An almost 50 year old concept is now all the rage in the payments space; disintermediation, which according to Wikipedia is; “…the removal of intermediaries in a supply chain, or “cutting out the middlemen.

It might be a cliché, and I hate any buzz-phrase not invented by me, but in the payments space this one makes perfect sense.

For example, to make a branded card payment you have not one, but several middlemen, all of whom add cost to the overall price of the goods you buy;

1. Terminal Manufacturers – those devices you slide / swipe your card into are a cost, If they are PTS and SRED compliant, a significant cost. Target, for example, spent $100 MILLION to replace theirs after their well publicised breach.

2. Acquiring Banks – The bank who authorises the payment charges roughly 0.02% of the total value of each transaction.

3. Issuing Banks – The institution who issued the card itself charges the lion’s share at a very rough average of 1.7% of the transaction value.

4. Card Schemes – The brands (Visa, MasterCard etc.) vary in the slice they take, but for the sake of argument, let’s say it’s around 0.1% of the transaction value.

5. Your Bank (in general) – May or may not charge you for the ‘privilege’ of having a card, mine does, but let’s ignore this for now.

According to statista.com the volume of credit card transactions in  2012 was around $6,000,000,000,000 (or 6 TRILLION USD), so let’s put that into perspective:

Terminal Manufactures – I cannot even begin to guess how many payment terminals there are worldwide. But I’m going to put my reputation on the line and say it’s a lot. Manufacturers have also received a very significant boost in the last year or so with the enforcement of EMV on our US brethren. For the sake of this blog, we’ll just assume many millions are spent by retail merchants on these devices.

Acquiring Banks – 0.2% of $6 trillion is $12 billion.

Issuing Banks – 1.7% of $6 trillion is $105 billion.

Card Schemes – 0.1% of $6 trillion is $6 billion.

In other words, the cost associated of using credit cards exceeds 120 billion USD!

This is actually not meant as a criticism. They provide a service, many services in fact (including paying for the inevitable fraud), and we are all very likely utilising the benefits of the non-cash services on a daily basis. My point is that we ALREADY have the ability to remove the majority of these middlemen sitting in our pockets; our mobile phones.

Your bank wants to be paid for storing, protecting, and providing access to your worth. The phone company wants to be paid for providing the bandwidth to get to your worth. That’s fair, but why should anyone else be paid? It certainly isn’t the retail merchant who’s absorbing the middleman costs, it’s us, the end consumer. And it’s about time we start demanding more options.

The disintermediation of the non-cash payments systems will be a slow process of disruptive innovation. One side will try desperately to hold on to what they have, and the other side is trying to move too fast to change everything. BOTH sides need to understand that things WILL change, but can only do so when the replacement mechanisms are truly fit for purpose. We simply aren’t there yet.

Card Schemes need time to turn their enormous ships onto a new course; banks need to take over the fraud loss liabilities; and biometrics companies need to shut the hell up about the death of password and the ridiculousness of their single factor solutions. Most of all, the consumers need to ask for something they don’t even know they need yet.

So yes, disintermediation in payments is coming, but likely not any time soon. Even with PSD2.

[If you liked this article, please share! Want more like it, subscribe!]

This blog was written by  and the original article is here; http://www.acuityid.com/?p=336;

“Today’s payment behemoths are trying to desperately hold on to control of the payment processing infrastructure because they intuitively – if not consciously  – understand that the true  inevitable disruption of mobile payments is radical disintermediation i.e. total or near total annihilation existing, seemingly haphazard and completely archaic business models.

This is apparent in their schizophrenic attempts to simulatneiously fight new security standards for e and m-commerce while clinging to very regulations they love to rail against to limit new market entrants. It is apparent in the reports generated by highly paid consultants to strategize about how banks can hold onto, i.e. arm twist their customers, while generating new revenue streams, i.e. fees, to compensate for  archaic service models and lost payment opportunities. It is apparent in their acquisitions and attempts to present them selves as “market innovators” and “consumer service organizations”.

If mobile payments play out the way similarly disruptive technologies have in the past, the payments landscape of 2020 and beyond will look radially different then it does today. Some, if not all of today’s industry stalwarts, in spite of their best attempts to survive, will be greatly diminished, shadows of their former selves, if not simply ghosts. Meanwhile, a host of new players with radically different visions of how payments systems ought to work will rapidly grow into expansive financial legends with global footprints.

