Click here to close now.

Welcome!

Microservices Journal Authors: Liz McMillan, Elizabeth White, Carmen Gonzalez, Pat Romanski, Jason Bloomberg

Related Topics: Security, Microservices Journal, Web 2.0

Security: Article

Ending the Tug of War: How Startups Can Help Banks Innovate

Startups can drive amazing innovation by rapidly iterating across ideas and testing with users

Banks face a difficult tug-of-war every day. Consumers demand innovative new services - regulators demand security, compliance and soundness of all offerings. How can a bank resist being pulled in every direction and find a middle ground?

Startups Provide Innovation
Banks can look to startup technology companies for new solutions. Startups are (at least initially) unfettered by regulations, approval committees, and long meetings. This is both a scary and exciting notion for bankers. There are a host of startups in the financial technology space, and bank-grade platforms like FIS's mFoundry originated from small teams working on an idea.

Startups can drive amazing innovation by rapidly iterating across ideas and testing with users. Startup product and service design and usability typically eclipse the made-by-committee-and-regulators look of bank applications.

Banks attend conferences throughout the year looking for innovative new partners. The excitement of possible collaborations is often tempered when you return to the office and discuss the regulatory implications with your business development and compliance teams.

Banks need a way to find compliant startups that do a great job of customer service and satisfy regulatory rules and frameworks.

Startups that Scale for Security
While the early days of a startup are heady times filled with dreaming, those that want to succeed in financial services technology must understand the environment that banks face. You can easily spot the savvier startups within their first 18-24 months - where appropriate they are already leveraging big company processes and practices, to make them look like "real" companies, even if they have only 10 or 20 people.

Signs of a bank-ready startup:

  • External certifications for security (e.g., PCI Level 1 Compliance, ISO 27001)
  • They've read the latest OCC bulletin on third-party provider compliance
  • The founder or management team has a banking or large-scale fintech background

We didn't just describe a unicorn: these startups to exist. The founders know they need a bank partner to launch their product (either as a part of the solution or as a customer). The founders understand what banks need to do from their side and they built their business from the ground up with respect for compliance.

Starting Right Leads to Efficient Compliance
Startups that build solutions that are strongly compliant are often asked: "How can a small company afford that?" While it is difficult and expensive to keep large, older organizations in compliance, smaller companies find it much faster and require much less expense.

The development of Wallaby's digital wallet software began less than two years ago, and included a strong focus on security from day one. Last month, we received our first Attestation of Compliance with PCI Level 1 Security Standards. It required twelve months and less than $50,000 to achieve this because it required so little rework and retraining.

Having participated in PCI compliance audits before, we were familiar with the requirements: We had all the basics like a firewall and anti-virus. We hired engineers for Wallaby with a security mindset. We took the approach that the standards are the minimum. We built our own tools instead of spending thousands on software.

This focus on compliance extends throughout our business. In our short history as a company, numerous partners have audited us. From our financial statements to our office, we keep everything in order at all times.

The Tug of War Ends Here
Innovative customer services and compliance can live together peacefully and productively. It is a key dynamic of working within a regulated industry that is entrusted with the security of people's financial assets. While not every new company is right for banking (and not every bank is looking to partner with startups), we believe there are methods, policies, procedures and audits that can help banks work comfortably with innovative new companies. Together we can provide improved products and services to customers and improve returns for banks.

More Stories By Matthew Goldman

Matthew Goldman is CEO and Co-Founder of Wallaby Financial, Inc. Wallaby Financial is a Pasadena, Calif.-based startup that is working to bring order to your financial life by helping you pay the right way—to earn more rewards and avoid fees, by helping you use the right credit card each time you pay. Previously, Matthew was Director of Retail Strategy at Green Dot Corporation (GDOT), the nation's leading provider of reloadable prepaid debit cards. Follow Matthew on Twitter @magoldman. Learn more about Wallaby at https://www.walla.by/

