Financial institutions face escalating cybercrime and mounting regulatory pressure, with bank executives ranking cybercrime as a top concern and attacks expanding from phishing and malware to insider fraud, transaction skimming, account takeover, and new account fraud. Incidents affecting millions of consumers continue to be reported, and attackers are increasingly sophisticated, sometimes using DDoS as a smokescreen and leveraging spear-phishing and malware (botnets, rootkits, keyloggers) to seize control of accounts. Account takeovers surged sharply in 2017, producing multi-billion-dollar losses, and are frequently enabled by weak authentication practices that still persist in digital banking.
Regulatory regimes are simultaneously reshaping security requirements. Global AML and KYC obligations drive the need for stronger consumer identity controls, while GDPR governs personal data usage in the EU. New York’s 23 NYCRR 500 mandates comprehensive cybersecurity programs and requires MFA and risk-based authentication for external-to-internal access, alongside governance measures such as CISOs, testing, incident response, encryption, and rapid (72-hour) reporting. In Europe, PSD2 and its RTS deadlines require Strong Customer Authentication (two of three factors) while enabling exceptions through transactional risk analysis, and introduce Third-Party Providers (AISPs and PISPs) that compel banks to expose and secure APIs—expanding competition beyond traditional banking.
Given password and KBA weaknesses, the paper argues for modern MFA and risk-adaptive authentication with behavioral analytics, mobile-first authenticators, and phishing-resistant FIDO approaches. It highlights OneSpan Intelligent Adaptive Authentication as a cloud service (with on-prem alternatives) combining diverse MFA methods, device/application protections, and machine-learning-driven risk scoring across many contextual factors, enabling step-up authentication when policy thresholds are exceeded. The recommended path is to begin with an IAM maturity assessment, identify architectural gaps, and modernize authentication and risk analytics to meet NYCRR/PSD2 while reducing fraud and customer friction.
See All Locations
See All Locations