Sound far fetched? History tells us otherwise.  Have a read through a post from 2011  A Kodak Moment. Between 2000 and 2009, Kodak imploded.  The decade started well enough for Eastman Kodak. In 2000 it clocked film revenues of $11 billion, had 70,000 employees and 14 factories around the world. Then things started going pear shaped. Come 2009, revenues from the sale of film had fallen to $1.3 billion, the workforce had dropped to 20,000 and the number of factories had gone down to one.

Or consider Digital Equipment Corporate, AOL, Kmart, or sen your local travel agency — those of you under 35, may not even know what they are.  Technology-based innovation is both the bane and savior of market evolution indifferent to the fate of those impacted by rapid, sometimes catastrophic transformation. The notion that the today’s seemingly untouchable payment legends will remain intact after the coming decade of market transformation is quite simply naive. In 1989, I consulted for a company that employed 500 people to facilitate highly-targeted,  database managed, email marketing. By 2001, I purchased a software program online that had far greater functionality for $195.

The beauty of this type of imminent and inevitable market transformation is that no one really knows how it will play out. Not the pundits or the prognosticators. Certainly not the CEO’s of major financial institutions.  So while American Express touts their “transformative move to tokenization” (quotes mine for sarcastic emphasis)  or VISA digs their heels in against the European Commissions payment card reforms,  brave entrepreneurs will continue to introduce new payment means and mechanisms, and the rest of us will continue to dance and jockey for position until the initial fallout subsides and the re-visioned marketplace emerges.

Hold on to your hats, this is going to be a wild and crazy ride!”

Have you ever wondered what it would be like to go through life blind? Or with a learning disability? Or perhaps what it will be like when you’re older and your mental acuity is not what it once was?

What must it be like to be almost totally reliant on loved ones, or worse, the honesty and goodwill of complete strangers?

I readily admit, these are not thoughts that I have very often, as any disabilities I have relate to my sparkling personality. However, I am now in a position to HAVE to think about it and it’s more than a little humbling to see what those with physical or mental challenges have to go through.

For the purposes of this blog, I will restrict myself to issues related to non-cash payments, as that is my skill-set, the limit of knowledge on the subject of disabilities, and there is more than enough material to fill several blogs, lets alone this one.

The issues faced today centre on the fact that the only ubiquitous form of non-cash payment is the branded credit / debit card (Visa, Mastercard et al), and both the cards themselves and the infrastructure necessary to accept them is geared almost entirely to those without any sort of disability. In fact, even if you wanted to make changes to the infrastructure, the effort would be entirely prohibitive given both the limited return on investment and the absence of any legislation.

For example, according to Action for the Blind there are approximately 360,000 in the UK with ‘sight loss’ (total population ~64M), yet the number of people who can actually read braille is under 20,000. So even card terminals with braille overlays are more for marketing / image purposes than actually providing a means for expanding independence. Terminal manufacturers don’t have to spend more, so why would they?

According to Dr. John Gill, one of the UK’s leading experts in the field of disabilities, challenges for the disabled related to non-cash payments go way beyond issues with sight. The elderly, for example, not only begin to have challenges with vision, but their declining ability to handle abstract concepts, hand tremors and even an aversion to / fear of new technology means that payment innovations will be largely avoided by this group. Especially if their individual needs are not built in from the beginning.

I have posited in previous blogs that mobile devices are far better placed to enable cashless payment for those with disabilities, but it’s clear that this will only be the case if considerable thought is put into the challenges from the outset. ‘Consistency of Interface’ (Dr. Gill’s primary interest), simplification of available technologies, and setting of individual preferences across all payment front-ends will all be required before adoption of mobile technologies is available to everyone.

Well, almost everyone.

Too many technologies aimed at disabilities are nothing more than smoke-and-mirrors, and any effort on the part of manufacturers is aimed at demonstrating that they are good citizens. And while there can and will never be 100% adoption of mobile technology, it represents a significant advance over current systems which are now in their 6th decade of use.

