Why don't we all move to our seats so we can get started? I'm Craig Moore with Autonomous for those on the webcast. From Autonomous in the room is my team, Matt O'Neill, Rob Wildhack, and Ken Usdin. We're very lucky to have with us today, Mastercard's Johan Gerber, EVP of Security and Decision Products. As everybody knows, Mastercard Services Group has been a hot topic. Everybody wants to discuss it. It's seemingly a huge differentiator versus their main competition. To have someone from that side of the business is rare in a forum like this. Johan is 17 years in the industry. I believe you said Mastercard, you joined them through acquisition. For the benefit of the audience, why don't you tell us a little bit more about your background and role at Mastercard?
Great. Well, thank you. First of all, thank you very much for the opportunity to be here and to speak to all of the investors. I've been with the company for 17 years. I started out in our European subsidiary at the time called Europay International, which got acquired by Mastercard, I think it was 2003. Through that acquisition, eventually found myself into the current role, moving to the U.S., and now I run this group called Security and Decision Products for us.
Okay. FYI, I do want this to be conversational still, even though it is being webcast. If you do want to interject with a question, just put your hand up so Leslie can get you a mic. Thinking about, obviously, in the name of your role, fraud. How has Mastercard approached the discussion? Obviously, the Equifax breach has probably had you working overtime to figure out where your risk points are from that. If you can help us understand a little bit.
Sure. Let me say this, we don't view fraud necessarily as a topic on its own. We have this strategy of security by design. It's part of everything we do. It's part of our DNA. It's part of how we think when we develop new products, new services, new campaigns. If I can just take a quick step back, there are four main, I would say, topics, drivers, that's constantly helping us to define our strategy. First of all, there's this whole context of intelligent connectivity. The world is this ecosystem which is intelligently connected, what we call the digital ecosystem. It changed the way we live. It changed the way we interact with each other, how we consume product, content, entertainment, how we interact with machines, with things. How I interact with my house, with my car.
Nobody's in control of this thing, but it really changes the way we live. It changes the way in which we will conduct commerce. It changes the way in which companies deliver service and product. This is going to be a big part of our future, and it's a big driver for us as we think through safety and security, because in that environment, the two next topics that are very important is cyber, and then digital identities. In this digital connected world, those will be the two biggest questions that we going to have to answer in the future within the context of safety and security. Are you who you say you are when you're trying to attempt this transaction, and are you authorized to do that transaction? Intelligent connectivity, cyber, and then digital identity is two main things. The last one is AI.
The importance of having real smart AI and technology to make sense of how all of these things should interact with each other. That's the fourth thing that's really a big driver for us as we design our strategy. That brought us to our strategy, and I'm sorry, I'm going around and around on fours, but a four-pillar strategy, which is basically down to layers. The first pillar is prevent. We do a lot of effort across the industry, working with competitors, people across the spectrum, around how do we prevent fraud up front. This goes to standards, it goes to things like EMV, tokenization, those big things that we put in. Just like if you have a house and you have a door with a lock, it doesn't mean you don't have an alarm system. It doesn't mean you don't have a safe inside.
We have the second pillar, which is detect. We constantly monitor the ecosystem to understand, even though we have those preventative things, is there something else we need to be looking out for? The third thing, and this is one way we differentiate quite a bit, is experience. We put a tremendous effort on fraud. Fraud, safety, and security should have minimal impact on experience. In fact, it should enable the stakeholders to create a unique experience, a differentiated experience. We put a big effort on that, and it's very clearly called out in our strategy. The last one is around identity. Going into this digitally connected system, identities will be a very, very big part of us. That's kind of a quick overview of how we look at it.
Within the context of the Equifax breach, it's that relentless making sure that you do your updates, making sure that you've got your basics down, making sure that you monitor, just making sure that those things are done really, really well.
Just staying on that for a second. Equifax, you think of them as this huge credit bureau responsible for hundreds of millions of individuals' data. You would think that they would be the most aggressive about staying up to date, making sure all the back doors are closed, things like that. Yeah. How many, in your view, when you think about large companies, are there thousands of Equifaxes out there waiting to happen because things just get lost along the way?
