This blog was written by  and the original article is here; http://www.acuityid.com/?p=336;

“Today’s payment behemoths are trying to desperately hold on to control of the payment processing infrastructure because they intuitively – if not consciously  – understand that the true  inevitable disruption of mobile payments is radical disintermediation i.e. total or near total annihilation existing, seemingly haphazard and completely archaic business models.

This is apparent in their schizophrenic attempts to simulatneiously fight new security standards for e and m-commerce while clinging to very regulations they love to rail against to limit new market entrants. It is apparent in the reports generated by highly paid consultants to strategize about how banks can hold onto, i.e. arm twist their customers, while generating new revenue streams, i.e. fees, to compensate for  archaic service models and lost payment opportunities. It is apparent in their acquisitions and attempts to present them selves as “market innovators” and “consumer service organizations”.

If mobile payments play out the way similarly disruptive technologies have in the past, the payments landscape of 2020 and beyond will look radially different then it does today. Some, if not all of today’s industry stalwarts, in spite of their best attempts to survive, will be greatly diminished, shadows of their former selves, if not simply ghosts. Meanwhile, a host of new players with radically different visions of how payments systems ought to work will rapidly grow into expansive financial legends with global footprints.

Sound far fetched? History tells us otherwise.  Have a read through a post from 2011  A Kodak Moment. Between 2000 and 2009, Kodak imploded.  The decade started well enough for Eastman Kodak. In 2000 it clocked film revenues of $11 billion, had 70,000 employees and 14 factories around the world. Then things started going pear shaped. Come 2009, revenues from the sale of film had fallen to $1.3 billion, the workforce had dropped to 20,000 and the number of factories had gone down to one.

Or consider Digital Equipment Corporate, AOL, Kmart, or sen your local travel agency — those of you under 35, may not even know what they are.  Technology-based innovation is both the bane and savior of market evolution indifferent to the fate of those impacted by rapid, sometimes catastrophic transformation. The notion that the today’s seemingly untouchable payment legends will remain intact after the coming decade of market transformation is quite simply naive. In 1989, I consulted for a company that employed 500 people to facilitate highly-targeted,  database managed, email marketing. By 2001, I purchased a software program online that had far greater functionality for $195.

The beauty of this type of imminent and inevitable market transformation is that no one really knows how it will play out. Not the pundits or the prognosticators. Certainly not the CEO’s of major financial institutions.  So while American Express touts their “transformative move to tokenization” (quotes mine for sarcastic emphasis)  or VISA digs their heels in against the European Commissions payment card reforms,  brave entrepreneurs will continue to introduce new payment means and mechanisms, and the rest of us will continue to dance and jockey for position until the initial fallout subsides and the re-visioned marketplace emerges.

Hold on to your hats, this is going to be a wild and crazy ride!”

Have you ever wondered what it would be like to go through life blind? Or with a learning disability? Or perhaps what it will be like when you’re older and your mental acuity is not what it once was?

What must it be like to be almost totally reliant on loved ones, or worse, the honesty and goodwill of complete strangers?

I readily admit, these are not thoughts that I have very often, as any disabilities I have relate to my sparkling personality. However, I am now in a position to HAVE to think about it and it’s more than a little humbling to see what those with physical or mental challenges have to go through.

For the purposes of this blog, I will restrict myself to issues related to non-cash payments, as that is my skill-set, the limit of knowledge on the subject of disabilities, and there is more than enough material to fill several blogs, lets alone this one.

The issues faced today centre on the fact that the only ubiquitous form of non-cash payment is the branded credit / debit card (Visa, Mastercard et al), and both the cards themselves and the infrastructure necessary to accept them is geared almost entirely to those without any sort of disability. In fact, even if you wanted to make changes to the infrastructure, the effort would be entirely prohibitive given both the limited return on investment and the absence of any legislation.

For example, according to Action for the Blind there are approximately 360,000 in the UK with ‘sight loss’ (total population ~64M), yet the number of people who can actually read braille is under 20,000. So even card terminals with braille overlays are more for marketing / image purposes than actually providing a means for expanding independence. Terminal manufacturers don’t have to spend more, so why would they?

