Three important steps small businesses should take today to combat cybercrime

The way Australians choose to pay and get paid continues to evolve, and so does the nature of fraud. As consumer spending moves further online, fraudsters have unfortunately followed, often targeting small and micro businesses. Visaโ€™s Head of Products and Solutions for Australia, New Zealand and South Pacific, Tiziana Bianco shares three steps small businesses can take today to protect themselves against new forms of cybercrime.

3 steps to keep your business safe from cybercrime

Business meeting with woman and man looking stressed

1. Bolster your online checkout to prevent enumeration attacks

One of the top threats to emerge for online merchants in Australia and globally over the past 18 months is enumeration. But what exactly is it?

Enumeration is the criminal practice where fraudsters use automation to test and guess payment credentials such as Primary Account Number (PAN), card verification value (CVV2), expiration date and post codes, which can then be used in fraudulent transactions.

Itโ€™s the rising use of botnets โ€“ which are networks of hijacked computer devices โ€“ that are being used to carry out and scale these attacks.

Investing in online security capabilities is the best way for businesses to protect against malicious cyber attacks that could damage their brand and customer experience, or even take them offline. In fact, doing so could also help Aussie businesses gain over 13,000 hours a year in otherwise lost time trading.[1]

As a first step, small businesses should talk to their payments gateway or acquiring bank to ensure their online checkout page has the right controls in place. This could include restricting the number of transactions that can be processed by the merchant from a single card per minute, scanning for anomalies in shopping cart data, blocking accounts after a certain number of login attempts and CAPTCHAs[2], which are tasks that are designed to be easy for humans but difficult for bots.

According to new research commissioned by Visa and conducted by YouGov, while nearly half (45 per cent) of Australian consumers find CAPTCHA-style tools annoying when they shop online, over three quarters (76 per cent) are supportive of merchants using the technology if it means keeping their online payments secure.

In fact, more than half (53 per cent) of Australian consumers have abandoned their shopping cart due to concerns their payments were not secure.

cybercrime victim locked out of electronic devices

2. Invest in secure technologies that balance evolving risks and customer experience

Customers today expect a digital payment experience that is both secure and seamless, and merchants should be investing in technologies that not only reduce fraud, but also reduce friction at the point of sale.

Tokenisation is one example. It is a security technology that converts a cardholderโ€™s 16-digit account number into a token or digital credential, so merchants donโ€™t have to store sensitive payment credentials.

In addition to enhancing security, tokenisation can reduce friction in the checkout process by enabling financial institutions to automatically update expired or compromised payment credentials without any manual updates made by the customer, in the event that their card is lost, stolen or expired.

For merchants this means that tokenisation not only reduces fraud, but also maximises conversions and drives long-term loyalty.

3. Stay alert to sophisticated cybercrime scams

Whilst card fraud in Australia has grown by less than 1 per cent as reported by AusPayNet[3], scams impacting Australian consumers and businesses have been on the rise over the past two years.

According to Scamwatch, Australians reported a record $211 million in losses to scams from January to September last year, an 89 per cent increase compared to the same period the year prior[4].

yellow sign with the words 'scam alert'

Fraud occurs when a third party obtains unauthorised access to a consumer or business payment credentials, typically through a data compromise. A scam, on the other hand, occurs when a consumer or business owner is misled to provide their payment credentials to someone they believe to be a trusted entity.

These credentials are then used to perpetrate account takeovers or for unauthorised payments or transfers, which can be highly stressful for any business.

According to AusPayNet, business email compromise (BEC) is one of the costliest scams impacting businesses. Common examples include invoicing fraud, payroll fraud, and data theft, as well as situations where fraudsters impersonate lawyers or the small business owner in order to scam employees.[5] That means itโ€™s vital for small business owners to educate not just themselves regularly, but also their teams, which in turn can help protect their customers.

At Visa, we believe that an industry approach through education and awareness is best to help prevent Australian businesses becoming victims of scams. We actively work with law enforcement agencies and across industry groups to drive awareness on what to look out for and common scam sources, through our Payment Intelligence alerts.

There are also numerous, free government and industry resources available offering practical community education and training, such as Scamwatch and eSafety.

Looking to the future of eCommerce in Australia, weโ€™re excited by the opportunities for small businesses to drive growth and deliver exceptional customer experiences, but itโ€™s important to remain alert to new threats.

As eCommerce becomes increasingly popular, small businesses can take simple steps today to bolster their defences against cybercrime, prevent fraud, and protect the trust of their customers.



Want more? Get our newsletter delivered straight to your inbox!ย Follow Kochieโ€™s Business Builders onย Facebook,ย Twitter,ย Instagram, andย LinkedIn.