It's kind of hard to say if there are thousands of Equifaxes out there to happen. I think cyber crime and the cyber threat is here to stay, is growing bigger. We see it taking on various forms. We see it taking on the form of stealing data and then exploiting it later on for various purposes. We also see the attacks against consumers. It's not even just against organizations and institutions, it's against consumers, stealing their data. Ransomware is a big deal for us. We also see attacks going against financial institutions. You know, not to steal data, but actually to manipulate the systems in order to commit fraud and to get direct financial gain out of that. I do believe the attacks are relentless. The financial industry particularly are under attack, we should be more vigilant than ever.
It's hard for me to comment to say how many people are vulnerable out there, and that kind of thing. It's a very big concern. It keeps us up at night every night.
Yeah. Speaking of attacks, I remember years ago, I was visiting Visa's newer data center, and they had commented that they were being attacked hundreds of thousands of times a day from China and Russia in terms of hacking attempts. I would imagine that's only escalated, can you talk about how Mastercard delineates their systems? We can see what you have on your website, how's the back end protected? That's not connected to what we can see.
The area of our cybersecurity strategy is not really my area. That's a person by the name of Ron Green, who manages the whole. He's our CISO. I can tell you that we have a very strong strategy around how we protect against cyber. We don't take anything for granted. While we put up, it's the same strategy of prevent, detect, and monitor, and continuously improving that whole process. There's a big drive to kind of separate environments so that if there is in the event of a breach, there's very limited exposure. The typical strategies you will find in most big companies. I can't really keep going into any of the details. That's not really my area, I can tell you the same principles that are there, this basically applies to ours as well.
Sure. In such a digitally connected world, Mastercard's talked a lot about AI.
Yeah.
How are you integrating that into what you're doing?
AI is a core component of us and especially for the future. In this digital environment, how do you connect the dots between all of these devices, how they interact? What are the relationships between consumers and their devices between devices? What kind of connections make sense? Which ones doesn't? You need AI to really help you make sense of that data. We have embedded AI into our network. Literally every single transaction that goes through our network gets AI applied to it. We basically use it at 2 main levels. First of all, if you think about we can, at any point in time, we have a view through AI of every single transaction across the globe in real-time. Think of it as a table where you constantly have a shift of how our transactions flow. The AI looks for pockets of risk.
If there, for instance, and I'm just going to make it up, if there's a pocket of risk starting to emerge between Hong Kong and Australia, for instance. The AI will see that, and then it's programmed that it will actually automatically intervene, surgically cut down that specific area of risk, and cause a risk. In the past, we had humans, alarms going off, pages going out, emails, and everybody would run in and try to triage the whole problem. What we've done now is we actually have a place where AI does that automatically for us. By the time we get on the phone and we start looking at the system, most of the risk has already been mitigated, shut down. It's been a great evolution for us from that point of view on the global network level.
We also look at AI on every single transaction. This is actually an interesting piece because, we've kind of evolved from the old previous AI users or machine learning more so than an AI was understanding the risk associated to every transaction. We've gone from that risk assessment to what we call prescriptive analytics. What is the right decision? Not just looking at risk, because risk without context doesn't mean a lot. I understand this transaction has a high risk, but is this a high-net-worth customer? Is this something she or he regularly do? What is my risk of attrition if I get this wrong? We're piling all those additional pieces of information into that equation, and then we come up with a prescriptive decision rather than, hey, what is the risk associated with this?
For us, AI is a really core component of driving more profitability in our transactions, better decisions, better consumer experience, and obviously the underlying safety and security, which is inherent in there.
What does Brighterion bring to the table for Mastercard?
Yeah. That's an interesting relationship. We started back in 2005 with them, took a minority investment in them, I think it was 2008, and eventually the acquisition took place in July. Really what they brought to us are, I would say, 3 main things. AI at scale as being a tough thing for the industry to deliver. We've heard many things around AI, beautiful algorithms that can do beautiful things. To deploy that at scale at thousands of transactions a second, milliseconds throughput, continuously 24/7. To do AI at scale is really hard. Brighterion brought us that. The other one is flexibility in AI, the ability to develop and design unique models and run multiple of these things concurrently in real-time. We have the Brighterion technology brings us more than one machine learning technology.
