Peter Nicolas Zavlaris's blog post was featuredHealth Insurance Firmly in the Cross HairsPremera Blue Cross is the latest victim of what appears to be a long-term APT perpetrated by China. Between CHS, Anthem and now Premera Blue Cross, it’s now safe to say health insurance is firmly in the cross hairs of powerful nation state actors.Brian Krebs from krebsonsecurity.com reports,Premera Blue Cross, a major provider of healthcare services, disclosed today that an intrusion into its network may have resulted in the breach of financial and medical records of 11 million customers. Although Premera isn’t saying so just yet, there are indicators that this intrusion is once again the work of state-sponsored espionage groups based in China.The indicators are the similarities between methods used, according threat intelligence gathered by ThreatConnect. Jeremy Kirk from cio.com explains that ThreatConnect discovered a similarly "mis-typed" domain called "prennera.com" tied to malicious infrastructure connected to Deep Panda, the group that breached Anthem.In Anthem’s case, the URL was ‘"we11point.com", a spoofed version of "wellpoint.com" (Wellpoint eventually became Anthem). The URLs are embedded in emails and sent to employees. Behind the URLs is malicious infrastructure that phishes for information like login credentials or spreads data-stealing malware.In the Anthem attack, subdomains referencing internal services used by employees were discovered. The purpose was clearly to spoof services into visiting the malicious domains. By "typosquatting" URLs that closely resembled official domains, the malicious emails could bypass email filters.Further obfuscating the malware was the use of digitally signed software certificates from a Korean based company called DTOPTOOLZ Co. This ties back to a RAT (remote access tool) called Derusbi, which is a known Deep Panda tool.If it is indeed a Chinese APT group, the scary question remains: Why is China so interested in our personal records? Selling the data for profit is an unlikely motive. Plus, to date no one has seen any evidence that the data stolen from CHS, Anthem and now Premera Blue Cross has appeared on the black market.However, having someone’s PII in combination with his or her login credentials grants an attacker access to pretty much everything. PHI (personal health information) can tell you if someone suffers from an embarrassing ailment or has physical vulnerabilities you can exploit. While cyber thieves are after money, nation states are after bigger game.Thus far, Deep Panda’s methods have been relatively low-tech. They use easy-to-access commercial malware and SPAM. The key to their success appears to be their ability to bypass email filters using well-crafted fake emails and recognizable domains.This is a serious threat. Large organizations receive millions of emails per day, and only a tiny percentage of them may be malicious. No matter how effective email filters become, malware is still getting through.CISOs responsible for protecting PII and PHI and looking to stay one step ahead of their adversary need greater visibility. When domains are registered that spoof those belonging to their organization, CISOs and their teams need an automated way to detect and test them to determine if they’re malicious. Just as attackers' tactics evolve, so must enterprise security intelligence.Peter Nicolas Zavlaris is the resident blogger for RiskIQ.See More
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:19am</span>
To help more of our readers with their crucial conversations, confrontations, and behavior change challenges, we recently introduced our new Community Q&A column! Please share your answers to this reader’s question in the comments below. Dear Crucial Skills, When I began dating my husband five years ago, his kids and I hit it off right away and I even had a friendly relationship with his ex-wife . . . at first. After we got engaged things changed. The stronger my relationship became with the kids, the more she seemed to look for reasons to attack me. I have attempted to explain that I am not trying to replace her, but that I truly love her kids and want them to feel at home when they are at our house (we have 50/50 custody). She seems fine after we talk, but then she either ignores me or has a big, dramatic outburst and accuses me of trying to be their mom. I reached my breaking point when she chewed me out in front of the kids at a Little League game last week. How do I help her see that I only want what is best for the kids? Keeping the Peace Related Material:Making a Safe Switch to Crucial Skills Before & After: Making BIG Changes Kerrying On: A Disaster in the Making
Joseph Grenny   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:19am</span>
Babak Hodjat's blog post was featuredThe AI Resurgence: Why Now?Artificial Intelligence (AI) has been enjoying a major resurgence in recent months and for some seasoned professionals, who have been in the AI industry since the 1980s, it feels like déjà vu all over again.AI, being a loosely defined collection of techniques inspired by natural intelligence, does have a mystic aspect to it. After all, we do culturally assign positive value to all things smart, and so we naturally expect any system imbued with AI to be good, or it is not AI. When AI works, it is only doing what it is supposed to do, no matter how complex an algorithm being used to enable it, but when it fails to work--even if what was asked of it is impractical or out of scope—it is often not considered intelligent anymore. Just think of your personal assistant.For these reasons, AI has typically gone through cycles of promise, leading to investment, and then under-delivery, due to the expectation problem noted above, which has inevitably led to a tapering off of the funding.This time, however, the scale and scope