Showing posts with label secure electronic document delivery. Show all posts
Showing posts with label secure electronic document delivery. Show all posts

Wednesday, March 2, 2011

Part III: Why & how email delivery is succeeding, where eBill Consolidators are failing:

My first two blog posts on this subject dealt with why consolidators here in the US will never work. In today's post, I cover the comparison between eBill / eStatement consolidators and true electronic delivery solutions:

There are five primary areas where email delivery of bills and statements succeeds, where consolidators have and will continue to fail.

1. Biller and consumer critical mass:


Why consolidators fail: To benefit consumers; consolidators should have the majority of a customer's bills in a central location. Due to the size of the US biller market this is simply impossible.To date, even mature consolidators that have been building a base for several years, have failed to exceed 20% of the average household's bills. The new entrants to this segment are yet to realize the futility of this endeavor.

On the flip side however, biller's won't subscribe to a service without a significant percentage of their consumers already enrolled. A true chicken and egg scenario.

Why email delivery succeeds: As the bill is delivered directly into the customer's inbox, it makes no difference whether it is one email bill or several a month. Just like in the physical mail scenario, getting one bill or many is just as convenient for both biller and recipient. Most importantly, it gives each and every biller the ability to deliver bills to their customers, without the need for a location to gather a critical mass of consumers.

2. Registration / enrollment:


Why consolidators fail: A recent survey conducted by InfoTrends showed that of the 1,042 consumers surveyed, 61% said that remembering multiple unique usernames & passwords remains a significant barrier to paperless adoption. Convincing the majority of consumers to register on biller's websites has proven to be an insurmountable marketing feat. For the consolidator however, it's even worse, as the customer has to have many pieces of information at hand for each biller at that location. Add to this the fact that consumers do not want another mailbox nor to have to choose and remember yet another username and password.

Why email delivery succeeds:
Quite simple - there is no registration process. The bill arrives in the customer's existing email inbox and is opened using a secure 'shared secret' (not a password, rather personal details known to the biller and the recipient). There is no need to choose or remember anything. There are also no marketing dollars required to drive the customer to sign up for anything.

3. Paper suppression:


Why consolidators fail: For a consolidator website to be considered successful at paper suppression by any biller, they will need to achieve suppression rates in excess of 10% per year, per biller. Currently statistics show that less than 5% of consumers enroll at consolidator websites and 50% of those still don't go paperless - the math cannot hope to add up.

Why email delivery succeeds: By delivering the bill or statement as a securely encrypted email attachment, the recipient can opt to go paperless with just one click - no form to complete, no website to visit, no username & password to complete, in fact, nothing to do at all except simply receive an email.

4. Bill stuffers / electronic marketing:


Why consolidators fail:
Due to the website nature of viewing bills at a consolidator, within a multi-biller environment and along with the fact that the biller does not have any ownership of the viewing real estate, marketing to consumers at consolidator websites is a considerable challenge, if offered at all. There is certainly no advanced personalization possible.

Why email delivery succeeds: It is automated and extremely cost effective to insert and overlay marketing messages into the body of an email, the white space of the bill and entire pages inserted into the secure attachment. Furthermore, this can be personalized down to the individual recipient, resulting in a bill marketing tool that is significantly more powerful than the paper bill, the biller's own website and definitely any consolidator.

5. Mobile:


Why consolidators fail: Navigating a mobile website or downloading an app is just inconvenient, a poor user experience and requires pre-registration. In addition, paying through a mobile website is an even worse experience than just viewing it. (To date no consolidators have offered a mobile option, but we believe that in 2011 there will be a first attempt.)

Why email delivery succeeds: An email attachment can be opened on any email capable device, without the need for the recipient to do anything. In addition, the same email will be waiting on the recipient's computer for viewing later. Payment can be initiated with just a single click.

And finally it is relevant to point out that where new consolidator entrants are in start-up / concept stage, secure electronic document delivery via email has been successful in 14 countries (including the USA) for 12 years, for more than 250 large Billers and Financial Institutions, including 3 of the top 10 banks).

When considering your paper suppression strategy, do you go with a new idea that has never worked before, but is at best a 'nice' idea, or do you chose a direction with a decade of referencable, proven success stories?

