Deciphering Multifactor Authentication: Strategies for Banks

Multifactor authentication (MFA) is the talk of the town. The Federal Financial Institutions Examination Council’s (FFIEC’s) guidance has presented financial institutions with a major dilemma – how to effectively deploy and manage one or more electronic banking authentication solutions for multiple customer segments. At first glance, this may seem like a simple project. However, this initiative requires far more than a glance. It is a multi-dimensional effort and a major decision for financial institutions.

Banks Slow to React

Interestingly, the talk has focused on retail online banking due to the sheer volume of customers this would affect. Additionally, retail considerations have thrown banks a curve – certain types of multifactor authentication can damage the customer experience. However, it is important to note that the guidance affects not only retail online banking but all forms of electronic banking across all customer segments. What type of impact does this all have on small businesses? What are banks going to provide to midsize and large corporate clients? Banks have to firm up their decision-making for all customer segments. They need to move forward with effective solutions that will satisfy the FFIEC, preserve the user experience, and provide an additional level of security.

Banks scrambled to put appropriate measures in place to mitigate the risk of electronic banking. Although banks have had since October 2005 to begin working on a response to the FFIEC guidance, many are stuck in a rut and did not meet the end of 2006 deadline. Why did this happen? How can they effectively plan solutions that will satisfy the requirements of retail customers, small businesses, and corporate customers?

In August 2006, Celent published the report, ‘North American Bank Priorities: Convention or Innovation?’ The report examines and analyzes – through the eyes of bank CIOs – bank IT and business priorities. Given the large emphasis placed on IT security, specific questions were directed at banks regarding their security practices. Not surprisingly, when asked to list their top three IT security priorities, 50% of banks mentioned MFA as their top priority. One would assume that such banks would be on top of the situation. Alas, priorities do not always translate into actions, and banks are often slow to respond to evolving marketplaces.

This lack of action is further witnessed when examining actual and planned solution deployment. As of August 2006, only 7% of banks had rolled out MFA solutions geared at small business online customers. This figure was expected to rise to 25% by the end of 2006. Corporate online banking/cash management fared far better with 50% of banks ready with an actual solution. There is, however, a reason that the figures for corporate users are higher than those of small business. Many banks have been supplying devices, such as tokens to corporate cash management users, for some time (used primarily as a form of authentication upon the release of a wire transfer). Given that the infrastructure and interfaces are in place already within the application, it is relatively straightforward for banks to adapt this to the login process. But the fact is that some banks are stuck in the planning and/or decision-making process.

Reasons Behind Confusion

Why has the FFIEC guidance thrown banks into a state of confusion? Why are banks so hesitant about deploying MFA? There are numerous reasons why banks were not able to meet the end of year 2006 deadline and they extend beyond being unable to properly segment their customer base and determine future banking requirements:

  • Banks don’t like ‘guidance’ and deadlines dictated to them. Regulatory requirements and compliance issues are eating up time, funds, and energy at financial institutions. Given the strict guidelines banks are following in a variety of areas, the last thing they want is to have Big Brother guide one of their most profitable businesses. While FFIEC guidance may push banks to speed up delivery of MFA, it also breeds animosity and resistance.
  • Although MFA is an investment in customer protection; it is still a cost, not a revenue opportunity. Security is a top concern for banks, but it is still a cost of doing business. Additional security initiatives represent additional expenses unless they provide a reasonable return on investment. Given that actual online banking fraud losses have been minimal, banks are having a hard time wrapping themselves around the necessity of MFA for all customer segments and profiles. Banks are far more inclined to invest in growth opportunities.
  • Bank IT budgets are tight. Bank CIOs attest to the fact that regulatory requirements and compliance issues are straining their IT budgets. The remaining dollars are distributed among high priority projects that support operations and drive revenues. MFA is yet another project that will tighten the belts of CIOs.
  • Banks are afraid to risk the popular online channel. The online channel has presented a major growth and cost-cutting opportunity to banks over the last several years. Online banking adoption rates have skyrocketed, and banks have enormous fear about the impact that MFA can have on its customer base. The last thing banks want to do is make the online channel cumbersome or difficult to use. This could deter customers from using online banking and thus lower revenues and profitability.
  • If it’s not broken, don’t fix it. Most banks currently handle login authentication with nothing more than a username and password. Customers are used to the process, and it is relatively easy for the bank to support. Banks are terrified of disrupting the user experience associated with this method because they fear customers will defect from the online channel or even the bank. Banks have pushed this to the point where customers are using passwords that are years old, unchanged, for the most part, since the customer signed up for online banking.
  • Banks can’t predict the future. The security solutions that work well today may not be so great months or years from now. Fraudsters stop at nothing. The persistence of these criminals has banks looking into crystal balls to figure out what solution will serve them best down the road.
  • Banks are wary of unforeseen costs. Disrupting the user experience can and will result in increased calls to the call center. Vendors are assuring banks that their solutions will minimize the impact on the call centre; however, banks have to read between the lines and hone in on reality. MFA will increase customer support requirements and banks are struggling to figure out which solutions will minimize the impact.

