Welcome, everyone. Thank you for taking time out a day before the show begins officially to come on in and talk some use cases with us all. We have about 90 minutes to go through three different use cases and also have a panel discussion, and we will open it up. So the way it'll work is I'll do an introduction first. That'll go over some of the trends that's happening right now that we're seeing with our customer base at Ping. And then we're going to go through a Bank of America presentation. Then we're going to go through a top five UK bank use case.
And then Swisscom, we'll go through their network and B2B solution. And then finally, we'll have a panel discussion at the end. And after each presentation, we're going to try to leave five minutes for any questions you have.
And then, of course, if you don't get answered, don't worry. We'll have the panel at the end.
Okay, make sense for everyone? Okay, so to get us started, I thought what I would do is just kind of walk through as an introduction some of the trends that we're seeing across our industry, across many market segments. We have a little bit of focus on financial services because, you know, Ping has over almost 500 banks as customers around the world. And so we get a lot of fast movement in identity verification and digital credentialing and wallets in the financial services industry. They're the fastest adopter. They're moving the quickest.
So to get us started, one of the big trends we have, and I'm sure it's in the news every day, is all this AI in our lives now. It's both a blessing and a curse. If you're a security person, it's a curse. As we talked to the CISOs at the organizations, our customer base, it's getting to be a very, very serious challenge. And there's two main types of AI that are really making life miserable for CISOs and CIOs.
One is, of course, the generative AI, which is probably what most people are aware of, which is where you're creating like deep fakes of people and copying their voices with only a few seconds of sampling and that sort of thing. And certainly that is true.
Also, generative AI is being used to create synthetic identities also. So it's not just imagery. It's also data. So keep that in mind. The generative AI can also create even an entire profile for an individual. There's actually cases where generative AI has been used to create profiles that have actually been officially registered with the credit bureaus, and then they created fake companies to report good behavior on your credit. And then that's being used to do fraud. So sometimes the fraudsters and the hackers are quite patient with their process.
So generative AI is one piece of the puzzle, but the one that's even scarier is adversarial AI, which is kind of a layer on top. It can actually orchestrate generative AI as it needs to. This is where fraudsters and hackers have a layer of control where they can actually orchestrate entire criminal activity from A to Z, end to end. And adversarial AI, what it's really good at is gaming the system. So it's really good at going to, let's say, a bank and finding loopholes in configurations, finding ways in, in the workflows that nobody else could figure out previously, right?
And then it exploits them. And I don't know if you've been watching the news, but CNBC put out an article about a month or so ago about how APIs are under attack. And it's adversarial AI that's the one that's attacking them the most. So your attack surface is in the sky today because we use Federation, right? So we have all these OpenID Connect and SAML stuff going around. And then we have, of course, APIs in the sky. And this is a massive attack surface that the fraudsters and the hackers are taking advantage of right now, right? And so the CNBC article came out.
There was another one in Wired magazine. And then we also saw an article in the American Banker magazine. And most recently, the CISO at JPMC, JP Morgan Chase, put out a letter to the industry and said, hey, folks, we can't just keep using OAuth and OIDC anymore. It's not enough. It's not sufficient. We're losing the battle, right? And everybody's doing everything in line. There's not very many out-of-band checks today. So your authentication and your authorization is all in one single channel, right? And that makes it super easy for AI to exploit it.
So we're seeing this, we're seeing numbers that are amazing. The 2021 value is from the United States, $212 billion due to impersonation in the US. And we already know that's gone up almost double since 2024. The official reports aren't out yet from FinCEN, but we know it's going to be frightening when they do come out. So besides this AI-driven fraud, scams in general are on the rise, whether it's state-sponsored events, actors that are after things, malware, of course, is through the roof.
APP scams is really hot, or the push scams, trying to get people to do things, like with their bank account, that they normally wouldn't do. And I found this one very interesting.
Right now, this is a pretty recent number. The average cost to remediate an API incident is $832,800. So if you have an API incident, and that could be a loose term, it doesn't have to be in a full breach, but the average cost to remediate it is almost a million dollars, and it keeps going up. And that comes from Akamai, who, you know, they manage all these APIs, right, for banks and other organizations.
So we see identity is going to continue to be more and more present in the conversations, beyond just security, and the convergence of identity and security and fraud detection is all starting to come together now. The other thing we have is even legislators pushing for open APIs, right, like, you have to let, if you have an account on somebody, you just got to open it up, baby, and let all these other companies get in the mix between the customer and you, right? That's really what's going on. And it's very frightening.
In the US, most of the banks don't want to do this. And they already see the fraud going through the roof. There's a very famous case with Synapse. It was a huge collapse of a fintech company. 350 million US dollars was lost by the banking consumers.
And, of course, FDIC, the insurance arm of the US government said, we're not insuring any of that money. That's money flowed through an organization that's not a bank. So don't call us for your money back, right? And Synapse was in the middle of things, and they were brokering out as a, you know, middleware, as it were, to many different rogue organizations. They weren't doing proper vetting, and also governance is critical.
But, so identity is more and more critical whenever you're interacting with these middle tiers in between the consumer and the service provider, the ultimate service provider, like a bank. Rising demand for more for less, consolidation and convergence. So we see a lot of customers now saying, you know what? Instead of having different identity platforms for my different use cases, I just want one. I want it to do it all. Even if it only gives me 80% of the functionality I need, I don't care. I'm going to use a platform, right?
So we continue to see this drive towards a platform model that's pushing for all, you know, to support all use cases. Even identity of things now, with AI assistants coming and AI agents coming, you know, identifying these bots, as it were. AI bots is also part of the new equation for convergence, right? Identities of users and bots in the same platform. So that's a big movement we see. And I call it battle for the eyeballs.
So, as I mentioned, this open API concept where you have to let these other third-party organizations enter your world and interact with your customers. What's happening now is that there's a big kind of a head-to-head battle going on between big tech and fintech and the banks, for example. Also in other market sectors, too, even healthcare. So like in healthcare, there's an organization called Epic, which kind of dominates in the U.S. And they're basically telling their customers what they're allowed to do now, that they're so dependent on this, right? So we see this big battle going on.
And it turns out that wallets are really coming into view on this. And you're going to see some of that in our presentation. But wallets are becoming one of the key battlegrounds, as it were. And do I just wait on Apple and Google and let their product managers decide my future? Or do I do something myself so I'm in control? I can do features and functions beyond what the platform wallets offer, right? And then the other option is third parties. Do I just use some third-party application or wallet? And that's what everybody's jostling for position right now.
But the trend right now is that if you're interacting with your user, you want control of your destiny. You want to be able to create new experiences now and not wait for others. And so the trend right now is to have your own wallet and build your own actions and not wait on the platform and try to debate with the product managers at other companies, right? So that's the trend at the moment.
You know, we're a big believer of let a thousand flowers bloom. You know, just let those flowers bloom. And over time, it's all going to work itself out, right? The other big thing is payments are a big part of our life every day with merchants and buying stuff online and in person. And we're seeing a massive convergence of payments and identity now where things are bound together very tightly. And your user experience is greatly improved. So you never have to type a credit card number ever again. So you never have to type in your billing address ever again, right?
It comes from the credential in the wallet that's tightly bound to the payment token, right? So one failed swoop, you can instantiate your payment details as well as your identity and including strong authentication as part of it, all leveraging the binding effect of like a verifiable credential. It's very powerful, right? So that's another big trend we're seeing. And finally, this idea of a super wallet, the unified smart wallet. We're getting requests constantly to add more and more capabilities to our wallet functions for our customers, including tickets, by the way.