Garin Toren
striata.com

Thursday, October 7, 2010

Dispelling the myths around email security

In previous blogs I addressed the benefits of presenting electronic documents via self service portals / Internet banking websites vs. their inability to achieve paper suppression.

Whether you choose to deploy a 'Push' or a 'Pull solution; security and risk are key to determining a successful strategy. Today I want to address what makes a "push" eDocument delivery approach the better choice when weighing up the risk and security factors. But before I do that, let me dispel some myths about email security that I've recently heard mentioned.


Email security myths dispelled:

MYTH 1: Email can be stolen en-masse at an ISP: I've heard some winners in my 15 years in this industry but this takes first prize. Yes, email can be stolen at ISP's in the same way your money can be stolen at the bank by bank employees. I know a few ISP Executives who would take some affront at this accusation.

MYTH 2: Email can be stolen en-route: Email can be stolen en-route in the same way a USPS vehicle can be hijacked and your physical mail stolen. It’s possible but incredibly difficult, expensive and most importantly, a serious crime. Unlike a USPS truck however, for a fraudster to locate a specific email would be like finding a needle in a haystack the size of Montana. On top of which they then have to brute force attack the encryption (more time & money.) The result of which is then a PDF copy of one consumer’s bill or statement. The reality is that even if one knew how, it is simply commercially unfeasible to do so (far easier to simply hijack that truck or steal your mail from your postbox.)

MYTH 3: PDF attachments trigger spam filters: Simply not true. Spam triggers spam filters. And if you send spam with PDF’s then these will also be blocked.

'Push' eDocument delivery - the better choice

Striata has delivered billions of secure electronic documents for over 11 years, in 14 countries and for over 250 major Financial Services, Telecommunication, Utilities and Corporates, including 3 of the top 8 banks in the world.

From a security and risk perspective, 'Push' eDocument delivery is the better choice. As major players in this field, this is how we address it:

The Striata eDocument Delivery process has four security areas:

  1. Email Address Verification – Explicit knowledge that your customer email addresses on file are accurate and current. For those who aren't; we have the Striata Email Address Verification program, which uses email and mobile phone text messaging to confirm and gather email addresses.
  2. Striata eConsent – The process of gaining intelligent & compliant consent to go paperless, with just one click. Once the sender has an accurate and current email address, a highly personalized and Sender Authenticated eConsent email is sent to the consumer. There are two buttons in the email body, one to consent to go paperless and one to decline to do so – the recipient just clicks on one of them. There is no website to visit, no enrollment form, no choosing & remembering of usernames & passwords
  3. Striata Sender Authentication – The recipient has intuitive knowledge that the sender is who they purport to be. Other than the various technology elements like SPF Records. DKIM etc, Striata utilizes a multi faceted approach to creating this intuitive trust. These include:

  • Actual sender’s domain: The message comes from the sender’s address: for example. This should always be the actual address and not a spoofed one (if you had to do a reverse DNS lookup you would find the sender’s verifiable domain.)
  • Subject line: We include the recipient's name in the Subject line
  • Salutation: A full greeting is used: Dear Mr. John Smith
  • Striata Authenticated: In the body of the email is a highlighted area which contains two to five partial pieces of information about the consumer. This may include physical address, account number, primary phone number etc.

  1. Recipient Identification – The sender is assured that only the intended recipient has access to the secured Document content. There are two major ways (levels) that the sender is ensured that only the intended recipient can gain access to the secured information (bill, statements etc.)

  • Access to the email inbox: Email accounts are very well protected by physical access to a device or in most cases through a username & password.
  • Knowledge of a 'shared secret': In addition to the previous layer, Striata Secured PDF's are encrypted with a minimum of 128 bit RC4 encryption. The PDF is decrypted through recipient knowledge of a 'shared secret'. This is a partial piece of information known only to the sender and recipient. (Last 5 digits of a Social Security Number is a good example of this.)

It is very important that these two security layers are viewed hand in hand. The PDF is not in a publically accessible location and can only be decrypted by somebody who has BOTH access to the email account and who knows the 'shared secret'.

Peace of mind that the message is genuine

The combination of all of the above is what gives consumers explicit and intuitive trust (without any education) that the message is genuine.

