# PSD2: What It Means, And Why We Should All Care
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2016-11-09
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: PSD2: Strengthening Security in the European Payments Market
Meta Description: Discover the key features of the Payment Services Directive 2, and how it aims to enhance online payment security and prevent hackers from exploiting the
URL: https://financedigest.com/psd2-what-it-means-and-why-we-should-all-carehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/banking-security-1736844390902-compressed.jpg)

By **Brian Spector,** CEO at MIRACL

The European payments market is on the cusp of a radical change.  Due to come into effect in January 2018, the revised Payment Services Directive, PSD2, is a centralised attempt by the European Parliament to, among other things, make online payments safer for businesses and individuals, by clearly specifying liability and authentication rules. But rather than being just a swathe of red tape, the directive is a much-needed attempt to [prevent our entire banking](https://www.financedigest.com/scams-avoided-how-to-prevent-bank-account-scams-in-2023.html "Scams Avoided: How to Prevent Bank Account Scams in 2023") system from being exploited by hackers.  In this article we’ll outline some of the key features of the Directive, and explain why it will benefit both the financial [services industry](https://www.financedigest.com/why-sustainability-presents-one-of-the-greatest-opportunities-for-the-financial-services-industry.html "Why sustainability presents one of the greatest opportunities for the Financial Services industry") and its customers.

![Brian Spector](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/miraclbrianspectorhi-res-200x300-1736844390811-compressed.jpg)

Brian Spector

As the payments market has become more open, with a plethora of [third parties](https://www.financedigest.com/why-a-replacement-to-third-party-cookies-is-key-to-post-pandemic-recovery.html "Why a replacement to third party cookies is key to post-pandemic recovery") now sitting between banks and their customers, it has become essential to accurately verify the identities of people accessing the data and systems involved. The PSD2 regulations specify that each payment provider is required to have strong authentication processes in place, whether they are the main [service providers](https://www.financedigest.com/high-energy-shockwave-therapy-units-market-end-user-demand-by-types-regions-top-players-service-provides-regional-outlook-and-forecast-to-2028.html "High Energy Shockwave Therapy Units Market End-User Demand by Types, Regions, Top Players, Service Provides, Regional Outlook and Forecast to 2028") or one of the new third party organisations. [PSD2 also states that for authentication](https://www.financedigest.com/psd2-merchants-must-regain-checkout-control-through-delegated-authentication.html "PSD2: Merchants Must Regain Checkout Control Through Delegated Authentication") to be seen as ‘strong’, it must not be replicable. This will prevent fraudsters from simply copying [authentication data to get a successful payment](https://www.financedigest.com/the-key-trends-in-payment-authentication.html "The key trends in payment authentication").  This is positive news for everyone involved in the payments process, and for the first [time sets common standards on how banks can verify their customers’ identities](https://www.financedigest.com/how-omnichannel-identity-servers-help-enterprises-enhance-customer-experience-unlock-cost-savings-and-accelerate-time-to-market.html "How omnichannel identity servers help enterprises enhance customer experience, unlock cost savings and accelerate time to market").

So why is this needed? Cybercrime is [already a huge problem for the banking](https://www.financedigest.com/czech-interest-rates-already-at-high-level-central-bank-governor-says.html "Czech interest rates already at high level, central bank governor says") sector, with several high-profile attacks reaping significant rewards for hackers. For example, in 2010, [attackers stole £44 million](http://www.telegraph.co.uk/news/worldnews/europe/ukraine/8038233/70-million-cyber-crime-exposed-by-US-and-European-police.html) in an international operation involving the Zeus Trojan, a computer virus that captured passwords and account details. But as hacking tools become more advanced, these [threats will evolve](https://www.financedigest.com/battling-the-evolving-fraud-threat-the-role-of-the-credit-team.html "Battling the evolving fraud threat: The role of the credit team") into a new generation of attacks that may worsen the already questionable security currently being used. While banks have long prioritised being as user-friendly as possible, the security risks have escalated.

