Episode 656 ·
Navigating eCommerce Security with Hrishi Talwar, Chief Product Officer at Vesta
Today we’re talking to Hrishi Talwar, Chief Product Officer at Vesta. We discuss Hrishi’s philosophy of being joined at the hip with his COO, the current state of financial fraud in eCommerce, and the trajectory that fraud will have in the age of AI.
All of this right here, right now, on the Modern CTO Podcast!
For more about Vesta, check out their website: https://www.vesta.io/
In case you missed it, check out our episode with FingerPrint
Have feedback about the show? Let us know here
Produced by ProSeries Media.

About Hrishi Talwar:
Results driven Management Executive with extensive global experience including product management, innovation, organizational leadership, business development and marketing.
Exceptional relationship builder and negotiator, successfully formulating and executing strategic programs.
Thought leader in technology, financial services, consumer identity management, organizational development and product led growth.
About Vesta:
Vesta is an end-to-end transaction guarantee platform for online purchases.
We use machine learning backed by 25 years of transactional data to increase approvals of legitimate sales for our customers, while eliminating chargebacks and other forms of digital fraud.
We drive the true cost of fraud to zero and transfer 100% of the liability for fraud, including chargeback processing, so customers can focus on increasing sales.
Transcript
Today, we're talking to Rishi from Vesta about where financial fraud is going in the age of AI. You're listening to Joel Beasley, Modern CTO.
So I saw that you were a co-founder, and I always like talking with other founders. Was this your first company that you founded?
It was, yes. I was running innovation labs at First Data and ended up spending a lot of time with startups. We took an approach where we didn't want to go build everything on our own. You know, large company, everything takes too long. You've got to get alignment across different sections of the organization. And so being in the innovation lab, what I suggested we do is stick with what we do best and then go work with startups that are hungry to coordinate, partner with big logos. It gives them more credibility and see if they can build something for us. So that's how it started.
It got to a point where it was very exciting to go see someone have an idea over dinner, and by the time you came into the office next morning, it was done. And so I said, hey, wouldn't it be great if I could align myself and actually build something from scratch? So started participating in the startup community in Atlanta, which was still pretty hidden back then. Now, obviously, you hear more about it and bumped into guys that had a similar thirst and hunger to go do something. And we took an idea, and we built something out of it, got through seed funding, decided to raise money for a Series A, and I think that's when we hit a little bit of a wall trying to do fintech in a payments-oriented market in Atlanta. And I think that was when—I think after trying for about 18 months, we said it's time to go back to corporate.
So you kind of lost me there at the end. It's time to go back to corporate. So you did a startup, and then you went back to corporate?
Yes. So I was at First Data. That enticed me to go to a startup. I did the startup, couldn't get through the Series A raise, and then decided to pack it up and go back to corporate.
Okay. And so what are you doing now?
So right now, I'm at Vesta. I joined them about a little over a year ago, and I'm the chief product officer. I've got a global accountability for product and marketing. We're a 400-person company. I would call ourselves mid-sized fintech, although we've been around since '95. But over the last three or four years, we have really gone through a pretty significant reinvention of ourselves and gone from a one-trick pony that's focused on a vertical within a few markets to a true global player across multiple verticals.
Yeah. And then the way we got introduced was through Valentin at Fingerprint. Do you actually know Valentin, or is he just a figurehead there?
So I know some folks that run partnerships at Fingerprint. Incidentally, one of them used to run my consulting team at Equifax when I was running identity fraud and compliance. So small world, and we do business with them as well, with Fingerprint. So that's how we got connected. And he's like, hey, would you like to do some thought leadership? Here's the Modern CTO. I was like, never done it before with them. So, yeah, why not?
Nice. Yeah. We like the Atlanta area. I was down there about a month or two ago for Atlanta Technology Professionals golf event, ATP, and I learned a lot about Atlanta. I learned a lot from the business aspects of growing up. My grandparents lived there, so I got to spend a lot of time there in the summers, but I learned all about the business community. You said Equifax. I know Bryson, and we got to his direct report, her name was D something. Josh, you remember?
D'Lovely. D'Lovely Gibson.
Yeah. Yeah. Yeah. So I got to meet her at the golf event, and I was like, hey, do you know Bryson? She's like, he's my boss. And I said, oh, that's so cool. But all those people that I run into in that community seem to be super high quality. Do you think it's just because there's a lot of money and a lot of big companies in Atlanta that it attracts such great talent?