There's the typical neural networks, they've got things like decision trees and case-based reasoning and a whole bunch of other types of technologies. Basically, depending on the problem we're trying to solve, we package different types of technologies together. Flexibility and scale, are 2 probably of the biggest things that they brought to us. The ability to now expand beyond our own industry, also start delivering services and value to nascent industries, around things like anti-money laundering, financial services and stock exchanges, healthcare fraud. We now have the ability to also go a little bit broader than our typical industry as well.
NuData, which was also an acquisition earlier this year.
If you go back to the original picture that I painted in the beginning, we've got this digitally connected world. We need to know a lot more about machines, how they interact, the detail of how these communications happen, and that's where NuData comes in. NuData is a capability for us that really helps us to gain a lot better insight into what we call the point of interaction. The minutia is what device it is, what IP address it is. Is it malware that's actually intervening, or is it a human that's interacting, or is it a machine? Really getting into that minutia of detail of what's happening when these machines are talking to one another, or when a human is interacting with her or his device. Is that a human, or is it really you?
In the long term, they're going to play a really, really important part for us to understanding this whole digital ecosystem, and that data will then feed into the AI technology to make it stronger. In the short term, they help us solve three big problems. One is around automated attacks. One of the fastest-growing attacks today is the whole notion of automated attacks. The criminals write scripts, and they just have a little computer program which take all these identities that they've stolen at, let's say, Equifax, or take the username and passwords that were compromised in the Yahoo breach. They will take those credentials, and they will fire them off at any website around the world that accepts a username and password to see is there a chance that the consumer used the same set of credentials at another site.
That automation attacks is a big part of our growing problem. What they can do is they can pick those things up very, very quickly, shut them down, just get them out of the way. That's one problem is automated attacks. The other one is what we call account takeover and account origination, synthetic identities. This is where somebody's trying to go into a system, pretend they're you, take over the account, transfer your money out, or order something new. Or just, if they, for instance, they take your Social Security number, they take my address, they take somebody else's email address, they create this synthetic identity, try to open up an account at a financial institution, they commit fraud. Those are some of the short-term wins that we get with them. They can solve a real big problem.
In the longer term, it's really about how do we understand the digital ecosystem? How do we make the best decisions to allow our stakeholders to differentiate, create economic value, create that consumer experience that we all want with inherent security embedded into it?
When we think about security has different layers, whether it's the consumer, it's corporate-level security. Biometrics are a big piece of where consumer security is going because-
Yeah
of ease of use and the pretty much unique nature of them. How does Mastercard view biometrics? How do you view Apple's change away from fingerprint to facial recognition?
On the first one, big fan of biometrics. I think Mastercard is a really big fan. You would've noticed our press announcements around what we call Identity Check Mobile. Also called Selfie Pay and a bunch of other stuff. That was a big, big deal for us. We do believe the concept of a password should be eliminated from our lives. We totally believe that. There's this concept that we have that we call intelligent friction. Think about you apply NuData, you apply the AI technologies that we have through Brighterion, and you come up with a transaction that seems to be high risk.
The only way to really mitigate that risk is to introduce friction into that process, meaning asking the consumer, "I need to verify that you are who you say you are, that you really want to do this transaction." How to mitigate that friction, the easiest possible way today is via passwords. For us in the future, that'll be a biometric. The form of biometric, I think our approach has always been we want to support whatever the consumers and the business out feels there are important. Our Identity Check Mobile, it supports voice, it supports fingerprint, it supports facial recognition. We're totally good with those various forms. I'm very positive about the move that Apple made. I think it will further help. It makes our lives a lot easier to just look at it.
There are certain parts of the world which may find facial recognition better or preferable than fingerprint. I won't say we're going to say this is a winner over something else, but we're definitely a big supporter. By Apple and other companies doing those kind of things, it really helps us to get better, broader adoption of these technologies as we move forward. We can use them in payments as well.