Payment systems for those with disabilities must be able to address the following or they will simply not be used:

  1. Consistency of Interface – Terminal manufactures have some standards they need to apply to their devices, but constancy of interface is not one of them. Even as a sighted person, I sometimes have an issue with where to put my card, where the OK button is, how to apply tip (or not) and so on. However, I CAN read the total, what are the options for those who can’t?
    o
  2. Swiss Army Knife Approach – I love technology and innovation, yet even I use a fraction of the abilities of my phone. The elderly not only use even less, they want to SEE less available. The drive is for more and more functionality, but no-where is there an option for less, and until there is, adoption in the elderly will be limited.
    o
  3. Non Reliance on Biometrics – You just have to look at payment innovation and see that biometrics will be a major factor. This ridiculous concept from MasterCard for example; MasterCard, Zwipe announce fingerprint-sensor card. But what about those with deformities, injuries, mobility issues? Apparently people who work with concrete or pineapples have fingerprint issues, as do those on various forms of chemotherapy. Who knew?
    o
  4. Size of Keypad – Something as simple as this can result in the avoidance of non-cash payments. Combine a small PIN pad with low contrast fonts and you have just lost a payment.
    o
  5. Learning Disorders / Mental Acuity Challenges – How do current payment technologies handle dyslexia? Or short-term memory loss? Or the onset of dementia? The use of the PIN is about as ubiquitous as the cards they authenticate, yet even this is out of reach for some. But who says the ‘PIN’ has to be numbers, can’t it just as easily be a picture of loved ones, or some other individual preference?

Clearly I am only scratching the surface here, and while there is no solution that will ever make everyone happy, there is a LOT more that can be done to make life easier for those with disabilities. Mobile devices are not perfect, but they represent a  considerable advantage over current payment technologies in terms of adapting preferences to an individual.

All we need is the attention this deserves.

 

[Note: A very special thank you to Dr. John Gill who was very generous with his time and his guidance. Please see http://www.johngilltech.com for more on this subject.]

I have written quite a few blogs on GDPR and data discovery, but it’s not about regulations, it’s about securing the only thing that really matters to an organisation; its data.

My premise stems from the fact that there is no such thing as 100% secure. That with the right motivation, skill, and time, a bad guy will get in. Anywhere. The criminals in question spend a significant amount of effort mapping the target systems to eventually find the weak spot(s), and because the environment rarely changes, their end goal is always achievable.

The analogy used most often in security is one of a castle. You build up many layers of defence (thick walls, moat, arrow-slits, battlements etc.) and your most precious possessions are held in the most secure room in the centre of it. However, because that castle can only change very slowly, a concerted attack will eventually result in the loss of the ‘crown jewels’.

All it takes is time.

However, all of these defences are really just a means to an end, it’s the data itself that’s the only thing that matters. The real problem therefore lies not so much in the systems, but their predictability. Spending money and resources on more and more ways to protect the systems is just building higher walls. Eventually you have to stop, and eventually someone is going to break them down. And to take the analogy one stage further, the higher the walls, the more fragile they become (see Insecurity Through Technology).

So what can we do when the rising interest in privacy, and the ongoing train-wreck that is PCI, is causing a tidal wave of new products and services all claiming to be the missing link in your security program? Oddly enough (given my dislike of buzz-phrases), the only one that makes sense in the context of this blog is Cloud-based services, where scalability, redundancy and resilience are generally built into the platform from the beginning. A system goes down and you bring a new one back up. Instantly.

But how about taking this one stage further? Don’t just replace when something breaks, instead change as a matter of course! From firewall functionality, to ‘servers’, to encryption, even as far as location, change something in your environment to negate as much of the reconnaissance as possible. For every benefit of this, there will likely be at least one, or even several reasons to keep things the same, but the benefits are extensive:

