The Blueprint is Sift’s new how-to series for fraud leaders who want practical guidance, not theory. Each session walks through a specific problem—from org design to benchmarking and revenue alignment—with clear steps, tradeoffs, and examples from real companies.

Friction and security are often treated as a zero-sum tradeoff: add more verification steps, lose more customers. But the best fraud teams have learned to do both. In this session, we cover how to map where friction actually lives in your user journey, identify which steps are doing real security work versus just adding drag, and redesign authentication and verification flows that reduce abandonment without opening the door to account takeover or payment fraud.

Sift’s Trust and Safety Architect Jeremy Cannon and AppSec Training CEO Jerry Hoff walk through how to use data from approvals, declines, chargebacks, and step-ups to tune controls over time—and how to align product, fraud, and CX teams around shared metrics so you can safely experiment, measure impact, and scale what works.

What You’ll Learn:

  • How to identify where friction actually lives in your user journey, and which steps are doing real security work vs. just adding drag.
  • How to redesign authentication and verification flows to reduce abandonment while keeping account takeover and payment fraud in check.
  • How to use data from approvals, declines, chargebacks, and step-ups to tune controls over time.
  • How to align product, fraud, and CX teams around shared metrics so you can safely experiment, measure impact, and scale what works.

Featured speakers

Jerry Hoff, CEO, AppSec Training
Jeremy Cannon, Trust and Safety Architect, Sift

Watch Webinar

Close

Thanks for submitting!

close

Video Transcript

WEBVTT

1
00:00:00.180 –> 00:00:14.819
Presenter: Blueprint Series. It’s a pleasure to have you all here. Today’s topic is going to be how to reduce friction without compromising security. So this is going to be a great talk. Today, I’ve got a very special co-host.

2
00:00:14.940 –> 00:00:25.880
Presenter: Jeremy Cannon. Jeremy actually has several roles at SIFT. He leads managed services, and he’s also the trust and safety architect. Jeremy, how you doing today?

3
00:00:26.340 –> 00:00:31.460
Presenter: I’m doing great, Jerry. Glad to be here. Happy to talk a little fraud and friction with you.

4
00:00:32.080 –> 00:00:47.470
Presenter: What’s amazing about your background is not only are you an engineer of sorts, a fraud engineer of sorts, but you used to be an actual engineer, like a locomotive engineer, which I find fascinating. I guess we’re here to help companies avoid train wrecks, so to speak, right?

5
00:00:47.970 –> 00:00:56.140
Presenter: That’s right, Jerry. Yeah, I had a kind of strange career pivot, but I think it gives me a unique perspective on the world, on fraud, on the space.

6
00:00:56.190 –> 00:01:12.200
Presenter: I love it, I love it, I love it. Today’s topic is really apropos, and it’s going to be on friction. I have to say up front, I am exactly the type of consumer that we’re going to be talking about today, such that if there’s too much friction.

7
00:01:12.200 –> 00:01:24.140
Presenter: it sometimes pops me out of my… my desire to buy something. I’m like, oh my gosh, okay, forget it. You’ve asked me too many things, I’m not gonna go forward anymore. But if there’s no friction, if there’s nothing that…

8
00:01:24.150 –> 00:01:27.570
Presenter: I feel holds up the transaction, there’s no security or anything.

9
00:01:27.650 –> 00:01:39.789
Presenter: alarm bells start going off, where I think, is this a fraud? Is this site legit? What’s going on here? So, let’s start off by going through, in your own words, Jeremy, what is friction, and how are we going to define it for today’s talk?

10
00:01:40.210 –> 00:01:49.479
Presenter: I think in the simplest terms, Sherry, the best way to define friction for the purpose of this talk is it’s any additional step you have to make to complete the transaction or purchase.

11
00:01:50.260 –> 00:02:09.159
Presenter: Gotcha, gotcha. I think we’ve all been there, we all buy stuff online, and sometimes it’s… it feels comforting, and sometimes it gets a little bit excessive. And I talked about that on the last Blueprint series. So, let’s get into, kind of, from the customer’s journey point of view, what are these different categories here? Help us understand.

12
00:02:09.560 –> 00:02:25.069
Presenter: Yeah, so the user journey, like it says from login to checkout, is every step or action you take along this journey to initially complete your transaction, right? Whether that’s a checkout or creating an account. And we can apply friction at various locations throughout that.

