CI&T Joins Claude Partner Network to Scale Claude Across the World's Largest Enterprises, with 1,000+ Certified AI Engineers Jun 08, 2026 CI&T Joins Claude Partner Network to Scale Claude Across the World's Largest Enterprises, with 1,000+ Certified AI Engineers. Learn more
CI&T Releases 2025 ESG Report Focused on Social Impact, Clean Energy, and Innovation Mar 26, 2026 CI&T Releases 2025 ESG Report Focused on Social Impact, Clean Energy, and Innovation Learn more
CI&T and AWS: how the partnership transformed customer service with generative AI at Alelo Aug 31, 2026 CI&Ters chatting animatedly in the office, tablet in hand: collaboration and technology, part of everyday life at the company. Learn more
CI&T Recognized in Everest Group’s 2025 Global PEAK Matrix® Assessments for Retail and Consumer Packaged Goods Services Dec 10, 2025 CI&T Recognized in Everest Group’s 2025 Global PEAK Matrix® Assessments for Retail and Consumer Packaged Goods Services Learn more
Cybersecurity’s Key Role in Open Finance Jun 07, 2023 | min read CybersecurityData SecurityFinance By Leonardo Horvath dos Reis Cybersecurity can increase customer acceptance of open banking. Explore best practices for boosting operations in this category. Practices that drive open banking security maturity One of the primary factors influencing customer acceptance of open banking is cybersecurity, as it is necessary to trust the platform in order to share personal and financial data for consultations and bank transactions.In other words, for the sector to evolve, financial institutions must commit to the adoption and consolidation of practices that increase open banking security maturity. I've highlighted a few of them below. Customer communication and education Educating customers on how to protect their information and use open banking services securely can build acceptance and trust. In this case, ensuring transparency around cybersecurity, including disclosure of defense policies and procedures, can make a difference. Data security Open banking depends on hosting and code development to integrate with other banks. Regardless of whether the platform is cloud, on-premise, or hybrid, an adequate defense posture against cyberattacks at the various layers, from the user's device to the information to be consumed, is crucial, which includes implementing market frameworks and compliance with regulations current regulations on data security in the country that will process the service, for example, LGPD, GPDR, BACEN, etc.Incidentally, it is essential to establish data governance to organize the flow for consent of customer information between institutions. In addition, it is essential to ensure security controls so that information is not exposed to unauthorized persons. Bring security early in the development cycle with Shift-left The sooner the institution takes care of the security of its processes, the less rework and impacts on the business will be accompanied by technical debts, incidents, and fines. Therefore, it increases, even more, the importance of the subject being part of the software engineering discussions. Gaining early visibility into what could turn out wrong is key to building a system more secure against cyber threats.Automated continuous code security analysis also drives efficiency in faster, more secure application delivery. In addition, the use of artificial intelligence in code security technologies accelerates the process of prioritizing the vulnerabilities that need to be resolved most urgently – according to severity and probability of impact –, as well as the vision of efforts in hours for correction connected to agile methodologies for backlog planning to solve security issues in a planned way.At the end of the cycle, validating the implemented defenses must be carried out through an intrusion test (pentest) before launching the application and when there are relevant changes to the code and platform. API security APIs (Application Programming Interfaces) in open banking transmit financial information and personal data of customers between different institutions and applications. API security is critical to protecting this sensitive information from unauthorized access, data leaks, and privacy violations.API security is a critical component of complying with regulations and maintaining customer trust. In order to avoid problems, good security practices must be applied during development. Network security Network security measures must be adopted to protect the open banking infrastructure, including firewalls, intrusion detection and prevention (IDS/IPS), WAF (Web Application Firewall), and DDoS prevention systems to avoid system disruption with attacks of denial of service. Robust authentication and authorization By using secure authentication and authorization methods, financial institutions can ensure that only authorized users have access to open banking services. This includes biometrics, security tokens, certificates, and multi-factor authentication to protect customer accounts. Identity and access management Establishing policies and procedures to manage access to open banking information and resources, including assigning permissions and privileges based on need and access role and the principle of least privilege (zero trust), is also part of the game. Data encryption Encryption protects data in transit and at rest, protecting sensitive customer information from unauthorized access. Constant monitoring It is essential to carry out constant monitoring to detect suspicious activities and security vulnerabilities in real-time, especially APIs, which are the main means of communication between institutions.This is because the controlling bodies of the open banking service require financial institutions to implement systems to prevent fraud and money laundering. Security certifications Some certifications can help increase customers' confidence in cybersecurity, such as ISO 27001, which sets standards for information security management systems.Obtaining certifications is a strategy for demonstrating a commitment to cybersecurity to customers and regulators. Incident response and disaster recovery Developing and maintaining incident response and disaster recovery plans to deal with security breaches, cyber-attacks, and other adverse events, ensuring open banking services continuity, is another practice to follow. Strategic partnerships Finally, it is recommended to work with strategic partners, such as cybersecurity companies, to implement security best practices. This will ensure that customers are protected from cyber-threats. Unprecedented opportunities According to the Open Banking Opportunities, Competitor Leaderboard & Market Forecasts 2023-2027 report (headed by Juniper Research, a global consulting and analytics firm in the mobile and digital technology industry), open banking payment transactions could exceed the value of $330 billion globally by 2027; by 2023, they are expected to reach US$57 billion.Therefore, financial institutions looking to increase customer acceptance and drive open banking success have access to unprecedented market opportunities that only grow. By addressing the cybersecurity aspects suggested above, you are on the right track.Sources: (in English) Tech Wire Asia(in Portuguse) Metrópoles, Valor Econômico, Estadão E-Investidor, Leonardo Horvath dos Reis Senior Security Officer, CI&T 2