We have very large gaming companies and sports companies as our customers and associations. And so they're asking for digital ticketing. They want payment in there. They want signing for signing documents. They want identity. They want it all in a single place and allow the user to do it both online and in person, right? With the exact same credentials and the exact same data. So that's another big push right now. So any questions before I go on in these trends? We have a little bit of time, and then I'll go into the Bank of America presentation.
Yeah, do we have our mics, please? Mic guys?
Andreas, up here in the front. Andreas, up here in the front. Yeah. Thank you. My name is Ashley. My question, because you talked about your customers and their demands, I would like to hear a little bit more about what kind of company are you and what are your expectations? Fair enough. I should have done that.
Yeah, fair enough. Yeah, Ping Identity is one of the kind of the big three identity and access management companies. You have Okta, Microsoft, and Ping are the major corporations in the space. So Ping Identity is, we have about 2,800 companies worldwide. We manage about 8 billion accounts around the globe. We have some of the largest customers in every market sector.
Airlines, banks, sports venues, car companies, airplane manufacturers, you name it. So that's who we are as a company. And I'm product lead for Neo, which is the portion of the solution suite that covers identity verification and also digital credentialing and wallets. And I've been in the business about 25 years. My first job, I was the first product manager for Touch ID. It's actually very old technology. If you guys want to ask afterwards, I'll tell you how it works.
And then most recently, I led the team at Idemia and we built all the mobile driver's license stuff and built the TSA checkpoint in the US. I had 90 people under me and we convinced Apple and Google to join the ISO body and convinced them to invest in government IDs and wallets. So that was my last job. And I've been at Ping for about four years. Is that helpful? Cool.
All right, so we're going to go... Any other questions? Good? Okay. So we're going to go right into Bank of America.
Now, Senior Vice President Sean Gonsley was supposed to be here today from Bank of America. We thought it would be cool to bring Americans over the pond and present. But at the last minute, he had an emergency that he had to deal with. And so he asked me to go ahead and present his slides instead. So just FYI, he did want to come. He apologizes. He asked me to send his greetings and apologies here. But Bank of America is the second largest bank in the world by assets managed. They're a very significant organization.
And this is a workforce use case where the challenges of workforce and state-sponsored actors from North Korea and bait and switch, people interviewing for the job and then a different person actually comes to show up for work. Things like this have been the challenge. And so they have been under a very significant comprehensive program they've implemented now to revolutionize, really, the whole entire process from job application all the way up to starting your first day on the job. Right? And we're going to tell you about their first steps today and what their future plans are.
But it's all around identity verification and deepfake protection. That's one of their two main angles on this. And they're using both digital credentialing as well as traditional methods like taking pictures of government IDs. They're throwing everything at it right now in the model. So the company, they have about 250,000 workforce personnel operating in 45 countries. So it's a global issue for them. You might think, oh, Bank of America. They must only do things in America. Not true. They're really a global bank. And most of these employees or many of them are remote workers, right?
You can imagine they hire on. They may go to an office maybe once, sometimes never, depending on the job role and position. But they do have to go through, of course, a proofing and vetting process for the bank. For bank tellers, of course, like working at a branch, they go through a much more rigorous process because they're handling money than somebody that's working on IT, for example. Right? But the challenge is it's obviously, you know, in the past, it'd be like, well, if you want the best security, just show up at a bank branch and we'll get you processed as an employee.
That's no longer an option, especially since COVID. The world's changed. And people, they don't want to spend the money. The organizations have everybody traveling in. So it's cost prohibitive to travel while you're onboarding, while you're unlocking an account. Let's say your account's locked. You're not going to show up somewhere in person. If you get a new laptop that's shipped out to you, it's going to ship out to you. You're not going to go into the bank to pick up your laptop, right?
Adding an authenticator, adding a new device that you're going to use to authenticate with, making a change to your account, like your address, or maybe you get married and you change your last name. Those kind of things, right? The threat vectors that they're really focused on is bait and switch is a big one, right? So I don't know if you guys have been, and gals have been looking at this, but there's a big availability now. You can just hire someone to take your tests for you online, to do your interviews for you. And then you're the person that ends up working for the company.
So we call it bait and switch, right? Where you leverage even paid actors to represent you and work and do things on your behalf. There's also what's called paid proxy. So after you get the job, you say, I ain't doing that job. I'll hire some cheap person over here on the side and they'll do all my work for me. So you can get a proxy worker that'll do all your work and you give them a quarter of your salary, let's say. And then you do nothing, right? The other one is account takeover, obviously.
So once you're onboarded and once you're working with the technical systems and all that, the threat actor of somebody coming in and trying to take over your account and do damage or to interact with the systems inappropriately. The latest one, the state-sponsored actors, that one's really surging now.
And I was just reading a new article, I think it was Wired magazine, that says that one state-sponsored actor in North Korea can generate up to $4 million in revenue for the government of North Korea by working at multiple jobs and doing just enough between these jobs and getting all those salaries coming in, right? It's pretty interesting. That's a lot of money for one person generating, right? So if you had a whole army out there doing this, you're raking in big dough into the government, right?
Then deepfaking AI, of course, including during video conference calls, impersonating your CEO and CFO. You've probably heard about this where there was one situation in South Korea where somebody was on the video conference and they thought their CXOs were all there, their chief financial officer, and instructing them to move $25 million to an account. And they thought, okay, I'll do it. I'm following direction. It was all fake. It was all deepfakes, right? So that's another big problem. And then BYOD. More and more in the U.S.
anyway, the corporations are leveraging devices you already have when you become an employee, right? And so how do you know the device is any good? How do you know what's the reputation of that device? Things like that. So that's another big challenge for organizations is BYOD. So they needed to upgrade their identity verification processes. And as part of that, they wanted to reproof all their existing employees. They made the assumption that there could already be rogue folks working for them, right? And so they forced everyone to go back through a whole proofing process again.
It's very interesting, right? Step them up, as it were. And then proof all the new onboards, of course. And then evolving by shifting everything left. So they started with IT and onboarding in the IT, and now they're gonna shift left all the way over to HR, all the way to job applications. We'll talk about that. So phase one was establishing the framework. And a lot of it was research. Researching the design and to convince all the stakeholders that a comprehensive change was needed, right? Digital transformation of a lot of processes.
The criticality of having this comprehensive approach and not having any holes in the technical processes. And then implementing the framework foundation, the basics, and rolling that out. That was phase one. Now they've entered phase two, and that's enhancing the framework. They're adding support for digital government IDs wherever they can. So if there's a French, even federated, ID when they hire on a French employee, let's leverage it. Let's force the use of digital technology where we can that are issued by the government, right? Implementing strong bindings via wallet and credentials.
So now that they know everybody's who they're supposed to be, now they want to be able to issue these verifiable credentials out to all the employees and be able to leverage that downstream for multiple use cases. And the magic there is the bindings. The unique identity, which FIDO can't give you, right? FIDO is not unique. You can have 10 people on a Samsung phone enrolled, right? With fingerprint. So unique identity bound to the proofing event, bound to the device, and bound to the entitlements. And that binding was critical technology that they're rolling out.
Also, more systems of record and device checks they're adding as well this year. And we'll talk about timeline in a minute. And then after that, really exploit the framework. Extend it out to many more use cases and processes within the bank and applications. And then look at adding value in everyday verification of these new digital badges for the employees. So that was the solution. You see the picture depicting this.
They're, in their mind, they're going to do proofing immediately when you apply for a job. The world's changed. You can't assume who's anybody who's who, right? So they're literally going to have you download an interview app. It's actually also their authenticator for the bank. They build their own authenticator using SDKs, by the way. They're going to have you download that app. And it's going to help you walk through your hiring process. You're going to have tips and tricks in there about interviewing. You're going to have photos of who you're going to interview with and their profile.
