Demand generation is defined as; “The focus of targeted marketing programs to drive awareness and interest in a company’s products and/or services.”

Done responsibly it can be a very effective tool in any organisation’s marketing/PR tool-set, and I applaud anyone doing it well. Done irresponsibly it can lead target organisations to make very poor decisions that they will end up bitterly regretting. Yes, each organisation is responsible for making their choices, and for performing proper due diligence, but in an industry as complex as payments, vendors are often seen as the experts.

This position must NEVER be abused!

The example of demand generation that I invariably use is that of the smartphone. Until I saw one I had no idea I needed so much functionality in a mobile device. Now, quite literally, I cannot do my job without it.

Off the bat, that suggests 3 things:

  1. Smartphone manufacturers were justified in their aggressive marketing efforts …eventually;
  2. The drive by each vendor to win the entire market for themselves, while promoting competition, has left us with an enormous variety of devices and technologies that are difficult to adopt for fear of backing the wrong horse, and;
  3. I’m not smart enough to be a futurist.

But what if they had worked together on standardisation in the beginning (like with bloody power adapters for example!), how much better off would we be?!

Now biometrics vendors are the vultures over the kill, and the password is the corpse (harsh I know, but the alternative is wolves, but they work in unison for the good of the pack).

Biometrics companies are spending vast sums on marketing and PR resources to become the next big thing in authentication, All the while completely ignoring the fact that they are offering something little different (single-factor, static authentication), and side-stepping the most basic of practicalities; ease of adoption, and future-proofing.

The FACT remains that implementation of effective biometrics is extremely difficult. Distribution, false positive rates, disability support, privacy issues and a plethora of other challenges will continue to ensure that single-factor authentication with biometrics will not replace the 4 digit cardholder PIN any time soon. Nor should it.

It’s not about replacing the PIN, it’s about seamlessly combining the PIN with other forms / factors of authentication like biometrics. Anything else is irresponsible in the extreme given that most smart phones are capable of all 3 authentication factors multiple times each! Passphrase, PIN, fingerprint, voice recognition, iris, geo-fencing, device registration, device profiling, social media profiling you name it, can all be entered into a mobile device through normal and already established consumer use.

The following is not necessarily an endorsement of Fast Identity Online (FIDO) Alliance, but you can see from their Mission that they fully appreciated the importance of evolutionary change, not revolutionary change:

“The Mission of the FIDO Alliance is to change the nature of online authentication by:

  • Developing technical specifications that define an open, scalable, interoperable set of mechanisms that reduce the reliance on passwords to authenticate users.
  • Operating industry programs to help ensure successful worldwide adoption of the Specifications.
  • Submitting mature technical Specification(s) to recognized standards development organization(s) for formal standardization.”

Reliance on single factor authentication with biometrics is a mistake, so avoid any organisation who adopts the ‘password is dead’ stance and just do your homework based on a business need, not a buzz-phrase.

An almost 50 year old concept is now all the rage in the payments space; disintermediation, which according to Wikipedia is; “…the removal of intermediaries in a supply chain, or “cutting out the middlemen.

It might be a cliché, and I hate any buzz-phrase not invented by me, but in the payments space this one makes perfect sense.

For example, to make a branded card payment you have not one, but several middlemen, all of whom add cost to the overall price of the goods you buy;

1. Terminal Manufacturers – those devices you slide / swipe your card into are a cost, If they are PTS and SRED compliant, a significant cost. Target, for example, spent $100 MILLION to replace theirs after their well publicised breach.

2. Acquiring Banks – The bank who authorises the payment charges roughly 0.02% of the total value of each transaction.

3. Issuing Banks – The institution who issued the card itself charges the lion’s share at a very rough average of 1.7% of the transaction value.

4. Card Schemes – The brands (Visa, MasterCard etc.) vary in the slice they take, but for the sake of argument, let’s say it’s around 0.1% of the transaction value.

5. Your Bank (in general) – May or may not charge you for the ‘privilege’ of having a card, mine does, but let’s ignore this for now.

