Thursday, June 2, 2011

How Your Bank Can Benefit from Using Twitter

While Jack Dorsey and the whole Twitter team continue to celebrate their successful 5th anniversary, I would like to take a minute or two to contribute a few ways that Twitter will help you stay in touch with your customers and current financial services industry and payments industry news.

Before you dismiss Twitter and cross it off as just another social media fad, you’ll agree with me that the following statistics are impressive:

  • 3 years, 2 months and 1 day: This is the time it took from the first Tweet to the billionth Tweet.
  • 1 week: This is the current amount of time it takes users to add another billion Tweets.
  • 460,000: The average number of new accounts opened per day in February 2011.

I’ll admit I was once a person who thought of Twitter as primarily a way to share thoughts on a new restaurant, interesting articles you came across, or to comment on your favorite sports team’s game. However, now Twitter is about more than just entertainment. When properly leveraged, it can be a very useful business tool for quickly sharing information, gathering information about your competitors and building relationships with current customers, as well as potential new ones.

If you are a new Twitter user, you may not be sure where or how to get started. One way to get started with Twitter is to use it as a tool to stay current on payments industry news. Below I have listed a handful of informative publications and organizations I follow that use Twitter to assist in promoting their latest news and analysis:

You should also follow your payment processing company and other service providers (if they are on Twitter). Login to Twitter and start a search for them by name or by their official Twitter handle (starts with @) then click the “Follow” button. Next, visit your Twitter home page where you’ll see the most recent stream of tweets from the companies and people you follow. Then when you come across an interesting headline, simply click on the link to read the full article.

Twitter also easily provides access to the latest payments industry news when you’re on the move with their mobile apps for iPhone, Android, BlackBerry and Windows 7 phones. That way you can quickly check Tweets when you have a few seconds and keep up with the latest news and more.

Are you still skeptical about Twitter? I suggest taking 15-30 minutes to give it a try. I’m sure you’ll be surprised at what you find.

Target Success with Your Merchant Account Service Provider

As you approach the end of each quarter, you are always looking a little closer into the profitability of your financial institutions merchant services program. What is the conclusion you are coming to? Are your program objectives being met? Have you met your expectations?

As you look over your results, it might be helpful to evaluate your current merchant account service provider and the value they provide in helping you meet these goals. Consider whether or not the services, products and support they deliver are helping you keep up with this rapidly changing industry.

If you find profitability is not where you want or expect it to be, it’s good time to ask the following questions that play a key role in your profitability:

1. Are your new merchant accounts growing as planned?

This question really asks if you are targeting your commercial account base effectively. To do so it’s crucial to have the correct mix of products and services for your merchants. How do your ancillary products and services match up to those of your competitors? Finally, do you have pricing that is competitive enough to attract larger merchants as well as the typical “mom and pop” establishments?

2. How much time is being spent on acquiring new customers compared to supporting your existing customers?

Today’s employees are given a diverse set of responsibilities and are expected to wear many hats. That’s why it’s important that your team is able to spend time on revenue-generating activities. We all know service is important, but the growth of your institution is extremely important as well. Does your payment processor offer “self service” tools for merchants to help deal with the easy questions? A few examples of this are online access to statements, data, etc. Another area to look at is the usability of your systems and the training time required for new team members.

3. How much money does your program make?

It’s essential to be able to evaluate your program’s profitability and truly understand your success. Is your payment processing company providing you with reports that are easy to understand and help you dig into the bottom line numbers? You should be able to quickly tell which of your merchants are most profitable and least profitable. Also, the fees are a key element of profit. Are you able to tell how much your provider is really charging you?

4. Are you getting the service you need?

Your financial institution is highly focused on providing top-notch customer service. Your payment processing company should be able to deliver the same. Are they working with you on ways to grow your portfolio and increase your fee income? Do they address service issues expediently, as well as those of your customers? And when it comes to your main point of contact, do you still have a primary relationship manager?

While evaluating your financial institution’s merchant services program, answer these questions truthfully. Also keep in mind what the definition of a partnership is, “a cooperative relationship between people or groups who agree to share responsibility for achieving some specific goal.”

