Hi everyone, I'm Mirela Ciobanu, Lead Editor with The Papers, a global financial publication, and I'm excited to have John Erik Setsaas, Director of Innovation at Tieto Everybanking here live at cyberevolution, and we are going to talk about digital identity and identity wallets. John, hopefully I pronounced your name correctly.
Yes, you did. You did very well. Thanks for having me.
Yeah, it's great. And it's great to meet with you again. The last time, yeah, it was actually one year ago back at the EIC, we met and we talked a lot about digital identity. And I'm curious to know, yeah, what trends have you been following since then related to identity and identity wallets?
So, I mean, identity wallets, since we spoke last, the EIDAS and identity wallets have been approved. So now we know it's going to be two years, according to the present timeline, which I think is too optimistic. But before we have this, the wallets in place. So and we have the large scale pilots are running to experiment, test around with this. So there's a lot of activity going on on that. We are struggling with some of the use cases, you know, why should users do this? Why should the relying parties be using this? Also issues around liability.
As you know, I work with banking, so I'm looking at how would banks utilize these wallets? And we see the challenges with liability. If a bank puts something in the wallet, OK, how could they be liable for misuse of that? So I think we are in the wallet area trying to look at these use cases, trying to find out where it's going to fit. And I think in a few years we're going to laugh at the use cases that really happened because I don't think we see them yet. Yeah.
And related to use cases, one of them, though it's it is an evident one, but on the other hand, it is a very important one, is to prevent fraud. So digital identity solutions usually help in identity, authentication, verification and managing fraud. What are some threats now related to digital identity and transactions payments in general that a digital identity solution wallet would be applied to?
Yeah, you're right. Identity is core.
I mean, we need to know who people are and we've seen a lot of work being done in the last few years now to ensure that the right person is doing the transaction. So we have the two factor authentication. You get a text message or you need to approve on the phone, et cetera. And that's been done really well. And also biometrics are being used. So we are pretty sure now the right user is doing that if all this technology is being deployed. That has been the threat. Somebody has reached out to you, a fraudster, and trying to get your credentials so I can pretend to be you.
Well, that's much more difficult now because I would need that second factor. I would need your biometrics. It's so much more difficult to impersonate now. So what's happening now? We're moving from that and then to the fraudsters hacking people, as I call it. They will do, they will use AI, they will use new technology to convince you that I'm calling from the bank or I'm your manager or I'm your child, et cetera. I trick you, I trigger your sense of urgency. You need to act. So I trick you into transferring money to me. And then I don't need a second factor because you are doing them all.
And that's what I see as the biggest threat going forward now with the identity. We have sort of blocked the impersonation or we are in the face of blocking that. But now the fraudsters, criminals are going to a new way, hacking people and tricking them. And I mean, typical fraud we're seeing is the safe account fraud. Somebody calls you say, hey, I'm from the bank. Somebody's hacked into your bank account and I see the money's disappearing. So you need to hurry. You need to transfer this to a safe account. And you transfer that money to the safe account, which happens to be my account.
And that's how the fraudsters now are operating and stealing the money. Yeah. So this indeed was also part of your presentation. And it seems that indeed the focus now shifts not necessarily on the actual user, but on the transaction itself to analyze it and to make it so we can stop it if it's done under emotional stress, let's say. Right.
I mean, yeah. But I mean, not even emotional stress. We have the long term frauds like the romance fraud where the fraudsters are going to going to work on you for a long time and, you know, pretend to be someone and make you fall in love, et cetera.
And then, well, and now I need some money to, you know, my mom's surgery or things like that. And in those cases, the victims are so convinced that this is real. So even when we as financial crime prevention, we reach out to this victim and say, you know, this transaction of one hundred thousand euros, this is a fraud. We want to stop it. And the victim says, no, no, no, it's not a fraud. This is for the surgery to my, you know, my my friend, lover. And they're so convinced of this being real. So it's not even emotional stress in that sense. Yeah. But how can we prevent this?
Can the European digital identity wallet be part of it or how to stop it? So what we are doing on the financial crime, I mean, we are working with financial institutions, so we monitor transactions. So we know what's a typical user behavior and deviations from that are flagged. So if you suddenly were transferring, you know, a large amount of money to me, which would be nice, of course, that would be unusual. And that unusual transaction would be then be flagged and check if this is a fraud.
Also, one thing we did now, we have just Black Friday. What happens during Black Friday is that a lot of fake stores pop up, stores that only take your money and don't send you anything. We try to keep a list of that. So we block transactions to those accounts. So this is all about monitoring behavior, monitoring what you are, how you are behaving, how you're logging in.
I mean, if I was logging in suddenly from a Mac, I always use Windows. That would be a signal. If I logged in at two o'clock in the morning, John Eric is never awake at that time.
You know, anything that's unusual doesn't mean it's fraud, but it's bigger. So we will analyze that. So so that's how we do analysis of financial transactions. And that's how we see, you know, if it's a romance fraud, you know, this it will recognize the two account very high amount and then it's probability that it's a romance fraud. And when we reach out to the victim, as I mentioned. Yeah. So on the other hand, also, we have this technology, but then to help consumers, on the other hand, we have different regulations, compliance.