If there's a change to your interviews in the day and time, you'll get a push to the app. So what they've done is they've incentivized security by providing this tool. That's what they built out. And so at that point, from the very beginning, there'll be a progressive proofing that happens in that binding of chain of trust all the way to the point of job application, right? It's a big deal.
I mean, that's very different than what we're all used to, right? But they don't have a choice. They have so much security threats going on. So live identity verification is part of it, including selfies down in the process. Digital employee badges, which is that binding we already talked about. Doing a lot of transaction risk assessment. So they've implemented a lot of risk signals now for about 20 to 30 now. They're looking at every single transaction, looking at risk that the employees are doing. And then orchestration with rapid integration. This was also key.
For example, they had to roll out an in-person identity verification application, and the board of directors wanted it done in three days. From design to delivery in three days, and it was over a weekend. The only way to do that is with orchestration tools. And they achieved it, and they were able to make the deadline and get the in-person verification app deployed within three days. So it's pretty impressive what you can do with orchestration tools, right? And then empower the workforce use cases across that entire user journey.
Again, priority is on IT onboarding now, and then HR next, and then it'll expand from there to other use cases. So here's the implementation. They started in November of 2023. And this tells you how, with such a large organization, you can't do it as fast as you would want to, right? Unfortunately. Especially when the lawyers get involved, right? So they started in November of 2023 when they kicked off the program. They began building all the framework and initial applications.
But actually, if you look, relatively quickly, the first self-service functionality was deployed not that long after they kicked off in April of 2024. And everything was web-based first and not embedded. Nothing in their native app in the beginning. It was all mobile web and self-service and be able to do the IT onboarding, the account reset, and the high-risk transactions. So any time the risk assessment said, hey, I don't know. Looks like he's operating somewhere in Iran right here. We better step up and do some additional stuff.
So then by January of this past year, they actually, almost all of the entire workforce of the company worldwide, has now gone through the new process. Pretty impressive, right?
250,000 people, plus including contractors. So they now have a very strong security posture based on all this work that they've done. And now what they've done is they kicked off implementing the embedded experiences inside this authenticator app that they build from scratch anyway. They have a bigger mobile team than I do. So now the next step is embedding everything into that mobile app, even making it more secure, having a single go-to place to interact.
Even if your account's locked, you can still do stuff in this authenticator, including present your digital credentials and things like that. And as part of this year, as part of that embedding is adding the wallet to that authenticator app, reducing costs in the proofing side of it, because it costs a lot of money, especially if you're taking pictures of plastic IDs. It's a pretty expensive process. So simplifying it and speeding it up, reducing costs, reducing timeline. And then by 2026, early part, there should have the HR processes on board.
So they're starting to do interviewing, doing identity verification as part of a Zoom meeting, a Zoom interview, and things like this. That's their goal. Does this make sense? So what's the impact already?
Well, even without the embedded part, and even when there's physical plastic IDs involved, the entire self-service process is all under 45 seconds. So you can reset your account. You can onboard, whatever it is if it's a high-risk situation. Within 45 seconds, they do a very strong identity verification. When the digital credentialing gets involved, that's going to even plummet more. You get down to 5 to 10 seconds, easy. They've had a 94% user success rate in the verification process. That's completely autonomous, completely self-service, all automated. That's not bad, if you think about it.
And they project to improve that in the next three months by about 3% to 5%, because of some of these digital government ID stuff they're adding around the world. And the burden on the help desk has significantly reduced. I asked them to share a metric with me, but they didn't get it to me in time for the conference. But you can imagine, if you have a self-service portal, the workers aren't calling an 800 number when they're locked out. It's huge. It's a great savings. And then their security posture, as I already mentioned, has been critically improved.
All right, questions real quick? Mic handlers? And then we'll get to the next presentation. Any questions about Bank of America's workforce implementation?
Yes, it does include Germany, by the way. No? OK.
Oh, one up here. It's just that this app is only for workforce, but yet you have wallet. And is it planned for customers, or is it something that? Eventually, yes. A lot of my customers focus on building out the workforce first, because it's lower risk, especially with new technology. It allows them to get their fingers pruney, and work with it, and deploy it, and play with it before they go SIEM. Right? So it's a lot of work. But it's a lot of fun. They're going to deploy it, and play with it, before they go SIEM, or B2B.
Actually, the next phase of Bank of America is going to be business banking. So they're going to do workforce first, then they're going to implement a lot of the same tech for business banking. And then SIEM is last, consumer. Because their size of their, they have like, I don't know, 110 million customers. It's big. Right? Any other question? Yeah? Paul Ashley, Anonymy Labs. Do you think that people in the next few years are going to have multiple wallets? Because you can see, this is a workforce wallet.
They could also have a government wallet, and they could have their Apple and Google wallets, and all that. Yeah.
In fact, they'll have wallets in even like, banking apps. They won't even know they have a wallet.
Remember, the technology around decentralized identity and credentialing, you don't have to instantiate it as a Rolodex of cards. That's just because that's what you've seen at Apple and Google in the platform. Right? So we have a lot of customers that have implemented the technology for decentralized identity, and there's no, the user doesn't even know they have a wallet. They just get the better user experience. Does that make sense?
But let 1,000 flowers bloom. Right? And it's going to work itself out over time. OK. Questions? Good.
One more, and then we got to move on. What about their identities? They are all in the cloud of ping, or it is in the on-prem at a bank?
Well, banks mostly do on-prem for the core identity records. But most banks have a hybrid. They use SaaS when they need to for certain functions. But the core identity records generally are either in their private cloud or their on-prem. But it just depends on the bank. Capital One is unique. They run everything in AWS. So like Capital One's one of the largest banks in the world. Everything runs in the cloud in AWS. So it just depends.
But OK, David, you're up. You can use the clicker or whatever you want to do. I'll go flip the clicker. So welcome from my side. So I'm David. I'm a colleague of Daryl. I'm a solution architect here at ping, and especially for the DACH region. Now I want to talk. We are switching. We're switching from work versus customer use case right now. Also in financial services. So we're currently running a pilot with a top five UK bank. And I want to give you some insights on how that project went, what phases there are, what kind of lessons learned we had.
But actually, I think everybody knows about problems during some kind of applying for a bank account, right? There's a lot of friction and so on. This is what they really wanted to empower. So they really want to go into that improvement and to go into that improving the user experience to really have a less, let's call it a less long experience for applying for services and also really don't want the redundant services applications and so on. So just give you some high level context about the company due to the fact that we cannot mention them.
So it's really one of the top five UK banks in here. They're really having around about 20 million customers on their side. And what's really interesting about them, that they really have a high percentage in utilizing their mobile app. So that means you really have a lot of difference between web application, user journeys and mobile application journey. So this is something that we had to cover during that pilot as well. So giving you some context, what is their current situation, right? What they really want to achieve with this kind of switching to a new technology.
They currently know that there's a lot of friction in regards of applying for services, right? As mentioned, I think you all experienced that, that for example, applying for a bank account really takes a long time sometimes, right? Because you have to go maybe to your bank store, right? You have to present your ID card to the bank agent. And then afterwards you have to wait for some kind of postal pin, postal password, whatever for their first entry into your online banking account. So this is really a long duration that is pretty annoying, to be honest, right?
I think everybody has experienced that one. Of course, when you're looking at a delegation, right? And so you're having, for example, you're having a girlfriend, a spouse or so, and you want to give her access to your bank account because maybe you put your bank account together. It's all a manual process, right? You have to go to the bank and you have to initiate that via your agent there. So it's also something that could be easily done in an online service functionality thing, a procedure.
