TL;DR: Risk-based authentication still depends on step-up methods like OTPs and push approvals that can be phished, intercepted, or socially engineered, while attackers increasingly use AI-enabled impersonation and session abuse to bypass them, according to iProov. The real gap is assurance, not challenge frequency: organizations need identity verification that confirms who is behind the login, not just which factor was presented.
Editorial analysis by NHI Mgmt Group, based on content published by iProov: “Deliver a Robust Risk-based Authentication Strategy When MFA Is Failing”.
Key questions
Q: What breaks when risk-based authentication still relies on OTPs and push approvals?
A: The control breaks when it assumes factor completion equals identity verification.
Q: Why do weak step-up factors increase account takeover risk in high-risk login flows?
A: Because they create a false sense of assurance.
Q: How can security teams know if step-up authentication is actually working?
A: Look for reduced fraud on high-risk transactions, fewer successful account changes after suspicious device or location shifts, and clear evidence that server-side decisions are using multiple signals.
Practitioner guidance
- Define high-risk login triggers Map the access moments where factor proof is no longer sufficient, such as account recovery, privileged access, new device authorization, and anomalous geolocation.
- Replace weak step-up methods Move the highest-risk flows away from OTPs, push approvals, and security questions when the organisation needs identity assurance rather than a second prompt.
- Prioritise liveness-based verification Require biometric controls that verify a live person, not just image matching, and use passive methods where possible to limit user friction.
Bottom line: Risk-based authentication can reduce friction, but it does not solve the problem of proving who is behind the login when the step-up method is weak.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Risk-based authentication only works when the step-up mechanism raises assurance, not just friction. Many programmes still treat OTPs and push approvals as evidence that the right person is present, but those methods mainly prove possession or response. Once the attacker can intercept the factor or coerce the approval, the control has already failed at the identity layer. The practitioner conclusion is to stop equating challenge frequency with trustworthiness.
A few things that frame the scale:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
A question worth separating out:
Q: Should organisations use biometrics or help desk verification for account recovery?
A: They solve different problems. Biometrics are better when the organization needs to verify the real person remotely, while help desk verification can still play a role in escalations that require human review. The key decision is whether the recovery event creates enough fraud risk to justify live person verification before access is restored.
👉 Read our full editorial: Biometric verification closes the RBA assurance gap in high-risk login