spot_img

Adaptive Multi-factor Authentication (MFA) in BFSI

Date:

Trending

A few months back (just after the Covid pandemic had started) an important change was implemented by a popular retail US Bank, Bank of America.  This was regarding how their retail net-banking customers would be logging into their banking account.  

- Advertisement -

All users of this bank can now set up an additional security measure during login in the form of a one-time authorization code, that would be sent to their registered mobile.  This will be in addition to their user id and password.  In the case of some users who are deemed to have a security risk during login (due to their high-risk score presumably arrived due to their inconsistent login patterns), this process has been made mandatory.  

Since the bank had suspected that post-covid the number of internet logins and transactions is going to be high, they probably implemented these changes to protect attempts to hijack genuine customer accounts by fraudulent means by hackers.

- Advertisement -

This shows that the era of Multi-Factor Authentication (MFA) has truly arrived and is here to stay.  Previously MFA was used only when bank transactions were performed by users, but now they are required even during the login process.  

The bank was using security questions as a second factor, but now probably had deemed that as risky, as typical user answers for popular security questions of theirs, can be lifted from their social media accounts by hackers.  

- Advertisement -

So where does this lead to?  Probably, to the next stage of MFA, which is Adaptive MFA in BFSI.  

What is Adaptive MFA? 

When a user login into a bank, several patterns about the login can be measured by the bank.  They can use this data to protect the customer from phishing and other hacker attacks. Like the typical time of the day the user logs in, the network & computer the login happens from, the Geolocation (GPS location) the user logs in from, the time they typically spend during the login, the type of transactions they normally perform, etc.  

With this wealth of data in-store, the banks can now assign risk scores for each activity through AI (Artificial Intelligence) and ML (Machine Learning) methods. If during any login there is an abnormal risk score detected for the user, an adaptive MFA authentication can be triggered.  That is, the user during that login session would be made to go through additional factors of authentication as part of their MFA Auth, for example, an OTP coupled with a Push based authentication sent through to the user’s mobile app, plus a security question or even a phone call based verification.  This helps to control or even eliminate the fraudulent access by a hacker, as it begins to happen.

How this prevents fraud?

During adaptive authentication, the key element to note is most of the factors that are used for authentication are instantly generated, so the hacker would not be knowing all the details of the authentication sequence and credentials in advance, for them to execute a phishing attack on the authenticated session of the user.  Even the user would not know these in advance for the hackers to target gullible users to get credentials from them, before the login.

What are the other adaptive authentication factors that can come into play?

MFA is normally performed by:

•    factors that the users know (passwords, security questions, pre-stored user-approved picture patterns and code numbers),

•    factors the users have (like OTP, mobile push authentication, google authentication) and 

•    factors that define who the users are (biometric authentications like retina scan, fingerprints, facial recognition).  

Out of these the first set of factors “the one the users know” are under severe attack by the hackers.  Hence banks will resort slowly to the second and third categories of authentications mentioned above.  These two categories of factors will be hard to pry out or reproduce like the passwords or security questions, for the reasons mentioned above.

What are the challenges in implementing Adaptive MFA?

The primary challenge is how to protect the user experience.  Users normally do not like too many restrictions just to get to their bank account.  Also, not all users are computer or mobile-savvy.  For example, the bank in the question above has instructed the users who do not have a mobile phone or do not have a valid phone number in the file, to call the bank to get authenticated.   

While this may work temporarily, this cannot be done by the user every time as the waiting times for such calls are high.  So, the banks have to arrive at the right mix of technology and user convenience to implement secure MFA login at the right cost to the user.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Raj Srinivas
Raj Srinivas
Primarily from a strong security and product engineering background, he has been the principal architect of MISP (Multi-Domain Identity Services Platform) & CIE (Cloud ID Exchange) – in-house IAM & Security products at 8K Miles.

More Latest Stories

More Articles

Meta Declares Quarterly Cash Dividend Of $0.525 Per Share

Facebook parent company, Meta Platforms Inc. (NASDAQ:META) said its board of directors has declared a quarterly cash dividend of $0.525 per share on its...

Lok Sabha: Government releases ₹68K crore under MGNREGS; wage payments routed via DBT

New Delhi, India: Union Agriculture Minister Shivraj Singh Chouhan said the government has released 68,393.67 crore rupees to states and Union Territories under the Mahatma Gandhi National Rural Employment Guarantee Scheme (MGNREGS) in the current financial year 2025-26. In a written reply in the Lok...

The Evolving Classroom: Venkateshwar International School’s Pooja Sharma on Changing Role of Schools in Delhi’s CBSE Ecosystem

Speaking with TechGraph, Pooja Sharma, Vice Principal of Venkateshwar International School (VIS), discussed how...

Digital Generics: How AI is Redefining the Future of Affordable Medicine

It was with pride that global headlines described India as the world's pharmacy, supplying...

Why NoSQL Databases Are the Future for Tech Startups

In today’s digital-first economy, tech startups continue to dominate the startup landscape. A startup...

Delhi IGI Airport Revamped Terminal 2 with Advanced Baggage screening systems

Delhi’s Indira Gandhi International Airport (IGI) has reopened its reconstructed Terminal 2, inaugurated by...

