Automatic (machine) translation. This text was translated automatically from the Polish original and may contain inaccuracies. In case of any doubt, the Polish version is the authoritative one.
← Back to Knowledge
Knowledge

Which tools protect bank customers from cybercrime?

Which tools protect bank customers from cybercrime?

Contemporary financial institutions operate in an environment of constantly growing cyber-attack risk. In response to this challenge, banks implement a range of advanced technologies and detection methods aimed at protecting customers' funds and data. From anomaly-detection systems to artificial intelligence – modern banking also means advanced cyber-protection.

Below we present the most important technologies and tools that a modern bank should have in order to effectively counter financial fraud.

1. Anomaly Detection Engines

Banks analyse patterns of customer behaviour, including:

  • login locations,
  • hours of activity,
  • typical devices and browsers,
  • transaction patterns.

When unusual activity is detected (e.g. a login from Russia, a transfer to an unknown account just after a device change), the systems generate alerts or automatically block the operations.

Popular solutions used in banking systems:

  • SAS Fraud Management
  • Actimize (NICE)
  • FICO Falcon Fraud Manager
  • Feedzai

2. Machine learning and artificial intelligence (AI/ML)

These systems learn a customer's individual patterns (so-called behavioural biometrics), which makes it possible to:

  • detect "fraud in real time",
  • distinguish the customer from a person impersonating them,
  • analyse unusual sequences of actions (e.g. a rapid device change and a transfer of funds).

Example: AI may notice that a customer always logs in from Warsaw, and suddenly someone logs in from Moscow and adds a new device – this is a signal for immediate action.

3. Strong authentication and access management (SCA & IAM)

Under the PSD2 directive, banks must apply Strong Customer Authentication (SCA), i.e.:

  • something the customer knows (a password),
  • something they have (e.g. a phone),
  • something they are (biometrics) — whereby SCA requires confirmation of at least two of these three independent categories (PSD2).

In addition, IAM (Identity & Access Management) systems control who has access to banking resources and how – including within the institution.

4. Geolocation and geofencing

Many banks use geofencing, a mechanism that compares the customer's location with the place of login and transaction. When the locations do not match or an unexpected login from another country appears, the operation may be:

  • flagged as suspicious,
  • rejected,
  • subjected to additional verification steps.

Geofencing is not mandatory by law, but its use follows from the obligation to apply appropriate security measures – which in practice may mean that it has to be implemented, especially in banking.

5. Device Fingerprinting – identifying devices

The systems recognise:

  • the phone model,
  • the operating system,
  • the browser version,
  • the screen resolution,
  • unique features of the device.

As a result, if a customer usually uses an iPhone 13 in Poland, and suddenly a login from a Xiaomi Redmi in Russia occurs, the system should react immediately.

6. SIEM and SOC – real-time monitoring

SIEM (Security Information and Event Management) systems and SOC (Security Operations Center) teams analyse, in real time, huge amounts of log data, alarms and alerts from various sources:

  • account logins,
  • transactions,
  • events from the mobile app.

This allows the rapid detection and analysis of potential security incidents.
Example solutions:

  • IBM QRadar
  • Splunk
  • ArcSight (Micro Focus)
  • Microsoft Sentinel

7. Voice verification and speech analysis (Voice Biometrics)

Modern banking hotlines use:

  • identifying the customer on the basis of their voice,
  • analysing emotions and warning phrases (e.g. "I have lost my data", "my account has been taken over").

This helps to detect impersonation attempts by fraudsters more quickly.

8. A centralised history of risky activities

Banking systems create individual risk profiles of the customer and the transaction, which include:

  • the frequency of device changes,
  • the history of rejected login attempts,
  • appearance on threat lists (e.g. IPs from RBL lists).

9. Inter-bank cooperation and cooperation with law enforcement

Contemporary banks use:

  • threat-information sharing platforms (e.g. CERT, FS-ISAC),
  • automated systems for detecting the convergence of attacks,
  • internal databases of identified fraud patterns.

Summary: technology is not everything

Although banks have extremely advanced tools, their effectiveness depends on:

  • proper implementation,
  • continuous monitoring,
  • and, above all, a genuine willingness to protect the customer, rather than merely formally meeting the regulator's requirements.

In cases where the customer is left without help despite signs of fraud, it is not the technology that fails – it is the institution's process and approach.

Prepared by: Waldemar Chodasiewicz Date prepared: 28 January 2025