63
| 03/27/22 | 1 © worldpay limited www.worldpay.com Company Confidential Secure Payment Systems Jose Saavedra Senior Partner Development Manager

| 02/06/2015 | 1 © worldpay limited Company Confidential Secure Payment Systems Jose Saavedra Senior Partner Development Manager

  • View
    215

  • Download
    0

Embed Size (px)

Citation preview

| 04/18/23 | 1

© worldpay limitedwww.worldpay.com Company Confidential

Secure Payment Systems

Jose Saavedra

Senior Partner Development Manager

| 04/18/23 | 2

© worldpay limitedwww.worldpay.com Company Confidential

Objectives

To raise awareness of the online payment industry

To look at barriers to online trading

To obtain a better understanding of WorldPay

To explore the issue of ‘Fraud’

| 04/18/23 | 3

© worldpay limitedwww.worldpay.com Company Confidential

The Card Industry Explained

| 04/18/23 | 4

© worldpay limitedwww.worldpay.com Company Confidential

The Card Industry Explained

• The Key Players

• Cardholder – consumer / shopper

• Card Schemes – Visa, MasterCard, American Express…

• Card Issuers – Barclaycard, MBNA

• Merchant – retailer, e-tailer or service provider

• Acquirer provider of Merchant Account and terminal / card authorisation & settlement to the retailer

| 04/18/23 | 5

© worldpay limitedwww.worldpay.com Company Confidential

The Card Industry Explained

• In the online world:

• Acquirers provide Internet Merchant Accounts

• PSP – Payment Service Provider, they interface between the merchant to the bank acquirers / card schemes

• WorldPay is unique as it offers both the Bank Acquired and PSP function ……and lots more

| 04/18/23 | 6

© worldpay limitedwww.worldpay.com Company Confidential

InternetCARDHOLDER

PSP -PaymentGateway

MERCHANT

VisaNet

ACQUIRERISSUER

Internet

ISSUER

MCNet

Cardholder(shopper)

Retailer(merchant)

Settlement

| 04/18/23 | 7

© worldpay limitedwww.worldpay.com Company Confidential

Who Charges What?

• The Card Scheme will charge the Acquirers for using their network / system.

• The Card Issuers will charge the Card Acquirers each time one of their cards is used.

• The above fees are know as INTERCHANGE and Internet Based Transaction typically carry a higher premium than POS and Mail Order Telephone Order

• The Acquirer charges the Merchant a processing fee – typically a % for credit card and fixed fee for debit cards

• The PSP will charge an additional processing fee

| 04/18/23 | 8

© worldpay limitedwww.worldpay.com Company Confidential

Who Is Liable?

• Whilst an transaction is authorised it does not guarantee payment

• Today the merchant is ultimately liable if there is a fraudulent transaction

• However this is changing - more on fraud later!

| 04/18/23 | 9

© worldpay limitedwww.worldpay.com Company Confidential

Any questions?

| 04/18/23 | 10

© worldpay limitedwww.worldpay.com Company Confidential

WorldPay Overview

| 04/18/23 | 11

© worldpay limitedwww.worldpay.com Company Confidential

Both the Acquirer and PSP……and much more

Global payment aggregator

Originally established in 1993

Wholly owned Subsidiary of RBoS

Global Presence - Offices in Cambridge, Virginia (USA), Singapore, South Africa & Germany

Over 18,000 customers in over 100 countries

1300 partners in over 50 countries

~250 employees

Leading EMEA online payment provider

Who are we?

| 04/18/23 | 12

© worldpay limitedwww.worldpay.com Company Confidential

Jon Prideaux, Executive Vice President, Visa said:

“The benefits 3-D Secure offers our cardholders and e-businesses will drive adoption and increase e-commerce revenues. Visa is delighted to be working together with WorldPay, the largest multi-currency payment aggregator in the world, to secure e-commerce globally for our cardholders”  

Quote from recent Visa Press Release

| 04/18/23 | 13

© worldpay limitedwww.worldpay.com Company Confidential

WorldPay Customers & Partners

| 04/18/23 | 14

© worldpay limitedwww.worldpay.com Company Confidential

How The WorldPay System Works

WorldPay(Payment Gateway)

Bank / Card Schemes

WWWShopper

StorefrontConfirm

ation

E-mail Receipt

| 04/18/23 | 15

© worldpay limitedwww.worldpay.com Company Confidential

What payment types can we process: Visa, including Visa Purchasing Card

Visa Delta

MasterCard / Europay

American Express

Diners

Switch / Solo

Electron

Laser

ELV

Discover – Q4 2002

JCB - Q4 2002

Maestro – 400m debit cards – Q4 2002

| 04/18/23 | 16

© worldpay limitedwww.worldpay.com Company Confidential

Any questions?

| 04/18/23 | 17

© worldpay limitedwww.worldpay.com Company Confidential

The Perceived Barriers to trading online

| 04/18/23 | 18

© worldpay limitedwww.worldpay.com Company Confidential

Businesses have websites, what is holding them back from trading online?

| 04/18/23 | 19

© worldpay limitedwww.worldpay.com Company Confidential

Dot com gloom

| 04/18/23 | 20

© worldpay limitedwww.worldpay.com Company Confidential

A few people got lucky, I wasn’t one of them or I wouldn’t be here today

Dot com gloom

Businesses are taking a more commercial view

Confidence !!

| 04/18/23 | 21

© worldpay limitedwww.worldpay.com Company Confidential

Security

| 04/18/23 | 22

© worldpay limitedwww.worldpay.com Company Confidential

There is still a perception that shoppers will have their card details captured from the Internet

The liability exposure

Complications of setting up secure servers

However….

Security

| 04/18/23 | 23

© worldpay limitedwww.worldpay.com Company Confidential

Credit card details are captured on our server

Trusting a brand

WorldPay is owned by the 2nd Largest bank in Europe, with servers designed for running financial transactions

WorldPay uses a range of encryption techniques to keep transaction data secure

Security

| 04/18/23 | 24

© worldpay limitedwww.worldpay.com Company Confidential

Internet Trading Accounts

| 04/18/23 | 25

© worldpay limitedwww.worldpay.com Company Confidential

Internet Trading Accounts To trade online, you will need an Internet Trading Account.

Large established companies can go directly to their bank

Banks typically require 2 years trading history, audited accounts etc..

It can be a long, daunting process

Not good news for SME’s

However…

| 04/18/23 | 26

© worldpay limitedwww.worldpay.com Company Confidential

WorldDirect WorldPay has developed an alternative model - WorldDirect

WorldPay can take on businesses with no trading history or audited accounts

Customers get an instant decision via an online application form - customer can have an account in as little as 48 hours

Once the customers are ready to go live, they complete an online form

Bank tests and QA take a day then the site goes live

WorldPay accepts over 90% of applications

| 04/18/23 | 27

© worldpay limitedwww.worldpay.com Company Confidential

Complication

Is the invention more complex than the problem merits?

| 04/18/23 | 28

© worldpay limitedwww.worldpay.com Company Confidential

Setting up an online store used to require a high level of technical ability and tools were not readily available to help

eCommerce sites were written from scratch and the customer would find it difficult to make changes to the site

As an SME with a small budget, £30,000 to test eCommerce was simply not viable

However…

Complication

| 04/18/23 | 29

© worldpay limitedwww.worldpay.com Company Confidential

This changed as storebuilding software came into the market

WorldPay has plug-ins for most of the leading storefronts

WorldPay also has a range of integration tools

Complication

| 04/18/23 | 30

© worldpay limitedwww.worldpay.com Company Confidential

Knowledge Base

| 04/18/23 | 31

© worldpay limitedwww.worldpay.com Company Confidential

Customer Management System

| 04/18/23 | 32

© worldpay limitedwww.worldpay.com Company Confidential

Online Statement

| 04/18/23 | 33

© worldpay limitedwww.worldpay.com Company Confidential

Online Statement – Refunds

Refunds

| 04/18/23 | 34

© worldpay limitedwww.worldpay.com Company Confidential

Offline orders

| 04/18/23 | 35

© worldpay limitedwww.worldpay.com Company Confidential

What do I do with offline orders? WorldPay developed a Virtual Terminal (WorldAccess) to save

the merchant from having to run a swipe machine in parallel.

Allows your customers to take offline orders and process through a single account through WorldPay

Ideal for fax / telephone orders

All that is needed is a browser and a username and password

Gives the customer a complete credit / debit card processing facility

| 04/18/23 | 36

© worldpay limitedwww.worldpay.com Company Confidential

| 04/18/23 | 37

© worldpay limitedwww.worldpay.com Company Confidential

| 04/18/23 | 38

© worldpay limitedwww.worldpay.com Company Confidential

Ongoing payments / Subscriptions

| 04/18/23 | 39

© worldpay limitedwww.worldpay.com Company Confidential

How can I process ongoing transactions?

FuturePay For customers that require regular subscription services. Facilitates online Standing Orders and Direct Debits Useful for billing customers for ‘bundled’ services

| 04/18/23 | 40

© worldpay limitedwww.worldpay.com Company Confidential

| 04/18/23 | 41

© worldpay limitedwww.worldpay.com Company Confidential

Pricing

Opportunity cost of not offering eCommerce

The costs of setting up online have reduced dramatically over the last 5 years

People think taking online payments is expensive

More expensive to pay somebody to take sales over the phone!!

| 04/18/23 | 42

© worldpay limitedwww.worldpay.com Company Confidential

Pricing WorldDirect Customers

£75 setup fee + £150 annual fee

4.5% service transaction charge. (Includes bank charges)

50p UK debit card charge

Bank Acquired Customers

Max of 1.6% service transaction charge (+ Bank charges)

25p UK debit card charge (+ Bank charges)

Other flexible pricing models available dependent on turnover

WorldAccess - £75 setup fee

FuturePay- £100 setup fee

| 04/18/23 | 43

© worldpay limitedwww.worldpay.com Company Confidential

Promotion

| 04/18/23 | 44

© worldpay limitedwww.worldpay.com Company Confidential

Promotion

The build it and they will come syndrome

Reality is very different….

How can merchants promote themselves?

| 04/18/23 | 45

© worldpay limitedwww.worldpay.com Company Confidential

| 04/18/23 | 46

© worldpay limitedwww.worldpay.com Company Confidential

WorldPay Shopping Mall

| 04/18/23 | 47

© worldpay limitedwww.worldpay.com Company Confidential

Questions?

| 04/18/23 | 48

© worldpay limitedwww.worldpay.com Company Confidential

Fraud

| 04/18/23 | 49

© worldpay limitedwww.worldpay.com Company Confidential

The impact of fraud

• Financial loss – ‘Chargebacks’• The Shopper disputes a transaction on their statement

with their Card issuer• Issuer asks the Merchant to prove they fulfilled the

transaction • If the merchant can’t do this, the amount is returned –

“Charged back”- to the Shopper’s account• Chargebacks occur for several months after a

transaction (up to 6 months)

The fraudster’s got the goods, the shopper has their

money back…

The merchant is left out of pocket!

What can be done?

| 04/18/23 | 50

© worldpay limitedwww.worldpay.com Company Confidential

Card Issuers Checks

•Funds – check that there are funds in the account to cover the transaction•Expiry Date – check that the Card hasn’t expired•Hot Card – check that the Card isn’t reported lost or stolen

| 04/18/23 | 51

© worldpay limitedwww.worldpay.com Company Confidential

Card Issuers Checks – Security Code

• Checks the Security Code number entered by the shopper, with the number held by the Issuer

• The 3 or 4 digit number is usually printed either on the white signature strip, or on the front face of the card or both

• Not embossed on the card• Not encoded in the magnetic strip• Helps ensure physical possession of the card• Support is mandated in the UK

| 04/18/23 | 52

© worldpay limitedwww.worldpay.com Company Confidential

Card Issuers Checks – Address Verification

• Compares the billing address with Issuers records• Support mandated in the UK• Simple but powerful

| 04/18/23 | 53

© worldpay limitedwww.worldpay.com Company Confidential

Card Issuers Checks

• Authorisation result, AVS and Security Code results returned in real time

• “An authorisation is not a guarantee of a good transaction and/or subsequent payment to the Merchant”

| 04/18/23 | 54

© worldpay limitedwww.worldpay.com Company Confidential

WorldPay Automated Checks

• LUHN Check – check the format of the Card number is valid

• Billing / Issue Country mismatch – Checks the country of the billing address entered by the shopper, with the Card issue country

• WorldPay’s Hot Card list – check that the Card is not reported lost or stolen

• Security code and AVS – data supplied to the Issuer

| 04/18/23 | 55

© worldpay limitedwww.worldpay.com Company Confidential

WorldPay WorldAlert

• Developed by WorldPay• Automatically scans all transactions• Checks for one off indicators and patterns of shopper

activity• Issues automatic real-time Alerts to Merchants

• Caution indicates increased risk • Warning indicates high likelihood of fraud

• Includes the Merchant “Configurator” interface to control blocking of

• Email addresses & Domains• IP Addresses and ranges• Shopper names

| 04/18/23 | 56

© worldpay limitedwww.worldpay.com Company Confidential

WorldPay WorldAlert

| 04/18/23 | 57

© worldpay limitedwww.worldpay.com Company Confidential

WorldPayTransaction Engine

Acquirer

WorldAlert

Auth RespAuth Req

Issuer

LUHN Check?Trans Data

Auth Req

Funds?AVS/Sec Code

Auth Resp

Merchant Site

Hot Card?

WorldAlert Warning?

WorldAlertWarning?

Auth Resp

Blocks?

Expired ?

Country?

Security Flow

| 04/18/23 | 58

© worldpay limitedwww.worldpay.com Company Confidential

Verified by Visa (3D Secure)

• Cardholder identity authentication process• Shopper asked to enter a pin on payment page• Merchant will then not be liable for fraudulent

transactions• Liability Shift• Available Q1 2003• Mastercard and Amex to follow

| 04/18/23 | 59

© worldpay limitedwww.worldpay.com Company Confidential

WorldPay Deferred Processing

• Set-up for Merchants on request• Defers processing the transaction for up to 5 days following

the Authorisation• Transactions accepted manually using the Customer

Management System or allowed to lapse• Allows time for additional checks• Prevents unnecessary refunds

| 04/18/23 | 60

© worldpay limitedwww.worldpay.com Company Confidential

Issuer’s Anti-fraud Systems

• Issuers, Banks, Building Societies etc. operate their own systems

• They will often check with their customers if they see unusual activity

| 04/18/23 | 61

© worldpay limitedwww.worldpay.com Company Confidential

WorldPay Anti-fraud Team

• Monitors regular output from WorldAlert• Employs search features of WorldAlert to investigate in more

detail• Fine-tunes WorldAlert Parameters and thresholds • Provides information to law enforcement agencies

| 04/18/23 | 62

© worldpay limitedwww.worldpay.com Company Confidential

WorldPay Guarantee

WorldAlert

3D Secure

SPA

Pre Auth

AVS

Security Code

Real Time

Auth, Issuers

Systems

The Onion

The Layered Approach

| 04/18/23 | 63

© worldpay limitedwww.worldpay.com Company Confidential

Questions? [email protected]

0870 742 7000