Welcome!

Cloud Security Authors: Elizabeth White, Rishi Bhargava, Matthew McKenna, Dan Potter, Pat Romanski

Related Topics: Cloud Security, Microservices Expo, Agile Computing

Cloud Security: Article

Ending the Tug of War: How Startups Can Help Banks Innovate

Startups can drive amazing innovation by rapidly iterating across ideas and testing with users

Banks face a difficult tug-of-war every day. Consumers demand innovative new services - regulators demand security, compliance and soundness of all offerings. How can a bank resist being pulled in every direction and find a middle ground?

Startups Provide Innovation
Banks can look to startup technology companies for new solutions. Startups are (at least initially) unfettered by regulations, approval committees, and long meetings. This is both a scary and exciting notion for bankers. There are a host of startups in the financial technology space, and bank-grade platforms like FIS's mFoundry originated from small teams working on an idea.

Startups can drive amazing innovation by rapidly iterating across ideas and testing with users. Startup product and service design and usability typically eclipse the made-by-committee-and-regulators look of bank applications.

Banks attend conferences throughout the year looking for innovative new partners. The excitement of possible collaborations is often tempered when you return to the office and discuss the regulatory implications with your business development and compliance teams.

Banks need a way to find compliant startups that do a great job of customer service and satisfy regulatory rules and frameworks.

Startups that Scale for Security
While the early days of a startup are heady times filled with dreaming, those that want to succeed in financial services technology must understand the environment that banks face. You can easily spot the savvier startups within their first 18-24 months - where appropriate they are already leveraging big company processes and practices, to make them look like "real" companies, even if they have only 10 or 20 people.

Signs of a bank-ready startup:

  • External certifications for security (e.g., PCI Level 1 Compliance, ISO 27001)
  • They've read the latest OCC bulletin on third-party provider compliance
  • The founder or management team has a banking or large-scale fintech background

We didn't just describe a unicorn: these startups to exist. The founders know they need a bank partner to launch their product (either as a part of the solution or as a customer). The founders understand what banks need to do from their side and they built their business from the ground up with respect for compliance.

Starting Right Leads to Efficient Compliance
Startups that build solutions that are strongly compliant are often asked: "How can a small company afford that?" While it is difficult and expensive to keep large, older organizations in compliance, smaller companies find it much faster and require much less expense.

The development of Wallaby's digital wallet software began less than two years ago, and included a strong focus on security from day one. Last month, we received our first Attestation of Compliance with PCI Level 1 Security Standards. It required twelve months and less than $50,000 to achieve this because it required so little rework and retraining.

Having participated in PCI compliance audits before, we were familiar with the requirements: We had all the basics like a firewall and anti-virus. We hired engineers for Wallaby with a security mindset. We took the approach that the standards are the minimum. We built our own tools instead of spending thousands on software.

This focus on compliance extends throughout our business. In our short history as a company, numerous partners have audited us. From our financial statements to our office, we keep everything in order at all times.

The Tug of War Ends Here
Innovative customer services and compliance can live together peacefully and productively. It is a key dynamic of working within a regulated industry that is entrusted with the security of people's financial assets. While not every new company is right for banking (and not every bank is looking to partner with startups), we believe there are methods, policies, procedures and audits that can help banks work comfortably with innovative new companies. Together we can provide improved products and services to customers and improve returns for banks.

More Stories By Matthew Goldman

Matthew Goldman is CEO and Co-Founder of Wallaby Financial, Inc. Wallaby Financial is a Pasadena, Calif.-based startup that is working to bring order to your financial life by helping you pay the right way—to earn more rewards and avoid fees, by helping you use the right credit card each time you pay. Previously, Matthew was Director of Retail Strategy at Green Dot Corporation (GDOT), the nation's leading provider of reloadable prepaid debit cards. Follow Matthew on Twitter @magoldman. Learn more about Wallaby at https://www.walla.by/