13
00:02:25.320 –> 00:02:27.450
Presenter: But our ultimate goal is we won’t…

14
00:02:27.580 –> 00:02:43.129
Presenter: we don’t want so much friction that we’re reducing conversions. You mentioned earlier impulse buys. Yep. I don’t want something to roadblock me from an impulse buy, and that’s absolutely right. Today, if you’re anything like me, you’re really susceptible to an Instagram ad, but too much friction might

15
00:02:43.230 –> 00:03:02.760
Presenter: snap you out of it, and you might say, I don’t… I actually don’t need this product after all, but at the same time, as we’ll learn as we get further into this, not applying some friction can have really big effects on your business. So that’s what we’re going to talk about today, balancing the internal and the external data points, trying to figure out what’s the right friction, when’s the right friction.

16
00:03:02.980 –> 00:03:05.099
Presenter: And who to apply the friction to?

17
00:03:05.860 –> 00:03:18.649
Presenter: It’s funny you say that. I’d have to think back on how many times I saw some product being promoted on social media that looked so awesome, and so I start to buy it, and…

18
00:03:18.810 –> 00:03:27.209
Presenter: depending on how many hoops I have to jump through, like, if I have to, like, oh, I gotta go find my wallet to get my 3-digit code or whatever, sometimes it does pop me out where I’m like.

19
00:03:27.350 –> 00:03:32.550
Presenter: Do I really need this thing? What am I doing? What’s going on in here? No, I think…

20
00:03:33.120 –> 00:03:48.979
Presenter: I think you’re actually right. I have abandoned multiple transactions because I can’t find the sidewalks and all the pictures, and that snaps me out of my, don’t actually need this dog toy for my dog. So I think we want to avoid that. We want to make it seamless, we want to make it feel like

21
00:03:49.290 –> 00:04:08.789
Presenter: this is for the consumer’s benefit, so that they continue on with that transaction. Excellent, excellent. Great. So, let’s look at specific examples of friction. I’d love to get into these various points. So, we’ve got here sign-up, or account creation, login and authentication, checkout payment.

22
00:04:08.860 –> 00:04:19.649
Presenter: ongoing pros transaction, we have all these different security controls. I’m assuming we’re not applying all of them. Jeremy, so give us a sampler platter, if you will, of these various friction points.

23
00:04:20.040 –> 00:04:21.900
Presenter: Yeah, you’re absolutely right. So…

24
00:04:22.100 –> 00:04:34.219
Presenter: if we applied all these, no one would buy anything, much less an impulse buy, right? So, a lot of these depend on what kind of business you’re running, what’s the purpose of the friction, sign-up and account creation.

25
00:04:34.280 –> 00:04:42.490
Presenter: It’s really good for marketplaces, if you’re the seller, or for social media type things. You want to try to verify you really are who you say you are.

26
00:04:42.980 –> 00:04:52.560
Presenter: But… and then login is good for ATOs, somewhere down the flow, if there’s any risky signals, you want to authenticate that login. But a lot of what our customers

27
00:04:52.780 –> 00:05:09.830
Presenter: here at CFC is they’re selling something, and so the checkout payment step is one that we’re going to probably talk about a little bit the most today, and I think that’s because most people are… the end goal is to complete a transaction and sell something, right? And then we have post… we have ongoing post-op. This could be…

28
00:05:10.150 –> 00:05:20.079
Presenter: After some amount of time, you need to redo one of these previous steps. You log in from a different location, you need to do one of these previous steps, especially if there’s stored credit card

29
00:05:20.710 –> 00:05:22.610
Presenter: Information in your account.

30
00:05:23.630 –> 00:05:32.839
Presenter: On last month’s Blueprint series, I gave the example that I was signing up for a cloud service, and what it did was

31
00:05:33.110 –> 00:05:34.930
Presenter: right when I made my account.

32
00:05:35.510 –> 00:05:52.989
Presenter: challenged me, and it said, you must upload your driver’s license or passport to continue. And it really annoyed me, because, number one, I was really just in the middle of seeing if this cloud service could even do what I wanted it to do. So, in other words, before I even thought about uploading

33
00:05:53.110 –> 00:06:09.829
Presenter: sensitive information like that, I would have liked to have at least had the chance to actually use the product a little bit, and then if it was really doing what I needed it to do, it would make sense. But what annoyed me was I gave up my email address, my first name, my last name, my home address.

