Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Finance > NEW EU REGULATIONS FOR ONLINE PAYMENTS: WHY PSPS SHOULD CONSIDER SMS-BASED TWO FACTOR AUTHENTICATION
    Finance

    NEW EU REGULATIONS FOR ONLINE PAYMENTS: WHY PSPS SHOULD CONSIDER SMS-BASED TWO FACTOR AUTHENTICATION

    NEW EU REGULATIONS FOR ONLINE PAYMENTS: WHY PSPS SHOULD CONSIDER SMS-BASED TWO FACTOR AUTHENTICATION

    Published by Gbaf News

    Posted on February 13, 2015

    Featured image for article about Finance

    By Thorsten Trapp, CTO and co-founder, tyntec

    Concerned about the increase in internet fraud related to online payments, the European Banking Authority (EBA) recently decided that the implementation of a more secure framework for internet payments across the EU was needed. Released in December 2014, the EBA’s guidelines on the security of internet payments set out the minimum requirements that Payment Services Providers (PSPs) in all 28 EU member states will be expected to implement by 1 August 2015.

    The guidelines require that PSPs “carry out strong customer authentication” to verify the identity and intentions of all customers in online transactions. This is a welcome development as the latest pan-EU figures showed that fraud on card internet payments alone caused €794 million of losses in 2012 (up by 21.2% from the previous year.

    “Strong customer authentication” is defined as something that employs the use of two or more elements to verify a person’s identity, so two-factor authentication is an obvious choice as a minimum standard.

    What is two-factor authentication?

    Two-factor authentication (2FA)is a security process in which the user is asked to provide two means of identification in order to access private information or complete a task, such as an online payment. Typically, the process will require the user to make use of something they “have” such as a physical object, like a phone or a token, or a unique physical identifier, like a fingerprint, in addition to offering up information they “know”, like a password.

    Choosing the right solution

    Thorsten Trapp

    Thorsten Trapp

    The EBA’s guidelines stipulate that the authentication method usedmust meet the following criteria: “mutually independent”, “not reusable”, “non-replicable” and “cannot be stolen off the internet”. This means that while there are many different types of two-factor authentication, not all methods are compliant. In addition, PSPs will need to consider specific requirements determined by country-level mandates and will want a solution that is easy to use,cost-effective and easy to deploy.

    Biometric data is one example which offers a strong authentication method but poses usability problems in a mobile environment and can cause issues related to data protection and privacy.Fingerprints can occasionally become unreadable due to cuts or bruises and glasses can prevent an iris from being recognised.No doubt this technology will improve with time but in its current form there is a distinct lack of understanding and practicality which makes it a difficult investment for PSPs to commit to in order to meet stipulated guidelines.

    In contrast, SMS-based 2FA is one solution which PSPs can viably consider investing in now due to its user friendly nature, economic cost structure and security effectiveness. Practically, this solution involves sending a One-Time Password (OTP) via SMS to a registered mobile number – a process consumers are already familiar with in their day-to-day lives. It requires the end-user to enter his or her password online after which they will receive an OTP in the form of a text message which can be entered to complete the authentication process. As a result, OTP SMS, an out-of-band two-factor authentication, meets the EBA’s security requirements of “strong customer authentication”and is user friendly, universally accessible, simple to deploy, and cost effective.

    Given the expansive reach and ubiquity of SMS, sending security codes via this medium provides an effective solution for service providers looking to provide increased security for their customers whilst adhering to the EBA’s guidelines.

    The SMS-based 2FA implementation challenge

    The EBA’s guidelines will no doubt spark a flurry of activity as PSPs look to strengthen their online security measures. However, it’s important that companies take the time to carefully consider how they can effectively deploy an SMS-based 2FA strategy.

    From an implementation standpoint, PSPs would be wise to work with OTP SMS specialists who can handle the mission-critical nature of the messaging service in terms of speed, delivery rate and coverage.Using SMS-based 2FA as an example, working with a reputable provider will ensure that you have access to a strong infrastructure in order to transmit SMS traffic securely and can provide real-time visibility checks of whether a mobile number is valid or not. This significantly reduces the likelihood of OTP failure making the solution significantly more effective for those using it.

