Adaptive Multi-factor Authentication (MFA) in BFSI

Date:

Trending

- Advertisement -

A few months back (just after the Covid pandemic had started) an important change was implemented by a popular retail US Bank, Bank of America.  This was regarding how their retail net-banking customers would be logging into their banking account.  

All users of this bank can now set up an additional security measure during login in the form of a one-time authorization code, that would be sent to their registered mobile.  This will be in addition to their user id and password.  In the case of some users who are deemed to have a security risk during login (due to their high-risk score presumably arrived due to their inconsistent login patterns), this process has been made mandatory.  

Since the bank had suspected that post-covid the number of internet logins and transactions is going to be high, they probably implemented these changes to protect attempts to hijack genuine customer accounts by fraudulent means by hackers.

This shows that the era of Multi-Factor Authentication (MFA) has truly arrived and is here to stay.  Previously MFA was used only when bank transactions were performed by users, but now they are required even during the login process.  

The bank was using security questions as a second factor, but now probably had deemed that as risky, as typical user answers for popular security questions of theirs, can be lifted from their social media accounts by hackers.  

- Advertisement -

So where does this lead to?  Probably, to the next stage of MFA, which is Adaptive MFA in BFSI.  

What is Adaptive MFA? 

When a user login into a bank, several patterns about the login can be measured by the bank.  They can use this data to protect the customer from phishing and other hacker attacks. Like the typical time of the day the user logs in, the network & computer the login happens from, the Geolocation (GPS location) the user logs in from, the time they typically spend during the login, the type of transactions they normally perform, etc.  

With this wealth of data in-store, the banks can now assign risk scores for each activity through AI (Artificial Intelligence) and ML (Machine Learning) methods. If during any login there is an abnormal risk score detected for the user, an adaptive MFA authentication can be triggered.  That is, the user during that login session would be made to go through additional factors of authentication as part of their MFA Auth, for example, an OTP coupled with a Push based authentication sent through to the user’s mobile app, plus a security question or even a phone call based verification.  This helps to control or even eliminate the fraudulent access by a hacker, as it begins to happen.

- Advertisement -

How this prevents fraud?

During adaptive authentication, the key element to note is most of the factors that are used for authentication are instantly generated, so the hacker would not be knowing all the details of the authentication sequence and credentials in advance, for them to execute a phishing attack on the authenticated session of the user.  Even the user would not know these in advance for the hackers to target gullible users to get credentials from them, before the login.

What are the other adaptive authentication factors that can come into play?

MFA is normally performed by:

•    factors that the users know (passwords, security questions, pre-stored user-approved picture patterns and code numbers),

•    factors the users have (like OTP, mobile push authentication, google authentication) and 

•    factors that define who the users are (biometric authentications like retina scan, fingerprints, facial recognition).  

Out of these the first set of factors “the one the users know” are under severe attack by the hackers.  Hence banks will resort slowly to the second and third categories of authentications mentioned above.  These two categories of factors will be hard to pry out or reproduce like the passwords or security questions, for the reasons mentioned above.

What are the challenges in implementing Adaptive MFA?

The primary challenge is how to protect the user experience.  Users normally do not like too many restrictions just to get to their bank account.  Also, not all users are computer or mobile-savvy.  For example, the bank in the question above has instructed the users who do not have a mobile phone or do not have a valid phone number in the file, to call the bank to get authenticated.   

While this may work temporarily, this cannot be done by the user every time as the waiting times for such calls are high.  So, the banks have to arrive at the right mix of technology and user convenience to implement secure MFA login at the right cost to the user.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -
Raj Srinivas
Raj Srinivas
Primarily from a strong security and product engineering background, he has been the principal architect of MISP (Multi-Domain Identity Services Platform) & CIE (Cloud ID Exchange) – in-house IAM & Security products at 8K Miles.

More Latest Stories

More Articles

Why Players Buy LoL Boost and How the Process Works

If you’re researching why players buy lol boost, you’re usually trying to understand two things: what people are actually paying for in ranked, and...

CasinoBonusesFinder UK: how filters, Telegram alerts and real bonus matching work in practice

Anyone who has spent serious time on casino bonus hunting knows the drill. You find something that looks promising, click through, and discover the offer expired three weeks ago. Or the wagering requirement is 50x - meaning a £100 bonus requires £5,000 in bets...

The Detroit Region’s Role in Modern Global Supply Chains

As global commerce continues to expand its reach, the Detroit region has emerged as...

The Importance of Keeping Up to Date With Auto Maintenance

Auto maintenance is one of the most important responsibilities that comes with owning a...

The HiPCO Advantage: NoPo Nanotechnologies’ Gadhadar Reddy on Scaling SWCNT Manufacturing for Emerging Industries

Speaking with TechGraph, Gadhadar Reddy, Co-Founder and CEO of NoPo Nanotechnologies, discussed how manufacturing...

