Gone are the days of fraud losses being cast as a mere write-off for enterprises. With easy access to tools that allow cybercriminals to launch scalable attacks—exacerbated by the explosion of generative AI—fraud can no longer be ignored by the C-suite. At the same time, executives have the opportunity to turn investments in fraud prevention into substantial, profitable growth.

Sift and special guests Andras Cser, Vice President and Principal Analyst at Forrester Research, and Alex Bolante, National Managing Director at Deloitte, have an insightful discussion about how executives can leverage fraud prevention as a growth driver. Some key takeaways include:

  1. Understanding the Financial Impact of Fraud: Learn about the direct and indirect costs associated with fraud, including loss of revenue, increased operational costs, and damage to brand reputation.
  2. Strategic Integration of Fraud Prevention: Discover how integrating fraud prevention into your customer identity strategy can enhance consumer experience, reduce churn, and drive customer acquisition and retention.
  3. Future-Proofing Your Business: Explore emerging trends in fraud and the importance of staying ahead of fraudsters with advanced, AI-powered solutions.
  4. Collaborative Approach to Fraud Prevention: Understand the importance of cross-functional collaboration within your organization, from IT and security teams to marketing and customer service, in building a resilient fraud prevention framework.

Watch On-Demand Webinar

Close

Thanks for submitting!

close

Video Transcript

0:00
Thank you for joining us. Uh we are here today to talk about the seuite
0:05
imperative and you can see the subtitle. It’s why execs must prioritize online
0:10
fraud management as a strategic growth lever and um a very involved topic uh
0:16
that certainly um welcomes perspectives from the outside. And so joining me
0:22
today is an esteemed panel um and I’ll ask everyone in to introduce themselves
0:27
briefly for me. I’m Armen Nagarian, the chief marketing officer here at Syft.
0:32
I’ve been in the fraud prevention space for nearly 10 years and I’m very excited
0:37
to be joined by two very esteemed colleagues. So, Andra, could you please
0:41
introduce yourself?
0:43
>> Absolutely. A man, this is Andra, chair. Uh hello. Um I am a vice president and
0:48
principal analyst with Forester and I cover fraud management as well as
0:52
customerf facing identity and access management. A pleasure to be here. Thank
0:56
you.
0:56
>> Thank you. And Alex, please introduce yourself.
1:00
>> Absolutely. Thank you, Armen and Andra. Uh, Alex Bonte here. I’m a managing
1:03
director in cyber strategic risk for Deote. I currently co-lead our digital
1:08
fraud task force, which essentially brings together cyber, forensic,
1:13
financial crime, AI, engineering, and data skills, uh, you know, to our
1:17
engagement center clients. Thanks for having me.
1:20
>> Excellent. Okay. And I think it’s worth noting that to be a member of today’s
1:23
panel, your first name must begin with an A. So, we fulfilled that goal.
1:28
All right, so let’s let’s get into it. A couple of framing slides for me. Um,
1:32
this is a point of view from SIFT. You may have seen versions of this before in
1:37
the industry, but when you think about the investment in fraud management,
1:42
there’s really two sides to the coin. On one hand, it’s stopping bad things from
1:46
happening, preventing fraud, mitigating fraud, reducing fraud loss, reducing
1:50
risk. Yet on the other side of that coin, that very same coin, there’s a
1:55
growth story. There’s a growth investment to deliver a better consumer
2:00
experience, to increase conversion, to drive incremental revenue. And it’s this
2:06
balancing act that we all struggle with in the industry, but is very core to
2:10
this discussion, especially as we have a narrative and have a discussion with the
2:15
seauite. Getting this balance right really puts the bullseye on what we call
2:21
the riskrevenue balance. A little bit of data here. Uh you know
2:29
fraud is not reducing in scope or scale or velocity and we see this quarter over
2:35
quarter, month over month, week over week. 11% of all revenue um is allocated
2:41
to fraud prevention or fraud protection. Bigger than you might have thought. um
2:45
reducing risk is a is becoming not just a sidebar activity or cost of doing
2:50
business. There’s a meaningful investment being made into mitigating
2:55
fraud and mitigating digital risk so that business businesses can operate
2:59
profitably. $27 uh dollars in losses for every $100 in
3:04
fraudulent ordered. So from a merchant perspective, the cost of fraud is
3:08
significant. again no longer a cost of doing business erodess
3:14
margin and bottom line by allowing these fraudulent transactions to go through.
3:18
And then finally 2.9% of total revenue is lost due to fraud. Now that metric
3:24
might look different depending upon what’s what sector you’re in or whether
3:28
you’re more of a traditional bricks and mortar retailer or if you’re a fintech
3:33
but on average nearly 3% of total revenue is lost due to fraud. It’s a not
3:38
insignificant number and for these reasons and many more this subject is an
3:45
imperative now for the seauite to to get it right and really transform the point
3:50
of view from stopping fraud to really really converting this investment into a
3:56
valuable growth lever. I’m looking here at some data from the merchant risk
4:00
council. This is from their study they released earlier this year right after
4:04
their Las Vegas summit. So it’s very fresh data and they went out and pulled
4:10
a number of members of their audience um more than three more than 260 uh members
4:17
of their audience both MRC samples uh I’m sorry MRC members and non-MRC
4:22
members and really the the question was what fraud attacks have you experienced
4:28
in the past 12 months and you can see what we’ve boxed on the top left the
4:32
yellow bars are the members of the MRC The blue bars are the non-members, not
4:38
they’re not nonparticipating members of the MRC. Still important, but you can
4:42
see some interesting disparities here. Um, but most notably the top three.
4:47
First party misuse um aka friendly fraud or first party fraud depending upon your
4:52
your context. Card testing as an as an attack type. It’s very very uh large and
4:59
growing as you can see. And then account takeover which um has always been
5:04
present but has in recent years and even quarters has rapidly escalated to being
5:10
to being a top three attack type even from a merchant perspective. So some a
5:15
little bit of data here a little bit of context setting around top of mind
5:19
attack types relevant to uh the audience that we’re speaking with today. And then
5:24
finally, you’ll hear discussion today around the rise of AI powered fraud. Uh,
5:31
and this is a point of view from the attack perspective, how AI is being
5:36
weaponized by fraud actors. And you can see a variety of different attack types
5:40
that are increasing the volume, the velocity or the intensity of fraud
5:47
attacks. We see this every day here at SIFT with the fraud that we’re stopping.
5:51
Our customers, merchants, fintexs are seeing this every day. There’s
5:56
innovation taking place from the fraud actor community harnessing the power of
6:00
AI to inflict uh even greater harm onto these digital businesses. So with that,
6:05
I’d like to turn it over to Andra uh for a few uh slides and his point of view.
6:10
>> Yeah, definitely Arin. Thank you. You know, definitely seeing similar trends.
6:14
So I I just want to kind of walk through um the delicate balance and a hard
6:18
problem to solve. So fraud management is is basically a four-legged stool in in
6:23
our opinion, right? So obviously if you look at the upper right hand corner the
6:28
lock, right? Fraud loss reduction or keeping fraud losses where they are is a
6:33
mandate. If you can’t like you produce skyrocketing chargebacks, bad fraud
6:38
rates, you’re going to be, you know, kind of ask be going to be asked
6:43
questions by your, you know, stakeholders, owners,
6:47
um, and staying in competitive is going to remain harder, right? Moving
6:53
anticlockwise to the guy with a hammer and computer, operational efficiency is
6:58
very important. So even if you’re able to maintain fraud losses, right? You
7:02
cannot hire an unlimited number of investigators,
7:06
data scientists, compliance personnel, etc. Right? So you have to keep all this
7:11
in in a check. the sort of cost of fraud that 11% right that that Armen mentioned
7:17
and in his stat slide you know can’t that’s even that’s already at a level
7:22
where you you do not want it to kind of rise the flower bottom leftand corner
7:27
the right level of customer friction you know uh putting customers through too
7:32
much friction is bad obviously they’ll go somewhere else where they can sign up
7:36
log in uh they buy things uh or do do the transactions but Not asking them
7:42
questions makes them kind of uneasy. Hey, you know, are you are you guys
7:46
running a good enough security program if you’re an e-commerce site or bank,
7:50
etc. And the bottom right hand corner, regulator compliance scrutiny. This is
7:55
getting worse and worse. We’re seeing a lot of questions by the regulators
8:00
technical in nature, more in-depth and and just checking the boxes, you know,
8:04
one by one is not going to be enough. Next slide, please.
