SardineCon SF/2026

Learn More
Fraudology

Convergência organizacional em fraude: novos benchmarks e o que realmente funciona

68 min

Bem-vindos de volta ao Fraudology.

Hoje é um episódio solo, construído em torno de um estudo que coloca um número real em algo que os líderes de fraude vêm debatendo há anos: a convergência organizacional em fraude realmente muda o desempenho ou é apenas uma tendência de organograma?

Durante anos, todos nós nos medimos da mesma forma. A taxa de aprovação aqui, a taxa de chargeback ali, talvez uma taxa de revisão manual se quisermos ser rigorosos. Mas o problema que vi se repetir empresa após empresa é este: você otimiza a taxa de aprovação e a taxa de chargeback sobe silenciosamente. Otimiza a taxa de chargeback bloqueando mais e a taxa de aprovação sofre. Você nunca vê o quadro completo, apenas uma alavanca se movendo às custas da outra.

A métrica Precise Yes é a principal descoberta de um novo estudo da Liminal e da Accertify, mas o estudo em si é muito maior do que uma única métrica. Ele entrevistou 250 líderes sêniores de fraude, segurança e risco em cinco verticais do setor, especificamente para testar a tese da convergência organizacional entre fraude e cibersegurança. Eu percorro o que os dados dizem, quais formas de convergência realmente melhoram o desempenho antifraude e quais não mudam nada.

Este é um episódio denso em dados, e digo isso como um elogio ao estudo. Se você já precisou de um KPI de fraude para reporte ao CFO que capture de fato o equilíbrio entre aprovações e perdas com fraude, este é o que vale levar de volta para a sua equipe.

O que você vai ouvir neste episódio:

  • Como a métrica Precise Yes é calculada e por que a taxa de aprovação e a de chargeback isoladamente podem esconder a história real do seu programa antifraude
  • Por que a convergência organizacional entre fraude e cibersegurança é impulsionada por necessidade operacional, e não por determinação da diretoria, e o que isso significa para a forma como as equipes estão de fato mudando
  • Por que o login se tornou o novo ponto de controle antifraude, com tomada de conta, credential stuffing e ataques de bots convergindo todos nessa etapa
  • Por que 63,6% das organizações ainda não conseguem distinguir um ataque cibernético de um ataque de fraude em tempo real, e o que isso lhes custa no dia a dia
  • Como a responsabilidade do CISO sobre fraude vem aparecendo mais cedo no processo de decisão sobre fornecedores, e por que o reporte de fraude no nível do conselho está se tornando um tema real de governança
  • Por que a integração parcial é o modelo de maior desempenho para a convergência organizacional em fraude, e por que forçar uma integração estrutural completa pode corroer a especialização que torna as equipes eficazes
  • Por que compartilhar apenas dois ou mais casos de uso entre as equipes de fraude e cyber é o verdadeiro ponto de virada de desempenho, entregando uma melhoria de 1,5x nas pontuações de desempenho antifraude
  • Por que orçamentos separados entre as equipes de fraude e cyber têm desempenho melhor do que os unificados, contrariando uma das suposições mais comuns sobre convergência
  • Como as métricas de fraude variam por vertical do setor, incluindo por que e-commerce e varejo lideram enquanto os marketplaces ficam bem atrás
  • O que o estudo encontrou sobre controles de fraude no comércio agêntico e fraude de identidade sintética especificamente no e-commerce

Quem deve ouvir:

  • Líderes de fraude em busca de um KPI de fraude para reporte ao CFO que capture o equilíbrio real entre aprovações e perdas com fraude.
  • Quem está construindo um business case para a convergência entre fraude e cibersegurança e precisa de dados reais para sustentá-lo.
  • CISOs e líderes de segurança cada vez mais envolvidos na avaliação de ferramentas antifraude e nas decisões sobre fornecedores.
  • Equipes de fraude tentando descobrir por onde começar com casos de uso compartilhados entre fraude e cyber sem uma reorganização completa.
  • Profissionais de fraude de e-commerce e marketplaces que querem um estudo de benchmarking de fraude em e-commerce para comparar o próprio desempenho.
  • Quem é responsável pelo reporte de fraude no nível do conselho ou por defender a visibilidade da fraude junto à alta liderança.

