By Ray Birch
RANCHO CUCAMONGA, Calif.—With all the attention now being paid to EMV, experts are advising CUs to avoid focusing too much on chip cards at the expense of the overall security strategy.
That was a key point made during a recent CO-OP Financial Services webinar on EMV. Michelle Thornton, director of product development at CO-OP, urged credit unions to be attentive to EMV, have a plan for it and migrate cards according to that plan. She emphasized that the Oct. 1 liability shift deadline stirred up a great deal of concern among financial institutions.
“Was the EMV liability shift deadline actually Y2K, the sequel? In some ways, we have to say yes,” said Thornton. “We had a lot of industry attention focused on the Oct. 1 liability shift deadline, but though it was significant, it was not the apocalypse. The key takeaway here is to be mindful of your whole security picture, not just EMV.”
Not A Sprint
Thornton noted security is a “marathon, not a sprint.”
“So while you want to allocate resources for EMV migration, you also want to invest in things like analytics—which also means looking at your data strategy,” she said. “And you need to make sure your long-term plan is sustainable, because security is a never-ending proposition. It’s always going to be evolving, and it’s always going to be important.”
As experts across the globe have consistently warned, U.S. card-not-present fraud is expected to spike as EMV takes hold stateside. Aite Group projects that between now and the end of 2018, card not present fraud in the U.S. will more than double—from $3.1 billion to $6.4 billion.
Thornton pointed out that during the first 10 years of EMV in the U.K. counterfeit card fraud dropped 70%, but in the three years following that country’s liability shift deadline, card not present fraud rose 79%.
Thornton suggested that CUs pay attention to the entire fraud fighting toolkit, which in addition to EMV includes tokenization, analytics, neural network fraud detection/prevention, and card control apps that allow consumers to aid in the fight.
CNP Fraud Rising
Amid growing concerns over card not present fraud, and also with mobile payments’ growth in the last year, Thornton said it’s the right time to consider tokenization.
“Tokenization is the security underpinning for Apple Pay. We’ve had over a hundred CO-OP credit unions sign up for tokenization service in order to participate in Apple Pay,” she said. “If you’re interested in doing this, Apple Pay rollout is about an eight-week process—not instantaneous, but not impossible either. Tokenization is also going to drive security in Android Pay, Samsung Pay and a host of other mobile payment opportunities.”
David Hooper, VP of strategy and innovation at the Ontario, Canada-based Everlink Payment Services, described how tokenization has taken hold north of the U.S.
“From a Canadian viewpoint at least, tokenization isn’t the earth-shattering technology that many make it out to be,” Hooper said. “Tokenization is very closely related to EMV and integrates very nicely with EMV. Tokenization protects data elements that are used in EMV, such as the PAN, or expiry dates, names, etc. On our side of the border we have all been doing tokenization of some form or another for a while. But mobile has made it a household phrase that everyone wants to know about and participate in—think of it as another layer of PCI—and don’t be surprised if PCI pumps up the requirements for encrypting data in our systems and soon recommends tokenizing everything we store.”
Thornton said that financial institutions are getting better at using behavioral analytics to detect fraud—at the right time.
“Where EMV and tokenization are limited to the transactions that they cover—in other words, EMV only applies to transactions done using a chip-enabled card— analytics can be trained on all transactions,” she said.