    With the guidelines due to come into force in August, there really isn’t much time before we start seeing a major step forward in the levels of security implemented by websites and online services. These regulations will put the idea of strong online security measures firmly in the minds of PSPs and cause them to look at how they can implement effective 2FA strategies in order to adhere to the guidelines of the EBA,or risk having to justify their non-compliance.

    Related Posts
    Russian ban on Roblox gaming platform sparks rare protest
    Russian ban on Roblox gaming platform sparks rare protest
    UK's Starmer and EU's von der Leyen discuss Ukraine peace plan, frozen Russian assets
    UK's Starmer and EU's von der Leyen discuss Ukraine peace plan, frozen Russian assets
    Thousands march in Hungary in protest over child abuse scandal
    Thousands march in Hungary in protest over child abuse scandal
    US says Belarus agreed to stop balloon flyovers into Lithuania
    US says Belarus agreed to stop balloon flyovers into Lithuania
    Ukraine says Russian drone attack hit civilian Turkish vessel
    Ukraine says Russian drone attack hit civilian Turkish vessel
    Who are the most prominent prisoners released by Belarusian president Lukashenko?
    Who are the most prominent prisoners released by Belarusian president Lukashenko?
    Spanish police bust gang that used helicopters to fly drugs from Morocco
    Spanish police bust gang that used helicopters to fly drugs from Morocco
    Lukashenko frees Nobel winner Bialiatski and key Belarus opposition figures in deal with US
    Lukashenko frees Nobel winner Bialiatski and key Belarus opposition figures in deal with US
    EU countries agree 2026 fishing quotas, avoid tighter Mediterranean curbs
    EU countries agree 2026 fishing quotas, avoid tighter Mediterranean curbs
    New Czech prime minister rejects guarantees for Ukraine loan
    New Czech prime minister rejects guarantees for Ukraine loan
    Ukraine's Odesa suffers major blackouts after Russian attack
    Ukraine's Odesa suffers major blackouts after Russian attack
    Bitcoin hoarding company Strategy remains in Nasdaq 100
    Bitcoin hoarding company Strategy remains in Nasdaq 100

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Finance

    Explore more articles in the Finance category

    North Korean leader Kim hails troops returning from Russia mission, state media says

    North Korean leader Kim hails troops returning from Russia mission, state media says

    Spain urges EU not to weaken 2035 combustion engine ban, letter shows

    Spain urges EU not to weaken 2035 combustion engine ban, letter shows

    EU vote on Mercosur trade deal set for next week, Denmark says

    EU vote on Mercosur trade deal set for next week, Denmark says

    King Charles says his treatment for cancer can be reduced in the new year

    King Charles says his treatment for cancer can be reduced in the new year

    Juventus 'not for sale' say Agnellis, rejecting crypto giant Tether's bid

    Juventus 'not for sale' say Agnellis, rejecting crypto giant Tether's bid

    Ukraine hits Russian oil infrastructure in Caspian for second time

    Ukraine hits Russian oil infrastructure in Caspian for second time

    EU, India unlikely to finalize trade agreement by end of year, Bloomberg News reports

    EU, India unlikely to finalize trade agreement by end of year, Bloomberg News reports

    Explainer-What are the legal risks of EU's 'reparations loan' for Ukraine?

    Explainer-What are the legal risks of EU's 'reparations loan' for Ukraine?

    Ice-cream spin-off turns up heat on Unilever to deliver on growth, margins

    Ice-cream spin-off turns up heat on Unilever to deliver on growth, margins

    Google faces $129 million French asset freeze after Russian ruling, documents show

    Google faces $129 million French asset freeze after Russian ruling, documents show

    Hundreds of storks found dead near Madrid amid wider bird flu surge

    Hundreds of storks found dead near Madrid amid wider bird flu surge

    EIB to boost lending for EU defence projects in 2026

    EIB to boost lending for EU defence projects in 2026

    View All Finance Posts
    Previous Finance PostCUT RISK OF FRAUDSTERS INTERCEPTING EMAILS TO STEAL MONEY
    Next Finance PostEMAIL-BORNE CYBER-ATTACKS IN THE FINANCIAL SECTOR