Wednesday, November 03, 2010

LoopFuse Announces OneView Marketing Automation Platform

eWeek reports that sales and marketing automation specialist LoopFuse has released OneView v3.28, a marketing automation platform aimed at small to medium-sized businesses, featuring inbound, content, and search engine marketing to enable marketers to analyze Website traffic in real-time, providing insight into which marketing programs are driving qualified leads to the Website.

"Similar to Google Analytics, OneView now offers real-time Web analytics that reveal who is linking to the Website’s marketing content articles. It also tracks how many visitors have accessed content from a specific source or referrering Website, as well as where visitors navigate to, after arriving from a particular referring site. In addition, OneView now provides insight into the keywords used to find the Web site across 12 supported search engines.

"Dashboards provide a real-time view across a company’s sales and marketing activities, including information on touchpoints with prospects, companies, customer relationship management (CRM) leads, and CRM contacts, as well as email marketing open and click rates and the number of leads created per hour within the CRM.

"Lead capture forms integrate with current Web site forms, allowing users to automate the process of capturing, funneling (in to the CRM), and qualifying leads. A Lead Nurturing feature automates the process of qualifying prospects in to leads or keeping existing customers' attention. The company said OneView's Lead Nurturing module is capable of analyzing all touchpoints with a particular prospect; Web site activity, contact information, email activity, and even real-time integration with the CRM."

Monday, November 01, 2010

Teradata Offers Integrated Web Intelligence

Most organizations have mechanisms in place to track their customers’ online and offline behaviors. But, historically, integrating Web data and traditional business data has been difficult, so many companies are not currently set up to track and analyze customer behaviors between channels. Accordingly, these organizations have enormous blind spots when they try to determine the efficacy of marketing campaigns in either channel or hone their communication plans and strategies.

To help remove these blind spots, Teradata has formed partnerships with Webtrends, a top Web analytics consulting firm, and Speed-Trap, a specialty Web data extract, transform and load (ETL) solution provider, to offer an easy, effective way to integrate Web data in the warehouse.

These partnerships enable integrated data that companies can use to analyze trends and customer behaviors across online and offline channels:

Webtrends, a global leader in Web analytics, provides a broad suite of reporting and analytics tools to capture and analyze Web data. With the purpose-built adapter offered by Teradata, data is transferred from the Webtrends server to the data warehouse. Technical support and expertise is jointly provided by Teradata and Webtrends to ensure the adapter’s successful implementation and ongoing optimization.

Speed-Trap is a unique software provider that offers a product that uses Web 2.0 technology to capture traditional and non-traditional Web data. These include HTML, flash, and data from a variety of interfaces, such as mobile phones, personal digital assistants and gaming consoles. With Speed-Trap, companies can track all the interactions of a Website visitor from the individual’s own browser and transfer the data, in near real time, to the data warehouse for detailed analytics.

Working with Teradata, these partners and others are part of an expanding, Web-focused ecosystem of solutions. Together, the various components enable customers to quickly and easily access information that was previously unavailable or extremely difficult and time-consuming to access.

In addition to Webtrends, Teradata has also developed adapters for other Web analytics vendors such as Omniture, Coremetrics and Google Analytics, as well as for search engines like Google, MSN and Yahoo, to bring valuable Web behavior data into the warehouse. In addition, Teradata is reaching out to other innovative software companies to offer new ways to capture data from the ever-growing number of online sources, including social networking and advertising sites.

SAS Offers Two New Hosted Services

Doug Henschen reports in InformationWeek that SAS has added two new hosted services to its portfolio of customer analytics aimed at mining online interactions.

The first is the SAS Conversation Center, an add-on module for driving customer engagement on social media networks such as Twitter and Facebook. "SAS had already announced a Social Media Analytics service last April, but feedback from the handful of customers implementing that service led to the optional Conversation Center module announced last week."

 "Social Media Analytics didn't address how you engage people in the social media space once you've identified relevant comments, so we came up with the Conversation Center," explained John Bastone, SAS's customer intelligence strategist.

Debuting in January, Conversation Center will start with comments spotted by the Social Media Analytics service and prioritize them based on their influence, such as the numbers of followers and retweets on Twitter. The module will also route comments to appropriate response queues.

(Henschen also reports in Intelligent Enterprise that "SAS is far from alone in addressing sentiment analysis. Attensity and Verint are among a handful of vendors now spotting and speeding responses to Tweets, Facebook posts, blogs and other forms of social network feedback. Both companies recently announced software that blends sentiment analysis with CRM applications. Verint's Impact 360 Text Analysis application was developed in partnership with Clarabridge, a head-on competitor to SAS in sentiment analysis.")

The second new service is SAS's Customer Experience Analytics, an application that  was formerly a user-hosted offering. CEA mines the detail of Web sessions and matches Web analytics, such as page navigation and campaign response, against known customer records and customer segments, such as loyal and high-value customers.  
 