of this surge in attention to AI is much larger than before. During the latter half of 2014, there was an injection of nearly half a billion dollars into the AI industry.What are the drivers behind this?For starters, the infrastructure speed, availability, and sheer scale has enabled bolder algorithms to tackle more ambitious problems. Not only is the hardware faster, sometimes augmented by specialized arrays of processors (e.g., GPUs), it is also available in the shape of cloud services. What used to be run in specialized labs with access to super computers can now be deployed to the cloud at a fraction of the cost and much more easily. This has democratized access to the necessary hardware platforms to run AI, enabling a proliferation of start-ups.Furthermore, new emerging open source technologies, such as Hadoop, allow speedier development of scaled AI technologies applied to large and distributed data sets.A combination of other events has helped AI gain the critical-mass necessary for it to become the center of attention for technology investment. Larger players are investing heavily in various AI technologies. These investments go beyond simple R&D extensions of existing products, and are often quite strategic in nature. Take for example, IBM’s scale of investment in Watson, or Google’s investment in driverless cars, Deep Learning (i.e., DeepMind), and even Quantum Computing, which promises to significantly improve on efficiency of machine learning algorithms.On top of this, there’s a more wide scale awareness of AI in the general population, thanks in no small part to the advent and relative success of natural language mobile personal assistants. Incidentally, the fact that Siri can be funny sometimes, which ironically is technically relatively simple to implement, does add to the impression that it is truly intelligent.But there’s more substance to this resurgence than the impression of intelligence that Siri’s jocularity gives its users. The recent advances in Machine Learning are truly groundbreaking. Artificial Neural Networks (deep learning computer systems that mimic the human brain) are now scaled to several tens of hidden layer nodes, increasing their abstraction power. They can be trained on tens of thousands of cores, speeding up the process of developing generalizing learning models. Other mainstream classification approaches, such as Random Forest classification, have been scaled to run on very large numbers of compute nodes, enabling the tackling of ever more ambitious problems on larger and larger data-sets (e.g., Wise.io).Big Data is, of course, another driver of the recent investment interest in AI companies. Cheap storage, sometimes in the cloud, paired with the intuition by all manners of industry that collecting every piece of data possible will someday come in handy, has brought about a high demand for solutions that go beyond simple statistical analysis of data, and promise new insights and intelligence. The AI industry to Big Data is as petrochemical industry was to crude oil. We have the promise of doing more with the Big-Data crude than to simply burn it.Most recently, confidence in AI has risen to the point where hedge funds, traditionally weary of black-box approaches to trading, are also starting to explore the use of machine learning (e.g., Bridgewater).The financial boost from the recent investment in AI has led to a rapid expansion of the AI industry. More companies are looking to provide smarter solutions for their customers, and an explosion of new AI related companies that are looking to provide these solutions are emerging. Most industries that don’t want to be left behind are looking to employ AI in some form or other. The impact on industry has been broken down many different ways, but perhaps one of the best AI market landscapes I’ve seen is from Shivon Zilis, an investor at Bloomberg Beta. This is yet more evidence supporting the fact that AI is being applied in practically every industry possible, from Finance to Medicine, from Automotive to Oil and Gas.Broadly speaking, AI companies fall into the following categories:Platform companies, providing general-purpose AI APIs to practitioners (e.g., Nuance, PredictionIO, Wise.io)Enterprise start-ups, bringing a combination of their core technologies and professional services customization to the wider enterprise, following a model not dissimilar to SAP’s (e.g., Skymind, Predii).Product companies focused on specific vertical applications of AI (e.g., Euclid Analytics, HoneyComb, Judicata)It is still early days for assessing the impact these players are having on their respective industries and hard to measure their success in the various application areas they have focused upon. In some cases, the investments have been more on the promise with little actual proof.Are we in another AI hype-cycle? Perhaps. In many cases, the term AI is certainly being conflated and sometimes confused with techniques that have never been thought of as AI being recast to be able to ride-out the buzz-wave. But the breakthroughs have also been coming at a fast and furious pace, pointing to the fact that there is ample room for innovation yet to be explored.What can we realistically expect from AI in the next two to three years? Some of the more promising areas in my mind are: better fraud detection, breakthroughs in medical diagnostics, more intelligent personal assistants, and superior browsing and discovery of products in online retail and commerce. Hype or not, AI is once again promising to be the next frontier for software innovation and application.Babak Hodjat is the founder and chief scientist at Sentient Technologies.See More
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:19am</span>
Leyla Seka commented on Leyla Seka's blog post Do You Have What It Takes to Be a Kick Ass Small Business CEO?