After all, it’s those shared goals and a strong commitment from each party that will put you on your way to increased profitability and retention. Does your current merchant account service provider share your goals?

For more payment processing updates subscribe to our payment processing blog for financial institutions.

Find a niche as a merchant services provider

If your approach is still broad when it comes to finding new merchants, you may find that you are losing business to competitors who have tactically focused on a particular niche in the industry. It’s my recommendation that you reevaluate your strategy and brainstorm ways to differentiate your service from your competitors.

I spoke to many ISOs in early March 2011 at the Southeast Acquirers' Association (SEAA) 2011 Annual Conference in Weston, FL. I was enamored by the fact that a large percentage of the ISOs in attendance no longer thought of themselves as a general merchant services provider. They have moved their focus to a niche segment of the market and offer a unique and more tailored solution to successfully target specific merchants.

So what is a niche exactly? Well, Merriam-Webster defines a niche as “a place, employment, status, or activity for which a person or thing is best fitted” as well as “a specialized market.” I like to consider it as focusing on something you do very well – better than your competition – instead of trying to provide everything for everyone.

If you are wondering what some example niches for an ISO might be, let me start with a few examples that were brought to my attention at the SEAA 2011 Annual Conference. One gentleman is in the process of starting a new ISO focused on point-of-sale solutions. He is planning to help merchants find the right software/hardware to meet their needs, and the merchant account is what comes along with it. Another ISO had the idea to create a loyalty program to use as a lead for new merchant acquisition and to help with customer retention. A third ISO focuses on businesses that create POS and other related software used by merchants to help integrate his merchant services into their software.

While each approach is different, they all have something in common: they make sure to focus on a niche rather than a shotgun approach in addressing the merchant services market. Given the highly competitive nature of our business, their approach makes sense.

  • How will you find your own niche as a merchant services provider? Here are additional examples to consider:
  • Specific merchants (e.g., medical offices, contractors, auto dealers, e-commerce)
  • Products (e.g., gift cards, mobile payment devices, plug-in for QuickBooks)
  • Geographic (e.g., new communities, small towns with less competition)
  • Cultural (e.g., Spanish-speaking merchants, your local ethnic hotspots like a “China town”)

To help identify your niche try asking yourself the following questions:

  • Which merchants are providing the most referrals?
  • What am I receiving the most compliments on?
  • What do I feel is my strength?
  • Which merchants and products excite me the most?

Really take some time to think of potential niches that fit you well. Chances are you will find it will make you more efficient in finding leads, closing them, and retaining your merchants. If you like the content of this post, please be sure to visit and subscribe to our payment processing blog for ISOs.

Thursday, May 5, 2011

Merchant Awareness of PCI: Success or Failure?

It's been nearly a decade now, so are small merchants aware of PCI? Yes, it's already been 10 years. Visa brought the Cardholder Information Security Program (CISP) to fruition in 2001, and in 2004 it evolved into the Payment Card Industry (PCI) Data Security Standard (DSS).

After several years of comprehensive efforts in the payment processing industry to inform and educate merchants, and the fact that payment card industry compliance is required, results and opinions are mixed. A recent study by the National Retail Federation provides information to make a case for both success and failure of the program and here they are:

Success

• 66% of small merchants are aware of the PCI DSS.

• The majority of merchants who are aware of PCI take it seriously. 74% of them have had a PCI compliance assessment.

• 94% of merchants care about keeping card information secure.

• 50% of merchants are aware of some consequences of a breach, such as getting sued by cardholders and losing the ability to accept Visa and MasterCard

Failure

• 34% still have a lack of awareness of PCI despite the immense industry efforts.

• 51% of all merchants still have not had a PCI compliance assessment.

• 64% are unaware of the dangers and don't believe their business is vulnerable to card data theft.

• 60% of merchants don't have a strong understanding of the costs, including fines by Visa/MasterCard, liability for use of stolen cards, and per-card fees for every canceled card.

So, has this all been a success or a failure? While my answer might be an open invitation to accusations of being a politician or fence-sitter, my answer is "Yes." As an industry, we've made great progress, and had a significant impact on the industry in a positive way, but we have a long way to go to get payment card industry compliance where it needs to be.

