be a strong,

157
00:27:51.790 –> 00:27:54.820
Kevin: Kind of way to build for scale.

158
00:27:55.890 –> 00:28:01.140
Jerry Hoff: Very good, very good. We got the… we got the results back. It looks like,

159
00:28:01.340 –> 00:28:05.400
Jerry Hoff: One was unaware, one was reacting, two were maintaining.

160
00:28:05.600 –> 00:28:15.709
Jerry Hoff: quite a bit we’re optimizing, which I think is a good sign, right? And then, too, we’re innovating, so it looks like the majority are kind of in the optimizing phase. Is that normal, Kevin?

161
00:28:16.690 –> 00:28:18.749
Kevin: I think that is…

162
00:28:19.340 –> 00:28:28.939
Kevin: pretty normal. Maybe we’re giving ourselves a little too much credit, but I think that is a good, kind of, way to, like, where… where to land, and obviously there’s

163
00:28:29.170 –> 00:28:44.970
Kevin: places to improve. So, when I think about teams that are in that optimizing bucket, from a mindset perspective, like, hey, they recognize where fraud is and kind of what they need to do. From a technology perspective, they definitely have some ML and AI in place. The full…

164
00:28:46.000 –> 00:29:04.489
Kevin: impact of that technology isn’t seen yet. Like, they’re building it, they’re doing a lot of launch generation, and they essentially, when it comes to process and structure, have a lot of aligned objectives with their sister teams, and it’s no longer, just keep the losses lower, is, like, the mindset. Like, no, no, we’ve got to be more holistic about this thing.

165
00:29:05.150 –> 00:29:19.439
Jerry Hoff: Very good. Kevin, this 30 minutes has gone by way too fast. All you’ve really done is wet my appetite, or I guess, like, I want to… there’s so much more that I want to dive into. But so this… thank you so much. This has been a great conversation. I want everybody to know, up next.

166
00:29:19.440 –> 00:29:35.669
Jerry Hoff: We are going to go through how to benchmark fraud performance and find hidden gaps. So please check your email. You’re going to get information on future sessions. This has been fantastic. So, Kevin, looking forward to the next discussion. Thank you so much, and thanks to everybody. We had

167
00:29:35.670 –> 00:29:49.379
Jerry Hoff: We had almost no drop-off, we had no drop-off the entire time, so this was clearly a topic that hit home for all of our folks, so thank you so much. Thanks for all that joined, and hope to see you back at the next webinar. Thanks, everybody.

168
00:29:49.910 –> 00:29:50.339
Kevin: Thank you all.