Skip to main content

Limit fraud and keep customers happy with context-based authentication

Share

To keep up with continually evolving account takeover (ATO) and card-not-present (CNP) fraud attacks, many financial institutions (FIs) seek new security solutions to patch over each new threat.

Fortunately, there is an alternative approach for FIs that can span across multiple channels and considers the context of each digital banking and payment interaction. Context-based, or context-aware, authentication considers the originating channel, transaction context, available authentication options and customer preference to determine the most appropriate authentication option.

Every day, FIs and their customers are bombarded by threats to their hard-earned assets. To protect their customers, FIs need the ability to determine friend from foe in real time, while still offering a customer experience that supports, rather than disrupts, their banking and payment journeys. Shifting to a more holistic authentication approach may be the answer.

Per Gartner: “Most banks have multiple fraud detection platforms, typically deployed at the banking product level (e.g., debit cards, wire transfers, digital banking channels), resulting in gaps between silos open to exploitation by fraudsters.” By unifying banking services on a central platform, banks and credit unions can cover any gaps in security, plus fast-forward their digital transformation journeys, by offering a customer experience that helps them remain competitive.

For issuers in particular, this would also translate into fewer false declines, fewer chargebacks, less first-party fraud and increased transaction success rates.

Moving beyond the legacy backstory

While there may be departments or teams that champion modern security and fraud prevention solutions, the reality is that the old ways are often entrenched by technological limitations. Another remnant from this era is the belief that fraud prevention and security are two separate challenges, with separate budgets and defense mechanisms.

Unfortunately, this fragmented approach can prevent cross-communication and data sharing between these systems. However, FIs have not been sitting on their hands as fraudsters dream up new attacks. In many cases, their defense strategy started with building a platform to support one-time password (OTP) technology.

Then, as digital banking fraud evolved, fraud prevention technology evolved too. And as FIs came across the need and budget, they added security measures to their banking platform—but not necessarily from the same vendors or with the same functionality. Yet, by blocking security gaps one by one as they pop up, the systems tasked with security and fraud prevention don’t necessarily work together or share intelligence, nor can they offer sufficient resistance to today’s advanced fraud schemes. “94% of Fls have recently or are planning to make changes to their authentication method. Fls are realizing the heightened susceptibility of OTP interception via text and email,” reports Datos Insights, 2023.

What’s more, fraudsters now leverage powerful technologies like AI to create compound attacks that can easily penetrate a bank’s legacy platform. They deploy multiple attack vectors in a single attack, rendering “legacy spaghetti” ostensibly useless as a defense.

Current trends in unifying digital banking services

An industry shift is underway to unify digital banking services, so banks remain competitive and customer-centric. This concept of unification encompasses the entire user experience. It’s about recognizing the customer and delivering contextual information or services based on what may already be known about them as a valued customer in other channels, and giving them a significantly more consistent, streamlined and personalized experience—one they’ll remember for the right reasons.

“By 2025, 50% of new fraud detection solutions for banking will be customer-centric platforms deployed across products and channels, replacing multiple siloed solutions, for better customer experience and fraud detection,” as Netecea reports. By unifying banking services on a strategic central platform, FIs can scale quickly to adopt new solutions that shield against today’s fraud schemes while proactively adapting to future needs. The bottom line—they’ll have the tools to continually improve the customer experience and remain competitive, even with emerging neobanks and other challengers at their heels.

Close security gaps with cross-channel authentication

According to a report by Datos Insights, CNP fraud losses are predicted to reach approximately $13 billion by 2026. And while closing security gaps can feel like an infinite cycle, cross-channel fraud prevention is the only way to safeguard FIs and their customers from these losses.

When a fraudster steals credentials, they will try every channel in real time to find the right one—the one that fails to detect them. When authentication is managed in silos, with a different provider for each channel, the opportunity to share risk signals across channels that would otherwise block the fraudster’s incursion is lost. For instance, when a hacker is blocked from four channels, but the fifth fails because it was not alerted to the risk detected in the other channels, they get in. In that moment, an FI has not only failed their customer, but likely also lost that customer.

By implementing a cross-channel authentication strategy, FIs can save on the cost of fraud, prevent breaks in customer trust and prevent the risk of losing top-of-wallet status.

Context-based authentication helps identify real customers

Customers want to be assured that their online transactions and payments are secure. A unified, or context-based, authentication strategy covers all of an FI’s customer engagement channels and shares context about each transaction, like the user’s device, location and behavioral biometrics between the channels. As a result, it silently recognizes the real customers without disrupting their transactions.

It also immediately spots higher-risk activity and steps up authentication measures or blocks the transaction, using the same risk signals, like biometrics or payment behavior, to quickly determine friend from foe. With this unified approach to fraud prevention, FIs can recognize their customers across all channels—from online, mobile, call center and branch, to 3-D secure card authorization—reducing both fraud and friction. Ultimately, a unified fraud prevention strategy brings together the right resources to effectively fight ATO and CNP fraud, reduce false declines and chargebacks and ensure customers remain their FIs’ biggest fans.

Dewald Nolte is Co-founder and Chief Strategy Officer for Entersekt.

A version of this article appeared in the January BAI Executive Report “Safeguarding Against Fraud.” Read more on fraud-prevention best practices there.

Related Articles

Login to View This Content

 

Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.