Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› How should financial institutions reduce the risk of…
Threats, Abuse & Incident Response

How should financial institutions reduce the risk of phishing and device-based intrusions across employees and customers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Threats, Abuse & Incident Response

Financial institutions should combine continuous user education with layered endpoint protection and tighter device governance. The article points to phishing, watering hole attacks, mobile devices, and BYOD as common entry points, so security teams need recurring awareness training, safer access practices, and controls that keep compromised devices from becoming easy paths into customer data and internal systems.

Why phishing and device compromise need to be treated as one control problem

For financial institutions, phishing is rarely just an email problem and device-based intrusion is rarely just an endpoint problem. The real risk is the handoff: a convincing lure reaches a user, a managed or unmanaged device is used to complete the action, and the attacker then exploits trust in the user, the session, or the device to move toward payments, customer data, or internal systems.

That is why employee and customer protection have to be designed together. The same control stack should reduce exposure to credential theft, session hijacking, malicious app installation, drive-by compromise, and unsafe access from personal devices that are outside normal corporate supervision.

Institutions that separate “awareness” from “endpoint security” usually miss the point. A user who recognises a phish can still be compromised by a malicious device state, and a hardened endpoint can still be defeated if users are steered into approving the wrong login, consent, or payment action.

How layered defenses reduce the attack window

A practical programme combines awareness, prevention, and containment. User education matters most when it is recurring, scenario-based, and tied to the actual fraud and intrusion paths the institution sees. That includes phishing, smishing, fake support contacts, malicious QR codes, watering hole links, and prompts that push users to bypass normal verification.

Technical controls should reduce the value of a successful lure. Strong authentication, phishing-resistant sign-in methods where feasible, conditional access, endpoint detection, and rapid session revocation all limit what an attacker can do after the first click. For customer-facing channels, the goal is not only stopping the fake login page, but also making stolen credentials or a stolen device much less useful.

Device governance closes the gap between trusted users and untrusted hardware. Financial firms should know which devices are allowed, what security baseline they meet, whether they are encrypted and patched, and whether risky combinations such as jailbroken phones, rooted devices, or unapproved browsers are blocked or stepped up for verification. The point is to keep a compromised device from becoming a shortcut into regulated data or transactional authority.

What strong practice looks like for employees and customers

Employees usually need the strictest controls because they can reach internal systems, privileged functions, and sensitive customer workflows. Customers need controls that are simple enough to use, but still resistant to account takeover and device compromise. That often means different friction levels, not different standards of care.

Institutions should align controls to the access path. If a customer signs in from a risky device or unusual location, step-up checks may be appropriate. If an employee device shows signs of compromise, the response should be faster and more disruptive, because the potential blast radius is larger. NIST SP 800-63 Digital Identity Guidelines is useful here because it reinforces how authenticator strength and phishing-resistant methods change the confidence of the sign-in process.

Good programmes also make it easy to report suspicious activity. The best employee training is the kind that shortens time to report, while the best customer controls are the ones that make unusual prompts, device changes, and transaction changes visible before money or data leaves the institution. NCSC UK Advice and Guidance remains a solid reference point for remote access, user-facing security, and operational guidance that supports this kind of layered defence.

Risk and Threat Considerations

Phishing and device-based intrusion reinforce each other. A stolen credential, a fraudulent consent action, or a compromised phone can be enough to bypass weak monitoring and create a trusted session that looks legitimate until funds move or data is exfiltrated. In financial services, that can quickly turn into fraud, account takeover, malware installation, or lateral movement into internal environments.

Failure mechanism: Attackers exploit the weakest trust point, such as a user’s response to a lure, a reused password, a stale session, or an unmanaged device that lacks modern security posture checks. Once inside, they aim to keep access through tokens, persistence on the endpoint, or repeated social engineering.

Impact: The institution may face customer loss, operational disruption, transaction abuse, incident response costs, and regulatory scrutiny. The larger the population of employees and customers, the more a single missed control can scale into repeated compromise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesPhishing-resistant authentication and assurance levels directly affect this login-risk problem
Recommendation — Prefer phishing-resistant authenticators and step-up assurance for risky sign-ins.
CIS Controls v8CIS-6 — Access Control ManagementDevice trust and access restriction depend on controlling who and what can connect
Recommendation — Restrict access paths for untrusted or unmanaged devices.
ISO/IEC 27001:2022A.8.1 — User Endpoint DevicesEndpoints and BYOD are central attack paths in this question
A.5.7 — Threat intelligencePhishing and watering hole activity require current threat awareness
Recommendation — Apply endpoint security rules to managed and personal devices accessing sensitive services. Use threat intelligence to tune phishing and lure detection.

Practitioner Guidance

What to prioritise: Prioritise the paths that combine user deception with device trust, because that is where phishing becomes intrusion. In practice, the highest-value work is usually better sign-in hardening, tighter conditional access, and rapid containment for suspicious devices.

What to verify: Verify that device policy is actually enforced for the workflows that matter most, especially customer authentication, remote employee access, and high-risk transaction approval. Also verify that security teams can revoke sessions and isolate devices quickly when a phish is reported.

Common mistake: Treating awareness training as the main control while leaving device posture, session controls, and exception handling loose. Training helps, but it does not compensate for weak access policy or permissive BYOD governance.

Practitioner takeaway: The most resilient programmes do not ask whether the user or the device is trusted, they make both prove they are trustworthy at the moment access is granted.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org