Industry executives and experts share their predictions for 2022. Read them in this 14th annual VMblog.com series exclusive.
Open banking will push banking institutions to ramp up cloud and application security
By Prakash Sinha, Technology Evangelist and Senior Director, Radware
In 2022, open banking will continue to gain market traction and acceptance in the U.S. as traditional banks and financial institutions compete on customer satisfaction and digital relevance.
Unlike traditional banking where all customer data is controlled by the parent bank, in open banking, customer data is securely exposed to third-party providers via application programming interfaces (APIs) when consent is provided by the customer. The sharing of that data promises to deliver innovative new services and spur competition. However, it also creates a broader threat surface that must be protected against cyber abuse and malice.
Predictions
Mobile banking coupled with a savvy generation of consumers who use fintech applications, like Venmo and Zelle, will drive the growth of open banking products.
These apps, which are built on open banking APIs, will trigger traditional financial institutions to streamline their processes to support digital onboarding and offer innovative mobile financial services.
The benefits of open banking for consumers are clear. It empowers consumers to take control of their finances, making it easier to shop around for competitive financial products and services. Rather than contacting each lender individually for information, consumers can give a fintech lending application temporary permission to audit their financial history and risk profile. In return they get faster, personalized, and competitive quotes from lenders – and simply, a much easier way to compare product offerings and make more-informed decisions.
Mergers and acquisitions will become even more common.
Traditional financial institutions will realize increasing competition from neo banks and nimble fintechs. Acquisitions will become an even more important strategy for innovating and staying relevant.
Open banking will drive new revenue streams for fintechs and traditional financial institutions that engage.
Many traditional institutions will be forced to re-think their existing product portfolio and align with the highly competitive open market. Currently, the cost of credit or debit transactions and mortgages are determined by a small group of large traditional vendors. New entrants and payment platforms are emerging in financial services to disintermediate the existing cost profile by using open banking APIs.
Open banking regulations will push banks and financial institutions to open customer data to fintechs through APIs and increase investments in cloud and application security.
Open banking regulations require that banks make valuable data available via APIs. To secure and scale the APIs to handle more users and transactions as well as provide access to third parties, traditional financial institutions will invest in cloud deployments, application and infrastructure security, and scalability.
While APIs are easy-to-build and easy-to-consume, and enable the sharing of sensitive data between systems, they also introduce availability and security concerns such as:
- Service disruption: Dependence on third party APIs and components may lead to unintended service disruptions if API services are unavailable due to security issues, network and application configuration errors, API denial of service attacks, or application or authentication infrastructure outages.
- Trust issues: Many solutions for open banking are built on cloud-only or hybrid infrastructures. However, migration to public clouds creates trust issues. These include incompatibility of security solutions, configuration challenges across different environments, misconfigurations, and issues around application security policies and profiles.
- Increased attack surface: API attacks are not uncommon. A survey by Radware revealed that 55% of organizations experience a DoS attack against their APIs at least monthly, 48% receive some form of injection attack at least monthly, and 42% experience an element/attribute manipulation at least monthly. Other attacks include API authentication and authorization attacks, embedded attacks such as SQL injection, cross-site scripting (XSS), and bot attacks.
- Bot attacks on APIs: Bot attacks are human-like automated programs scripted to break into user accounts, stealing identities, initiating payment fraud, scraping content such as pricing or data, spreading spam, and impacting legitimate business activities.
- Data theft: Many APIs process sensitive personally identifiable information (PII). The combination of sensitive and confidential information coupled with the lack of visibility into how these APIs and third-party applications operate are a security nightmare in the case of a breach.
- Undocumented but published APIs: Undocumented APIs may accidently expose sensitive information if not tested and may be open to API manipulations and vulnerability exploits.
While open banking is still in its infancy, it is rapidly growing. More consumers are opting in by giving their consent to share data. The banks and fintechs that thrive in this environment in 2022 and beyond will deliver solutions that are secure and win the trust – and ultimately the business – of the consumer.
##
ABOUT THE AUTHOR
Prakash Sinha is a technology executive and evangelist for Radware and brings over 29 years of experience in strategy, product management, product marketing and engineering. Prakash has been a part of executive teams of four software and network infrastructure startups, all of which were acquired. Before Radware, Prakash led product management for Citrix NetScaler and was instrumental in introducing multi-tenant and virtualized NetScaler product lines to market. Prior to Citrix, Prakash held leadership positions in architecture, engineering, and product management at leading technology companies such as Cisco, Informatica, and Tandem Computers. Prakash holds a Bachelor in Electrical Engineering from BIT, Mesra and an MBA from Haas School of Business at UC Berkeley.