I think there's a little bit of that, but it's a great place to live in. You get four seasons in a year. Cost of living is not too expensive. You've got some pretty big Fortune 50 and 100 companies. But I think the community is so well-knit. You end up meeting so many people together all the time that you end up staying in touch. And if you ever wanted to go do something else, because you've got the connections, you'll always find an opportunity to go somewhere else within the same city. So that's the good news about it. Yeah. You know, I landed in Atlanta in '97 to go to grad school and haven't left yet and have done six or seven jobs, and they've all been local.
That's amazing. Yeah. I was in Florida for 30-plus years, and then we decided we wanted seasons. So we went up to Tennessee. So I'm only about four hours from you.
Yeah. Cool.
Yeah. So you guys use Fingerprint. Do you know how you particularly use them or why you chose them?
Yeah. So we use Fingerprint as part of our solution because it allows us to understand the device that a consumer is using as they go through a typical payment or purchase transaction. And what our company does is uses a lot of those signals and a bunch of stuff on the back end, part of our IP, to understand the risk of that transaction being fraudulent. Why we use them? Again, I think in a mid-sized company, we're always looking to partner with up-and-coming organizations, people that are doing something in a much more innovative way than the rest of the world. And so we got introduced to them. We really liked how they built their overall offering with a technology-first approach rather than just building a bunch of features and hoping it maps to the technology. And we found out that they were doing it very well. So just like everyone else tries out a new partner, we clubbed together our technologies. We went and tested it out in a market, and we got some very, very good positive response. And that allowed us to expand our relationship further.
Nice. Yeah. When I heard about them, my team pitched them to me, and I looked at their website, and I thought, wow, this is actually pretty cool.
Yeah.
So that—yeah. It's because there's a lot of technologies out there. You know? Right. And particularly, I was a software engineer for 17 years, and then when the podcast took off, that's when I stopped actively. I still manage one application with a developer or two, but I'm not coding every day. And so when I see products now coming out, I'm like, oh, that's so cool. I could think of 80 different ways to use that.
Yeah. Yeah. Totally.
I noticed in my notes that you had this phrase that you used that you're joined at the hip with your COO, and that stood out to me because we don't talk about that relationship a lot. We always talk about, you know, the CTO or the CPO and the C-suite in general. But I want to dive into specifically what your relationship looks like with your COO.
Yeah. So to me, one of the cornerstones of a product doing really well is when you take it out into the market and it actually does what the promise is behind the product. Right? And it's all about making sure it does it at scale, and it allows customers to actually use that product effectively and quickly. If you've got long integration cycles and it requires them to put a 200-person team, most people are going to eventually put that on the back burner and move on. So to me, the COO joined-at-the-hip relationship is very important because his and my partnership allows our teams to build, to deploy, to make the products available to our customers as quickly and seamlessly as possible so they can get the benefit out of the product as quickly as well. Because at the end of the day, they're paying for something.
Yeah. And I noticed that I know what the company does. I read through it. Josh does. But we didn't actually explicitly tell everybody. Can you just tell me what the problem is you solve, what it is that you guys do?
Absolutely. So Vesta is in the business of assessing risk associated with any financial transaction. And the risk is primarily around fraud, especially as you think about how people are transacting more and more online. And they are moving money from their account to a merchant account, to a retailer's account, or maybe to a friend's account because they're paying for a particular service. So what we can do is sit within the transaction stream seamlessly, frictionlessly, and within a few milliseconds, tell either the sending party or receiving party what is the fraud risk associated with that transaction. Typically, the fraud risk sort of emerges itself as chargeback fraud when you're talking about your traditional card-based payments. But there's all sorts of scams and money laundering fraud that happens when you move outside of cards to ACH, virtual accounts, and wallets. And so we can sit within those payment streams and within a few milliseconds say, this transaction is fraudulent. We highly recommend you do not initiate the transfer of funds. And it's up to then the party that gets this message to decide if they go through the process or not.
Oh, that's cool.
And we do it in two different ways. In one way, we can actually indemnify the merchant of all risk associated with the transaction if we said it's safe and the transaction results in fraud. So there's zero liability associated with the merchant in that scenario, or we can provide the merchant or the customer all the tools so they can make their own decision if that's what they like to do.