Conecte-se com Karisse Hendrick | LinkedIn
Apresentadora do podcast Fraudology
Especialista premiada em cyberfraude
Consultora de prevenção à fraude em e-commerce
Conselheira de startups, palestrante e
consultora de varejistas da Fortune 500

Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:06
Welcome back to Fraudology. I'm Karisse Hendrick. I'm still getting used to this YouTube thing. And especially doing solo episodes by myself. So bear with me a little bit. Still working on the lighting, doing the best we can here. This, I have a new light, but it it keeps moving. But I'll try to keep it on me. I appreciate your guys' patience. For those of you that are still listening, nothing's really changed for you. But yeah, it's just weird for me to be watching myself talk. And think that other people are gonna watch myself talk to myself in the computer. Today I'm gonna go through a study that I found really interesting on e-commerce merchants, in the fraud landscape specifically. And the convergence of cybersecurity and fraud teams working together. And how that impacts and is directly correlated to success. Which we measure success in higher authorizations and lower chargebacks. And a lot of time, and I know money, was put into that study. And so I'm really looking forward to sharing more about it and going through it with you on today's episode. But first, a couple of announcements. Or just kind of reminders. If you have not watched the last few interview episodes, or listened to the last few interview episodes of Fraudology, you have been missing out on some really good conversations.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
01:47
First I started off with Mark Porteous, previously the head of Fraud at StockX. And we talked about market volatility and how it really impacts marketplaces in some unique ways.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:00
Then Tal Yeshanov, who has worked for Uber and several other companies in the fintech startup space, joined me and we talked about AI. And AI specific to fraud fighting, and how it's changing the game. We've seen a couple of iterations of fraud fighting over the last 20 years. And AI is definitely impacting is the newest iteration of that. And I I just I really enjoy talking with Tal. I honestly enjoy talking with all three of them. But I've known Tal a long time and I know how good she is at what she does. And I know the specific things that she's done in her career that we can't really talk about. So I always hang on every word she says because I know she knows what she's talking about.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:00
Same goes with Dave G. We could not mention the name of the company that he works for. Because we just have to go through so many more hoops with PR and communications and everything else. If you do light looking up on, you know, a certain professional social media site. You will probably find that out, and be very impressed. He's the guy there for fraud and oversees all of their business lines and everything else. He's worked at Google for over 10 years on some really impressive projects that are well known. And also at Airbnb and really has a good insight on the future of agentic commerce. From his unique vantage point, of where he works now, as well as just all of his experiences combined. I actually found myself quoting him the next day when I was on a business call with a company that I advised. Talking about how he doesn't think that agentic commerce is gonna be big in retail, the way that a lot of people think.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:18
But that instead it's gonna be things, you know, like milk, bread, and eggs. And he really broke that down. And explained a different world of agentic commerce than everyone is talking about right now at conferences and everywhere else. It actually influenced some of the direction that we're going for content for Merchant Fraud Alliance, actually. Because I think he's right in a lot of ways. And we need to be prepared for that world, not necessarily the one that we have envisioned already.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:54
Speaking of MFA, I know it's always hard in our industry because MFA also stands for multi-factor authentication. But now it stands for Merchant Fraud Alliance. I have talked about this on the podcast before. I am directly involved in one of the co-founders of MFA. I am responsible for the content as well as a lot of the speakers, or most of the speakers and the ambassador program that we have. Which is basically our advisory board. We do, I'm really just wanted to remind everyone that it is now less than two months away. It's in Chicago, October sixth and seventh. We will be in the Willis Tower, which is formerly the Sears Tower. I know anyone that lives in Chicago refuses to call it the Willis Tower. The hotels are only a block away. It's just it's so exciting. I've been working on the content and working with the speakers for the last several weeks and I I just can't imagine anyone missing it, to be honest. Especially because of our ambassadors and our, you know, who are basically our advisory board. We have topics on the agenda and conversations that are happening that have never happened at conferences before. At least not formally. Right? Maybe they've happened in the hallway a little bit here and there. But we're gonna have a strong focus on leadership and fraud. There are some very unique things to leading a fraud team that you're not gonna pick up in any leadership book. You know, cross-functional relationships, cross-functional leadership. That's one of them. Setting up a center of excellence for fraud. Honestly, you know, what I'm talking about today as far as the convergence of cybersecurity and fraud and working closely with them more upstream than just at the checkout funnel. Those are things that are all going to be talked about in depth.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:02
One of the most unique things about MFA is that we are not selling vendor tickets. That would be a very easy business model. That would be the safe route. We're not doing that because we want to preserve the conversations between merchants. We are inviting, we do have about 15 solution providers that have been invited and that are attending as sponsors. They're really covering the cost of the event, primarily. And so we will have some great solution providers contributing to the conversations. Because they have some great perspectives, you know, across all different types of merchants. But we're not going to have, you know, 80% of the room be salespeople. That's just, that's what merchants have been asking for for years. Is, we just want to have a space to talk to each other. Without constantly being a target for sales. Now obviously there will be those conversations being had, but the ratio of merchants to vendor will be multiple. And so, you know, we'll have, you know, three or four merchants to every one vendor. And that's gonna make a difference in the conversations that we have and the people that you meet. So if you are a leader in fraud or you want to be a leader in fraud, I really hope that you make it a priority to attend MFA.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:35
We do have a few promotions to help cover the costs. I realize more than anyone, because I'm talking to a lot of you every day. Budgets have changed, especially in the second half of 2026. Travel is much more difficult. So we're, we have ways to help you get there if you need to. So reach out to me on LinkedIn and I can share a couple of options that we have. If you want to speak it's not too late. I do have a couple of openings. That's a good way to get a free ticket. So anyway, I just I don't want you to have FOMO in October. And I'm really proud of what we're building. So you know, check out the website for names of just a few of the merchant attendees. The ones that are ambassadors and have been advising us on content and direction and what, you know, merchants really want. I mean, I think I have a pretty good idea, but I haven't been on the front lines in like almost 15 years. So I never want to assume that I know what people want to learn about or, you know, do.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:50