In conclusion – when executed correctly, the processes and methodologies described above result in a security landscape that is significantly more secure than a two field password protected website. Most importantly however, is that these processes are many, many times more convenient for the end consumer, and, as we all know, convenience equals customer satisfaction.

Garin Toren
Chief Operating Officer, America
striata.com

Wednesday, June 30, 2010

Why I love and hate HSBC

When I moved to the UK I needed to open a bank account. So began a rigmarole that circled back into a catch 22 situation; you can't rent a property without a bank account and you can't open an account without a local address.

Bank after bank transferred my call to different departments; none of which could assist me in opening an account until I had formally arrived in the UK and lived at one address for more than a month.

HSBC rescued me with a limited function account that I could open with just a passport. I still needed to go to a branch to complete the paperwork, but I could evade the circular reference of not yet having a fixed address.

Falling in love with HSBC

But this is where I started to fall in love with my bank – the branch manager needed authorisation on the process and came down to meet me – I explained that I was moving to the UK and from that point on she took away all the bureaucracy and red tape. I communicated by email, scanned documents and as soon as I had a permanent address, my accounts were automatically converted to standard accounts without the limitations.

People often say that when dealing with their banks, they have just become a number. They call distant call centres and don't have access to a traditional bank manager. I guess this is true in many instances – banks have to be efficient and maintaining high touch, personal relationships is expensive.

I guess it depends on your branch, the manager and your circumstances, however I love HSBC.

The balance of love-hate

But I'm incredibly frustrated at the amount of paper that my bank produces. I hate that they say, "Go Green", but then send me paper for every transaction. I admit that I am not a 'run of the mill' client – but every foreign transfer into my account results in a letter confirming the funds. Every change of terms and conditions results in a small forest being sent through the mail.

I realise that the Royal Mail needs the work – but there are far more convenient ways to do this – secure electronic document delivery is no longer a black art.

Hands up everyone that would rather receive most of their post in an email ? Countless studies have shown that consumers, SMEs and businesses prefer email to paper.

Come on HSBC – put my email address as my primary contact point and just email it.


Michael Wright
Global CEO
www.striata.com

Wednesday, January 27, 2010

I DO NOT want another mailbox

It seems like every time I get another / new financial services provider, I get another mailbox.

Let’s be clear, consumers do not want additional mailboxes. It is complicated enough, keeping multiple email accounts in sync between work, home and mobile devices, especially as most of us have at least two accounts. (Some of us three or even six…..)

On top of these, we now have banks, credit card providers, eBill consolidators and telecommunications providers, all insisting that the only way they will communicate with us electronically is within their portal. I don’t know about you, but after receiving a cryptic message that some unidentifiable communication type is waiting for me, I have to navigate to a portal, remember a username & password and then find the well hidden message center to read the actual message. (5 clicks??)

Then to make matters worse, it is usually some inane, useless message that I wouldn’t have read in the first place. After my bank cried wolf the first 15 times, I simply started ignoring these messages completely and also turned the paper back on. It takes me 2 seconds to throw out useless bank paper mail.

After email, the only way to get my attention is to call me or send me a paper letter. If banks cannot reach a point where they can deliver email communication and eDocuments in a secure way that does not require me to jump through hoops to get them, then paper it is going to have to be.

This is the primary reason why paper suppression initiatives are failing here in the United States. Consumers wish to be communicated with in a manner that is convenient to them and until it is in the inbox, it is simply not.

Statements & bills: If you cannot find a way to send them to me electronically, then although I may pay them electronically (because that is more convenient for me), I will not turn off the paper bill.

Other communication / letters: If you cannot communicate with me in the channel of my choice – email, then sadly you are only left with paper / phone.

Bottom line: in order to change consumer behavior, you have to provide alternative solutions that are at the very least as convenient as the current one, but preferably more.

(PS – Nobody cares how ‘green’ paperless is if it's less convenient than the paper option. This is clearly shown by the fact that after 7 years of trying, 97% of all consumers are still getting all the paper they did before. In fact, now they are also getting all the paper communication about their online initiatives too.)

Garin Toren
Chief Operating Officer
www.striata.com