All these things are interesting, but at the end of the day, the guys in the room are interested in how Mastercard makes money, right?
Yes.
In terms of what you've just told us, what is differentiated from competitors? What's part of Mastercard's secret sauce, per se? How's that helping you win contracts?
I think the biggest driver for us is this notion that our technology has to be an enabler for our stakeholders to differentiate and be profitable. When we walk into a contract negotiation, we want to say, "We are your best technology partner that will allow you to differentiate from your competitors and become successful in your business and make the Mastercard brand the most profitable brand out there without compromising on security." I think at a very high level, that's a very big statement that we are going after. If you look at our acquisitions of NuData and Brighterion, our innovation around the biometric space, it means that you can clearly see our vision is this digital connected world.
How do we make best sense, and how do we allow the stakeholders, be that a merchant that's trying to sell you a service or drive a product through this channel, be that a consumer who wants to consume it, be it a financial institution who's trying to create a very unique consumer experience, how do we enable that differentiation? We're sitting in the middle trying to navigate this whole ecosystem, and I think our role is how do we standardize those things and then really allow them to innovate while you can plug into a core set of security that's there ultimately. Embedded AI into our network, we're really the only network that's out there. We're the only network who's got the capability that NuData brings for us.
From the beginning, when we started playing with AI, we thought our strategy to be better to go after who's in the industry, who we think is best in the industry, rather than trying to organically grow it inside our organization. We've always had this notion of let's take the best that we can find out there, then put those things together versus just trying to do everything ourselves. That's been a big approach, then with the ultimate goal of how do we allow the marketplace around us and our customers to then become successful and really show that differentiation.
We've seen in the digital evolution of Mastercard and Visa, we've definitely seen different strategies take hold at each company. The idea of data security, data collection also seems to be a little bit different. Where I'm going with this is Visa Checkout requires direct consumer input.
Yeah.
Visa is therefore capturing personal data, even though historically the networks have always just had anonymized account numbers, but now they're connecting those dots. With Masterpass, you seem to be more of white-labeling the solution, letting others collect that data, keeping it within the banks. Could you talk a little bit about how that decision was made with Masterpass versus the obvious competitors' decisions?
It kind of goes back to what I explained to you, the same way of differentiating our security services as well. It's around enabling our banks to create differentiation from each other and to create their own business strategies. If everything is owned by one owner, there is no real competitive differentiation for those who play within that ecosystem, if you think about that. What we create is we will facilitate the creation of a Masterpass wallet set up at a financial institution, but they control the consumer experience. They are the custodians of that data. You just have to think about Equifax for a minute and think the burden that you get of bringing all of that data in-house in a single place. We see our view, we are never going to go consumer direct. Okay? That's not our agreement.
Our agreement is to enable our financial institutions to be that service delivery. That's the place where they stay, and how do we create an environment where they can really differentiate, be themselves, and create a better business strategy than somebody else? That's the fundamental change, where there may be some things that makes it easier to implement and so forth, but ultimately, in the long term, the business strategy is what we believe will win, and how banks can create that unique experience for their own customers.
I wanted to ask your opinion on different data privacy regulations around the world, because one thing really jumps to mind, which is Mastercard recently won the digital wallet. It's now going to be the digital wallet solution for La Caixa with Masterpass. La Caixa is almost entirely a Visa issuer. From what I understand, it was because Visa Checkout wasn't compliant with European data privacy rules. Can you talk about how that's a challenge globally, how you have to adapt to each region, especially with things like China and Russia and others now requiring on-soil processing?
Data privacy and data compliance is a really big part of my life every day. Because if you think about all of these AI and data products that we do, it's all about data. The compliance of that is a critical component, which is why it's fundamental to our business as well. We don't try to take shortcuts when it comes to privacy.
Just because ultimately our brand and the reputation of our brand is way too important in that. We are working very closely with a number of regulators around the world when it comes to what we call data nationalism, understand where they're coming from. There is also a lot that we can bring to those scenarios. For instance, in many of the countries where those are active projects going on, we provide education. We provide infrastructure. We provide best practices. How do you run a domestic system like this in a domestic level? What kind of infrastructure? How do you embed safety and security in the house? We still see ourselves as a big player in those areas. We'll be supportive of whatever those governments want to do there to make sure that we are adhering.