And I, one of the ideas that came out of an ambassador meeting was an AI boot camp. The day before the conference. We have Stephanie Gorostiza at PlayStation, and working on filling that second spot, who are going to actually give you takeaways in AI. They're gonna show you how they're using AI and their company to just increase their workload and their workflows. And improve their workflows. And going to give you actual takeaways that you can take back to your company in the form of queries, prompts, a dashboard, that type of thing. You know, ways to use your data. That's included in the cost of your conference registration, and only available to the first fifty attendees. I know we have a few spots left. Not everyone who has registered wanted to attend, or is gonna be in town early enough to attend. But that's one of the things that came out of the ambassador, you know, working or our meetings was hey, there's a lot of people that just wanna know, what do I do? How do I do it? How do I use Claude? How do I use Copilot? What what can we do? What shouldn't we do? How do I train my team on it so that they're more efficient? And that's what we created.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:20
So, like I said, check out the website for the names of just a few of the attendees, our ambassadors, as well as session topics. We're gonna have a strong focus. We're gonna have a cohort of sessions focused specifically on leadership and fraud, as I said. You know, the specifics that somebody who is a leader in fraud has to deal with. That someone in as a leader in another part of the business just doesn't have to think about. But a lot of content and people that you don't usually see at conferences. So that is my plug for MFA. If you have any other questions, let me know. It'd be great if you could bring your team. If you can only bring yourself, that's fine. I just don't want anyone to miss out, because it's gonna be really awesome. And I'm very proud to be a part of it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:16
One more thing before I dive into the survey. I wanted to clear something up. There's been a little bit of confusion. About some announcements that were made about Fraudology about a month ago. And that was along with the rebranding and the launch of YouTube. It was also announced that Fraudology is a part of Sardine Media. And I tried on all the, all the postings that I had some influence on. I tried to be very thoughtful about the wording of it. There was one specific post, that made it really confusing for people. And I'm not blaming the person that posted it at all. They just didn't know that that was important to me. Or why, you know. We just hadn't had that conversation. But basically, I wanted to just clarify. That even though Fraudology is, you know, on Sardine Media's platform, as a network. Fraudology is still independent and autonomous. We weren't acquired by Sardine. If you've been listening to Fraudology for a while, you know that we were on the Rolled Up Network for several years. I had a producer that I worked with at Rolled Up. They, he really helped me with a lot of things, in creating the podcast, you know, consistency and sponsorships, the business model. He helped with, you know, making this a good production. And having really excellent editors. A lot of things for the growth, of Fraudology. And really to make it the number one podcast in fraud. Which I'm still so grateful that I get to say. Sardine has been a sponsor for the past year and a half, maybe two years now. And we do offer exclusive partner sponsorships. So, and it's been a hundred percent their choice to continue, and and my choice as well. Because I still really respect them as a product, and as a company, and as people. And I really like working with them. And I've yet to have anyone who has talked to Sardine, you know, complain. Or anyone who's using Sardine, to complain to me about them. So I'm gonna continue to partner with them. I ended the relationship with the Rolled Up network at the end of 2025 and it was always on the roadmap, or agenda, to move Fraudology to the Sardine Network. Which is called Sardine Media. There was an offer to acquire Fraudology, as part of Sardine, as the company. And they would own that. For various reasons, I chose to keep it. To own, so I still own all of the content. I still own the independence, and the autonomous nature. I don't have to run anything by them before I say it, or anything like that. I can talk about other solutions, that type of thing. I mean, it is part of the sponsorship, that I not interview competitors. But that's a standard thing, in all sponsorships, in these type of podcasts. So, but I still, you know, can mention other companies. I still can provide my, my opinion on things without running it past them.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:00
With the rebranding and the relaunch on YouTube, we just expanded the partnership. We announced that Fraudology is on the Sardine platform. They are now the, the network of sends. Instead of Rolled Up media. But nothing else has changed. I've gotten several messages, phone calls, emails asking me about it. Especially from other solution providers. But also from merchants. Who, and banks. Who, let's be honest, don't always trust vendor produced content. Because they see it as having you know agenda. Whereas I don't have skin in the game. I don't have stock in Sardine. I don't have stock in other, you know. There's just, my performance is not tied to their performance, and vice versa. So, I wanted to make that super clear. I'm gonna try to clear that up on LinkedIn as well. I just know it was a little muddy, in how it was framed in some posts. And I just wanted you guys to know that I'm not being censored. I can still be trusted with your secrets, and your problems. And they won't be, you know, shared with anyone else. So anyway, that's that was really important me to share on this podcast. But as somebody in fraud, the details are important to me. So I'm gonna go deep. Speaking of that, let's get into the main topic.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
17:42
I wrote a few things on a post-it note. That I was going to put up on my screen, and then I realized it covered up my camera. So I'm gonna read this off a little bit, but the main part of today's episode is gonna be going through a new study published by Liminal and a Accertify. And it's on the e-commerce merchant fraud landscape and fraud. I know that lots of banks listen. You are still very welcome to listen or watch the podcast. But today is gonna be mostly focused on e-commerce merchants. And how they're navigating fraud operations as well as strategy. This study had some really unique insights and data that I found insightful and interesting. So I think you will too. Anytime new data is thoughtfully shared in our industry, I think we should consume it. And think about its relevance to your own fraud ops and strategies. It provides a way to benchmark your progress and identify areas to improve. I first saw the preview of this study's findings at the Accertify Customer Summit back in May. I can't believe it was that long ago. They've since published two full studies, and have three more to look forward to. From all the data that came from this project. The main report, the one I want to go through today, is on the CNP merchant landscape as a whole. They've also published a study specific to retail, that's really interesting. They sectioned things off by vertical. Because they recognize that different verticals within e-commerce or CMP as a whole, whether that's in-app purchases or e-com on web, etc.They recognize that those, not only are those companies structured differently, so they have different priorities and different objectives and different makeup. But also different problems and different data. They really looked at, you know, the success markers that we talk about in fraud. The, you know, a percentage of approved orders versus the percentage of chargebacks to sales. And they recognize that those verticals have different results. Because they're handling things differently. They have different priorities and different approaches to fraud. And so they'll be producing a couple more reports about other verticals. Such as marketplaces and quick service restaurants, and I think one more. I think travel is one, travel and ticketing. I'm so sorry. I'm gonna be grabbing my water more today than ever before. Side note. I, we moved to Spokane, Washington from Seattle a few years ago. And if you've been watching the news at all in the US. You know that we have a lot of wildfires right now. That are actually, you know, in the city. Separate topic for a separate podcast. But my throat is so dry. I had a migraine for the last two days. The air quality index is really high. And so I'm gonna be drinking a lot more water today. I'm also gonna probably be stopping a few times to clear my throat. It's just the reality of where I live right now. Obviously my family and my house are safe.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