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:19am</span>
ABOUT THE AUTHOR David Maxfield is coauthor of three New York Times bestsellers, Crucial Accountability, Influencer, and Change Anything. READ MORE During the month of July, we publish "best of" content. The following article was first published on August 1, 2012.   Dear Crucial Skills, One of my main concerns at work is how we talk about each other—the staff lunchroom can be especially toxic. What feels most shocking to me is how our boss is often thrown under the bus. I am having a hard time thinking of an appropriate comment to make as I feel that listening to these conversations implies my agreement. And I have to admit there have been times when I’ve piped up with a rude wise-crack or two, so I don’t want to seem like I’m above it all. There are times I just avoid the lunchroom and I know others do, too. What suggestions do you have for responding to wisecracks made behind coworkers’ backs? Staying In From the Lunch Room  Dear Staying In, You’ve done a great job of describing a familiar problem. I bet many of us have been in the same situation. We’re joking around in the lunchroom, one-upping each other’s wisecracks, when somehow the topic turns to our boss or maybe to a colleague. We keep on with the jokes and banter, but at some point, it crosses the line from play to poison. As you said, we’re throwing someone under the bus—all in the name of fun. In these situations, silence isn’t golden. It’s agreement. When we don’t speak up, we show our support for the people doing the badmouthing. We’re helping to throw the person under the bus. It’s this kind of poisonous conversation that causes bad morale to spread across a team or organization. It begins with a seemingly innocuous joke, which is really the leading edge of an attack. Instead of saying something like, "I see it differently," others in the conversation remain silent or add to the wisecrack, amplifying the attack. The group is creating a villain story at someone’s expense, without stopping to question the story’s truth or giving the person a chance to respond. As the story is repeated and grows unchallenged, it becomes full of what the comedian Stephen Colbert calls "truthiness." It may be several steps away from the facts, but it feels true. And it poisons the workplace. Why do we do this? Sometimes it’s because we don’t know the person’s true motives and we assume the worst. Jamaicans have a saying, "If you don’t know a man, you’ll invent him." The implication is that we’ll invent him as an ogre. Few of us know our managers—especially senior leaders—really well. We aren’t privy to their information or motives. And as the saying suggests, we judge them harshly. We don’t give them the benefit of the doubt. Sometimes these conversations are as simple as failing to give the benefit of the doubt, but there is often more going on. Sometimes your colleague is motivated by jealousy, revenge, fear, or dislike. Regardless of the cause, you need to speak up when you see this inappropriate behavior. Use CPR to decide what to say. CPR stands for Content, Pattern, and Relationship. CPR can help you think about a problem and decide how to focus your conversation. Suppose a person at your table says, "Sure, the boss says she’s trying to improve staffing levels, but that’s just to shut us up. What she really means is ‘staphing‘ levels—you know like a staph infection!" A statement like this may contain issues related to Content, Pattern, and Relationship. As a problem-solver, you can decide which issues are most central to you. You can use CPR to focus on the issues that are closest to the heart of your concerns. Content: Addressing the content means you focus on the facts in the person’s statement. Focusing on content is usually the simplest and safest way to respond because you aren’t drawing any conclusions beyond what the person has just said. An example of addressing the content would be, "I don’t think she’s trying to shut us up. Why do you think that?" Addressing the content frames the problem as a question of facts. It focuses the discussion toward what your manager said and why your colleague doesn’t believe it. Pattern: Suppose this comment is just one in a pattern of passive-aggressive comments this group uses to badmouth the boss. You might address this pattern by saying, "I like the way we kid around with each other, but not when we start to throw people under the bus—people who aren’t here to defend themselves." Addressing the pattern focuses on your colleagues’ inappropriate behavior. It’s a tougher discussion, but it may be closer to the