All right. We want to talk about Mastering CIAM. We want to talk about Best Practices for Secure and Seamless Customer Experiences. And before we dive into the topic, I would ask each one of you to quickly introduce yourselves, name, what's the role, and also your relation to this topic.
Sebastian, you can start and then we go. Okay. Wonderful. Some of you have seen me. My name is Sebastian Rohr. I'm a founder and managing director of Umbrella Associates. We are a consultancy dedicated to CIAM implementation. So we've been working with a larger number of B2B and also B2C companies that have challenges in migrating away from the homegrown solution and centralizing CIAM.
And yeah, well, one of the major challenges is sometimes the user identifier. My name is Ulrich Herberg. I'm jumping in for someone else who canceled the session. So three hours ago, I didn't know I would be sitting here. Me neither. And that also explains why you will see me for the next hour on stage. So that wasn't because I chose it. Yeah. So my name is Ulrich Herberg. I'm a senior director at eBay, leading software development in Berlin.
And before that, I was working in our San Jose office as an identity architect, software architect, and helping to design software in particular related to identity, to authentication, strong customer authentication, et cetera. And I'm John Tolbert, lead analyst, director of cybersecurity research here at Coupier Gold, been around about nine years. Fraud and CIM are two of the topics that I cover. We try to release updates to those reports about every 18 months or so. All right. Thank you so much. Just a quick hint. You can raise questions. Just lift up your hand.
I will scan the room and pick up any questions that arise during our talk. Okay. So to start the conversation, we already learned that customer demands are becoming faster. We need more safety integrated. The experience shall be more personalized. And CIM has become a critical enabler for business growth, trust, and compliance. And I would like to hear your experiences on how to align the CIM strategy with business goals like customer relationships, personalization, and also digital transformation. Who would like to start?
Maybe, I don't know. Sure.
I mean, eBay, as you know, is a large marketplace. We have about 134 million users, and that's the amount of users we have in our user database. We have everything developed ourselves. And it is interesting, identity is often perceived as friction for our users. Because we're not a bank, but because of regulations, we're often required, in particular in Europe, to have equally strong customer authentication. But people are used to suffer through two-factor authentication when they log into their banks. But it's a whole different story when they want to buy some pants.
But for us, it's still the same thing. So we have to balance how to make sure that we don't have drop-offs, people get frustrated, and particularly when it's two factors, they drop off after the first one, they don't remember their passwords and all that, or they don't have their phone handy with the SMS code.
So for us, it's often a balance between being secure and also making sure that people can buy the products that they want to buy. That is a perfect ramp-up, because that's exactly the situation that we're facing in those two projects that I've been referring to in my talk. There is lots of fraud going on in those B2B businesses. For example, in the plumbing business here in Germany, or in Europe in general, oil and gas-based heating is going down, and the government's mandated some of these citizens to actually move to heat pumps. I don't know. Who has bought a heat pump recently?
They are quite expensive, right? It's not like, yeah, well, car parts for 500 euros.
No, it's thousands of euros. And what happened is that people had those ordered and delivered to some remote places where there was no mobile phone reception and anything, and they just faked some signature, and off they went, and never paid. So it's huge. It's really, really, really huge fraud.
So balancing the security and telling a plumbing business that, yes, when they order a high-value spare part or a heat pump, then their plumber on site needs to be willing to show some sort of identity card or be willing to have some sort of fraud prevention mechanisms, like, you know, is that really the person that we should deliver to? And I can tell you they are not happy about it. But they still want to order the heat pumps.
Big, big problem. Do you think that a certain amount of friction is okay in certain circumstances?
I mean, don't users have an expectation, like if you're going to transfer 10,000 euros out of a bank account or something, I would like to see something that pops up that says, are you sure you really want to do this or not? Yeah, that's a very good point, and that's actually where we at eBay spend a lot of effort in not always the same type of customer authentication for different purposes. Maybe someone just wants to look at their current account balance. You can now keep a balance in eBay.
That may not be such a, even if someone looks at that who's not authorized to look at it, it's not the end of the world. If you buy an NBA baseball card for a million dollars on eBay, which you can, that's a bigger issue. Maybe you're okay with having some more friction. And I can totally jump in on that. I personally was scammed for 75,000 euros once in a business environment where I had done that transaction, or at least I thought I had done that transaction, and my bank actually called me and said, are you really sure you want to do it?
