Skip directly to search

Skip directly to content

 

Cyber Security Incidents in Australia Highlight the Need for a Balance Between Risk and Innovation

 
 

Payments | David Marsh |
23 November 2022

A series of high-profile cyber security incidents have dominated the media in recent months. Major brands have been compromised across health, telco, retail and real estate, exposing the data of millions of Australians and international students, including sensitive information such as passport numbers and medical details. The incidents present a timely reminder about the importance of a continued focus on security.

Banks and payment service providers have long been a target for fraudsters. According to the Australian Signals Directorate, Banks and Financial Services make up 4% of cyber security incidents (requiring ACSC assistance), which, while still concerning, compares favourably to other sectors. The payments industry has been an early adopter of cyber security threat mitigants, such as two-factor authentication, encryption and penetration testing. The resulting stability is one reason why banks have retained the trust of their customers.

As banks and payment service providers have shifted to close the gaps that hackers might target, consumers have become the weakest link in the chain. Criminals are looking to achieve their objectives by either scamming consumers into initiating payments or taking over a consumer’s identity to accumulate debt in their name. The Australian Competition and Consumer Commission (ACCC) estimates scams to be costing Australians $2 billion a year, but that figure is difficult to validate as consumers are often too embarrassed to come forward.

THE NEED FOR SECURITY REMAINS HIGH

A conversation going on at the moment relates to action initiation under the Consumer Data Right (CDR). Support for action initiation was recommended under the “Future Directions of the Consumer Data Right” review and endorsed in December 2021 by the Liberal government who were in power at the time. The recent spate of cyber security incidents has some in the industry concerned about potential risks.

A key feature of action initiation will enable an authorised third party to trigger payments from a bank account. In the ensuing consultation, the Australian Banking Association (ABA) submission calls out new attack vectors presented by such access. The ABA submission also calls for clarity in regards to liability where a third party sits between the bank and the customer, preventing the collection of data points that are normally used as part of a risk assessment.

Endava recently surveyed over 1,000 global non-bank organisations on their finance and payments strategy. The results highlight that security remains front of mind for organisations:

Figure 8 from Endava 2022 Global Payments Report, showing “Fraud and security issues” as the top payment issue or challenge the surveyed companies experienced.

Figure 10 from Endava 2022 Global Payments Report, showing “Controlling data security” as the top challenge in international payments the surveyed companies experienced.

Figure 12 from Endava 2022 Global Payments Report, showing “Secure” as the top benefit that the surveyed organisations report about their payments tools.

BALANCING RISK AND INNOVATION

If we look to the UK, where payment initiation has been available for some time, advocates point out that open banking payments avoid sharing sensitive card numbers and the risks associated with manual data entry. Meanwhile, critics highlight that the UK’s Payment Systems Regulator is consulting on mandatory consumer protection to minimise the impact of authorised push payment scams. Measures under consideration include reimbursing customers, which would presumably push up costs and may dilute some of the benefits associated with a basic account-to-account payment offering.

In Australia, regulation has traditionally played a role in protecting the interests of all participants in the payments ecosystem. Whether that be issuers, acquirers, merchants or consumers, regulation sets the rules each participant must abide by. In recent years, the number of participants involved in a single payment has increased dramatically. Digital wallets, payment orchestrators, BNPL services and other innovators form part of the value chain. With a more diverse set of stakeholders comes a broader set of perspectives.

Whilst it’s prudent to focus on risks associated with change, it is also important to recognise that many of the advances we have seen in payment technologies are a result of disruptive business models introducing innovation in payments. Without action initiation, some organisations have opted to use screen scraping technology to deliver payment services to customers. There are mixed views as to whether screen scraping should be permitted – but from a purely technical perspective, a robust set of formalised APIs would be preferable.

So, what is driving the need for third-party action initiation? Payments are just one component of the Consumer Data Right. It’s worth remembering that the initiative was designed to be an economy-wide framework. In the future, it might enable consumers to choose a trusted companion app or wallet that not only manages all their banking, telco, insurance and energy services, but also compares competing offers based on actual usage data and, with consent, switches services without the administrative barrier that impedes competition today.

