Payment Card Roll Call: “Not Present” fraud likely to increase as EMV takes hold

Payment Card Roll Call: “Not Present” fraud likely to increase as EMV takes hold

rollingballNo retailer wants to become the next Target (pun intended).  Payment card fraud costs businesses and consumers billions of dollars every year.  What’s even more frightening, many of the breaches in the news are the result of innocent participants inadvertently granting access to the bad guys.  The Target breach in 2013 exposed the data of 110 million payment cards.  Hackers got into the network using perfectly good credentials of the HVAC company.  Sometimes password security just isn’t enough, which might bring in to question the security of all those SaaS subscriptions and online shopping sites folks use these days.

EMV chip technology, the standard around the world which has just recently become a standard in the United States, has done a lot to stem the tide of credit card fraud in other countries.  As it was implemented in various countries, guess where it pushed the fraudsters?  Where the anti-fraud technology wasn’t, of course! The United States was among the laggards in requiring EMV chip technology for payment cards, opening the door for bad guys and turning the US into a veritable haven for credit card fraud, “accounting for nearly 50% of global fraud losses, according to the Nilson Report[1]”.

EMV chip (or chip and pin) technology will go a long way to prevent credit card fraud for businesses accepting payment cards… in-person and counterfeit card fraud, anyway. Online retail, on the other hand, not so much.  A chip on the card doesn’t really help when the transaction is completed with the card not present (CNP).  Some industry analysts suggest that CNP fraud losses will exceed $6 billion within the next few years, making e-commerce and online payment security a high stakes game for even the smallest of retailers.  As it gets more difficult to hack the payment system when the card is presented, bad guys will fall back in even greater numbers to the card-not-present model to find their victims.

Online retailers and service providers must take additional steps to secure their systems and protect customers and business partners, and face the challenge with the understanding that effort must be ongoing as new threats emerge. Tokenization is a prime method of layering the system with security, making the merchant system somewhat less of a worthy target by not storing the card data in the system.  Even if the system becomes compromised, the bad guys wouldn’t find customer payment card information.  There are numerous other steps a business can take to secure the CNP sales, including applying behavioral analytics which might identify rogue activities, or using 3D Secure to authenticate a cardholder’s identity at the time of purchase.   The point is that CNP fraud is likely to spike as EMV technology takes a firm hold in the US.

Card fraud is already escalating rapidly for ecommerce retailers and other card not present channels – it didn’t take EMV to start on that roll but it will surely give it a push.  Paperless payment systems, SaaS subscription services and online application service usage are increasing dramatically and there’s no chip to get in the way of these transactions.  Sellers of any and every service utilizing online payments need to now pay particular attention to system and information security.  The risk has always been there, and EMV chips and other shifts in pay card technology simply give it a push.

jmbunnyfeetMake Sense?

J

 

[1] Chipping away at Credit Card Fraud with EMV; Information Week Tech Digest powered by Dark Reading, Nov 2015; NilsonReport http://www.nilsonreport.com/publication_newsletter_archive_issue.php?issue=1071

Mobile Device Security is a Moving Target

Mobile Device Security is a Moving Target

mobile-devicesAs businesses mobilize their workforces and processes the volume and variety of sensitive data passing through and sitting on mobile devices increases dramatically.  Even though the business owner or IT manager may recognize the importance of mobile data and device security, doing something useful about it is altogether another issue.  New considerations enter into the picture frequently, turning mobile security into a moving target. Protecting the business – the organization, its employees and its customers – requires adopting mobile security strategies that cover a broad range of issues.

First of all, is there any means of monitoring the activities of the connected or mobile devices?  Knowing which devices are interacting with your information would seem to be an essential part of business information security, yet smartphones and tablet devices often fall under the proverbial radar of IT or business management.  Actually, business management is likely among the base of users with the very mobile devices in question.

Are there ways to limit what information is accessible via these mobile devices, and is that data encrypted?  Consider also that data is sometimes at rest (like when it is just sitting on a hard drive) and sometimes in transit (like being uploaded/downloaded/transmitted over the wire).  In either state, the data should be encrypted in order to be more secure.

