Uphold - March 2024

Page 1

Uphold: Facilitating a Future of Financial Inclusion

IN ASSOCIATION WITH:

DIGITAL REPORT 2024

UPHOLD: FACILITATING A FUTURE OF FINANCIAL INCLUSION

INCLUSION fintechmagazine.com 3 UPHOLD

Christopher Adjei-Ampofo, CIO & CISO at Uphold, details how the firm is keeping customers safe while offering an ‘anything-to-anything’ trading experience

Launched in 2015, Uphold offers financial services to the global market and has grown to become a world-renowned force, serving 140 countries and offering more than 280 assets on its Web 3 platform.

It would not be an exaggeration to say Uphold is one of the very first to offer a true ‘anything-to-anything’ trading experience, enabling customers to trade directly between asset classes and facilitating a future of financial inclusion.

Ultimately, the firm is providing the infrastructure – licensing, control framework and information security compliance –for anybody building on a blockchain to access the wide range of digital assets being made available.

But in an increasingly saturated market, what exactly makes Uphold unique and able to stay ahead of the competition?

“We have a high-frequency trading engine that sits on top of the connectivity that we have with the 30 underlying exchanges we operate with,” explains Christopher AdjeiAmpofo, who works in a dual role as CIO and CISO at Uphold.

“This allows us to poll the market for the best prices, and institutional customers can move their positions in and out of the market with minimal price slippage. And, because we’re able to source from the cheapest venues, we can offer that to our customers and give them the best price on the retail side.”

4 March 2024 UPHOLD
fintechmagazine.com 5
Christopher Adjei-Ampofo, CIO & CISO at Uphold

Uphold: Meeting its customers’ needs

Like all competently-run organisations, Uphold can boast a portfolio of key aims, strategies and capabilities stretching right across the business.

On the retail side of the operation, the priority is to provide a crypto-enable bank account that anticipates the wants and needs of Gen Z and alike, such as the transfer of ownership of assets using NFTs, or instant access to decentralised apps (DApps) on the blockchain, offering yields and borrowing capabilities.

Uphold’s enterprise app, meanwhile, allows companies building on blockchains to plug into its bank connectivity, thus enabling them to move fiat currency. Customers are given instant ability to buy crypto assets using a credit or debit card, as well as take part in projects on the blockchain in a non-custodial manner.

“What we also have is our vault noncustodial product,” Adjei-Ampofo continues, “which offers the best of both worlds.

“So, you can have your non-custodial, but, in the event of you losing your private keys, we can help you restore that in a safe way without compromising any security concerns.”

What’s more, Uphold’s institutional app is allowing the very largest of institutions to purchase significant quantities of crypto assets, Bitcoin or Ethereum, without impacting the market price.

Adjei-Ampofo adds: “We do that by distributing the order across 30 different fs, providing the best-possible price.”

Also of note is Uphold’s white label service, giving traditional banks or fintechs the means to use its crypto services without having to worry about using its wallet or KYC requirements, instead plugging in their own interface.

“We source from many venues so we can offer customers the best price”

Staying ahead of cyber challenges

Keeping abreast of the cybersecurity landscape is, comfortably, one of the biggest challenges facing Adjei-Ampofo in his role as CISO.

The rapid, and some may say astonishing, rise of generative AI over the past year or so has only served to exacerbate the situation, leaving leadership teams facing an uphill struggle to stay at least one step ahead of cyber criminals and modern-day threats.

“We’ve already seen forces using AI and deepfake to fight against us, to try and compromise our systems – and the technology can only get better,” says Adjei-Ampofo.

“Making sure we’re prepared and getting better at protecting ourselves is what’s keeping me awake at night.”

Ultimately, social engineering – which Gen AI is contributing to and, in many cases, enhancing – perhaps remains the biggest cyber threat facing Uphold.

The business and its experts can work round the clock to protect customers within its ecosystem but, ultimately, the prospect of account takeover (ATO) can never be fully eradicated.

6 March 2024 UPHOLD

CHRISTOPHER ADJEI-AMPOFO

TITLE: CIO/CISO

COMPANY: UPHOLD

An IT leader and entrepreneur with over 20 years of experience in steering transformative initiatives, orchestrating technological advancements, and spearheading successful projects across global organisations.

Acknowledged as one of Computing Magazine’s Top 100 UK IT Leaders, showcasing a consistent track record of achieving multi-milliondollar savings while implementing cybersecurity frameworks in

compliance with industry standards including NIST, SOC2, ISO 27001, and GDPR.

Career Highlights

• Led transformative initiatives resulting in over $3M in operational savings.

• Responsible for safeguarding assets exceeding $2B.

• Founded Knowledgewire Systems, a software company specialising in FX trading systems, acquired by Caxton in 2011.

burdensome, but instead part of your daily routine”

“Once malicious forces socially engineer our customers and they become very trustworthy, our customers may hand over the keys to their accounts – in other words, account takeover,” outlines Adjei-Ampofo.

“There is this term ‘pig butchering’, where cyber criminals are constantly feeding the customer information to build that trust to the point where they hand over those assets.

“It’s very difficult to monitor, but we’ve done a good job to bring it down with the tools we have. So, when you log into our

platform we know where you’re coming from and who you are from slight changes in the way our system is being used.”

Then there is the prospect of managing insider threats.

Adjei-Ampofo goes on to explain that Uphold’s front door is “pretty much secure” from a security perspective, without ever being able to truly guarantee 100% security.

The people with the “golden keys” in this scenario are Uphold’s own employees, which presents the firm’s cyber experts with a delicate balancing act.

