According to last month's Harris Interactive study, about 50 million Americans have been informed--mostly by their banks or government--that their personal credentials have been somehow compromised. In addition, nearly 10 million Americans are aware of specific instances in which they were victims of identity theft. As staggering as these numbers are, the actual numbers are necessarily higher than what's reported. It would be quite a stretch for you to imagine that somehow your data remain safely stored among all the vendors, doctors, banks, web sites, and government agenices whom you've engaged in your lifetime. More likely, your personal credentials are all for sale in black market exchanges like this one.
In other words, the horses are out of the barn. There's little point trying to re-tool or regulate the world's IT infrastructure to contain consumer data. Even if your concern is future generations whose identities are still safe from thieves, there are so many ways for data to leak that it's futile to expect brittle secrets like our social security numbers to be both useful and sustainably confidential. So rather than fund "extrusion detection" startups, as so many other VC's have done, I have instead looked for technology that can protect our identities in a way that does not presume the secrecy of our credentials.
But I did learn from Cyota that if you can't keep a secret from phishers and laptop thieves, and if you can't trust spyware-infected computers, you can still protect your assets through multi-channel authorization of risky transactions. That is, thieves can't get to your assets if you are consulted prior to withdrawals and account changes over a medium separate from that in which the transaction originated.
That's why Bessemer set out to find a company focused on putting consumers in charge of their own finances, through mechanisms that require their out-of-band authorization for any extension of credit. There are many possible mechanisms, including opt-out lists, credit fraud alerts (courtesy of the 2003 FACTA Act), and credit freezes (courtesy of California's Consumer Credit Reporting Agencies Act). We assessed many startups in the field, but the best among them is Lifelock.
Todd Davis, the CEO of Lifelock, got our attention when he disclosed his social security number on TV, proving his personal confidence in the Lifelock service. By focussing on easy enrollment, Lifelock has built by far the largest subscriber base in the industry, with stellar customer satisfaction rates that yield annual churn rates below 5%.
Obviously I'm excited about this investment (like the Men's Hair Club President, I'm also a customer!). Bessemer's anti-fraud practice has been consistently successful to date with Verisign, Cyota (RSA), SiteAdvisor (McAfee) and Coral Systems (Lightbridge). And this was one of those easy investment decisions where several road maps (Consumer Internet, Multi-Channel Authorization, Get Big Cheap) converged.
Technorati Tags: ID+theft identity+theft lifelock bessemer ssn kerckhoffs schneier fraud+alert phishing credit+freeze cyota
Blogged with Flock
No comments:
Post a Comment