Bindings, there's currently in most banks, there are no bindings between payment transactions and identity. So it's basically a transaction number, which has no relationship to any identity. That's also something that they really want to change. And of course, Daryl mentioned it while talking about the trends, right? The tech service is growing bigger and bigger, right? Also for banking. So they're really thinking about deep fakes and AI threats, API threats, and so on. And this is also something they currently want to solve when they are going with a new technology, right?
And of course, it's all about monetization. So when they want to go for some kind of a bank ID, they really want to reuse that for monetization as well as give the service that used their bank ID a really non-fraudulent community access. So that's all about the context. Let's talk about the challenges that we saw during that pilot right here. So of course, it's just about what we want to achieve. We want to achieve some kind of a basic pattern, like a basic framework for a digital wallet, right? That really fits all the business needs of that bank, right?
So that they can streamline all the processes within. Of course, we have to be sure that everybody knows about the standards relying on the new technologies, if they are natively integrated in our software, if they're using open standards like OpenID for VCI or whatever they're called. So this is really something that you really have to teach them or teach new customers about the standards and what the benefits are using them. Definitely, you have to create a roadmap of the capabilities.
So this is something that is really important and really challenging because sometimes they really came up with some ideas, mostly say their requirements, right? They don't really... And I think you all know about this, the difference between requirements and use cases, right? They can really spread the words. So this is really something that's really important, right? Not talking about capabilities, just talking about really use cases. And of course, how do you convince stakeholders for going with the technology? It's all about deploying use cases, right?
Showcasing that the experience is getting better, right? That it's getting easier for the customers and so on. So these are basically background features that I wanted to mention. But currently, what we are doing with this customer, with this top five UK bank, currently we've spread this broad check into three phases. We have finished phase one. Now we are currently in phase two and there's also an upcoming phase three. Let's talk a little bit about phase one, which is currently completed. What we did.
Of course, we have some text in here for you to read it. I will just go through my experience that I had during that pilot phase. So first of all, phase, just to give you an indication, phase one lasts about one and a half years, okay? It was really low phase one, to be honest. But this is really because it was some kind of a lack of information because they came up with the idea of a wallet because it was up to date. Everybody was talking about it, but they did not really have the idea what kind of use cases they are solving with this, right?
And so we did a lot of workshops, a lot of iteration about really going into use cases, convincing them that it's the right technology to improve the user experience, right? To make things easier and simpler, not only for the customer, also for the backend, for the implementation of their identity and access management system. So this was really the maybe last round, about six months, to be honest, to really go into that kind of implementation phase. But at the end, it was really good. So we really had a good roadmap.
We had a good definition of what project phase one shall look like with really some defined use cases. So we really know about this. We knew about the must-haves, the should-haves, the could-haves. So it was really good things. That's why we started with these project phases. What we did first, to be honest, is we just rebuilt what they actually had, right? So we just came up with a web application that really mimics their current web application. Just rebuild the logging process. Afterwards, we just added a user journey for an authentication flow with a credential, right?
Just to showcase what's easier. Is it easy to just use username and password, what they currently had, without MFA, or just scanning a QR code, right? And sharing the credential details. So this is where we started, right? And then we just grow up and improve the POC until we said, okay, we have some kind of a service that gives us the opportunity to really apply for an account. Which means we really had that kind of registration process in place for that web application that really asked for identity verification in one place.
Then we are handling some kind of, let's call it, some kind of a contact details verification. So we were approved that the email that was entered was valid as well as the mobile phone number was checked at the end. And what was what last was, is just pairing it with the wallet, right? And issuing some credentials. And what we did is we not only issued one credential, we issued several. Just to give them the idea that doesn't matter, for the registration process, it doesn't matter if you need one credential or you need several ones.
It's the way that you want to deal with a data model at the end. So what we did is we really gave them three credentials just due to the fact that we really want to have some kind of a bank ID, which is basically some kind of mimicking the ID document that was used during the identification process. Then we just gave them an account credential, which holds all the necessary account information. And we also just gave them some kind of a sample credential that holds all the contact details.
Because we thought that this is some kind of a benefit to really have them all separated for just giving some other service provider the possibility to not use the overall dash. So just picking the right one at the right time just for really doing this kind of data minimization principle as a core process. So this is what we started with. Then of course, I've mentioned it. We know that a lot of guys at this bank using their mobile app, right? So next sub step in phase one was really some kind of an implementation of a mobile app.
So we really developed a mobile app that was really close to the current, let's call it the current production app, which shows cases of the authentication process and the whole credentialing thing. As Daryl also mentioned, so this is really some kind of a, they really want to have an inbuilt wallet in their current app. And at the end, we don't know if they really want to show all the apps in some kind of a preview form, if they really want to hide that wallet and just give you the information. So we don't know.
But what we did is we just give them some kind of an Apple wallet experience, right? Where they really have some kind of a catalog where they can scroll through the credentials. And what we also did afterwards is we just gave them an idea how this registration process looks like in the mobile wallet app, in the mobile app. So what we did with that, so it's just, we just give them a single end-to-end user experience the first time ever, right?
So, because when you're looking at the web app, right, you have multiple devices involved, right? You're starting with your laptop, opening up the browser, browsing to the application, right? Signing in, applying for the account. But then you just basically change during the identity verification process, right? Normally you have to switch to a mobile app. So you're just really switching from laptop to your mobile, to your mobile phone to do the identity verification. Then you're jumping back to the browser again to finish it all, right?
And then, of course, some postal errors could come into play. We all know that. So you have really some kind of an omni-channel experience when applying for it. That's what they currently had. So with the mobile app, we also really sketched that out that it's possible to really stay on one device, right? Just opening up the app, applying for the service, running through all the processes so you're still on the mobile. You can use an in-built identity verification system, which just uses your camera. And you're just staying on the app. And at the end, you're just in, right?
So this was also something that we've proved that this is really working. And also that the process is really seamless at the end. So nobody really had some kind of a hurdle to go through the process. So it was really a simple process that really took only around about, I think, overall, it's around about one and a half, two minutes to really make that all work from entering some data in a form, going through the identification process with biometric matching.
So we will just also make some kind of a matching of the input form against the data that's coming from the biometrics of the ID document. If that matches, then we are going through the other steps. So as mentioned, it was a long time, but this was a really deeply detailed phase one, right? Which was really driven by ourselves.
So really, it was some kind of a vendor-driven phase one. Currently, phase two, where we are in right now, we just switched to a partner approach. So currently, one of our partners is driving this project forward. What they are currently doing is they really want to go from this pilot, which is currently based on an orchestration tool that Daryl mentioned. So because they want to switch that to their current installation. So currently, they are running on an on-prem stack of Ping. And they really want to build that all in, into their real architecture, right? So this is the plan.
And also, of course, improving the phase one pilot so far, and to just adding more and more services, really, to make that all work out. So this is what currently phase two is. This is where we're currently in. And of course, when you're going in phase three, then we're really having some kind of a production pilot for a specific user group that they want to deploy at the end. So this is basically, really, what we're talking about, this one. So this is the steps to success. We are having, as I think we've mentioned a lot of these solutions, what we've built for them.
We've built a live identity verification. We have the cred for the Know Your Customer stuff, entitlements, and bank ID.
Of course, last thing is really important, feature-proof with convergence of payment and identity. Also a big topic for them. Just give you some lessons learned as well. A lot of what's mentioned before. So it's really hard to really talk about new technologies with new customers if they are not really aware of what this technology means. So it's really about educating the stakeholders and giving them as many use cases as you can with the advantages around. So this is what we've learned. It's all about demonstrations.
