Today’s organizations depend and thrive on data for marketing, customer service and staff management, and like anything that is valuable, criminals have been seeking it to commit ID theft, blackmail or other crimes.
The 2009 Identity Fraud Survey Report by Javelin Strategy and Research reports that the number of identity fraud victims has increased 22 percent to 9.9 million adults in the U.S., while the total annual fraud amount increased by seven percent to $48 billion over the past year. The reasons include profitability, safety and simplicity, explains Greg Young, research vice president, Gartner.
To limit ID fraud U.S. Federal Trade Commission requires financial institutions and creditors to comply with its new Red Flags; after much delay enforcement begins Nov. l, 2009. The regulations mandate these firms to implement programs to identify, detect, and respond to the warning signs, or “red flags,” that could indicate identity theft.
Unfortunately firms have been launching new data-using processes without having the tools in place to adequately protect users and themselves.
“The business uses of data have gone far beyond what the security architectures and procedures are designed for and these have not caught up,” explains Young. “There is a disconnect between what businesses do and intended to do with data and what security fence system is in place to enforce those policies.”
Also companies have been erring in favor of not inconveniencing customers as opposed to security such as asking for authentication through passwords and answers to challenge questions. These methods have become more difficult because the secrets used for authenticating users via passwords are readily available. This matter comes to a head with contact center agents who face annoyed buyers on the phone and who have to keep handle times short.
“There is a line between customer access and customer service that is tread more often than not…