21:28
We're about five miles from the fires. I do know people that were impacted. I actually grew up in the neighborhood that was impacted most by the fires. So several of my friends from high school's parents, as well as some of my friends from high school, were evacuated and have had damage to their property. I don't think any of them have lost their houses, not that I've heard. But there's a lot of smoke damage, just such a mess. Anyway, now what we're here to talk about, but I felt like I had to explain why I'm gonna be reaching for my water bottle a lot today. So anyway, they're in the process of publishing those separate studies for the other verticals. Including marketplaces and QSR. So make sure that you look out for that. It's not, it's not every day that we get new data and information about our industry. Benchmarking is tough. And some of the studies that are out there don't always feel relevant or necessarily, I don't want to say accurate, but just not relevant. And so I think it's really good to be able to take a step back and look at the industry as a whole. Where you fit into it, how you fit into it, how you compare to it, and also identify ways to improve. And that's what I think this study does. So we reading it on my laptop. I tried to print it out, but it's on landscape, not portrait, and I was having issues with the settings. It's always a thing. So I'm gonna be reading it this way. But this study really tests whether fraud and cybersecurity convergence are producing better results. They say that fraud and cybersecurity have long operated as separate disciplines. But as attackers increasingly blend tactics across both domains, this study tests whether organizations that converge their defenses achieve better outcomes.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:43
I had a hypothesis about this and I was mostly right. But there were some things that were interesting to me, or that I had never thought of before. So in the background to the study they say, fraud leaders and cybersecurity leaders have historically operated as separate buying centers with separate budgets, tools, and reporting lines. That separation is breaking down. Attackers now blend fraud and cyber attacks in a single campaign and the same identity. Oh, the same identity device and network signals sit at the center of both functions. As the threats converge, the question for every security and risk organization is whether their teams, data, and investments should converge too. This report uses proprietary study data to test the that thesis, and to quantify the value of convergence. Their hypothesis is that fraud and security are converging, and that organizations that converge deliberately at the level of data and operations, outperform those that don't. The two buying centers are merging. CISOs are buying fraud tools, and fraud leaders are buying cyber capabilities. Operational necessity is driving it. Resource constraints and shared visibility needs, not executive mandates. And that the customer experience is the prize. CX improvement, not compliance, is the top justification for converged solutions. I've long talked about, and all my guests on Fraudology have long talked about, over the last six years, but especially the last three or four, about how fraud signals are moving upstream.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:33
We used to just take a snapshot at the time of checkout. All of the data that was input at the checkout page, would go to a PSP and or a fraud provider. And would be looked at and cross-referenced, maybe with some outside third-party data provider. But really we're just looking at the snapshot, the device that's being used, the browser that's being used. If if you were capturing device information, that was what you were capturing. Was the time of checkout. Just like this report said, attackers are blending their tactics into single attacks. They're moving upstream. Or they're using one device to enter your website, and another device to make a purchase. Because they're assuming that you're just taking that snapshot. The best analogy I've heard, I think, came from Matt Vega several years ago when he joined Sardine. And that was that, you know, we used to just take a picture at the time. You know, If you make the analogy of someone breaking into your house, they would just take a picture. It would be like taking a picture of somebody entering your house. But what if you had video cameras that could take pictures of them, or take video, like constant surveillance. Of how they're accessing your house, and how they're studying your house, and what they're observing. And just all of those things. And then what they do once they're inside your house. Where do they go first? What do they steal, right? That's the difference between just looking at checkout, and just using fraud tools within our fraud domain that we've always had. Which was checkout. To using cybersecurity tools. Such as using you know device ID, and behavior biometrics, and the signals that are being passed on from the moment someone enters your website, or your app. Until the moment they're gone. And they leave. Even to post-purchase when they're, if they're asking for a refund. That is a huge difference. That's a huge change. You can, when you have video, or constant surveillance, into how they are attacking your system and what they're doing earlier on, you may not need to call the bank. You may not need to check the payment method.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
28:20
You might be able to know that they're suspicious before. Or you may not need to do a fraud check after the payment goes through. Because you feel completely good about that transaction and that interaction. You know that the person behind that that purchase is who they say they are and that they're using their own payment method. So that's really what we're talking about today. I wanted to talk about the reason for the convergence before talking about the convergence. Fraud attacks are definitely happening further upstream. Think about account takeovers, about bots, about so many different other things. Or they're combining them, right? They're, you know, using a bot to do card testing, for example.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:09
Let's talk a little bit about the methodology. I'm not gonna go into all of it, but I think it's important to understand it. So it's a proprietary survey of 250 qualified security, fraud, and risk leaders. To test the convergence theories, or thesis, Liminal and Accertify surveyed 250 senior security, fraud, and risk leaders across five industry verticals and three regions. Measuring not just how organizations are structured, but whether convergence actually produces a better fraud performance outcome.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:47
