A Guide To Network Tokenization (PDF) - CyberSource

Transcription

A Cybersource guideA guide to networktokenizationWhy tokenizationThe arrival of network tokensCybersource Token Management Service 2022 Cybersource. All rights reserved.

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstartedContents3WelcomeWhy are we talking about tokenization?4Why tokenizationCreating secure and seamless payments is harder than it sounds5Payment tokenizationHow it works, why it’s important8Cybersource Token Management ServiceThe enormous benefits for business16Getting startedHow Cybersource can help 2022 Cybersource. All rights reserved.A guide to network tokenization2

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstartedWelcomeThe payments revolution ishappening all around us, and it’simpossible to ignore. Nor shouldany business want to ignore it:from the opportunity to servecustomers worldwide to thesimplicity of going cashless,digital commerce is providingbenefits at every level.Of course, with new opportunities inevitablycome new challenges. Customers now expectsimple and consistent payment experiences,but payment environments keep growing morecomplex. And while worldwide digital commercegrew 27.6% in 2020/21, 2020 also saw a 20%rise in security breaches.1But as so often happens, necessity has bredinvention. New tokenization technology isfundamentally changing how sensitive paymentdata are managed.While solving security challenges, tokenizationalso helps businesses create seamless paymentsexperiences that are making a material differenceto conversion and revenue.This guide will show you how payment tokenizationcan benefit your business, and of course, howCybersource can help.1 Gibson Dunn, U.S. Cybersecurity and data privacy council outlook and review, Jan. 28, 2021 2022 Cybersource. All rights reserved.A guide to network tokenization3

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstartedWhy tokenizationSo why is creating seamless payment experiences so hard?The problem stems from the risks associated with sensitiveaccount data.The current payments ecosystem still relies on customeridentifiers consisting of personal account numbers (PANs),billing addresses, expiration dates, and card security codes.“ Digital commerce presentsnot only huge opportunities,but also a particular setof challenges: transactiondecline rates, online fraud,and the customer’s paymentexperience. At the sametime, keeping up withrapidly evolving technologyis becoming increasinglycomplicated.”Jignesh KachariaVice President, Product ManagementCybersource8.4billionrecords were exposed inQ1 2020, 273% vs Q1 2019 2Used online, these account details draw the attention offraudsters looking for ways to exploit the data on an industrialscale, so businesses must bear the cost of keeping them safe.Equally, if these identifiers are compromised, it’s hard forbusinesses to tell if they’re being used legitimately. 8.19millionthe average total cost perbreach in the U.S. in 2019 3The result is that businesses are faced with a no-win situation:decline any transaction that looks remotely suspect andnegatively impact sales or accept all transactions and riskfraud and reputational damage.2 8.4 Billion Records exposed in Q1 2020, Security Magazine, May 12, 20203 Marty Puranik, What is the Cost of a Data Breach? Forbes, Dec. 2, 2019 2022 Cybersource. All rights reserved.A guide to network tokenization4

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstarted1 2 3Payment tokenizationTokenization technology arrived nearly two decadesago and is now at the heart of keeping data securewithin the payment process. Almost all businessescurrently use tokens to some extent to prevent fraud.How tokenization works1. A customer’s PAN is replaced with a uniqueidentifier created by a seller’s in-housesystem, an acquirer, or a payment platform.2. Crucially, the token bears no mathematical linkto the PAN and cannot be reverse engineeredto uncover the PAN—even if a fraudster gainsaccess to it.3. The real PAN is stored securely by the acquireror gateway and is at no point revealed to theseller or used in processing payments.PANPANPANCustomerMerchantAcquirer bankThe concept of using a token tosafeguard something of value is nothingnew: think of chips in a casino or tokensin an arcade. Payment tokens follow thesame principle.Tokenization means a customer’ssensitive account data is replacedwith a digital identifier while the realdata is stored securely. If the tokenis compromised, it is meaningless andcannot be used. 2022 Cybersource. All rights reserved.Card networkIssuer bankThe result is win-win. Customers don’thave to worry about their accountdetails being vulnerable online, andbusinesses don’t have to worry aboutkeeping sensitive data safe within theirown environment.The widespread moveto tokenization is wellunderway.A guide to network tokenization5