The Rise of the AI Agent Economy: How Voice AI Agents Are Becoming the New Frontline Workforce For Call Centers

The work inside a call center has always depended on two things: speed and...

The Road to Equality in Tech: Women In Cloud’s Chaitra Vedullapalli on Reshaping Opportunity for Women Entrepreneurs Globally

In an interview with TechGraph, Chaitra Vedullapalli, Co-Founder of Women In Cloud, discussed how...

Understanding What Makes Sunscreen Truly Effective

Many people pick a sunscreen merely based on its SPF, thus they think that a higher number means better protection. However, SPF is only...

How AI is Improving Risk Management Among Crypto Traders

Over the past few years, the role of Artificial Intelligence in almost every sector...

The AI Advantage: How Intelligent Learning Solutions Are Rewriting Workforce Productivity in 2025 and Beyond

In 2025, artificial intelligence is no longer a futuristic concept — it’s the invisible...

Bajaj Financial Securities Acquires Stake in Lemnisk from Early Investors

Bajaj Financial Securities has acquired stakes in Bengaluru-based customer data platform Lemnisk through a...

The Rise of Cyber Cartels: How the Dark Web Fuels Digital Extortion?

In 2025, cybercrime has evolved beyond individual hackers or little ransomware criminal gangs into...

AI Research Startup Redrob Draws $10 Mn In Series A Funding Led By Korea Investment Partners

AI research startup Redrob has secured $10 million in its Series A round led by Korea Investment Partners with KB Investment, Kiwoom Investment, Korea...

The Future Employability Equation: PrepInsta’s Manish Agarwal on How AI Is Reshaping Student Readiness for Hiring in India

Speaking with TechGraph, Manish Agarwal, Co-Founder of PrepInsta, discussed how the increasing adoption of AI-led assessments and automated hiring platforms is shifting campus recruitment away from reliance on pedigree and location toward a more merit-driven model that values consistency, analytical reasoning, and practical application...

Norovex Review: Inside the Trading Platform Gaining Momentum

The online trading industry has entered one of its most dynamic periods in years....

Why Zero Code Exposure Is the Future of Trust in AI

AI coding assistants have quickly become indispensable for developers, promising faster deployment, cleaner code,...

Trump Says He Will Sue BBC Over Edited Broadcast of Jan 6 Speech

US President Donald Trump has said he plans to take legal action against the...

Starbucks Baristas Rally in New York as Strike Over Pay and Staffing Extends Nationwide

Starbucks baristas rallied in New York City as part of an open-ended strike that...

Demystifying Private Equity Market: WWIPL MD Krishna Patwari on Expanding Retail Access to India’s Unlisted Ecosystem

Speaking with TechGraph, Krishna Patwari, Founder and Managing Director of Wealth Wisdom India Pvt....

The Aesthetic of Longevity: Aesthetica’s Tanisha Bansal Gokharu on Redefining Luxury Home Interiors

Speaking with TechGraph, Tanisha Bansal Gokharu, Founder and Principal Designer at Aesthetica, discussed how...

Empowering Creators: Studiobackdrops’ Archisman Misra on Making Professional Production Accessible Across India

Speaking with TechGraph, Archisman Misra, CEO and Founder of Studiobackdrops, discussed how India’s fast-growing...

Trade Gaia Emerges as a Key Player in Global Altcoin Trading

While Bitcoin continues to dominate headlines, the real growth in 2025 is coming from...

The Conversation Shift: Doceree CRO Thomas Shea on Making Healthcare Marketing More Relevant for Physicians

Speaking with TechGraph, Thomas Shea, Chief Revenue Officer (CRO) at Doceree, discussed how artificial...

Bajaj Financial Securities Acquires Stake in Lemnisk from Early Investors

Bajaj Financial Securities has acquired stakes in Bengaluru-based customer data platform Lemnisk through a...

Digit Life Insurance posts 31% rise in H1 FY26 revenue to ₹858 crore

India-based, Go Digit Life Insurance said its revenue for the first half of FY...

Debt Recovery Reinvented: Collectedge’s Ranjan Agarwal on Reshaping India’s Collections Ecosystem for Lenders

Speaking with TechGraph, Ranjan Agarwal, CEO and Co-Founder of Collectedge, discussed how India’s debt...

AI as a Growth Multiplier: How Smart Companies Accelerate Without Breaking

In today’s business environment, smart growth is just as important as any other form...

Beyond Price Points: Unix India’s Imran Kagalwala on Redefining Consumer Expectations in the Mobile Accessories Market

Speaking with TechGraph, Imran Kagalwala, Co-founder of Unix India, discussed how a crowded accessories...

The Rise of Cyber Cartels: How the Dark Web Fuels Digital Extortion?

In 2025, cybercrime has evolved beyond individual hackers or little ransomware criminal gangs into...

Trade Gaia Emerges as a Key Player in Global Altcoin Trading

While Bitcoin continues to dominate headlines, the real growth in 2025 is coming from...

How Fleet Maintenance Scheduling Supports Business Vehicle Performance

Managing a fleet of vehicles can be challenging for any business. From delivery vans...

The Conversation Shift: Doceree CRO Thomas Shea on Making Healthcare Marketing More Relevant for Physicians

Speaking with TechGraph, Thomas Shea, Chief Revenue Officer (CRO) at Doceree, discussed how artificial...