34
00:06:10.250 –> 00:06:24.949
Presenter: credit card, CVV, I had to give all that, and then it still challenged me based on my IP address, because I happened to be in an airport lounge, saying, hey, your IP address is very suspicious, you must upload these things. Jeremy, is it… is it common

35
00:06:25.630 –> 00:06:41.770
Presenter: such that you might allow somebody to use something a little bit, or I guess it probably depends on the situation, but maybe you could speak a little bit to that. This is just… I’m just very curious. Is there… is that kind of part of the… of the process of making sure that the friction is done just right?

36
00:06:42.280 –> 00:06:48.719
Presenter: Yeah, I feel like that seems a little excessive to use an AI agent of some sort, right?

37
00:06:49.070 –> 00:06:51.530
Presenter: People are a lot more…

38
00:06:51.630 –> 00:07:03.180
Presenter: cautious. They’ll give up their email and their phone number pretty easily. They’ll even enter their credit card pretty easily, right? But when you start talking about, upload your ID, people become suspicious. You see all of these…

39
00:07:03.330 –> 00:07:04.160
Presenter: Yees.

40
00:07:04.310 –> 00:07:08.840
Presenter: news articles about people’s identities getting stolen that I think people are more…

41
00:07:08.870 –> 00:07:20.999
Presenter: a little more cautious when it comes to that. There are use cases where that makes sense. We’re talking about banking, we’re talking about things where financials move around. There are some, you know, your customer-type stuff that’s really regulatory.

42
00:07:21.030 –> 00:07:38.199
Presenter: without knowing all the specific details, it’s hard for me to imagine that was the case here. And so, if there is any sort of free trial associated with this platform, I would almost… this is like a… might be a good example of the ongoing post-transaction, right? Let them use it a little bit when it comes time to

43
00:07:38.300 –> 00:07:50.820
Presenter: put up a payment for this, if you still don’t have the data that you want to authenticate, this is, in fact, Jerry, then maybe ask for that when you have them on the hook. You know, because I think this is a perfect example of

44
00:07:51.360 –> 00:07:57.189
Presenter: Too much friction at one stage of the journey that then just made you abandon the card.

45
00:07:57.240 –> 00:08:09.950
Presenter: Yep, yep, exactly. Also, on login and authentication, it might be because I work in security, but I look very positively if certain organizations allow me to use my YubiKey.

46
00:08:09.950 –> 00:08:22.510
Presenter: Right? So, I’ve got a… the two-factor authentication, the little YubiKey itself, the USB drive, and I have to put it in. It’s a little bit annoying, but it definitely gives me reassurance that, especially with my more.

47
00:08:22.510 –> 00:08:29.900
Presenter: sensitive accounts that it’s going to be exceedingly hard for bad guys to get into that, so this is actually

48
00:08:29.900 –> 00:08:44.470
Presenter: friction as a competitive advantage. Am I the only one, or are other folks think that way, too? No, I think we’re seeing across the industry more and more companies allowing authenticator apps, UB keys, those sorts of, like, more persistent

49
00:08:44.550 –> 00:08:52.790
Presenter: types of things where you’re saying, I’m actually choosing this, but in the same terms, if someone is then making the choice to…

50
00:08:52.990 –> 00:09:07.939
Presenter: to use their Authenticator app, to use their YubiKey, to use these sort of things to authenticate themselves. You want to be careful what you do down the line, right? If they’re already taking that step to be very security-minded. You then do not want to ply them with extra friction.

51
00:09:08.030 –> 00:09:13.270
Presenter: Yeah, yeah. Now, on the checkout payment, this is where I think I’m probably…

52
00:09:13.590 –> 00:09:18.990
Presenter: least bothered. I’m in the middle of a checkout. It makes sense to me, okay.

53
00:09:19.150 –> 00:09:35.930
Presenter: give me… give us your CVV. What I don’t like to do is enter a whole bunch of information again, like my address or whatever happens to be. So what are, like, your thoughts on the checkout and payment part of friction points in that phase of the customer journey?