It's all about taking videos because they are more convincing than words or PowerPoints. So mobile app team, positive stakeholders. So it's a lot of team sport. Everybody has to be involved. Everybody has to be engaged at the end. So a lot of potentials right here, what we have. So it's all about really working together as a team and really giving the right information to the right person at the end, at the right time. So this is basically our lessons learned. So thank you. Just a short overview of what we've did with the UK top five bank. Any questions?
Well, we're running behind. So we'll do your questions on the panel.
Yeah, sure. OK.
All right, great. Thank you very much, David. So you can see these large projects are not for the faint of heart. It's a lot of work, a lot of stakeholders to educate. And I will say, this bank was interesting because this whole concept of a reusable identity that could be used with their business partners and affiliates and other third parties is really, really driving the art of the possible in their future. Doing this is really driving a lot of this project. So the idea that we're going to be a lot of this project.
So the idea that you remember a government ID, whenever you get issued a government ID, they don't care that you launder money all day. You could be a criminal. You still get the exact same ID as another person. The government's not going to help you figure out that additional proofing. But banks can. In the financial world, the proofing that banks do has extremely valuable importance, right? You'll hear from Swisscom the proofing that they do in the telco world. Extremely valuable, because it adds on to what the government's root of trust identity is, right? Does this make sense?
So even in the EI-2 world, if everybody thinks these EI-2 government creds are going to solve everything, and they aren't. They're only going to say that it's Daryl. That's it. You don't know about Daryl's behavioral history, the trust level that you can extend to Daryl based on that government ID. Does that make sense, everybody? So remember that the additional credentials that will be issued after proofing with a government ID are going to be very, very valuable to other third parties. OK. All right.
Next up, I've got to get over to Christina Hirsch. She's vice president at Swisscom. And she's going to talk about their digital trust service and how they're introducing credentials and wallets.
Thank you, Daryl. And welcome from my side as well. It's a pleasure to introduce what we're doing, actually, as partners of PING together and with the technology. And I first want to start with the vision of Swisscom, which is not on the slide. OK. Surprise. It's innovators of trust. And we got a new CEO three years ago, Christoph Eschleman. Maybe some of you know him. So we went through a process to see where the future goes. And innovation has always been in the roots of Swisscom. And we believe that innovation only functions if people trust in a positive result.
And it can be as simple as you probably never heard of somebody who said, oh, I switched to that mobile operator because they're super expensive and the network is not good. No, if you do something, you do it because you expect a positive result and you expect your expectations to be met. So we see as tech companies and tech innovators, we tend to be very much in love with the technology. But if the customer experience is not right and the trust is not there in a positive result, you end up getting nowhere.
So as innovators of trust, we started to put a stronger focus still on the innovation, but also on the trust piece. And to give you an example, what this looks like is the pieces of what we call the trust elements. And the trust elements have been there, that has been in Ping, that has been in Swisscom. And it's basically pieces in the value chain that take care of identification. It's certificates. It can be a qualified signature. So you have those handshakes that have not been possible online for quite some time, and that can close the digital gap right now. But they have to be connected.
And that is a very important learning from the Swisscom side as well. And that was mentioned in the previous examples also. It's super, super important, not only to pride the technology, but also to provide those digital processes. So what we do is we have those elements. We do customized solutions. And what is very important is that we can also touch the long tail. So if we digitize projects for the customer, we don't only do the 20% of the processes that typically account for 80% of the volume.
We digitize so many processes that we can go all the way through, which again is important because as a company, and I've been responsible for customer experience projects in my previous roles, often it's very easy to tackle the top 20% of the processes. But if you only digitize them and you don't make it up to the end, you end up with 80% of broken processes that somewhere end up in a hotline call and a manual workaround and a PDF that needs to be signed. So the entire beauty of digitization is lost because you don't push through with a business case.
So that for us is very important to find some means and technology to do that. And then also important is we are compliant to the Swiss regulation, which is obvious as a Swiss company. But there are four TSPs in Switzerland. We are one of them, and we are the only one that is also certified for Europe. We even offer in selected countries abroad some services. That means that we really help the international B2B community to work with us and use those trust elements and digitize the processes. Just a quick example, closing the digital gap. I've already mentioned it. Why is it so important?
Because right now there are still, if you work with banks, with insurances, with various companies, there are so many elements that are still analog and require the customers to show up at a touch point, to print out something, to sign it, to send it back while postal mail, etc. So we go through all those pieces. We do digitization workshops with our customers and we help them to change those pieces in a fully digital experience. Looking at the regulation, this is very much focused on the signature, but you can see two streams.
In Europe, we see the regulation rather around trust elements. So the European regulation tends to look like the entire bucket. Switzerland typically, in many cases, is more pragmatic. We started with a signature regulation, but then we have another regulation for the EID and we take it from there. I think that's also the beauty of the service. If you understand both regulations, you can bring together the best of both worlds and offer a complete service and again support the international business, which is important.
Switzerland is a relatively small country with 9 million inhabitants, but it's globally so connected. We have people flying into Zurich just to do their bank business from an international perspective.
It's also, in many cases, used for arbitrage courts. So in international contracts, and I also did this in my previous jobs, if you don't manage to agree to a legal site to clarify the legal questions, you go for Switzerland because it's neutral and it's arbitrage. So we have a lot of those signature business coming in and out. And giving an example also from banking, which is the majority of our customers, we see that 67% of acquisition potential is missed because the onboarding process is too complicated.
So last year, we initiated a project with a cantonal bank in Switzerland that has a fully digital onboarding process, which was actually quite an innovation because the checks, the anti-money laundering, know your customer, relatively complicated in Switzerland. Maybe you remember that we ended up on a small blacklist of the United States and had to stricten our banking rules to get off that list again. So we managed to digitize the entire process for our customers. So basically, you can open a bank account from anywhere now, but still being legal and being compliant.
And what happens is that we receive the information, what kind of contract shall be signed from the bank. Then we go through the entire onboarding process and then the bank receives a completely signed contract together with the customer. And we have all the information. So later on, we can even still help them in a communication with a customer, go through the onboarding and take it from there. Going back to the regulation, what's up next?
The EID, I think, which all makes our hearts beat a little faster these days. So EU is about to launch a new wave of regulation with the EIDAS 2.0. In Switzerland, we're working on an EID. And I think that will be very, very exciting times for all of us because I'm sure you know we all have those video ident solutions and you have to like dance in front of the video. You have to take a picture of your passport and it's amazing how things can go wrong.
We did a test to improve our success rate on the video identification and customers, you ask them like, please check your NFC code and they don't know what it is. So like with the QR code, they do the phone here and the NFC chip from the passport here and they never managed to complete the process. So if you're coming from a technology mindset and you watch the customers, how they handle it, you can see all the hurdles that have to be crossed. And I think innovations cannot be successful if the customers don't get it. So the customer experience has to be super easy.
The product has to be super accessible. So I think with the EID, we really have a lifesaver to digitize the last mile and ease this process a lot and make it really usable for everybody and not only for those who are almost experts on the matter. So my call to action at the end of the presentation and I think in this room, we're probably all on the same side. We should all push the EID, we should push the digitization and we have to be the forerunners. We have to build the trust. Maybe a small example, if you look at the car industry, they were invented roughly in 1890.
In 1910, we had a big wave of introduction of driver's licenses. So the first 20 years, you only have to have to afford a car and then they recognized it's not working. Seatbelts in 1950, that became obligation in 1970. Seatbelts in the last century, despite the big world wars, were the biggest lifesavers. So that was a good invention. And now since 10 years, maybe we're looking into electric cars. And if you compare that with the industry of the internet, it's still fairly young.
