Do Your Customers Feel Safe? Here’s How to Help

It’s not enough to make customers safe. I’ve worked with several businesses that did everything they were supposed to on the back end, including hiring IT security professionals, developing safer websites, and actively monitoring for threats—but customers never see the back end.

In addition to making customers safe, enterprises have to make them feel safe, which is arguably the harder of the two to accomplish.

Why “feeling” safe is so important
If customers get to your online store and feel like they aren’t safe—even if they are—they aren’t going to make a purchase. Even if they do make a purchase and everything goes through without issue, all it takes is one point of suspicion to make them apprehensive about shopping with you again. That’s why breached companies have such a hard time rebuilding their reputation—even though the company is taking all the proper precautions and most of the damage is already done, customers no longer feel as safe with them. Therefore, customer feelings of security are vital to both acquisition and retention.

The problem, as I see it, is that “feeling” safe is subjective, while “being” safe is objective. You can easily hire security personnel to verify that your customers are safe, but how do you gauge their feelings? Triniti explains that it’s all about collecting, storing and interpreting customer data in an efficient and accurate way. Take surveys. Talk to your clients. Make notes and aggregate your information to understand how your customers feel.

Strategies to build trust
What if you’re having trust issues? How can you make your customers feel safer?

  1. Show off your credentials. If you’re working with major security organizations, show them off with small “trust badges” that demonstrate your affiliation. As VWO notes, including trust badges can lead to a 32 percent increase in conversions—or more. Any credentials you have that prove your commitment to security should be in the public’s eye.
  2. Demonstrate your history. According to BrightLocal, 88 percent of consumers trust online reviews as much as personal recommendations. If you have a wealth of satisfied customers, make sure your new customers see that. Explain how long you’ve been in business and how many people you’ve served. For new businesses and startups, this is difficult, but still, try to prove your track record.
  3. Serve multiple layers of authentication. Multi-factor authentication doesn’t just feel safer—it is safer. Forcing your customers to provide a secondary means of identification (like signing in with a specific device) gives them a tighter feeling of security and makes them more confident in your brand. It’s also not that hard to implement.
  4. Minimize redirects. It’s often tempting to build in redirects to third-party sources for verification, additional sign-in information or some other important function to your backend process. However, redirects can shake customers’ feelings of comfort. Try to minimize them whenever possible.
  5. Improve your site speed. Improving your site speed can give customers the impression that your site is modernized and fluid, and give them less time to hesitate about their decisions. It also gives them a better overall experience as an added bonus. CrazyEgg has a fantastic article about how to accomplish this.
  6. Accept multiple forms of payment. Accepting multiple forms of payment proves that you’re an established online business with a commitment to its customers. You’ll also earn reputation benefits by proxy; listing PayPal as a possible payment option will help your brand be seen with a similar authority as the payment giant.
  7. Be transparent about your security efforts. Finally, don’t keep all your security measures in the dark. Let your customers know exactly what you’re doing to keep them safe. You can make regular press releases or dedicate an entire page of your site to updates of your security features. The more they know, the more they’ll trust you.

These strategies are proven to help customers feel safer when they shop with you online—assuming you have first done the work to actually make them safer. In any case, the more attention you pay to your customers’ security and feelings, the more they’ll be willing to engage (and spend) with you, and spread the word about your company.

Anna Johannson, Writer

[ISACA Now Blog]

The Outlook for Biometrics Security

Deloitte Technology, Media and Telecommunications predicted recently that more than 1B devices would be reader-enabled for biometrics by the end of 2017. This is a very significant milestone for many reasons.

Over the years, there has been a lot of hype about the potential of biometrics for authentication and other purposes, but the lack of availability to consumers meant adoption was behind the hype curve. Device manufacturers have since changed this picture with native biometric support of mobile and tablet devices.

In a broader sense, it is important to understand the benefits of biometrics and how they can fit into an organization’s security strategy.

The death of the password – are we there yet?

Biometrics are used for individuals to authenticate to a service or a device. In some instances, authorization of a transaction has been built into applications. Due to its many intuitive uses, biometrics have long been a favorite of those who sing the tales of the demise of the password. While it is unlikely that we’ll get rid of passwords anytime soon, biometrics can offer a lot of value.

Why biometrics?

Biometrics have some significant benefits. Their adoption into ever more uses bring with it a number of benefits.