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@MicroservicesExpo Stories
T-Mobile has been transforming the wireless industry with its “Uncarrier” initiatives. Today as T-Mobile’s IT organization works to transform itself in a like manner, technical foundations built over the last couple of years are now key to their drive for more Agile delivery practices. In his session at DevOps Summit, Martin Krienke, Sr Development Manager at T-Mobile, will discuss where they started their Continuous Delivery journey, where they are today, and where they are going in an effort ...
SYS-CON Events announced today that the "First Containers & Microservices Conference" will take place June 9-11, 2015, at the Javits Center in New York City. The “Second Containers & Microservices Conference” will take place November 3-5, 2015, at Santa Clara Convention Center, Santa Clara, CA. Containers and microservices have become topics of intense interest throughout the cloud developer and enterprise IT communities.
Disruptive macro trends in technology are impacting and dramatically changing the "art of the possible" relative to supply chain management practices through the innovative use of IoT, cloud, machine learning and Big Data to enable connected ecosystems of engagement. Enterprise informatics can now move beyond point solutions that merely monitor the past and implement integrated enterprise fabrics that enable end-to-end supply chain visibility to improve customer service delivery and optimize sup...
Buzzword alert: Microservices and IoT at a DevOps conference? What could possibly go wrong? In this Power Panel at DevOps Summit, moderated by Jason Bloomberg, the leading expert on architecting agility for the enterprise and president of Intellyx, panelists will peel away the buzz and discuss the important architectural principles behind implementing IoT solutions for the enterprise. As remote IoT devices and sensors become increasingly intelligent, they become part of our distributed cloud en...
I’ve been thinking a bit about microservices (μServices) recently. My immediate reaction is to think: “Isn’t this just yet another new term for the same stuff, Web Services->SOA->APIs->Microservices?” Followed shortly by the thought, “well yes it is, but there are some important differences/distinguishing factors.” Microservices is an evolutionary paradigm born out of the need for simplicity (i.e., get away from the ESB) and alignment with agile (think DevOps) and scalable (think Containerizati...
In this Power Panel at DevOps Summit, moderated by Jason Bloomberg, president of Intellyx, panelists Roberto Medrano, Executive Vice President at Akana; Lori MacVittie, IoT_Microservices Power PanelEvangelist for F5 Networks; and Troy Topnik, ActiveState’s Technical Product Manager; will peel away the buzz and discuss the important architectural principles behind implementing IoT solutions for the enterprise. As remote IoT devices and sensors become increasingly intelligent, they become part of ...
Enterprises are fast realizing the importance of integrating SaaS/Cloud applications, API and on-premises data and processes, to unleash hidden value. This webinar explores how managers can use a Microservice-centric approach to aggressively tackle the unexpected new integration challenges posed by proliferation of cloud, mobile, social and big data projects. Industry analyst and SOA expert Jason Bloomberg will strip away the hype from microservices, and clearly identify their advantages and d...
There is no doubt that Big Data is here and getting bigger every day. Building a Big Data infrastructure today is no easy task. There are an enormous number of choices for database engines and technologies. To make things even more challenging, requirements are getting more sophisticated, and the standard paradigm of supporting historical analytics queries is often just one facet of what is needed. As Big Data growth continues, organizations are demanding real-time access to data, allowing immed...
SYS-CON Media named Andi Mann editor of DevOps Journal. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. DevOps Journal brings valuable information to DevOps professionals who are transforming the way enterprise IT is done. Andi Mann, Vice President, Strategic Solutions, at CA Technologies, is an accomplished digital business executive with extensive global expertise as a strategist, technologist, innovator, marketer, communicator, and thought lea...
Even though it’s now Microservices Journal, long-time fans of SOA World Magazine can take comfort in the fact that the URL – soa.sys-con.com – remains unchanged. And that’s no mistake, as microservices are really nothing more than a new and improved take on the Service-Oriented Architecture (SOA) best practices we struggled to hammer out over the last decade. Skeptics, however, might say that this change is nothing more than an exercise in buzzword-hopping. SOA is passé, and now that people are ...
While the DevOps movement and associated technologies have garnered much attention and fanfare, few have addressed the core issue - the hand off from development to operations. We tend to not acknowledge the importance of Release Management - a critical DevOps function. Release Management is the bridge between development and operations that needs to be strengthened with the right approach, tools, teams and processes. The white paper "How to set up an Effective Enterprise Release Management F...
I’m not going to explain the basics of microservices, as that’s that’s handled elsewhere. The pattern of using APIs, initially built to cross application boundaries within a single enterprise or organization, is now being leveraged within a single application architecture to deliver functionality. Microservices adoption is being driven by two forces: the need for agility and speed; and the re-composing of applications enabling experimentation and demands to support new delivery platforms such as...
Announced separately, New Relic is joining the Cloud Foundry Foundation to continue the support of customers and partners investing in this leading PaaS. As a member, New Relic is contributing the New Relic tile, service broker and build pack with the goal of easing the development of applications on Cloud Foundry and enabling the success of these applications without dedicated monitoring infrastructure. Supporting Quotes "The proliferation of microservices and new technologies like Docker ha...
There’s a lot of discussion around managing outages in production via the likes of DevOps principles and the corresponding software development lifecycles that does enable higher quality output from development, however, one cannot lay all blame for “bugs” and failures at the feet of those responsible for coding and development. As developers incorporate features and benefits of these paradigm shift, there is a learning curve and a point of not-knowing-what-is-not-known. Sometimes, the only way ...
You often hear the two titles of "DevOps" and "Immutable Infrastructure" used independently. In his session at DevOps Summit, John Willis, Technical Evangelist for Docker, will cover the union between the two topics and why this is important. He will cover an overview of Immutable Infrastructure then show how an Immutable Continuous Delivery pipeline can be applied as a best practice for "DevOps." He will end the session with some interesting case study examples.
Data-intensive companies that strive to gain insights from data using Big Data analytics tools can gain tremendous competitive advantage by deploying data-centric storage. Organizations generate large volumes of data, the vast majority of which is unstructured. As the volume and velocity of this unstructured data increases, the costs, risks and usability challenges associated with managing the unstructured data (regardless of file type, size or device) increases simultaneously, including end-to-...
The 5th International DevOps Summit, co-located with 17th International Cloud Expo – being held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the...
The 17th International Cloud Expo has announced that its Call for Papers is open. 17th International Cloud Expo, to be held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, APM, APIs, Microservices, Security, Big Data, Internet of Things, DevOps and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding bu...
Cloud services are the newest tool in the arsenal of IT products in the market today. These cloud services integrate process and tools. In order to use these products effectively, organizations must have a good understanding of themselves and their business requirements. In his session at 15th Cloud Expo, Brian Lewis, Principal Architect at Verizon Cloud, outlined key areas of organizational focus, and how to formalize an actionable plan when migrating applications and internal services to the ...
Most companies hope for rapid growth so it's important to invest in scalable core technologies that won't demand a complete overhaul when a business goes through a growth spurt. Cloud technology enables previously difficult-to-scale solutions like phone, network infrastructure or billing systems to automatically scale based on demand. For example, with a virtual PBX service, a single-user cloud phone service can easily transition into an advanced VoIP system that supports hundreds of phones and ...