The technology has been there for a while, but it only got a mass product in, I would say, on the PCs in the 90s, on the mobiles after 2009, 2010 with the smartphones. So we're at a very early start. And this is why I believe trust is so important because if consumers don't trust, they will not buy it, they will not join in. And no matter how beautiful the technology is, we will all be stuck.
So please, let's push this together. Mind the trust and bring the best benefits out of the digitization to everybody. Thank you. We have about five minutes if anybody has any questions for Christina regarding her presentation, and then we'll do the panel. Anyone? Good morning. I am Ketela Porbes. I have a question about the reusable identifiers or identities. Is that only for consumers? Are you also considering for legal persons to do the same? That is a very good question.
For consumers, I mean, the EID for consumers is very highly regulated and at least in Switzerland, the EID that is valuable for consumers will only be in the hands of the governments, at least for the first phase. We can imagine that this may change over time, but as we start, it's going to be with the government full stop. But a lot of the value comes in with legal bodies and around the EID.
So what we're going to do is since we have B2B driven products, we'll evolve the B2B side of the EID and everything that is required to do the business and set up on the governmental services wherever it's necessary. Okay. We'll do the panel. Any more questions? Any other questions? All right. All right. Let's come on and sit down and I'll change the slide back. Thank you. Just to remind everybody. All right. To get us started, I have some questions first and then we'll open it up to the audience as well. So my first one is for Christina. First question.
There's a lot of confusion now between these wallets and the audience even said, should there be hundreds of wallets? We've got government wallets. We've got platform wallets. We've got wallets inside of mobile apps, including Swisscom app probably. What's going to happen in the upcoming experiences with these government wallets, like in Suiyu, which is the Swiss wallet. What do you expect how that's going to interact with your network of customers versus when do they want to use your wallet? Yeah.
I think, first of all, it's important to have a starting point. I had the pleasure to be at the World Economic Forum in Davos this January and there was also a panel and one question was like, how to bring a wallet to developing countries? And I thought, okay, wait a moment. Probably we are the developing countries regarding the wallets. We have different means here.
So for me, step one really is to have it, especially in Switzerland. We had an attempt in 2021, which was blocked politically. So we do it again. And I really hope that we're going to do it fast because if you interact, for example, with people from Sweden, for them, it's supernatural. If they want to open their bank account, they jump into the bank ID, which is the standard there. And then they take it from there and we still type in passwords. We do the video show and everything. So it really feels super complicated what we do these days.
And we have dropout rates for some customer groups in the onboarding process around 30%. So they're basically cut off because they don't manage to access the technology.
So for me, first, very, very important, we have to start it no matter what. But we cannot prevent technology from happening. It's like being part of a soccer game and not entering the field, what we're doing right now. So first of all, do it, do it, do it. And then second of all is a matter of integration. And I think step one will be that we jump into the governmental application and we connect with the governmental application as much as we can. And step two may potentially be in the future that we have an own wallet with an identification.
I wouldn't overstress the wallet because if you look at the old school wallets, I mean, some people carry books with them with so many things in it. So you can almost call anything a wallet. And I think it's also fashionable way right now to say, yeah, I have a wallet. So I would go for the functionality and then we'll take it from there.
Yeah, we have the mentality of a standards plus. So we always want to support standards, but there's always advanced functionality that the interoperable wallets can't deliver. Things like push notifications, that's not in the standards yet. Delegation, you can't delegate a credential anywhere with the standards. So there's these advanced functionality that will always be out in front of the standards. And I think that's where delivering user experiences that are much better, even above the standards, that's where our customers have said, yeah, let's do some of this other stuff too.
I totally agree. And I also think that at least in Europe, we are very smart of thinking ahead, but we tend to standardize too much. If you imagine airplanes wouldn't be invented today, we would have like 50 years of discussion if an airplane is too dangerous. And once one crashes, we stop everything, try to regulate. So I think we kind of lost the braveness. And I believe that we should standardize, but really to a necessary minimum to be interoperable, but we don't have to standardize everything.
And then the beauty comes in setting up on the standards and making useful applications and a certain competition on user experience and good technology should still be possible. It's a positive thing. And then eventually the standards will catch up.
So David, question for you. One of the things you said was the year and a half, as it were, from beginning of the idea, all the way to the delivery of the first set of code and everything for the customer. And now we're in this next phase. What do you think as a person that works with customers all the time, what was the most important discovery in your mind with this bank as you went along? Or maybe it was something that surprised you. I think there's always surprises in these kind of projects.
But honestly, I think it's really about planting some seeds in their head towards innovations, right? Because we all know that these kinds of financial services institutions have mature systems, right? And why should they really change from their mature systems to completely a new technology stack? I think this is something that is really a challenge, to be honest. I think we can really adapt that to every kind of industry, which is really into that space, right?
And this is really something that you definitely have to convince, in my opinion, first, the technology leaders, so that this is really good for user experience, for also simplifying their architecture. And then, of course, when you have these guys, you have your champion on site, then you really have to go building a solid, Proof of Rock, solid presentation for the stakeholders, right?
And I think this is really what I think is the most important part of this project, phase one, that we did with NetWest, really planting the seed on the technology side, giving them the idea what's behind technology-wise, and then coming up with some cool use cases, build them up, building some cool videos for the stakeholders, and giving some good presentations on the benefits. And benefits is not only technology-wise, you only have to have a business value behind it, right? Saving money, monetizing, these kinds of technologies.
This is really some kind of really important stage to get this kind of project running, right? And this is really something that really, as mentioned, this was the longest time in this one and a half years, really convinced the guys. It was not the implementation time, right? This was just a case of- Convincing time.
Yeah, it really was about convincing them that that's the right time to start with the technology, that the technology fits, and so on. And of course, it's like when you're looking at, maybe this is kind of like why we called it Neo, so it's a little bit about metrics and so on. And then currently, we're thinking, when you're looking at metrics, I think you've all seen this, we're currently at the stage with this blue and red pill, right? Yeah. So do you really want to jump on one board with DCI or do you want to stay with the old world and see everybody rushing towards you, right?
So I think this is where we are currently right now. And you really have to be brave, as Serena mentioned. So we really need to have this kind of brave attitude to really see, yeah, this is the technology. It's not only a vision, right? That's technology that really changes our lives in the next couple of years. Yeah. I think what I find interesting, and engagement with the bank as well, is that with decentralized identity and these credentials, it's a whole new architecture, right? You're integrating through the wallet, right? You're making the customer the API. The user becomes the API.
You don't need anything in the sky. You don't need a federation anymore. You don't need APIs. And so the challenge is, it's such a new fundamental change, partly. And then also, it's like a Rorschach. If you know what a Rorschach is, whenever somebody learns it, everybody looks at it in a different way. So every stakeholder in the room is thinking something different on what this thing can solve for them, tactically and also art of the possible. And so it's always fun, now that we've got deployments going out everywhere around the world, with Neo, transportation, healthcare, insurance.
For example, one big life insurance company in the US, they realized that because they have regulatory issues around data systems talking to each other, they had to build this massive data lake to aggregate all their metadata and everything. They figured out by using the wallet and having the user be part of the experience, they could reduce data lake costs by 30%.
Now, we didn't think of that. That was their Rorschach view of this technology.
Oh, you're going to reduce my data lake costs for 30%. Oh, we are? I had no idea. I was floored when they told us this, right? So everybody looks at it differently. And it's hard when it's a Rorschach because you have different perspectives in the room and people see different tactical solutions with it, right? But I think the fraud is really driving it now. Like a year ago, AI, yeah, it was there, but it was still too new to be scary.