8:10
Uh so generative AI and fraud management and AML are def is definitely making a
8:15
lot of headway right this is on top of you know traditional AI machine learning
8:20
processes uh such as um you know logistic regression neural networks n
8:26
Beijian classifiers etc. This is generative AI typically uh large
8:32
language models and large transaction models uh that are being used. So the
8:37
areas that we see genai being used in in fraud management is one area from the
8:43
model management uh perspective. We see large transaction models. So large
8:47
transaction models mean that the system generative AI is able to generate
8:52
synthetic set of resource synthetic set of attributes on top of native
8:57
attributes for each transaction. So for example, you can create create
9:00
cumulative um uh measures such as how much money this customer has spent with
9:06
a certain retailer, how many times a certain device has been seen in bad or
9:10
fraudulent transactions etc. And then on top of so basically then combining these
9:16
synthetic attributes with the native attributes and running uh AI, machine
9:20
learning, anomaly detection models on top of these larger uh transaction
9:24
models yields better accuracy. uh AML as a generative AI in addition in
9:30
the model management can also do sentiment analysis right so it can
9:33
detect in a chat session if there’s any kind of a uh distress with the caller it
9:39
can detect things like you know too being somebody being too calm you know
9:43
if frosters doing something for the you know millionth time they’re going to be
9:47
very calm about something that a normal user would be upset upset about u valid
9:53
model validation is a use case that genai is definitely working in so this
9:57
is more like the generative adversial adversarial networks that we’ve seen in
10:02
the deep you know go you know basically two AI models training each other model
10:09
improvements and rule recommendations are absolutely important so genai can uh
10:16
synthesize and create rules create models and using AI governance
10:21
understanding the model um you know how the model is getting better the
10:25
explanability um is is absolutely important. So that’s
10:29
the model ris risk waring part. On the investigation side of things, we’ve seen
10:35
u generative AI producing uh insights based on visual link analysis. So this
10:41
is how transactions hang together connected by a phone number or connected
10:46
by a physical address or a name or an email address. These can be good or bad
10:50
transactions, fraudulent or non-fraudulent transactions.
10:54
uh when you see uh these generative AI can actually go further and deduce and
11:01
and generate kind of further insights in these situations. Gen AI can produce
11:07
investigator guidance. So basically for newbie or less savvy investigators you
11:12
can tell you know it can act as a co-pilot right and say hey look at this
11:16
look at that have you thought about investigating this device ID or that
11:20
other shipping address or this card number and lastly in investigation genai
11:25
can create narratives this is very similar to how chat GPD works verbal
11:29
responses or textual natural language textual responses to natural language
11:34
textual questions reporting again narrative creation and natural language
11:38
queries and responses. On the threat side, you know, we’ve seen large
11:42
transaction models and large language models being used. So again, being able
11:47
to use um for example large language models to detect review
11:52
fraud, right? So you look at um a bunch of reviews or or look at first party or
11:58
or friendly fraud kind of return uh explanations and reasons, right? when
12:03
people type in why they want to return something genai can definitely help
12:07
there as well. Next slide please. Uh so basically um use cases are
12:15
understanding user intent, user help and guidance for data scientists and
12:20
business users, report formulation, model improvement, sentiment analysis,
12:24
synthetic data creation and detecting deep fakes. Deep fakes is is a hugely
12:29
hugely uh prevalent problem these days. We probably see every 80% of of our kind
12:36
of fraud management asking the question about deep fix. So if we go to the next
12:40
slide Armen how can we detect against deep fakes
12:47
right uh protect against deep fakes? Well, protections are typically going to
12:52
exist in the audio or voice analysis as well as the video or image analysis
12:57
domains, right? Uh they’re always almost always going to be multi-layered. So
13:01
there’s no single single layer defense against um deep fakes in the voice space
13:07
as well as in the video space. We see spectral audio analysis. What this boils
13:12
down to is deep fake algorithms create uh basically artifacts in sounds and
13:17
artifacts in voices that humans cannot generate, right? Or cannot actually
13:22
create the vocal system. Your vocal boxes, your vocal cord will not be able
13:26
to create certain sounds that algorithms and deep fakes will. And they will do
13:31
it. The fake algorithm will do it repeatedly versus humans are not able to
13:37
repeatedly create the exact same sound, the exact
13:41
same uh uh audio artifact with the same spectral analysis.
13:47
Uh video artifact analysis again similar things uh around that you know how come
13:51
somebody’s mouth is moving strangely? How come somebody’s uh facial muscles
13:57
are not moving in in unison background? So basically something that’s behind uh
14:02
a person can be telling uh it you might see repetitive backgrounds being used
14:09
and then device posture device integrity and drivers device drivers are very
14:14
important. So controlling the channel and not allowing a a deep fake uh
14:18
generator to in inject uh fake audio or fake uh video into the camera or
14:25
microphone uh device driver is very important. A lot of times we see
14:30
corporate managed devices being used here especially for high-risisk high
14:33
value transactions and then strong authentication passwordless
14:38
authentication is is definitely a a measure to protect against deep fakes
14:43
when you know the CFO uh is being instructed by a CEO in a supposedly in a
14:48
supposed mobile call mobile phone call to transfer a million dollars from point
14:53
A from the company to a fraudster. There should be some kind of a of a an an
15:00
extra layer of authentication that the C that the CEO needs to provide to the CFO
15:05
before this transaction can move forward. And then looking at risk
15:08
signals, these are things like uh device identities, behavioral biometrics and
15:15
other types of uh of signals. Next slide.
15:21
Workflow. I cannot emphasize the the importance of workflow in in in your
15:25
various products. You have to kind of bring all these layers set of defense
15:29
tools like your audio uh and and voice biometrics, front end, call center
15:34
biometrics, mobile devices, transaction risk scoring, identity verification,
15:39
authentication um and other uh systems together. So the
15:44
workflow should be able to uh basically make API calls to systems out and
15:50
receive API calls for other systems. You should always plan for a non-monolithic
15:55
approach where you can add new components relatively easily to to your
15:59
fraud management architecture and things should be orchestratable. That means
16:03
that you should be able to change the order in which things are being called
16:07
in a relatively easy uh manner without having to kind of create uh code or or
16:14
uh customization configuration should be uh the preferred mechanism. So I just
16:20
want to kind of put up you know lay the lay the landscape here uh and set the
16:25
stage here for the discussion. So let me hand it back to Armen.
