# Challenger banks: Ensuring trust in your email 
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2020-04-15
Category: BANKING
Category URL: https://financedigest.com/category/banking
Meta Title: Protecting Financial Institutions Against Email Fraud
Meta Description: Maintain trust with customers by safeguarding emails against cybercriminals. Learn how to prevent fraudulent activity and keep your reputation intact.
URL: https://financedigest.com/challenger-banks-ensuring-trust-in-your-emailhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/lack-of-partnerships-holding-back-open-banking-innovation-report-finds-1736838925707-compressed.jpg)

_By **Paul Wilson,** Product – Risk Based Authentication, AppGate_

With nearly 300 billion emails being sent every day in 2019, the use of email by both individuals and businesses shows no sign of slowing down. In fact, in light of recent governmental lockdowns causing more people to work from home, there will arguably be more emails sent now than ever before. For most organisations, it is the primary way in which they communicate with their [customers](https://www.financedigest.com/why-poor-customer-communication-is-holding-open-banking-back.html "Why poor customer communication is holding open banking back") so the need for email to remain a trusted method of communication is crucial.

But it is not just the enterprise [world that is taking advantage of the cost-effectiveness and easy to use nature](https://www.financedigest.com/fund-nature-protection-now-or-face-huge-losses-says-world-bank.html "Fund nature protection now or face huge losses, says World Bank") of emails. It is understandable that fraudsters are increasingly tapping into these benefits with 49 per cent of businesses reporting that fraudulent emails the one [cybersecurity breach](https://www.financedigest.com/why-training-your-staff-is-key-in-spotting-the-warning-signs-of-a-cybersecurity-breach.html "Why training your staff is key in spotting the warning signs of a cybersecurity breach") that caused the most disruption to their organisation.

For businesses, particularly those within the financial [service industry](https://www.financedigest.com/how-digital-identity-verification-will-revolutionize-security-defenses-in-the-financial-services-industry.html "How Digital Identity Verification Will Revolutionize Security Defenses in the Financial Services Industry"), it is absolutely paramount that their customers maintain a level of trust in their provider’s email communication. This is especially true as we [see an increase in call centres closing down due to COVID-19](https://www.financedigest.com/uk-sees-biggest-rise-in-foreign-workers-since-covid-19-pandemic.html "UK sees biggest rise in foreign workers since COVID-19 pandemic") and email becoming a vital form of communication for the foreseeable future for many organisations. To truly protect themselves against cybercriminals and ensure their trustworthy reputations are kept intact, financial institutions [must ensure](https://www.financedigest.com/developmental-best-practices-must-change-to-ensure-the-post-pandemic-recovery-of-financial-services.html "Developmental best practices must change to ensure the post-pandemic recovery of financial services") they have the correct tools in place.

**The price to pay when trust is lost**

When it comes to people’s [personal](https://www.financedigest.com/cracking-the-personal-finance-code.html "Cracking the Personal Finance Code") and financial details that are at risk of being compromised there is very little room for forgiveness. Once a customer has experienced fraudulent activity, it is not just a matter of having to [rebuild their trust](https://www.financedigest.com/why-trust-and-technology-are-the-perfect-partnership-to-rebuild-the-financial-sector.html "Why trust and technology are the perfect partnership to rebuild the financial sector"). The likelihood is, they’ll move on to another provider.

For the larger banks, this can be a setback but it is unlikely they’ll suffer in the long term. However, for the increasing number of [challenger banks](https://www.financedigest.com/the-rise-of-challenger-banks.html "challenger banks") such as Monzo and Starling, who face acquiring costs of US$ 349 (£268) for new banking customers, it is not just short term reputational damage they have to battle. The [cost of losing](https://www.financedigest.com/back-to-basics-for-cost-control-as-the-usual-levers-lose-value.html "Back to basics for cost control as the usual levers lose value") a customer can be a matter of make or break for them.

What’s more, the likelihood of suffering an attack is high and continuing to rise. The number of phishing emails has risen by 25 per cent in the last year alone, according to the AppGate’s [latest Fraud Beat Report](https://www.financedigest.com/listen-care-share-ofwats-latest-report-on-the-water-industrys-handling-of-customers-during-the-pandemic.html "Listen, Care, Share: Ofwat’s latest report on the water industry’s handling of customers during the pandemic"). Unlike other forms of fraudulent attacks, phishing attacks are easily masked through the use of mimicking official bank [email addresses](https://www.financedigest.com/how-to-create-a-professional-email-address.html "How to Create a Professional Email Address"). This makes it almost impossible for the customer to even notice if they are receiving questionable emails.