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstarted1 2 3The arrival of network tokensA major step forward in tokenization has been the arrival ofnetwork tokens, which unlock higher authorization rates,lower fraud, and create a better customer experience.The first payment tokens were issued by sellers, acquirers,or payment platforms for individual credentials. In contrast,network tokens are generated by a payment network suchas Visa. Instead of replacing a single PAN for its lifespan, theyrepresent a customer’s credentials for the entire buying cycle. 2.2%Authorization ratesThe ability to recognizemore legitimate repeatcustomers is proven tolift conversion rates byan average of 2.2%.4-26%What this means is that, at the point of initial payment, a businesscan ask the network to generate a token that can then be used(and importantly, tracked) for all subsequent transactions, evenif the card has been replaced by the cardholder. The credentialswill automatically be updated via lifecycle management, be it fora card or a digital wallet like Google Pay.FraudNetwork tokenization canreduce fraud by an averageof 26% without creatingadditional payment frictionfor your customers.5This allows businesses to recognize their customers andunderstand them better, enabling higher authorization ratesas well as fraud reduction.4 Visa global card-not-present transactions for token vs non-tokenized credentials, May–July 20215 CNP & CP Average is for set of Token participating Merchants (by Merchant DBA) (PAN & Token)with digital wallet TRs April–June 2018, Issuer region: US 2022 Cybersource. All rights reserved.A guide to network tokenization6

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstarted1 2 3Network tokenization madeeasy by CybersourceCybersource can accelerate your business’s adoptionof emerging network tokenization technologies witha suite of fast, comprehensive solutions.We are a Visa solution with tremendousglobal scale, serving 190 countries andterritories.Cybersource acts as a bridge to network tokenizationfor Visa and Mastercard and will soon include AmericanExpress and Discover. Our brand-agnostic global accessand network token expertise can help you maximize thebenefits of network tokenization, regardless of whereyou are on the journey. 2022 Cybersource. All rights reserved.A guide to network tokenization7

WhytokenizationWelcomePaymenttokenizationToken ManagementServiceGettingstarted1 2 3 4 5 6 7 8Cybersource Token Management ServiceToken Management Service is the simplest way foryou to maximize the potential of network tokenizationand become an early adopter of new innovations andomnichannel experiences.The power behind Token ManagementService lies in Cybersource’s supertoken, which links network tokensfrom different card brands (such asVisa and Mastercard), banks, paymenttypes, and channels together.Cybersourcesuper tokenCard brands 2022 Cybersource. All rights reserved.BanksPayment typesThis super token centralizes andsimplifies the management of previouslyseparate tokens and payment types,making it possible to create a completetransaction history for each of yourcustomers. You get a 360-degree viewof your customers’ shopping habitsacross different channels, and you canmake customer loyalty and rewardsopportunities part of every online,mobile, and in-store transaction.If you offer multiple card brands youcan see a customer’s activity acrossall of them, too.ChannelsA guide to network tokenization8

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstarted1 2 3 4 5 6 7 8The super token:A Cybersource innovationCybersource’s proprietary network token linkspayments, customer data, and other network tokensto create a super token.Links tokensfrom differentnetworks, issuers,and channels.Includesalternativepayments.Creates a unifiedview of yourcustomers.Makes paymentssimple and safe.Only Cybersource Token ManagementService offers a proprietary networktoken that links tokens from differentnetworks, issuers, and channels to helpresolve the tension between simplepayment experiences and complexenvironments.Token Management Service improvescustomer experience by creating aunified view of your customers and theirbuying behaviors across channels andpayment methods, seamlessly updatingpayment credentials to provide asmooth path to improved conversion.Cybersource’s super token not onlyconnects data from all card types andissuers, it includes alternative paymentssuch as eCheck, ACH, and other debitproducts. The super token powers ourToken Management Service in managingcustomer data, simplifying customermodels, keeping credentials refreshed,and reducing PCI compliance scope.And it integrates seamlessly with otherCybersource solutions, such as DecisionManager, Payer Authentication, AccountTakeover Protection, Recurring Billing,Global Gateway, and others.Using Token Management Service makespayments simple and safe for yourcustomers—no matter how complicatedthings get behind the scenes. 2022 Cybersource. All rights reserved.A guide to network tokenization9

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstarted1 2 3 4 5 6 7 8The benefits of CybersourceToken Management ServicePayment options your customers loveBy helping you understand your customers’ shoppinghabits across payment methods, networks, and channels,Token Management Service enables:One-click checkout options using cardon-file information across differentchannels.More ways to pay, including digitalwallets, direct debit, Click to Pay, ACH,online bank transfers, international andregional cards, and whatever else is thenext big thing. 2022 Cybersource. All rights reserved.Personalized payments that usecustomers’ cross-channel paymenthistories and data to pinpoint theirpreferred way to pay.New ways to shop, including buy online,pick up in store (BOPIS), curbsideordering, touchless kiosks, and more.A guide to network tokenization10