Ultimately, if we can't provide a business model that allows that kind of flexibility across the world, how do we really see our future strategy? Our future strategy is built on allowing those stakeholders, be they governments, be they banks, to allow that because that's always going to happen. We're not in a world where everything goes around the same way. It's a big part of our strategy. It almost goes back to what I told you about safety and security, being there to help stakeholders to differentiate. Masterpass being there to say, "We recognize the bank's role in this relationship, their custodianship of the data." This place is the same. We recognize that certain governments have specific strategies, and we'll still provide technology. We'll still provide best practices.
We'll still provide education, infrastructure, and help them to actually get going on those things and make a success out of it. Ultimately, our goal is this war on cash. If that means we work with governments locally to facilitate that electronification of commerce, we'll be right there and we'll play our role.
In thinking about attacking these new territories and also rule changes in existing territories, we've been talking about this for a very long time since the IPO, but it didn't become a real topic until recently. Mastercard's network architecture is different from Visa's. You have a distributed architecture versus Visa's hub and spoke network architecture, and I believe that's something Robert Selander put in place a long time ago-
Yeah
foreseeing a lot of this. How does that help you with speed into market, with the need for new investment into market? It seemed that when discussions were out there around Russia and China, Mastercard consistently had a lower new investment need than Visa did. Was this because of the way the networks are architected?
Yeah. If you think about that, for those of you who don't understand a distributed network, basically, we have thousands of endpoints spread all across the world, and a transaction basically takes the shortest route. It doesn't have to go through a center. There's no central point that where every transaction has to go through in real time, all the time.
Except through cross-border, right?
Well, even on the network. A transaction could go between China and Sydney, without going through the United States, for instance. You can just stay on the shortest possible path. Where the star network, our competitive network out there is what we call a star. Everything has to go through the center and then out. It always does this, where we can simply take the shortest path. We've actually created what we call a hybrid network, which is, a lot of transactions go central when we need to apply a service like safety and security, like loyalty or something else, and the ones that don't, take the shortest path. By nature of that, we have a lot of intelligence at the edge, which means that our edges are far more intelligent, so we can do a lot more in China.
We can do a lot more with a lower investment. I think the architecture of the network played a big role in that. The fact that it's a hybrid network, we can still work with local authorities and local customers to say, if some of them require services that can only be supplied in the center, those transactions can then on demand, can be routed to the center, get the service applied, and then get back to them. I think the flexibility, obviously, I think that played a very big role, in our speed of market, as well as the investment required to getting there.
Mm-hmm. Do you see the majority of territories globally going to a on-soil processing stance?
That's interesting. I wish I had that crystal ball. There's definitely a trend that we see more and more of that. Whether that ultimately where everybody ends up, I'm not sure about that. That's a hard question to answer, but there's definitely a trend that more and more countries are asking for. The whole notion of data nationalism is definitely a trend that we see growing in the industry.
What complications does it introduce for Mastercard when you have to start working with an NSPK Russia or a domestic switch, that you have to, a degree, trust with the transaction for them?
Yeah. Two things. On safety and security, there is a concern. We're fighting against criminals who are operating globally. When you isolate your view of safety and security to a very specific market, that makes it harder to see global attacks and really respond to them as fast as you want to. We're in constant discussions with regulators when they do these things to say, "How do we help you to also make sure we don't lose the safety and security blanket that we can provide from a global network point of view?" What if the attack doesn't happen cross-border, but the attack happens domestic, and we can't apply all of this beautiful AI and the NuData technology that we have.
There's a lot of discussions in how do we ensure that we have that safety and security blanket across it. Also, you want to make sure that the consumer who's interacting with the brand has a consistent experience no matter where they are in the world. For that reason is why we are so actively involved in these things to make sure that we provide technology, that we provide best practices to ensure we can keep some level of input to ensure that level of consumer experience.