Henschen notes that SAS works with the Speed-Trap data capture service to collect raw session data. "In the on-premise version of Customer Experience Analytics, the captured data is stored and compared to behavioral data behind the customer's firewall. SAS says it came up with the hosted service announced last week because many customers don't want to have to manage yet another data warehouse. In this scenario, customer behavior and segmentation data is sent to SAS for analysis against Web navigation data."

"Many of the larger companies we work with don't have a problem sending us customer behavioral data in a secure way," Bastone said. "They would much rather gain the convenience of getting up and running within a couple of weeks."

PCI and Tokenization, Standards, and Log Management

Mike Vizard notes on ITBusinessEdge that Protegrity claims to have the fastest, most distributed tokenization architecture for secure credit card data management. At the same time, virtualization vendors HyTrust, VMware, Cisco, Savvis and Coalfire have announced that they are working on a reference architecture for deploying PCI DSS 2.0-compliant systems on top of virtual servers, which HyTrust CTO Hemma Prafullchandra said is a deployment model that is now officially supported in the PCI DSS standard.

Ulf Mattsson, CTO, Protegrity, notes that chief security and compliance officers also need to consider the following issues:
  • Interoperability: Encryption algorithms, FIPS 140 equipment and key management solutions that are based on industry standards will be necessary to facilitate the sharing of sensitive information across the different stakeholders in the complete payments process, but standardization will require a central body to initiate and arbitrate trust between participating organizations and individuals. This could offer a great opportunity for an established player within the payments ecosystem (retailer, payment processor or vendor) to lead the way.
  • Protect the card:  The beginning of a comprehensive end-to-end solution must always start with protecting the card. Approaches such as EMV smartcards, for example, remove the payment processor from the equation by giving the merchant a direct relationship with the issuing bank. The challenge is that approaches like this need to have wider adoption to make a sustained difference.
  • Tokenizing to reduce audit costs and risk:  Tokenization is an emerging data security method that is closely related to encryption, but instead of encrypting the data in a reversible fashion, tokenization assigns a value that is only associated with the "real" data in a well-protected lookup table. "As merchants and credit card processors continue to struggle with securing cardholder data, many of them are increasingly using this approach to help reduce the scope of their risks. With the allure of easier deployment and smoother interaction with applications, tokenization's biggest draw is the fact it can dramatically reduce the need for costly PCI audits."
"Taking into consideration these factors, I don't see one silver bullet to answer the payment industry's data security problems. Rather, a combination of changes needs to happen that focus on safeguarding data in every part of the payments data flow." Vizard concludes that "the best thing about the new specification is that it calls for a risk-based approach to credit card security, which is code for telling people they need to rank their risks and apply levels of security rationally from there. What that really means is that when it comes to PCI DSS, don’t let the requirements drive you crazy."

Finally, Brian Prince notes in eWeek that the changes in the Data Security Standards taking effect in January focus on Log Management. He quotes Bob Russo, general manager of the PCI Security Standards Council: "If you don’t use a centralized logging facility then your guys have got to look in more places, and chances are if [they] have to look in more than one place...you’ll wind up missing some of this stuff," he said, adding it is a "proven fact that every time we find a breach, it’s always found in the log.” [my emphasis]

Validation against the previous versions of the standards (1.2.1) will be allowed until Dec. 31, 2011 to give organizations time to implement the latest incremental changes. From Jan. 1, 2012 onward, all assessments must be under version 2.0 of the standards.

PS - Gary Palgon, VP Product Management, nuBridges writes: "While the new PCI Data Security Standard 2.0 (PCI DSS) and the Payment Application Data Security Standard 2.0 (PA-DSS) have been released along with the recently issued supplemental guidance documents, 'PCI DSS Applicability in an EMV [EuroPay, MasterCard, and VISA] Environment' and 'Initial Roadmap: Point-to-Point Encryption Technology and PCI DSS Compliance' many organizations are now waiting for the subsequent “validation” documents that will eventually accompany this recent guidance.  At the same time, the merchant community is eager for the guidance to be released from the PCI Security Standards Council about tokenization, tentatively scheduled for late November." Palgon leads the Tokenization Working Group within the Scoping Special Interest Group (SIG) and they’ve made great progress in pulling together the beginning of a “tokenization standard,” which will not only help the PCI community, but also those companies wishing to use tokenization beyond just cardholder data, like PII, PHI and other evolving requirements.

Aria Offers Universal Payment Token

Aria Systems, Inc., a leading provider of cloud billing and subscription management solutions, today announced the Aria Universal Payment Token, an option for merchants facing new requirements in the next version of the Payment Card Industry (PCI) Data Security Standard (DSS), PCI DSS 2.0.