According to statista.com the volume of credit card transactions in  2012 was around $6,000,000,000,000 (or 6 TRILLION USD), so let’s put that into perspective:

Terminal Manufactures – I cannot even begin to guess how many payment terminals there are worldwide. But I’m going to put my reputation on the line and say it’s a lot. Manufacturers have also received a very significant boost in the last year or so with the enforcement of EMV on our US brethren. For the sake of this blog, we’ll just assume many millions are spent by retail merchants on these devices.

Acquiring Banks – 0.2% of $6 trillion is $12 billion.

Issuing Banks – 1.7% of $6 trillion is $105 billion.

Card Schemes – 0.1% of $6 trillion is $6 billion.

In other words, the cost associated of using credit cards exceeds 120 billion USD!

This is actually not meant as a criticism. They provide a service, many services in fact (including paying for the inevitable fraud), and we are all very likely utilising the benefits of the non-cash services on a daily basis. My point is that we ALREADY have the ability to remove the majority of these middlemen sitting in our pockets; our mobile phones.

Your bank wants to be paid for storing, protecting, and providing access to your worth. The phone company wants to be paid for providing the bandwidth to get to your worth. That’s fair, but why should anyone else be paid? It certainly isn’t the retail merchant who’s absorbing the middleman costs, it’s us, the end consumer. And it’s about time we start demanding more options.

The disintermediation of the non-cash payments systems will be a slow process of disruptive innovation. One side will try desperately to hold on to what they have, and the other side is trying to move too fast to change everything. BOTH sides need to understand that things WILL change, but can only do so when the replacement mechanisms are truly fit for purpose. We simply aren’t there yet.

Card Schemes need time to turn their enormous ships onto a new course; banks need to take over the fraud loss liabilities; and biometrics companies need to shut the hell up about the death of password and the ridiculousness of their single factor solutions. Most of all, the consumers need to ask for something they don’t even know they need yet.

So yes, disintermediation in payments is coming, but likely not any time soon. Even with PSD2.

[If you liked this article, please share! Want more like it, subscribe!]

This blog was written by  and the original article is here; http://www.acuityid.com/?p=336;

“Today’s payment behemoths are trying to desperately hold on to control of the payment processing infrastructure because they intuitively – if not consciously  – understand that the true  inevitable disruption of mobile payments is radical disintermediation i.e. total or near total annihilation existing, seemingly haphazard and completely archaic business models.

This is apparent in their schizophrenic attempts to simulatneiously fight new security standards for e and m-commerce while clinging to very regulations they love to rail against to limit new market entrants. It is apparent in the reports generated by highly paid consultants to strategize about how banks can hold onto, i.e. arm twist their customers, while generating new revenue streams, i.e. fees, to compensate for  archaic service models and lost payment opportunities. It is apparent in their acquisitions and attempts to present them selves as “market innovators” and “consumer service organizations”.

If mobile payments play out the way similarly disruptive technologies have in the past, the payments landscape of 2020 and beyond will look radially different then it does today. Some, if not all of today’s industry stalwarts, in spite of their best attempts to survive, will be greatly diminished, shadows of their former selves, if not simply ghosts. Meanwhile, a host of new players with radically different visions of how payments systems ought to work will rapidly grow into expansive financial legends with global footprints.

Sound far fetched? History tells us otherwise.  Have a read through a post from 2011  A Kodak Moment. Between 2000 and 2009, Kodak imploded.  The decade started well enough for Eastman Kodak. In 2000 it clocked film revenues of $11 billion, had 70,000 employees and 14 factories around the world. Then things started going pear shaped. Come 2009, revenues from the sale of film had fallen to $1.3 billion, the workforce had dropped to 20,000 and the number of factories had gone down to one.

Or consider Digital Equipment Corporate, AOL, Kmart, or sen your local travel agency — those of you under 35, may not even know what they are.  Technology-based innovation is both the bane and savior of market evolution indifferent to the fate of those impacted by rapid, sometimes catastrophic transformation. The notion that the today’s seemingly untouchable payment legends will remain intact after the coming decade of market transformation is quite simply naive. In 1989, I consulted for a company that employed 500 people to facilitate highly-targeted,  database managed, email marketing. By 2001, I purchased a software program online that had far greater functionality for $195.

