ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Open finance is widening the financial sector’s attack surface

As financial data moves between a growing number of banks, insurers, fintechs and technology providers, security will depend on more than protecting the institution that originally collected it.

Linked InXFacebook
bookmark_borderSave to Library

As financial data moves between a growing number of banks, insurers, fintechs and technology providers, security will depend on more than protecting the institution that originally collected it.

 

Open finance promises to give customers greater control over their financial lives by allowing them to share data across banking, insurance, pensions, investments and other services. For providers, the same model could support more personalised products, faster decisions and greater competition.

 

It also changes the boundaries of financial security. A bank may protect its own systems effectively, but open finance requires sensitive information to pass through APIs, identity services, consent platforms and third-party applications. Each connection creates another dependency and another place where security can fail.

 

The European Commission’s proposed framework for financial data access would extend the principles of open banking beyond payment accounts. Customers would be able to authorise third parties to access a much broader range of financial information, while data holders would be required to make it available through standardised technical interfaces.

 

This expansion is intended to give customers more control. In practice, it will also require financial institutions to maintain that control across an increasingly complex ecosystem.

 

More data, more dependencies

 

Open banking has already shown that financial data can be shared securely at scale. The UK now has more than 19 million active open banking connections and processes over 40 million payments through the system each month, according to Open Banking Limited.

 

Its latest fraud monitor found that around one in 6,000 open-banking payments made during 2025 was fraudulent, compared with approximately one in 2,500 payments across the wider payments industry. That is an important counterpoint to claims that greater connectivity is inherently less secure.

 

However, open finance will involve more than payment initiation. It could allow third parties to access information about savings, investments, mortgages, pensions and insurance policies. A compromised account or poorly controlled integration could therefore expose a far more detailed picture of an individual or business.

 

The risk is not limited to a vulnerable API. Institutions must also consider how third parties store the information they receive, which subcontractors can access it and whether permissions remain appropriate after the original service has changed or ended.This makes open finance a supply-chain security issue as much as a data-sharing initiative.

 

The Financial Conduct Authority said that more than 40 per cent of cyber-incidents reported to it in 2025 involved a third party. New reporting rules, which take effect in March 2027, will require firms to provide regulators with clearer information about serious incidents and their external technology arrangements.

 

For procurement and risk teams, identifying a regulated provider will therefore be only the start of due diligence. Firms will need to understand a provider’s technical dependencies, incident-response arrangements, subcontracting chain and ability to revoke access quickly. Contractual assurance will have to be supported by continuous technical oversight.

 

Consent cannot be treated as a checkbox

 

Open finance is built around customer consent, but obtaining permission at the start of a transaction does not guarantee that access will remain appropriate throughout the relationship.

 

A customer may understand that an application needs access to a current account but may be less clear about the consequences of combining transaction histories with pension, insurance and investment data. Even where each use is permitted individually, aggregating the information can reveal patterns that are far more sensitive than any single dataset.

 

Consent must therefore be managed as a lifecycle rather than a one-off authentication event. Customers need to be able to see which organisations can access their information, understand why access was granted and withdraw it without navigating several different platforms.

 

Institutions also need assurance that revocation is enforced throughout the supply chain. Removing a token at the bank does not necessarily delete information already copied into another provider’s systems or passed to one of its suppliers.

 

This is where the boundary between cyber-security, privacy and product governance becomes difficult to maintain. A technically legitimate request may still exceed what the customer reasonably expected, while a compromised third-party account could use valid permissions to retrieve data without exploiting a conventional software vulnerability.

 

Resilience across the ecosystem

 

The security of open finance will ultimately depend on how well institutions can detect and contain problems that begin outside their own infrastructure.

A disruption at an identity provider, cloud platform or API intermediary could affect several financial services simultaneously. In a highly connected market, apparently separate firms may depend on the same small group of technology providers, creating concentration risks that are not visible when suppliers are assessed individually.

 

The UK government intends open banking to provide the foundation for a wider open finance system. Its Payments Forward Plan includes work on long-term open banking rules, stronger regulatory oversight and continued improvements to operational resilience.

 

Financial institutions should not wait for that framework to be completed. They can begin by mapping where shared data travels, testing whether access can be revoked across connected services and establishing who is responsible when an incident crosses organisational boundaries.

 

They should also examine whether monitoring systems can distinguish between normal API activity and the misuse of valid credentials. Rate limits and authentication controls remain essential, but they may not detect a provider extracting more information than expected while operating within its authorised scope.

 

Open finance does not make insecurity inevitable. Open banking’s fraud figures show that well-designed standards, strong authentication and industry collaboration can produce safer payment journeys. Yet the expansion into a much wider range of financial data raises the consequences of weak governance.

 

The central challenge is no longer simply whether an institution can protect the data it holds. It is whether it can remain accountable for that data once access extends beyond its own systems.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543