16:29
>> Thank you Andra. Appreciate the point of view here. So just a little
16:33
housekeeping. So um we finished kind of the prepared comments. We’re going to
16:37
transition into a discussion um around topics uh related to what was queued up
16:44
in the point of view from upfront. You can also submit questions through the
16:48
Q&A module in your Zoom uh console. So please do submit questions and we’ll
16:54
certainly take questions at the end of the moderated discussion. And this
16:58
session will be it and is being recorded and I believe a link will be sent out
17:02
afterwards for uh for those that want to uh share with others. So with that I’m
17:08
going to go off of screen share and let’s uh let’s get into a discussion
17:13
Alex and Andra. Um I would I would like to start off
17:17
with you know one of the elephants in the room and that is we are seeing from
17:22
a SIP perspective a massive influx of what I would call AI fueled or AI
17:28
powered or AI enhanced attacks. We see it every day among our customer
17:33
community. We talk about it with our partners. Um, I would love both of your
17:38
points of view on um, how are you what trends are you seeing with AI powered
17:43
fraud attacks and how are you seeing companies react to that?
17:52
>> Yeah, absolutely.
17:56
>> Yeah, I was gonna say you can go first. Yeah,
17:58
>> sure. Sure. So, you know, there’s definitely the AI bots, robots that we
18:03
see out there to automate the work and and activities of fraudsters are
18:08
definitely using AI in there. Um definitely you know if you’re looking at
18:15
tools to uh really beat u you know kind of behavioral biometrics sensors and
18:22
check such as you know mouse movements that are absolutely straight
18:27
perpendicular lines or instead of like a human moving the mouse or screen swipe
18:32
generation a lot of AI has actually you know solve quote unquote solved this
18:37
problem. So modern bots do not generate you know completely straight
18:41
perpendicular line mouse movements. They’ll add some randomness in typing
18:45
patterns as well. Uh and then you know we so that’s one area. Another
18:51
interesting area is that we’ve seen uh basically data scraping robots uh
18:57
searching and seeking public sources about people
19:02
leans, tax records, property records about people that they can then use in
19:06
you know an identity verification. Um, you know, obviously, you know, the
19:11
deep fake generation is a topic that I’ve already talked about, but that’s
19:14
another, you know, hugely, you know, uh, threatening area, right, of of AI AI
19:20
powered fraud, uh, you know, perpetuation out there.
19:25
>> Yeah,
19:25
>> Alex, what are your thoughts?
19:26
>> Yeah, to that to that point, it’s interesting. So like I think
19:29
statistically the last few numbers that I saw around AI uh enabled or power
19:35
fraud were something to the tune of you know 3,100%
19:40
increase in deep fake fraud attempts uh over the last year. Um that was from an
19:45
onfo report. I think it was something like 1,200%
19:49
uh increase in fishing emails after the introduction of chat GPT. fishing,
19:54
fishing, smishing, by the way, one of the top six cyber threats published in
20:01
um Deoid’s cyber threat trends report last year or really the last two years.
20:05
Um and then you were mentioning Armen earlier account takeover attacks like
20:10
within the last year we’ve seen a 354% increase right in just that alone. And
20:16
so I think to me like that’s a testament of the rise of um when we say genai
20:23
specific product attacks even right voice cloning market the availability of
20:28
voice data um the lack of awareness about voice cloning techniques right and
20:33
then you know what investments firms or companies are making to uh improve or
20:40
enhance their deep fake deep voice detection prevention capabilities. these
20:46
um if you think about the two types of in my view like AI enabled fraud attacks
20:51
the common one I see would be uh corporate fraud right so there’s been
20:56
examples where um you know scammers use deep fake voice tools to call the CFO of
21:02
a company posing as the CFO saying there’s a pending business transaction
21:06
that requires funding and then that funding is then processed as an example
21:11
right so corporate fraud um has been a big one that I’ve seen across uh uh the
21:17
industry or sectors. Um and then the other is really individual scams. You
21:22
know, there was a deep fake scam uh in another country where fraudsters used
21:26
deep fakes to mimic friends on a phone call um believing that that friend
21:32
needed, you know, urgently funds, right? And transferred I think it was something
21:36
like $600,000 US of stolen money. So between corporate
21:41
fraud, individual scams and all these other AI enabled or powered
21:47
fraud attacks, I I think companies are certainly be becoming more tuned to the
21:51
fact that they need to start doing something in this space. Right.
21:54
>> Very good. And I think there’s an important distinction that both of you
21:57
touched upon um with how AI is being weaponized, what I would say weaponized
22:02
by the fraud actor community both in terms of Gen AI powered fraud attacks
22:08
and deep fakes is one great example. Alex, you touched upon what I’d call
22:11
business, you know, business email compromise, even, you know, leaving the
22:15
voice aside. Just better crafted emails, right, that are lifelike and and very on
22:20
point. Very basic use.
22:24
>> No typos like we’ve seen in some, you know, Nigerian 419 scams, right? Like
22:29
like the grammar is not perfect, right? The chat GPD knows how to how to type,
22:34
you know, kind of write a letter without titles. Definitely. Yeah. perfect
22:38
syntax, perfect context. Um, you know, it it’s in virtually undetectable. So um
22:45
generative AI powered AI uh generative AI powered attacks uh different from
22:51
what I’d call data science-driven AI powered attacks uh that’s for example we
22:55
see in the world of payments you know here at SIFT um a different type of
22:59
velocity of attack types in the world of payments leveraging science um even card
23:04
testing leveraging AI from a fraud actor perspective to try to circumn the
23:10
defenses that are in place and certainly on account takeover right? A a better
23:14
use of bots leveraging AI um not necessarily generative AI but leveraging
23:20
data science from a fraud actor perspective. So it’s pervasive. It it’s
23:24
across the spectrum of generative AI to what I would call data science driven AI
23:29
and um and and the threat is real. So I think we’ve kind of made that point in
23:33
observation. Any other final thoughts just on how in light of that, how
23:37
companies are gearing up for this onslaught that that we’re already facing
23:43
as an industry? I
23:45
>> I would say the the only chance, right, that that you have on the defensive side
23:50
is basically use AI and Gen AI to defend against AI and Gen AI based attacks,
23:56
right? I mean, there’s nothing else out there that you could do. It’s it’s
23:59
basically beating the adversary at their own game with their own tools. Um
24:04
obviously you know large language models, large transaction models that I
24:09
I talked about uh you know GANs, GANs are definitely areas of of um of
24:16
improvements. uh I would say even if if we don’t want to go there to this more
24:21
like you know AI versus AI uh story better threat detection using artificial
24:27
intelligence using a multitude of traditional models an ensemble of models
24:33
right in in decision- making usually yields a lot better um and highly a lot
24:38
more accurate response um and also built you know we are seeing
24:44
a lot of um money invested into understanding and
24:50
building uh customer device and any really any kind of an entity uh
24:55
behavioral baseline using artificial intelligence. So, you know, obviously
24:59
there’s there’s things that you see for the very first time. But if you see
25:02
somebody um basically buying bad covers, right, and and having it having them
25:09
shipped to a certain address, right, from an e-commerce provider
25:13
and now suddenly you’re seeing a completely different set of activities,
25:16
completely different addresses being used, completely set mix of of
25:21
completely different mix of of items being ordered. Um you may want to
25:27
increase the risk level. It’s not necessarily so changes in behavior are
25:30
not necessarily fraud but they definitely have an impact on the risk
25:34
and to usually increase the risk level uh that and it’s a signal to a more
25:40
accurate decision-m process.
25:42
>> Very good. So you’ve kind of touched upon you the fighting fire with fire as
25:45
a response which I think is very true. Excuse me. Leveraging AI to fight AI.
25:51
One could argue that this is really the new arms race, right? that that the
25:55
weapon of AI is the defense against that weapon and we’re seeing a lot of
26:00
innovation surrounding that uh that very real arms race. So, Alex, any final
26:05
point of view on on this topic?
26:07
>> Yeah, if I if I think about just from a you know
26:11
program, people process governance perspective outside of the tech, right?