According to Dr. John Gill, one of the UK’s leading experts in the field of disabilities, challenges for the disabled related to non-cash payments go way beyond issues with sight. The elderly, for example, not only begin to have challenges with vision, but their declining ability to handle abstract concepts, hand tremors and even an aversion to / fear of new technology means that payment innovations will be largely avoided by this group. Especially if their individual needs are not built in from the beginning.

I have posited in previous blogs that mobile devices are far better placed to enable cashless payment for those with disabilities, but it’s clear that this will only be the case if considerable thought is put into the challenges from the outset. ‘Consistency of Interface’ (Dr. Gill’s primary interest), simplification of available technologies, and setting of individual preferences across all payment front-ends will all be required before adoption of mobile technologies is available to everyone.

Well, almost everyone.

Too many technologies aimed at disabilities are nothing more than smoke-and-mirrors, and any effort on the part of manufacturers is aimed at demonstrating that they are good citizens. And while there can and will never be 100% adoption of mobile technology, it represents a significant advance over current systems which are now in their 6th decade of use.

Payment systems for those with disabilities must be able to address the following or they will simply not be used:

  1. Consistency of Interface – Terminal manufactures have some standards they need to apply to their devices, but constancy of interface is not one of them. Even as a sighted person, I sometimes have an issue with where to put my card, where the OK button is, how to apply tip (or not) and so on. However, I CAN read the total, what are the options for those who can’t?
    o
  2. Swiss Army Knife Approach – I love technology and innovation, yet even I use a fraction of the abilities of my phone. The elderly not only use even less, they want to SEE less available. The drive is for more and more functionality, but no-where is there an option for less, and until there is, adoption in the elderly will be limited.
    o
  3. Non Reliance on Biometrics – You just have to look at payment innovation and see that biometrics will be a major factor. This ridiculous concept from MasterCard for example; MasterCard, Zwipe announce fingerprint-sensor card. But what about those with deformities, injuries, mobility issues? Apparently people who work with concrete or pineapples have fingerprint issues, as do those on various forms of chemotherapy. Who knew?
    o
  4. Size of Keypad – Something as simple as this can result in the avoidance of non-cash payments. Combine a small PIN pad with low contrast fonts and you have just lost a payment.
    o
  5. Learning Disorders / Mental Acuity Challenges – How do current payment technologies handle dyslexia? Or short-term memory loss? Or the onset of dementia? The use of the PIN is about as ubiquitous as the cards they authenticate, yet even this is out of reach for some. But who says the ‘PIN’ has to be numbers, can’t it just as easily be a picture of loved ones, or some other individual preference?

Clearly I am only scratching the surface here, and while there is no solution that will ever make everyone happy, there is a LOT more that can be done to make life easier for those with disabilities. Mobile devices are not perfect, but they represent a  considerable advantage over current payment technologies in terms of adapting preferences to an individual.

All we need is the attention this deserves.

 

[Note: A very special thank you to Dr. John Gill who was very generous with his time and his guidance. Please see http://www.johngilltech.com for more on this subject.]

I have written quite a few blogs on GDPR and data discovery, but it’s not about regulations, it’s about securing the only thing that really matters to an organisation; its data.

My premise stems from the fact that there is no such thing as 100% secure. That with the right motivation, skill, and time, a bad guy will get in. Anywhere. The criminals in question spend a significant amount of effort mapping the target systems to eventually find the weak spot(s), and because the environment rarely changes, their end goal is always achievable.

The analogy used most often in security is one of a castle. You build up many layers of defence (thick walls, moat, arrow-slits, battlements etc.) and your most precious possessions are held in the most secure room in the centre of it. However, because that castle can only change very slowly, a concerted attack will eventually result in the loss of the ‘crown jewels’.

All it takes is time.

However, all of these defences are really just a means to an end, it’s the data itself that’s the only thing that matters. The real problem therefore lies not so much in the systems, but their predictability. Spending money and resources on more and more ways to protect the systems is just building higher walls. Eventually you have to stop, and eventually someone is going to break them down. And to take the analogy one stage further, the higher the walls, the more fragile they become (see Insecurity Through Technology).

So what can we do when the rising interest in privacy, and the ongoing train-wreck that is PCI, is causing a tidal wave of new products and services all claiming to be the missing link in your security program? Oddly enough (given my dislike of buzz-phrases), the only one that makes sense in the context of this blog is Cloud-based services, where scalability, redundancy and resilience are generally built into the platform from the beginning. A system goes down and you bring a new one back up. Instantly.