  1. Security – The entire premise of this blog; if you change things frequently, bad-guys are less able to keep up and the rewards become less and less worth the effort. Back to building your fence higher than your neighbour;
    o
  2. Simplicity – To even think about replacing a system outside of a disaster recovery scenario, everything you do has to be simple. There is no security without simplicity;
    o
  3. Business Transformation / Competitive Advantage – I contend that in terms of competitive advantage in the Information Age, any head start will be closed in a matter of weeks / months, not years / decades. Any organisation that has the capability to quickly change aspects of their environment clearly has a thorough understanding of their business processes. Understanding is knowledge, the correct application of knowledge is wisdom, or in this case; appropriate transformation;
    o
  4. Business Continuity – Most organisations have distinct gaps between their continuity needs, and their ability to meet them. Even if Incident Response and Disaster Recovery processes are tested annually, only an organisation that makes significant changes frequently has the well-honed skill-set to meet or exceed the continuity plan goals. Practice, in this case, can indeed make perfect. Perfect enough anyway;
    o
  5. Innovation – Only from simple and well-known can innovation be truly effective. When you’re not worrying about how to keep things running and can focus on what else you could be doing with what you have, you are free to be either more creative, or recover quicker from your mistakes. Too often the inability to adjust begets the fear to even try.

As I stated previously, there are probably more reasons that this theory is completely unsustainable than there are apparent benefits, but I don’t think that means it’s not worth a try. Humans tend to overcomplicate things and then get lost in the detail, but with simplicity comes the freedom to focus on what really matters; the data from which all of your knowledge springs.

[If you liked this article, please share! Want more like it, subscribe!]

In a recent post (Digital Anarchy? Not Without Identity Management) I posited that eventually Identity Management would consist of a construct of your entire life. From the beginning, all the way through your to your present day, and continuing without pause until the end. The premise is that the more that is known about you, the harder it becomes to pretend to be you. Most fraud mechanisms work on making value judgements related to ‘normal’ behaviour, so why don’t we help that process along?

Privacy and profiling issues aside of course! 🙂

So it occurred to me that if all potential employers knew exactly what I believed in, and – assuming they agreed with me – how I could provide benefit to their organisation, then a CV is almost unnecessary.

LinkedIn already provides the factual information about my previous employment, and as much detail regarding my functions / achievements as I deem fit to share. Employers can do a background check based on my online presence long before approaching me directly. So add a blog on top of that, and what else could they possibly need to make a decision regarding next steps?

References? Background Investigations? Yes, but these are final steps, as the only purpose a CV serves is to get you that first interview. As such, it is VERY hit and miss, and a shining gem of a CV to one HR pro is a not-so-polished turd to another. In the end, HR are not even your final audience, but every candidate is expected to know all about writing CVs and cover letters, as well as interview techniques and etiquette. All you end up doing is filtering out the worst candidates, not narrowing down the best.

A blog, on the other hand, shows many things, all of which have good and bad elements depending on your point of view:

  1. Communication Skills – Writing is not easy, and even doing an average job of it takes a level of skill. If you cannot get your point across in 500 – 1000 words, AND in a way that the majority can understand, you either need to work on your writing skills, your knowledge of the subject, or both.
    o
  2. Subject Matter Expertise – Blogs on specific subjects should be written by people who have relatively significant experience in their chosen profession. But that does not mean they are alway right. A blog from a ‘security expert’ with whom I vehemently disagree will be dismissed just as quickly as would a blog on intelligent design.
    0
  3. Desire to Help – While my blog [for example] was initially started because my wife told me to, it soon became an integral part of my weekly tasking. The skill-set I have (such as it is) does no good to anyone until everyone can follow the guidance I am trying to impart. Security expertise [for example] is NOT something that should be used just as a competitive advantage. There is plenty of opportunity to make a living while giving as much as you can back.
    o
  4. Thought Leadership …Or Not – One of the fastest growing buzz-phrases / clichés, but the concept is sound; Are you a person who creates the new, improves the old, or sustains the present? All of these things have their place, any one of them is not necessarily better than the others, but you need to know which you are, and so do your potential employers.
    o
  5. Skin In The Game – A phrase I’m borrowing from our American friends, it means that you are actually taking part in something, and not just sitting on the sidelines watching. Good if you’re contributing positively, bad if you’re an idiot.

Anything that fights against “But we’ve always done it this way!” is to me a good thing, and that’s where a blog really comes into its own. All of your ideas, concepts, or even random thoughts need to be put down into words that others can follow, which mean YOU have to clarify them first. Ideas catch on, but only the ideas that see the light of day.

For good or bad my blog is now my CV, let’s see how it pans out! 🙂

[If you liked this article, please share! Want more like it, subscribe!]