26:17
I I think you know most organizations or at least leading organizations
26:21
understand that the interconnected risks between cyber fraud, financial crime is
26:28
um it’s it’s pretty tight now. It’s pretty it’s it’s it’s more or less
26:31
blurred boundaries and so the siloed approach to fraud detection prevention
26:38
um just isn’t tenable right or working for them um particularly around those
26:42
fraud risk signals or indicators. So I think one aspect would be um you know I
26:47
see organizations at least my clients centralizing those risk signals and risk
26:52
indicators from an aggregation response and just overall strategy perspective so
26:57
they have a holistic risk view um of the fraud events and attacks right the
27:02
second thing I think they’re doing is they’re realizing they need to relieve
27:06
pressure from the business units um who are building frankly their own
27:10
strategies to prevent and detect fraud and so they’re they’re standardizing
27:16
um you know developing a common way to you know govern manage and measure um
27:22
those fraud detection prevention cap capabilities and those overall
27:25
operations. And then the last thing or the third thing I would say they’re
27:28
really doing is if you think about it, you know, they they have a need to
27:36
eliminate redundancies obviously from a cost takeout or reduction perspective
27:40
across the tools in tech and and they certainly can do that um you know by
27:45
leveraging the right tools at the right layers you know with the right stack if
27:50
you will um working cohesively together um to orchestrate you know both the
27:55
friction and the fraud aspects of it. So yeah, obviously fighting fire with fire
28:00
is a big one, but I think there’s also that people, you know, part of it,
28:04
right? This concept of fusion uh that was that was built or
28:08
established a while ago, which is now much bigger than what it was before.
28:13
>> Great. And we will touch upon that fusion topic in just a moment. So great
28:16
uh great queue up for that, Alex. Thank you. Um and I want to remind the the
28:20
audience we are accepting questions. Use the Q&A feature. Um I’ve seen a couple
28:25
of questions submitted already. So thank you very much. Um and let’s continue. So
28:29
let’s transition to really the theme of this this webinar. Really the reason for
28:34
being for this webinar is that in light of the shifting the rapidly shifting
28:38
landscape and intensity really fueled by AI around the attack types the um the
28:46
view of fraud management from a seuite perspective has also rapidly evolved.
28:51
historically very much focused on a cost of doing business, a cost center. Let’s
28:56
just mitigate or minimize fraud losses to now this is an existential threat to
29:02
running a profitable business and we know that getting it wrong, making wrong
29:07
fraud decisions will materially negatively impact the consumer
29:11
experience which has implications on revenue. Right? So this has become much
29:15
more of a revenue focused consumer experience discussion more so from a
29:20
seauite perspective than a cost management discussion. I would love to
29:23
hear your points of view on this. Alex, why don’t we start with you? How are you
29:28
seeing that mindset shift from the seauite perspective?
29:32
>> Yeah. Um you know so I was talking about these the the salad approach to these
29:37
interconnected risks becoming untenable and I think the seauite realizing this
29:42
operating model uh of how different functions obviously if you’re in
29:47
financial services first line second line third line work together right it
29:50
it needs to be rethought essentially so much that the operations need to shift
29:55
with the profile of these types of cyber and fraud uh events um you know I think
30:02
in a world where where customers are infrequently interacting with their
30:07
companies, their brands, different products almost entirely through digital
30:12
channels. It’s this digital trust quote unquote, right? That’s fast becoming the
30:17
significant differentiator for customer experience. And so if you are a company
30:23
that is offering seamless, secure, speedy digital interactions, a digital
30:29
interface, you know, that sort of simple and secure experience, you’re going to
30:33
see a positive impact on revenue or at least you’re going to see that digital
30:37
trust established, right? That that you know, um hopefully doesn’t erode value
30:42
or potentially lose business. And so like I think companies are demanding
30:46
these faster risk decisions. If you think about again like a banking
30:50
real-time payments and so there’s a need to strike the balance between friction
30:54
and fraud and handling these transactions instantly and so I think
30:58
when when executives are able to tell that story to the seauite let alone the
31:04
board to gain sponsorship and buyin to your point far it becomes about revenue
31:09
protection or revenue recapture versus this just being a cost center for the
31:15
organization and that’s how I’ve seen some of my clients build the case for
31:18
change.
31:19
>> Very good. I appreciate the perspective. Andra, what are your thoughts on this
31:23
topic?
31:23
>> Um, I mean, obviously the competitive pressures from other firms, right, and
31:28
other similar providers in your area that are able to kind of lower the cost
31:32
of fraud, lower the cost of fraud management and investigation
31:36
really factors in their prices, right? So, you won’t be able to maintain the
31:40
same kind of um high prices that kind of bury all and and absorb the cost of
31:46
fraud management. So there’s the leaning of of basically um of of cost right u
31:53
for fraud management. So that’s one thing. The other thing um I would I
31:57
would mention here is there’s definitely some um role that the compliance uh
32:05
mandates play here right so um it you know PSD2 has just kind of
32:10
revolutionized in in at least in Europe you know customer authentication uh for
32:16
certain industries right mainly the financial institution uh financial
32:20
institutes uh story PCIDSS right is going include a lot of fraud management,
32:28
secure authentication data, organizational aspects of of um of of
32:34
identity management as well as fraud management in in it, right? So that’s
32:39
definitely going to have a u an impact and I would say the value right that
32:44
better fraud management unlocks typically when we do our you know total
32:48
economic impact analyses right in this space right at forester this is a
32:53
forester product um we regularly hear uh interviews talk to us about penetration
33:00
of new markets uh where they could not sell before. So you deploy better fraud
33:05
management tools, you lower the co lower the friction for customers, lower the
33:08
friction, pass more transactions. So you’re able to kind of get to markets
33:13
where the fraud rates have been too high for you to even think about entering
33:18
those markets, right? And I would say, you know, the lowering just
33:23
old-fashioned chargebacks, right? and and basically money lost to chargebacks
33:28
even with the tougher uh you know Visa, Mastercard, American Express, Discover
33:34
and payment card network um kinds of rules as well as lowering the spend on
33:40
chargeback management right is is also going to play an important role. Um I I
33:46
typically also bring in you know on inquiries we get a lot of questions on
33:51
these fraud management related questions and customer identity related questions
33:56
from fraud from not just security and fraud management teams but also from
34:02
marketing line of business engineering teams that really are primarily
34:06
concerned about um just providing a decent customer experience. Not
34:11
insulting you know customers that are no good. not putting people through ringers
34:16
of difficult you know account unlocks or or false positive decisions and so on
34:23
right so um listening to the the marketing people internally and and
34:28
listening to the line of business and sales people that are trying to sell the
34:31
product is sometimes a you know a very important kind of best practice that I
34:36
recommend to our clients in this fraud management space
34:40
>> very good yeah great points of view and again holistic points of view you So my
34:45
very quick point of view on this is this landscape, this industry is rapidly
34:50
orienting around the consumer experience and revenue linked to is directly linked
34:56
to a positive consumer experience and defection of that consumer if you have a
35:01
false positive is very real. And so driving fraud decisioning and investment
35:06
through the lens of what’s best for the consumer. Um I’m seeing and we’re seeing
35:10
here at SIFT as a major driver and how companies are gearing up for this new
35:14
wave of of attack sophistication.
35:17
>> I’ve heard opinion is a data point. Right. So
35:21
building on what you just said Armen. Right. Um the way to kind of socialize
35:26
and internalize these things is basically establish measurements metrics
35:31
such as right um success rates in registration like you know out of a
35:37
thousand people approaching how many successfully established their profile
35:42
login success or login failure rates right how what percent of known
35:46
customers can log in or not login um you can also look at things like um you know
35:52
conversion rates like people who have approached your site, what percentage of
35:56
those people are not able to buy something because of of just bad
36:01
decisions in the fraud management or customer identity process, right? Um you
36:06
know this is obviously on top of the false positive false negative true
36:11
positive true negative rates and their combinations and ratios in traditional
36:16
uh basically chargebackman fraud management, right? But tracking these
36:20
measures, right? and and basically tying these to the revenue um you know
36:25
improvement goals right is a very kind of real way of of making the case for
36:31
fraud management in in the company.