But now we see the fraud levels going so high, CISOs are really eager to snip the wire in the sky and reroute it through the wallet and frustrate the hackers and the fraudsters. Because by doing that, the adversarial AI, the generative AI, it gets very frustrated. It makes the hack very, very expensive. You've got double cryptography, you've got liveness technology also as part of the equation and biometrics, uniqueness. So that is really now driving a lot of the conversations that I've seen is how security is now looking at an out-of-band check through the wallet as being a priority.
So maybe just to add on that, I think that the video ident, it's just going to be over in a couple of years because it's going to be too easy to copy. So we do need an alternative. And I think that may potentially also speed up the EID development if people understand that it's easier and more secure. Yeah. So another question for you, Christina, how many countries does Swisscom provide a signing service for today? And are there any plans for expansion? Yeah. So it's the entire EU, it's Switzerland for sure. And then we have seven or eight countries in the Americas and Latin America.
And basically there are two sides. We have a white label solution that we provide and that's the technology for the signature. And that can scale very easily because it's a technology part. If it comes to the local regulation, what exactly are the anti-money laundering requirements, the know your customer, the process to open a bank account, that does very much rely on the country. So we always need a partner in place or a customer that guides us through the regulation to scale the technology is the easier part of this. Yeah.
I know a lot of countries are starting to adopt regulations around this. The US hasn't yet, but we're eager to get your services and technology into our customer base because the ability to even let's say for a workforce employee to sign something using their credential and wallet, it's huge inside the Ping ID app, right? We have 40 million users using Ping ID. So we're really excited by this partnership and the ability to empower even countries where there is no regulation to get the same level of assurance and quality. Yeah. And for us, again, we absolutely appreciate it.
And if the regulation status is low, it's easier to enter the market for sure. Exactly. For sure.
Okay, David. I think there was a question in the audience. Okay. Yeah. Let's turn it to the audience. Let's do that. Good morning. My name is Julia von Oertzen from Nexus Group. And I found it interesting that you say they are saving money on their data lakes because they have the data then in the wallet. But what happens, you know, it's on your phone and you lose your phone, it happens. Where is the backup?
Well, it's a real-time integration method. So the wallet is a new avenue of data integration. So it's not just about identity data. It could be any data. And so by leveraging the wallet as a method of integration, a decentralized integration point instead of in the backend with consent and approval built in by the user, they can now move data back and forth between these data systems securely and within regulatory bounds without having to, at the end, collate it on the backside. Does that make sense on the backend?
So that's why they're going to save money because a lot of the data will be integrated and the systems will know about each other without doing it after the fact, after the transaction's over. Does that make sense of what I'm saying? But I think that's a beautiful point.
Like, do you take the red or the blue pill? Exactly. Because in Switzerland, we had this discussion also around our eID application. And the decision was that everything shall be stored locally on the phone. Like 70% of the phones have a special chipset that is super protected where you can leave your credentials. But that means if you lose your phone, you will lose everything. You have to go through the onboarding process.
So for me, it's a very, very interesting example. Like blue pill, make it more secure.
Red pill, improve the customer experience. And I think that's the kind of choices we have to take. And that will also evolve over time. Very good. Any other questions from the audience, including about the presentation or in general in the industry?
Hi, I have a question, which is outside of the financial industry, maybe. Sure. What are the major trends that you see in retail customers with respect to SIAM when they're integrating wallets? Do you hear maybe trends related to the crypto wallets, metamask, something like that, which needs to be integrated for signing processes?
Yeah, I'll give you some examples. Like in the airline industry, we provide services to all the major US airlines, for example, several of the world airlines. One of the airlines said, we don't want to store all this data anymore on our frequent flyers. We don't want the central repository. We would love to move everything out to the edge, except for the email address. And that's it, right?
Otherwise, they're going to interact through the wallet. So we have another retail chain that's deploying credentials and wallets too. It's a huge fast food chain all over the world. They want to do the same thing. They want to empower coupons for free food. It's more secure. They want to move all that data out and the loyalty stuff out to the edge. And they don't want to be liable anymore in case there's a breach, right? So some of the retailers, they don't have these regulatory bodies forcing them to have giant central data stores, right?
The other thing we see is any merchants that are relying parties, like with bank ID, for example, if you're going to leverage that in order to onboard, let's say, to a small loan service, you know, a loan provider for pay-as-you-go loans and things like that, they would love to not have this giant repository of data. They would love to just rely on the fresh data from the bank every time they encounter the user. Does that make sense, what I'm saying? So I think relying parties especially have the opportunity to reduce their breach footprint, as it were.
And I think there will be issuers also, like in the case of the fast food chain, maybe even airlines, that will push everything out to the edge, right? And then have a proofing process to recover or recreate that data, right? Or maybe even back it up and recover it. One of the big shopping mall chains, they want to store the private keys, even in Google Cloud and Apple iCloud and Google Drive, because you do it with passkeys already. The Fido passkey keys are stuck up there anyway. So they made the decision, well, we'll always be able to recover the credential into the wallet.
Let's put everything in the sky as your backup. You know, it's lower risk. It's a loyalty program.
Who cares, right? Now a bank, they're probably not going to do that with their bank ID and credentials, right? Does that help or make sense? Anybody else want to say something? Maybe I would add something, because we're currently in conversation with a sports brand from Germany, which really are interested in DCI and credentials as well. But I just want to switch perspective a little bit, because why are these sports brands or just collecting so much information and storing in the central directories?
Basically, it's just a marketing purpose, to be honest, right? Because they want to send out personalized emails, personalized coupons, marketing letters, right? And now when we're talking about verifying a credential and say, okay, we want to store the data in a credential so you don't have to save your storage. So they are a little bit afraid. So that's why I just want to come up with the other perspective, right? So they came up, yeah, what if we don't have access to the information permanently? How can we set up our marketing scenery in this case?
But at the end, what they actually need is basically your email address, right? So they don't have to collect your delivery address. That could easily come from the credential, right? So this is something that's currently in their mindset that they have to have the overall access to every kind of information. But honestly, they are just using maybe one or 2% of the information they are collecting of a user, right? Every other thing can be outsourced easily.
So this, in my opinion, some retailers have to switch their mindset, to be honest, in this case. That's why I just want to add that one, right? It's just out of tradition.
Yeah, that's it. Do you have a comment?
Yeah, it's just like from a marketing perspective, it's totally right because you collect all the data. And if you want to use it, you recognize that 70% of the data is outdated anyway. So you pay this huge amount of energy for storage, for holding things that are outdated and your campaigns fail because you plan them on mall information. So I think, yeah, future will be different.
I agree, I agree. Any other thoughts from the audience? Questions? Yeah.
Actually, just following up from a previous question, I think one of the questions is, we've been talking about wallets, DI wallets, you know, private public key pairs, verifiable credentials, et cetera. I think the question before also said, what about wallets? We've all got secondary wallets for say cryptocurrencies and stuff. Is there any point that they're going to merge together or separate?
No, it's already happening. And we just, you know, we have contracts that are telling us we have to do this. And payment and identity, I think are going to be the first things to merge. But even document signing and signature and identity obviously is merging together, tightly bound. And we also see a lot of things around ticketing, sports events, a ticket. We have one major association that wants to get rid of Ticketmaster. They want to do all the ticket sales themselves and use digital verifiable credentials in their app.
And then you go to the game, you tap your phone to the gate and you get into the game, right? So you're going to see some big disruptions. Also Visa and MasterCard are struggling. If you look what's happening in India, they're losing all the market share in India because now it's just direct payments to payments. A lot of banks are just enabling this. Verifiable credentials only make it easier and help the security levels. And so you won't need all this insurance anymore. I know Europe wants to get rid of Visa and MasterCard.