Where is 80% of your customers?
80% of our customers in terms of verticals or—
Like, which way are they using? Yeah. Are they building it themselves or are they using your system?
I think it varies from market to market. In the emerging markets where card-based payments are still the majority of payments, they end up wanting us to manage those transactions. But as you start thinking about the emerging markets where they don't want to deal with cards and networks and interchange fees, they actually incentivize consumers to use non-card-based payments. And so you're seeing a higher degree of usage there, and they like to be a little bit more in control of what happens to that transaction.
Okay. And what's going on with fraud right now? I mean, is it—I haven't been in the fraud space for a while. The closest I got was I built a financial retirement planning software several years ago. But what's going on in fraud?
So fraud is ever-evolving and getting more and more sophisticated as the technology around it continues to get more and more sophisticated. I was reading a stat, I would say, about six months ago where they were saying that the fraudsters are now starting to act like VCs. They're starting to act like Fortune 50 companies where they're reinvesting their gains to improve their technology. So our whole vision of a fraudster being a guy sitting with a hoodie in a basement with a computer trying to hack into stuff is long gone. And now you're thinking about a rack of servers and fraudsters being experts in AI and machine learning, and they're using technology to actually outsmart a lot of the tools that are out there. So you can go look at all the analyst reports, but they're actually expecting payment fraud worldwide to exceed about $340 billion over the next five years. That's almost like the GDP of some countries on the map.
Yeah. It's where they expect podcast revenue to be in ten years. I just saw that report today, and I was like, whoa. So that would be bigger than the entire podcast industry.
Yeah. Yeah. Wow. And so they're getting into every channel. They're finding ways to circumvent tools and technologies that are sitting there to prevent fraud. They have access to more data than we can imagine, and they know actually how to use it. So the goal for us now is less about creating a Fort Knox. It's more about doing whatever it takes to stay two, three steps ahead of them and then constantly seeing the decisions we are making, the outcomes we are driving, and continue to learn and adapt so we never let them catch up.
Why is it so hard to catch these individuals?
It's hard to catch these individuals because it's not like you can trace everything back to a person because of technology advancements, because of privacy laws. So you are dealing with a faceless person on the other side that's got access to all your data, that acts like you, behaves like you, does everything that you do, and then being able to pinpoint in a dark room who is that person behaving like you is very hard.
But from this standpoint of they're acting like big companies, they're growing—I did an interview about maybe three years ago with one of the individuals that negotiates with these, and he was telling me they have customer service lines you can call. And I thought he was joking. He's like, no. You can call the customer service line and negotiate with them and get your stuff unbricked and whatnot. But if they're grouping together like this, presumably, they have an office building, they're going to work. Let's say they're decentralized. Aren't there enough—when you hit a certain mass, it's kind of hard to hide what you're doing. If I opened a chocolate factory in my town, right, people know me and they'd know the other people that work there, and then the word would get out. So how are they keeping it quiet?
It's all about them using all of these decentralized technologies that are aimed at keeping consumer privacy first so you can't trace it back to an individual or a physical location. They're using all these technologies to go commit fraud, and everyone talks about this electronic trail that you can travel back to, and it'll take you to a physical location or a person. But those trails don't exist because the technologies that they're using are built around not keeping that trail active once the act is completed.
Yeah.
So it's become more—I would say, it's less about being reactive or being able to go chase that down. Easier when you're dealing with a physical good, less when you're dealing with a digital good because that just—once it leaves your laptop, it's gone. It's more about being proactive and creating barriers around what you have so they can't get in instead of trying to trap them or trace them back and catch them at the act.
Do you think that there are these groups and some of the participants don't know that they're doing something illegal? Like, they think they're working on other types of projects, but it's really that.
I don't believe so. I think they have gotten smart enough where they may make a consumer go through an act where the consumer doesn't think that they're doing something illegal. But on the back end, the people that are running the software or running this hack know exactly what they're doing.
Yeah. Because I was thinking, I could just start a security company. Right? We're a penetration testing company. And then, you know, my engineers, they don't work with the clients directly. It comes from sales, signs a contract, comes down to them. You're to do this specific set of actions.
Right.
Do you think any of that's going on or no?