So does working with your cybersecurity team, or using some of their tools that they use for cybersecurity, and vice versa. Letting them use some of your tools for fraud, for cybersecurity, or purchasing a new tool and splitting it with cybersecurity. Does that actually impact your bottom line? Does that actually impact your fraud performance? That's the question. So the regions were in North America, Europe, and APAC. I know that it was primarily North America. And then the industry verticals. I should have just looked at the next page to be able to tell you. E-commerce retail, travel, marketplaces, restaurants and QSRs, and entertainment and media. So those will be the five studies that will come out. I think marketplaces next after retail. And I'm ninety percent sure that the retail survey is out. If you can't find it on the Accertify website, it might be because they gave me an early copy. But I think it's out. So if for whatever reason you can't find it, let me know and I'll check with them where to you know direct you. What the survey measured: how organizations structure their fraud and security responsibilities, where detection and investments are concentrated across the customer journey, how fraud and cyber teams share data, signals, and decisions, and then real performance. They provide approval rates, chargebacks, and fraud outcomes. If nothing else, you should use this survey to benchmark your approval rates, and your chargeback rate, and what they call a yes score. That was a new term for me at the conference. And we'll go through that in just a minute, but they tell you how to do the math and you know why it's relevant. If nothing else, compare those statistics of your company with those in the study. For nothing else, use it as a benchmarking tool. But I think there's other nuggets in here too. So the threats organizations care about most are hybrid. They cross the fraud and cyber boundary. Payment fraud, bot attacks, and synthetic identity top the priority list across every vertical surveyed. And each of these threats crosses the fraud-cyber boundary in ways that a siloed organizational structure is fundamentally unable to address. The threats that, so they were asked about their top fraud and cybersecurity threats. That are discussed within the organizations.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
32:29
Number one was payment fraud. Number two was bot and automated attacks. Then came synthetic identity fraud, which different companies define that in different ways. So I'm not a hundred percent sure how that was defined in the survey. Synthetic identity is typically used in banking and underwriting, consumer lending, etc. So not sure how they were identifying synthetic identity fraud in an e-commerce context, but that was third. Promotional and loyalty abuse was fourth. Social engineering was fifth. This is across all verticals. This changes, I can give you a little preview at least of the retail survey. This changes dramatically by vertical. What they're most worried about. But overall, social engineering, then the ATO attacks, then malware and ransomware and data theft. A lot of the typographies within fraud are covered within that list. And they're talking about which ones are most important to your company right now? What are they talking about the most? The threats that organizations rank as most pressing share a common trait. They don't belong to fraud or security alone. A bot-driven attack like credential stuffing is a network security event and a precursor to fraud. The synthetic identities near the top of the concern list are built from stolen data, a cybercrime. Long before they're ever used to commit financial fraud. The three threats that buyers, meaning merchants, prioritize most all sit squarely on the line between fraud operations and security operations. Which is exactly why attacks of this kind are so hard for either team to fully own. That blurring is what leaves siloed teams at a structural disadvantage. When a single attack chain is split between two groups, each one sees only half of it and responds to only half of it. The pattern in the data makes the point. The threats traditionally associated with cybersecurity, like malware, ransomware, and data theft, fall to the bottom of the priority list. Like I said, malware and ransomware and data theft, those were at the bottom of the priority list that I just mentioned. The organizations surveyed aren't running conventional IT security programs. They're running digitally native commerce protection programs. And the hybrid nature of the threats they face is precisely what makes a unified detection model necessary. So, because bots, and synthetic ID, and loyalty abuse, and account takeover, and all of these things are crossing the boundaries. They aren't just happening at checkout. We need to go upstream and we need to use cybersecurity signals.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
35:40
Attacks now chain across every stage of the customer lifecycle, and login is the new frontline. Account login has emerged as the most contested control point in fraud prevention. Concentrating the highest share of current investment while also leading every other lifecycle stage as the top expansion priority for the year ahead. So they were asked you know, what they're prioritizing today and what they're prioritizing next year. As far as purchasing products, right? Like in an RFP, what type of products are they looking for? Or what are they looking to solve with the products that they're looking for? Account login was highest for this year. It was also highest for next year. Then it was checkout, then it was account changes, then account creation, and then post purchase was pretty far down the list and mostly for next year.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Henrick
36:37
The traditional focus on checkout has given way to an approach that spans the entire customer lifecycle. With login emerging as the primary control point. That's because login is where account takeover, credential stuffing, and bot attacks converge, making it a shared problem. The credential stuffing and bot traffic are cybersecurity concerns. While the account takeover and fraudulent access they enable are fraud concerns. Defending the login stage requires both teams to work from the same control point and the same signals. Because a successful login by a fraudster or a bot is a failure that propagates through every subsequent stage. So, you know, once they get through the login, then they can commit their crime. And it's harder to identify them. From there, organizations are extending coverage earlier in the life cycle, upstream. Account creation and account changes are both growing areas of expansion. Each nearly matching the growth in login prioritization. And spending is rising at every lifecycle stage. With the strongest signal at login. What was once a single checkpoint at checkout has become a continuous effort. The entire customer journey is now a fraud control service. So basically what I was saying just a little bit ago. And what we've been talking about on Fraudology for the last several years. But it's good to see it in data, right? To have the data support what our observations, is validating.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:19