Offered as part of the Aria Billing and Subscription Management Platform, the Aria Universal Payment Token gives online merchants the flexibility to change payment processors without causing customer churn. The Aria platform’s cloud-based delivery model also provides an outsourced alternative for merchants looking to avoid the cost and risk associated with achieving internal PCI DSS compliance.

Payment Processor Lock-in and Customer Churn
Typical SaaS-based billing and payment solutions rely on a technique known as “tokenization” to enable secure, recurring payment card transactions over the internet. Tokenization works by replacing entered cardholder data with a surrogate “token”, a unique ID that can be stored and then reused with a given payment processor, which in turn enables merchants to avoid having to store cardholder data.

This approach lacks open standards for tokenization across different payment processors, leaving merchants “locked in” to a given payment processor. If a processor raises its fees, or another offers superior service, merchants are unable to switch without forcing their customers to re-enter their payment card information, a process that creates significant potential for customer churn.

Outsourcing Compliance to Avoid High Fees, Customer Churn and PCI Challenges
The Aria Universal Payment Token approach securely encrypts cardholder data without relying on a payment processor-specific token. Merchants can easily move between payment processors for better services or lower fees without having to recapture all of their clients’ payment card information. In doing so, merchants save money and get better service, while avoiding unnecessary customer churn.

In addition to the challenges with vendor processor lock-in, merchants are struggling with the costs and complexity associated with PCI compliance. Leading analyst firms have estimated million-dollar costs for many merchants to achieve PCI DSS Level 1 compliance, due to the technology, process controls, security infrastructure and mandatory periodic audits required. Aria Systems offers a much faster, less expensive alternative by using Aria’s cloud-based delivery model as a means to outsource the risk and complexity of compliance, with complete support for a wide range of monetization models that blend one-time, recurring subscription fees, usage-based charges as well as virtual goods and currencies.

“A vendor-neutral, universal approach is the best way for payment card tokenization to be flexible and cost-effective. Aria Systems would like to see the payment card industry create open standards in the future to prevent vendor lock-in and lower costs for customers,” said Ed Sullivan, Founder and Chairman at Aria Systems. “Fortunately, with the addition of the Aria Universal Payment Token to our Aria Billing and Subscription Management Platform, merchants now have a secure, low-cost way to outsource PCI DSS compliance and avoid processor lock-in, excessive processing fees and customer churn.”

VeriFone, RSA to Offer End-to-End Payment Card Security Service

VeriFone Systems, Inc. and RSA, The Security Division of EMC, have announced a strategic partnership to market their end-to-end encryption and tokenization solutions as an integrated payment security offering to be branded VeriShield Total Protect.

When implemented, VeriShield Total Protect will use industry-proven security technology and leverage electronic payment systems deployed in the majority of merchants world-wide to provide a consistent, consolidated approach to protecting payment card data from end-to-end, both pre- and post-authorization.

“Merchants have had to navigate among a variety of technical offerings in order to protect customers and meet compliance requirements for credit card transactions,” said VeriFone CEO Douglas G. Bergeron. “RSA and VeriFone are combining to solve this problem and let merchants focus on meeting customer needs, not mastering security protocols.”

In addition to proven technology, the goal of the strategic partnership is to bring extensive implementation and business enablement resources to processors to ensure successful deployment of the service within their infrastructure and sales channels. This will ensure broad availability and a deployment model that offers the greatest degree of risk reduction and PCI DSS scope reduction.

Processors will market the solution to merchants as a means to reduce cost and effort associated with PCI compliance, gain new abilities to safely use transaction data to support customer analytics, and drastically reduce their overall risk profile. VeriFone’s VeriShield Hidden Encryption (VHE) preserves both data format and data field structure, so end-to-end encryption can be implemented without major retrofit with existing retailer POS systems. Elements of RSA’s SafeProxy™ architecture tokenize card data for safe storage and use by merchants post-authorization.

VeriFone will be offering VHE algorithms royalty-free to any point-of-sale producer interested in offering their customers compatibility with VeriShield Total Protect.

About RSA
RSA, The Security Division of EMC, is the premier provider of security, risk and compliance management solutions for business acceleration. RSA helps the world’s leading organizations succeed by solving their most complex and sensitive security challenges. These challenges include managing organizational risk, safeguarding mobile access and collaboration, proving compliance, and securing virtual and cloud environments.

About VeriFone
VeriFone provides expertise, solutions, and services to the point of sale with merchant-operated, consumer-facing and self-service payment systems for the financial, retail, hospitality, petroleum, government and healthcare vertical markets.  

Sunday, October 31, 2010

Assessing mCommerce Performance

Moble Commerce site management "often tries to apply lessons learned in E-Commerce to M-Commerce, and that doesn’t always work," says Evan Schuman, Editor of StoreFrontBackTalk. Read his useful analysis of the"immaturity" of the mCommerce platform environment for helpful isights -- or certainly very relevant questions -- about the evolving state of the art.

Web Analytics