• Home
  • News
  • Privacy

Small Business Insider

Business Finance and Insurance

  • Insurance Guides
  • Business Finance
  • Business Advice
  • News
  • Business Insurance
  • Business Bank Accounts
  • Wirex Card
Home Technology Why establishing ‘who you are’ is still the biggest challenge in Internet Customer Experience

Why establishing ‘who you are’ is still the biggest challenge in Internet Customer Experience

Posted on May 18, 2022 Written by Administrator

On the Internet, nobody really knows who you are. Digital identity has been an afterthought. Today this is one of the biggest weaknesses in terms of cybersecurity and long-term sustainability of the digital economy. However, things are changing, and fast. This is an area that needs to be understood much better.  

Let’s begin by clarifying the definitions of personal data.

Identification: the process of identifying an individual

Authentication: the methods used to re-identify and validate individual identities either by what they have (eg SIM, phone, cookie), what they know (eg password or pin) or who they are (eg biometrics)

Verification: the steps taken to corroborate information provided by the individual by accessing trusted data sources and services (eg data brokers, aggregators, telcos)

ARE OUR IDENTITIES SECURE?

The security of personal data and identity is now a major concern for consumers. Each year, the Mobile Ecosystem Forum (MEF) surveys the level of trust in the ecosystem, and 2021 data revealed a clear gap between the level of expectations from consumers versus real experience. The gap for mobile apps and services keeping data secure (versus the expectation) is 27 percentage points; the gap for privacy is 28 percentage points. This size of gap usually indicates a breaking point in the level of trust between users and a product. In short, the situation looks serious.

After scandals such as phishing or account take-overs, consumers are worried. From the 2021 MEF Survey, the top user concerns are:

  • Being defrauded / losing money – 49%
  • Cybercriminals gaining access to my data – 49%
  • Someone gaining access to my mobile – 47%
  • My online activity being monitored – 43%
  • Losing data from my device – 41%
  • Companies sharing or selling my data – 39%
  • Spam / junk email – 37%
  • Companies experiencing a data breach – 33%

Interestingly, None of the above scores just 6%.

Concerns over Personal Data Security and Privacy is now a reason to delete an app (37%), avoid installing one (33%) or stop using a service altogether (29%). The level of authentication/security is an element with clear impact to consumer preferences.

ONLINE THREATS

In 2015, global fraud amounted to $3trillion dollars. By 2025, the figure will be $10.5trillion from fraud and cybercrime. The implication is that identity and access management to enterprise systems is becoming increasingly critical.

Globally, we are seeing a pronounced move towards an increasing reliance on digital identity and a clear move away from a distinctly unexceptional user experience and inadequate underlying security. Industry is having to develop new solutions that (a) meet the evolving needs of the user experience and (b) work to mitigate the threats.

Online threats are becoming more intense, as is the inevitable fraud that drives these threats. Globally, 59% of enterprises surveyed in 2021 by MEF cited security and fraud prevention as the key driver for digital identity and authentication. The solutions becoming available seek to tackle some of the major issues we are currently seeing:

  • Device compromisation – where a hostile party can take control of a device remotely
  • Smishing – when fraudsters attempt to elicit sensitive personal data, passwords, or banking details through SMS (the most common ways to authenticate globally)
  • SIM (Subscriber Identity Modules) swapping: where a mobile phone identity is swapped with the intention of taking over an account in order to impersonate the user (e.g. making calls, receiving authorisation codes etc.)

MODELS FOR PERSONAL DATA AND IDENTITY

So, what are the models for personal data and identity? This is a critical question to ask. We need to analyse the ‘architecture’ of personal data/identity. The differences among these models implies different applications and threats. We can identify three architectures that are developing and succeeding across the globe that link the individual’s attributes to databases. Interestingly, biometrics are the common thread across all these architectures:

Centralised model – often operated by a government or consortium of financial institutions. In this model, an individual’s information is handled on a centralised database from cradle to grave and has the effect of offering a simplified means of establishing digital identity for a range of services. An example of this approach is Singapore’s SingPass.

