Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› When should organisations prioritise stronger authentication over reducing…
Authentication, Authorisation & Trust

When should organisations prioritise stronger authentication over reducing customer friction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Authentication, Authorisation & Trust

Organisations should prioritise stronger authentication when the fraud loss, account takeover risk, or downstream remediation cost outweighs the friction introduced by additional checks. In high-value or high-abuse journeys, a small increase in authentication strength can prevent much larger losses later. The key is to match control strength to risk, not to apply the same step-up requirement everywhere.

When stronger authentication is the better business decision

Organisations should treat stronger authentication as the right choice when the cost of fraud, account takeover, or recovery is higher than the extra effort a customer must spend to sign in or verify. The practical question is not whether friction exists, but whether the journey carries enough value or abuse potential to justify a harder step-up.

This is most obvious in high-value transactions, administrative actions, account recovery, payment changes, and any flow that would be painful to unwind after compromise. In those cases, authentication strength is part of loss prevention, not just an access gate.

How to balance security strength against customer drop-off

The balance changes by journey type. Low-risk browsing and routine self-service can usually tolerate lighter checks, while actions that expose funds, data, or privileges merit more assurance. A sensible model is to let the risk of misuse decide when step-up authentication is necessary, rather than applying a universal policy that either overburdens everyone or protects nothing well.

Stronger authentication also matters when the attack path is cheap, repeatable, and scalable, such as credential stuffing, phishing, MFA fatigue, or token theft. Where the same attack can be reused across many accounts, small improvements in authentication quality can materially reduce expected loss. The question becomes whether the additional friction meaningfully changes attacker economics and customer safety.

That is why organisations often reserve stronger controls for account creation, password reset, new device enrolment, payout changes, and access to sensitive records. These are the points where compromise is easiest to monetise and hardest to recover from.

What to measure before changing the default authentication path

Before adding friction, teams should test whether the control is aimed at the right pressure point. If the problem is mainly impostor access, use stronger authentication; if the problem is checkout abandonment, use risk-based step-up only where the fraud exposure is real. The decision should be informed by abuse rate, loss severity, and the operational cost of recovery, not by a generic preference for more checks.

It is also worth separating user experience from security effectiveness. A control that creates friction but can still be bypassed by stolen sessions, weak recovery, or help desk abuse may reduce convenience more than risk. In practice, the best outcomes usually come from targeted friction at high-risk moments, not from making every sign-in equally hard.

Risk and Threat Considerations

Weaker authentication increases exposure to account takeover, fraud, unauthorised actions, and expensive remediation, especially where a single compromised account can trigger payments, data access, or privilege escalation. The risk is not just the direct loss, but the downstream cost of investigation, customer support, dispute handling, and trust damage.

Failure mechanism: Attackers exploit the easiest path into the highest-value journey, often through credential stuffing, phishing, social engineering, MFA fatigue, or token theft. If the organisation keeps the same low-friction path for every action, the attacker only needs one successful compromise to reach a materially valuable outcome.

Impact: Stronger authentication at the right point raises attacker cost, reduces successful abuse, and limits blast radius. The trade-off is that misapplied friction can hurt conversion, but under-protected high-value flows can create losses that far exceed any customer inconvenience.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, OWASP ASVS, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesSets assurance levels and phishing-resistant auth choices for higher-risk sign-in flows
Recommendation — Apply higher assurance for high-risk journeys and prefer phishing-resistant authenticators where assurance needs rise.
OWASP ASVSV6 — AuthenticationAuthentication strength and step-up decisions directly affect user sign-in and recovery security
V7 — Session ManagementStronger login must be paired with session protection or stolen sessions bypass auth gains
Recommendation — Require stronger authentication for sensitive flows and verify recovery is at least as strong as sign-in. Protect sessions so higher sign-in assurance is not undermined after authentication.
CIS Controls v8CIS-5 — Account ManagementAccount and recovery controls govern where step-up authentication meaningfully reduces abuse
Recommendation — Harden account and recovery paths before expanding friction across low-risk journeys.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementAuthenticator lifecycle and strength determine whether stronger authentication actually reduces takeover risk
Recommendation — Manage authenticators tightly and rotate or revoke weak credentials on high-value accounts.

Practitioner Guidance

What to prioritise: Put stronger authentication first on the journeys where compromise is expensive to reverse, such as reset, recovery, payout, admin, and sensitive data access. If the action can directly create financial loss or irreversible exposure, treat it as a candidate for step-up by default.

Decision rule: If the expected loss from compromise is greater than the incremental drop-off from added verification, tighten authentication on that flow; if not, keep the path lighter and apply controls only when risk signals rise.

What to verify: Confirm that stronger authentication is matched with safe recovery, fraud monitoring, and session protection. A harder login does not help much if an attacker can still win through recovery abuse or session hijacking.

Practitioner takeaway: The right balance is usually selective, not uniform, stronger authentication should be concentrated where the business impact of compromise is high enough to justify the friction.

MFA GuideCustomer IAM (CIAM) GuideWorkforce Identity Security Guide

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org