Apr 15th, 2020

Work From Home Hangover, Finastra Fallout, Is Covid The Contactless Catalyst

TL;DR

In the first episode of Cents Chat, Jason and Hayden discuss how the early COVID environment stress-tested the payments ecosystem. They cover why business continuity planning cannot stop at technology, how the Finastra incident exposed the risk of relying on critical vendors without real contingency plans, and why the pandemic may have finally pushed contactless payments and direct deposit into broader adoption.

Payments Got a Stress Test

The first episode of Cents Chat dropped in April 2020, right when the payments industry was getting shoved into a real-world stress test.

Companies were rushing into remote work. Customer service teams were buried. Security programs were being tested outside the comfort of office networks. And payment habits that once felt normal — cash, checks, physical cards, PIN pads — suddenly felt a little less appealing.

Jason and Hayden opened the show by looking at three early pandemic pressure points: the work-from-home hangover, the Finastra security fallout, and whether COVID-19 would finally push contactless payments into the mainstream.

Remote Work Exposed the Gaps

The work-from-home problem was not just about laptops and video calls. It was about whether companies had continuity plans that covered the actual business, not just the technology stack.

Hayden shared a simple example: trying to cancel a gym membership and getting stuck on hold for far longer than normal. Jason used that as the bigger point. A lot of businesses had business continuity and disaster recovery plans, but many were focused on systems while leaving out customer service, HR, training, and other people-driven workflows.

That gap matters. When teams are suddenly remote, under pressure, and working outside normal routines, security awareness becomes more than a compliance checkbox. Spoofed emails, rushed approvals, and weak processes can turn into real financial exposure.

Jason’s advice was practical: make security awareness a real priority, test continuity plans with realistic scenarios, and use automation to reduce pressure on human support teams when volume spikes.

Finastra Showed Why Vendor Risk Matters

The Finastra incident added another layer to the conversation. During an already chaotic period, a major financial services software provider experienced a security event that disrupted critical services for financial institutions.

The lesson was not just “vendors can get hacked.” Everyone knows that. The real lesson was that critical vendor risk cannot be handled as a once-a-year documentation exercise.

Jason pushed for deeper vendor conversations around business continuity, disaster recovery, and process redundancy. A PCI attestation or SOC report may check a box, but it does not answer the question that matters in a crisis: what happens if this vendor cannot perform when the business needs them most?

Contactless Finally Had a Reason

The final topic was contactless payments. Before COVID, many consumers did not feel much urgency to change behavior. Cards worked. Cash worked. Checks still existed, whether anyone liked it or not.

The pandemic changed the context. Suddenly, contactless was not just a feature. It solved an immediate problem: people wanted to touch fewer things.

Jason also pointed to direct deposit and ACH growth, especially with stimulus payments and closed branches pushing more people away from paper checks.

The big takeaway was simple: resilience is not a checkbox. Payments companies need continuity plans that include people, vendors, processes, and customer behavior. COVID did not create every weakness in the ecosystem, but it made them much harder to ignore.

Featuring
  • Jason
    The Nerd
  • Hayden
    Guest Speaker
    Transcript

    Hayden: Jason, you and I have been discussing the possibility of a podcast for some time, but why now?

    Jason: Hayden, it is actually twofold. First, a lot of people we talk to are asking the same questions in the payments industry, and I felt like a podcast was a great way to share that information more broadly. Second, my already limited social life has become basically nonexistent with the coronavirus, so I find myself with extra time on my hands.

    Hayden: There you go. Speaking of the coronavirus, we are practicing our social distancing by sitting on opposite ends of the studio just to be safe. Anyways, a little bit about me: I am a finance major in my sophomore year, so my knowledge of payments is pretty minimal. That is why Jason is going to be the brain, and I am going to be the pretty face behind the mic. Jason, why do you not tell us a little bit about your background in the payments industry?