For a start, biometrics are user-friendly. After years of passwords and pins on fiddly mobile device keyboards, having a simple fingerprint reader is a welcomed alternative, particularly when, as Deloitte research noted, biometric readers are used on main devices, on average, 30 times a day.

Another benefit of biometrics is increased accountability. As biometrics rely on something you are, the days of sharing authenticators could be numbered.

Biometrics also are cheap. The device manufacturers have already distributed upwards of a billion readers to date.

Lastly, where the system is properly architected, biometrics can have the advantage that attacks won’t scale. Proper design entails not using the representation of the body feature as a secret and, in turn, not storing such representations in a central location. Often it is these databases that are a target for motivated attackers.

How do I embed biometrics in my digital strategy?

Organizations should definitely consider using biometrics in their consumer authentication strategy, but this should be part of a wider security model. Having a single factor (in this case of biometrics, something you are) might be enough for simple uses – for example, to log into your electricity provider to review your latest bill. This will not be enough for other uses, though, such as authorizing a major payment from your bank current account. There are a few things to keep in mind for organizations in all industries:

  • Balance a good user experience with appropriate security. Happy consumers can be a real differentiator; lack of security can lead to significant losses and cause real damage to your company’s reputation.
  • Make customer authentication and use of biometrics a part of a wider strategy. For some use cases, a fingerprint might be enough to authenticate. In other cases, you want another factor, such as out-of-band authentication. In some, very high-value use cases, you might even want to continuously monitor that your authenticated user is still likely to be the same user. This is known as behavioral biometrics.
  • What do you do if your main authentication mechanism is breached? Do you have a fall-back plan? Will you have strong protection for the consumer to increase adoption in the first place? Are you able to detect and respond to such an event? Your authentication strategy should be part of a much wider security-by-design strategy.

Multifactor authentication is here to stay, and biometrics are fast gaining pace. As part of your overall customer-facing initiatives, build in a strong authentication mechanism, and leverage the growing presence of biometrics to enhance security and user experience.

Kristian Alsing, head of identity and access management, Deloitte UK

[ISACA Now Blog]

Faces of ISACA: Integrity Central to Santor’s Career Success

One of the most influential conversations in Cheryl Santor’s career required plenty of gumption.

Santor, working in IT at a mortgage banking firm in the 1990s, had major concerns about non-proprietary memory that had been installed, jeopardizing the main system for collecting loan information. She voiced her concerns to her CIO in no uncertain terms, believing the integrity of the loan origination system was at stake.

It turns out, Santor’s candor – and insights – were respected more than she could have anticipated. About a year later, that same CIO hired her to work at a national bank where she eventually became CISO.

“He appreciated my diligence, integrity and forthrightness,” Santor said. “This boosted my career and provided the backdrop for my future.”

Santor, a longtime ISACA member, recently retired as the Information Security Manager of Metropolitan Water District of SoCal, where she ensured the security of the business and SCADA network systems. Her responsibilities included review of all national and global intelligence that might affect water system reliability. She continues her ISACA involvement, and work with the FBI InfraGard and other professional organizations, to provide expertise in her areas of focus.

The fourth-generation Californian recently was nominated by a colleague as a finalist in the Los Angeles Business Journal’s CTO Awards.

“I have been in this work for 28-plus years and it has always been a passion, so to be recognized for that passion is reward in itself,” Santor said.

An information security professional “before there was such a title,” Santor said she emphasizes awareness of security best practices, including disaster recovery exercises and access controls.

Santor has been actively involved in ISACA’s Los Angeles chapter for 17 years. She was an IT auditor when she first joined.

“Seeing that audit and security went hand-in-hand, in providing the best for any organization, I joined ISACA,” Santor said. “I knew that ISACA would provide me the intelligence and expertise as I moved through my career.”

In recent years, Santor has become especially passionate about ISACA’s Cybersecurity Nexus (CSX) program as a resource for cyber security professionals to gain the needed skills and training to keep pace with fast-evolving cyber threats.

“Whether they are entering the field, changing careers or just becoming the person who is taking cyber security on for their company, they can look to ISACA’s knowledge to support their efforts,” Santor said.

Santor and her husband, Louis, have four children and eight grandchildren. Rather than having a hard time keeping up with her grandchildren, it might be the other way around; Santor is a car enthusiast whose hobbies include racing Corvettes and Cadillacs.  A less adrenaline-infused passion is quilting, which Santor said benefits from a similar mindset to her professional wiring.

