Trident Digital Fraud Resilience Framework


As fraud and scams become more sophisticated through the use of AI, Fraud detection becomes less effective. Companies who are fraud resilient are prepared for the onslaught. The Trident Framework is an aid to achieve a desired Fraud Resilience.

Prevention

The Prevention Process Area is the most effective of the 3 main pillars.

  • The purpose behind Secure Design is to provide an inherently secure application to clients that is secure by design as well as easy to use in a secure manner. It is recommended to use a Digital Trust framework to ensure that all components and aspects are covered. Special care needs to be given to ensure that AI generated Deepfakes and Synthetic Identities are prevented from opening or to authenticate to an account.
  • Awareness is a crucial part as the user is often the best scam detector. It is important to make the clients aware of ongoing scams affecting the company as well as how to behave securely when dealing with sensitive data like passwords. Clients should also be made aware of how to use the application or service securely, including security settings and notifications.
  • Due to the sheer number of malicious actors, it is not possible for a single entity to fend off everything alone.Collaboration can help by sharing information about encountered scams as well as potential preventative or remediate actions. It provides a time advantage to prepare for a potential upcoming fraud wave.
  • Although awareness is crucial, the advances in AI driven scams can produce the most convincing messages that even professionals have difficulties identifying. To support the clients, the company should provide a Verification service to allow clients to validate whether the message they received is legitimate.


Governance

The Governance Process Area plays an important role in keeping everything up to date and at the maximum preparedness level.

  • Core to an effective fraud risk management is to have an individualised taxonomy of all the different fraud use cases that can apply to the company. They may also be very specific cases based on industry and sales model (B2B, B2C). Once the fraud risks are assessed and prioritised, control updates and remedial actions can be implemented
  • To be effective, the digital fraud use cases need to be regularly reviewed and aligned with Cyber Security Risks. As both disciplines overlap, it is important to ensure that the detection and response measures are well coordinated.
  • As Fraud is a highly dynamic topic, Fraud Risks need to be monitored proactively as criminals have a high innovation rate.This provides time buffer for preparation to detect and respond to new fraud schemes as well as combatting detection control degradation and fight complacency. Even if nothing happens, it is still advised to conduct an annual review of the Fraud Risks.


Detection

 The Detection process area is the traditional focus of the major solution providers.

  • All fraud detection solutions traditionally use Machine Learning very early on to detect anomalies and outliers, practically all have evolved to AI. Additionally, they have also detection rules and detect back-listed entries, which is also a typical use case for Anti Money Laundering. It is also advisable to deploy hardened mobile solutions that can detect malicious manipulation on the device. The whole process needs to be monitored and this is especially challenging when there are media breaks and human responses are not always predictable
  • Although the solution vendors provide regular updates for their products, having additional fraud intelligence will help provide a broader view of the ongoing scams that may not be detected by existing tools
  • Black listing plays a crucial to prevent transfer of assets to a known non-compliant entity, be it a sanctioned or money-mule accounts. Sometimes, it might be necessary to observe transactions to a suspicious account while not yet blocking. Often money-mule accounts are commandeered legitimate accounts, and they need to be taken off the Blacklist once the legitimate owners regained control.


Remediation

The Remediation process area plays an important role to prevent financial loss once a fraud is detected.

  • The fraud detection system is traditionally integrated within the main payment system which blocks all detected fraudulent transactions.. However, if fraud is detected too late, there should be a procedure in place to recover or repatriate the funds
  • Once the fraudster's initial modus operandi has been identified, their infrastructure and websites need to be taken down to contain and prevent further damage to other clients.
  • Investigation of a fraud case will potentially need involvement of cyber specialists for technical information. All the recovered logs should be easily stored in a forensically sound manner reduce both workload as well as accelerating the prosecution. Investigations may laos show gaps in controls and identify areas of improvement
  • Very often, the detected fraud is not a single occurrence. it is important to have a enhanced surveillance in place to detect and prevent similar behaviour. Another possibility is to analyse past transaction data for indicators of fraudulent activities once additional intelligence is available (fraud hunting).

Trident Digital Fraud Resilience Framework is a registered trademark of Prod AG. This framework is allowed for own use adoption only.

Prod AG declines any responsibility for your own implementation and their consequences.
Using or integrating this framework for consulting or advisory purposes without prior consent from Prod AG is strictly prohibited..