The beauty of this type of imminent and inevitable market transformation is that no one really knows how it will play out. Not the pundits or the prognosticators. Certainly not the CEO’s of major financial institutions.  So while American Express touts their “transformative move to tokenization” (quotes mine for sarcastic emphasis)  or VISA digs their heels in against the European Commissions payment card reforms,  brave entrepreneurs will continue to introduce new payment means and mechanisms, and the rest of us will continue to dance and jockey for position until the initial fallout subsides and the re-visioned marketplace emerges.

Hold on to your hats, this is going to be a wild and crazy ride!”

Have you ever wondered what it would be like to go through life blind? Or with a learning disability? Or perhaps what it will be like when you’re older and your mental acuity is not what it once was?

What must it be like to be almost totally reliant on loved ones, or worse, the honesty and goodwill of complete strangers?

I readily admit, these are not thoughts that I have very often, as any disabilities I have relate to my sparkling personality. However, I am now in a position to HAVE to think about it and it’s more than a little humbling to see what those with physical or mental challenges have to go through.

For the purposes of this blog, I will restrict myself to issues related to non-cash payments, as that is my skill-set, the limit of knowledge on the subject of disabilities, and there is more than enough material to fill several blogs, lets alone this one.

The issues faced today centre on the fact that the only ubiquitous form of non-cash payment is the branded credit / debit card (Visa, Mastercard et al), and both the cards themselves and the infrastructure necessary to accept them is geared almost entirely to those without any sort of disability. In fact, even if you wanted to make changes to the infrastructure, the effort would be entirely prohibitive given both the limited return on investment and the absence of any legislation.

For example, according to Action for the Blind there are approximately 360,000 in the UK with ‘sight loss’ (total population ~64M), yet the number of people who can actually read braille is under 20,000. So even card terminals with braille overlays are more for marketing / image purposes than actually providing a means for expanding independence. Terminal manufacturers don’t have to spend more, so why would they?

According to Dr. John Gill, one of the UK’s leading experts in the field of disabilities, challenges for the disabled related to non-cash payments go way beyond issues with sight. The elderly, for example, not only begin to have challenges with vision, but their declining ability to handle abstract concepts, hand tremors and even an aversion to / fear of new technology means that payment innovations will be largely avoided by this group. Especially if their individual needs are not built in from the beginning.

I have posited in previous blogs that mobile devices are far better placed to enable cashless payment for those with disabilities, but it’s clear that this will only be the case if considerable thought is put into the challenges from the outset. ‘Consistency of Interface’ (Dr. Gill’s primary interest), simplification of available technologies, and setting of individual preferences across all payment front-ends will all be required before adoption of mobile technologies is available to everyone.

Well, almost everyone.

Too many technologies aimed at disabilities are nothing more than smoke-and-mirrors, and any effort on the part of manufacturers is aimed at demonstrating that they are good citizens. And while there can and will never be 100% adoption of mobile technology, it represents a significant advance over current systems which are now in their 6th decade of use.

Payment systems for those with disabilities must be able to address the following or they will simply not be used:

  1. Consistency of Interface – Terminal manufactures have some standards they need to apply to their devices, but constancy of interface is not one of them. Even as a sighted person, I sometimes have an issue with where to put my card, where the OK button is, how to apply tip (or not) and so on. However, I CAN read the total, what are the options for those who can’t?
    o
  2. Swiss Army Knife Approach – I love technology and innovation, yet even I use a fraction of the abilities of my phone. The elderly not only use even less, they want to SEE less available. The drive is for more and more functionality, but no-where is there an option for less, and until there is, adoption in the elderly will be limited.
    o
  3. Non Reliance on Biometrics – You just have to look at payment innovation and see that biometrics will be a major factor. This ridiculous concept from MasterCard for example; MasterCard, Zwipe announce fingerprint-sensor card. But what about those with deformities, injuries, mobility issues? Apparently people who work with concrete or pineapples have fingerprint issues, as do those on various forms of chemotherapy. Who knew?
    o
  4. Size of Keypad – Something as simple as this can result in the avoidance of non-cash payments. Combine a small PIN pad with low contrast fonts and you have just lost a payment.
    o
  5. Learning Disorders / Mental Acuity Challenges – How do current payment technologies handle dyslexia? Or short-term memory loss? Or the onset of dementia? The use of the PIN is about as ubiquitous as the cards they authenticate, yet even this is out of reach for some. But who says the ‘PIN’ has to be numbers, can’t it just as easily be a picture of loved ones, or some other individual preference?