54
00:09:36.340 –> 00:09:44.230
Presenter: Yeah, I think from my personal experience, this is the place where most customers are okay, right? They understand

55
00:09:44.350 –> 00:10:00.790
Presenter: that this is the… most of us, sadly, have had an unauthorized transaction on our credit card before at this point. It’s just the nature of existing in this digital world, right? So, I think this is a really good place where most people will accept it. Again, to your point.

56
00:10:01.050 –> 00:10:09.540
Presenter: But also, a lot of people are making these transactions and stuff on the fly, so sometimes re-entering your whole credit card is a little bit…

57
00:10:09.730 –> 00:10:28.120
Presenter: unobtainable to you. You might have the CVV in your brain, you might remember your zip code. I know my American Express card, sometimes they step up with the safe key, but I know my login credentials, I have them saved in a box. You still want to make sure that it’s something, to your point earlier, where

58
00:10:28.120 –> 00:10:39.250
Presenter: you can’t abandon that impulse control. I think people will take a little more friction at this stage, but you still don’t want to make them abandon the car, even if it’s thinking, like, oh, I’ll have to get back to it, because I don’t have my card on me.

59
00:10:39.280 –> 00:10:45.809
Presenter: Yeah, CVV, and obviously it depends on the situation, but I always find CVV and zip code

60
00:10:45.960 –> 00:11:00.950
Presenter: That gives me assurance that there’s some security going on, but it’s also not too onerous. But I’m sure it’s… it depends on every company, right? Every single company’s gonna have a different set of these friction points optimized for what they’re doing. Is that right, is that right, Jeremy?

61
00:11:01.060 –> 00:11:16.220
Presenter: Yeah, absolutely. If you’re a marketplace, and you’re going in, and you’re selling designer handbags, they’re going to want to check you out earlier in the process, right? They’re going to want to make sure that you are who you say you are. That’s the place where ID verification and stuff like that makes a lot of sense.

62
00:11:16.300 –> 00:11:32.559
Presenter: I might want to do a checkout payment stage upon withdrawal, but you’re not actually making a purchase on this website, right? So you… you’re going to be limited to where you can add the friction there, versus on the other side of the marketplace, if you’re the person making the transaction.

63
00:11:33.040 –> 00:11:36.350
Presenter: You might want to think about that at the actual payment stage.

64
00:11:36.460 –> 00:11:44.550
Presenter: Let them create an account, let them scroll, let them see what you’re selling, and then add that friction at the checkout stage.

65
00:11:44.700 –> 00:11:59.769
Presenter: Makes sense, makes sense. I’d love to hear from the audience. So, for folks who are on, we’d love to know, does… where does your team feel the most pressure? Is it… you have too many customers being flagged, or there’s too much friction?

66
00:11:59.820 –> 00:12:12.289
Presenter: Or is it the opposite? You have not enough friction, and you have too many fraudulent transactions getting through, or is it both? Or is it neither? Jeremy, is it better to have too much or too little? What’s your thought?

67
00:12:12.420 –> 00:12:32.330
Presenter: I think in the end, we’re trying to find that balance, right? And I’m really interested to see what some of the people on the webinar say, because as fraud practitioners coming from the security world, sometimes we’re like, you gotta be the safest, it’s gotta be… give them all friction. But we know that’s not the reality, and so I’m really interested to see what everyone says here, and where

68
00:12:32.520 –> 00:12:42.770
Presenter: inside of their business, inside of their organization, they’re feeling the pressure. Is it to add more friction? Is it to add less? What are they trying to optimize for?

69
00:12:42.820 –> 00:13:02.540
Presenter: Yep, yep, it makes sense. They work in cybersecurity, and in cybersecurity, you don’t want any incidents, right? You want to make sure that incidents just never happen. But at the same time, very similar to fraud, there’s a balance. If you have… if things are too tight, you’re going to negatively impact the business. If they’re too loose, then obviously you can have an incident, but

70
00:13:02.610 –> 00:13:06.839
Presenter: In the case of fraud, I can imagine, okay, yeah, we had

71
00:13:07.300 –> 00:13:19.160
Presenter: a certain number of fraudulent transactions come through, but the benefit was that we had more deals complete. We did get some feedback from the audience, it’s interesting.

