Loading...

Account Takeover: The Defense in Depth Strategy

Published: December 22, 2020 by Guest Contributor

Preventing account takeover (ATO) fraud is paramount in today’s increasingly digital world. In this two-part series, we’ll explore the benefits and considerations of a Defense in Depth strategy for stopping ATO.

The challenges with preventing account takeover

Historically, managing fraud and identity risk in online banking has been a trade-off between customer experience and the effectiveness of fraud controls. The basic control structure relies on a lock on the front door of online banking front door—login—as the primary authentication control to defend against ATO.

Within this structure, there are two choices. The first is tightening the lock, which equals a higher rate of step-up authentication challenges and lower fraud losses. The second is loosening the lock, which results in a lower challenge rate and higher fraud loses. Businesses can layer in more controls to reduce the false positives, but that only allows marginal efficiency increases and usually represents a significant expense in both time and budget to add in new controls.

Now is the perfect time for businesses reassess their online banking authentication strategy for a multitude of reasons:

  • ATO is on the rise: According to Javelin Strategy & Research, ATO increased 72% in 2019.1
  • Users’ identities and credentials are at more risk than ever before: Spear phishing and data breaches are now a fact of life leading to reduced effectiveness of traditional authentication controls.
  • Online banking enrollments are on the rise: According to BioCatch, in the months following initial shelter-in-place orders across the country, banks have seen a massive spike in first time online banking access.
  • Users expect security in online banking: Half of consumers continue to cite security as the most important factor in their online experience.

Businesses who reassess the control structure for their online banking will increase the effectiveness of their tools and reduce the number of customers challenged at the same time – giving them Defense in Depth.

What is Defense in Depth?

Defense in Depth refers to a strategy in which a series of defense mechanisms are layered in order to protect data and information.

The basic assumptions underlying the value of a Defense in Depth strategy are:

  • Different types of transactions within online banking have different levels of inherent risk (e.g., external money movement is considerably higher risk compared to viewing recent credit card transactions)
  • At login, the overall transaction risk associated with the session risk is unknown
  • The risk associated with online banking is concentrated in relatively small populations – the vast majority of digital transactions are low risk

This is the Pareto principle at play – i.e., about 80% of online banking risk is concentrated within about 20% of sessions. Experian research shows that risk is even more concentrated – closer to >90% of the risk is concentrated in <10% of transactions. This is relatively intuitive, as the most common activities within online banking consist of users checking their balance or reviewing recent transactions. It is much less common for customers to engage in higher risk transaction. The challenge is that businesses cannot know the session risk at the time of challenge, thus their efficiency is destined to be sub-optimal.

The benefits of Defense in Depth

A Defense in Depth strategy can really change the economics of an online banking security program. Adopting a strategy that continuously assesses the overall session risk as a user navigates through their session allows more efficient risk decisions at moments that matter most to the user. With that increased efficiency, businesses are better set up to prevent fraud without frustrating legitimate users.

Defense in Depth allows businesses to intelligently layer security protocols to protect against vulnerability – helping to prevent theft and reputational losses and minimize end-user frustration. In addition to these benefits, a continuous risk-based approach can have lower overall operational costs than a traditional security approach.

The second part of this series will explore the cost considerations associated with the Defense in Depth strategy explored above. In the meantime, feel free to reach out to discuss options.

Contact us

1Identity Fraud in the Digital Age, Javelin Strategy & Research, September 2020

Related Posts

Day 1 of Vision 2025 is in the books – and what a start. From bold keynotes to breakout sessions and networking under the Miami sun, the energy and inspiration were undeniable.&nbsp; A wave of change: Jeff Softley opens Vision 2025&nbsp; The day kicked off with a powerful keynote from Jeff Softley, Experian North America CEO, who issued a call to action for the industry: to not just adapt to change, but to lead it.&nbsp; “It isn’t a ripple – it’s a tidal wave of technology,” Jeff said. “Together we ride this wave with confidence.”&nbsp; His keynote set the tone for a day centered on innovation and the future of financial services – where technology, insight and trust converge to create lasting impact. Jeff continues this conversation in the latest Experian Exchange episode, where he explores three forces shaping the industry: the rise of AI, the demand for personalized digital experiences and the mission to expand credit access for all.&nbsp; Turning vision into action: Alex Lintner on agentic AI&nbsp; Building on Jeff’s message, Alex Lintner, CEO of Experian Software and Technology, took the stage to show how Experian is turning innovation into measurable results. His keynote explored how agentic and advanced AI capabilities are redefining financial services ROI and powering the next generation of the Ascend Platform™.&nbsp; For a deeper look into how Experian is reshaping the economics of credit and fraud decisioning, read the latest American Banker feature.&nbsp; Unfiltered insights from “Mr. Wonderful”&nbsp; The day’s highlight came from Kevin O’Leary, investor, entrepreneur and the always-candid “Mr. Wonderful.” With his trademark wit and honesty, Kevin shared sharp insights on thriving in a disruptive economy, offering candid advice on leadership, risk and opportunity. He even gave attendees a peek behind the Shark Tank curtain, revealing a few surprises and the mindset that drives his bold business decisions.&nbsp; Breakouts that inspired and informed&nbsp; The conference floor buzzed with energy as attendees joined breakout sessions on fraud defense, AI-driven personalization, regulatory trends and consumer insights. Sessions highlighted how Experian’s unified value proposition is fueling double-digit growth, how to future-proof credit risk strategies and how data and innovation are redefining customer engagement across the lifecycle. &nbsp; Hands-on innovation and connection&nbsp; The Innovation Showcase gave attendees an up-close look at Experian’s latest tools and technologies in action. Meanwhile, friendly competition kept the excitement high through the Vision mobile app leaderboard – with every check-in and connection earning points toward the top spot.&nbsp; Networking beyond the conference hall walls&nbsp; As the sun set, Vision 2025 shifted into high gear with unforgettable networking events across Miami – from golf at the Miller Course to art walks, brewery tours and a scenic cruise through Biscayne Bay. &nbsp; An evening to remember&nbsp; The day closed with the first-ever Vision Awards Dinner, celebrating standout leaders who are shaping the future of financial services. &nbsp; Up Next: Day 2&nbsp; The momentum continues tomorrow as more keynote speakers take the stage. Stay tuned for more insights, innovation, and inspiration from Vision 2025.&nbsp;

Published: October 7, 2025 by Sharis Rostamian

Discover how data-driven risk management strategies are transforming credit risk management in the fintech industry.

Published: October 7, 2025 by Theresa Nguyen

Tenant screening fraud is rising, with falsified paystubs and AI-generated documents driving risk. Learn how income and employment verification tools powered by observed data improve fraud detection, reduce costs, and streamline tenant screening.

Published: September 4, 2025 by Ted Wentzel

Subscribe to our blog

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Experian Insights blog

Don't miss out on the latest industry trends and insights!
Subscribe