Coupled with supporting legislation for Digital Identity, customers could be onboarded to those new services without the need to collect identity documentation at all, greatly reducing some of the risks that have been surfaced by the recent cyber security incidents. Interoperable Digital Identity is a separate initiative banks have stayed close to, with plans in the first instance to allow consumers to use their banking relationship to “vouch” for identity attributes.

CONCLUSION

If there is a takeaway from the recent cyber attacks and subsequent publication of sensitive information, it is that the loss of data may be as, if not more, damaging as the loss of money – and it cannot be resolved through re-imbursement.

Australia’s regulators have a good track record balancing the competing need for innovation with the requirement for security and stability, which is reflected in our nuanced payments regulation. Past examples include Australia’s Card-Not-Present (CNP) Fraud Mitigation Framework and a Consumer Data Right legislation that extends beyond the finance industry. The growing number of stakeholders will make this an increasingly challenging balance to strike, particularly from a timing perspective.

Next month, the Australian payments industry will come together at the industry association’s annual payment summit, aptly themed “Paving the way”. With reviews pending for the privacy act, licensing, crypto asset regulation and action initiation, industry participants will be looking for insights on when and where some of these issues might land.

David Marsh will be speaking on the “Future of Payments” panel at the AusPayNet Summit 2022, alongside representatives from Visa, NAB and Stripe.

You can find more insights in the Endava 2022 Global Payments Report.

David Marsh

Principal Industry Consultant

With over 13 years in the payments industry, David’s career has been centred around innovation, transactional banking integration, and technology. Having worked with government clients, corporates, and the industry association for payments, he brings broad experience and a hands-on perspective to challenges and opportunities in the payments space. Away from work, family commitments permitting, David enjoys mountain biking, bouldering and DJing.

 

Related Articles

  • 05 December 2022

    An Australian Eye on the Global Effort to Improve Cross-Border Payments

  • 23 June 2022

    A Payments View on Marketplaces – How to Be(come) Successful

  • 22 February 2022

    4 Buy Now Pay Later Trends Set to Disrupt the Industry

  • 14 September 2021

    Once Upon a Time … in Payments

  • 16 September 2020

    MPE Summer Week Recap – a Seismic Shift in the World of Payments

 

From This Author

  • 30 January 2023

    G’day, I’m David Marsh

  • 05 December 2022

    An Australian Eye on the Global Effort to Improve Cross-Border Payments

  • 23 March 2022

    Real-Time Payments in Australia – Why Corporates Should Get on Board

Most Popular Articles

An Anatomy of the Data-Driven Retail Supply Chain
 

Transportation & Logistics Insights | Jeremy Eaton | 25 May 2023

An Anatomy of the Data-Driven Retail Supply Chain

BNPL Regulation to Protect Consumers and Control Third-party Lenders
 

Banking | Annmarie Mahabir | 23 May 2023

BNPL Regulation to Protect Consumers and Control Third-party Lenders

How Offer and Order Management Systems Are Expanding The Aviation Business Model
 

Mobility | Joachim Zintl | 17 May 2023

How Offer and Order Management Systems Are Expanding The Aviation Business Model

Salut! I’m Adriana Calomfirescu
 

Meet the SME | Adriana Calomfirescu | 16 May 2023

Salut! I’m Adriana Calomfirescu

Hi, I’m David Boast
 

Meet the SME | David Boast | 15 May 2023

Hi, I’m David Boast

The Business Impact of Fan Engagement: How to Leverage Technology to Improve Loyalty
 

Innovation | Robert Milner | 12 May 2023

The Business Impact of Fan Engagement: How to Leverage Technology to Improve Loyalty

Staying Relevant – Why Merchants should Embrace Alternative Payment Methods
 

Payments | Steven Purton | 09 May 2023

Staying Relevant – Why Merchants should Embrace Alternative Payment Methods

How IoT is Changing Insurance
 

Insurance Insights | Vince Francis | 02 May 2023

How IoT is Changing Insurance

A Veteran Game Developer's Perspective on Tool Development
 

Automation | Thomas Bedenk | 26 April 2023

A Veteran Game Developer's Perspective on Tool Development

 

