/security

News and resources on cyber and physical threats to banks and fintechs worldwide.

Entering the OTD era: Why Originate-To-Distribute Models are key to Portfolio DiversificationFinextra Promoted[Webinar] Entering the OTD era: Why Originate-To-Distribute Models are key to Portfolio Diversification

Join the Community

Learn, share and discuss the latest banking, payments and fintech innovations with the world’s largest fintech community.

Access unique research, content, and real-time alerts, services – free to registered members.

43,762 Members   23,201 Expert opinions

Join the community Sign in

284Reports  275Webinars

Find out more

/security

Expert opinions

Roy Zur

Roy Zur CEO at Charm Security

Training AI Agents Like Behavioral Scientists to Excel at Preventing Scams and Fraud

As scams become more advanced and personalized, the tactics used to manipulate individuals are increasingly rooted in behavioral psychology. What once required blunt deception now relies on nuance: fraudsters exploit victims' fears, biases, and emotional vulnerabilities with surgical precision. With fraudsters now equipped with generative AI tool...

/security /crime Banking Strategy, Digital and Transformation

John Reese

John Reese Business Analyst | Platform Growth Expert at Hashcodex

What Security Measures Should MT5 CRM Systems Implement?

Imagine waking up one day and realizing your entire brokerage platform has been hacked. Client data? Gone. Trust? Broken. That’s the nightmare no broker wants. Having even one small loophole in your CRM can be extremely dangerous in today's world. If you’re reading this, maybe you are planning to build or upgrade your CRM that integrates with MT5. ...

/security /markets Financial Risk Management

Steve Carpenter

Steve Carpenter Chief Operating Officer of North America at Creditsafe

Act Now or Pay Later: Why Anti-Fraud Training Is Your Best Line of Defense

Fraudsters are more creative than ever, and businesses are paying the price. With 41% of companies facing 7 or more fraud cases in just the first eight months of 2024 alone, the question isn't if your organization will be targeted—it's when. Yet, despite this growing threat, many organizations remain unprepared, relying on outdated or insufficient...

/security /crime

Frank Moreno

Frank Moreno CMO at Entersekt

Banks still unnecessarily burdened by porous security

Banks have invested heavily in fraud prevention over the past five years. However there are still some glaring gaps (as well as some hidden risks) that have yet to be addressed. And, if these are not remedied in 2025, threat actors will exploit them – at massive cost to the financial institutions (FIs) and their customers. GenAI gets smarter and ...

/security /retail Artificial Intelligence and Financial Services

Prashant Bansal

Prashant Bansal Sr. Principal Consultant at Oracle

Resilience at Scale: Understanding and Implementing the Circuit Breaker Pattern in Microservices

Resilience at Scale: Understanding and Implementing the Circuit Breaker Pattern in Microservices In the evolving landscape of financial services, where milliseconds matter and system reliability is non-negotiable, modern software architecture must accommodate resilience by design. Distributed systems—particularly those employing microservices—are i...

/security /inclusion Banking Strategy, Digital and Transformation

/security

Research

Impact Study

Why DevSecOps is key to navigating innovation and compliance

Explore how DevSecOps enable organisations to navigate economic uncertainties while treating innovation and compliance as complementary forces rather than competing priorities. A balancing act is underway within the financial services industry. Driven by client demand and fintech competition, institutions are increasingly obliged to innovate, while at the same time, ensure every step forward is secure and compliant. Often, it feels as though these two goals sit on either side of a seesaw – when one goes up, the other must go down. Many such challenges are born from the software delivery process, where countless organisations are struggling to source the expertise and capabilities necessary to deliver secure and compliant applications, at speed.  Much of the conflict stems from fragmented DevSecOps (a software development practice that integrates security throughout the development lifecycle) strategies which are built upon outdated infrastructure. Indeed, many financial institutions (FIs) today operate with disjointed security and development workflows – sometimes patching together between five to 10 separate tools that were implemented incrementally over time. While this approach worked five years ago, better options exist today. A simplified stack is conducive to both innovation and compliance – without either being compromised.  This Finextra impact study, produced in association with GitLab, explores:  How the evolution to a unified software delivery platform can deliver on both innovation and compliance;  reduce the risk of security incidents;  supercharge operational efficiencies;  amplify business agility and scalability;  and even support talent acquisition. 