Mm-hmm. With every smartphone essentially becoming an endpoint for the network.
Yeah
That also must introduce a whole layer of complication.
Yeah, look, it's a beautiful thing. We truly believe every device is a potential commerce device. Right? That shouts opportunity. It shouts opportunity of converting cash into electronic payments, but it does raise risk. Every point now is a vulnerable point to a cybercriminal, to somebody who's trying to take over a device. That is where this whole strategy of NuData, get insights into what's going on on that device, understand is it a human interacting, is it the right human? Things like behavioral biometrics. One of the things that they do with NuData is just by the way you type on your phone, we can say it's you or it's not you. How hard you press on the glass. Do you hold it like this? Are you right-handed, left-handed? Do you type with two fingers, one finger? Do you hold it flat?
All sorts of different points. All of these things, and then you need AI to really understand when something is happening, be that at a device level, at a merchant level, at a network level, how to get this. That's why our investments in these technologies are really geared towards these risks that you rightfully highlight. They are big concerns, but the opportunity is massive, and that's why we think we're well-positioned for that.
Okay. Stepping outside of Mastercard for a minute. Can you talk about cryptocurrencies, what type of risk that might pose to the network, might not pose to the network, and how Mastercard might deal with that?
Yeah. Look, we always look at these things very carefully, right? Because the payment space is so big, you always need to be very careful of people that are trying to get in there. From a competitive point of view, yeah, we are very acutely aware of them. We are looking at them. The thing is, I think there's this perception that cryptocurrencies provide a level of safety and security that normal payments cannot provide. I think that is simply not true. If you look what's happening with this, I'm going back to this digital ecosystem where cyber and identity become your two biggest things. We've seen the media reports lately where criminals have taken over a user's device, emptied out their Bitcoin account. They're susceptible to exactly the same risk of a cyberattack, of an identity theft, somebody taking over an account, and then performing those actions.
We're no different in those areas, and those will be the areas we are putting a lot of investment and effort into making sure that we can at least mitigate those risks as they come up, and that we have a way to identify new risks coming up, and that we can quickly respond to them. I do think we are acutely aware of them. I'm not going to dismiss them at all. They're very real. But I don't think the notion that we need them because safety and security is not adequate. EMV tokenization, that inherent security is as good as anything else in terms of the everyday transaction. When it comes to cyber and authentication, the playing fields are equal, and that's why our investment in that technology are so critical for us to make sure that we have a good handle on that.
In that investment, do you need the banks to be playing along? They're obviously the contact point for the consumer.
Yep. Very important point. We go about this two ways. There are several of these things where we actually need the banks to cooperate. They need to drop something onto the device, onto their website in order to help us to collect the data. They need to connect to our systems. There are several places where we can actually just put it inherently into the network. Like for instance, the AI where we scan our entire network. We don't need the banks to do anything. There's zero implementation. It's us sitting from a network point of view, having AI looking at everything that's happening in real time all the time, and then finding these areas of risk and mitigating them. There are some of the finer areas where you do need the banks to play. That is an important role.
Even things like 3DS 2.0, there are certain industry standards, EMV, are places where we standardize this technology to make that implementation easier. You'll never do away with it. Look, implementation and IT resources, you're always in that constant battle, this is a really hard thing. We do ultimately believe that getting a standard across the industry is a big, strong motivation for the banks to get there. Just to cut down on the answer, not to make it too long, some of the things we need the banks for, and some of them we do at a network level, and we basically embed it at our network level.
Okay. I want to see if there are any questions in the room. Chris.
Johan, Mastercard introduced a biometric credit card, I think back in April, and was trialing it in South Africa. My understanding is that chip card, that credit card with a biometric in it costs about $20. I'm just curious how the trial is going and what you see as the potential for adoption in the next year or two among financial institutions globally.
Yeah. Thank you for that question. It's actually a good point. I should've brought that up earlier when we had the discussion around biometrics. The trial is going really well. We see a lot more demand outside of the trial area, in other areas. Interestingly enough, some of our banks are really looking towards this as a big play in the affluent consumer portfolio, in really underlying places where trust and integrity really means a lot. We see a lot of interest. That's going well. The trial is going well. As that demand grows, we believe the price will go down. I'm not sure the $20 is accurate, quite frankly. I don't have the amount with me, but I'm not sure. I've heard a lower amount, but it's higher than what we want it to be.