Archive

  • 25 May 2023

    An Anatomy of the Data-Driven Retail Supply Chain

  • 23 May 2023

    BNPL Regulation to Protect Consumers and Control Third-party Lenders

  • 17 May 2023

    How Offer and Order Management Systems Are Expanding The Aviation Business Model

  • 16 May 2023

    Salut! I’m Adriana Calomfirescu

  • 15 May 2023

    Hi, I’m David Boast

  • 12 May 2023

    The Business Impact of Fan Engagement: How to Leverage Technology to Improve Loyalty

  • 09 May 2023

    Staying Relevant – Why Merchants should Embrace Alternative Payment Methods

  • 02 May 2023

    How IoT is Changing Insurance

  • 26 April 2023

    A Veteran Game Developer's Perspective on Tool Development

  • 24 April 2023

    How Digital Ecosystems Enhance the Healthcare Experience

  • 21 April 2023

    Green machines: how tech can help companies hit Net Zero targets

  • 20 April 2023

    The Role of People and Technology in the Future of Underwriting

  • 19 April 2023

    Media 2030: Why Advertisers and Publishers Are Racing To Find New Strategies

  • 18 April 2023

    Alright, I’m Adrian Sutherland

  • 14 April 2023

    How Synthetic Data Could Solve The Patient Privacy Dilemma

  • 11 April 2023

    Payments makes the world go round! How banks can get creative

  • 06 April 2023

    Higher Fidelity: Good Outcomes and Harnessing the Challenge of FCA's Consumer Duty

  • 05 April 2023

    AI in Pharma: How Machine Learning is Revolutionising Every Step in Drug Development

  • 04 April 2023

    Hello! I’m Leane Collins

  • 31 March 2023

    The Dos and Don’ts of Successful Carve-Outs in Private Equity

  • 30 March 2023

    Cage of Reason: FCA's new Consumer Duty heralds the rise of the 'Reasonable Insurer'

  • 28 March 2023

    A legal view on the ownership and future of AI-generated works

  • 24 March 2023

    Championing Women in Tech

  • 23 March 2023

    5 Ways Capital Markets Firms Can Ensure Resilient Operations to Improve Credibility and Efficiency

  • 15 March 2023

    Buenas! I’m Leticia Chajchir

  • 14 March 2023

    4 Ways to Improve Customers’ E-Commerce Search Experience

  • 28 February 2023

    4 Healthcare Innovations That Can Benefit People and Profit

  • 21 February 2023

    Hey, I’m Lewis Brown

  • 17 February 2023

    Top Considerations for Financial Services Providers Entering the Cross-Border Payments Space

  • 13 February 2023

    Better Together: Harnessing the Power of Digital Ecosystems

  • 09 February 2023

    What to Include in a Customer Re-Engagement Content Library

  • 07 February 2023

    Supercharging Wealth Management with Hyper-personalisation

  • 02 February 2023

    How Innovating the Insurance Customer Journey Creates a Competitive Advantage

  • 30 January 2023

    G’day, I’m David Marsh

  • 26 January 2023

    Empowering Underwriting and Unlocking Revenue with Legacy Insurance Data Sets

  • 24 January 2023

    Four Stakeholders Who Win the Most When Healthcare Innovates

  • 23 January 2023

    Journey to the Centre of the Cloud with AWS – Part 3

  • 20 January 2023

    Journey to the Centre of the Cloud with AWS – Part 2

  • 18 January 2023

    Journey to the Centre of the Cloud with AWS – Part 1

  • 17 January 2023

    The 4 Most Common Mistakes in Retail Site Design

  • 13 January 2023

    Boost and bolster your innovation. Three tips to help get it to the next level.

  • 10 January 2023

    5 Questions in Smart Energy That Will Define the Net Zero Transition

We are listening

How would you rate your experience with Endava so far?

We would appreciate talking to you about your feedback. Could you share with us your contact details?