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
There will be new vendors providing applications, middleware, and connected devices to support the thriving IoT ecosystem. This essentially means that electronic device manufacturers will also be in the software business. Many will be new to building embedded software or robust software. This creates an increased importance on software quality, particularly within the Industrial Internet of Things where business-critical applications are becoming dependent on products controlled by software. Qua...
In addition to all the benefits, IoT is also bringing new kind of customer experience challenges - cars that unlock themselves, thermostats turning houses into saunas and baby video monitors broadcasting over the internet. This list can only increase because while IoT services should be intuitive and simple to use, the delivery ecosystem is a myriad of potential problems as IoT explodes complexity. So finding a performance issue is like finding the proverbial needle in the haystack.
Machine Learning helps make complex systems more efficient. By applying advanced Machine Learning techniques such as Cognitive Fingerprinting, wind project operators can utilize these tools to learn from collected data, detect regular patterns, and optimize their own operations. In his session at 18th Cloud Expo, Stuart Gillen, Director of Business Development at SparkCognition, discussed how research has demonstrated the value of Machine Learning in delivering next generation analytics to imp...
The 19th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Digital Transformation, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportuni...
The Internet of Things will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform. In his session at @ThingsExpo, Craig Sproule, CEO of Metavine, demonstrated how to move beyond today's coding paradigm and shared the must-have mindsets for removing complexity from the develo...
SYS-CON Events announced today that MangoApps will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. MangoApps provides modern company intranets and team collaboration software, allowing workers to stay connected and productive from anywhere in the world and from any device.
Large scale deployments present unique planning challenges, system commissioning hurdles between IT and OT and demand careful system hand-off orchestration. In his session at @ThingsExpo, Jeff Smith, Senior Director and a founding member of Incenergy, will discuss some of the key tactics to ensure delivery success based on his experience of the last two years deploying Industrial IoT systems across four continents.
Basho Technologies has announced the latest release of Basho Riak TS, version 1.3. Riak TS is an enterprise-grade NoSQL database optimized for Internet of Things (IoT). The open source version enables developers to download the software for free and use it in production as well as make contributions to the code and develop applications around Riak TS. Enhancements to Riak TS make it quick, easy and cost-effective to spin up an instance to test new ideas and build IoT applications. In addition to...
Identity is in everything and customers are looking to their providers to ensure the security of their identities, transactions and data. With the increased reliance on cloud-based services, service providers must build security and trust into their offerings, adding value to customers and improving the user experience. Making identity, security and privacy easy for customers provides a unique advantage over the competition.
"We've discovered that after shows 80% if leads that people get, 80% of the conversations end up on the show floor, meaning people forget about it, people forget who they talk to, people forget that there are actual business opportunities to be had here so we try to help out and keep the conversations going," explained Jeff Mesnik, Founder and President of ContentMX, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
"There's a growing demand from users for things to be faster. When you think about all the transactions or interactions users will have with your product and everything that is between those transactions and interactions - what drives us at Catchpoint Systems is the idea to measure that and to analyze it," explained Leo Vasiliou, Director of Web Performance Engineering at Catchpoint Systems, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York Ci...
Internet of @ThingsExpo, taking place November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with the 19th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world and ThingsExpo Silicon Valley Call for Papers is now open.
I wanted to gather all of my Internet of Things (IOT) blogs into a single blog (that I could later use with my University of San Francisco (USF) Big Data “MBA” course). However as I started to pull these blogs together, I realized that my IOT discussion lacked a vision; it lacked an end point towards which an organization could drive their IOT envisioning, proof of value, app dev, data engineering and data science efforts. And I think that the IOT end point is really quite simple…
"My role is working with customers, helping them go through this digital transformation. I spend a lot of time talking to banks, big industries, manufacturers working through how they are integrating and transforming their IT platforms and moving them forward," explained William Morrish, General Manager Product Sales at Interoute, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
You think you know what’s in your data. But do you? Most organizations are now aware of the business intelligence represented by their data. Data science stands to take this to a level you never thought of – literally. The techniques of data science, when used with the capabilities of Big Data technologies, can make connections you had not yet imagined, helping you discover new insights and ask new questions of your data. In his session at @ThingsExpo, Sarbjit Sarkaria, data science team lead ...
Extracting business value from Internet of Things (IoT) data doesn’t happen overnight. There are several requirements that must be satisfied, including IoT device enablement, data analysis, real-time detection of complex events and automated orchestration of actions. Unfortunately, too many companies fall short in achieving their business goals by implementing incomplete solutions or not focusing on tangible use cases. In his general session at @ThingsExpo, Dave McCarthy, Director of Products...
WebRTC is bringing significant change to the communications landscape that will bridge the worlds of web and telephony, making the Internet the new standard for communications. Cloud9 took the road less traveled and used WebRTC to create a downloadable enterprise-grade communications platform that is changing the communication dynamic in the financial sector. In his session at @ThingsExpo, Leo Papadopoulos, CTO of Cloud9, discussed the importance of WebRTC and how it enables companies to focus...
Verizon Communications Inc. (NYSE, Nasdaq: VZ) and Yahoo! Inc. (Nasdaq: YHOO) have entered into a definitive agreement under which Verizon will acquire Yahoo's operating business for approximately $4.83 billion in cash, subject to customary closing adjustments. Yahoo informs, connects and entertains a global audience of more than 1 billion monthly active users** -- including 600 million monthly active mobile users*** through its search, communications and digital content products. Yahoo also co...
A critical component of any IoT project is what to do with all the data being generated. This data needs to be captured, processed, structured, and stored in a way to facilitate different kinds of queries. Traditional data warehouse and analytical systems are mature technologies that can be used to handle certain kinds of queries, but they are not always well suited to many problems, particularly when there is a need for real-time insights.
Amazon has gradually rolled out parts of its IoT offerings in the last year, but these are just the tip of the iceberg. In addition to optimizing their back-end AWS offerings, Amazon is laying the ground work to be a major force in IoT – especially in the connected home and office. Amazon is extending its reach by building on its dominant Cloud IoT platform, its Dash Button strategy, recently announced Replenishment Services, the Echo/Alexa voice recognition control platform, the 6-7 strategic...