Your Bank’s Security Experience May Be Driving Customers Away
By Jessica Kendall, Contributor at The Financial Brand
Simple Subscribe
Subscribe Now!
Consumers continue to place substantial trust in banks and credit unions to protect their money, but that trust comes with increasingly specific expectations.
Entersekt’s 2026 research reveals a growing tension between security, convenience, and control. Consumers want their banks and credit unions to take responsibility for detecting threats, but they also expect security practices to reflect modern technology and give them meaningful choices. That creates a challenge for institutions still operating with fragmented systems and authentication methods that customers increasingly view as outdated.
Key insight: The report points toward a more adaptive approach, in which authentication, fraud detection, customer behavior, and device intelligence work together to make security decisions in real time. This isn’t about adding another security checkpoint but designing a digital experience where stronger protection feels seamless, intelligent, and worthy of the trust customers place in their institution.
Need to Know:
- Ninety percent of respondents cite security as a top factor when choosing a financial institution.
- Authentication has become a customer experience issue. Consumers increasingly judge their financial institutions by the security methods they encounter, and 43% would consider switching institutions based on authentication alone.
- Technology gaps are visible to consumers. Text-based OTP remains the most widely deployed authentication method in the survey, despite being among the least trusted.
- Trust does not mean surrendering control. Fifty-nine percent of consumers trust their FI to flag suspicious transactions without their review, while 28% still want an active role in deciding which transactions require approval.
- More than half (59%) trust their FI to flag suspicious transactions without requiring their review, while 28% want an active role in deciding what gets flagged.
Trust Remains a Valuable Asset
Consumers still largely view financial institutions as trusted custodians of their money and personal information. However, Entersekt’s research suggests that trust is increasingly tied to the quality of the digital security experience.
More than 90% of respondents identified security as a top factor when choosing a financial institution. Consumers also expect their institutions to act as security experts. Sixty percent trust their financial institution to select the most secure authentication methods, while 59% trust it to identify suspicious transactions without requiring them to review everything themselves.
Security can become a meaningful strategic distinction for bank leaders. It is not confined to the fraud department or the compliance function. It can influence acquisition, retention, and the broader perception of the institution.
The stakes become clearer when consumers are asked whether security concerns could change where they bank. Forty-three percent say they would consider leaving their institution based on its authentication methods alone. That makes authentication a customer experience decision as much as a cybersecurity decision.
The challenge is that consumer expectations are moving faster than some institutions’ technology. The report identifies legacy systems and constrained budgets as major reasons some community and regional institutions continue relying on older authentication infrastructure.
Key insight: Retail banking leaders should evaluate authentication through the same lens used for other customer-facing experiences. How much effort does it require? How does it affect trust? Does it reflect what customers perceive as secure? And does the institution have the intelligence to determine when additional verification is actually necessary?
Authentication Has a Trust Problem
There is a clear disconnect between what financial institutions deploy and what consumers trust. Text-based one-time passwords are a leading example. Nearly half of respondents reported their financial institution uses OTP via text. But, just 18.2% consider text OTP the most secure verification method.

Push notifications fare similarly poorly: 27.1% reported their use by FIs, while only 9.3% viewed them as the most secure option. On the other hand, half of respondents consider biometric authentication, such as fingerprint or face ID, the most secure option. But only 41.1% reported that their institution uses it.
That does not make biometrics a complete answer. The report notes that AI-powered attacks — including voice cloning, deepfakes and techniques designed to circumvent live biometric checks — introduce new vulnerabilities.
Social engineering presents another problem because legitimate customers can be manipulated into authorizing fraudulent transactions themselves. Authentication can confirm who is initiating a transaction without necessarily determining whether that transaction is legitimate.
That distinction matters as fraud becomes more sophisticated. A customer can successfully authenticate and still be the victim of a scam.
Key insight: Rather than relying on a single credential, institutions can combine authentication methods with device signals, customer behavior, and real-time fraud analysis. The goal is to make security decisions based on the context surrounding a transaction, rather than repeatedly asking customers to prove their identity.
Consumers Want Security With Control
The report also complicates a common assumption about personalization. Consumers may want financial institutions to make more decisions for them, but they do not necessarily want those decisions made without their involvement.
Consider suspicious transactions. Fifty-nine percent trust their FI to flag suspicious activity without requiring their review. At the same time, 28% want an active role in determining which transactions are flagged for approval.
Authentication shows the same pattern: 60% trust their FI to use the most secure methods, while 24% want to choose the methods themselves.

Personalization is partly about giving customers meaningful choices. A highly automated security system can still communicate what is happening, why an action was taken, and where the customer has control.
While customers may welcome technology that makes security less burdensome, they need confidence that the institution remains accountable for the decisions being made on their behalf.
Build Intelligence Behind the Experience
Today, authentication and fraud detection are often treated as separate functions, creating fragmented views of customer activity. Instead, banking leaders can bring together the data already generated across the customer journey, including purchase behavior and authentication events across devices, and apply machine learning and AI to identify fraud patterns in real time.
That approach has an important customer-experience benefit: more security can happen without adding more steps. Friction can be useful when it stops a legitimate threat, but unnecessary friction can also drive abandonment.
Security modernization should focus on making the experience smarter, rather than simply making it stricter. For instance, a customer whose device, behavior, and transaction patterns all look familiar should not necessarily encounter the same authentication process as a customer whose activity looks anomalous.
That is where security can become a competitive experience. Consumers already expect their financial institutions to protect them. The institutions that translate that expectation into adaptive, intelligible, and low-friction digital experiences will be better positioned to preserve the trust that remains one of banking’s most valuable assets.