36:33
>> Very cool. Let let’s just do a quick double click. You’ve referenced
36:36
chargebacks a couple times on and that’s you know among the most visible and
36:42
visceral ways that that companies are feeling the results of fraud and AI
36:46
power fraud is chargeback. Um quick point of view here just like on has the
36:52
has the measurement of how chargebacks are managed evolved at all from your
36:57
perspective how companies are viewing that and any other specific techniques
37:02
you’re seeing to reduce the chargeback problem and why don’t we start with you.
37:08
Yeah. So, um obviously, you know, you want to look at the the the waterfall,
37:14
right? A cascading um numbers that you have, right? You
37:18
know, what percentage of of uh your transactions went to the past. So, green
37:24
bucket, the red bucket stop, the yellow, the manual investigation. So, so having
37:30
a standardized understanding of of rates of good, bad and and you know basically
37:37
in between transactions throughout the entire process and if there’s multiple
37:42
rounds of chargebacks like there’s arbitration right like you might you
37:45
might go to three rounds right in in coroner cases having an understanding of
37:51
of these metrics is absolutely important and then you know doing post-mortem uh
37:56
why a decision was incorrect fact or inaccurate uh is definitely important.
38:01
Um and and being able to bring in these types of decision decision decision root
38:09
causes into the model building process. So the the early stage of the model
38:14
building process uh is definitely an important element here. So
38:18
>> very good. Alex, what are your thoughts on this topic? Yeah, I mean I’ I’ve
38:21
generally seen with the clients that I’ve worked with looking at obviously uh
38:26
broader KPIs and KIS around fraud, right? Like the number of fraud losses
38:32
by product, by scheme, fraud rates, things like that. But one of the things
38:37
I think that is probably not spoken about or called for is also retention of
38:44
top talent. A lot of my clients are hiring less investigators, more data
38:49
scientists and data architects as an example. So, you know, I I think there’s
38:53
an element of like do you as an organization or company have a good view
38:59
of how you are managing and measuring the effectiveness of your current fraud
39:04
management or detection prevention response capability. And if not, you
39:08
know, that’s probably a good place to start is looking at those KPIs and KIS
39:12
>> 100%. So, so leverage so basically repeatable scalable investments you know
39:18
which you know investing in manual labor uh for investigation and followup and
39:23
narrative creation is probably not going to scale but investing what you said
39:27
Alex in in um data scientists people who build the models is a lot more leverage
39:33
and a lot more you know scalable investment absolutely 100% agree with
39:38
that’s your
39:39
>> very good very good um let’s transition to a new topic Alex You touched upon
39:43
this in your opening comments and in some of your answers and it revolves
39:47
around cross functional collaboration. So the context here is fighting fraud
39:51
effectively really touches a number of departments, right? You’re touching a
39:55
fraud department if one exists, a risk management department, an operations
39:59
department, typically a finance department, a compliance team, etc. And
40:03
so my question on this, Alex, is how are you seeing from your point of view
40:09
better collaboration, better alignment and better organizational structures to
40:14
align these very disperate functions in a unified front?
40:20
>> Yeah, I I think so maybe two parts to this. The first part would be if you
40:24
think about it at its core, uh let’s just keep it, you know, simple
40:29
to cyber fraud and crime, right? like those functions generally perform the
40:34
same three roles. Identification, you know, who is my customer, monitoring, is
40:40
this transaction legitimate? And uh response, right? How do I respond to a
40:45
threat? And when you look at the control activity that are in place across those
40:49
three functions, you look at the data, the risk signals, the tools, the tech,
40:54
there’s clearly a an opportunity for synergies across those functions. like
40:58
in identification who’s my customer risk scoring right of those customers using
41:03
common similar customer data sets like your digital footprint or even
41:09
non-digital records as an example and then when you’re doing transaction
41:13
authentication and transaction monitoring to determine what
41:16
transactions are legitimate. There’s also synergies around risk scoring of
41:20
those transactions using analytics or some common taxonomy
41:25
um or uh some common framework that looks at active data, passive data and
41:30
account level data, right? Like your device, email and phone reputation. And
41:35
then in responding to a threat, clearly there’s a common feedback loop to, you
41:39
know, or need to develop like a holistic view um of, you know, who’s first on
41:45
deck when an event quote unquote happens. How does the FIU or financial
41:49
intelligence unit work with the SOCK, the forensics, the investigations, the
41:54
resolution teams, the knock um to essentially respond to a threat. So I
41:59
think I think like understanding that like one those are the functions and
42:04
they’re performing similar roles they need to collaborate more is the first
42:08
part. The second part is I see some organizations collaborating like they
42:14
still have independent reporting and roles and responsibilities. They have
42:19
their own independent framework um because regulators are used to that
42:22
model. It’s least disruptive from the perspective of like change within the
42:26
organization. The problem is it’s you can’t really scale, right? You’re still
42:31
putting pressure on the business or different functions to solve for fraud.
42:36
And so I’ve seen several of my at least my clients start to at least partially
42:41
integrate around customer identity, customer authentication, risk
42:46
identification, risk assessment. So they have a more unified approach to, you
42:52
know, lower the risk of gaps or overlaps. they have a more consistent
42:56
like organizational structure. They still maintain somewhat separate
43:00
reporting, but in general like they’re partially integrated. I probably have a
43:05
few clients, no more than I can count on one hand, that actually have a
43:09
completely integrated consolidated unit using a single framework. They have a
43:14
single view of the customer and risk, right? They have shared analytics. Um,
43:19
and that’s working for them because back to the talent and attracting and
43:22
retaining them. um it’s giving people who historically have done let’s say
43:27
commodity cyber uh services are now doing things outside right like around
43:32
AI engineering and data or MLAI modeling and clustering and link analysis so
43:38
complete integration I think is somewhere where some companies are
43:41
headed um but certainly from an operating model perspective that’s the
43:45
most disruptive right that’s the largest organizational change
43:49
>> very interesting you know really spanning the the excuse me the people
43:54
process technology continuum um as as how you’re seeing companies react and
44:00
and maybe even proactively gear up for this next wave of um of risk management.
44:06
Very very fascinating. And what are your thoughts on this topic?
44:09
>> Sure. Uh so you know as I said fraud management is one of the most intriguing
44:15
kind of topics right in terms of ownership
44:18
um because of the reasons that that you know we just talked about right that um
44:25
Alex you know mentioned in detail. So we see IT security, IT operations,
44:32
identity and access management, typically customer identity access
44:35
management and sometimes BDB or workforce facing identity and access
44:39
management people, chief risk officers, chief financial officers, compliance
44:44
teams, line of business people, engineering, marketing and application
44:50
developers all being interested in this whole story. Right? So there’s a lot of
44:54
kind of a lot of chefs in a kitchen, lots of cooks in the kitchen. Um and and
45:00
as such it’s it’s not an easy thing to manage, right? But most organizations
45:04
have a fraud team or fraud responsibility
45:07
that at least has a dotted line relationship to IT security and and some
45:13
kind of a chief risk officer, chief financial officer type type setup. Um
45:18
Alex mentioned uh the importance of of um you know kind of what we call cyber
45:24
fusion um our fusion center. So this is basically cyber the whole authentication
45:30
flow registration authentication flow self-service password reset passwordless
45:35
authentication identity verification type of use cases being integrated with
45:41
you know transaction rescoring transaction monitoring. So that’s the
45:45
you know you kind of look at the entire chain of events or the customer journey
45:49
from inception enrollment all the way to even you know purchasing the buying
45:55
cycle right sometimes refi where it’s relevant there’s another kind of um uh
46:02
convergence happen which we call framal fraud management and anti-moneyaundering
46:06
so this is basically using the same tools the same data integration models
46:11
investigation techniques u and data sources u for basically fraud and AML
46:18
and KYC kinds of processes right so at the end of the day right I think the
46:24
longer term kind of integration could be around uh cyber so so you know online
46:33
plus the fraud management transaction monitoring plus where it’s applicable
46:38
compliance um and AML KYC kinds of things which AML and KYC is being
46:43
applied to or being asked to be applied to and a broadening kind of number of
46:48
verticals you know uh beyond banks we see it in an insurance vertical online
46:54
marketplaces and others as well.