Maybe. Maybe there is. I haven't ever explored that side or known anyone that's come out or been associated with it. But possibly, you could have some employees that think they are trying to see if they can break into something from a cybersecurity perspective for prevention, but it's actually doing harm than doing prevention.
I got real interested in this when I was, I don't know, 11 or 12. My dad had taken me to Best Buy or not Best Buy, Books-A-Million or one of the bookstores that used to exist. Yeah. There was a book called, like, Hack This Computer or something to that effect. I bought it.
(Joel Beasley at 00:18:18) I got really interested, starting learning a whole lot about security and the script kiddies and whatnot. And after playing with that for several months, I realized really, really fast that if I'm smart enough to do this, I'm smart enough to figure out how to make money legitimately. Right? And so that was the fork in the road between me choosing a life of criminal mischief and me choosing a life of being a software engineer and just getting paid to write code.
(Rishi at 00:18:46) Right.
(Joel Beasley at 00:18:47) So that was my limited experience with security.
(Rishi at 00:18:52) Yeah, you're true. I mean, we all think about it, right? When we are writing code to catch fraudsters, we have to think like them. But you're doing it for a good cause. You're not doing it to harm someone or a consumer or a business.
(Joel Beasley at 00:19:06) Yeah. Yep. What's the coolest fraud story that you've—obviously, you hear stories. You're in it. You've got peers in it. What's one cool story that you've heard?
(Rishi at 00:19:16) Yeah. I mean, we hear stories about criminals or fraudsters coming in and looking at how a merchant or a business is preventing fraud, what are some of the typical things they catch, and the merchant thinks that they're being super transparent to the consumer. So they're giving away as much information as possible about what things got flagged and what things didn't. And then you have the fraudster waiting for a holiday event or a sale or a specific category of goods that comes in on a promotional level, and they just go nuts. And within six, eight hours, completely take away all of the inventory and make merry with it.
(Joel Beasley at 00:20:11) Wow. Yep. So something happened to me a year or two ago on Facebook advertisements. Shout out to Meta. But what happened was this. We run ads to promote the show, right, to find new people and promote different content and so on. Well, one day I go into my ad account, and I got some alerts, and I was like, oh, this is interesting. And I apparently spent $10,000 in one day. That was one of my limits, right? And I said, well, that's strange because we spend a couple hundred dollars a day. We don't spend $10,000 a day. And I went and looked. There were these ads running for a variety of different products, a variety of different websites. They were really odd types of products too. I mean, like, I don't know, lipstick on one, Frisbees on another. They were very disjointed, right? It wasn't a clear pattern. And then I could see them advertising, and then I could actually see the results. And it was a horrible result in the sense that if you were actually spending your own money, right? But they were spending $10,000 and generating five or $6,000, right? So they were operating at a serious loss, but they had hacked Facebook, and so it wasn't their money. And then I'm assuming that they were doing this at scale because what happened was in the audit trail, it said that the person who made these changes to my settings was a Facebook employee. And so it took, I don't know, it took two months for me to get the money back and all that and get it all sorted out. It was a lot of work, but I told them, I said, hey, look. You guys can see in your own audit trail, it says your employee did this. And so it's obviously not—I don't sell Frisbees. I'm nothing connected to lipstick. It's not even close, right?
(Rishi at 00:22:12) Right.
(Joel Beasley at 00:22:12) Yeah. That was my recent experience with fraud.
(Rishi at 00:22:18) Yeah. Yeah. I mean, most of the times, the types of fraud that we end up seeing are either someone's stolen a credit card, and they've got a pretty small window in which they can go in and buy things and get them delivered either as a digital good to an email address that's easy to take over these days, or a physical good that's getting delivered to an address that's a PO box that doesn't line up with the actual billing address of the consumer. Or we end up seeing a lot of first party fraud that I call buyer's remorse, right? You bought something you do not want your spouse to know you're buying, or you went and bought Bitcoin because you wanted to ride the hockey stick curve, but you caught it on the way down. And now you're trying to figure out how much of that you can salvage because it's no longer worth what you paid for it.
(Joel Beasley at 00:23:19) That's interesting. Go a little deeper on that. Let's say I buy a pressure washer, right? My wife is not happy about that. What would that—give me an example of first party fraud with that.
(Rishi at 00:23:33) Well, you would call your card company and say that wasn't me.