Let's not stop at that, let's offer a few explanations for why awareness and compliance are potentially lower than one might expect.

1. Quantities of new businesses

Many small business owners have a lengthy list of responsibilities and to-dos; it's not a huge surprise that these businesses are not familiar with PCI out of the gates. Exaggerating this impact is the fact that many new businesses open every year. According to Census data, 700,000 new businesses are "born" each year. This is reflected in the NRF study where 27% of merchants were less than three years old.

2. "Bad things only happen to other people" mentality

It can be human nature to assume the best and that "it won't happen to me." When dealing with the risk of a security breach involving cardholder data, many merchants appear to take that approach, rather than planning with Murphy's Law in mind.

3. Focus on fees rather than compliance

There is no reason to hide the fact that most processors and acquirers have fees for PCI programs. The fees have created controversy because they can seem high and are often not tied to compliance. As a result, perhaps PCI fees have become the main focus for many ISOs and merchants instead of PCI compliance itself.

ISOs are you fed up with high fees associated with your current payment partner's Payment Card Industry (PCI) compliance assessment program? Are they causing attrition in your portfolio? Do their fees make it difficult for you to sign new merchants? Clearent has a unique approach to PCI compliance:

No PCI Fees - That's right, there are no PCI fees for merchants who complete our questionnaire
Keep it Simple - Merchants save time thanks to our simplified PCI questionnaires
Know Your Status - Monitor your portfolio's status at-a-glance with our online reports

Contact Clearent for more information on payment processing solutions for ISOs and FIs.

PCI DSS Compliance and Adressing the Blame Game

We all know the "Blame Game." We were introduced to it as a child. It typically involves breaking, spilling, or loosing something that your mother didn't want you tinkering with in the first place. The game changes as we get older - our arguments get stronger but we still pass the blame.

Here are some classic responses we've either said - or heard - at one time or another:
• "(Name) did it."
• "It wouldn't have happened if (Name) did (Desired Action)."
• "It's not my fault."

As a result, today our society could be defined as a litigious one. People are quick to sue and claim that they shouldn't be held accountable and that it's someone else's fault that something bad happened.

Merchants are no different because of the pressures they face, especially with the varying changes in regulation and the economy over the past few years. There are all sorts of opportunities for errors and finger pointing.

One area that is very important is maintaining data security, PCI DSS compliance. Vulnerabilities can be created from careless actions, and vulnerabilities can result in a breach, as well as hefty fines, penalties and more.

When this happens, it's likely that the merchant is going to look outside of his business for someone to blame. And when he thinks he's found that someone, a lawsuit could be the next thing to follow.

To protect themselves and their merchant customers, most payment processors will insist on the completion of a PCI compliance assessment. The processor then reviews the assessment to identify merchants whose actions may put them at risk for a compromise. This helps keep the blame at bay but its not the best.

It's common for ISOs to want to provide the best possible service to their merchants and they may want to complete the self-assessment questionnaires (SAQs) on behalf of their merchant.

What happens if, for some reason, a merchant is then breached? If it is determined that the merchant was not PCI compliant and the questionnaire was not completed accurately, who will the merchant blame? It was the ISO who helped them complete their PCI compliance assessment, of course.

PCI DSS compliance and data security are very important, but processors shouldn't put ISOs in the middle of their approach. That isn't their job, and frankly, they shouldn't be expected to be a PCI compliance expert. Also, remember that why one of the best way to avoid this Blame Game is a self-assessment questionnaire, designed to be taken by merchants because they know the details of their operation best.

So what's the solution?

At Clearent, we use an online questionnaire, designed to be completed by the merchant to assist with PCI DSS compliance. We believe it shouldn't be part of the application process, but rather part of the support your payment processor provides to your merchants. And it shouldn't come with a cost to complete.

It's a simple approach, but one that any ISO today with the desire to grow should appreciate. That way if a breach should ever happen, you can easily say, "It wasn't me. I wasn't even involved." - and truly mean it. Otherwise, it may be prudent to have an attorney on retainer.