46:55
>> Yeah.
46:56
>> Yeah.
46:57
>> Very interesting. I mean you both touched upon a a theme there was
47:00
commonality and that what is what I would say is customer identity. Um and
47:06
so the CIM customer identity access management providers um from through the
47:11
lens of authentication which I’m sure you see this a lot Alex right starting
47:15
to see downstream visibility into fraud transactional fraud um and so they’re
47:21
one step removed but in that critical path to being to being able to help
47:25
solve that problem. So in my view you know identity is one of the underlying
47:31
threads that will drive better alignment that cyber fraud fusion center you know
47:36
seeing some of these investigations show up in the sock where they otherwise
47:40
would not have you know five years ago um through the lens of customer
47:44
identity. So a very fascinating topic much more that could be discussed on
47:47
that but certainly a mega trend with respect to this discussion around how
47:51
seuitees are reorienting rethinking their investment in fraud management.
47:59
Okay, just being mindful of time. We did start a little bit late so we’re going
48:02
to run past the top of the hour. So apologies for those that have to stop at
48:05
the top of the hour. Again, please submit your questions through the Q&A.
48:08
I’m seeing several flow in which is awesome. We will get to those. Um let’s
48:12
move on to the next topic. Let’s just look at futures. We’ve talked about a
48:16
lot about the here and now, present threats, shifting organizational
48:20
structures, investment being rationalized in certain ways as you
48:24
project forward over the next three to five years. Both of you would love to
48:27
hear your point of view of what do you see shifting? What other mega trends
48:31
might be playing out that would further affect investments or organizational
48:37
structures or even systems in the world of fraud management? And let’s start
48:40
with you on this topic. So I I would say you know I mentioned the following
48:45
things right. So mediumterm or short medium-term I would say deep fakes and
48:50
prevention of deep fakes will keep people busy big time. It is something
48:54
that is really hard. All the vendors biometrics vendors are investing in deep
48:59
fake detection but it’s a cat and mouse kind of you know arms race at this
49:04
point. Um I would all so that’s the first you know long you know kind of
49:08
future trend. Next thing is scam. So basically uh we call these authorized
49:15
push push payments or or you know this is basically the use case when the
49:20
fraudster you know kind of reports and uh to be calling from the bank right
49:26
calling an elderly victim who’s not that digitally savvy and explaining to the
49:30
victim that hey your old account’s been compromised but we created a new account
49:34
for you which is absolutely safe. can you please just you know transfer all
49:38
your money from this old compromised account to this new safe account which
49:43
obviously is the fraudster account thus basically siffening off the of the
49:48
victim’s you know kind of funds into the fraudster account right these are 100%
49:53
authorized transactions how you’re able to actually combat these and do them um
50:00
kind of prevent them is is really interesting and important and really
50:04
hard to do really hard too hard to deal with. And the third trend that I would
50:08
mention here is the use misuse, fraud and abuse of uh digital identities,
50:16
governmentissued digital identities, right? So we’re seeing mobile drivers
50:20
licenses, we’re seeing wallets, we’re seeing governments like login.gov GV and
50:24
then there’s the EIDAS scheme in in the European Union starting to actually
50:30
issue real digital drivers licenses, digital citizenship artifacts, which
50:35
obviously fosters will download, right? I mean, there’s no way they’re not going
50:40
to kind of move into this space and kind of use fraudulently obtained mobile
50:44
drivers licenses uh or mobile uh national ID cards to per you know
50:50
perpetrate fraud. protection against this is is going to be a absolutely
50:54
brand new uh level of of ID theft prevention.
50:59
>> Alex, if you look into your crystal ball, what do you see over the next
51:02
three to five years?
51:03
>> Yeah, I there’s a couple things trend-wise I I think you know you’re
51:07
going to see and I saw a question about the crowded landscape, right? So
51:10
certainly an increasing increasingly complex fraud technology ecosystem um
51:17
with cyber uh vendors now playing in the fraud space and fraud vendors playing in
51:22
the cyber space or vice versa, right? Um you’re going to see obviously uh more
51:27
sophisticated cyber and fraud related attacks given the convenience of digital
51:32
first experiences. um that are frankly really the reason
51:37
why we see new advanced fraud attack vectors like Andros was mentioning right
51:42
authorized payment push real-time payments account takeover identity fraud
51:45
etc. I think you’re going to see increasing speed of financial and
51:48
reputational damage with the sophisticated fraud schemes that are
51:52
exacerbated by the bad actor’s ability to efficiently cause damage now, right?
51:56
And exploit weak identity related systems. Um, you’re going to see
52:02
certainly rising customer expectations despite the transaction complexity uh uh
52:08
complexity because customers obviously want a secure simple omni channel. They
52:12
didn’t even use the word omni channel, right? um experience. And then I think
52:17
lastly, you’re going to see from an organizational perspective
52:21
um the need to manage talent and costs as fraud expands. And we’re talking, you
52:27
know, AI savvy talent and fraud subject matter specialists that can adapt and
52:34
scale as needed, right, to the shifting profile of these financial crimes.
52:39
>> Very fascinating. Excuse me. Just a double quick question,
52:42
Alex. Are you seeing um any uh larger presence of you know staff augmentation
52:49
not full-time employees but you know more of a managed services model for
52:52
certain types of workflows. I I am mostly because uh for and I’ll I want to
52:58
use the term managed services uh loosely here because that means a lot of things
53:01
to a lot of people right I I think I think is if you think about like
53:05
maturity of a fraud program you know some organizations are aware they’re
53:10
aware of the risks but they over rely on manual intervention by investigators
53:16
right for fraud prevention investigations recalls there’s high
53:20
friction everything’s pretty much on default settings the data data siloed.
53:25
So, generally speaking, those organizations that are kind of in the
53:28
aware phase or stage of maturity, um they need a you know, let’s call it
53:32
chief of staff, like uh you know, people to help with the latest fire of the day.
53:37
Um so, there’s certainly a need for augmenting
53:40
um their current teams if you’re in that sort of aware stage. Most of the
53:45
organizations I’ve worked with are in the reactive stage where they’re still
53:49
reactive um in the sense that yes they have
53:53
technology yes they have tools they’re able to evaluate you know risk at high
53:58
risk moments for example in the customer journey but they’re not proactively for
54:03
example or even predicting like emerging patterns and schemes and scams you know
54:09
curated based on risk if you will to truly balance the friction and fraud
54:14
aspect So I I think like those clients are
54:16
looking for more people that want to uh can help them drive top down the overall
54:22
strategy around how they move from reactive to
54:25
proactive if that makes sense.
54:27
>> Yeah, absolutely. We’re seeing that as well. It’s a very interesting topic.
