# AI is the new password: security and ease for finance users 
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-02-01
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Enhancing Financial Security: The Shift from Passwords to AI
Meta Description: Discover the drawbacks of traditional username/password systems in financial services &amp; how AI can enhance security with continuous authentication and
URL: https://financedigest.com/ai-is-the-new-password-security-and-ease-for-finance-usershtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/mental-health-while-remote-working-6-1736838603042-compressed.jpg)

_By **Baldeep Dogra,** Director of Solutions Marketing at [Blackberry](http://blackberry.com/)_

For over 50 years, a password and a username have been the fundamental and largely unchanged model for identifying and verifying users – both in the financial sector and beyond. Nevertheless, there are drawbacks to this strategy, which can certainly be seen in the financial sector.

Firstly, employees often prove unable to use usernames and passwords safely enough to protect their data. Indeed, 94% percent of financial [services’ IT managers](https://www.financedigest.com/cyclic-innovation-to-drive-the-medical-case-management-services-market.html "Cyclic innovation to drive the Medical Case Management Services Market") are not fully confident in the ability of their employees, consultants and partners to adequately safeguard data. This was revealed in a [survey](https://blogs.blackberry.com/en/2019/07/its-time-to-recognize-user-needs-and-secure-them) conducted by BlackBerry of 500 financial services IT professionals across six countries in North America and Europe.

Furthermore, complex and long usernames and passwords are not user-friendly. This leads to an area of tension: how do we balance user experience (UX) with security? For example, ‘Waiting phrases’ are more secure than the familiar ‘passwords’, but with the advent of [mobile devices and apps](https://www.financedigest.com/why-you-should-use-a-mobile-banking-app-and-how-to-make-the-most-of-it.html "Why You Should Use a Mobile Banking App – and How to Make the Most of It"), user preferences have shifted. Nowadays, users want fast and practical access – passwords seem too long and impractical.

The consequences of these drawbacks can be severe, especially within the financial [sector](https://www.financedigest.com/the-technologies-set-to-boost-the-finance-sector-in-2022.html "The technologies set to boost the finance sector in 2022"). If safety guidelines are [breached and sensitive data](https://www.financedigest.com/when-not-if-why-a-data-breach-response-plan-is-more-important-now-than-ever.html "When not if: why a data breach response plan is more important now than ever") is compromised, the company is vulnerable not only to damage from competitors or criminals, but also to violation of GDPR. This is not to mention considerable damage to its reputation and the subsequent loss of business.

**Automatic scrutiny**

Fortunately, an approach is emerging that can take away the [concerns: Artificial Intelligence](https://www.financedigest.com/the-future-of-artificial-intelligence-in-cyber-security.html "The Future of Artificial Intelligence in Cyber Security") (AI). The emphasis shifts from recognising usernames and passwords to recognising the user as such. Here, AI techniques are applied to gain insight into how verified users deal with business apps, [data and services](https://www.financedigest.com/four-ways-data-and-ai-can-transform-financial-services.html "Four ways data and AI can transform Financial Services"). For example, cybersecurity professionals in the financial sector can detect when malicious users or malware attempt to access [data](https://www.financedigest.com/whose-role-is-it-anyway-why-finance-underpins-data-led-digital-transformation.html "Whose role is it anyway? Why finance underpins data-led digital transformation").

The different, individual techniques that can all [work together to identify users](https://www.financedigest.com/brics-aerial-work-platforms-market-competitive-growth-strategies-based-on-type-applications-end-user-and-region.html "BRICS Aerial Work Platforms Market Competitive Growth Strategies Based on Type, Applications, End User and Region") generally fall into two main categories:

**– Continuous authentication** – Unlike password-based authentication and other two-factor authentication (2FA) techniques, continuous authentication uses techniques to compare the user’s behaviour during each session with existing (learned) models of past behaviour. Continuous authentication also looks for abnormalities that may indicate that the session has been taken over by an external threat. These techniques include, for example, biometrics (by looking at typing speed and mouse movements) and transactional behaviour (such as transactions and associated amounts).