72
00:13:19.330 –> 00:13:32.989
Presenter: 67% of folks who are watching right now, they said that actually both. They’re trying to solve both of these problems at the same time. That was followed up by 22%, which was too many trusted customers being flagged

73
00:13:33.130 –> 00:13:38.310
Presenter: And then, actually, 11% said, we don’t have clear visibility into either yet.

74
00:13:38.630 –> 00:13:53.100
Presenter: Nobody said too many fraudulent transactions are getting through it, so it sounds like this audience, at least, is a bit more on the tightening side, making sure that they’re reducing the fraud, which is probably what you would expect for folks who are coming to a fraud webinar.

75
00:13:53.610 –> 00:14:04.080
Presenter: Yeah, I don’t think I’m super surprised by those numbers, but I do think ultimately solving for both is the right thing, right? We’re gonna talk… we’re gonna talk about balance a lot throughout this webinar.

76
00:14:04.180 –> 00:14:14.129
Presenter: And really, throughout this series, more than likely, right? It’s like finding that balance. So, I’m not surprised to see the majority of people are trying to solve both at the same time.

77
00:14:14.190 –> 00:14:23.110
Presenter: This next slide is actually, I think, my favorite slide. This is an inside view on how customers across a wide spectrum of folks

78
00:14:23.130 –> 00:14:38.039
Presenter: view friction versus security. So this first number, Jeremy, caught me by surprise. I didn’t realize it was this high. 42% of consumers are extremely or very worried about fraud. Was that surprising to you? Maybe not, as a fraud expert. What are your thoughts on that one?

79
00:14:38.080 –> 00:14:47.530
Presenter: Yeah, obviously, as a Friday expert, we’re always in our own little bubbles. I expect this number to be even higher, because we’re solving these problems all the time, but I think what this really shows is that

80
00:14:47.830 –> 00:14:57.209
Presenter: Fraud is top of people’s mind, right? Like we talked about earlier, almost everyone has had, or at minimum knows someone who’s had unauthorized transactions.

81
00:14:57.370 –> 00:15:15.259
Presenter: my bank account got hacked, all of these things, so we know that. And if you look to the chart over to the right of this, it shows that the results of something like this happening can be catastrophic to your business. 52% of people said they would stop using the platform. It’s almost an even split between who’s

82
00:15:15.870 –> 00:15:27.380
Presenter: responsibility, I guess, preventing fraud, split between the bank, which often has you as a captive audience and you can’t move away from, and the website or app that you can

83
00:15:27.780 –> 00:15:32.589
Presenter: almost always abandon and go to a competitor, so I think this is very important.

84
00:15:32.950 –> 00:15:36.979
Presenter: To think about as we talk about friction, and what are the trade-offs?

85
00:15:38.560 –> 00:15:56.649
Presenter: There’s also that number at the bottom left that says, consumers willing to accept additional security steps during checkout or login, 93%. That makes sense. That’s from a baseline of just username or password. They’re saying, hey, they’re willing to accept additional security, so that’s almost universal, which makes a lot of sense to me.

86
00:15:56.790 –> 00:15:59.160
Presenter: Jeremy, what… I’m sorry, go ahead

87
00:15:59.410 –> 00:16:05.590
Presenter: I was just gonna say, this number, I actually think is good news for all of us here, right? It’s good news. It means that we

88
00:16:06.440 –> 00:16:14.250
Presenter: Customers are willing to accept friction, being said, we have a little more rope than we thought we had in the past to apply friction.

89
00:16:14.560 –> 00:16:28.680
Presenter: to customers. But at the same time, it does not mean, to your point, we can apply it all through the journey, we can make it overly complex, but it does allow us to say, our customers do value security over

90
00:16:29.320 –> 00:16:31.489
Presenter: a little bit of inconvenience.

91
00:16:31.610 –> 00:16:42.779
Presenter: And then, real quickly, the other thing that caught my attention on this slide is who consumers believe is responsible for preventing fraud. So, 52% think the bank or the card issuer

92
00:16:42.900 –> 00:16:48.660
Presenter: is responsible for preventing fraud? What are your thoughts on those numbers on the bottom right?

93
00:16:49.440 –> 00:17:07.829
Presenter: Yeah, like I was saying before, I understand, I think a lot of people do think it’s the bank of the car. I think a lot of times when fraud happens, a lot of people think, my bank got compromised, right? And usually it’s a little more complex than that, but as I was saying before, often your bank… you’re a captive audience to your bank.

