No video. Yet.
The Flawed Perspective of “Go-to-market”: It’s Really “Come-to-market”
If you’re a vendor, it’s not all about you.
Medieval cities, as well as modern yuppified cities, often featured a market. Once a week vendors would congregate in the marketplace to sell their wares, and townspeople and others would go to the market and peruse what was on offer.
One Thursday morning, one prosperous vendor of apples announced to his workers, “Today we are going to GO TO MARKET!”
The trumpeter blew his trumpet, the workers assembled in a line, and the vendor mounted his horse and headed toward the city to GO TO MARKET.
His workers were already pre-briefed with internal sales enablement materials, and the vendor had printed flyers for the townspeople who could read. For the others, there were the trumpets.

Now THAT is how you go to market.
Except that by the time the vendor arrived at the market, seven other vendors were already selling apples at the market and doing a brisk business. The vendor and his wares were ignored, and the trumpets were reluctantly put away.

Too late.
Because while everyone planning the go-to-market initiative thought it was all about them, the prospects had other ideas.
Come-to-market
I have read hundreds of product marketing job descriptions, and they all describe the product marketer’s go-to-market duties as spearheading a go-to-market plan, and coordinating with internal departments to ensure the go-to-market runs smoothly.
Never mind the fact that the market itself may have other ideas.
And that the prospects, not the vendors, control whether sales happen.
Because in reality it’s not a GO-to-market exercise.
It’s an exercise in which the vendors COME-to-market to sell their wares to the prospects.