So I'm thinking here about the GDPR, about the EIDAS wallet provision not to do profiling. And also I'm thinking since we are referring to financial institutions, this instant payment regulation when things have need to happen instant. So it seems so many things, so many variables within the game for banks to mitigate, to offer the seamless user experience where you would pay and be feel and feel safe and secure. How to balance? It is complex and the banks are under a lot of stress with the financial regulations.
Yeah, I mean, it's it's complex. Just I mean, touch on the IPR, the instant payment regulation, which, you know, is instant payment. Right.
Which is, I think, a fraudster's dream. Right. Because then it has to happen very fast. That gives us little time to investigate. It's only 10 seconds for that transaction to go through. So that's a challenge. GDPR is a challenge for this because we would love to share information with different banks. If we discover you're a fraudster, we would love to tell all banks, you know, but we're not allowed to that. We need to protect the privacy. So which means if you're blocked in one bank, you will just go to another bank and do the same thing and they won't know that that's happening.
So in that sense, GDPR is also a challenge for us. It's protecting the fraudsters. And don't get me wrong. I do. We really do need to protect privacy. That's not what I'm saying. But in this case, we're protecting fraudsters. There are things happening there now. So it's opening up in the financial regulations for sharing information for this. And I think even according to the current regulations, you have the just cause in GDPR for fighting crime would be a way to share information. But it's not very often done.
It's often blocked by the privacy compliancy officer because these are different regulations, you know, fighting for the same thing. And then regarding the European Digital Identity Wallet that they are maybe to expand on how they are helping. Exactly. So and I mean, if you read that, one of the things with the identity wallet is that you're it's very privacy oriented and it's clearly stated you're not allowed to profile. Right. And that causes a problem.
Well, we will still, you know, profile the financial on the financial side, you know, your transactions, the bank and so on. So that's not going to change. But imagine everything you can use the wallet for. You can do a direct person to person payment. How do we control that? You can transfer your potentially your asset. Let's say you have proof that you own this property. Could you imagine that that could be transferred to another wallet? How do we monitor, you know, transfer of value like that? And the problem is, according to current regulation, we cannot do that. Yeah.
So we've been quite pessimists so far. And I want to also share some advice, some positive information. And I'm curious if I am a bank or on the C-level suite of a bank, what should I do to be prepared for everything that is coming in terms of regulation of fighting fraud? Prepare for everything.
OK, that's that's a big one. I mean, so let's start with preparing for regulations. Yeah.
I mean, the regulations are good. They are here to protect us. Yeah. They are here to, you know, make sure we are safe, to catch more fraud and they're tightening. And it's really challenging for the regulated industries because there's a tsunami of regulations coming now with the PSR, PSD3, IPR, DORA, everything. And since you are exactly at the cyber revolution, there are also some things on cybersecurity side. Exactly. So there is so much. And I mean, you and we need to remember there is a reason behind this regulation. And it's all to protect.
That's the reasoning behind them to make sure we do business in a good way and protect people and values. Yeah. But in terms of technology solutions, human expertise, what should the banks use, deploy?
I mean, you need to have user friendly solution and consistent solutions. So for the user, it looks the same every time. We want to try to educate the users to behave in a good way, but then we also need to have consistency on how things are done. If things are done very different in different banks, that's confusing for users. And it's an opportunity for criminals. It's easier for them to come in to do something. So we can have consistency in the user interface, try to educate.
But as you mentioned, if you are under stress, if somebody calls you, I mean, you can with AI today, you can sample anybody's voice and one scam is typically your child, your child. The voice is calling you and, hey, I'm in trouble.
You know, I lost my phone. You don't transfer money. That's a stressful situation. And then it's easy to forget the things you learned.
But still, we need to educate the users. And the three good words are stop, think, check.
Yeah, it's a campaign we're using there, I think. And that is good. And tell users a lot of times things are not really that urgent. In most cases, it's not urgent.
Stop, think, check are the words. So education, consistent user interfaces. I think that's how we can help the end users not to fall victim of fraud. And since you mentioned education, what are some trends or some things that you are taking for cyber evolution back home?
Yeah, I mean, it's what I'm going to say. I mean, education has been mentioned. There's been some interesting presentations on sort of the human, the emotional part of the emotional challenges of this, both for the people involved in from the business side, you know, that's being hacked and so on, how to handle that. And I think that's interesting that that even come into the picture of a fairly technical conference. You start to talk about human, human emotions. There was an interesting presentation this morning about looking at the comparison with personal health and company health.
And I really appreciated that one. I mean, for personal health, I mean, you try to eat healthy, you try to exercise and you should do more, etc. But at least you have some goals and try to do that on your company level as well. Think of your company health. I think that was for me, that was a good takeaway.
Yeah, actually, yeah. Max, we also had him on the interview, had an inspiring story that it seems it has ripples within the minds of everyone. I really appreciate that. I like people and I like stories about people and bringing them into into the picture. And I think that was that was really good. So that's one of my big takeaways.
Yeah, great. Thank you, John, for this discussion. And I'm sorry that I don't have the fake voice video that you had with Jean-Luc Picard to end.
Yeah, on a funny note, our interview. No, but that's fine.
Hey, thank you so much for having me here.