And AI is amplifying both sides. It makes attacks more sophisticated while expanding the surface. Generative AI is escalating fraud sophistication at the same time that agentic commerce is expanding the transaction surface. Leaving organizations that build their defenses for human users increasingly exposed on both fronts. This is true. So seventy six percent of the participants, of those two hundred and fifty participants, reported an increase in AI enabled fraud. Over the past twelve to twenty four months. 57.6% of them see 6 to 15% of transactions initiated by AI agents. Indicating a need for sophisticated fraud controls. And then 92.8% of them expect Agentic commerce to require strategy changes to their fraud prevention approach. Even if it's just for milk, bread, and eggs, you still are gonna have to have a fraud, you know, strategy and approach. AI has become both an attack vector and a new commerce channel. And the fraud playbook written for human users doesn't apply to AI agents. Defending against them calls for new detection logic, new authentication models, and new risk signals. Most organizations recognize this. And 96.4% already have some form of agentic fraud controls in place. Having control is not the same thing as having adequate coverage. 32% admit that those controls only partially address the risk. That space between adoption and confidence is where the next wave of fraud losses will land. And closing it will require teams to build agent aware defenses together rather than in parallel. So together with their cybersecurity team rather than in parallel within their silos. Fraud and cyber teams rely on the same signals, but run them through separate systems. I hadn't totally thought of it that way, but it's, that's true. I hadn't thought about that till I read the survey, I should say. Identity, network, and device signals anchor both fraud and cybersecurity toolkits at nearly identical rates. Meaning most organizations are paying for the same data twice and building the same detection logic in two separate places. I think there's a lot of truth to that. Both are collecting device ID, both are, you know, doing bot detection. Both are creating like all these other things. They're, you're paying for it twice. That's a good way of looking at it. So they talked about the fraud and cybersecurity team signal reliance. And asked the fraud team and cyber teams, and they're almost identical. Both rely on identity and authentication the most. Both rely on network and IP intelligence, device intelligence, behavior signals, and bot detection. So they're both relying on the same signals. But they're ingesting them into different tools and looking at different risks and different risk factors. Depending on if they're trying to protect the data that's within the walls of the organization, like cybersecurity's purposes, or if they're trying to protect the money and stop fraud. Both teams ultimately rely on the same core data. The differences in how fraud and cyber teams use signals are marginal. Cyber teams lean slightly more on behavioral signals and bot detection, but identity network and device signals anchor both toolkits at nearly identical rates. That overlap is exactly why running the same signals through separate platforms is redundant, costly, and prone to blind spots. When a fraud team's device intelligence and a cyber team's network intelligence sit in separate systems, the signal one team catches may not reach the other in time to stop the attack. So they're only gonna see one piece of it. And so they're maybe not gonna talk to each other and say, Hey, I'm seeing a sign of account takeover here. You might see it as payment fraud down there, and vice versa.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
42:34
Yeah, the signal one team catches may not reach the other in time to stop the attack. The organization also ends up paying twice for the same data feeds and building the same detection logic in two places. The heavy signal overlap isn't just a curiosity in the data. It's a direct, measurable argument for consolidating onto a shared platform. 63.6% of the respondents cannot distinguish a cyber attack from a fraud attack in real time. I thought this was really interesting. When organizations can classify only, or can only classify a threat after the fact, they cannot route it to the right team, apply the right playbook, or stop the downstream damage that follows. Making real-time detection a prerequisite for effective convergence. So yeah, sixty-three point six percent of respondents have no way of distinguishing in real time, whether an attack is cyber related or fraud related. And that means that 36.4% can detect it in real time. But as this study says, if you cannot classify what's hitting you in real time, you cannot respond to it effectively. An unclassified incident can't be routed to the right team, met with the right playbook, or measured correctly once the post-incident review comes around. And the ambiguity compounds. A credential stuffing attack misrouted to the security team might receive a patch based response while the fraud team stays unaware of account takeover risk building downstream. They have no idea that, you know, at login there wasn't suspicious activity or credential stuffing if they're not working in tandem with cybersecurity. The deeper problem is that the attacks themselves have already converged while the detection architecture hasn't caught up. Maintaining separate detection systems for threats that can't be classified in the moment, builds a structural weakness into the organization. And converge detection is simply the practical response to a threat landscape that has already merged. This is the most operational argument for platform integration. So, and it says and notably it holds regardless of whether an organization ever changes its reporting lines or structures of its team. So if you're not yet working with your cybersecurity team, use this survey, or this study, to talk with them. And say, hey, I really think we should be working together. Maybe we don't need to be sharing the same tools yet. However, we should be sharing signals. We should be sharing, we should have some kind of an alert system. Or you know, we should be able to use the same signals as cybersecurity to fight fraud for this reason.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
45:38
96.8% report ownership changes and the CISO is at the fraud table. This was also new information to me. Convergence is reshaping who owns fraud decisions with risk leaders in most organizations. But the CISO is now involved in fraud solution evaluation at nearly three-quarters of the companies surveyed. Making both stakeholders essential to any vendor conversation. So obviously, you know, this study was produced by Accertify to understand the market. But they're sharing the results with the market because they know that it can help you do your job better. And you can learn from this on how to improve your fraud strategy by, you know, sharing information and working with your cybersecurity team. So you know, fraud and cyber related ownership, they cited more coordination, fraud is expanding into cyber, they're moving towards a unified function, cyber is expanding into fraud. Only 3.2% of merchants surveyed said that they really haven't seen any change in fraud and cybersecurity working together. Risk owners own fraud in 77.6% of organizations and would sponsor convergence in 70% of the cases. So the budget and the mandate still sit largely with the risk function. But the CISO is increasingly in the room too. Already at the table for fraud evaluation in 70% of organizations. It used to be that when you went through an RFP, you only needed cybersecurity's input at the very end. Not the very, but like the fraud team would select which tool to use or they would at least very strongly advise. And then you would need legals sign off on the contract. You would need cybersecurity to do their due diligence on the vendor to determine the safety of your customer's data with that vendor. Now, cybersecurity lead, what this study is saying is that cybersecurity leaders and CISOs are more involved in that first part of an RFP. The part where the decision is made. Once the decision is made, yeah, they have to check out the vendor and make sure that their systems are safe and all of that. But, they're in the room while those decisions are being made. Not just after the fact. Where the CISO doesn't yet lead, the appetite for change is striking. 94.9% expect that stronger CISO involvement would reduce fraud incidents. For solution providers, the implication is hard to miss. Selling to fraud alone or to cybersecurity alone is increasingly inefficient because both stakeholders are now evaluating the same decisions. So this is saying that fraud metrics have a narrow range. Requiring historical data to access convergence. So approval rates, chargeback rates, and pass-through rates, cluster tightly across all five verticals studied. Which means the meaningful performance differences between organizations only become visible when you examine how these metrics have shifted over time. So, you know, you look at how your approval rate has moved over time. Or how your chargeback rate has gone down over time. Your legitimate pass-through rate, you know, your legitimate customer pass-through rate, your manual review rate. So you're looking at all those indicators and saying, are they going up or are they going down? Are we doing a good job or do we need to invest more? That type of thing.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