Is there a standard set of apps or services that users can enable, or is it pretty much personal choice?  Too often a user will innocently install a malicious app on their device, exposing the business to a variety of potential threats.  Creating strict policies around app selection and use is a really good idea, and finding a way to actually enforce them is even better.

The big issue is separation of work and personal apps and content.  Especially in small businesses where personal devices are the norm (well, not just in small business… Hey Hillary!) it is quite a challenge to create any useful separation between personal and business use.  The mobile device is often adopted as a personal choice of the user – who elects to invest their personal mobile device in their work – so exacting any real level of control in how the device is used is tough.  The security of the information is only as good as the security of the device, meaning that it is usually up to the device owner to decide if a password or pin is required.  Unfortunately and for the sake of convenience, there is often little or no real security on the device meaning there is no real security around the information on the device in the event that it becomes lost, stolen or compromised.

There are a lot of things that the business can do in order to improve the security of their business data in a mobile device environment.  Here are a few of the basics:

  1. Have defined procedures for what happens when a device is lost or stolen; make sure they’re followed
  2. Have a way to do a remote wipe of the device
  3. Make sure all devices lock after a period of inactivity, and that they have password or pin protection
  4. Have a mobile device use policy, and make sure all employees understand why it matters and agree to it.

jmbunnyfeetMake Sense?

J

The Cloud, The Desktop and QuickBooks

subtitle: Just When They Told You the Desktop Was Dead… 

along comes another desktop app.

Everything is moving to the cloud! Everything is going online!  At least, that is what they’re telling you.  And, to a certain extent, it is true that a lot of things are moving to the cloud; just not everything.  And some of what has moved in is moving right back out.  Use of the cloud and cloud services is increasing, but that certainly isn’t proving that the desktop is going away anytime soon.  The only thing we can be certain of is that things are going to continue to change fairly rapidly, yet the lion’s share of business users will retain working models they have come to trust and rely upon until they are forced to do something else. Today, many accounting and business professionals feel that they are being forced out of the software they have known and worked with for years: QuickBooks desktop software.

I was recently asked to present to a group of accounting and tax professionals, the topic being “alternatives to QuickBooks Online”.  I thought it was interesting that this would be a topic of such interest, as QuickBooks has long been recognized as the market leading application for small business bookkeeping and accounting.  Accountants and bookkeepers, as well as tax professionals, have worked with QuickBooks for years – many having even styled their practices around the QuickBooks brand and offering QuickBooks-specific training and other services.  Why are these professionals now asking to learn about alternatives?  Well, it is an alternative to the online version of QuickBooks that these folks are seeking, and they have been given the impression that the desktop editions of their beloved QuickBooks are no more and their businesses are being forced to change.

Due to Intuit’s focus on promotion of the QuickBooks Online edition as THE  QuickBooks to buy, there is a growing belief that the desktop products are going away.  Many professionals who have worked with the product line for years are now operating under a belief that their only future with QuickBooks is with the online edition, so they are searching for alternatives for their clients and their own practices.  The QuickBooks Desktop editions aren’t being eliminated (2016 editions and certifications coming!), but any real mention of them in the direct marketing is gone, because Intuit isn’t pushing these solutions to new customers. It is no wonder the accounting and tax pros are looking at alternatives – and their customers are, too.

QuickBooks has always been a direct-to-consumer solution and was pretty much the only thing a small business owner would find if they shopped for software at the local computer or office supply store. The high-value desktop editions continue to be available, but it is difficult to tell a business owner they need to purchase licensing and then pay for mobility for QuickBooks desktop editions while QBO sounds much cheaper and they can get it on their tablet or PC for that cheap price. Also, there is more shopping online – from phones and tablets as well as PCs – so consumers are being exposed to other brands and the plethora of new online solutions. Now that they are considering buying or changing accounting/bookkeeping software… they could just as easily elect to use something completely free and not spend anything with Intuit or anybody else.