Also, there's a big initiative to get rid of these middle people, you know, making money off the transaction. Does that make sense? So I think that there is going to be a lot of disruption, especially as these things come together, right? We have one project where, well, Swisscom has a project they just announced, right? Maybe you want to talk about that. Which one do you refer to? The central bank.
Oh, yeah. Yeah. Did the press release on that, right?
Yeah, right. We're just starting to integrate all the identity pieces more intensively into our banking software that we provide also, so we can offer a more complete solution to the customers. And I totally agree. It's going to be more and more. I think in the end, it will still be the consumer's choice. If the consumer wants to have their Visa app and only maintain their Visa in there, they will still be able to do it. But I think there are two factors that drive innovation, or it's three, actually.
It's the ease of use, it's the accessibility, like easy installation, easy maintenance, low costs also, and then it's the trust. So I think if there's new animals of application that we're pushing as well, we'll play on those three factors. They're going to be super successful, yeah. Yeah. For example, I think also the... One thing that Swisscom and Ping has done, I don't know if you recognize it, but we just created the first network of networks.
We have 2,800 customers. They have like 1,000 or something like this. And now we have a network of networks with DCI, decentralized identity. So anybody that gets issued from their side will be able to interact with our customers and vice versa, right? It's going to be wicked cool. And we're already starting to see the viral effect. And I think that's going to also drive the multifunction capability of these wallets, right? We have one that's a brokerage firm in the United States, the fastest growing transportation company.
They broker between truck drivers and carriers to be able to deliver loads. And they've built out their own identity verification and credentialing technology. And now we just started making the first connections with them because as a trucker, you like to eat a lot of donuts. You eat a lot of, you know, fast food restaurants because you're on the go. So we're starting now to bridge conversations between our own clients and their synergies forming where they want to honor each other's credentials and even issue into each other's wallets. It's pretty cool, right?
To build these storyboards for them and for their board of directors. And so I think that too will also drive the multifaceted nature of a wallet because you may have two brand affinities that want to honor each other's stuff. And one might say, hey, I need to put a ticket to a venue into your wallet. You got to make sure your wallet supports digital ticketing for getting access to the game, right? Does that make sense of what I'm saying? So that I think will also drive the multifaceted.
But a lot of the analysts, including Kaepernick and Kohl are saying, you know, the smart unified wallets are definitely a big trend for the future. So, yeah. I see a little like roaming in the future.
I mean, first when mobile technology was launched, you could only use it in your country. And I remember I was traveling to the US and first thing I would do was trying to get, well, SIM cards came later, but somehow get me connected. And now you can just switch on your phone and you can use it anywhere. And if you look how many people travel globally, move around, et cetera, if you want to apply for a credit card in the US, you need a track record that you have paid a credit back. And if you moved over there, it's a complicated process.
So there are so many tiny bits that we can make easier, but that will help a lot of people on the use cases to have an easier life using the digital technology. Yep, in the back over here.
Daryl, you touched upon the regulation plus, but for customers or clients of yours who are in the regulated kind of sector, how do they go about meeting the challenge of regulation plus because they are still in an environment which restricts them in how they can use it? How they go about trying these new cool features or things which do like make ease or more security or more functionality?
Yeah, well, I called it standards plus so that standards is the common denominator, right across vendors, let's say, or across a regulation or both. But typically, internally, for sure, they can use the value add of any proprietary capabilities in the platform, right?
Now, when it comes to when they start interacting externally, that might be where they may struggle. They may be restricted on what they can do externally. But so far, we have not really experienced that. Any additional functionality, as long as the standards are a checkbox and the platform handles the standards, fine. Anything on top of that is just icing on the cake and value add and most cases, the regulations don't address it because it's not in the standard. So there is no restriction if you want to do push to the wallet to create a presentation, right?
Or if you want to do delegation of credential, for example. You see the point?
So yeah, that's been the experience so far. Is it definitely internally, no problem. When you start going externally, sometimes it can be an issue, but usually because it's outside the scope of the standard or regulation, you can do it. I think maybe also giving a view from a region that loves regulation.
I think on the one side, it's a good thing because it's a very protected environment and also brings a certain level of trust, but it also comes with high costs because if you're a startup, if you're a small company, a lot of our partners, they would simply not be able to provide one of the trusted elements I was talking about before because they're so expensive to produce and the setup costs for all the audits, all the legal checks, et cetera. So it's also kind of preventing a certain level of competition, which is not always good. So the plus is very important that you compete on the plus.
And then I think it's super important if you come from a heavy regulated area that you always scan outside, maybe even perform tests in a country with lower regulation. As you were just saying, Daryl, if it's internally, you can do whatever you want. You can play with the technology, but you cannot launch it to the market. But then there's always like showcasing the next step, promoting things.
And I think that's also a role of the tech industry to provide those information, showing those vision and working together with the regulatory bodies to really make the population profit from the innovation, but in a trusted manner. Maybe one thing to add from my side, because Germany also loves regulations. And when we are especially looking at, for example, the BaFin stuff, right? For financial services. I think we had a lot of discussion with the German banks about the technology and so on.
And definitely we see that the regulation really has some hurdles in regards of identity verification, because when you're applying for an account, you have to go through a manual inspection, right? This is part of regulation. But I definitely think that the overall service of a DCI, including identity verification, as well as credentialing, could solve their problems right now. Because as Christina mentioned, some of the regulation are pretty general. And at the end, it's just all about the exchange of data, right? And if this is secure or not.
But at the end, the whole EID scenario will have an impact on the regulations in the next couple of years, for sure, right? Because everything will change when we have a solid EID infrastructure, right? Where we can really identify a person, right? Because currently, what we're currently talking about authentication, authorization, but in the upcoming future, we're just talking about identification, in my opinion, right? And the EID is one of the part of identification that we need to get. Verified trust, yeah. Verified trust. There's a term verified trust.
You know, we coined the term federation, by the way. Ping invented that word many years ago. So verified trust, we think is the next big wave. And it's really continuous verified trust under the covers, constantly doing, you know, verification on the cover. We're in an implicit model now with just MFA and those kinds of things. It's an implicit that you're the person that's actually getting access. But we need to move to an explicit model where the bindings are very tight.
Identity, the proofing, the device, and your entitlements all being checked and presented together, even on a continuous basis. So that's where the industry's headed and we're calling it verified trust. So FYI. And it's so important also for the customer experience. If you look at digital processes and service problems today at hotlines with customers, 20 to 30% come from sign-on problems, identification problems, video ID going wrong. And that really cuts people off the innovation and off the ability to use those features.
So I certainly believe that we're seeing the next big wave of really making it much, much easier for people to use the digital world in a more secure manner. And I think we have some good solutions on the table for that.
All right, we're coming to the end now. So just to leave you with something, the train has left the station. This is the year for wallets and decentralized identity, including large deployments. It's now time to decide if it's a threat or if it's an opportunity to your organization. And I encourage everyone, you have to get on the train and start playing with it, understanding it, educating. It might take a year and a half just to educate all your stakeholders before you even get to do anything. So it's really important now.
This is the year, we think, and we're seeing it obviously with our deployments now. We have a German saying that says, everybody who stops will be overtaken. And I think if you stop and discuss too long, we will be the developing countries or the developing region in the digitization and you just don't want to be. So I think it's important to see the opportunities, respect the threats and jump on the train.
Yeah, exactly. Okay, well, thank you very much. We'll give back a couple minutes to your time. Enjoy the conference. Thank you.