    Jason: Hayden, I think we are ultimately going to have to let our listeners vote on who has the pretty face, but I will certainly take the title of the brain. My payments experience is a little bit unique in that I have had the opportunity to play in just about every aspect of the supply chain. I started with a cloud-based point-of-sale platform. We were an ISV, and I ultimately ended up serving as the chief technology officer of an acquirer, where I was responsible for building out a full acquiring and ACH platform. In more recent years, I have consulted for acquiring banks that either had their own acquiring program or wanted to launch one and needed help and guidance setting it up, building it, staying compliant, and attracting the right payment partners.

    Hayden: Well, Jason, I know we are going to enjoy this, but what do you hope our listeners get from this podcast series?

    Jason: I think the biggest thing is that unless you are constantly surrounded by payments developments and technology updates, it is very easy to fall behind. Payments is a vast category that covers everything from technology to security, compliance, risk, and probably my favorite topic, innovation. This is a great medium to discuss exciting things happening in the payments ecosystem and spread that information more broadly.

    Hayden: Awesome. Let us dig into our topics.

    Jason: Let us do it.

    Hayden: Our first topic is the work-from-home hangover. Before you jump to any conclusions, this has absolutely nothing to do with drinking on the job.

    Jason: Next, we will discuss the impact of the Finastra fallout. For those not familiar with Finastra, it is not a nuclear power plant. Finally, is COVID the catalyst that contactless payments has been waiting for? Hayden, after weeks of being stuck at home, I am sure you are excited to be back in the office and get some time away from your significant other.

    Hayden: Yeah, I am super excited to get out of the house. Although our transition to a work-from-home environment was very seamless, it seems like many companies struggled with the transition, especially their customer service departments. I was on hold for over an hour with my gym just to cancel my membership. Normally, this is a ten-minute interaction that ended up being a two-hour waiting game.

    Jason: Fortunately, a gym membership was one thing I did not have to worry about. I do not know how long it has been since I have been to the gym. But it is a common theme, and I think it is very evident which companies actually spent time on their business continuity and disaster recovery plans versus those that treated them as a formality. So many companies I have reviewed as part of PCI readiness assessments have business continuity and disaster recovery policies that are focused on the technological aspects of the business and miss key functions like customer service and HR.

    Hayden: Why do you think these companies leave critical business functions out of their continuity and disaster recovery plans?

    Jason: I think a lot of it has to do with security. Technical staff are generally well versed in security awareness and data security, while customer service teams tend to be lacking.

    Hayden: I know PCI compliance requires security awareness training, but it seems like many organizations were scrambling to implement those protocols when this hit.

    Jason: I think a lot of that is because many businesses look at security awareness training as a PCI requirement and more of a formality. They have to do it to be compliant, but the level of effort that actually goes into training non-technical staff in security precautions is minimal. I think this is the outcome. Barbara Corcoran, one of my favorite sharks on Shark Tank, had someone hijack her email shortly after this happened. A spoofed email was sent to her assistant, and it ultimately ended with $400,000 being wired out for a fake invoice. Security awareness needs to be a priority and less of a formality.

    Hayden: In your professional opinion, how can the payment supply chain be better prepared for the unknown in the future?

    Jason: I think it comes down to three things. First, somebody in the organization has to have a strong security awareness mindset. They have to be passionate about it. If you are passionate about security and doing things the right way, it is easier to build programs and deploy them throughout the company. Second, on top of having the program, it is important to test these programs. Take your business continuity plans and your security awareness plans and actually test them with mock scenarios. What is the organization going to do in the case of an earthquake, fire, pandemic, or some other scenario? Make sure the protocols in place are sufficient during a disaster. Lastly, automation. A lot of companies struggling with migration to work from home would have benefited from better automation. For example, with your gym, if you could have gone online and suspended your membership for ninety days, it would have led to much better customer satisfaction and minimal impact to the business and its customers.

    Hayden: It looks like Finastra could have used this advice when it comes to data security and minimizing impact.