For challenger banks, who are in phases dedicated to fast growth and [customer acquisition](https://www.financedigest.com/rationalfx-drives-customer-acquisition-with-regtech-platform-from-trunarrative.html "RationalFX drives customer acquisition with RegTech platform from TruNarrative"), having a trustworthy email system is not simply a nice to have. It is an absolute necessity if they are going to successfully hit their targets, maintain their existing customer base and retain new customers.

**Straightforward protection**

To add further difficulty into the mix, the majority of [security solutions](https://www.financedigest.com/securing-financial-institutions-with-the-help-of-pam-solutions.html "Securing financial institutions with the help of PAM solutions") require a high level of technical knowledge. For larger organisations, this is easily solved by onboarding a specific security team. But for challenger banks, who often have small teams and very tight budgets, this is a luxury few possess. Challenger [banks need](https://www.financedigest.com/what-banks-need-to-prepare-for-eba-pillar3-disclosure-of-esg-risks.html "What Banks Need to Prepare for EBA Pillar3 Disclosure of ESG Risks") solutions that are not only simple and efficient but one that fits around their fast-paced operations.

This is where authenticity policies and reporting protocols, such as Domain-based Message Authentication Reporting and Conformance (DMARC), can come into play. By hosting an approved list of domains, DMARC works by allowing email [service providers](https://www.financedigest.com/high-energy-shockwave-therapy-units-market-end-user-demand-by-types-regions-top-players-service-provides-regional-outlook-and-forecast-to-2028-2.html "High Energy Shockwave Therapy Units Market End-User Demand by Types, Regions, Top Players, Service Provides, Regional Outlook and Forecast to 2028") to quickly cross-check the lists and block spoofing email attacks. For challenger banks, once they publish their [details on the DMARC Domain Name System](https://www.financedigest.com/all-natural-flavors-system-market-overview-with-details-analysis-competitive-landscapes-forecast-to-2022-2029.html "All-Natural Flavors System Market Overview With Details Analysis, Competitive Landscapes, Forecast To 2022-2029") (DNS), they establish a strong foundational layer of protection for their customers.

It is through the use of two reporting methods that DMARC can work to block spoofing emails. The first method, known as Sender Policy Framework (SPF) reports, checks if the incoming mail is from a domain that is authorised by that domain’s administrators. The second report, called DomainKeys Identified Mail (DKIM) reports, checks that the email, and any attachments in it, have not been altered in any way during delivery. If an email fails either of these tests, the sender’s DMARC policy will notify the receiver of the emails to either monitor the unauthenticated email, separate it or reject it.

With the use of real-time threat visibility and analytics platform, this protection can be taken a step further. These [platforms connect to the DMARC DNS data](https://www.financedigest.com/mercedes-benz-and-microsoft-collaborate-on-supply-chain-data-platform.html "Mercedes-Benz and Microsoft collaborate on supply chain data platform"), enabling them to not only show where malicious emails come from but then assist in preventing the malicious emails reaching customers. By capitalising on these platforms, challenger [banks can quickly close](https://www.financedigest.com/lebanese-bank-closes-over-30-british-held-accounts-after-uk-ruling-depositors-group.html "Lebanese bank closes over 30 British-held accounts after UK ruling-depositors’ group") down spoofing sites and disable additional attacks. In addition, as more security features are added over time, the threat visibility and analytics platforms can also assess their effectiveness. Having this additional layer of insights and ability allows challenger banks to simultaneously ensure trust in email communications whilst not affecting the [customer experience](https://www.financedigest.com/getting-customer-experience-right-in-financial-services.html "Getting customer experience right in financial services").

**Start as you mean to go on**

For challenger banks, trustworthy email communications are not simply the difference between a good and a bad day in the office. It is the lifeblood of their survival. Having [effective security measures in place to protect their customers](https://www.financedigest.com/5-simple-steps-to-an-effective-customer-complaint-response-strategy.html "5 Simple Steps to an Effective Customer Complaint Response Strategy") is vital. For challenger banks to really provide that added value of faultless security protection for themselves and their customers, a combined [approach of security](https://www.financedigest.com/as-saas-grows-financial-services-must-rethink-their-security-approach.html "As SaaS grows, financial services must rethink their security approach") solutions such as DMARC and an analytic platform is a necessity.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