Clearly I am only scratching the surface here, and while there is no solution that will ever make everyone happy, there is a LOT more that can be done to make life easier for those with disabilities. Mobile devices are not perfect, but they represent a  considerable advantage over current payment technologies in terms of adapting preferences to an individual.

All we need is the attention this deserves.

 

[Note: A very special thank you to Dr. John Gill who was very generous with his time and his guidance. Please see http://www.johngilltech.com for more on this subject.]

[Ed: I am very pleased to present a guest blog for a good friend of mine. He and I have spent more time in the PCI trenches than we would either care to admit;]

“I read your blog somewhat religiously and I find myself thinking about my feelings towards PCI both from an assessor and client perspective and moreover as a security professional.

With breaches now on the rise, it is time to reflect a bit on how did we get here? Why are things this way? Is PCI working?

We got here because of money. The all mighty dollar (pick your currency). Greed, my friends, has fueled this issue, and for years and will continue to do so.

Greed by the card brands has pushed them to promote acceptance so wide that the only way anyone even thinks about non-ash payments is with a card. This push for acceptance came in the early 1990’s and continues today. At that time, very little was thought of PCI other than a little fine print that was quietly overlooked until breaches began to result from this push.

At that point, the card brands felt that the public – being sufficiently hooked on the drug of convenience – was finally ready for enforcement of compliance with standards. Shortly thereafter the PCI SSC was born, and the real greed and corruption was to begin.

Below are a few points that have been smoldering quietly in the back of my head that are now demanding to be shared.

  1. Unless it’s my core business, it will never be my core competency. You cannot make merchants into military. They won’t go, they never will, stop trying to make them. Realize this now and move on.
    o
  2. The card brands have created the problem by pushing their acceptance channels as hard as they have, and then attempted to throw security on top of the pile long after the fact. Security first, acceptance of cards later.
    o
  3. The card brands added insult to injury by creating the PCI SSC. This is a self serving group that dictates a set of documents and charging fees, then completely and utterly fails to enforce its own assessor quality assurance program.
    o
  4. The SSC has, through their actions and inaction, contributed to the creation of a scandalously corrupt cottage industry of PCI QSACs. These companies are selling assessor services for a flat fee and assigning work at a rate of 35 to 45 PCI assessments a year per QSA. This volume is horrific and does not serve the client, or the card brands. The delivery of an appropriate assessment is simply not possible. You can have two of the three, “cheep”, “fast” and “good” but only two. Cheep and fast does not make for good, yet the SSC has allowed the QSAC’s to promote and aggressively sell just that.
    o
  5. The SSC has allowed the same QSAC and QSA to assess the same environments year after year creating complacency and further corruption. If you care about compliance, rotate assessors. Assessors make bad calls, and in order to maintain the client, must live with them year after year. Fresh eyes are critical to maintaining integrity.
    o
  6. The card brands have failed to adopt more secure methods of moving funds. The clear text account number adhered to the back of a piece of plastic via technology rivals that of the 8 Track player in my mother’s 1976 Mercury Cougar. This is criminal.

I could go on and on, but the key points remains the same, the card brands are the cause of the problem, and have made it worse by setting up an unrealistic security program rather than focus on their own flawed methods.

The reality is this; PCI is a way to shift the burden of securing the otherwise insecure from the card brands to the merchants, banks and service providers. God forbid the card brands pick up the tab??

As long as I am ranting, how is it that Moore’s Law drives down the cost of all technology except when it comes to transaction processing?

Will my rant change anything? No, but I do feel a bit better sharing with you all.

Regards,

Frustrated Assessor”