TABLE OF CONTENT
The assumption everything was built on
For a generation, security architecture assumed a boundary. Inside it were trusted users, trusted systems, and controlled infrastructure. Outside it was everyone else. Firewalls marked the edge, access meant crossing it, and defence meant holding it.
That assumption shaped how the industry thought about risk. Risk was something on the outside trying to get in. Fraud and security teams watched separate doors. Compliance confirmed the doors were locked on the day of inspection.
The boundary is now gone. Not weakened, but structurally dissolved. Many institutions are still defending a line that no longer marks anything.
What replaced the perimeter is not a bigger perimeter
When a wall fails, the instinct is to build a taller one. But the change underway in BFSI is not the erosion of the perimeter. It is the removal of the perimeter as an organising idea. This is clearest in four foundational shifts:
- Identity moved from a gate to a plane. Access used to be a single moment: authenticate, cross the line, and you were inside. Identity now runs continuously across biometrics, behavioural signals, identity wallets, and session tokens that chain across systems. As a result, a single identity compromise is no longer the loss of one account. It provides broad, persistent, cross-system access. The attacker does not break in; they inherit trust that was already granted.
- Decisions moved from humans to models. Credit, fraud, and onboarding decisions were once human-reviewed. They are now model outputs, executed at machine speed. This relocates the attack surface. The target is no longer the transaction but the inputs that shape the model — training data, feature stores, inference-time context, and adversarial inputs designed to change an output. Watching the transaction does not help when the decision was made upstream.
- Payments became instant and irreversible. Real-time rails removed the one thing post-facto detection relied on: time. When a transaction clears in milliseconds and cannot be reversed, detection that flags it seconds later records a loss rather than preventing one. A growing share of these transactions are also initiated by automated actors rather than people, so "unusual user behaviour" is a weaker signal when the user is not a person.
- Infrastructure dissolved its own edges. Monolithic core systems gave way to cloud-native, containerised, event-driven architecture. Open banking APIs, ISO 20022 streaming data, and programmable finance through smart contracts and tokenisation each open the institution to the outside by design. The boundary between "inside" and "not inside" was not breached. It was engineered away deliberately, for speed and interoperability.
Taken together, these shifts mean the perimeter is not just gone. The idea it stood for - that there is an inside to defend - no longer matches how financial services are built.
What exists now: the trust mesh
What sits in the perimeter's place is not another boundary. It is a mesh: a distributed, continuously shifting network of relationships across partners, platforms, models, APIs, and infrastructure layers, none of which a single institution fully owns or controls.
In this environment:
- Customer journeys span multiple partner platforms, each with its own risk model, and security context fragments at every handoff.
- Identity is the connective tissue between systems, which makes it the highest-value target.
- Models make consequential decisions in real time on data drawn from across the network.
- The institution's real attack surface is the sum of every trust relationship it participates in, not the sum of the systems it owns.
This is why "inside and outside" has stopped being a useful frame. There is no inside. There is a web of trust, extended continuously across entities, and exploited wherever that trust is assumed but never re-verified.
How attackers have adapted
Attackers moved with the architecture, not behind it. Attack patterns in BFSI have shifted from direct compromise to trust-chain manipulation. In practice, this means:
- Attacks now move across biometric onboarding, partner apps, AI decisioning, real-time payments, APIs, programmable finance, and third-party ecosystems.
- They exploit the gaps between systems, institutions, and workflows, where no single control owner has full visibility.
- A breach is no longer contained to a credential or a transaction. It is embedded across identity, AI, APIs, payment logic, and supply chains at the same time.
The underlying logic is straightforward. In a mesh, an attacker does not need to break through a boundary. They need one point where trust is granted and never re-checked, and that trust carries them across the systems the old boundary used to separate.
What this breaks, and what it demands
Two pillars of traditional security don't survive the transition, and it's worth being precise about why.
- Post-facto detection stops working when transactions are irreversible and clear faster than any pipeline can respond. Detection that arrives afterwards is a record of a loss, not a prevention of one. The discipline has to move from detecting outcomes to validating trust before an action is taken.
- Compliance monitoring becomes exploitable when it depends on control signals an attacker inside the environment can manipulate. Logs can be suppressed and thresholds adjusted, so the environment can appear clean while an attacker operates inside it. A control that was present on the day of assessment says little about whether it held under pressure. This gap between certified and secure is a critical finding and a recurring theme in SISA’s Digital Threat Report 2025-26.
There is also a timing problem. Regulation is adapting to an architecture that is still moving. The lag between structural change and security-model adaptation is the window that sophisticated actors are exploiting now.
What security becomes instead
If there is no perimeter, security cannot be the defence of a boundary. It has to become the continuous assurance of trust across a network that keeps shifting. That is a different discipline, not a larger version of the old one:
- Treat identity as a dynamic control plane, not a gate.
- Treat software as an environment to be continuously verified, not a system certified once.
- Treat the ecosystem as shared exposure, not a list of vendors to vet individually.
- Treat trust itself as the primary asset under attack — something to be validated and re-validated, never assumed.
The institutions that lead the next decade will not be the ones with the tallest remaining walls. They will be the ones that recognised the wall was already gone and rebuilt around what replaced it.
The perimeter is dead. What follows is the harder work of securing a system that has no edge.
.png)