The President of the card company for Europe speaks to Economedia’s Capital Weekly about the new cyber center in Brussels.
Mark Barnett is the President of Mastercard for Europe and a member of the global card company’s board of directors since 2020, responsible for its market in a total of 53 countries. He has been with Mastercard for 20 years, having held various positions before that. He graduated in Economics from London University and holds an MBA from Imperial College Business School. Mark visited Sofia this summer.
This year you opened your new cybersecurity center in Brussels. What are your plans for it, and why Brussels?
Brussels is our European headquarters, and it was the ideal place for it. The essence of cyber defense and so-called cyber resilience is cooperation – for example, between the private and public sectors. Mastercard cannot solve cybersecurity alone, nor can European governments do it by themselves. Collaboration among a large number of partners is necessary. And that’s where the center plays its role. At the opening, the director of Europol, the person responsible for cybersecurity at NATO, representatives from various state and European law enforcement agencies, and other payment companies were present. This center is the place where different teams can work together. There are currently about 20 different teams there. For example, we have a lab that deals with things like hacking chips.
And that is its goal: to gather different experts and experiences and share them with others. The truth is that we are very good at security within our organization, but we also want to export this expertise to the entire ecosystem – to merchants, to banks, and then to the entire digital economy. It sounds like a huge ambition, but you have to start somewhere. The center employs really high technology. We have a large screen that shows and monitors the entire Mastercard network, where abuse can be tracked in real-time.
Every year we participate in a NATO exercise, which is a kind of simulation of an attack by malicious actors, where they try to breach various military installations of the alliance. And only if we all cooperate in this way can we prepare for real attacks.
Do you think cyberattacks are the biggest threat to your industry?
In a world that is becoming increasingly digital, opportunities for cybercriminals are also growing. This means that we, all participants in this ecosystem, must become even better at defending against these criminals. And if we work together, we will be able to respond appropriately.
Where do you see this center in the future in terms of team and capabilities?
As I said, we have about 20 different teams there. One of them deals with scanning the cyber footprint of various organizations and companies. They can look at your web page and immediately tell you where the biggest vulnerabilities are. Another team deals with predicting future threats – what they will be in three, four, five years. These teams usually do not talk to each other, but now we connect them and will gradually include other specialists as well. Here is also our crisis and incident response unit. So, if there are future incidents, everyone is in one place and ready to respond. So, I see this center as uniting teams and organizations that think about the future of cyberspace and also work on future cybersecurity solutions.
So, if some cyber threat occurs in Bulgaria, for example, will it be the task of this European center to analyze and respond?
Cybersecurity is a global task, and we have teams worldwide, but yes, the initial response will be from this European center.
How prepared do you think countries like Bulgaria are for such cyber threats?
We recently conducted a study for Bulgaria. What I can tell you is that usually, the smaller the business, the less prepared it is for potential attacks. And vice versa – the larger the organizations, the better protected they are. We do not observe significant regional variations.
What role does the much-talked-about artificial intelligence play in this conversation?
At Mastercard, we have been using AI and machine learning for years, primarily to detect fraud. Last year, about 143 billion transactions were processed by Mastercard. Each of them has a so-called fraud score. Years ago, it was about tracking certain criteria and rules: if Mark buys an electrical appliance from Glasgow, it’s unusual behavior. Or if he makes a transaction in Sofia and ten seconds later another in Paris, it is most likely a fake card. We conducted SAS analyses to monitor all these things. Then we acquired the company Brighterion, which deals with machine learning. And they came up with even more sophisticated criteria and rules for detecting fraud. Later, we started using generative AI. This adds another layer and level of predictability for what might happen next with the fraud. We work very hard on artificial intelligence both in cyber defense and in other areas, such as increasing productivity or interacting with customers.
Where do you see the payments industry in a few years in terms of technology and players?
The major trend we have observed over the past five to ten years is tokenization. When I started in the industry, we worked with the so-called zip-zap machine. Then each transaction was approved by the authorization center, followed by the magnetic stripe, chip and pin, and contactless payment. This led to tokenization on your smartphone. And in Europe, over 80% of all transactions are contactless.
When you use your phone to make a payment, you don’t do it with your card number but with a token. This means that the card cannot be hacked. So, tokenization is a big trend that will continue. At some point, everything will be tokenized, for example, managing your subscriptions is much easier, you don’t need to change your card, etc. You will register once and pay much more easily with every merchant. This applies to the consumer side. As for the commercial side, many changes are also happening there. In my opinion, the biggest is what we call Tap-on-Phone – in the near future, every phone in the world will be able to accept payments. This means that you will be able to make payments from person to person easily, and merchants will accept digital payments without any problems.
At the same time, with the development of fintech companies, we see more and more payment intermediaries and players in this segment, improving the experience for both consumers and merchants.
It is clear that over time, most payments will be digital, easy, and super secure for everyone – both consumers and merchants. In this part of the world, there is more cash. We have nothing against cash – if people want to pay in cash, let them do it. But due to convenience, comfort, and security, more and more people choose to pay with cards, phones, or whatever is more convenient for them.