FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

Open banking: Balancing innovation with security

Open banking sector to be worth $43.15B by 2026

Prakash SinhabyPrakash Sinha
May 24, 2022
in Risk & Security
Reading Time: 4 mins read
0
Share on Facebook

After years of stop-start evolution, the market boom that open-banking advocates have been waiting for appears to be underway. The potential of this sector is as large as it is untapped with the sector projected to be worth $43.15 billion by 2026, equivalent to an annual growth rate from 2019 upwards of 24%.

Open banking provides a way for traditional banks to share customer transactions and financial information via application programming interfaces (APIs) to non-bank, neo-banks and third parties. This allows market disruptors to offer new services, such as real-time transfers between accounts, online mortgage payments, buy-now-pay-later options and nearly instantaneous personal credit, innovations mainstream banks have been slow to adopt.

Prakash Sinha, senior director at Radware
Prakash Sinha, senior director at Radware

What the optimists don’t always mention, however, is how this new era of API access will be secured. This follows a cycle experienced by almost every significant technology of the internet age. A new technology is proposed and enthusiastically embraced. As its popularity increases, bad actors probe for ways to abuse and misuse it at which point some of the good feelings evaporate. The industry finds itself retrofitting security from a position that gives gifted attackers a head start.

Gartner predicts that API abuses and related breaches will nearly double over the next two years. It also forecasts that in 2022, the API interface attack will be the most frequent attack vector causing breaches for enterprise web applications.

APIs, then, offer tremendous benefits but introduce service availability and security concerns that consumers and financial institutions alike must be aware of. This includes service disruption, trust issues, an increased attack surface, data theft, and manipulation of the APIs themselves.

The power of APIs

Open-banking APIs allow smaller financial institutions to compete with large banks while democratizing digital services. Equally, traditional institutions can also compete with the nimbler neo-banks which means that open banking is an opportunity as well as a threat. In 2022, expect to see community banks and credit unions partner with fintechs that use open-source technology to overcome their legacy infrastructure challenges and provide better digital experiences.

Open banking makes possible innovations, such as consumers being able to use a single app to view all their financial accounts at different institutions, while making it much easier to shop around for and compare different financial services. Instead of filling in separate forms and enduring arduous credit scoring with every institution, consumers can simply give institutions temporary access to their financial history through APIs. Businesses, meanwhile, can assess new customers rapidly and accurately, making possible new types of lending, remittance, mortgage and insurance products.

Open banking complexity

API-driven services sound like a radical simplification, but they are built on top of a complex and potentially vulnerable infrastructure. The first layer of this is simply the number of players on which the ecosystem depends. These include:

  • Payment Service User (PSU): Consumer initiating a transaction;
  • Account Information Service Providers (AISPs): Registered account aggregators authorized by the customer to use (but not modify) customers’ bank account data;
  • Payment Initiation Service Providers (PISPs): Registered providers allowed by the consumer to initiate payments directly from a customers’ bank account;
  • Account Servicing Payment Service Providers (ASPSPs): Banks responsible for making APIs available to third-party providers; and
  • Regulatory Authorities: Policymakers that regulate banking and promote competition, data sharing and security.

Expanding attack surface

The second area of vulnerability is that the APIs and the access they allow will be abused. Top concerns include:

Service disruption: Dependence on third-party APIs and components may lead to unintended service disruptions. For example, API services may become unavailable due to security, network and application configuration errors, API denial of service attacks, or application or authentication infrastructure outages.

Trust issues: Many solutions for open banking are built on cloud-only or hybrid infrastructures. However, migration to public clouds creates trust issues. These include incompatibility of security solutions, configuration challenges across different environments, misconfigurations, and issues around application security policies and profiles.

API attack surface: API attacks and vulnerabilities are not uncommon. A survey by Radware revealed that 55% of organizations experience DoS and bot attacks against their APIs at least monthly; 48% receive some form of injection attack at least monthly; and 42% experience an element or attribute manipulation at least monthly.

Data theft: Many APIs process sensitive personally identifiable information (PII). The combination of sensitive and confidential information coupled with the lack of visibility into how these APIs and third-party applications operate are a security nightmare in the case of a breach.

Undocumented but published APIs: Undocumented APIs may accidently expose sensitive information if not tested and may be open to API manipulations and vulnerability exploits.

Fraud against consumers: In the worst-case scenario, attackers might be able to clean out a customer’s account or steal data, resulting in serious data breaches.

Preparing for the future

The industry must develop a comprehensive security strategy before diving in too deeply to reap the benefits of open banking. This requires numerous controls which are not always present in today’s general-purpose security products, including web application firewalls (WAFs) and API gateways, legacy technologies designed to cope with security issues that long pre-date open banking.

Overcoming this problem demands a next generation of dedicated defenses, such as web application and API protection (WAAP) systems, which make it possible to enforce security policies on APIs, and aid compliance with the growing number of regulatory frameworks.

Meanwhile, to secure and scale the APIs to handle more users and transactions while allowing access to third parties, traditional institutions need to invest in cloud deployments, application and infrastructure security, and service scalability. Only with a multi-layered safety net will banks and fintechs be able to maximize the huge potential of open banking in a way customers trust while keeping cybercriminals at bay.

Prakash Sinha is senior director and technology evangelist, application security and delivery at Radware. He has more than 30 years’ experience in strategy, product management, product marketing and engineering. Prakash previously led product management for Citrix NetScaler and was instrumental in introducing multitenant and virtualized NetScaler product lines to market.

 

Tags: open bankingPremium
Previous Post

JPMorgan Chase allocates nearly half of infrastructure spend to cloud

Next Post

Transactions: Scienaptic AI, Teslar Software continue run of community bank wins

Related Posts

data streams being bottlenecked
Risk & Security

Implementing AI can relieve bottlenecks amid growing AML complexity

July 20, 2026
A flag displaying Capital One's logo
Risk & Security

Capital One’s Evan Baker to speak at FinAi Lending Summit

July 20, 2026
fintech icon on abstract financial technology background
Risk & Security

Q&A with Luis Pinedo on his move from Santander to ThetaRay

July 13, 2026
Next Post
Transactions: Scienaptic AI, Teslar Software continue run of community bank wins

Transactions: Scienaptic AI, Teslar Software continue run of community bank wins

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account