49:30
But Accertify and Liminal really think that we should introduce a new metric. A metric that I hadn't heard of before. I mean I've heard of attack rate, you know, all the things. But I'd never heard of a precise yes score. But they say that it captures both the approval performance and fraud control. Because optimizing approval rate and chargeback rate independently can quite quietly make the other one worse, a composite metric that captures both dimensions simultaneously is the only reliable way to measure whether an organization is genuinely outperforming its peers. So if you just look at your approval rate, or your manual review rate or your chargeback rate, then oftentimes if you improve your chargeback rate, your approval rate goes down. If you improve your approval rate, your chargeback rate goes up. So the math that they say to get to the precise yes score, I probably would have named it something else, but that wasn't, I wasn't asked to, so we're just gonna call it what they're calling it. It's the approved dollar volume percentage divided by the fraud chargeback rate percentage. So if you divide the approved dollar volume percentage by the fraud chargeback rate, you get this precise yes score.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
51:02
You can improve your approval rate by letting more fraud through. You can improve your chargeback rate by blocking more transactions. Basically what I just said. Optimizing either number on its own, can quietly make the other one worse. The precise yes score captures both dimensions at once. It rewards organizations that achieve high approvals and low fraud together. And it penalizes those trading one for the other. So the score represents the number of dollars approved for every dollar of fraud loss. An organization approving 98% of dollar volume with a 0.25% chargeback rate receives a score of 392. The higher the score, the better, better your organization is at balancing the two, is basically how they explain it. So if you have 98% approvals but, and 0.25% chargeback rate, you're gonna have score of 392. One that approves 98.5 percent with, at, with 0.15% chargebacks achieves a 657. That means that for every you're approving $657 for every one dollar of fraud that you're declining. Same approval story, different fraud control. So then they provide the precise yes methodology and score for those verticals. E-commerce retail is highest with, marketplaces being the lowest. When you read, and I hope you do read the retail specific study, especially if you're in retail e-commerce, you'll see just how much those little basis point differences impact the performance of your org. Performance of your tools, performance of, you know, your workflows and your processes and and the people that you hire and all of that. Convergence produces better outcomes, but the deals are more important than a yes. So not all forms of convergence improve fraud performance equality. And the data shows that operational integration, specifically shared data and shared use cases, drives measurably better outcomes while structural reorganization alone does not. So just moving the fraud team under the CISO is in an org chart isn't going to improve your precise yes score. It's not gonna improve your approvals or your declines or your chargebacks, anything like that. But sharing the data and the use cases through operational integration is going to have a better outcome.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
53:59
They say there's four dimensions of convergence that they tested against performance. One is team structure, how fraud and cyber teams are organized. The other is shared use cases. How many use cases the two teams share. So are both teams working on ATO? Are both teams working on bots? Are both teams working on loyalty abuse? That type thing. Then the third level of convergence is data integration. How fully the teams share data, the only linear level. Or yeah, lever. And then the fourth is harder to achieve, but that's board governments. How regularly fraud teaches the board. Historically, and I would say just on average, most e-commerce companies' boards don't concern themselves with fraud metrics. I certainly think that they should, but I'm very biased. So that's kind of the holy grail, is when the board gets involved. And they, and they allow fraud to teach them about what's actually going on in their, within their systems. And within their org. And having, you know, canceling good orders and approving bad orders, can lead to poor brand reputation. Having higher account takeovers can lead to worse brand, you know, reputations. So there are reason, established reasons why boards should want to get involved. But they don't yet.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendricks
55:39
So the study says that convergence works, but only when it's operational. Organizations that restructure without operationally integrating may actually be worse off than before. I would concur with that based on conversations I've had with merchant fraud fighters over the years. Structural integration alone, meaning merging org charts, creating program charters, and unifying budgets does not produce better or does not produce better precise yes scores. The dimensions that matter are team structure, use case sharing data integration, and board level governance. The path to a better fraud solution, or the path to better fraud outcomes runs through operations rather than administration. So you're gonna have better outcomes when you actually focus on your fraud metrics than you do just changing the org chart. Team structure matters, but the most integrated organizations do not perform best. So moving from siloed to collaborative teams roughly doubles fraud prevention performance scores. But pushing all the way to full structural integration erodes the domain expertise and clear accountability that make partial integration the highest performing model. So if you just smush fraud and cybersecurity together and say, okay, you guys all work together, you're responsible for keeping our network safe from intruders and malware and, you know, ransomware. That same group is also responsible for reducing payment fraud and chargebacks while also increasing the approval rate. They're saying that doesn't work. That's not effective on its own. What's effective on its own is the partial integration. Where they you know, partially integrate fraud and cybersecurity. So they work together. Maybe they share the same tools, maybe they share the same data, maybe they have meetings on a regular basis and share their metrics and what their concerns are and what the trends are and all of that. But they're not on the same team. And I think that's good. And I I appreciate that they say that if they were, it would erode domain expertise. And clear accountability. Who's responsible if you're the same team? Sharing at least two use cases across fraud and cyber is the performance tipping point. This might be where I leave off and then highly encourage you to read the rest of the study. But this is a big takeaway. So organizations that coordinate on just two shared use cases see a 1.5x improvement in fraud performance scores. Suggesting that a targeted starting point delivers most of the benefit that full convergence promises, without requiring an all or nothing commitment. So you can get really good performance increases by working together on at least two use cases without fully integrating. And I thought that was interesting. Looking at the precise use scores, the use cases. It's like