(Joel Beasley at 00:23:40) Oh, so just straight up lie.
(Rishi at 00:23:42) Yes. It was someone else that bought this. And if they can go trace it back to—it was delivered to your address, you'd say, well, I never got it. So someone must have ordered it, and they were watching for that particular physical good to get delivered at my house. And before I came to the front door to pick it up, they took it away. Or it was a digital good that you bought, and you got access to it. And now you're claiming your mailbox was hacked, and you didn't even realize that you bought that particular good because when you logged into your email account, there was nothing there. Someone had already taken access to that, you know, code or gift card or whatever, and it doesn't exist in your mailbox anymore. So you would claim that that wasn't me. I never bought it. And they would say, hey, but we delivered it to your mailbox because here's the electronic proof it was delivered. And then you'd say, but my mailbox account was hacked. I never got access to that particular good.
(Joel Beasley at 00:24:59) And they'll go with that?
(Rishi at 00:25:01) They won't. You have to trace it back, and that's where our technology comes in and helps, and we're able to go tie it down to very specific stuff. If it's a physical good, sometimes we can go connect with the delivery company and confirm that that good was delivered to your house, and here's a picture. And, you know, there's certain things that a consumer can do versus cannot do when something is delivered to your doorstep, but you still claim you didn't get it. If it's a digital good, we can go trace it down to it being delivered to your email address, and we can tie that when the order came in. Everything about the device and the behavior and the fingerprint of the device told us it was you ordering that particular item. So you cannot claim that it wasn't you. It was someone else acting on your behalf.
(Joel Beasley at 00:25:58) How are—with the rise, I'm assuming I saw a bunch of graphs before the show, and I'm assuming it's increasing. Fraud is increasing with the AI tools and making it just even easier to help you learn to write malicious code and whatnot. How are the banks responding? I mean, do they have some sort of—I'll make an assumption. You tell me how wrong I am. Because I have, I don't know, maybe a chargeback a year if you average it out over the past five years. It's not often that I have it. But I'm assuming they have some sort of system in there that tracks the number of transactions I do, the amount of money that flows through my accounts, and then the dollar amount of things that I've been refunded or claimed, because they always seem to do it really fast and really easy for me. And I just assume that it's because I do it so infrequently that I'm flying under some sort of limit of how seriously they take it. Is that one of the—I don't want you to disclose exactly or whatnot, but is that a strategy? Am I generally in the right area?
(Rishi at 00:27:01) Yes. Yes. It's all about your patterns, your behaviors, the frequency, the day and time of month, the category of goods that you're buying typically. And then when something comes out that's a complete outlier, typically, you lean towards that being higher risk than something that you typically buy, and it's just part of your behavior and the pattern that you have. And that's where some technologies will come in, and they'll either be able to quickly predict the behavior and pattern, or if it's an anomaly or an outlier, it's being able to catch signals behind that to help influence whatever decision you want to make.
(Joel Beasley at 00:27:51) When you look at services like Amazon or maybe PayPal that obscure the exact product they're buying, right? My bank statement just says Amazon, Amazon, Amazon. There's not specific products tied to that on there. Are there data companies and data sharing things that happen behind the scenes that allow—you know, if I'm a bank, I could partner with Amazon and get more detail into what makes up that transaction, or do you guys just have to go off of a retailer?
(Rishi at 00:28:18) Typically, you don't share that information because, you know, for an Amazon, what you're buying and the actual details and the quantity is part of their IP. So they may be building tools that help them understand you as a consumer better, which influences a lot of the choices you make. Amazon knows exactly what you're browsing because every time you go in, they have Amazon Recommends.
(Joel Beasley at 00:28:50) They're great at it, by the way.
(Rishi at 00:28:51) Right? Because they're seeing what you're browsing, what you click on, what you buy, and they're able to inform through their technology what are the most likely next set of things that you're going to buy. If they were to share that information with a bank, they would disintermediate themselves, which they would never do.
(Joel Beasley at 00:29:09) Right. So the fraud companies only have to go off the merchant inform—okay.
(Rishi at 00:29:15) Right. If you're sitting on the merchant side of the equation. Now, you've got the bank that's issuing you the credit card that's linked to your bank account, and they're seeing patterns of you buying things from Amazon but 20 other places. So they may have access to your spend patterns. They may have access to your earning patterns. And so they're looking at the problem from a slightly different lens. Obviously, when fraud occurs, your first call as a consumer always goes to your bank. And only in those cases, when that trace goes back to the retailer, in this case, our example is Amazon, that's when information sharing may occur between all the parties, but that's related to just that transaction and the details around it.