heart of your concern. Relationship: The long-term impact of these corrosive conversations is the undermining of trust and respect. The relationship with the boss is put at risk. If you feel that people’s comments reveal a rupture in basic trust and respect for your boss, then you might address the relationship itself: "It sounds as if you’re questioning whether you can trust and respect her. Is that right? If that’s your concern, then I think you need to find a way to talk with her and hash it out." Note that you may decide to have this conversation in private, instead of putting the person on the spot in front of everyone. Again, it’s a tough discussion, but it may be closer to the heart of your concern. The mistake many problem-solvers make is to focus on content, the simple and safe route, when their true concern involves the pattern or relationship. They address a problem, but it’s not the problem they really care about. This CPR skill can be used in a wide variety of situations, not just in confronting gossip about your boss. The next time you have a concern, use CPR to decide which part of the concern to address. CPR can help you focus on the heart of your gossip problem. David Related posts: Dealing with Personal Issues at Work Dealing with Resentment at Work Dealing with a Know-It-All
Joseph Grenny   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:19am</span>
Michael Daly's blog post was featuredThe Seven Megatrends in CybersecurityIn today’s information economy where everything is connected, the health and viability of a company’s computer systems directly impacts its ability to thrive and survive. Major cybersecurity breaches in retail, healthcare and the financial sector have proven even large organizations are not appropriately prepared to deal with current cyber threats. A new survey commissioned by Raytheon in partnership with the Ponemon Institute of 1,006 cybersecurity CIOs, CISOs and senior IT leaders in the U.S., Europe, Middle East and North Africa, identified what respondents consider to be the top factors affecting the success of their cybersecurity operations today and in the future. From these responses, seven major trends emerged that predict how organizations manage cybersecurity over the next three years.Board of Directors and CEOs are not involved... Only 34 percent of senior leaders across global organizations view cybersecurity as a strategic priority. Moreover, nearly 80 percent of Boards of Directors have not been briefed on cybersecurity strategy in the last 12 months. Only 14 percent of respondents said the CISO or head of cybersecurity reports directly to the CEO. To be heard, CISOs must focus on the key metrics that get to the heart of how cybersecurity impacts the business. For example, "dwell time" measures the duration an intruder has access to the network. By focusing on this metric, CISOs can benchmark the effectiveness of internal policies, technology and campaigns.Cyber Crime will keep information security leaders up at night. Cyber crime and enabling technologies are keeping information security leaders from a good night’s sleep these days. In the wake of the Sony breach, senior leaders also fear risks from nation state attackers and risks associated with cyber warfare or cyber terrorism. These threats, while less probable than others when it comes to inflicting network damage, will continue to make news headlines and remain a source of stress for security leaders worldwide.Insider threat risks from employee negligence will decline. CISOs and IT leaders should anticipate risks associated with employee behavior, whether malicious or unintentional, will decline. The most dramatic change will be a reduction in simple negligence, where a lack of awareness of cybersecurity practices will decrease by 26 percent and employee complacency toward cybersecurity will decrease by 33 percent. Better and more frequent training around cybersecurity practices will help mitigate the number of accidental vulnerabilities and risks on the network and will also help employees identify any suspicious behavior or online activity.Organizations are not ready for an inevitable "Internet of Things" world. Currently, only about one-third of organizations are prepared to handle risks associated with the Internet of Things (IoT). As we add more personal and business-driven devices such as building automation and smart medicine to the chain of interconnectedness, vulnerabilities will be compounded and create weaknesses throughout the organization. We won't be able to manage the risks if we don't recognize the risks.Cyber talent is in short supply. Across