The small business owner isn’t focusing on the qualities of the accounting solution or how it impacts their accounting professional’s processes – they are focusing on monthly price of the solution.  Accounting professionals are now recognizing that the software isn’t (or shouldn’t be) the basis for their practices, it is simply a tool.  And there are a LOT of tools available to work with, not just QuickBooks, so the value of aligning solely with that solution is perhaps not as good an idea as it once was, but it is not gone.  There is still a tremendous volume of work to be done with businesses using the QB desktop products – you just wouldn’t know it from the marketing hype around QBO.

The thrill of exploring SaaS (software-as-a-service) and online application models has introduced new competition in markets where the dominant player once felt secure (small business accounting, for example).  While Intuit’s QuickBooks products were a defacto standard and essentially owned the smb accounting market, the diminished response to the QBO product has created opportunity for many newcomers.  Xero, for example, has been able to make great progress, even recruiting long-standing QB ProAdvisors as Xero advisors and promoters.  gnuCash, once a bit of an outlier, is getting new business because it IS desktop based (some people like that!) yet it doesn’t require an an ongoing commitment to internet connectivity or to pay fees to the developer. NolaPro, Wave, Freshbooks and more are growing in popularity as more freelancers and small business owners begin using applications other than spreadsheets to manage their business finances.  The generation that grew up with online banking is now readily adopting computerized bookkeeping, but they aren’t necessarily interested in QBO.  Still, a great many move to QuickBooks desktop editions because QBD is a recognized and respected solution.

It also remains to be seen what happens with usage of some of these online smb accounting solutions when the business reaches some size or complexity.  While they may be highly useful for startup or freelance business, many are not likely to satisfy business requirements far into the business lifecycle.  This is when the going concern and growing business demands more functionality and performance, which often becomes the catalyst for seeking faster and more powerful software and systems and has been a driving force for businesses returning to locally-installed or hosted accounting and ERP solutions.  Along with QuickBooks desktop editions, Sage is positioned extremely well here. The Sage 50 solutions (good old Peachtree!) can scale and also have very strong accounting functionality.  These were actually the preferred solutions for most accounting pros for a time, but the momentum of QuickBooks pushed them to the side.  With the attempt to now leverage the QB user base to the QB Online solution, Intuit has created the opportunity for Sage to regain a position with accounting professionals and their clients who demand more.

As these software and systems have (in some part) migrated from the local infrastructure to the web, we have also seen a lot of hybrid or “tweener” approaches come about.  These approaches, just as cloud service of any type, come in many varieties and exist to solve different problems.  The problem of browser-based functionality and modality is among the issues identified with QBO.  The browser-based app doesn’t allow for multiple operating windows – you have to use browser functionality for that.  And it is relatively slow – performing data updates and screen refreshes like with a website and not as one would require of a business application.  The solution provided is a great example of a hybrid approach.  The desktop app for QuickBooks Online (yeah) is a software app that comes in a flavor for Windows and Mac, and which provides more of a desktop user experience even though it mimics the interface and connects to the data of QBO.  It is faster, and multiple windows can be used, and more… which are some of the great benefits of running software on the local device and why desktop software is so great a performer.  This hybrid model simply allows for desktop software to work with cloud-stored data and back-end processes, and potentially delivers some of the best of both technology models: cloud and localized.

If you consider how much of the actual QuickBooks desktop product has been turned into web service (payroll, merchant processing, etc), it seems like QuickBooks desktop is already beginning to be a bit of a hybrid approach.  And when QB desktop is run with a hosting service provider, the whole thing becomes available anytime/anywhere.  Hosting is the way to provide the management and mobility aspects of QuickBooks and other desktop software.  The hosting model delivers benefits of cloud service – providing users with all the features and functionality of the desktop solution – and introduces the system management and mobility that is part of the underlying value of a web-based or SaaS application approach.