54:31
Again, a little bit of a sidebar, but you know, your emphasis on the
54:35
organizational structures and the people um cannot be ignored, right? when we’re
54:39
talking about large scale um shifts,
54:41
>> PCIDSS definitely for PCIDSS 4.0 starting March 2025 will absolutely play
54:48
a big role in in kind of requiring this from the compliance and and regulatory
54:54
perspective as well.
54:56
>> Fascinating. Okay. Um in the interest of time, let’s transition to questions.
55:00
There’s been a number of questions submitted. I’m just going to go through
55:04
um I’ll I’ll kind of pick a question and I will uh you know ask one or both of
55:08
you to to react. Um here’s one very basic one does a
55:17
customer identity access management cam solve for fraud? Alex would love your
55:22
point of view on that.
55:24
>> So yeah I’m obviously biased uh having uh established and led our our deoid
55:29
scan practice at large in the US. What I would say is the acronym itself is very
55:33
confusing uh in the sense that there’s a difference between the CI and
55:38
AM and CIM. Number one, most organizations have focused on
55:43
authentication from a login SSO MFA experience, not so much the identity
55:49
aspect of it. Uh which is the collection and exchange of the underlying
55:54
attributes, right? And so if I think about the buyers of Siam, who’s buying
56:00
Siam solutions and services, typically what they’re buying is experiences
56:05
and and Siam is a revenue center. Absolutely. But I also think it’s a
56:09
prerequisite to fraud digital fraud management. So one of many components in
56:16
an endto-end fraud solution, right? So does it solve for it by itself? No. Is
56:21
it a core component for revenue protection? Absolutely. It would be one
56:25
of many components in an endto-end fraud solution.
56:30
>> Very very clear answer. Thank you. And do you have a point of view on that
56:33
topic?
56:33
>> 100%. So I look I cover customer identity access management here at
56:37
Forester addition to fraud. Um so obviously you can think of it and fraud
56:42
management as ven diagrams. There’s things in in an intersection. There’s
56:46
things that each one of these things do but the others does not do. Um I I would
56:51
say you know in agreement with Alex here right that you know most organizations
56:56
are shifting their attention to the entire customer acquisition and and
57:01
journey to transaction life cycle right so the registration
57:06
the mobile data master data customer data management integration with
57:10
customer data platforms analytics uh portals right e-commerce portals the
57:15
whole identity verification right so today on an e-commerce site you can you
57:20
can pretty much sign up as Mickey Mouse right uh but you know in the future we
57:25
expect to see some level of identity verification lightweight which may be
57:30
brought in but that’s by the scan vendor it may be coming in from you know like a
57:36
uh from a fraud management vendor but things like checking for the valid
57:40
validity of a phone number or an email address or a physical ID document that
57:44
you have to show to the camera right or your mobile device or your mobile
57:49
driver’s license, digital identity, and and being able to triangulate your
57:55
customers really quickly from very early perspective, you know, very very kind of
57:59
early stage in the registration process, right, without impacting the customer
58:03
experience, creating unnecessary friction and then u in essence once you
58:09
have this established right the authentication part is as Alex mentioned
58:13
is relatively easy right I mean you know you can send you can have somebody
58:17
established and user ID may be be it a phone number, be it an email address,
58:23
send a text message or magic link or or use a mobile authenticator application
58:28
or even biometrics, right? But the question in Siam is is basically who you
58:34
on board and what how that onboarded person’s customer data relate to what
58:40
you already know about and have have you know maybe even fraud management aspect
58:44
related uh knowledge of. So I would say that identity and entity graphs and
58:51
relationship graphs in the future will play a huge role in fraud management and
58:56
obviously Sam customer identity and access management identity verification
59:02
as well as fraud management will all support uh these identity relationship
59:07
graphs.
59:08
>> Yeah,
59:09
>> we could easily have a one-hour discussion on this very topic and and
59:12
maybe we’ll do that as a follow-up webinar. So I it’s fascinating topic.
59:15
This is something that five years ago didn’t get a whole lot of attention and
59:19
it’s interesting Andra, you you sit at the intersection of these two very
59:22
important disciplines that are better aligning, maybe even converging. So,
59:26
thank you for the points of view in that. Let’s jump to another question.
59:29
Oh, go ahead, Alex. You have one more point
59:31
>> really quick. Obviously, that’s very uh US- ccentric, right? Because if this
59:34
were China, we just need your WeChat ID to know everything about you. So,
59:38
>> that’s true. Yeah, that is true.
59:40
>> That’s true. There are other ways to solve it. Yes.
59:43
>> Yeah.
59:43
>> U Good. Okay. This is a little bit of a um a sidebar but important question
59:50
that’s come in and that is around the world of consumer education market
59:55
education right around so with the rising so I’ll read it so how do you see
59:58
education of the general public the client base for for our companies
1:00:02
playing a role in combating AIdriven fraud what role do you think our
1:00:07
industry should play in being the driver of this education and I’d say and
1:00:12
awareness so Alex please share your point of view this
1:00:15
>> what um in our industry I assume could mean a lot of things but maybe specific
1:00:21
to fraud right like we’re in fraud industry
1:00:25
>> well one of the things is so in in 2016 um Armen and Andra I mentioned this
1:00:30
before we had published a world economic form report in 2016 with a number of
1:00:35
financial institutions called the blueprint blueprint for digital identity
1:00:39
identity blueprint for digital identity and one of the things we talk about is
1:00:43
how there’s no common fraud tax ought to be when you even use the word fraud what
1:00:47
does that mean right um so I think the first thing is our role is to one
1:00:54
whether it’s a fraud risk register or you know uh developing a risk assessment
1:01:00
strategy it’s number one to establish that taxonomy within your organization
1:01:05
or your company so what does what’s the difference between identity fraud
1:01:09
man-in-the-middle fraud synthetic identity fraud software vulnerability
1:01:13
fraud business emo compromised fraud, account takeover fraud, right? All these
1:01:17
different fraud types and fraud vectors number one. The second thing I think
1:01:21
that’s on us is to then think about the actual threat scenarios. So what is the
1:01:28
motive? Who is the actor? What is the relationship with that actor? What
1:01:32
techniques or tactics, techniques, procedures, right? TTPs and cyber are
1:01:37
they using what type of fraud is it? What channel
1:01:40
are they attacking us in? what is the target and what is the impact. So I
1:01:44
think those two things from an education and awareness perspective it’s on us and
1:01:50
then at the seuite level it’s to make the case for change and to me like the
1:01:56
case for change could be something as simple as well we want to detect and
1:02:00
prevent fraud events because it’s just increasing right um with the way we do
1:02:06
business digitally today or we want to enable the business and drive profits
1:02:09
and relieve pressure from them or look we just want to respond to threats with
1:02:14
speed and agility. So I think it’s being able to create that proper seauite or
1:02:20
executive level messaging from an education perspective that falls on us.
1:02:25
That’s my view.
1:02:27
>> Very very good. And what are your thoughts here?
1:02:29
>> I would say so education in my opinion splits into two um kind of big kind of
1:02:35
directions or big aspects, right? one is the seauite you know the the executives
1:02:40
at end user organizations right the I would say showing metrics showing
1:02:44
benchmarks showing you know kind of if you if you have a better fraud
1:02:49
management kind of metric better false positive rates how that translates into
1:02:55
better registration and conversion rates right I mean that is a very simple thing
1:02:59
to see right and all the investments that Alex mentioned in in data science
1:03:04
is is worth more than just kind buy more human investigators. So that’s the
1:03:10
internal executive education on the customer end user consumer education
1:03:15
right I would say that every organization should put out some level
1:03:19
of a you know basic IT security hygiene type of you know kind of guidance maybe
1:03:24
just point to some larger providers you know that that’s definitely a good
1:03:31
starting point um I would also mention you know in this customer consumer
1:03:37
education the need to show your customers consumers as to how to
1:03:43
establish trust from the customer to the service provider and the service
1:03:48
provider’s employees. Right? So give them give people tools, give your
1:03:52
customers tools and emphasize these tools that hey you know what are the
1:03:56
things that will happen you know and what are the things that will not happen
1:04:00
right? you know, we’ll never ask you for your social security number on an
1:04:03
unsolicited phone call, right? Or we’ll call you on these certain types of
1:04:07
marketing things, but never on those other types of sale sales things, right?