(Joel Beasley at 00:30:08) And then are you a layer above the specific type of currency? Can someone use your product for crypto fraud, for different types of fraud, or is this just fiat currencies?
(Rishi at 00:30:20) So it's mostly fiat currencies today, but we said it doesn't matter what vehicle you're using to move the currency back and forth. We are able to analyze the vehicle and everything else that a consumer is doing to be able to make the assessment. So going back to the example, we will typically sit with the merchant well before the payment information is actually sent to the bank for authorization. And that authorization event getting approved is a trigger for the merchant to start sending you the stuff, whether it's a digital good or a physical good.
(Joel Beasley at 00:31:02) So sometimes your customer's the merchant, sometimes it's the bank, sometimes it's both?
(Rishi at 00:31:07) Sometimes it's both. Correct.
(Joel Beasley at 00:31:09) Very cool. That's super interesting. What questions am I not asking about fraud?
(Rishi at 00:31:15) The big thing is, you know, the unanswered question is where is it going to go next? And I'm not sure. I think everyone will give you the answer that fraud's going to continue to increase as we're doing more and more things online. Fraud's going to continue to increase as we start using different currencies, different payment types. But I think it's the evolution of the tools that are being made available to merchants and to consumers that's going to help us curb, you know, fraud or keep it under control. I don't think we'll be able to completely ever eliminate it from the face of this earth. It's more about keeping it under control so it doesn't start hampering economies and what consumers do on a day to day basis. Going back to your example, right? You get one chargeback maybe a year. But if you were getting one chargeback a day, eventually, you will reach a point where you will say, I don't want to transact online anymore. I'm going to go back to the old ways of walking into a physical location, looking at what I'm buying, taking possession of it, paying for it in cash, and then I'm going to go back home. And at least then I know for sure that I got what I wanted.
(Joel Beasley at 00:32:38) Are people doing that?
(Rishi at 00:32:40) I would say probably the older generation, like my parents or my grandparents probably don't feel comfortable buying anything online. But the younger generation is more about convenience. It's more about the one click. It's about looking at my bank and expecting the bank to keep me safe from fraud or looking at my merchant and expecting the merchant to have the right controls so that my information is safe from fraud. And the moment something bad happens, we change and move away, and we may never go back to the bank or to the merchant ever again because we've lost confidence that they know what they're doing.
(Joel Beasley at 00:33:24) I think you're right when you say we'll never get rid of it. To me, it feels a lot like the classic story of good versus evil. It'll always exist. One will always start to push the yin and the yang, and this odd balance. But I do think that—or what I have seen historically, usually when a group of people are in an industry, they sort of agree what's going to happen, and there's some debate, and there's two very distinct sides. I usually find that it's a third thing that pops up that nobody was looking at that ends up being where you end up. It's always a surprise, but that's the fun of it too, right? Just moving the industries forward and seeing where it goes next and making better tools than the bad guys have, and then they surprise you. And then you figure some stuff out and surprise them, and you're out there fighting. It's kind of fun. Sounds fun.
(Rishi at 00:34:16) I hate to put it this way, but it's a mutually beneficial relationship if you think about it at the 20,000 foot level, right? They're keeping us employed because we are making sure we're two steps ahead of them. And in some way, we're keeping them employed because they're trying to catch up, because they're looking at other loopholes, other cracks in the door to get through and be able to monetize that piece.
(Joel Beasley at 00:34:41) Are these people—do you think if I met them out and about, are they a gang? Is it a gang type of person? Is it a white collar type of person? Is it a kid? What's this profile of this Fortune 500 hacker type that—
(Rishi at 00:34:59) It's certainly not what we are made to believe. It's not a guy wearing a hoodie, sitting in the dark, in the basement, trying to hack through stuff. These are regular people that go make a living this way to feed their families. They get up every morning, and that's their goal, to go do their job, to make money for their organization that's not evolved in good behavior, but they're getting paid to go support themselves and their families just like we are on the other side.
(Joel Beasley at 00:35:36) They're sitting there looking over P&Ls. They're, you know, writing paychecks, and they're operating. That is so important.