“I like to take fabric, cut it up and create a new version or outcome,” she explained. “To me it is somewhat like computer forensics. You are presented with a puzzle and you need to make sense of it as the final outcome – an investigative process in both instances.”

[ISACA Now]

Connecting Business and IT Goals Through COBIT 5

Business leaders must take accountability for governing and managing IT-related assets within their units and functions just as they would other assets, such as those involving physical plant or human resources.

This is critical as achieving enterprise goals becomes increasingly interconnected with successfully managing and governing its technology. COBIT 5 provides the framework needed to connect business goals with IT goals while utilizing non-technical, business language, as explored in a recent ISACA podcast. John Jasinski, a COBIT certified assessor, discusses the framework’s core principles and enablers, and ways in which enterprises can successfully leverage them.

“The main purpose of the governance of enterprise IT is to achieve strategic alignment of information and related technology with the goals of the enterprise,” Jasinski said. “However, a continuing challenge for enterprises is how to achieve and maintain the alignment as stakeholder needs and enterprise goals change. The COBIT goals cascade provides context, structure and content for consistency of goals and meeting stakeholder needs.”

The COBIT 5 goals cascade provides a model to define and link enterprise goals and IT goals in support of stakeholder needs.

Decisions on how to utilize IT assets and resources should be made by business managers in an overall governance and management context, according to Jasinski. Directors should govern IT through three main tasks:

  1. Evaluate the current and future use of IT;
  2. Direct implementation of plans and policies to ensure the use of IT meets business objectives;
  3. Monitor conformance to policies and performance against the plans.

COBIT 5, which aligns with other relevant standards and frameworks used worldwide, provides a technology-agnostic common language to more effectively address information and cyber security, risk, vendor management, cloud controls and many other challenges faced by enterprises. Distinctions between governance and management also are addressed.

“If you’re looking for context, structure and content to address your biggest digital business challenges and opportunities, you must have an understanding the COBIT goals cascade, enabling processes and the entire COBIT library,” Jasinski said. “COBIT can help you understand how to connect all the dots, and fit the puzzle pieces together. This is important stuff.”

Further ISACA insights on the topic can be found in the white paper, “COBIT 5 Principles: Where Did They Come From?

Editor’s note: The ISACA Podcast is now available on iTunes, Google Play and SoundCloud. Listen to experts in cyber security, audit, governance and more as they explain the latest trends and issues facing professionals.

[ISACA Now Blog]

Three Questions with Daymond John

Editor’s note: Daymond John, the FUBU clothing founder, Shark Tank reality TV judge and a self-made multimillionaire, will deliver the closing keynote address at ISACA’s North America CACS 2017 conference, which will take place 1-3 May in Las Vegas, Nevada, USA. John visited with ISACA Now about what innovation means to him, his approach to taking business risks and the Shark Tank experience. The following is an edited transcript:

ISACA Now: The word ‘innovative’ is thrown around a lot. What does that mean to you, and in what ways has that kind of mindset allowed you to achieve such a high level of success with FUBU and your other ventures?
Innovation is the process of creating something new, which oftentimes is just a newer version of something that already existed. For example, to me, Twitter was a note on a pigeon’s leg hundreds of years ago. It’s just a new form of delivery.

There’s a huge misconception about innovation, which is that it starts with some grand idea. The truth is that it typically begins with people collaborating and working together on ordinary ideas that transform into something innovative.

When I started FUBU, I didn’t put three sleeves on my T-shirts. I didn’t start trying to be “innovative.” I just did what I could with what I had, and the brand became more than what even I imagined it could be.

ISACA Now: What advice would you give somebody who has a business idea that he or she is excited about but is nervous about taking that entrepreneurial plunge?
Take affordable steps. You don’t need to take great leaps of faith. Again, start with whatever you can afford to lose.

The idea is not to get over your fear of taking a plunge – it’s not to take a plunge at all. Baby steps; that way, you don’t hurt yourself too much when you run into problems. That way, you can survive your mistakes and live to take another step.

ISACA Now: What has it been like to be involved with Shark Tank, and what aspects of the show do you think resonate most with viewers?
It has been a great learning experience for me. I learn as much from the entrepreneurs as they learn from me sometimes.

What resonates with people? I think the show illustrates that the American Dream is still achievable. It shows that ordinary people can do extraordinary things if they’re willing to act on their ideas.

[ISACA Now Blog]

English
Exit mobile version