Transcript
And joining me today for our executive exchange is James Simcox, the Chief Operating Officer and Chief Product Officer at Equals Money. Welcome. Thank you for having me. Well, I'm so excited to have you back to Chit Chat. We've been learning a lot from you. Today, we're going to dive into a topic that's top of mind for leaders across every industry, and that is how to embed security into the core of business operations in the age of AI. James, to kick us off, could you tell us what embedding security looks like at Equals Money? So Equals, we've taken the approach that whilst we have a security team, and they're really important to us and they keep us safe while we're at work, security is actually everyone's responsibility at Equals. So even as far as like, it's not very often that people have a CEO or CPO talking about security, but I do it all the time because it's important for me, as much as the CTO, as much as our CEO, that we have the security kind of across the whole business. And we kind of make sure that our staff feel really, really empowered to have security themselves. So we have this whole security champions program in the business where any member of any team can join. We give them special training and then they can kind of compete to win badges and stuff internally to kind of show how much they're doing security. Because for us, as a financial services firm, we cannot just kind of go, yeah, all security will handle that, right? Because it's fine. Because if you break into a normal business, you might walk out with a bunch of data perhaps, or you might leave with, I don't know, some kind of trade secret, which is a big problem, but you then have to exploit that, sell it or monetize it later. Whereas for us, if someone breaks into our systems, they can walk out with billions of dollars, right? Our customer's money, which is gone, and that's not going to work for us, right? As a financial services business, we have to build on trust and our customers have to believe that we're taking security seriously. And so we push that the whole way down to the org. And if I look at where like most security kind of things get raised in the business, they're not raised by a security team. They're raised by random people across the organization who goes, hey guys, what about this? What's going on? You know? And that's a really healthy culture for us to have as a business. I love that because, you know, sometimes we get asked, like, who has the ownership of security? And what I'm hearing you say is that it's part of your culture and it's really everyone's job and responsibility to show up and think about security, to focus on the business. Absolutely. And it has to be, right? Because if you say, oh, who owns security? Oh, it's Dave in the corner. Okay, well, great. But what if he's on vacation? Because it doesn't work, right? And so it has to be that even your executive team feels like they own security. We have this like monthly security council, which sounds very dramatic and big, but it's where we as a business discuss security as a whole, but our CEO attends, right? And he actually says one of his favorite meetings because he gets to see what the business is doing. And we get to talk about the security challenge you face as a business, as a group, which I think is really important for executives to do as well. So I think what's really great is that you have this unique perspective of being both an operations and a product leader, and you're very customer centric. So how are you defining the ROI of security, not just in terms of mitigating loss, but also enabling new business opportunities? The loss is the easy one, right? If we could protect our customers' accounts and we can see a reduction in account takeovers, let's say, where we often refund the customer anyway because it's the right thing to do, even if it was a mistake that they made, it's still on us, right? We'll refund them. That's easy for us. We can monitor that, track it, it's paid out cash, straightforward. Thankfully so far, we've never had a data loss in the business, so I haven't had to deal with that, but we're very mindful of that as a cost that could happen to us. But on the other side, putting too much friction in front of your customers can be a real problem, right? And so we're very, very conscious about how do we get our customers to use our products as easy as they can without security getting in the way? I think that's where Auth0 particularly has helped us out a lot, where historically we've just gone, well, do some 2FA if it feels suspicious, do some more 2FA if it feels really suspicious, give us a call, that kind of stuff. Whereas now we can go, it felt 70%, but we're going to let you in anyway, let you to the account, and then if something happens later on, like a big payment, or you do something very strange with cards or whatever, we might then suspend your account, or we might then suspend the payment and intervene at that point, right? Pushing the security challenge to the customer to the point of the action, not at the point of the login, because you can't always get it right up front, and if you're too secure with customers sometimes, they can just be like, this is not a product that I want to use, it's getting in my way, right? And it's really important, particularly for our business customers that often use their web browser, so they don't have the benefit of using Biomex on their phone, that kind of stuff, so they want to get in and do their jobs, right? They want to make the payments and all that stuff, so it's important for us to get them in as quickly as we can, and then secure them further down the chain using those adaptive risk controls where we can pull in all that login information along with other stuff we've collected throughout their entire journey with us. I would love to learn more about how you are prioritizing security into your product roadmap, but also how you're getting your developers on board, and just getting the whole company to think about security. That must be really challenging. Yeah, it is challenging, and it's also, if you don't put enough friction in, people feel a bit suspicious as well, right? It's like, is this company actually secure enough, right? What is that really sweet spot? We also have a wide range of customers, so for our direct business where we sell to customers directly, it's almost entirely business customers. Business customers actually all kind of work in the same way. You're A, you're either an SSO company or you're not, and then you're probably after that point either a big company or a small company. Your staff then generally work in a similar way in our platform. But for our indirect customers, where we're supporting another business with their customers, the whole point of the business is they've got a really specialized set of people they work with, right? Are their customers all pensioners, or are their customers all musicians on the road, or like, they all have a very different set of behavior, and so we're having to handle different things. When you deal with older customers, a lot of them are really SMS and phone call heavy. They don't understand pass keys, they don't understand biometrics, even some of the device. Versus if you're a musician on the road, perhaps you're on your own mobile app the whole time, so I can use that kind of biometrics piece. And so balancing those different security journeys is quite hard. But as for putting it into the roadmap, well, as I mentioned before, security for us is just part of what we do, right? So one of our core engineering teams is just onboarding an identity, and their entire job is to ensure that our customers are onboarded correctly, because obviously financial services is what we have to do, but that's the first part of our security journey. And then moving into identity, that we continually improve our identity products to make sure we're always identifying our customers correctly. And for us, it's more about identifying the customer, and that's kind of the thing about internally then is just security, because really, that's the point. It's identifying, are you the right person using the account at the right time? And there's a lot of ways we can do that. Totally. Is it a challenge to get your developers really onboard with this secure by design approach? Or to your point, is it just so much part of the DNA, the culture that they're easily onboard with it? I think when we first started out a few years ago, it was definitely like a change for a lot of people, because lots of developers like to work quickly, and they think that security can be a way that slows them down. But when you kind of embed it into the culture, security becomes such a part of what people are doing, that actually they realize it can speed them up, right? Because nothing worse than building a feature, getting to the point of release, and people go, well, you can't release that, because it's completely insecure. And so if we've built it that way to start with, people realize actually that gets you to ship things faster, because you're not going to get a weird blocker later on where you haven't thought about it. And we also have a really good track internally of people moving from our engineering functions into those security roles as well. So we kind of keep that knowledge in the organization, such that our security team isn't just a bunch of people we've hired from outside. They're a mixture of people we've hired from outside and internal experts we've then trained up and moved into that function to make sure we keep that org knowledge in there as well. Yeah, that's exciting. It seems like it's a fun, like your security meetings and your culture just really helps your engineers and your company continue to build and innovate. I love it. So embedding security in business operations requires a cultural shift. And spoiler alert, it sounds like that's something you guys are heavily invested in that you're thinking of. Are there challenges? Do you ever run into like a non-security, non-technical employee that's not embracing it? Or is it really truly in the DNA of Equals Money? I don't think we have any of those non-security employees in the business, but there's definitely different levels, right? If you're working with the engineering function, they're working with it every single day. When things go wrong, they're the first people that are seen, right? They're aware of it a lot more. But if you think about someone in our customer service operation, who security is part of their lifecycle because they're identifying customers through their journeys, but they're not thinking so much about that whole much wider business, like, oh, is this thing actually something happening somewhere else? And so we kind of continually run that kind of company-wise training to make sure our customers, our staff, are aware of everything that's going on across the whole business and that they understand the right channels to raise things up to. And just kind of make people aware of what the potential new threats are, right? Because it's very easy to just sit in a customer service center the whole day. You don't understand how like threats are changing their ways of behaving. And we make sure we share whenever we come across something with that wider business that this is something we've seen, and you should be aware of it. Because if you spot it next time, tell us right away, right? Totally. I can imagine like a developer's already thinking of security, and they're a little suspicious, but maybe on your customer support line, they're there to help. And they're there to offer solutions, not realizing it could be a sophisticated threat actor. They just want to help customers out. And I mean, a few years ago, you could be pretty certain if you spoke to someone on the phone, and they sounded like the right age, and they gave the right information quickly enough that it made sense. You know, if you ask your date of birth, it comes out like that, right? Right. A key thing is it comes out so early. Now with AI, I can just create all that myself. I can responsibly answer questions. If you change tack on security questions, you can just create an answer straight away. And that's something which has made that whole serving customer experience piece a lot harder. And they are now on the front line of that piece. And so we make sure that they're kind of aware of what's going on. I think to your point, training and enablement is such a key part. Now in the quest for productivity, you just talked about AI tools. There are some out there that can be a little dangerous, but there's also some that can be really helpful for employees. So how are you thinking around shadow AI? Is it a big concern for you? Again, is it something that you guys are talking in your security councils to enable the team? How are you thinking about that across equals? So shadow AI is terrifying for me, right? Yeah. It's something that we do worry about a huge amount. And it's mostly because people like to get on and do their jobs, and they don't necessarily think that using that tool is a problem, right? And so we actually pushed out ChatGPT to all our staff early on because we were worried about if we didn't do something, they would do it themselves, right? But I can't do that for every single AI tool. Like, am I design team using an online AI designer? Potentially they are, right? Just try something out. But trying something out quickly becomes, oh, this is really helpful. I'll just use it. And they also forget to think about following that right process to make it happen. And so as a business, we're nervous about it. And we track a lot of touch points across our identities of all our staff and what's going on in our platforms. But yeah, shadow AI is a challenge. But shadow IT has always been a challenge. Staff always bring in new tools. They bring in new software. And so this isn't any different. I guess the challenge here is that before you might buy some software and it might be some malware, fine. It's confined just to you. If you accidentally bring in an AI agent-type product that's hooked up to a bunch of services and no one notices, that's a real problem. Yeah. So shadow AI, some of the tools we talked about from Okta, IPSM, ISBN, really helps out with keeping track of those things across the org. Love it. Yeah. Thank you so much. It was really helpful today hearing about just creating culture, thinking of your customers, thinking of your employees. Just some great tips. Thank you so much for joining us today. Thank you for having me. Of course.