industries, cyber talent is in short supply and high demand. Organizations need more knowledgeable and experienced information security employees to secure their business and their customers. Educators and the private sector must work together to integrate cybersecurity into educational programs at an early age and encourage students to pursue this career field in order to grow the talent pipeline.Big shift in technology toward big data analytics and forensics. According to survey respondents, there will be a shift toward big data analytics and behavioral profiling, with a 38 percent increase in use by 2018. There will also be a 21 percent increase in the use of automated forensics tools. Meanwhile, the use of anti-virus and anti-malware software will decline by 15 percent in the next three years.The good news. Despite all the dramatic cyber-related news in the media today, information security leaders remain optimistic about their organizations’ future in regard to cybersecurity strategy and posture. Fifty-nine percent of respondents believe the state of their organization’s security posture will improve in three years.As basic human nature, we tend to fear the extreme or the attack that has no remedy. We fear the Ebola virus more than the cigarette we may smoke. While cyber terrorism is a real threat, and zero-day attacks will continue, organizations should also focus on the devices lingering on their networks that have not been patched and expose their enterprise to vulnerabilities. And, with an increasing number of devices and types of devices on our networks (internal and external; company and employee), we need to spend more effort thinking about how to compartmentalize the risks through segregation and monitoring. We may not be able to patch many of these new devices.Michael K. Daly is the Chief Technology Officer of Cybersecurity and Special Missions (CSM), a business of Raytheon Company’s Intelligence, Information and Services (IIS).See More
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:19am</span>
ABOUT THE AUTHOR Dave Angel is a Master Trainer. READ MORE My participants often ask how they can be certain if they are really addressing the right crucial conversation. I’d appreciate any insights on how to effectively answer this question. Great question! If our ultimate goal in dialogue is to produce results and strengthen relationships, we need to ensure we are holding the right conversation. But just because we are talking, doesn’t mean we are holding the right conversation. Think about the last time you were frustrated with a conversation that didn’t go well. Did you end up feeling like Bill Murray in "Groundhog Day"; holding the same conversation over and over but expecting different results? If you did, you were probably holding the wrong conversation. Another way you know you are holding the wrong conversation is when the other person continues to go to silence or violence. You need to be able to recognize that the conditions of dialogue are failing and work to restore safety. We also go astray when we focus on the wrong issue. One of my favorite methods for focusing on the right conversation is to utilize the skill-set of CPR. As you prepare to dialogue, think about what is most important to you and what you really want the outcome to be. Sometimes we need to talk about a specific, one-time occurrence and so we focus on the Content; what was said and done. If we find there is a recurrent problem we can then take it to a deeper level and address the Pattern of behavior. If you’ve addressed the Content and the Pattern of behavior and you still aren’t getting results you can take it to the deepest level and focus on how it is impacting the Relationship. When you are trying to determine at what level to enter the conversation, ask yourself: "What’s most important to me?" Is it a one-time occurrence, a pattern of behavior, or something that is really impacting the relationship? If you are unsure, I always encourage people to start with Content. If you find you’re not getting results, look for a Pattern of behavior. If you still find yourself stuck, focus on how the Relationship is suffering. The next time you find you’re not getting the desired results or wonder if you are holding the right conversation, consider using CPR. I find this important skill-set helpful in getting back to dialogue, producing results, and strengthening relationships Related Material:Before & After: My BIG Crucial Conversation by Maureen Winningham How do you handle a crucial conversation with a really difficult person? How do you hold a crucial conversation via e-mail?