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstarted1 2 3 4 5 6 7 8Safeguardyour businessKeep customer data encryptedand secured: Cybersource TokenManagement Service protects yourcustomers’ sensitive personal and cardinformation before, during, and afterevery transaction.Tap into the advantages of top-tier, Visagrade security: Store your customers’card-on-file information in Visa’senterprise-level, tier-4 data centers—the highest level of security used forsensitive customer payments data.BoostrevenueLift authorization rates: The abilityto recognize more legitimate repeatcustomers is proven to boostauthorization rates by an averageof 2.2%.6Avoid lost revenue from expired cards:Payment cards are updated seamlessly,providing a smooth path for ongoingauthorizations.Reduce fraud: Reduce fraud by anaverage of 26% without creatingadditional payment friction for yourcustomers.7Improve customer loyalty strategies:Visibility across channels means you canalso reward customers across channelswith discounts, loyalty points, and promocodes, driving repeat business andincreasing revenue.Enhance lifecycle management:Optimize revenue using lifecyclemanagement to ensure the latestaccount information is available viaautomated updates.Save moneyReduce your PCI DSS compliancescope and costs: Token ManagementService meets the strictest regulatorystandards for encryption and datasecurity. There’s also no need to staffand manage multiple network tokensystems to prove PCI compliance—almost everything is done for you.Gain better customer insight: Create acomplete, unified view of your customersand their purchasing behaviors so youcan give them a personalized experiencewithout a time and resource-intensiveeffort by your IT department.Move efficiently toward networktokenization: Accelerate your journeytoward network tokenization with a fast,comprehensive solution for adoptingVisa Token Service and other networktokenization technologies.6 Visa global card-not-present transactions for token vs non-tokenized credentials, May–July 20207 CNP & CP Average is for set of Token participating Merchants (by Merchant DBA) (PAN & Token)with digital wallet TRs April–June 2018, Issuer region: US 2022 Cybersource. All rights reserved.A guide to network tokenization11

WhytokenizationWelcomePaymenttokenizationToken ManagementServiceGettingstarted1 2 3 4 5 6 7 8Tokenization is a critical part of amodular solution to combat fraudAnother enormous benefit of Cybersource Token ManagementService is that it easily integrates with our other solutions,including Decision Manager, Payer Authentication, AccountTakeover Protection, Recurring Billing, Global Gateway, andothers. These products, when combined with Token ManagementService, create powerful solutions that reduce fraud, increaseauthorization, and optimize revenue.Once integrated, our modular services and global reach give youthe flexibility to design a tailored experience for your customers,with payments seamlessly embedded.Modularservicesinclude onsPayerAuthenticationAccount sAll channelsMany verticalsBuilt on VisaRetaileCommerce99.997% uptime9TransitTelecomRestaurantAirlineData-based fraud preventionInsuranceUtilitiesGlobal connectivity9 Cybersource enterprise platform uptime based on FY21 internal data, Oct. 1, 2020 to Sep. 30, 2021 2022 Cybersource. All rights reserved.A guide to network tokenization12

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstarted1 2 3 4 5 6 7 8Solving your business needsBusiness needs solved by Cybersource Token Management ServiceIntegrating network tokenization into your businessI don’t want to have to integrate with each major cardbrand to start using network tokens.Token Management Service provides network tokenizationfor Visa and Mastercard, with American Express andDiscover coming soon.I want to process card, non-card, and alternativepayments using the same token.Token Management Service provides a single customertoken for all payment methods.I want to change processors or acquirers withouthaving to update my token or import/exportpayment data.With Token Management Service, tokens stay the same inyour systems, even if you change acquirers/processors.I need a token solution that supports all my existingprocessors and acquirers, so I don’t have to changemy tech and bank relationships.Our solution provides a unifying layer for all your existingpayment tokens and/or gateways, enabling them tocoexist in a single payment environment.I want a single token to work across multiple acquirersand regions.Token Management Service works across multipleacquirers and regions using a unified token from yoursystem.I want support with our PCI assessments so we cankeep up and not get fined.Token Management Service maintains PCI DSS complianceto reduce your audit time and ensure full compliance. 2022 Cybersource. All rights reserved.A guide to network tokenization13