    Jason: No kidding. You want to talk about the perfect storm. Here we are in the middle of a global pandemic, and London-based Finastra, the world’s third-largest financial services software provider, gets hacked. The impact was extraordinary. We do not know exactly what happened. There were rumors that it was a ransomware attack. But the point is that countless financial institutions around the world could not process customers’ wire transfers and ACH transfers. The fallout for banks that did not have contingency plans in place was that they were left scrambling to find a backup solution in an already chaotic environment.

    Hayden: How could banks be better prepared for such a critical vendor being offline for an extended period of time?

    Jason: I think it is a twofold answer. First, banks and the payment supply chain in general have to get better at asking tough questions. We have migrated to a climate where, just because somebody has a PCI attestation of compliance or a SOC audit, it checks all the boxes from a critical vendor perspective. The reality is that if you are evaluating a vendor that is going to be critical to your operations, you need to dig deeper. It needs to be more than once a year getting their updated documentation. Have conversations with them about what their business continuity plans and disaster recovery strategies look like. How are they going to ensure continued operations in a crisis? Those dialogues are missing. Second, regardless of how much faith you put in a critical vendor, you have to have process redundancy. There has to be a ready-to-go process so that, if the unimaginable happens, your company does not suffer and you can continue to operate and provide services to your customers.

    Hayden: You sound like you do not have any confidence that anything or anyone is safe.

    Jason: Hayden, I think that is the point of this discussion. That is the mindset you have to have if you are really going to be prepared for worst-case scenarios. If you are not planning for the worst and analyzing the impact to your business when those worst-case scenarios could happen, you are leaving gaps in your strategies and setting yourself up for disaster. Critical vendors are just that.

    Hayden: Jason, speaking of high touch, let us talk about something nobody currently wants to touch, and that is cash, checks, and cards.

    Jason: Hayden, I will be more than glad to take any cash you do not want to touch off your hands. But in all seriousness, it is really interesting. I have never seen more contactless payments happening than I have in the last few weeks. Every time I have gone out to grab groceries or food, people in line at grocery stores and pharmacies are using contactless forms of payment. It has been interesting. I think this could be the start of the transition to us actually being a cashless society.

    Hayden: Direct deposit seems more important than ever, with so many bank branches closed and people working from home.

    Jason: Absolutely. I think direct deposit is massively on the rise, especially with everybody working from home. Do not forget, a vast majority of the stimulus payments are going out by direct deposit. Looking at Nacha’s recently released first-quarter results, there was a 7.1% increase, with more than 6.4 billion items processed through the ACH network, and a 42% increase in same-day ACH payments. I think a lot of that has to do with the cap on same-day ACH being increased to $100,000. A lot of people are saying those numbers are going to go down in the second quarter. I think that, with stimulus payments and the fact that nobody is getting or wants to get a paper check anymore, those numbers are actually going to skyrocket.

    Hayden: Do you honestly believe COVID is going to be the catalyst contactless payments needed in the United States?

    Jason: I actually do. The big problem with contactless payments up until this point is that there has not been a need for it. I have always had the philosophy that if it is not broken, do not fix it. I do not know about you, but my credit card always swiped fine everywhere I went.

    Hayden: I agree with you there, Jason.

    Jason: Until there is an actual need for change and an opportunity to retrain customers, the vast majority of the population is not going to be made up of early adopters who just migrate to contactless. But I am seeing more and more contactless payments every time I leave the house, and I think that trend is going to continue. With the current pandemic, this is a valuable opportunity to retrain consumer behavior. I think people are going to get more comfortable with contactless, more people are setting up contactless payments on smart-enabled devices, and this is going to be the tipping point.

    Hayden: I am really excited to see Apple and Google’s updated contactless payment solution statistics in the coming months. All right, Jason, it is time to make payments make sense. Give me the takeaways.

    Jason: First, do not treat business continuity and disaster recovery as a formality. Embrace it. Banks, you need to inspect what you expect from your critical vendors. Lastly, if your payment solutions are not contactless-enabled, use this time to fix that.

    Hayden: Thanks for joining us today. If you have a topic you would like us to discuss, follow and message us on social media at Cents Chat. As always, we would love your feedback. Hayden out.