94
00:17:07.910 –> 00:17:13.319
Presenter: How much you have to go through to move banks or move cards is a lot of…

95
00:17:13.470 –> 00:17:18.980
Presenter: steps, and a lot of hurdles. But if the website that… got compromised.

96
00:17:19.160 –> 00:17:21.430
Presenter: was buying shoes. There’s…

97
00:17:21.869 –> 00:17:34.460
Presenter: 3,000 other places you can go buy shoes, right? So, I really think while the top line number is bank and car issue, the one that we, as this audience, should be really concerned about is that it’s very closely related to

98
00:17:34.590 –> 00:17:48.819
Presenter: we take the blame. Our app, our website, we’re the ones that take the blame, and as we all know, often that’s not true. You were compromised somewhere else, etc, etc, but it doesn’t really matter, because at the end of the day, people will abandon your platform.

99
00:17:48.860 –> 00:17:57.419
Presenter: Yeah, yeah, absolutely. And that all comes from the Q1 2026 Digital Trust Index, which is a great report.

100
00:17:58.070 –> 00:18:02.370
Presenter: So, now that we have a pretty good understanding of friction.

101
00:18:02.620 –> 00:18:22.460
Presenter: We gotta talk about optimizing it, and we’ve been talking a little bit about this throughout the course of the conversation, but Jeremy, give us a couple of thoughts on optimizing. Again, it’s like hot sauce. Too much? Not good. Too little? Too bland, or something like that. How do you get to that happy medium, and do you have to do it on a phase-by-phase basis?

102
00:18:22.920 –> 00:18:35.539
Presenter: Yeah, I think we covered some of this earlier, like you said, but I think the things that are important to remember here is use the data you have to understand when is the right time, and if you’re using a tool like SIFT or some other tool.

103
00:18:35.540 –> 00:18:43.470
Presenter: Use those signals to say, this is more risky, let’s apply friction. Jerry’s ordered here with those same

104
00:18:43.860 –> 00:18:57.809
Presenter: credentials, the same address, a thousand times, letting through. Make it as frictionless as possible. And I don’t think that this is a set it and forget it type of thing. I think we often are like, look, we put 2FA in, we’re good.

105
00:18:58.040 –> 00:19:11.080
Presenter: All is good, but we need to be working with other teams across our organization to see what is the impact of this, and at the end of the day, our goal is that we want to make sure we have more revenue coming into our bank accounts, and, like, friction is to help them.

106
00:19:11.590 –> 00:19:26.610
Presenter: Makes sense to me. Jeremy, is there the concept of good friction versus bad friction? I think you might have mentioned it, but I can’t quite remember. I’m assuming that there are some activities that just add no value or negative value, and some are exceptionally positive.

107
00:19:26.790 –> 00:19:35.829
Presenter: Is that something that folks should be doing, is identifying or trying to figure out, or is that the… is that the secret sauce of how to figure out what is the bad friction versus the good friction?

108
00:19:36.170 –> 00:19:41.949
Presenter: Yeah, I think we talked about this a little bit earlier on, and a lot of it is, like, where you apply it, but also…

109
00:19:41.950 –> 00:19:57.059
Presenter: making it seem like you are doing this for the consumer. I think we’ll talk about it a little later on in this. Branding is really important when it comes to this friction. You want to make sure that your customers know this is to protect them, not that you’re just having them jump through countless hoops.

110
00:19:57.060 –> 00:19:59.000
Presenter: To maybe protect…

111
00:19:59.000 –> 00:20:08.119
Presenter: Even if it is to protect you at the end of the day, you want it to feel like it is a protection for them as a consumer, and not some hindrance that they have to do.

112
00:20:08.190 –> 00:20:09.710
Presenter: I mentioned earlier.

113
00:20:09.920 –> 00:20:25.539
Presenter: You want to make it easy, too. You want to make it easy for them. I don’t want to have to pick out 100 motorcycles out of a thing. I know people love that, but sometimes I miss a motorcycle, and I gotta start over. We want to make it something that they can accomplish easily, and get on with the transaction so they don’t lose that momentum.

114
00:20:25.860 –> 00:20:26.920
Presenter: Makes sense.

