Friday, October 14, 2011

Secured with spit - Post Office insists letters are safer than email

It's not easy being a Post Office nowadays! Globally, postal services are being adversely affected by the changing communication preferences of consumers - the state of the United States Postal Service (USPS) highlights this issue very clearly.

The USPS lost a staggering US$8.5 billion in 2010 – that's $25 million each day. While a portion can be blamed on excessive retirement and health benefit payments, the fact is that postal mail volume has decreased by 50% over the past 10 years. This is due to the rise of email and other electronic messaging options that suit our modern lifestyle better. Sure, we probably all appreciate the sense of occasion when we receive a personal letter, but how many of us are willing to take the time to actually write one?

 

Snail mail more secure than email?


Postal services are now looking at how they can adapt to the evolving communications paradigm; searching for a niche they can fill to keep the business afloat; looking for ways to turn the tide on electronic communications. Recent internet security scares have provided a straw for USPS to grasp at and their recent advertising campaign has focused on the safety and security of snail-mail; "A refrigerator [with a paper bill stuck to it with a magnet] has never been hacked," they tell us. Some USPS executives suggest focusing on the hand delivery of documents too sensitive to be entrusted to email.

Certainly web-portals can be hacked and so, there is concern that phishing attacks can compromise the security of such sites. Such security breaches can be on a massive scale, as has been recently observed. But how about secure email delivery of bills and statements, policies and other sensitive documents?

 

It comes down to 256-bit encryption vs. the trusty postman


The delivery of password protected, encrypted documents via email is fundamentally the safest, most secure option. Why? Because there is no central repository to hack into, and should the email somehow fall into the wrong hands, 256-bit encryption ensures that it can't be opened without the password. How long do you think a hacker would be prepared to spend to open just one eBill or eStatement, with no facility to go any further once he's "in"?

And the idea that human involvement in the delivery process is more secure than using electronic channels, is also flawed. Here in Hong Kong, we have an excellent Post Office, but in the past two weeks, I've had two letters delivered to my house by mistake. One was a credit-card bill addressed to someone in the next village – the postman clearly misread the address, and the other was an insurance policy, where the recipient name wasn't mine, but the address was – a data error at the insurance company. In both cases, I'd opened the envelopes and read the documents before I'd realised they weren't for me. In the electronic world, the credit-card statement would never have been sent to me because email servers don't "misread" email addresses, and had I received the insurance policy due to a data entry error, I wouldn't have been able to open it without the required password.

So, while I feel for the plight of the Post Office and I enjoy the friendly wave from my postman as he does his rounds, running a PR and Marketing campaign that smears email security and focusing on the delivery of sensitive documents isn't going to provide the necessary lifeline to stop the decline in postal figures.

I don't have the answer to the Post Offices' problems, but I suggest the following: if you're looking to deliver documents to your customers, sensitive or otherwise, perhaps you should consider the following questions:

  • What is the fastest method of delivery available?
  • What's the most cost-effective method of delivery?
  • What level of security is required to ensure the safety of the data being delivered?
  • What can I do to encourage my customers to adopt the most appropriate delivery channel?

And if the answers aren't immediately clear, don't "go postal", just drop Striata an email - maybe we can help...

Keith Russell
striata.com

Thursday, September 29, 2011

What if your eBill could remind you to pay?

As an email marketing and billing provider, I choose to receive most communication by email, including the majority of my monthly bills (except for those vendors that don't offer email billing – SO 'last year'). Every month, when I open an electronic invoice to see how much I have to pay and by when, I end up manually creating a reminder in my calendar, so as not to miss the payment due date and potentially be charged overdue fees. Or even worse, have my electricity or telephone cut off!

Now, I'm the first person to admit that I covet efficiency and the concept of a bill payment reminder would work really well for me. But there's no way I am going to use a web-based Bill consolidator to remind me, nor download an 'app' onto my desktop or mobile - even if it's free, it's just too much work for all my different billers. If I have to log into my Online Banking website to set a reminder (and many banks offer this) I might as well just schedule the actual payment. Hence none of these methods score highly on my efficiency gauge.