Federated model – operating with a series of distributed databases that represent different groupings and where parties can access personal data in one of those databases. The European eIDAS system is an example of one federated approach where trusted service providers can issue and deliver digital signatures and identity. Countries adopting this model include Belgium, the Netherlands and Italy

Self-sovereign identity model – which has no centralised database where the individual owns, manages, controls, and issues their personal data.

Each of these models needs to ensure that the digital identity provided by a trusted service provider has strong authentication. In practice, we are starting to see the emergence of a new model based on these three models. This could be considered as the establishment of digital credentials. An example of this would be an individual’s Covid status. This would allow a person to obtain their signed and verified health credentials which would then be trusted for access to venues or travel.

Clearly, there are issues around maintaining an individual’s privacy and how authentication fits into the process. Standards are developing that can provide further reassurance. Furthermore, there is the issue of regulation, how liability is distributed in this model of verifiable credentials, and how data is controlled and handled under regulatory requirements such as GDPR.

THE FUTURE

The ecosystem is fighting back from the threats of cyberattacks and we will see more of these innovative solutions emerge. There might not be an overall winner, but the co-existence of alternative approaches is now expected.

The good news is that the effort required to maintain security and reduce fraud will be significantly lessened by these technologies. This is because they will replace or enhance inadequate access control and authentication. Organisations and governments need this enhanced measure of multi-factor authentication to progress in the coming years. And individuals need the knowledge that their data is safe and that they can exercise trust in the integrity of it.

The global economy needs solutions to the developing issues that personal identity and authentication present. There are three major pillars to these solutions:

  • the role of the individual
  • establishing trust with organisations
  • handling the online experience.

To review or define an internal solution we should cover these three essential points. Covid has had a major impact on the way we live our lives and the ability to conduct in-person transactions has been transformed. Individuals are forced to navigate a remote and brutal online environment whilst establishing their identity. They are subject to ransomware and continual threats. This transformation is fast-paced and is requiring a strong degree of trust with sharing personal data with organisations and authorities. Clearly, there are inherent risks with online interactions and the sharing of personal data and the traditional ways of handling these are no longer fit for purpose.

ABOUT THE AUTHOR

Dario Betti is CEO of MEF (Mobile Ecosystem Forum) a global trade body established in 2000 and headquartered in the UK with members across the world. As the voice of the mobile ecosystem, it focuses on cross-industry best practices, anti-fraud and monetisation. The Forum provides its members with global and cross-sector platforms for networking, collaboration and advancing industry solutions.  

Web: https://mobileecosystemforum.com/

Twitter: https://twitter.com/mef

LinkedIn: https://www.linkedin.com/company/mobile-ecosystem-forum

Facebook: https://www.facebook.com/MobileEcosystemForum/

Related Posts:

  • Steps for ensuring that your processes keep up with…
  • Top vegan trends for Veganuary 2021 and beyond
  • Ways for improving business processes and profitability

Filed Under: Technology

Recent Posts

Boosting Business by Training Paralegal Employees

Boosting Business by Training Paralegal Employees

Whether it is drafting employment contracts or ensuring that debts are chased and collected, it is very likely that someone on your team will be performing tasks with a legal element to them. This requires an element of expertise. Of course, staff can be trained to systematically do the job, but would it not be […]

Whatever Your Décor, Make Your Hotel Greener

Whatever Your Décor, Make Your Hotel Greener

If you are running a hotel, there is no excuse for not being aware of the increasing importance customers put on green credentials. Almost a decade ago a TripAdvisor survey warned that two-thirds of travellers take environmental issues into account when choosing hotels, transportation and meals. [1] Since then, pleas for the planet from the […]

Picking The Right Architect Is Essential For Your Small-Scale Property Development Project

Picking The Right Architect Is Essential For Your Small-Scale Property Development Project

The most important thing you will need to do to successfully complete a small-scale property development project is putting together the right team for that project. Just because one person was good for a previous project doesn’t mean they will be good for every project. This is something that applies particularly to architects.  I once […]

Categories

Speedie Consultants Ltd
10 College Gardens
Westgate-on-Sea
Kent
CT8 8EY

Registration number: 4797388.
Telephone: 01843 831088
Email: enquiries@speedieconsulting.co.uk
Website: www.speedieconsulting.co.uk

© 2022 Small Business Insider

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish.Accept Read More
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT