CFOtech Asia - Technology news for CFOs & financial decision-makers
Asia
Fintech growth exposes security & finance weaknesses

Fintech growth exposes security & finance weaknesses

Tue, 4th Aug 2026 (Today)
Karen Joy Bacudo
KAREN JOY BACUDO Finance Editor

Executives from Keeper Security, Flywire and F-Secure have warned that fintech's rapid growth is exposing structural weaknesses in security and finance operations. Their comments coincide with World Fintech Day and fintech's expanding role in global financial services.

Credentials, automation and customer trust emerged as the central themes across the three viewpoints, spanning cybersecurity, finance operations and consumer protection. Each executive identified different weak points in today's fintech stack, but all pointed to control and governance as decisive for the sector's next phase of growth.

At Keeper Security, attention has shifted to the machine-to-machine connections that underpin modern banking and payments. Takanori Nishiyama, Senior Vice President APAC and Country Manager, Japan, highlighted the growing dominance of non-human identities within financial institutions and their partners.

"As the industry marks World Fintech Day, it is worth remembering what fintech actually runs on: the connections between machines, and the credentials that authorise them. Every open banking connection, payment integration and embedded finance partnership depends on an Application Programming Interface key, a service account or a token. These non-human identities now far outnumber people in any financial organisation, and most carry standing access that no one reviews until something goes wrong. Cybercriminals have noticed. Verizon's 2026 Data Breach Investigations Report found credential abuse featured in 39% of breaches, while third-party breaches surged 60% to account for nearly half of all cases - a direct warning for a sector built on integrations. Akamai's research found 96% of financial services firms experienced at least one API-related security incident in 2025. Fintech's greatest strength, its interconnectedness, is also its most exposed surface.

"Regulators across APAC are responding in real time. Japan's Financial Services Agency introduced mandatory cybersecurity self-assessment requirements for financial platforms effective April 2026, with penetration testing obligations to follow. The Monetary Authority of Singapore's revised TRM Notice closes its consultation window this week, with compliance becoming mandatory within 12 months of the final notice. It covers continuous monitoring, incident management, IT asset management, capacity planning and data backup, alongside tighter third-party oversight as part of a parallel MAS initiative. Australia's APRA prudential standards reinforce the same direction. The message from regulators across the region is consistent: continuous verification and documented control of privileged access are no longer optional.

"For security and compliance teams in financial services, the practical response is clear. Standing privileges should give way to just-in-time access, while service accounts and API keys should carry least-privilege access by default. Phishing-resistant multi-factor authentication should be enforced at every login point, and the most sensitive data should remain encrypted at the infrastructure level. These controls apply equally to human users and the machine identities that now dominate fintech environments. Fintech has earned its place in the financial system by making trust programmable. The next stage of growth depends on proving that trust can also be governed. On World Fintech Day, the standard worth holding is this: verify every connection, account for every credential and log every session," Nishiyama said.

While Keeper focused on infrastructure security, Flywire focused on how finance teams use AI within that infrastructure. Chris Couch, Head of Product, B2B, said finance leaders are assessing AI less as a novelty and more as a tool for specific operational problems.

"For the past two years, much of the conversation has centred on AI adoption: which tools to use, how quickly to implement them and what impact they will have. Those are important questions, but in my conversations with finance leaders, the discussion has become far more practical. Today, the question is how and where AI can create measurable business value.

"That shift is reflected in research Flywire recently commissioned among more than 300 finance professionals on AI, automation and getting paid faster. While respondents overwhelmingly see AI as an essential part of their operations, they identified fragmented systems, manual processes and limited visibility as the biggest barriers to using it to improve performance.

"The most successful AI initiatives may not be the most ambitious. They will be the ones that remove the repetitive work preventing finance teams from focusing on more strategic priorities, such as payment matching, cash application, collections prioritisation and cash forecasting. These are high-volume, repeatable processes where AI can improve speed, consistency and decision-making, while giving finance professionals more time for planning, analysis and business partnership. Finance leaders identified these capabilities as having the greatest potential to improve their operations.

"If you are adding new tools to an already disparate set of systems, you are only adding complexity to your accounts receivable workflows. Look for AI that is native to your financial systems. Finance leaders are not resisting AI. They are approaching it thoughtfully, with an eye on transparency, accuracy, data privacy and appropriate human oversight. Finance has always required accountability, and AI does not change that. The most effective implementations will automate routine work, surface better insights and help teams make better decisions, while ensuring people remain responsible for the decisions that matter.

"Perhaps the most telling finding from the research was that finance professionals believe greater automation would allow them to become more strategic in their roles. Success will not be measured by how much AI an organisation deploys. It will be measured by whether finance teams gain the time, visibility and confidence to make better business decisions," Couch said.

Customer trust formed the third pillar of the commentary. F-Secure's Scam Intelligence & Impacts Report 2026 underpinned its view that AI-driven fraud is reshaping what users expect from digital financial services.

"The conversation around fraud is no longer about how often scams happen; it is about how effective they have become. Our latest research found that while scam exposure continues to increase steadily, the percentage of victims who actually lose money has nearly tripled in the past year alone. AI is allowing criminals to scale deception with unprecedented speed and sophistication, making consumer trust both more important and harder to earn.

"Consumer feedback mirrors this exactly: 93% say cybersecurity matters when choosing a digital service provider, 82% say it directly influences that decision, and more than half are willing to pay for stronger protection. Simply put, security has evolved from an operational requirement into a business differentiator.

"The fintech companies that lead the next decade will not simply build the fastest or most seamless payment experience. They will be the ones that make customers feel peace of mind at every interaction. Trust is no longer something brands earn after a breach. It has become part of the product itself," said Dimi Vellikok, Senior Vice President of Product Engagement.