Like with anything, the moment you introduce scale, that unit cost will come down. We're pretty confident that that will make a big difference for us in the future as well.
The banks, those who you are relying on to make investment, are they investing enough? Are they on board with the level of due diligence and investment in new technology that you would like to see them be at?
I would always love to see more. I think, with most of our banks, we are in a place where they understand the importance of safety and security specifically. They are making the right decisions, and we work with them on a constant basis to just get the minimum bar to get it higher and higher. We have different ways of doing it. In most of the cases, we work very closely with our banks, and where we see inadequate protections, we will go in with some of our franchise rules and really try to get that compliance to get up. We have different ways, but in general, I think most of our banks are really good at this because they all understand the importance of this.
These events, like what happened with Equifax, will again underscore why this is so important that banks invest in this. I would say, in general, we're very happy with it. Can we do better? Oh, absolutely. We put programs in place to continuously put that bar higher and higher to make sure we also help them with that prioritization.
That brings me to my next question, which is how do you get entities motivated? Do you think regulators should be involved? Does Mastercard want to see regulators involved in creating minimum standards for all entities to meet? Because it would seem that without a fixed minimum bar of security going forward, we have no chance of normalcy in terms of data privacy.
Yeah. It's an interesting question, Craig. In most of our cases, if not all of them, we've been working very effectively with regulators to move that bar. If you think about what's happening in Europe with the Payment Services Directive 2, PSD2, as everybody calls it, if you look at what happened in India with the government there, with their level of security, authentication, and biometrics, we welcome those kind of things because, to your point, it just drives up the minimum standard, and then it levels the playing fields for everybody to compete there. I think we welcome regulators to get involved in this. Obviously, we want to be working with them to be smart because ultimately, we want to have a balance in the regulation so that while security is critical, they just don't lose sight of the consumer experience.
For instance, in Europe, we've been working very actively with regulators there to bring in the concept of risk-based authentication. Why should I do an authentication for every single transaction, even if it's EUR 2 and it's something that I regularly do or my subscription payment that goes off every month? How do we deal with those things? When we can get into a dialogue with the regulators, we always find that things come out in the benefit of the industry and how that evolves.
Okay. Taking that forward, what risk does Well, actually, go ahead, Jeff.
Just on fraud risk, I think it's six or seven basis points of volume. We've seen some stats like that. If that goes up or has it been increasing, and who's on the hook for the fraud risk? Is it the banks that are making the loans, or do other parties, could Equifax or Mastercard one day have to share in the burden of future fraud risk?
Right now, Mastercard has no liability on the fraud risk. Just to put that one out there first, because that came into your last part of your question. If you look at the everyday transaction, the answer is really, is it depends. There's a general rule that the party with the lowest end of security carries the burden of the risk. For instance, if the consumer has an EMV-enabled card, the merchant doesn't have the ability to accept that highest level of security, then liability will flow to the lowest level of security entity. There are so many nuances around these things that it's really hard to give you a definitive answer. At a higher level, liability typically goes to the area with lowest level of security. That's the rule of thumb.
In cases like Equifax, there are a number of programs that we do run, depending on how many accounts has been compromised, what are the cost involved with the banks to reissue, monitor these accounts. There is typically, we get to some agreement with these entities on how to navigate that level of liability and make sure that parties are compensated for now having to address that kind of risk. In your everyday transaction, the general rule of thumb is lowest level of security carries liability. It's sometimes the merchant and it's sometimes the bank, just depending on how that plays out. In all fairness, there are so many nuances to this. We can go in for a fair long time looking at each one of those. At a general level, that's kind of how it plays out.
Can you talk about what level of risk is introduced to the system by third party wallets, things like Alipay and WeChat Pay and PayPal? I mean, obviously you have the agreement with PayPal, so you have a better footing with them, but in general?