119 downloads

Survey

US Regulation Survey 2025: Compliance at a Crossroads

Assessing financial industry preparedness in a shifting US regulatory landscape as organisations struggle with deadlines, cost, and technology. In an environment of rapidly evolving regulations, driven by legislative and policy shifts at the federal and state levels, the US regulatory landscape is marked by complexity and uncertainty. Understanding the level of preparedness across industries is crucial for ensuring compliance, mitigating risk, and enhancing operational efficiency. This survey was conducted at the beginning of 2025, gathering financial services industry sentiment as the Trump Administration took office and began pivoting on key regulatory elements. With the US financial regulation regime also somewhat in limbo, that uncertainty was – and is – increasingly impacting the views of the 200 organisations surveyed. Analysis of our survey responses provides a comprehensive overview of the state of regulation readiness in the US, differences in reporting obligations, the impacts of automation for compliance, the roles of technology and data, and industry plans for modernisation. We explore: Which regulations will have the biggest impact on US financial services in 2025; Regulatory effects on organisational frameworks, budgets and staffing; How organisations are leveraging technology and partnerships to streamline regulatory compliance.

276 downloads

Event Report

Risk-based authentication: Enhancing security and user experience in fraud prevention

In today’s rapidly evolving digital landscape, the importance of robust cross-channel authentication cannot be overstated. As businesses and consumers increasingly interact across multiple platforms, ensuring secure and seamless authentication processes is paramount.  Online platforms have become integral to modern financial activities, which necessitates secure and seamless transactions, backed up by robust authentication mechanisms. Risk-based authentication offers a dynamic security approach, balancing user convenience with stringent fraud prevention.  The integration of cross-channel data and advanced technologies like machine learning (ML) and artificial intelligence (AI) is vital, as well as access and understanding of data. High-quality data is the cornerstone of effective fraud prevention and detection, which is why organisations must invest in robust data engineering practices to ensure collected data is accurate and well-labelled.  This investment enables the development of sophisticated models to better identify and prevent fraudulent activities. Prioritising data quality enhances fraud prevention strategies, protecting businesses and their customers from potential threats.  So how can organisations holistically address risk-based authentication in a dynamic world? This webinar report summarises the discussion of a Finextra webinar, hosted in association with Mastercard, and explores:  Risk-based authentication in fraud prevention;  Adapting fraud prevention to evolving threats;  Advanced authentication strategies for corporate fraud prevention;  Digital IDs, channels, and exclusion. 

274 downloads

/security

FinextraTV

Verification of Payee Future is Bright, But Must Go Further

Attending the 2025 NextGen Nordics event, Vasile Valcov, Business Development Consultant, Banfico, shared his optimism and passion for the development of VOP and Open Banking. Contextualising the current landscape and positive trajectory, Valcov also explains its challenges and discusses whether it is enough as it currently is.

/security

Long reads

Sehrish Alikhan

Sehrish Alikhan Reporter at Finextra

A crisis of trust: European and global verification brings safety to payments

Verification of Payee (VoP) has rapidly become an essential aspect of banking and payments, ensuring security and safety in payments transactions. By October 2025, all European Payments Service Providers (PSPs) using SEPA instant and non-instant transfers will need to verify payee account details before processing payments. As the EPC’s deadline is...

Scott Hamilton

Scott Hamilton Contributing Editor at Finextra Research

New treasury pro survey shows fraud's penetration into US financial services

There’s hope in them thar hills… or, at least, with some of the responses showing dips among several new peaks in one of the US financial service arena’s largest and longest running annual payments fraud surveys. These insights from treasury colleagues across the country might not be worth their weight in gold. In fact, though the results include m...

Scott Hamilton

Scott Hamilton Contributing Editor at Finextra Research

Where’s the first stop for financial trust? Our guts!

As we outlined in a previous Finextra story, financial services ‘schemers’ and ‘scammers’ can come in many different shades. Indeed, victims of online fraud and illegal schemes lose money every day to not just criminals and nefarious enterprises, but also to supposedly ‘above-board,’ legitimate products and their purveyors. To help avoid non-crim...