It’s about the prospects, not the vendors. (Customer focus.)
Managing Privacy When Your Face is Your Password
We know the damage that can happen when people steal passwords. But other stolen information can do harm, including facial templates.
Non-password authentication
I’ve been writing some use cases around the common “selfie plus ID” method.
- Usually you use facial recognition plus a government-issued ID (such as a driver’s license) to enroll in the system and verify your identity. (Although you could use other factors.)
- Usually you use only facial recognition (against the template stored from enrollment) to authenticate your identity. (Again, you could use other factors, even a password.)
If the identity mechanism is centralized, you don’t store a password, but instead store a biometric template.
The threat of theft
What happens when—not if—the central storage is hacked?
Even if the storage is decrypted (you did encrypt the data at rest, right?), all may not be lost. Biometric templates from one vendor may not be usable by another vendor’s system.
But even in the worst case scenario in which someone steals and reuses someone’s biometric template, it’s practically useless if the system guards against presentation attacks (liveness) and injection attacks. With those guards, you need more than a valid template to get into a system.
And for those who respond that decentralized identity is the perfect solution…edge devices can be hacked also.
The threat to privacy
But those are just the technical issues. You have to deal with the business issues.
Because the theft exposes personally identifiable information, which may result in legal issues.
Depending upon local law, you have to inform your users of the breach, potentially disclosing what data was breached.
What now?
Are you ready to deal with the business consequences?
Bredemarket can help you get ready.
The Privacy Breach
More tomorrow morning.
Whose Card Is That?
Find out Friday.
The “Safe Word” KBA is as Vulnerable as Other KBAs
Why knowledge-based authentication? Because, in theory, it’s something you know that no one else knows.
“Safe words” are a form of KBA.
- You get a call from your son, who says he’s in jail and won’t be released unless you send money now. The voice sounds like your son, so you send the money. Of course, it isn’t your son, but a deepfake engineered to scam you of your money..
- But if your son volunteers the “safe words” that the two of you previously selected, you have a much higher assurance that the voice on the phone is your son.
But, as Secrets of Privacy notes, safe words are also vulnerable. Some of their tips:
Safe words, not safe word
While password length requirements sometimes become ridiculous, they have a purpose. A longer password is harder to guess than a shorter one.
Similarly, four safe words are harder to guess than a single one.
Provided the words are unrelated. “The quick brown fox” is a terrible safe phrase.
That no one else knows
If someone can read your safe phrase online, it’s unsafe. I cannot use “California State University Fullerton” (on my LinkedIn profile) or “biometric product marketing expert” (all over this website).
Established together, preferably in person
Don’t rely on online establishment. People see things.
“Don’t text the safe phrase (even via Signal), never email it and don’t save it somewhere like in a cloud document or note app.”
And one more thing
If your purported son calls you, he’s the one to use the safe phrase…not you.
“Eva Velasquez, CEO of the Identity Theft Resource Center, sees this mistake constantly. A family sets up a safe word, and then in the panic of an actual emergency call, the intended victim blurts it out themselves trying to be helpful or trying to speed things along. A scammer who hears “wait, is this about our safe word, it’s soggy trombone” now owns your safe word. The rule has to run one direction only. Whoever is asking for money says the phrase unprompted, or the call gets treated as fraud, no exceptions.”
Admittedly the victim is under extreme pressure, but try to remember this. Blurting out the safe word is the equivalent of leaving your house keys in your front door lock, with a red arrow labeled “For burglars.”
When done right, safe phrases work
But don’t let this scare you away from safe phrases.
“The reason a safe phrase beats even a flawless voice clone is that it doesn’t rely on the voice being fake or real. It relies on information the scammer physically cannot have.”
Power
A Box
A box just sits there.
The Quadruple-Penalty Mistake: Inside UBS’ AML Failure
When a company runs afoul of regulations, there’s always the chance that they’ll be caught and fined. But what if they’re caught multiple times for different facets of the same offense…because they had never heard of YOUR company’s anti-money laundering (AML) solution?
deepidv on “coordinated enforcement”
Take the story of UBS Financial Services and FOUR different government and private entities.
“UBS Financial Services Inc faced simultaneous enforcement action from four separate US regulators. FinCEN [Financial Crimes Enforcement Network, part of Treasury] fined the firm $125 million for AML and suspicious transaction reporting failures. The SEC [Securities and Exchange Commission, independent agency] fined UBS $20 million for related AML failures. The CFTC [Commodity Futures Trading Commission, independent agency] fined the firm $8 million for AML monitoring deficiencies. FINRA [Financial Industry Regulatory Authority, private corporation overseen by the SEC] issued its own fine for overlapping AML shortcomings.”
Ouch.
If you don’t check money laundering, you’ll be out of money yourself.
And those are only the fines in the United States. Other countries may pile up and add more fines.
Could your company have solved UBS’ problem?
Now, there’s the chance that a vendor could have helped UBS Financial Services stay in AML compliance.
And perhaps YOU are that vendor.
If your software costs less than $125 million, it’s a win.
So how do prospects learn about your AML solution?
You tell them…with Bredemarket’s help.
Learning the Systems, Multiple Times Over
The difference between working FOR one company and working WITH multiple companies is that one company—sometimes—does things one way, while multiple companies definitely don’t.
Well, unless Bredemarket were so ginormous that I could dictate to every client and prospect that I only work in a single way.

I’m not, so I don’t.
One example: when I worked for Incode 3-4 years ago, we primarily used one communication tool and one project management tool. After I left Incode, my Bredemarket clients and I have used a multitude of communication and project management tools, to say nothing of all the other tools Bredemarket uses with its clients. Microsoft Office vs. the Google equivalents. WordPress vs. other apps I can’t even access. SharePoint vs. Google Drive. KnowBe4 (yes, I work frequently enough at one company that I have to complete mandatory training). And, most importantly for Bredemarket’s bank account, different invoicing and payment systems. (Gotta learn those.)
It’s comparable to the months before I joined Printrak, when I was working with a multitude of firms. (Printrak was supposed to be one more firm, but I stayed there for over 25 years.) Most notably, one client was standardized on OS/2. I had never used it before, and would never use it again.

But I learned all the systems before Printrak, at Printrak, at all the other companies, and at all the Bredemarket clients.
It’s part of doing business.