This got me thinking . . . what if the eBill itself could remind me - on the appropriate date?

All it takes is a 'Set Reminder' button on the eBill, which enables me to request a payment reminder by email or text. I can select how far in advance I want to be reminded and even an appropriate time of day.

What is sent to my inbox or mobile is something like this:

Payment Reminder: pay City Power the amount of $138.80 by 14/09/11.

What this means to me is avoiding the consequences of a missed payment, which is not only inconvenient, but it could also result in financial penalties or termination of service.

For the Biller, this means increasing the likelihood of receiving my payment by the due date, which for most businesses is an attractive proposition. I suspect Billers would even be happy to cover the minimal cost of the reminder message, as it would improve their DSO.

But the potential for efficiency and convenience doesn't stop there.


With the steady increase of consumers using the Internet and mobile technology to do things faster whilst on the move, it would be a smart 'next step' to enable payment directly from within the payment reminder.

Think about it - not only does the eBill remind you to pay, but you can pay immediately, with just one click or call. Now that's sexy!

The payment reminder for mobile (USSD) looks like this:

Payment Reminder: pay City Power the amount of $138.80 by 14/09/11. Dial *123*456# to pay.

And the email looks like this:

Payment Reminder: pay City Power the amount of $138.80 by 14/09/11. Click here to pay.

My efficiency gauge is going into overdrive!

Interested?


As a consumer, would you use a service like this?

And if you're a Biller, would you pay for the reminder notices?

Alison Treadaway
striata.com

Thursday, September 22, 2011

Dedicated IP or shared?

The effectiveness of your email marketing campaigns could be related to your decision to use either a dedicated or shared Internet Protocol (IP) address.

One of the key challenges of deliverability is achieving and maintaining an excellent sender reputation with ISPs and Webmail service providers. Your sender reputation is one of the deciding factors of whether to block your emails or let them through.

Sender reputation is associated with a sender's IP address – the theory is: if you have a good sender reputation your IP address can be trusted, which equals valid email and a higher delivery potential. There are many additional factors that can affect deliverability, but let's zoom in on the specific issue of dedicated vs. shared IP.

Understanding the implications of a shared IP address

If you are using an ESP to deliver your email marketing campaigns, it's likely that your emails are being sent from a shared IP address used by multiple clients on that system and infrastructure.

Sharing an IP address has many benefits, but there are certain risks too – which a reputable ESP should be managing on your behalf anyway.

The good and the bad of a shared IP address:

  • Good sender reputation is developed by consistently sending email, ensuring the bounce rate is kept low and the interaction is high (opens and clicks). If you are not a consistent email sender – sharing an IP enhances your sender reputation by leveraging off other senders on the same IP.
  • A good reputation is also derived by adhering to email best practice - benefitting you if these sound policies are adopted by all the senders sharing the IP.
  • The flipside of sharing is that you are at risk of other senders behaving badly and should the shared IP earn a poor sender reputation, your deliverability will be adversely affected.

If a shared IP is not desirable, then what do you need to know about a dedicated IP?

  • You have full control. Your practices alone determine the sender reputation of your IP address. There is no risk of others spoiling the party.
  • Unfortunately, the flip side of this is that you need to maintain regular volumes to keep your IP address 'warm', which can be difficult if you do not communicate with your database on a frequent basis (at least weekly – if not daily).
  • Over and above this, if you happen to slip up on the odd occasion and not adhere to best practice, you run the risk of putting your IP address under threat of blacklisting. You do not have the luxury of falling back on the good sender reputation achieved by others.

To sum up:

  1. You need to discuss the benefits of a dedicated vs. a shared IP address strategy with your ESP.
  2. Question their shared IP sender reputation and what proactive measures they are taking to keep their shared environments in good standing with ISP's.
  3. Your ESP should also consider your overall communication strategy and advise you on the best fit for your needs, rather than what is best for their needs.
Haydn James
striata.com