No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

Does Increased Compliance Mean More Fraud?

Combatting the Unintended Consequences of Compliance

by Iftah Gideoni
October 24, 2019
in Featured, Fraud
man in silhouette with long nose; concept of lies, deceit

Regulations like GDPR and PSD2 are creating an attack shift for fraudsters and alternative methods for them to create havoc. Forter’s CTO Iftah Gideoni discusses how to fight back against fraud with similarly evolving fraud prevention measures.

Today, data is the most valuable asset for consumers, businesses and fraudsters alike. Thanks to the rise in technological innovations, including the cloud, remote work and e-commerce breakthroughs, we now have the ability to do anything, from anywhere, at any time. But there’s also a dark side to this constant connectivity: criminals seeking to exploit personal, sensitive information, ranging from bank account numbers, credit card credentials and even customer loyalty accounts. In fact, according to recent research, fraud attacks on loyalty accounts increased by 89 percent in the past year alone.

In parallel with this data evolution, we are witnessing a growing focus by consumers, enterprises and regulators on the privacy and security of data collected, stored and shared online. Legislatures and regulatory bodies are passing more wide-reaching and comprehensive privacy laws, including Europe’s GDPR, which became binding in May 2018, and the California Consumer Privacy Act (CCPA), which takes effect in 2020. We should expect this trend to only increase; any enterprise dealing with personal data must be able to stand behind its privacy compliance program.

In the European Union, the Second Payment Services Directive (PSD2) came into effect last month. This regulation is intended to democratize access to data and simultaneously protect it through strong customer authentication. Given the complexity of compliance and attendant business implications, the U.K. and several other nations have announced enforcement delays, which vary from country to country. And while this regulation is intended to better safeguard data and payments, it may create headwinds for customer conversion — in fact, as many as half of consumers (49 percent) are likely to abandon online/mobile purchases if faced with a multi-step authentication process as outlined by PSD2.

As regulatory and legislative bodies continue their efforts to protect consumers and personal data, businesses need to build compliance programs that still optimize user experience and customer satisfaction and that take into account the adaptability and ingenuity of fraudsters and cybercriminals.

The Unintended Consequences of Increased Compliance

While both GDPR and PSD2 are intended to protect data, in reality, today’s payments ecosystem is too complex for legislation to predict and guard against fraudsters’ next moves. Making matters worse, online fraudsters are only growing in sophistication. These criminals are shifting their focus from brute-force attacks, where a high quantity of attacks increased the likelihood of a payoff, to investing in higher-quality, targeted attacks, where one attack translates to a larger and more meaningful payoff.

In the case of PSD2, a potential unintended consequence of this regulation is the shift in fraudulent activities outside the EU. PSD2 may make fraud more difficult at the point of transaction in the EU, leading fraudsters to shift to other geographies and attack points outside of the region. Criminals who stop using European data won’t stop stealing; they’ll just start stealing elsewhere.

Privacy regulations like GDPR and CCPA are giving consumers more rights to access and request deletion of their data. This introduces the risk of fraudsters disguising themselves as legitimate actors and demanding all data on their personas be removed. The ability to identify fraudsters as returning bad actors is vital to all fraud-fighting efforts, and the loss of historical data would be a serious handicap to proper prevention.

Fighting Back Against Fraud: Understanding Your Ecosystem

One of the most effective ways to combat the unintended risks that regulations like PSD2 and GDPR bring is to develop a deep understanding of your organization’s ecosystem, as well as the users who are a part of it. This includes:

  • A full understanding of good and bad actors, as well as the connections between them, which can provide the necessary framework for protecting an online business.
  • Knowing how your fraud prevention system recognizes fraudulent behavior – for example, can your system detect fraudsters when they return in different guises?
  • Going beyond matching obvious data points such as addresses, names or even IP addresses to instead, match behavioral data and patterns, while using cyber intelligence to piece together unclear elements.
  • Lastly, in order to guard against the risk of geographical fraud patterns, it’s important that your fraud prevention system be sensitive to genuine behaviors within different geographical areas and be able to flag when a user does not match the expected norms for their location.

Fraudsters are becoming ever more sophisticated, so your organization needs to evolve in turn when it comes to fraud prevention. Add to this equation the ongoing challenges and changes that compliance regulations like PSD2 and GDPR bring, and it may create a recipe for disaster.

Make sure your customers and accounts are protected by a system that knows your customer base just as well as you do. It requires flexibility, continuous innovation and an ongoing effort to stay ahead of criminals and to keep up with the evolution in customer behaviors and expectations. However, with constant, accurate and informed protection, you can maintain compliance, security and customer trust.


Tags: California Consumer Privacy Act (CCPA)GDPR
Previous Post

CCPA Update: Changes, Clarifications, But no Major Overhaul Heading to Governor’s Desk

Next Post

Employers Must Carefully Navigate Using AI in HR Functions

Iftah Gideoni

Iftah Gideoni

Iftah Gideoni is CTO of Forter, a fraud prevention solution provider. He is an experienced executive with a diverse technology background. Prior to Forter, Iftah served as Chief Data Officer and VP of R&D at myThings. Before that, he led a portfolio of research projects for the Australian national research agency, CSIRO. In the past, he was the VP of R&D, CTO of B.V.R. Systems and CTO of Proxy Aviation Inc.

Related Posts

federal trade commission building

[Q&A] Big Tech & Free Speech Under the Microscope: FTC’s New Direction

by FTI Consulting
April 28, 2025

What compliance teams need to know about the changing approach to consumer protection and data privacy

data governance concept

The US Still Lacks Its Own GDPR, But That Doesn’t Mean Data Privacy Enforcement Isn’t Happening

by Brian McGinnis and Maddie San Jose
April 16, 2025

Despite the absence of comprehensive federal privacy legislation, American businesses face mounting regulatory pressure from multiple directions. Brian McGinnis and...

origami tiger

Paper Tigers Won’t Protect You: The Reality of Effective NIS2 Compliance

by Hans Kayaert
March 24, 2025

Why Belgium's early adoption model could prevent another round of ‘compliance theater’ across Europe

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

Next Post
illustration of robotic arm selecting man from row of candidates

Employers Must Carefully Navigate Using AI in HR Functions

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights