The Delayed FinTech Revolution

Technology has transformed how we work, communicate and travel. In contrast, modern digital technology has not yet transformed financial services. Open data is the key to change in this sector of the economy.

The time has come for the financial services industry to join the open data revolution. Open data means interoperability of digital information to increase its usability and accessibility. The Obama administration has done much to make open data a cornerstone of its digital government strategy.

 When open data is brought to the private sector, moreover, one of the benefits will be information portability for consumers. “Informational portability” means that consumers will be able to share and use their personal data in different individual services and products.

Consumers and businesses have, of course, long shared their key financial information with trusted third parties, such as accountants, lawyers and financial advisors. Today, advances in technology have made it easier for customers of banks and insurance companies, among other financial institutions, to share their information with others. Rather than storing key documents in shoe boxes and file folders, consumers and small businesses can pass along digital online and mobile banking credentials.

The promise of fintech is to bring consumer finance into the 21st Century. Fintech companies have already created products that enable consumers to budget, pay their bills, limit spending and identify fraudulent transactions on credit and debit card statements. These enterprises also offer sophisticated tools for facilitating individual investment, financial planning and portfolio management.

This happy story of progress, however, is far from complete because of concerns around privacy and security, and the intermittent choke-points on data sharing. Financial institutions, such as banks and insurance companies, warn against the risks that would follow from allowing their customers to authorize access by third parties to their digital account information.

The time has come for the financial services industry to join the open data revolution.

Financial entities have also periodically taken steps to prevent their users from delegating such access to third parties. These steps are based on understandable concerns about privacy and security.

In the Dodd-Frank Act, Congress took a major step toward ensuring open data. In its Section 1033, this law authorizes the Consumer Financial Protection Bureau (CFPB) to make rules requiring financial institutions to give consumers information upon request about their use of financial products and services.

Congress also authorized the CFPB to develop standardized formats for information. In light of the current absence of cross-industry cooperation, the CFPB should act to enable consumers to get the digital financial services they desire and deserve.

Three policy principles for CFPB rulemaking stand out.

First, the law should enable mechanisms that safeguard and promote consumer consent. Consumers should be in charge of the conditions under which third parties can access their financial information, be provided with clear information about the terms under which such functionality is permitted and be able to turn access on or off.

Second, the concerns regarding privacy and security have merit and banks deserve praise for their concern about them. At the same time, these issues are eminently solvable. Encryption enables firms to share information without making it visible to third parties. Identity management tools allow firms to build systems that provide access to some but not all information, much in the way that a valet key to a car allows someone to drive it but not open the glove box.

The first move should be to seek broad industry agreement on best practices in these areas. Only if there is gridlock regarding self-regulation, the CFPB should develop regulations to establish strong privacy and security requirements.

Finally, the CFPB should act to protect consumers from liability from data sharing, so long as they behave with reasonable care. This model already exists for electronic fund transfers due to measures such as the Federal Reserve’s Regulation E and Regulation Z. These regulations limit a consumer’s liability for unauthorized electronic transactions when using credit cards and debit cards. Similar regulations are needed in the fintech context to clarify questions regarding a consumer’s liability for harms following from delegated account access.

The digital revolution will come to financial services only if consumers are guaranteed consistent, secure and up-to-date access to their financial information. The time has come for the US government to take the first steps to guarantee financial data mobility.

TechCrunch: http://tcrn.ch/1SQ3AER

« Cyber Insurer Offers Some Ransomware Insights
Cyber Threat Intelligence: Sharing Is Caring »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

QATestLab

QATestLab

QATestLab is a leading International software testing company offering a full range of software testing services including security testing.

EclecticIQ

EclecticIQ

EclecticIQ is a global provider of threat intelligence, hunting and response technology and services.

Living Security

Living Security

Living Security specializes in metric driven and engaging security awareness solutions that reduce risk by increasing security culture and changing employee behaviour.

WiJungle

WiJungle

WiJungle is an Indian Cyber Security Company that develops and markets a unified network security gateway solution.

Vigilant Software

Vigilant Software

Vigilant Software develops industry-leading tools for intelligent, simplified compliance, including ISO27001-risk management and EU GDPR.

Infosec Global

Infosec Global

Infosec Global provides technology innovation, thought leadership and expertise in cryptographic life-cycle management.

CRI Group

CRI Group

CRI Group excels at deterring, detecting and investigating crimes against businesses using a global network of professionals specially trained in Anti-Corruption, Risk Management and Compliance.

Stratia Cyber

Stratia Cyber

Stratia Cyber is an independent, technology agnostic company providing high quality, pragmatic cyber security consultancy and expertise.

Extreme Networks

Extreme Networks

Since 1996, Extreme has been pushing the boundaries of networking technology, driven by a vision of making it simpler and faster as well as more agile and secure.

LogicMonitor

LogicMonitor

LogicMonitor provides SaaS-based IT infrastructure monitoring services for on-premises and multi-cloud environments.

OSC Edge

OSC Edge

OSC was founded with the vision of providing expert solutions in IT to government and businesses. OSC Edge empowers organizations with solutions that prepare them for today and tomorrow.

Unciphered

Unciphered

Unciphered was created as the first company providing services for opening locked hardware cryptocurrency wallets.

Cygna Labs

Cygna Labs

Cygna Labs is a software developer and one of the top three global DDI (DNS, DHCP, and IP address management) vendors.

Highen Fintech

Highen Fintech

Highen is a blockchain software development company with offices in the United States and development centers in India.

SECTA5

SECTA5

SECTA5 is a cybersecurity company building a next-generation Continuous Threat and Exposure Management platform, leveraging the expertise of offensively trained cyber defenders.

SecAI

SecAI

SecAI is an innovative threat intelligence-driven, and AI-powered vendor aiming at cyber threat detection and response.