And I said, of course, yes, I want to do it, and they did it. Second thoughts? I lost that money. I never recovered it. It's gone.
So yeah, I like that friction a lot, learning by burning. I try to convey that exactly with that story of me, myself, being an entrepreneur, working in security and identity, being scammed for such a large amount of money, and telling them that's going on all over the place, and you should really, really, really consider talking to your customers and explaining to them why you are starting now, to make them jump through, apparently, burning hula hoop circles just to get a larger transaction through. I personally push forward on that all the time.
You know, for lower value items, often, you know, there's a dual role of being in the identity field and then also being a consumer. You know, when you're interacting with websites, you start looking at it and go, there's a better way they should be doing this.
You know, they should be doing things like risk-based authentication. They should be looking at the IP address and the device and all this information, and then they wouldn't have to ask me so many questions or make me authenticate unless, obviously, something had changed, but if I'm sitting at home ordering the same stuff from my computer, you know, I don't want to be bothered unnecessarily, but if I was trying to do that from another location, then I would go, okay, I accept that. And we at eBay do that.
We look at the risk of a specific user, like you said, IP address based, based on their prior history, unusual behavior, but we have an 80-people identity team of just engineering and probably, I don't know, a dozen product managers, and risk, we have another, I don't know, 40 people or so. Not every company is willing to spend that amount of money, and then it's often defaulting to some standard. We always apply the same rule for everything.
Yeah, I've been impressed with what eBay's been doing. I've been buying some old CDs lately, you know, off of eBay, and yeah, the identity and fraud protection implementation seems pretty thorough to me.
What I see, especially in those kind of settings, where the platform or the organization that provides that service is upping up the ante by investing in these kinds of fraud reduction scenarios, the scammers actually take evasive action, like, oh, yeah, well, no, I'll pick it up myself, I'll come to you, and then you don't have any proof that you actually hand it over, the thing that you just sold on eBay, and then they'll just say, I never received it, and claim fraud from their site, and you don't have, that is like, wow, okay.
Now, do me one favor, never underestimate the intelligence and the drive and energy of these crooks out there. They are barely using any kind of setback. They are investing heavily in that new technology, like scamming, like the pig butchering that you came up with as a frontline. That is such an enormous market. According to some analysis from The Economist, it's a multi-billion dollar business globally on fraud from those pig butchering scams.
There was a CEO of a bank in, I think, Arkansas it was, and he got pulled into one of those relationship building scams, and invested first his own money, then the money of the bank, then the money of the bank's customers, into that scheme, and the bank lost 47 million Euro due to that pig butchering scam. So, it's real, and it's growing quickly, and they are using AI everywhere.
Yeah, that sounds like a worst case scenario. Absolutely. Yeah.
Okay, we touched risk, we touched customer expectations. What about regulatory requirements? What is your opinion on the regulatory pressure? How does it shape CAAM, and what developments do you see there?
Maybe, Ulrich, you would like to start. Yeah, I worked on regulatory topics, specifically around Europe, PSD2, for the last two years.
At eBay, 100 teams were involved in this. It's massive.
Yes, maybe we're not efficient, maybe you could do it with fewer teams, that's debatable, but it is definitely a massive undertaking, because we have these close to banking licenses. And so, I talk to lawyers at some point daily, even though I'm an engineer, and I learned a lot about the regulations, it's for sure. I think the regulations help.
In US, where I used to live for a long time, there are fewer regulations, and sometimes that's a bad thing. I think European users are better protected by strong customer authentication, and I'll talk about this in my coming talk in 20 minutes. On the other hand, sometimes the regulations just go too far. We've seen they're too prescriptive, too bound to specific technologies, it doesn't age well.
You know, passkeys, for example, came, I think, after the regulation came out in its original form. So that, then, the European regulators are often very strict. They look at word by word how it is interpreted, that makes it very tough, and requires all these expenses that smaller companies just cannot do. That's true, yeah. Any additional thoughts on that?
Well, not necessarily driven by AML, but the, like, identity verification light seems to be increasing in demand across industries that aren't even necessarily regulated in the same ways. But I think we're seeing the emergence of needs for at least some lightweight identity verification to help prevent some of these, like, account opening and synthetic identity fraud accounts. Let me add one thing. So who of you is a fellow German citizen living in Germany?