Joseph Grenny   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:18am</span>
Daniel Green's blog post was featuredWill Apple Watch Make Us More Productive?Since the announcement of Apple Watch back in October 2014, a range of productivity focused apps have popped up, designed specifically to be compatible with the new wrist-bound interface. Popular apps such as OfficeTime, Todoist, and Mailbox will be among the first to be available on the new wearable interface.However, a variation of these apps already exists on the iPhone, and noted over at Fast Company,"What we’re getting is not so much a new set of capabilities, but a new interface. And crucially, it’s an interface that we wear on our bodies, rather than tuck away in our pockets."The debate over whether Apple Watch will make us more productive appears to center around the distractibility of the device- indeed, will Apple Watch add more distraction to our 24/7 technology-enabled switched on lives?The Institute of Advanced Motorists is concerned this will be the case, and noted by Neil Greig, IAM director of Policy and Research- "An iWatch has the potential to be just as distracting as any other smartphone device. Indeed more so if you have to take your hand off the wheel and your eyes off the road to interact with it."VentureBeat’s Mark Sullivan, also pointed out that the Apple Watch is entirely dependent on the battery life of the linked iPhone- if your iPhone is dead, so will any functionality on your Watch that requires a network connection (Apple Watch does not have its own cellular or Wi Fi connection). And in short, killing any hopes of having your workday planned out via the wearable interface.While a lack of network connection will not affect Apple Pay, music, or exercise related apps on your Watch, it will certainly impact your organisational plans for the day. Indeed major criticism of the Watch tends to be centered on its necessary link to a recent model of the iPhone, and while this may be excellent for Apple’s bottom line, it will likely end up being an efficiency drawback for users.Daniel Green is the founder of GetSerio.See More
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:18am</span>
Ryan Wilk's blog post was featuredWhere Should Fraud Detection Start? Shifting the Focus From Check-Out to Account CreationOnline fraud, from the merchant’s standpoint, is defined as someone other than you spending your money online. As the purchaser, you have a credit card with a secret code on the back that you only know if you possess the card. You type in your card information and your secret code, and then the retailer runs the numbers to see if your credit card checks out. Retailers left that task to the banks and credit card companies, and that became the standard strategy as online shopping started to ramp up in the ’90s.As time went on, sales and marketing teams realized that asking the user for any additional information, like that security code, resulted in lost sales. Marketers within retail shopping portals constantly pushed for new ways to safely and securely store customer data in order to reduce customer friction and make the order confirmation path as smooth and speedy as possible.But for each additional marketing-driven change, fraud teams felt the knock-on effects in the form of new challenges. The architecture of online shopping changed fundamentally. Instead of checking the card at transaction, the fraud test shifted to the user account, which holds all your sensitive information secured by a password.This created a gap between the login screen and the "confirm purchase" button because the events were not connected. So fraudsters tried to steal accounts by guessing passwords - a strategy that often worked!The Rule of Unintended ConsequencesIn response, rules were used to tie login and purchase together. With the advent of the virtual shopping cart, merchant marketers needed a way to not just track sales but verify that the person making the transaction had the right to do so. Historically, retailers focused on the transaction itself because that was the pain point and because back then, fraud happened individually, one transaction at a time.The rules engine seemed like the answer, but retailers founds themselves building ever more complicated rules to assess whether or not a particular purchase was legitimate or fraudulent, and finding that this method still didn’t work. More restrictive rules also had the unexpected side effect of increasing false positives, turning legitimate users away and souring potential and long-term customers alike. In the end, fraudsters kept getting better at exploiting a system that created as many holes as it patched.Passwords Are Not EnoughNo number of complex rules will save you, though, when all of a customer’s relevant information is stolen and made public. Wide-scale data breaches make it easy for savvy criminals to bypass primitive rules because usernames, passwords, credit cards numbers and personally identifying information are freely available. Now, fraudsters can either pilfer legitimate accounts or make up new ones with the stolen data.Whereas fraud used to entail one person making a series of bad transactions on a single stolen credit card, fraudsters now think bigger — much bigger. These days, the favorite tactic is seeding a site with hundreds or thousands of fake accounts well before any attempt is made to steal a dime.Passwords are only one part of a modern, effect fraud prevention strategy. We must look beyond whether a password is correct when entered before approving a purchase, which means we need to take a closer look at account creation. We need to shift our focus to when the account is created in the first place. And it all comes down to intelligence gathering.Consumers and Hackers Do Their HomeworkTypically, before a user makes a purchase, they conduct research until they feel the product is right for them. This could include researching the product and the seller, looking at user reviews and ratings, seeing what configuration options the item offers, and so on. If it’s the type of item that’s purchased often, eventually that purchase becomes automatic, trusted.Intelligence gathering is step one in any hack as well. Gone are the days when fraudsters could brute-force their way in through weak rule-sets. They’ve had to become more clever and, to do that, they’ve had to slow down and do their homework. Before they plan a fraud, they plot out their steps, what they want to steal and where the likely security holes are. Only when they are sure will they launch the fraud attempt. And once they have one working strategy, they’ll use it again and again until it stops working.So if customers and hackers alike understand the value of research, what about retailers?Applying Marketing Tactics to Fraud DetectionMarketers long ago learned that studying their prospective customers resulted in increased sales. Retailers initially sought out the most basic demographics—gender, age, income—but quickly diversified, and they used that information to divide their customers into smaller groups more descriptive of their needs and then tailored their marketing approach to each subset. Retailers could better predict what products would appeal to each group and, in some cases, lead to entirely new product lines being developed.No retailer would dream of opening up a storefront without having categorized and investigated their intended market and having plans in place to respond to feedback so they can continually adjust both the message and their product. Why? Because it works.Given how sold retailers already are on gathering intelligence to entice customers to their storefronts, it’s surprising that more retailers don’t scope out their prospective customers once they arrive at their website but before they try to make a purchase.Gathering Intelligence on Account CreationSo if intelligence-gathering helps retailers draw in the right customers, what would happen if they spent some time looking at the account before the first purchase is made?Successful fraudsters have taken intelligence gathering on prospective targets to new heights because they have no choice. As rule-based fraud detection became more and more complicated, fraudsters had to continually change tactics. Before, they could take a single account and test a thousand stolen credit cards, one after the other, until one worked; when that behavior got flagged, fraudsters started making thousands of accounts, each with a single credit card. You can put new rules in place to flag them, but then fraudsters let the accounts sit fallow until that rule has expired. These accounts then appear indistinguishable from legitimate accounts. Yet the creation of these accounts does leave telltale hints about their purpose, distinct from that of a legitimate user, if you’re looking for them.Marketing intelligence can often predict the upcoming needs and desires of a customer before the customer is even aware of them. So accurate that in some cases, they can predict customer pregnancies. That same level of precision can be applied to deciding ahead of time whether a newly minted account is for a real person or for a foot soldier waiting for orders in a future fraud assault. Evaluating account creation helps determine good users from bad and predict fraud before it happens.Ryan Wilk is the director of customer success for NuData Security.See More
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:18am</span>
ABOUT THE EXPERT Steve Willis is a Master Trainer and Vice President of Professional Services at VitalSmarts. READ MORE Recently, I was in the back of the room (no, I was not asked to sit there—at least not this time) of a training session. I was watching Angela as she worked her way through the material. She was working well with the group and doing a nice job of engaging them with the material. After lunch on the first day, her class found themselves wrapped up in a fascinating discussion. They were engaged. They were applying the material to themselves and pulling poor Angela off her schedule. Time began to fly. The first ten minutes of discussion quickly doubled. Twenty minutes behind and they were still interested in continuing on. Angela paused to ask, "Wow, this seems valuable. Should we spend more time on this, or should we move on to the next concept?" While this is a great question, she addressed it to the wrong audience. She should have directed it to herself. She was asking the group to make a decision without all the information to do so. They don’t know what they’re giving up in order to spend more time where they are. Yes, there are ways to make up time, and yet so many times what happens is the sections toward the end of the training are shortened—sometimes to the point of being non-recognizable. You condense the heck out of the materials, and in the end, the participants suffer. Participants need you, the facilitator, to make these types of decisions. Instead of asking the group and allowing them to make the decision, solicit input and make the decision yourself. At times, you’ll decide to spend the extra time, and other times you’ll decide to move forward in the material. But you, the facilitator, need to decide to decide. Related Material:From the Road: Wrong is Wrong Your First Ten Minutes Could Be Your Last From the Road: What Happens in Training, Stays in Training
Joseph Grenny   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 08:18am</span>
Displaying 42731 - 42740 of 43689 total records
No Resources were found.