115
00:20:27.120 –> 00:20:40.980
Presenter: So it’s time to ask the audience as well, when was the last team, your team, when was the last time your team did an audit of your step-up authentication or manual review triggers?

116
00:20:41.140 –> 00:20:50.199
Presenter: So I guess the options are within the last 6 months, 6 to 12 months, more than a year ago, where we have not done a formal audit. Jeremy, what are you seeing in the field? Is it…

117
00:20:50.380 –> 00:21:06.200
Presenter: do people think that this is a set it and forget it type thing, or are they adjusting too much, or where does that… what does that look like from what you… Yeah, I think this is an interesting one, because I do sometimes think people think of this as, like, set it and forget it. We’ve implemented this thing, it’s here, it’s great.

118
00:21:06.750 –> 00:21:09.649
Presenter: it’s stopping fraud. A lot of times, too, that is…

119
00:21:09.840 –> 00:21:12.270
Presenter: The only metric we have is it’s…

120
00:21:12.450 –> 00:21:24.870
Presenter: fraud is down, right? But I think this is an opportunity to collaborate with other teams in your organization. What is the customer experience team experiencing? Are people complaining that they can’t get their orders through?

121
00:21:25.040 –> 00:21:41.369
Presenter: Talk to finance. What are the revenue numbers? Stopping fraud is super important, and for all of us, we’re fraud practitioners, maybe the most important. But for the business, at the end of the day, we want to be auditing this and seeing if it’s actually accomplishing what we want it to accomplish, to not just stop fraud, but to

122
00:21:41.540 –> 00:21:45.830
Presenter: Keep more good transactions in our ecosystem and bad transactions out.

123
00:21:45.990 –> 00:21:55.469
Presenter: Yeah, yeah. It’s very similar to security, as I keep mentioning, but whenever we have these discussions, it makes me think so much that

124
00:21:55.470 –> 00:22:08.660
Presenter: applications, like if you have a food ordering app or whatever, the security controls themselves could be inhibiting sales, so those need to be reviewed as well as all part and parcel of this. Very interesting. The results are back.

125
00:22:08.880 –> 00:22:18.779
Presenter: So, probably, you might have expected this, but 44% of folks say that we have not done a formal audit, which means somebody put it together, and…

126
00:22:18.940 –> 00:22:37.119
Presenter: That’s it, nobody’s ever reviewed it. 11% said more than a year ago, 33% said 6 to 12 months ago, and then 11% within the last 6 months. So it sounds like it’s about split. Some folks, about half the folks, are doing it at least on a yearly basis, and the other half

127
00:22:37.470 –> 00:22:41.759
Presenter: Maybe they’ve never done one. Does that kind of match up with what you see as well, Jeremy?

128
00:22:42.010 –> 00:22:48.520
Presenter: Yeah, I think that’s what we expected, and I think, in the end of the day, the cadence isn’t the most important thing, right? That’s gonna be…

129
00:22:48.640 –> 00:23:00.610
Presenter: up to your business, it’s gonna… when do you have enough data to actually do this review, right? But I do think we should do this review at some cadence, and talking about coming from the security world, there’s…

130
00:23:00.930 –> 00:23:18.330
Presenter: I know that you often try to find security advocates, evangelists on each team. We want to do that with the fraud team, too, so this is also a good opportunity to cross-functionally work with some other teams to see if this is working, but to also get them on your side to say, this is important.

131
00:23:19.500 –> 00:23:24.209
Presenter: People are leaving a lot of money on the table. If… in either way, if it’s too…

132
00:23:24.460 –> 00:23:38.100
Presenter: again, we’re circling this thing over and over again, but it’s like, too much friction, you’re losing revenue. Too little friction, you are… you have too much fraud. Yeah, it’s a really fun… must be a fun and challenging

133
00:23:38.340 –> 00:23:44.389
Presenter: A set of variables, and you’ve got to look on this… look at this on a client-by-client basis to try to figure out this happy medium, right?

