{"id":10906,"date":"2025-03-28T21:52:55","date_gmt":"2025-03-28T21:52:55","guid":{"rendered":"https:\/\/mena-fintech.org\/demo\/?p=10906"},"modified":"2025-03-28T21:53:13","modified_gmt":"2025-03-28T21:53:13","slug":"boardroom-session-on-payments-security","status":"publish","type":"post","link":"http:\/\/mena-fintech.org\/demo\/boardroom-session-on-payments-security\/","title":{"rendered":"Boardroom Session on Payments Security"},"content":{"rendered":"<h5><b>Outcomes, Recommendations &amp; Actions<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">On July 5, 2024, The <\/span><a href=\"https:\/\/mena-fintech.org\/\"><span style=\"font-weight: 400;\">MENA FinTech Association<\/span><\/a> <span style=\"font-weight: 400;\">convened a Payments Boardroom on the topic of <\/span><span style=\"font-weight: 400;\">Payments Security<\/span><span style=\"font-weight: 400;\">. This was part of the Association\u2019s Payments Working Group. Senior leaders from FIs, FinTechs, and venture gathered to discuss the critical topics of transaction security, anti-fraud, and cybersecurity (attendee list at the end of this document).<\/span><\/p>\n<h5><b>Context<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">The MENA region has been a pioneer in the adoption of payments security protocols, evidenced by the early adoption of 3D Secure, as well as the creation of government bodies (e.g., UAE Cyber Security Council).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, as is the case globally, payments in the region face unprecedented threats on both transaction security and cybersecurity fronts. This has been exacerbated by the rise in AI tools and increased sophistication of bad actors. The region is expected to increase its spending on security and risk management (SRM) to $3.3 billion in 2024, re\ufb02ecting a 12.1% increase from the previous year (<\/span><a href=\"https:\/\/trendsmena.com\/business\/mena-ups-cybersecurity-ante-to-combat-genai-challenges\/\"><span style=\"font-weight: 400;\">TRENDS Mena<\/span><\/a><span style=\"font-weight: 400;\">).<\/span><\/p>\n<h5><b>Speciffic Ecosystem Challenges<\/b><\/h5>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">People remain the weakest link:<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Despite massive investments and efforts towards customer education, individuals are still prone to falling for scams and sharing sensitive data.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">For example, in a Visa study, 56% of respondents expressed con\ufb01dence in being able to recognize fraud, however, in practice, only 10% could.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">This trend is equally true for digital native generations such as GenZ; they are likely to fall prey, often because of their expectations of speed and con\ufb01dence online.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Fraudsters have honed and premiumized their attacks, knowing which segments yield more.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Still not considered a shared responsibility<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">There is no clear\/proactive ownership and accountability in the industry when it comes to fraud and payment security. As a result, there is no strong, uni\ufb01ed effort to combat these threats.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">A classic example is that when fraud does occur, there is often blame-shifting between the multiple enablers in the transaction cycle.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bad actors have access to cutting-edge tools and collaboration techniques<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Given the increasing democratization of technology, fraudsters and scammers are able to deploy these tools for criminal purposes.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">One of these technologies is generative AI, which aids criminals in creating highly convincing fraud messages and deep fakes.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Bad actors are also known to collaborate globally. A classic example is a bad actor providing \u2018ransomware as a service\u2019 for other fraudsters.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h5><b>Increasing overlap between Cybersecurity and Fraud<\/b><\/h5>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">The industry is seeing a disturbing convergence between these threat vectors.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">For example, a cyber attack yields personal and payment information, which is followed by an attack on the card and transaction infrastructure to misuse these cards using with merchants, for example<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Know how to collaborate globally. A classic example is a bad actor providing \u2018ransomware as a service\u2019<\/span><\/p>\n<h5><b>Suggested Industry Initiatives<\/b><\/h5>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increased Ecosystem Dialog and Collaboration<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">The mindset needs to evolve away from liability rules to shared ownership of the solution.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Some industry associations have already begun to create regular meetings of Chief Information Security Of\ufb01cers to address threats facing the industry.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul>\n<li aria-level=\"2\"><span style=\"font-weight: 400;\">Action: The MENA FinTech Association will increase the frequency of hosting Boardroom and similar industry events on payments security.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Education of Younger FinTechs<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">It is observed that early-stage FinTechs often tend to deprioritize payment security. This can hobble them in the later stages, as their infrastructure may be deemed insuf\ufb01cient to work with a large FI.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Early-stage FinTechs should be educated to view payments security as not only as critical infrastructure but as a competitive advantage.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul>\n<li aria-level=\"2\"><span style=\"font-weight: 400;\">Action: The MENA FinTech Association will partner with specialized players to create an education program for younger FinTechs.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stringent Requirements for Chief Security Of\ufb01cers<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Participants commended the Bank of England\u2019s requirements for Chief Security Of\ufb01cers.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">For example, BoE mandates minimum quali\ufb01cations and support staff requirements for a CSO or CISO, which is audited annually.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">While such requirements increase the overheads, especially for smaller bank startups, they represent a sound investment in critical security infrastructure for the industry overall.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increased Public-Private Partnership on Threat Management<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">It is encouraging to see some public-private partnerships in the region such as Cyber Fusion Centers that allow real time action by multiple parties.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h5><b>Attendees<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">Akshay Chopra: 237 Ventures, MENA FinTech Association Imane Adel: PayMob, MENA FinTech Association Nameer Khan: Fils, MENA FinTech Association<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Gaurav Dhar: Marshal FinTech, MENA FinTech Association Charles Lobo, Visa<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Pati Murtazalieva, Sumsub Ani Sane, TerraPay<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Sailesh Malhotra, Geidea<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Ronit Ghose, Citibank, MENA FinTech Association Fernando Plaza, ADIB<\/span><\/p>\n<h5><b>APPENDIX<\/b><\/h5>\n<p><span style=\"font-weight: 400;\">Sumsub\u2019s Identity Fraud Report 2023<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Outcomes, Recommendations &amp; Actions On July 5, 2024, The MENA FinTech Association convened a Payments Boardroom on the topic of Payments Security. This was part of the Association\u2019s Payments Working Group. Senior leaders from FIs, FinTechs, and venture gathered to discuss the critical topics of transaction security, anti-fraud, and cybersecurity (attendee list at the end &#8230; <a title=\"Boardroom Session on Payments Security\" class=\"read-more\" href=\"http:\/\/mena-fintech.org\/demo\/boardroom-session-on-payments-security\/\" aria-label=\"Read more about Boardroom Session on Payments Security\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":10907,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[169],"tags":[],"class_list":["post-10906","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-boardrooms"],"_links":{"self":[{"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/posts\/10906","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/comments?post=10906"}],"version-history":[{"count":2,"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/posts\/10906\/revisions"}],"predecessor-version":[{"id":10909,"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/posts\/10906\/revisions\/10909"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/media\/10907"}],"wp:attachment":[{"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/media?parent=10906"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/categories?post=10906"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/mena-fintech.org\/demo\/wp-json\/wp\/v2\/tags?post=10906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}