A few, okay. So in Germany, we have, it's not government regulation, it's not legal, it's the Deutsche Krediten Giroverband. Anybody of that organization here? No? Good. Because I've got a Bachelor. They are the ones regulating, technically, what their members, and if you are a credit institute, you have to be a member, what they can use as two-factor authentication mechanisms, which is one of the reasons why we in Germany suffered a very, very long time about those TAN and ITAN thingies.
And despite the fact that there were more modern two-factor authentication mechanisms available, they never get adopted. And I personally hate that, right? It's really, really horrible. I would love to see a little bit more innovation in the German finance market with regard to multi-factor authentication and things. We've just learned so much about PASCYs, and I would love to use those mechanisms instead of a self-invented 2D, three-color QR thingy that a certain large online bank north of Hamburg offers. It's crazy.
So sometimes regulation, even if it's just a vertical one or one by the organization, can actually be detrimental for improvement or for any kind of innovation. So yeah, there is the good and the bad and the ugly.
Well, and privacy regulations, are they preventing people from collecting this information that can help determine whether or not something is fraud just because it might be considered personal information? Do you think that that is impeding fraud detection at all? I probably shouldn't have asked that.
Wow, okay. Anyone? Scott? I do think that, especially in all those SIAM use cases, at least my personal preference is, gather as little PI, PII about your customer as possible inside the SIAM solution. I want a username and I want the credential and information about the second factor they may or may not have.
And, well, maybe some functionality that provides me the consent somewhere else. But everything else is, from my point of view, something that belongs to a CRM solution or something else.
SIAM, for me, should only be the very hard coconut shell and everything that's inside is protected by that. How you get there?
Well, I'd like to hand that off somewhere else to those fraud reduction platforms maybe. And if it's a necessity to improve my fraud detection, well, you've got to, again, balance the risk, right?
It's like, do I risk being hacked and then some personal addresses get stolen or looked at in my SIAM solution because I used that to try to verify if that is a reasonable address to send a package to? Oh, well, I'd rather have that verified address. Great. Thank you so much. We are almost coming to an end already. I would like to hear your thoughts on what developments do you expect in the next years? And also maybe looking ahead, what emerging technologies do you believe will maybe, let's say, disrupt the SIAM landscape? We talked about PASCEs already today.
We touched maybe identity verification, which might be AI-driven. So do you have anything to share on that with the audience?
Yeah, I mean, PASCEs, let me start with that. I think it's an amazing technology. It's the first one that's phishing-resistant, highly secure, and also easy to use. So we definitely see and hope that their adoption will increase. We're still seeing it's a minority of our users. The technology is there and it's good. It's more the education that's still missing. And I'm sure over time, people will recognize what it means, what a PASCE is. I think that the term itself is still not very used.
On the other hand, AI agents, eBay, we're investing a lot in AI technologies and also not so much in identity yet, but I think it will also come. Certainly for anomaly detection, I could imagine, as you can imagine, with 134 million users, we have a ton of data. Just the logs for the sign-in and the two-factor authentication and all of that, it's gigantic. Nobody can view it.
And so having AI that can create a baseline, that can look through the data and see anomalies, that help also with the risk classification of users, what does it actually mean, a risky user, that will certainly be another technology that I see coming a lot. For me, there's one thing I'm all about, that fraud with the heat pumps. And there is one technology I find quite promising, and that is identity validation on-site, where the delivery person just gets a QR code, and in this QR code is sort of the biometric pattern of the person authorized to receive the packet.
So what they do is they come up to your door, and they ask you if I can take a photo. They snap the QR code, and then they verify that it's really the person who ordered or who was authorized to receive the packet. I do think that this is one of the technological things that's going to change.
Else, I think we still have to do lots of evangelism around fraud reduction and about the opportunities that we have in those identity fabrics, weaving the SIEM login technologies with the risk reduction technologies together, and make them work with less integration effort, and keep the data that I need for the one thing there and for SIEM there, so we limit our exposure and enhance our attack surface. Those two are definitely going to be continually growing in importance. Any thoughts from you, Ant? Areas for innovation, I think B2B SIEM.
Typically, or at least I think C in SIEM stands for consumer, but many, many organizations are using their SIEM for business-to-business relationships, and I think there's going to be a lot of innovation in how they handle that. How do you do identity verification in those kinds of use cases? How do you do HR system integration? Things like that, so I think that's going to be an area of a lot of growth over the next few years. All right. Thank you so much for taking the time and for jumping in spontaneously. Pleasure.
Yeah, it was a great conversation. Let's give a round of applause for our panelists.