134
00:23:44.950 –> 00:23:55.039
Presenter: Yeah, absolutely, and like I said, this is where bringing other teams in is really going to help you, because we only see a part of the picture on this side of the house in fraud, and

135
00:23:55.420 –> 00:24:14.900
Presenter: at the same time, the other side of the house, they don’t see a part of the picture, so if we really bring this full picture together, I think we can make good decisions and make more money for our companies. There we go. So for those folks who have not done a formal audit, or it’s been a long time, please reach out to Jeremy. He and his team are going to help

136
00:24:15.060 –> 00:24:25.630
Presenter: Get that just right for folks. So, let’s talk… so what would that look like, Jeremy? Let’s say somebody comes and says, okay, we want to redesign our friction. What are the things that you look at?

137
00:24:26.260 –> 00:24:38.290
Presenter: Yeah, we talked about some of this before, right? We talked about the user journey. Where’s the highest risk point? And that’s going to be very business-dependent, right? It’s your marketplaces versus selling. We talked about data-driven results.

138
00:24:38.310 –> 00:24:46.970
Presenter: we have to customize, randomize. You and I were having an interesting conversation about setting thresholds. If we’re gonna do this after a certain

139
00:24:47.400 –> 00:25:02.979
Presenter: monetary threshold, how do we decide that? And the one thing that I always suggest to my customers is we want to make it feel as random as possible. If you set it at $100, that’s hackable. Someone can figure that out, right? They’re going to keep their orders right under. But if you set it at

140
00:25:03.240 –> 00:25:16.300
Presenter: $99.98, so a little harder to figure out, right? We want to keep things as random as we can, so that the bad guys can’t hack it, and it essentially makes no difference to the

141
00:25:16.450 –> 00:25:26.989
Presenter: a regular consumer. And then branding. We haven’t talked about this yet, it’s the one thing we haven’t talked about, but what is the message that you’re sending to your customers when you’re asking them to

142
00:25:27.450 –> 00:25:37.779
Presenter: do this extra step to complete their transaction. You want to make sure that they know this is for their safety, to protect their purchases, their information.

143
00:25:37.990 –> 00:25:45.789
Presenter: So that they feel that this is not an inconvenience, this is actually an awesome step that you as a company are taking to protect them.

144
00:25:45.920 –> 00:25:58.540
Presenter: Yeah, yeah, it’s like, fraud protection as a competitive advantage, as I said before, yeah, absolutely. So, this was a very interesting slide. So, bad is…

145
00:25:58.720 –> 00:26:06.300
Presenter: here’s your two-factor authentication. If this wasn’t you, ignore this email, or we noticed you tipped 100% of your bill. Was this you? So what is the thought there?

146
00:26:06.680 –> 00:26:12.879
Presenter: Yeah, so I was actually talking to a colleague recently, and we were talking about this, and they were saying that they had these two different

147
00:26:13.310 –> 00:26:16.670
Presenter: Types of messages recently, and they resonated differently.

148
00:26:16.780 –> 00:26:28.589
Presenter: I think that ignore this email is… while I understand where that’s coming from, I think that saying to ignore this email, often people have more questions. They want to know, how did I get this if it wasn’t me?

149
00:26:28.620 –> 00:26:40.419
Presenter: what was happening here. Depending on where the two-factor is, it means someone might have gotten through your email and your password, and now they’re being presented with the two-factor, so you should prompt them to do something, change that password.

150
00:26:40.480 –> 00:26:52.889
Presenter: The other, while not technically friction, is basically, we noticed this thing, we’re not applying friction, we allowed it to go through, but it does look anomalous, and so we want to make sure that you

151
00:26:53.030 –> 00:27:05.629
Presenter: if this wasn’t you, do a thing. Yep. And one of… I know we’re short on time, but one of the things we want to make sure that we cover here is that don’t give away too much information. No, we don’t want to give the fraudsters a playbook.

152
00:27:05.920 –> 00:27:15.939
Presenter: Excellent, excellent. We’re a few seconds over, but Jeremy, thank you so much. That was a fantastic conversation. I want to invite everybody to our next month’s

153
00:27:15.970 –> 00:27:34.900
Presenter: how to have a seat at the revenue table. It’s going to be a fantastic conversation, and for those of you who haven’t seen the rest of the Blueprint series, please go to the landing page that is on SIF’s website, and you can look at past episodes. Jeremy, thank you so much. Audience, thank you all, and looking forward to seeing you at the next

154
00:27:34.900 –> 00:27:38.309
Presenter: Blueprint Series. Have a wonderful rest of the day. Thanks, everybody.