**– Contextual Awareness** – This approach is based on understanding the context of a particular session or transaction and then aligning it with [security policies](https://www.financedigest.com/uk-finance-regulators-should-pay-heed-to-energy-security-policy-says-sunak.html "UK finance regulators should pay heed to energy security policy, says Sunak"). The security policy performs context-based checks and can then take appropriate action. This typically includes both the physical (e.g. device/network used, time of day, location, etc.) and transactional contexts (e.g. transferring or recovering amounts).

From the user’s point of view, the great advantage of the above techniques is that they do not [need to perform any additional actions](https://www.financedigest.com/new-uk-pm-will-need-to-take-urgent-action-on-energy-bills-ofgem-ceo.html "New UK PM will need to take urgent action on energy bills – Ofgem CEO") to authenticate themselves. The techniques make automatic and continuous authentication possible. At the same time, it can adapt to the user’s context, while the user concentrates on their work tasks. For example, less strict [authentication is applied when a user is working](https://www.financedigest.com/get-real-how-to-be-your-authentic-self-at-work.html "Get real: How to be your authentic self at work") within a context with a lower risk, such as routine transactions.

**Zero Trust design**

The [application of these techniques can lead to a user](https://www.financedigest.com/catharanthine-market-2022-research-on-user-demand-size-applications-key-players.html "Catharanthine Market 2022 Research on User Demand, Size, Applications, Key Players:") experience that rarely requires a password. Authentication is then only requested when the risk of the context is too high. At the same time, the bar for cybercriminals is considerably higher because they have [to navigate through multiple](https://www.financedigest.com/how-to-navigate-multiple-data-privacy-regulatory-frameworks.html "How to navigate multiple data privacy regulatory frameworks") layers of behavioural and contextual risk assessment. They need to do this continuously, with an increasing degree of control as the transaction risk increases.

Incidentally, this does not mean that implementing these authentication techniques goes without a hitch. For example, changes in apps and [services are needed](https://www.financedigest.com/why-banks-need-to-embrace-ai-first-customer-service.html "Why Banks Need to Embrace AI-First Customer Service") to integrate these new techniques. This is even more complex than building a login page to collect passwords and [send messages](https://www.financedigest.com/with-tighter-grip-beijing-sends-message-to-hong-kong-tycoons-fall-in-line.html "With tighter grip, Beijing sends message to Hong Kong tycoons: fall in line"). However, this [challenge can be overcome](https://www.financedigest.com/how-to-overcome-the-challenges-faced-by-women-in-business-3.html "How to Overcome the Challenges Faced by Women in Business") by using a platform-based approach. This is in contrast to an individual approach in which individual apps and [services are tackled](https://www.financedigest.com/tackling-the-cloud-skills-gap-in-financial-services.html "Tackling the cloud skills gap in financial services") each time.

**A new** [era of security](https://www.financedigest.com/identity-security-in-the-era-of-sox.html "Identity security in the era of SOX")

Although strong usernames and passwords have long been seen as the best way to protect the financial sector, they are too vulnerable in themselves, especially when it comes to [securing the data the sector](https://www.financedigest.com/why-the-finance-sector-must-prioritise-mobile-security-over-innovation.html "Why the finance sector must prioritise mobile security over innovation") owns. Using AI, [cybersecurity professionals are working](https://www.financedigest.com/are-businesses-using-cybersecurity-as-a-scapegoat-for-a-desperate-return-to-office-working.html "Are Businesses Using Cybersecurity As A Scapegoat For A Desperate Return To Office Working?") to develop more legitimate authentication techniques tailored to each individual user. By recognising behaviour instead of log-in data, users can rely more on the [security of their finances and data](https://www.financedigest.com/how-financial-services-can-secure-data-and-build-trust-in-todays-modern-environment.html "How financial services can secure data and build trust in today’s modern environment"). This frictionless experience ultimately means the best UX whilst [assuring security](https://www.financedigest.com/cyber-security-data-re-assurance.html "Cyber Security: Data ‘Re’-Assurance") and privacy and delivering optimised productivity.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