India’s Air Crisis Needs a Deeptech Answer, Not a Consumer Gadget

Twenty years ago, an air conditioner in an Indian home was a luxury. Today...

Top No-KYC Crypto Casino Sites in 2026

Most online casinos demand a lot of personal information from you before you can...

Redrob AI Launches Professional AI Platform for India’s Workforce

In a bid to help students and professionals navigate an increasingly fragmented digital work...

PatexOne: Could This Platform Be Smarter Than Your Impulses?

Australian investors are used to platforms that shout about leverage and “opportunity”. PatexOne takes a different tone. It positions itself as a multi‑market environment...

Simple Habits That Keep Your Car Running Longer

Keeping your car running longer doesn’t require expert-level knowledge—it comes down to building smart...

Why Resume-Based Hiring Is Failing India’s Workforce

India needs a shift from credential-first hiring to skill-first validation

Borade AI Founder Shiv Kumar Borade on Building an AI Growth Engine for Small Businesses

Speaking with TechGraph, Shiv Kumar Borade, Founder & CMD of Borade.AI, discussed how many...

Capabilities Over Credentials: Scrabble’s Naveen Tiwari on the Changing Nature of Leadership Hiring

Speaking with TechGraph, Naveen Tiwari, Co-Founder of Scrabble, discussed how leadership hiring is shifting...

From Intuition to Analysis: How AI Is Becoming Every CEO’s Second Brain

Most CEOs are making important decisions with partial information. The challenge is not just speed. It is the fact that markets, operations, customers, and...

Rethinking Executive Search: Venator Search Partners’ Deepraditya Datta on Leadership Hiring in a Changing Talent Market

In an interview with TechGraph, Deepraditya Datta, Founder and Managing Director of Venator Search Partners, outlined how organisations are reassessing leadership hiring as long-term business outcomes become increasingly tied to executive appointments, and how companies risk significant setbacks when hiring decisions are driven by...

Beyond the MVP: Gacsym Ventures CTO Nandagopal P on Helping Startups Through Venture Studios

In a conversation with TechGraph, Nandagopal P, Chief Technology Officer at Gacsym Ventures, shared...

How Air Can Become Urban India’s New Water Source

India's cities are running dry. Chennai nearly ran out of groundwater in 2019. Bengaluru's...

More Than Just a Scratch: The Importance of Windshield Care

Maintaining your vehicle’s windshield often appears as a seemingly minor task that can easily...

The world’s largest crypto market is building in the dark

India remains one of the few significant economies without a comprehensive crypto and stablecoin...

How Location Data Storage Technology is Making City Travel Smoother

India’s mobility ecosystem is undergoing a quiet but powerful transformation, driven not just by...

Can Intelligent Optimization Redefine How Businesses Solve Their Toughest Problems?

The modern enterprise is no longer just a business; it is a complex, hyper-connected...

As Crypto Markets Mature the OpenSea Insider Trading Case Still Shapes Governance Debates

When federal prosecutors charged former OpenSea employee Nathaniel Chastain in June 2022, the case...

Serhii Tokarev Spoke About The Third Season Of The Generation H Accelerator

Serhii Tokarev spoke about the Generation H 3.0 HealthTech accelerator, which is opening applications...

MochaTrade Raises Pre-Seed Funding From Y Combinator and Pioneer Fund

MochaTrade, a global trading platform focused on offering perpetual futures linked to U.S. stocks,...

Borade AI Founder Shiv Kumar Borade on Building an AI Growth Engine for Small Businesses

Speaking with TechGraph, Shiv Kumar Borade, Founder & CMD of Borade.AI, discussed how many...

“Budget should focus on reducing taxes on capital gains,” Says Abhishek Gupta of Hex N Bit

Speaking in the upcoming Union Budget 2021, Abhishek Gupta, Founder, and CEO, Hex N...

“China is a Global thief” Rep. Tom Rice on Uyghur Forced Labor Prevention Act

Speaking at the House on Uyghur Forced Labor Prevention Act, Rep. Tom Rice (R-SC)...

AI and Fake Content: Can Technology Win the Battle Against Misinformation?

Artificial Intelligence has transformed how content is created, manipulated, and distributed at scale. News,...

Why Micro Learning at 3 Minutes Works Better Than Lectures at 3 Hours

In the fast-moving world of digital education, there is one myth that continues to...

Capabilities Over Credentials: Scrabble’s Naveen Tiwari on the Changing Nature of Leadership Hiring

Speaking with TechGraph, Naveen Tiwari, Co-Founder of Scrabble, discussed how leadership hiring is shifting...

Alphabet Discloses $2.14 Billion in Public Equity Holdings as of June 30

Alphabet Inc. disclosed $2.14 billion in equity securities held across 39 positions as of...

The Role of Edtech in Addressing Equity Gaps in Higher Education

In the fast-paced world of EdTech today, the opportunity to bridge educational gaps and...

India to generate $100 bn from telephonic investments

India expects to attract $100 billion in investments in the telecom sector, a union...