(Rishi at 00:35:47) It's totally a business that's paying for everything they do, which is why, you know, just after COVID, when we all heard about how much money was stolen through all these government benefit programs, all of that was reinvested going back to them actually getting more investments back from all of that money than the total VC investment globally that year.
(Joel Beasley at 00:36:13) Say that again. There was more money stolen from the programs than all of global VC investment.
(Rishi at 00:36:19) Money reinvested from all of these programs that was stolen from into organizations to improve their fraud, AI, and machine learning and technology, than the total money invested by VCs into companies to build out new things.
(Joel Beasley at 00:36:41) How do you think they do? You think it's a job? They have a job posting online. You join. They figure out if you're trustworthy, if you want a better life. And then you're part of the inside group, so the company's half legit, half not legit. You think it's like that? I want to make a movie about it.
(Rishi at 00:36:56) I'm not sure, but you could make a pretty good movie about it.
(Joel Beasley at 00:37:00) Right.
(Rishi at 00:37:01) And if someone contacts you and said, "How do you figure out?," then you've probably gotten in touch with one of them.
(Joel Beasley at 00:37:06) There you go. Yeah. Who's the person right now that would be listening that would be interested in your services? Would it be a CISO? Who would that be? Who buys your services most often?
(Rishi at 00:37:18) I think it's typically, I would say, a committee-based purchase because if you think about the problem that we solve, in that committee, on that table, there will be a bunch of influencers that have different benefits from this. I'll give you an example. The operations person or the security person, their core focus is, "How do I minimize fraud?" It's an expense on that balance sheet. It's costing me operational dollars to manage a group of people that are sitting down and looking at this data and trying to figure out what decisions I make. So I've got to make sure the fraud is kept to a minimum. It's a business owner or a channel owner that's looking at the profitability of the channel. And so their core focus would be, "How do I make sure that because of me trying to prevent fraud, I'm not creating friction where consumers come in, they find it too hard, and they abandon the process?" Because that's impacting my top line revenue. So you could also have a technologist that's sitting on the table that's saying, "Okay, great, you have a fraud solution. Is it going to require me to rejigger my entire infrastructure? Am I going to have to spend $5 million to integrate your solution into all my different channels, or is it very seamless to integrate?" So you're always looking at these multiple personas, and the solution has to appeal to all of them because they are looking for a very specific benefit, which is very different than the others.
(Joel Beasley at 00:39:01) That's super interesting. Last question for you before we wrap up. If we're having someone on that's fraud-smart and knows about all of this stuff, I guess I'd say for practical, actionable, useful knowledge, what's one thing that everyone should be doing to reduce their chance of fraud? Something easy, something simple, something I could tell my parents to do. Just one basic thing that would reduce their risk by 50% or something like that.
(Rishi at 00:39:35) Yeah. I would say when you go and transact online, typically there are some very subtle things that you will notice that might be leading indicators of a fraudulent website or a fraudulent email. Just be diligent about it. Make sure you're looking at it and make sure that you're not clicking on something that sounds too good to be true, because typically it's not the case. And just be careful about where and how you divulge information out there in social networks because these are all things people use to come in and start acting like you or on your behalf to go commit fraud. I always joke about people going on social media and talking about their pet and posting pictures of their pet with the names, and then you go to their merchant account or ecommerce account, and their secret question is, "What's your pet's name?" Right? So if you're giving all this information out there for someone to easily get access to and commit fraud, then you're not being very smart, and fraudsters are looking for these weak links to come in and do something as quickly as possible.
(Joel Beasley at 00:40:58) Yes. Well, I never underestimate stupidity.
(Rishi at 00:41:03) Common sense is not common.
(Joel Beasley at 00:41:06) No. I was at a comedy show, and they got the person. They're like, "What's your password, or what's your Social Security number?" And they just shouted it out because they asked them a series of questions, and it just—you know, it's just how humans work. If you're not really vigilant about it, you can get used pretty easily. So, yeah, this was great. Thank you. I really appreciate you coming, hanging out.
(Rishi at 00:41:24) Sure. Thanks for having me.
(Joel Beasley at 00:41:30) You did a podcast. You feel good?
(Rishi at 00:41:32) Absolutely.
(Joel Beasley at 00:41:33) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.