Adjei-Ampofo adds: “The balance of making sure you allow employees to freely operate and do their jobs, while protecting the company, is a challenge, because one careless mistake could really have detrimental effects and compromise all your front-door controls.”

fintechmagazine.com 9 UPHOLD

Uphold: Facilitating a Future of Financial Inclusion

“The balance of making sure you allow employees to freely operate, while protecting the company, is a challenge”
CHRISTOPHER ADJEI-AMPOFO CIO/CISO, UPHOLD

Increasing cybersecurity awareness

Adjei-Ampofo and his team spent much of last year focused on protecting Uphold’s external perimeter, before shifting their attention to these aforementioned insider threats.

It is paramount, from their perspective, to ensure cybersecurity awareness stays top of mind for every member of the workforce, regardless of their department.

The CISO considers this to be an ongoing campaign and believes it is beginning to bear fruit.

“Now, when they receive that fake email, immediately they question it,” says AdjeiAmpofo, with discernible pride in his voice.

“That’s as a result of a really robust security awareness training programme.

WATCH NOW
10 March 2024 UPHOLD

“We’ll give you training that’s relevant and make it fun, rather than just seeming like noise. It’s not a case of security being burdensome, but instead part of your daily routine. And that’s the message that resonates across the whole company.”

When it comes to measuring progress in this space, the numbers cited by AdjeiAmpofo do most of the talking.

Prior to the recent period of dedicated cybersecurity education, Uphold was dealing with more than 30 cases of employees clicking on malicious links. Now, that figure has been reduced to just a handful.

“One person can still cause problems,” highlights Adjei-Ampofo. “So, although you might have protections in place, education should be top of mind.”

Addressing the skills shortage

The digital skills gap has been well documented over the past couple of years, with companies big and small clamouring for talent and bemoaning their inability to fill crucial positions.

Uphold is among those to fall victim to this crisis – which is far from an exaggeration because, to many organisations, not having the people required to function effectively does indeed represent a crisis.

Shedding light on these struggles, AdjeiAmpofo says: “We’ve been trying to find people in various specific roles for quite a while.

“A good example: we found someone, gave them an offer and, five days before they were supposed to start, they got poached by a competitor. It’s something we see all the time.”

fintechmagazine.com 11

CUSTOMERS RELY ON BANKS. BANKS RELY ON POSTGRES.

Avoid revenue loss from database outages. Keep mission-critical apps running smoothly with Postgres, the most admired and desired database.

Learn why

As a consequence, Uphold approaches recruitment differently, emphasising its core values, long-term strategy and the prospect of becoming part of a family.

“That goes a long way because, when you need us or have personal issues, we’re there to support you,” adds Adjei-Ampofo.

“This has been our focus and it’s starting to work.”

Partnerships critical to success

No high-performing company – regardless of its capabilities – can function to its full potential without forming fruitful partnerships.

140+

Number of countries served by Uphold

High-frequency trading engine that sits on top of the connectivity to 30 liquidity venues

Licensed in the U.S. (FinCEN, 45 MTLs), U.K. (FCA CryptoAsset Firm & EMI), and Europe with security certifications PCI DSS Level 1, ISO 27001 and SOC 2.

fintechmagazine.com 13 UPHOLD

The success of a fast growing company is only possible with a strong ecosystem of critical partners to deliver core services, protect customers, and support growth.

CloudZone is Uphold’s authorised AWS partner providing outsourced managed services to complement Uphold’s internal infrastructure team responsible for the infrastructure environment hosting critical assets and services.

Cloudzone also provides FinOps services continuously identifying areas of potential savings by highlighting incorrectly configured resources, unused assets and eliminating wastefulness.

“Regular check-in’s with CloudZone ensures we stay abreast of technological changes, and it’s great how they’ve integrated themselves into the fabric of the company,” Adjei-Ampofo explains. “They’ve become an extension of our infrastructure team.”

Uphold’s collaboration with Plaid, an ACH banking rails provider, allows US customers to seamlessly deposit money via ACH to buy crypto assets.

Uphold implemented Signal, an ACH risk assessment and scoring service to reduce first-party ACH fraud, where customers would abuse the consumer protections offered by the ACH framework to commit first-party fraud also known as buyer’s remorse, claim chargeback and deny authorisation of the transfer of money to purchase the crypto assets.

14 March 2024 UPHOLD
fintechmagazine.com 15

Signal has been instrumental in the reduction of ACH fraud by providing a detailed analysis of customers financial profile to allow us to confidently manage risk, improve transaction success, and reduce fraud.

It would be remiss of Adjei-Ampofo not to mention Sift Science, a Machine Learning (ML) fraud detection and prevention tool which sits at Uphold’s front door of the online platform and

helps the firm to protect customers from Account Take Over (ATO) and payment protection.

He continues: “Using a whole raft of attributes about the customer’s transaction and behavioural analytics, we’re able to determine if the transaction is legitimate or suspicious and take action immediately.

“That’s been transformational in the way we manage fraud, and protect our customers and assets.”

fintechmagazine.com 17 UPHOLD
already seen
AI and Fighting fraud is hard. Getting the right benchmarks Introducing FIBR, the Fraud Industry Benchmarking Resource, powered by Sift. Access key fraud metrics across industries, geographies, and time. Always on. Always free. Explore the benchmarks for your business shouldn’t be. 18 March 2024 UPHOLD
“We’ve
forces using

Finally, there’s EDB, Uphold’s critical database provider of critical high availability database service and 24x7x365 remote DBA support.

“The services offered by EDB removes the burdensome tasks of continuous critical patch and capacity management, ensuring our resources can scale as the business grows, protecting our critical assets from

vulnerabilities and threats, and the comfort of knowing we have experienced DBA’s readily available.” Adjei-Ampofo concludes. “They’re another great partner within our ecosystem supporting our growth and services we provide.”

fintechmagazine.com 19
www.uphold.com
Uphold POWERED BY:
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.