But how about taking this one stage further? Don’t just replace when something breaks, instead change as a matter of course! From firewall functionality, to ‘servers’, to encryption, even as far as location, change something in your environment to negate as much of the reconnaissance as possible. For every benefit of this, there will likely be at least one, or even several reasons to keep things the same, but the benefits are extensive:

  1. Security – The entire premise of this blog; if you change things frequently, bad-guys are less able to keep up and the rewards become less and less worth the effort. Back to building your fence higher than your neighbour;
    o
  2. Simplicity – To even think about replacing a system outside of a disaster recovery scenario, everything you do has to be simple. There is no security without simplicity;
    o
  3. Business Transformation / Competitive Advantage – I contend that in terms of competitive advantage in the Information Age, any head start will be closed in a matter of weeks / months, not years / decades. Any organisation that has the capability to quickly change aspects of their environment clearly has a thorough understanding of their business processes. Understanding is knowledge, the correct application of knowledge is wisdom, or in this case; appropriate transformation;
    o
  4. Business Continuity – Most organisations have distinct gaps between their continuity needs, and their ability to meet them. Even if Incident Response and Disaster Recovery processes are tested annually, only an organisation that makes significant changes frequently has the well-honed skill-set to meet or exceed the continuity plan goals. Practice, in this case, can indeed make perfect. Perfect enough anyway;
    o
  5. Innovation – Only from simple and well-known can innovation be truly effective. When you’re not worrying about how to keep things running and can focus on what else you could be doing with what you have, you are free to be either more creative, or recover quicker from your mistakes. Too often the inability to adjust begets the fear to even try.

As I stated previously, there are probably more reasons that this theory is completely unsustainable than there are apparent benefits, but I don’t think that means it’s not worth a try. Humans tend to overcomplicate things and then get lost in the detail, but with simplicity comes the freedom to focus on what really matters; the data from which all of your knowledge springs.

[If you liked this article, please share! Want more like it, subscribe!]

So Apple have finally adopted NFC, huh?  Big deal, Samsung have partnered with Visa and MasterCard to promote NFC for over a year, and included NFC chips in their devices long before that.

Apple’s wallet provides you options to choose which credit card you want to use. CREDIT CARD?! REALLY?! How is that innovation in payments?! The whole point of mobile payments is that you don’t need a branded card to make a payment, at least it should be the point!

Payments has been, and will always be, just an exchange of stored value for a service or product whose value is, in turn, entirely arbitrary. e.g. I work for an entire week for a value I have agreed with my employer, and I am now going to buy a designer suit for the same ‘price’. The fact that the suit was made for a fraction of the ‘cost’ I paid for it is why its value is arbitrary; because regardless of the price, I agreed to it.

So what have Apple done differently? You can now authenticate the payment with your fingerprint. Seriously? People barely trust the fingerprint to log into their phones, let alone authenticate a payment. And seeing as the value of the contactless transaction is set below £20 (for the UK) and authentication is not required at ALL, why would you add an extra step?

I can tell you now that the credit card brands will not accept biometrics any time soon to replace EMV for higher transaction values when even software PIN (as opposed to hardware) is still rejected. Couple the fact that Apple’s global market share for phones is less than 12%, with the US being their only viable new market (who love their credit cards), and you have a completely empty offering.

But, you may say, Apple has 800 million iTunes users! Irrelevant, because there are nowhere near 800 million iPhones in use. From their initial inception way back in 2007, Apple sold their 500 millionth iPhones in June 2014. That’s total sales, all models, in seven years. Estimates suggest that there are less than 300 million in use globally, compared to a total of 1.75 billion smartphones.

On top of Apple’s minimal – and shrinking – market share, the transition of credit card payments to direct bank account payments through a mobile device has, through necessity, started small. Security is absolutely an issue, which is why the back-end wallets generally consist of credit cards, which handle the fraud / loss liability. With your bank account, it’s YOUR money, and the banks have yet to accept the liability for loss though mobile apps. When they do, the card brands will have no benefit and the transition to mobile will accelerate.