Moving Forward

Whether they like it or not, banks must overcome their reluctance and see the bigger picture. A single username and 10-year-old password just doesn’t cut it anymore, nor should they. Banks have to accept that now is the time to implement multifactor authentication for all forms of electronic banking across all customer segments. MFA is an investment in customer protection and a cost of doing business for banks.

The overwhelming majority of financial institutions have a varied client base spanning retail, small business, midsize and large corporate clients. Although banks do tend to lean one way or another, they are conscious of being able to accommodate all client types. Additionally, banks that are weak or not focused on a particular segment may want to attack new markets or improve their offering over time. Thus it would be shortsighted, for example, for retail focused banks to select an MFA solution specifically for retail clients and automatically assume that it would serve all customer segments. The same can be said for a wholesale-focused bank that has been using technology tokens for some time and wants to apply them to all parts of its operation, including retail.

There may be a ‘catch-all’ solution, but it requires the bank to start from the ground up and put aside their bias based on what they currently have in place. In fact, certain banks will be able to find a catch-all solution to serve their needs once they go through a detailed risk assessment and vendor evaluation process. The key is not to get hung up on what is already in place at the bank; those trusty tokens, for example, may not be the best long-term solution for the client. The best place to start is at the bottom – knowing who your customers are. Banks need to define customer segments and decide what bucket customers belong in. For instance, how is a small business client defined by the bank?

Choosing a MFA Solution

Banks need to be methodical when selecting an MFA solution. They are presently attempting to determine their present and future MFA requirements before they understand who their customers are and what they require. Unfortunately, due to time constraints, absence of advanced analytical tools, and a lack of dedicated small business banking platforms, most banks are treating MFA as a stand-alone project and are not following an order.

Banks must pay careful attention to the segments they are defining and take care to focus on future banking and customer requirements when selecting an MFA solution. A focus on expendability and flexibility is paramount. The security challenges faced by banks today will not be the challenges they meet tomorrow. Banks cannot predict the future, but they will have to anticipate it by having the flexibility to grow and expand their security requirements as challenges evolve.

Numerous permutations and combinations of MFA options exist. It is important to note that banks will most likely and should choose more than one of the MFA options available to them. Banks will want to employ a layered MFA approach. This will allow the bank to devise a comprehensive MFA program that can meet a wide variety of needs. For example, a bank may choose a mutual authentication solution for all customer segments in which the client pre-selects an image and a familiar phrase. This solution may also analyze the user’s computer for certain items (e.g. IP address, location) to recognize the person logging in. In addition, the bank may choose to distribute tokens to business clients who are conducting large-value transactions.

Some banks may also choose to take advantage of a risk-based monitoring solution in order to track user behavior and patterns and throw out challenge questions in the event that the system detects an anomaly. MFA choices will vary depending on transactional risk, mix of banking platforms, disturbance threshold, and the existing use of a particular technology (e.g. tokens).

Once options are chosen, banks have to work on selling the concept to its client base. This is key to adoption and acceptance. Banks will need to promote MFA at industry conferences, launch contests and promotions, offer solutions free of charge, and work on overall customer education.

Whitepapers & Resources

2021 Transaction Banking Services Survey
Banking

2021 Transaction Banking Services Survey

5y
CGI Transaction Banking Survey 2020

CGI Transaction Banking Survey 2020

6y
TIS Sanction Screening Survey Report
Payments

TIS Sanction Screening Survey Report

7y
Enhancing your strategic position: Digitalization in Treasury
Payments

Enhancing your strategic position: Digitalization in Treasury

7y
Netting: An Immersive Guide to Global Reconciliation

Netting: An Immersive Guide to Global Reconciliation

8y