Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› When should teams prioritise fraud deterrence over tighter…
Governance, Ownership & Risk

When should teams prioritise fraud deterrence over tighter login friction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 10, 2026 Domain: Governance, Ownership & Risk

Prioritise deterrence when abuse is being automated at scale and the main objective is to raise attacker cost rather than block every attempt. The right balance is targeted friction on risky paths, because universal hardening can hurt legitimate users without materially reducing organised fraud.

When is deterrence the better lever than universal login friction?

Deterrence should lead when the abuse pattern is industrialised, repeatable, and designed to probe many accounts or journeys quickly. In that setting, the goal is not to make every login equally hard, but to raise the cost of abuse on the paths that matter most while preserving conversion and supportability for legitimate users.

The practical distinction is between blocking and shaping. Universal friction treats every user the same, while deterrence uses risk signals, rate shaping, bot resistance, and step-up controls to make hostile automation expensive without turning the whole login flow into a bottleneck. That is usually the better trade when fraud is opportunistic at scale rather than targeted at a single account.

Deterrence also works better when you can measure attacker adaptation. If added friction only shifts the attack to another route, or if fraud attempts are already distributed across many credentials, then the more valuable outcome is to slow, segment, and expose the abuse rather than attempt perfect prevention at the front door. That is where targeted controls and telemetry matter more than blanket inconvenience.

Where login friction becomes counterproductive

Heavy-handed login friction can degrade the very signals teams need to distinguish fraud from legitimate behaviour. More prompts, more resets, and more failed logins can increase abandonment, generate help-desk load, and mask whether the real problem is password spraying, credential stuffing, account takeover, or monetised bot traffic. The security value falls when friction is broad but not selective.

Good deterrence design keeps the highest-friction steps for the highest-risk actions, not for every authenticated user. That means treating login as one control point in a wider abuse journey, rather than the only place to intervene. If fraud is happening after sign-in, or through low-and-slow automation, then stronger login gating alone often adds cost to defenders without materially hurting the attacker.

For control design, teams should align the challenge to the abuse path. For example, rate limits, device reputation, anomaly scoring, account recovery protection, and step-up checks can deter bots more precisely than a universal hard stop. CIS Controls v8 emphasises account management, access control, and audit logging as core operational safeguards, which supports this kind of selective, evidence-driven posture. CIS Controls v8 is a useful baseline for structuring those safeguards.

How to decide whether the goal is friction or deterrence

The decision depends on whether the threat is individual misuse or scaled abuse. If the likely actor is a single human adversary, tighter friction may buy time. If the pattern is credential stuffing, scripted sign-ups, automated payment abuse, or other high-volume fraud, deterrence usually wins because the attacker can absorb delays that ordinary users cannot. In those cases, the control should be chosen for asymmetric cost, not absolute blockage.

Teams should also evaluate whether the business can tolerate a small amount of residual abuse in exchange for better user experience. Many fraud programmes do better when they accept that not every malicious attempt will be stopped at login, provided the path is instrumented and the damage is bounded. That is a different objective from classic authentication hardening, and it should be stated explicitly in policy and tuning decisions.

External guidance on financial-crime reporting is relevant when login abuse is part of a broader fraud or laundering pattern. FinCEN is the authoritative source for US AML advisories and SAR-related expectations, which matters when suspicious access behaviour becomes part of a reportable fraud or laundering workflow rather than a pure access-control issue.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementLogin deterrence depends on controlling account abuse and access paths.
CIS-6 — Access Control ManagementTargeted friction is an access-control design choice for risky paths.
CIS-8 — Audit Log ManagementDeterrence works best when abuse can be detected and measured from logs.
Recommendation — Use account controls to narrow abuse opportunities and reduce repeated fraudulent access attempts. Apply selective access controls to raise attacker cost without broadly slowing legitimate users. Log risky login and recovery events so you can tune deterrence against observed fraud patterns.

Practitioner Guidance

What to prioritise: Start with the paths that produce the most abuse volume or the highest downstream loss, such as login, account recovery, promo redemption, checkout, or payout. Those are usually the places where targeted deterrence creates the best cost asymmetry.

Decision rule: If stronger friction would mainly slow legitimate users while attackers can rotate identities, devices, or proxies, prefer selective deterrence. If a specific protected action has a high fraud cost and a narrow user base, use tighter friction there even if the main login remains lighter.

What to measure: Track attacker conversion, user abandonment, help-desk contacts, repeat abuse rate, and the proportion of blocked events that were truly malicious. If friction rises but fraud volume does not fall, the control is probably too broad or misplaced.

Practitioner takeaway: The best balance is usually not “less security” or “more security”, it is choosing the control point where added friction most strongly disadvantages the attacker while least disrupting legitimate behaviour.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org