So why DON’T the banks provide this function themselves? Because they make money from credit cards, plain and simple, and it will be a tough sell to charge the fees they do now when accessing your own funds, even if they do provide a ‘fraud resistant’ service. Besides, the money from credit cards is not from the cards themselves, it’s on the interest you pay for your LINE of credit, so the poor banks can still make their squillions. That’s a relief.

Besides, people take their phones for granted, just as they do water coming out of the tap (I know, 1st world problems), and people simply do not see the issue with continuing to use plastic, so how will the mass adoption of mobile payments really take off? Simple; value-add services and guaranteed security.

Value-Add Services: Retailers are the only ones who can make this happen, not phone companies, not card brands, and certainly not the banks. For retailers to make the enormous investment required to change from a credit card infrastructure to mobile / hybrid there needs to be a clear positive effect on the bottom line. Unfortunately, with the ridiculous number of choices related to loyalty schemes, instant coupons, e-wallets and so on, no retailer knows which to back.

Guaranteed Security: The reason credit cards still eclipse mobile payments is because if you use a credit card you are not liable for fraud, the issuer is. The so-called liability shift. If you take out this middle-man, who accepts the risk? The retailers? The bank? The mobile app service providers? Someone has to, because you can be damned sure it won’t be the consumer.

Which brings us to only relevant thing to come out of Apple’s announcement; NFC is now the technology of choice. All we need now is the consolidation of every other service, someone to accept the inevitable losses, and mobile payments can come into its own.

Yeah. Right.

I don’t think anyone in the payments arena has any doubt that credit/debit cards, in their current form, will die over time in favour of mobile devices. It’s a natural next step to replace something ubiquitous with something even more ubiquitous.

So where does that leave the SSC, and the card schemes themselves for that matter?

You only have to look at Visa Europe’s website Visa Vision to see that they are moving towards mobile (and other innovations), and articles like The Revolution is Here, do not even mention EMV, and the only reference to plastic is in a future past-tense.

It also begs the question as to why the card schemes are pushing EMV when they themselves see an end to their reign-of-plastic. But the answer is obvious, the cost of fraud over the next 5 – 10 years far outweighs the cost of the transition. The US alone saw $7.1B in credit card fraud in 2013 (according to Business Insider), and I have estimated that the cost of EMV transition in the US is ‘only’ $12B (Why the US Will Not Adopt EMV (Chip & PIN), EMV in the US, a 12 BILLION Dollar Mistake).

So why am I so anti-EMV? Because there are technologies NOW that can replace it, are in more hands, and more widely distributed than cards ever were. Your mobile phones.

So back to my point; what WILL the cards brands and the SSC do once the plastic dies? Clearly the brands have an enormous leg-up on any new player in the cashless game, and have massive amounts of capital to invest in meeting every aspect of this [so-called] disruptive innovation; research on innovation, testing proofs-of-concept, garnering adoption within the finance community, and of course, rolling it out to end users.

Mobile phone companies made a small play, and missed, banks could have done it, and didn’t, and large retail could have had a huge impact, and haven’t. Probably because in these three case – even banks – payments is not a core function. Being PAID is core, making the payment is not, so only the card schemes have payments as their entire reason-to-be, and therefore the most motivation.

OK, so if we assume that the card schemes are going to make a huge play in every cashless payment innovation from this point forward, where does that leave the SSC? Probably in exactly the same place, with only one change in title; From Payment Card Industry Security Standards Council, to Payment Industry Security Standards Council.

Regardless of the form of payment there HAS to be a security standard around the protection of the data. Not that the current standards are anywhere near adequate, even for cardholder data, but the SSC has significant experience adopting and implementing standards globally. From mobile apps, to software PINs, to identity management (for KYC, AML etc.) to crypto-currencies, everyone developing technologies must adhere to a minimum set of protective baselines.

So am I really proposing, after so many less-than-positive blogs related to the PCI DSS and the SSC, that they be a standards body for every form of payment globally? Well, no, I’m not, but I think that if they don’t TRY to be just that (with the card brand’s backing), there is no-where else for them to go.

Despite my voluble criticisms of the card brands and the SSC alike, they ARE well placed to do good. I hope they take the opportunity now, because it won’t come again.

[If you liked this article, please share! Want more like it, subscribe!]