account takeover, bots, you know the typology that I mentioned earlier. If you share two or more of those use cases, if you're working with a cybersecurity team on two or more of those instances, your precise yes score goes through the roof. So that's it. It's hard to explain it without showing you the chart. But the bar graph. But take my word for it for now. Unified data processing also demonstrate a higher precise use score, validating convergence. Decisions of convergence tested, data integration demonstrates that every incremental step produces a measurable gain in fraud performance. Making it a reliable lever for organizations pursuing convergence. So it says if you have an integrated plot, if you just have defined processes, you're gonna have kind of a medium and average precise yes score. But if you actually integrate things and work together and have it be uniform, then your yes score, which is basically your percentage of approved transactions divided by your percentage of chargebacks, is gonna be higher. If they're integrated and uniformed versus just defining the processes, or having them be kind of ad hoc and manual. Like, hey, we'll invite you to a meeting. The tipping point is having, you know, working on two or more use cases together. And having your teams be integrated or uniform.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
60:36
Having the same goals. Here's another, okay, I did want to share this one. I maybe this is gonna be like a two-hour episode. I hope not. But when fraud is a regular board level topic, outcomes improve significantly. Organizations that bring fraud to the board regularly, score nearly twice as high on the precise yes metric as those that keep it at the executive level. Because governance attention creates the cross-functional accountability that operational teams cannot generate on their own. Fraud has graduated from a back office issue to a governance topic. It's now discussed primarily at the executive leadership level in over 40% of organizations. Regularly at the board level in another 30%. And at least occasionally at the board in a further 22%. Only 5.2% of respondents still keep it confined to operational teams. So merchants are realizing as they share this with the board, it you know, impacts their performance. It, the outcomes improve significantly. Combining all four factors produces the best outcomes, of course. So if you're partially or fully integrated, fraud and cyber share two plus use cases, data is integrated or fully unified, and fraud is regularly on the board agenda, you're gonna have far and away the best precise use score. It's going to show you that you're being precise with your decisions. Your decisions are better because you're working upstream, you're gathering signals from upstream, and you're working with cybersecurity and working together to also bring board visibility. Convergent looks different in every industry. Threat profiles and scores vary by vertical. So that's what I'm saying. Like those, the specific threats as well as the precise yes scores really do vary by the vertical. And it was interesting in the e-commerce retail study, not to give everything away, but they identified account takeovers as the biggest priority for them right now. Anecdotally, I would agree with that. Marketplaces perform the worst at this. It goes e-commerce, retail, restaurants, QSRs, travel, entertainment, and then marketplaces. I think one reason for that is that we've had e-commerce and retail for 30 years. Marketplaces have really only been around since like 2010. The maturity of a fraud program as well as the knowledge that the leadership has, the resources that are given, those are gonna vary based on how long an industry has been around. So that's my hypothesis. I'm not gonna read into all of this, but I just highly recommend that you do. The next portion is all about what does not actually matter.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
63:42
And how there's some misconceptions about convergence. But, you know, they talk about barriers that persist across every dimension. You know, it's not like it's not sunshine and roses, you know, it all the time to work with cybersecurity. Because they have different goals and different metrics. But they call those out. Whether an organization has made convergence a priority or not, has no significant impact on performance. Having a formal convergence program doesn't have a statistically meaningful performance impact. Intent isn't what matters, execution is. So whether you've made it a priority or not doesn't matter. It's what you've done with it. And then budget unification is the most cited barrier, but separate budgets actually outperform. So separate budgets are cited by nearly half of respondents as the top barrier to convergence. Yet organizations with fully separate budgets achieve the highest fraud performance scores, revealing that budget structure and operational effectiveness are largely unrelated. So you might think that having a combined budget is gonna make a difference, but it actually doesn't. Having separate budgets actually outperforms. So anyway, I encourage you to finish reading the study. They have a bunch of deep dives on the verticals at a higher level in this main study. I'm going to include a link to this Liminal and Accertify study in the show notes. I think what we can take away from that is that it's really important to work with your cybersecurity team. It's important to work together on specific instances.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
65:18
There's just, there's a lot there. And I think it's good to as I said at the beginning, it's good to be able to benchmark yourself across this data. And also make priorities. And say, hey, we're actually not doing as much. We're only working on one shared instance, right? We're only working on bots together, but we probably should be working on account takeovers and you know, loyalty points and all of those things together as well. That will then improve your fraud, your precise yes score in fraud. It will improve the performance, and improve your metrics. And the purpose of that precise yes score is to provide some, not quantification, but it will help you identify the relationship between approvals and chargebacks. But also, it'll combine them together into one performance score. So we've gotten a new metric out of this study. We've gotten, you know, new guidelines. We've gotten some benchmarking material and data. It, this report is full of pretty graphs. I used to joke that was the only thing my CEO responded to, was a pretty picture. So use them, right? Use them as you're telling the story and pitching it within your organization. If you don't feel like you're fully balanced on work, on that convergence and working with them. I hope that you also found it interesting. I really did. I really appreciate the Accertify team for making this available to me to deep dive.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
67:00
And for doing this study. And actually Mayor from Accertify along with Krista Porter from Reverb, which is an online marketplace for musicians, will be going over this report. But also talking about it in practice, so not in theory, but not just in theory, but in practice and what that looks like, at MFA. So all roads lead to The Merchant Fraud Alliance. I just, I think that this is important to talk about. And the proof in this study shows that it impacts your performance. So it's important to learn more about. All right, you guys, I'm gonna stop talking. At least on this recording. I will probably continue to talk today. But I need to drink like a gallon of water. I just, this air is so dry. Anyway, I will have a great guest for you next week. Thank you so much for being a supporter of Fraudology, for subscribing on YouTube, watching on YouTube, for continuing to listen on Apple and Spotify, and for reaching out occasionally when you appreciate something that a guest said. Or something maybe that I said. I just appreciate you all so much. I thank you for your time and I look forward to speaking with you more next week.