The real discussion, I believe, is not about the death or  near death of the desktop and locally installed applications – that’s just silly. Even phones are now being touted as possible desktop replacements, as the processing and storage capacity has increased to rival the most useful portables and laptops.  Clearly, devices continue to be more powerful and capable, and these advancements aren’t done solely to make web browsing more enjoyable.

pendulumDevices are more powerful so that they can run more applications – fast – and deliver more useful functionality to the user. Maybe the data will be in a cloud, and maybe even some app functionality will be delivered via a cloud, but it is very unlikely that everything will be in the cloud.  Complexity and cost drove developers to seek out alternatives, and advancements in technology will introduce new options that change everyone’s thinking again.  While the pendulum did swing to one extreme (move it all to the cloud and off the device!), we are now seeing it swing back  in the other direction a bit and those who didn’t swing all the way the first time are in a position to reap some benefit.

Joanie Mann Bunny FeetMake Sense?

J

 

Confused about QuickBooks and the Cloud? Join the club

cloud-computingIn most regions around the country high-speed broadband is readily available, and using the Internet for working and playing online is a part of everyday life.  Facebook and Twitter and Instagram are household names and just about every conversation starts or ends with a reference to a meme.  It seems that everyone is connected and app-savvy, using high technology while doing business, doing homework, or doing just about anything.  Yet this move to online and cloud technologies has come with a high price tag for some businesses, especially small businesses trying to keep up with the pace of change and who are being encouraged to adopt just about every new thing that comes their way.  It’ll make them more efficient, more profitable, more attractive to customers, more interesting to prospects, and will allow them to do more in less time.  All of the “apps” for this and that have created a great deal of confusion for the average small business owner who may need a few tools to help get business done, and who is now facing the daunting task of figuring out which ones to use as the type and number of tools grows exponentially every day.  It used to be so simple, but now even the simple things are becoming difficult to understand – like QuickBooks, for example.

QuickBooks desktop editions, born from Quicken personal finance management software, continues to be the most popular small business bookkeeping solution available.  Yet QuickBooks is now offered as either desktop application (software you install on your PC), as a hosted solution (software installed and run on service provider systems and which you access via the Internet), or as an online application (QuickBooks online edition).  Initially, the lines were fairly clearly drawn – the desktop software gets installed on the local machine and the online edition runs from Intuit’s servers.  Then things got a bit more complicated as hosted services rolled out, and users were able to have their desktop QuickBooks managed with a service provider and accessible via an Internet connection.  Now, just to add to the confusion, Intuit delivers a new desktop app to access the online version of QuickBooks.   What?!  Yeah, you heard me.  There’s a desktop app to install to the PC (97MB!) that accesses the QuickBooks online system.

When Intuit, like to many other software companies, began pushing the online-only version of their solution, the messaging was all about making life easier with “no software” to install or manage.  Customers could simply sign up and have all the features and capability they need using only the browser on an Internet-connected machine.  Failing to consider that computing devices (PCs, tablets, phones, et al) continue to get smarter and more powerful each day, the software companies firmly believed that everything would eventually be on the Web, and the “access device” wouldn’t matter any more.  However, things haven’t turned out quite as planned, and users continue to not only demand desktop and device-based apps, they will often forgo the browser-only approach until a better app and interface comes along.  The truth is that the market wants apps and software running on their devices because the user experience and performance is almost always better than with a purely browser-based approach.  Browsers are great for visiting websites, but not so much when it comes to running business applications.  Sure, there are a lot of browser-based solutions out there, but not too many of them are as trusted or as heavily used as their desktop-based counterparts or competitors.

There is little argument to be made regarding the fact that many software developers are working towards entirely online application models, where little or no software would exist on the device and all data is managed and stored online.  What is arguable is whether or not the “fully online” model will ultimately win, or whether software will continue to be installed and maintained on the device.  Performance, functionality, integration with other applications, and usability will all influence the buyer’s decision regardless of the marketing hype.  It may simply be that users will have to try each model before they decide which one works best for them.  It seems that, with the introduction of the desktop app for QuickBooks Online, the QuickBooks-users club has voiced an opinion which sounds a lot like they liked the desktop software approach best.

Joanie Mann Bunny FeetMake Sense?

