• | 9:00 am

Why customer experience is the missing piece in cybersecurity

Fraud prevention cannot end with a blocked payment. The test is how a bank contains the risk, explains what happened, and helps the customer recover.

Why customer experience is the missing piece in cybersecurity
[Source photo: Krishna Prasad/Fast Company Middle East ]

Many people don’t realize how much they rely on their service provider to keep their digital lives safe, leaving them vulnerable to cyberattacks. Cybersecurity often appears to customers as a series of small obstacles: a CAPTCHA, an authenticator prompt, a delayed payment, or a transaction they must confirm twice. The real test comes after a scam, when a bank has to explain what happened, secure the account, and give the customer a clear route to resolution.

This is a real concern in banking. It’s at the heart of how banks try to prevent fraud, and according to Morey Haber, Chief Security Advisor at BeyondTrust, most banks still don’t get it right.

“CX is important for any service provider,” says Gonçalo Magalhães, Head of Security at Immunefi. 

He adds that CX is even more crucial in the cybersecurity industry. “Given the nature of what is at stake: trusting the provider with some of the most sensitive data and access to the customer.” 

“So a proper service experience is adamant about building that trust and making the customer not just be secure, but also feel secure,” Magalhães adds.

DETECTION IS THE START 

When fraud is detected, the customer may already have clicked, authenticated, or transferred money. That makes detection a trigger for response, not a finish line.

“Detection should be the beginning of the response, not the end,” he says. “Once fraud is identified within a banking identity, cybersecurity providers should help establish what identity, device, credential, session, or authorization mechanism was compromised and provide the telemetry necessary to contain the incident quickly and prevent it from happening to others.”

This approach involves what he calls rapid credential revocation, session termination, account protection, evidence preservation, and investigation. The goal, he says, is not just to say, ‘We detected fraud.’ It’s to stop one successful scam from leading to more and to protect customers from ongoing fraud.

“Generally speaking, the cybersecurity provider should serve as a partner for detection, mitigation, retrospective, and looking forward,” Magalhães says. 

Agreeing, Haber adds that, depending on the bank, legal rules may require sharing details about the attack with other banks, government agencies, and vendors to help stop similar attacks from spreading.

“A good provider will help the customer leave the engagement with a more robust company security framework, not just know the details of the incident it suffered,” Magalhães adds.

WHERE THE CUSTOMER JOURNEY BREAKS

The traditional cybersecurity journey, Haber says, “focuses heavily on prevention and detection but often underinvests in what happens after the victim clicks, authenticates, transfers money, or leaks credentials (a watering hole attack). That is where the security journey and customer journey frequently diverge. Security teams witness an incident, open an investigation, and the customer sees missing money, compromised trust, and uncertainty about what happens next. “

Effective fraud protection should integrate detection, identity security, investigation, problem resolution, and customer communication into a single process. But this doesn’t mean sharing everything. Instead, banks should reassure customers that they are protected against future attacks and that any missing funds have been returned, regardless of how they were lost or insured.

In the end, Haber says, what’s most often missing is good communication with customers, resolving their issues, and making sure they’re satisfied.

THE NEED OF THE HOUR

When something goes wrong, Haber says recovery depends on three things: speed, context, and automation.

Banks should give customers enough information to understand who did what, from where, and using which identity, device, and session. Often, just having this information helps fix the problem. Many times, customers can avoid repeating a mistake if they know what happened. This might include simple steps such as changing compromised passwords or removing malware from their devices.

Haber adds that it’s just as important for fraud and customer service teams inside the bank to get this information. Customers shouldn’t have to explain the same scam over and over because different teams aren’t sharing what they know or aren’t prepared to help others who face the same kind of attack.

AUTHENTICATION IS NOT INTENT

Haber says the toughest problem in banking fraud today is that authentication doesn’t always show intent. For example, someone tricked by an authorized push payment scam might log in correctly, use their usual device, and approve the transaction themselves. On the surface, everything looks normal. 

He highlights four warning signs: whether the beneficiary is new, whether the transaction is unusual in value, destination, or timing, whether the customer suddenly broke from established behavior, say, paying a new vendor instead of a familiar one, and whether there was suspicious account activity just beforehand, such as balance verification, a new device login, or impossible travel. Strong fraud detection, he says, has to weigh identity, device, behavior, transaction context, and risk together. The question shifts from “Was this really the customer?” to “Does this transaction make sense for this customer?” In the end, he argues, the difference comes down to behavior, not authentication.

THE CASE FOR INTELLIGENT FRICTION

This brings us back to CAPTCHA. Haber says customer experience is crucial because security controls always involve people. If there’s too much friction, users try to get around the controls. If there’s too little, fraud becomes easier.

He says the goal is to create ‘intelligent friction.’ This means adding extra verification only when risk increases, while letting normal activity proceed smoothly. For banks, this involves using identity checks and behavioral analysis to ensure transactions are legitimate.

This also means cybersecurity does more than just protect transactions. It also helps maintain trust between the bank and the customer. In financial services, that trust is one of the most valuable things to protect. A simple user experience that rewards good behavior will always attract customers more than complicated, strict processes that aim for perfect security.

  Be in the Know. Subscribe to our Newsletters.

ABOUT THE AUTHOR

Rachel Clare McGrath Dawson is a Senior Correspondent at Fast Company Middle East. More

FROM OUR PARTNERS