Many banks store user credentials, such as username and password, in whole form and in one central place, [leaving them vulnerable](https://www.financedigest.com/how-remote-hiring-could-leave-fintechs-vulnerable.html "How remote hiring could leave fintechs vulnerable") to being compromised at source or stolen in transit while being sent over the Internet.  Besides the well-known hacking tools, such as malware and Trojans, there is an increasing [trend for attackers to use browser rootkit attacks to enable](https://www.financedigest.com/top-fintech-trends-for-2021-enabling-smart-and-secure-finance.html "Top Fintech Trends for 2021 Enabling Smart and Secure Finance") fraudulent transactions. These are malicious programs that run at the administrative level, usually operating as an extension to a web browser. They are [fully automated and capable of performing fraudulent transactions and covering their traces at the same time](https://www.financedigest.com/is-it-time-for-smes-to-go-fully-cashless.html "Is it time for SMEs to go fully cashless?").  In an online banking transaction, all the [information displayed](https://www.financedigest.com/software-to-display-your-businesss-important-information.html "Software to Display Your Business’s Important Information") on a customer’s PC, including: account numbers, name, balance and transaction details can be leaked by a browser toolkit and sent to an attacker, who can use this information to physically target users, through identity theft techniques.

While many [banks also offer](https://www.financedigest.com/any-business-can-now-offer-their-customers-financial-services-how-embedded-finance-is-reinventing-the-wheel-when-it-comes-to-banking.html "Any business can now offer their customers financial services: How embedded finance is reinventing the wheel when it comes to banking") additional security features such as two-factor authentication, or authentication via SMS text message,this kind of security no longer provides much of an obstacle to attackers.  Two-factor authentication doesn’t protect against browser rootkit attacks, and in addition, hackers can easily hijack [phone numbers](https://www.financedigest.com/your-phone-number-on-google-search-giant-now-takes-removal-demands.html "Your phone number on Google? Search giant now takes removal demands") or intercept text messages, so this kind of authentication is becoming increasingly redundant. This reality led the US government agency responsible for establishing [digital security](https://www.financedigest.com/how-digital-identity-verification-will-revolutionize-security-defenses-in-the-financial-services-industry.html "How Digital Identity Verification Will Revolutionize Security Defenses in the Financial Services Industry") guidelines, the National Institute of Standards and Technology, (NIST), to announce that it would no longer be recommending the practice of SMS-based authentication.

As a result of these factors, the PSD2 guidelines require each payment initiation [service provider](https://www.financedigest.com/high-energy-shockwave-therapy-units-market-end-user-demand-by-types-regions-top-players-service-provides-regional-outlook-and-forecast-to-2028-2.html "High Energy Shockwave Therapy Units Market End-User Demand by Types, Regions, Top Players, Service Provides, Regional Outlook and Forecast to 2028") to have strong customer authentication processes in place, by establishing: something a user knows (such as a PIN number or username), something they have (such as a token); and something they are (such as biometric authentication).  This is good news for all concerned because it will reform the payments industry and encourage new [technologies and innovations](https://www.financedigest.com/marine-mining-market-expand-substantially-owing-to-technological-innovations-during-2018-2026.html "Marine Mining Market Expand Substantially Owing to Technological Innovations During 2018-2026") that will help to keep users more secure, while keeping the end-user experience simple and straightforward.

In the last few weeks, [Mastercard](http://www.theregister.co.uk/2016/10/05/mastercard_selfie_pay/) and Lloyds have announced that they are testing a range of new authentication methods, such as ‘selfie pay’ facial identification, and it’s exciting to see what other types of authentication will soon become more mainstream.The truth is, [real digital](https://www.financedigest.com/the-real-time-pcr-qpcr-market-to-get-digitally-innovative.html "The Real-Time PCR (qPCR) Market to get digitally innovative") security requires the complete elimination of centralised security systems.  For example, MIRACL’s zero-factor authentication allows customers to authenticate using a secure app on their mobile device, like an ATM machine, rather than a username and password, and never sends authentication credentials across the web for storage in the cloud.

By regulating new [Payment Institutions](https://www.financedigest.com/how-payment-institutions-can-leverage-data-to-support-merchant-customers.html "How payment institutions can leverage data to support merchant customers"), the Directive will also accelerate competition across the industry, helping to drive innovation and develop new methods which will make the entire payments industry a safer place for all concerned.

[www.miracl.com](http://www.miracl.com)


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