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstarted1 2 3 4 5 6 7 8Business needs solved by Cybersource Token Management ServiceIntegrating network tokenization into your businessI want to remove payment data from my system,so we don’t get breached.Token Management Service is cloud-based, with datastored in Visa’s tier-4 data centers.I want a token solution that bridges across vaultsthat were used for ecommerce and card-presentseparately.Token Management Service supports a seller-wide vault,irrespective of channel and with access provisioning bybusiness unit, if needed.There are still parts of my ecosystem that need PAN,like our call center. How will that work?Token Management Service can return the last 4 or6 numbers of a PAN, as well as full PAN decryption ifspecifically approved by your business.Increasing revenue captureI want to stop getting declines due to expired cards,invalid account numbers, and CVV2 failures.Token Management Service includes Cybersource AccountUpdater, which updates card details automatically forbetter lifecycle management and increased revenue.I want to maximize successful authorizations forcustomer purchases.Token Management Service is the fastest way to connectto Visa Token Service—which uses network tokens toobtain more data from the issuer during tokenization fora more trusted payment credential.I want to reduce recurring billing and card-on-fileinterruptions for seller-initiated scheduled paymentsand customer-initiated payments.Token Management Service provides the merchant-initiatedtransaction (MIT) and cardholder-initiated transaction(CIT) protocols (on supported processors) to reducedeclines for network tokens using credentials-on-file.Offering extra flexibility for customersI want to process payments and returns across allchannels and locations using a single token.Token Management Service comes seamlessly integratedwith Global Gateway for payment processing and can alsosupport in-person payments.I want to allow online purchases with in-person pick-up(BOPIS) using a single token.With Token Management Service, a single token worksacross channels, even with separate acquirers/processorplatforms for purchase and pickup.I want to allow online purchases to be returned at retaillocations, and vice versa.Token Management Service allows returns to an original ora new payment method securely through a unifying token.For goods not in stock in-store, I want to take paymentin-store and deliver the goods to the customer’s home.Token Management Service links across channels,allowing back-end fulfillment systems to completea store-originated purchase with a token. 2022 Cybersource. All rights reserved.A guide to network tokenization14

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstarted1 2 3 4 5 6 7 8Business needs solved by Cybersource Token Management ServiceOffering extra flexibility for customersI want to offer new digital experiences for mycustomers, like curbside pickup, mobile key check-in,grab & go, biometrics/face-to-pay, fob, chat bot, etc.When payment credentials are tokenized, businessescan innovate customer experiences and journeys.I want to track customer reward/loyalty programsand see purchasing behavior with a single identifier.Token Management Service can show a customer’sloyalty and reward signups and usage.I want to sign customers up online and in personfor recurring services through a subscription.Token Management Service can be used as a storedcredential for recurring subscription billing.I want to let my customers place an order usingAlexa or Siri.Token Management Service tokens can be used bypartners who enable IoT commerce, without exposingcard details to third parties.I want to be able to see a customer’s purchasingbehavior across channels.Token Management Service isn’t limited by channeland can identify customers and their purchases acrosschannels.I want to leverage a customer’s purchasing activitiesfor more targeted marketing.Token Management Service can provide omnichannelreporting on purchasing behavior.After an order is placed, I want my customer to beable to make changes that may require follow-onauthorizations.With Token Management Service, a single token can beused to re-authorize a payment instrument or partiallyrefund from another internal department (like distributionsystems) without any impact on the customer. 2022 Cybersource. All rights reserved.A guide to network tokenization15

WelcomeWhytokenizationPaymenttokenizationToken ManagementServiceGettingstartedGetting startedCybersource Token Management Service can supportall your existing processors and acquirers across theglobe. You won’t have to change your tech and bankrelationships to implement tokens.From start to finish, you’ll have a dedicated support team on hand to help:Getting started Implementation Specialists Technical Account Management Enablement TeamInnovation solutions Development and Test Engineering Team Technical Product and Business Solutions Team Acquiring Solutions TeamAdapting and growing Product Innovation and Strategy Team Architecture Team DevOps and Release Management TeamOngoing support Product Innovation and Strategy Team Architecture Team DevOps and Release Management TeamLet’s talk tokensIf you’d like to discuss howtokenization can enhance yourbusiness, and how Cybersourcecan help, let’s talk.Contact sales 2022 Cybersource. All rights reserved.A guide to network tokenization16

Cybersource acts as a bridge to network tokenization for Visa and Mastercard and will soon include American Express and Discover. Our brand-agnostic global access and network token expertise can help you maximize the benefits of network tokenization, regardless of where you are on the journey. Cybersource can accelerate your business's adoption