Yeah. I think it's like everything else. It's how do we make sure that we have that same bar of safety and security that's in there. Ultimately it boils down to consumer trust in the electronic payment system and the integrity of the payment system. If you have a third party with a very low focus on the risk and something happens that shakes the confidence of the consumer, that's a concern for us. What we've seen is traditionally is that most of these third parties that come in, they do have a fair amount of focus on fraud and risk as it should be. It's with anything else, even in our existing ecosystem, in this whole connected world that we are out there, every new point that comes in is a potential point of vulnerability.
Within a framework where we know what's going on, where we can monitor it, I think we can mitigate those risks and maintain them at least to a point. Yeah, third parties introducing risk, that is something else that keeps us up at night. We do look at those very carefully, and we have to be mindful of them, and especially if they're outside of our industry. What will be the impact on the consumer confidence ultimately? That's our biggest concern.
I'm a subscriber to Brian Krebs' blog, so I get an alert.
You don't sleep every now and then.
Every other day, you're getting an alert about a retailer that's been breached, whether it's a hotel, the Targets of the world.
Yep
whoever. How do you work with those entities, have they improved at all since the days of the Target breach or even well before that?
We've seen big improvements overall. I think the awareness in the industry is at a much higher level than it's ever been. The answer on that one is we see the right strides are going there. The problem you have is, for cybercriminals, it's an arms race, right? There's always something new. There's always a new evolution with a new point of vulnerability. For that reason, if you go back to the strategy under what we call our prevent pillar, things like tokenization and EMV, ultimately the answer is that data should be rendered useless. I think that's something we as an industry has now completely, Mastercard, Visa, all of us, are heading down this path of how do we get to a point that that data is rendered useless. Because the strategy of trying to protect it at all times can only be so effective.
Ultimately, the core will be take the value out, create that unique piece of data that has to go with every transaction so that you remove the incentive for criminals to really go in and go after those technologies. I think if you speak to folks like Brian and others, they would tell you if with the right level of equipment and focus, it's really hard for these retailers to protect 100% around what's going on. Really the answer is, the strategy is not stronger and stronger protection. The answer is just render the data useless. Get it into the core and get the incentive out of the way.
How willing are large cards-on-file merchants like Amazon, Walmart, and others, Netflix, how willing are they to tokenize their cards-on-file base? Are they willing to work with you in that regard?
We are actively working with a number of merchants out there. In fact, I was in India last week with Netflix on stage, talking about the benefits of tokenization. They're actively working with us to do that. They're great partner of ours in that sense, tokenizing their entire card-on-file portfolio. It's an active discussion with those merchants. There are some operational implications of doing this. I need to make sure that there's a cardholder, you still recognize your card. What does a token mean? All of those things. We have to work through all of the operational issues. In general, the conversation has been very strong.
With partners like Netflix, I think we've seen a very positive movement, and they're going out in public talking about the benefits of this, not just of the security component, but also about the component of the consumer convenience. Every time one of these breaches happen and we get our cards reissued, I have to go to 14, 15 more places to go and change out my card, make sure the payments go through. Another product that, or another area that we focus on really hard is what we call card continuity. How do you make sure that that card is always available when we issue a new one, that the consumer experience will not be interrupted? We have a very strong strategy around if it's a token, that's pretty easy. We'll just replace the token. The token at the merchant can remain the same.
If your card is replaced, what Netflix will have will remain the same, and there's no risk there. If Netflix gets compromised, we'll replace that token. We've got a very good way of managing tokens. On our normal open plans, we have a product called Automated Billing Updater where banks and merchants will subscribe. Netflix is a big subscriber to that. Automatically when your bank issues you a new card, we will update at all these merchant places. We'll tell the merchant, "Replace this card out." All of that is done to kind of protect that consumer experience at the end of the day.
I think we're about out of time. I would imagine with everything going on in the news, when you put your hand up in budget meetings, Martina's more than happy to recognize you these days. Thanks again for joining us, and we look forward to hearing from you again in the future.
I appreciate that. Thank you very much, Craig, and thank for the audience. It's a really good opportunity for us.
Thanks.