1:04:11
and and when someone calls you, right, pret pretending to be a uh a rep of an
1:04:17
energy company and asks for a bunch of things, how can you authenticate that
1:04:23
representative or that person that purports to be the rep of that energy
1:04:27
company or bank or e-commerce or retailer to prevent these types of
1:04:31
authorized push payment and scam kinds of measures, right? So, so basically um
1:04:37
that that’s an important element. And then I didn’t mention this but basically
1:04:42
providing people you know kind of clues as to how to recognize deep fix right
1:04:47
you know what are the things they should look for very simple things backgrounds
1:04:52
you know facial muscle movements etc that you or audio kind of artifacts that
1:04:58
you can use and if you’re in doubt don’t hesitate to kind of turn down that
1:05:03
transaction right and call back the bank or call back your e-commerce provider
1:05:07
and ask for more clarification. ation, right? Um I think these are the kinds of
1:05:12
important elements in the
1:05:13
>> Yeah, this whole topic around consumer education is is very important,
1:05:17
something that historically has not gotten enough attention and I do predict
1:05:21
that yes, there will be um organizations rising up and taking responsibility to
1:05:27
to better drive that. Um
1:05:29
>> one more thing, it’s it’s better. So I used to say that it is
1:05:33
>> bad to reveal too much and overeducate the customer and consumer, right? I kind
1:05:38
of changed my position on this because the frosters will know more about your
1:05:43
organization and and processes that you can imagine. So but if you fail to
1:05:48
disclose and explain to your consumers as to how you know you check for
1:05:52
validity, how you prevent fraud at a at a you know kind of at a level that is
1:05:58
understandable or kind of you know explainable to a normal non technically
1:06:04
savvy person I think does a lot more good than bad in terms of just
1:06:08
disclosing information.
1:06:10
>> I think that’s well said and very true. Um I see a couple questions here. I’m
1:06:13
just going to quickly address about CIF specifically. One was what Gen AI
1:06:17
products is SIFT planning on introducing? Another one was um as a
1:06:21
current Sift user, I’m curious to know what AI powered features or advancements
1:06:24
we can expect. So the the very brief answer is SIFT has been an AI company
1:06:30
since day one. Founded in 2011 in San Francisco, the AI capital of the world.
1:06:34
The company used to be called SIF Science. Um and so everything that we
1:06:38
do, our models are driven through machine learning and our investment is
1:06:44
through the lens of machine learning. and we have over 40 patents. So on the
1:06:47
on the continuum of of AI, we are very heavily on the side of machine learning
1:06:52
driven AI. The question around generative AI capabilities today, you
1:06:58
won’t see anything in the CIF console to um that that manifests itself as a
1:07:03
generative AI capability. However, you can anticipate seeing some innovations
1:07:08
there over the coming quarters that might touch upon, you know, better
1:07:11
policy writing, rules management, reporting that leverage generative AI.
1:07:16
Not committing to a road mapap here, of course, but um in my view, we’ve solved
1:07:21
one of the harder parts from a machine learning perspective. And yes, you’ll
1:07:24
start to see some of those other capabilities that leverage generative AI
1:07:28
in our product experience moving forward. So, thank you for the question.
1:07:31
Certainly, you know, please follow up with your account manager. um or or
1:07:35
follow up with me if you have any other questions. Well, we have time for one
1:07:38
more question and so I’m going to jump to um Ken Pala. Hi Ken, thanks for
1:07:44
joining us. The question is, how do you engage the seauite in understanding that
1:07:49
fraud and scams really impact future revenue? So, um I think from an
1:07:54
intellectual perspective, yes, we we have made the connection. We said it all
1:07:58
revolves around consumer experience, but what’s landing with the seauite as far
1:08:02
as like getting the seauite to act today and embrace the fact that this whole
1:08:08
subject is in fact a future revenue protector.
1:08:16
Alex, you have a thought? Yeah, I you know the the quick response
1:08:21
to that would be I think today if you think about fraud broadly within an
1:08:25
organization and how it’s managed no single person or business unit is solely
1:08:29
responsible for it. So I think it’s a shared responsibility. So if you’re
1:08:33
talking to the seauite first is understanding who you’re talking to. Is
1:08:37
it a chief risk officer, first line risk leader, a line of business leader or
1:08:41
supporting leader, right? Like a head of fraud prevention reporting to a CISO. If
1:08:45
you’re talking to let’s say the chief risk officer in my view their pain
1:08:50
points are they lack visibility into each line of business uh around their
1:08:54
practices for fraud prevention detection. So how does that uh compare
1:08:59
to industryleading or common practices right and then when you think about a
1:09:03
chief risk officer’s role they’re looking at the as as Andraas was saying
1:09:09
the rapidly evolving regulatory environment right that’s focused on
1:09:12
potential for consumer harm and so to make the case for a CRO it’s got to be
1:09:17
focused on those specific pain points whereas if you are if you are like a
1:09:22
firstline risk leader you’re probably struggling to balance budget constraints
1:09:26
right and pressure around specific fraud losses or rising costs of technology and
1:09:32
software. So I think shaping the conversation around those buyer personas
1:09:36
is probably going to be those stakeholders is probably going to be the
1:09:38
most important approach.
1:09:40
>> Very good. And any final thoughts on this topic.
1:09:42
>> Sure. So I would I would say to some advice right how how you help sea level
1:09:48
people you know really link um you know the effectiveness of the fraud
1:09:53
management program and revenue um very simple in my opinion just just
1:09:58
do do some AB or alternative testing right so let a certain proportion of
1:10:03
your customers maybe 3% 5% go through an upgraded redesigned you know you know
1:10:10
identity verification program slash and or uh transaction monitoring,
1:10:16
transaction risk scoring, watch the fraud KPIs, right? Fraud management
1:10:20
KPIs, false positives, false negatives, true positive, true negatives and
1:10:24
conversion rates for this branch of the alternative, right? For these these
1:10:29
transactions and people and just compare them with um you know with the the
1:10:34
regular rates, right? And you’re going to see big differences, right? And this
1:10:38
is by the way, you know, it’s it’s not only just a convincing mechanism, it’s
1:10:43
also like a methodology for improving and linking um fraud to business uh
1:10:49
business results.
1:10:50
>> Well, very good. Well, so with that, I would like to bring today’s webinar to a
1:10:54
close. I want to thank our audience for sticking with us. Uh we started a little
1:10:57
bit late. We ran a little bit late. So, thank you for your flexibility. I want
1:11:00
to thank our panelists, Andra Chair with Forester, Alex Balante with Deote.
1:11:06
fascinating discussion. Again, we could have gone, you know, much much longer if
1:11:10
given the time and um I want to, you know, thank everyone for engaging with
1:11:14
us on a very important topic. Uh there will be a follow-up email links to the
1:11:18
recorded webinar and um and feel free to follow up with uh with SIFT if you have
1:11:24
any questions uh about any of this and we’re happy to uh you know to reach out
1:11:27
to and Alex if there’s anything specifically that you need from them. Uh
1:11:31
so thanks very much everyone and have a great day.