J

 

Formula for Success: The Cloud and a Pair of Bunny Slippers

Formula for Success: The Cloud and a Pair of Bunny Slippers

drawn-bunny-slippersInformation technology and the “cloud” is amazing.  With the right IT resources and connectivity, individuals and small businesses are able to compete at global levels with much larger organizations, and are proving that placing focus and attention on the right aspects of the business helps the business perform better. The right IT approach is to use technology to make the business smarter so more gets done in less time and with fewer resources – this is wearing the bunny slippers.  The goal is leveraging systems, software and connectivity to be more efficient and effective, creating the time to stop and think for a while, innovate, or simply relax.

Too often the business owners or managers are tending to computers and systems which simply support status quo and aren’t spending their quality time growing and managing the business – getting more clients, creating new products, rising above the competition. Cloud computing models play a big part in changing that standard, supporting new levels of business sustainability and supporting process improvements never before imagined.

Cloud computing is now integral to many business technology models because the potential benefits are great.  Cloud computing solutions and outsourced information technology management allow businesses to focus on what they do best, and  not on the IT supporting it. These solutions and services are in high demand because they allow businesses to scale easily and affordably, paying only for what is needed at the time.  Improved collaboration and centralized access to applications and data make cloud computing models an important consideration for every business.

I’m not the only one who recognizes how beneficial the right IT approach and anytime/anywhere access can be. Others have recognized the freedom and flexibility these new technology models have enabled… and know the value of a pair of bunny slippers.

Joanie Mann Bunny FeetMake Sense?

J

Doing Business In Bunny Slippers Around The Globe.

Susan Solovic

When I first started my business, like many start-up operations, I decided to work from home.

I equipped an empty bedroom with a card table for a desk, cardboard boxes for filing cabinets and my dogs served as my office assistants. Voila! I was ready to roll, and it was great.

I could go to work in my fuzzy pink robe and bunny slippers. After all, no one other than the dogs would know.

Start-up business operations are always strapped for cash. It’s much less expensive to conduct business from your home than to rent commercial office space. And thanks to the Internet and technology home-based businesses can easily become international enterprises.

Read more at http://www.business2community.com/startups/doing-business-in-bunny-slippers-around-the-globe-01252506

 

 

To the EU and Beyond! Avalara acquires VAT Applications

To the EU and Beyond! Avalara acquires VAT Applications

Avalara, perhaps the best known and respected purveyor of sales tax compliance solutions in the US, has made another acquisition to expand their service line.  Just announced is Avalara’s acquisition of VAT Applications, provider of the iVAT suite of VAT compliance software and services. The iVAT solutions work for customers doing business in Europe and around the world, providing (among other things) cloud-based VAT compliance services for filing returns on all EU countries… in the required formats and languages.  By incorporating the iVAT solutions into the Avalara product line, the company extends its reach and capability to serve the global market.

To Infinity and Beyond! Buzz Lightyear from Pixar film Toy Story; image from wikipedia

To Infinity and Beyond!

While Avalara solutions are quite popular with US-based small businesses, the solutions are geared to work for businesses of virtually any size. iVAT solutions now take Avalara into EU and beyond, where VAT compliance is a necessity for enterprise as well as small biz (just as sales and use tax compliance is in the US).

Avalara has successfully acquired and incorporated several companies and solutions into its fold over the years, including EZtax, HotSpotTax, SuitePlus and Zytax.  This latest acquisition fills the cloud-based tax compliance solution line very well, and positions Avalara’s portfolio among the most comprehensive available anywhere.

Sales tax and VAT compliance is a big issue for business large or small.  Finding a solution that can not only address the business need, but that can serve businesses across borders and boundaries is essential in serving today’s global economy.  Even the smallest of businesses may find itself doing business internationally, selling to customers via the web often means crossing those lines and introducing new tax and compliance wrinkles and requirements.  Avalara addresses those business needs, and delivers solutions for the market whether it is local or global. It’s light years ahead of the rest.

jmbunnyfeetMake Sense?

J

 

Over 130 Marketing Tips in this Free eBook!Over 130 Marketing Tips in this Free eBook!.

I had the opportunity to contribute to this cool free ebook from Brother, sponsored by Small Business Trends.  Check it out.

it’s FREE!  🙂