The Core Conflict: Friction vs. Flow
At the heart of the debate is a fundamental tension: how to keep criminals out without locking legitimate customers in. One camp of engineers argues for 'positive friction'—deliberate, noticeable security steps that make users pause and confirm critical
actions. They believe that in finance, a completely frictionless experience can be dangerous, as it might prevent users from catching mistakes or noticing fraudulent activity. The other side contends that cumbersome security is a business killer in the digital age. They argue that every extra login step, confusing prompt, or password requirement increases the chance a customer will abandon a transaction or switch to a competitor with a smoother app. This group champions seamless experiences, like biometric logins and behind-the-scenes risk analysis, that secure the user without demanding constant input.
The Zero Trust Philosophy: A New Battleground
The rise of 'Zero Trust' architecture has created another major fault line. The traditional 'castle-and-moat' model, which trusts anyone inside the network, is now widely seen as outdated. Zero Trust operates on the principle of 'never trust, always verify', meaning every user and device must prove its identity and authorization for every single action. While almost all engineers agree on the principle, they disagree fiercely on its implementation. One side advocates for a radical overhaul, arguing it's the only way to protect against modern threats like insider attacks and compromised credentials. The other side warns that applying such stringent, continuous verification across legacy banking systems is operationally crippling, expensive, and risks breaking critical, decades-old infrastructure that still runs core banking functions.
User Experience: Convenience vs. Absolute Security
The disagreement over user experience (UX) is where the philosophical becomes practical. Security purists often advocate for multi-factor authentication (MFA) for almost everything, believing that the inconvenience is a small price to pay for robust protection. They point to the prevalence of phishing and credential theft as proof that relying on just a password, or even just a face scan, is insufficient. On the other side, a more user-centric group of engineers pushes for passwordless solutions and adaptive authentication. They argue that security should be intelligent, only adding friction when a situation is genuinely high-risk. For example, a customer checking their balance from a recognized device might not need any extra steps, but transferring a large sum to a new recipient would trigger a 'step-up' verification. This side believes security should feel supportive, not obstructive.
The Compliance Conundrum
Ultimately, many internal disagreements are rendered moot by an external force: the regulator. Financial institutions operate under a mountain of rules, from the Sarbanes-Oxley Act (SOX) to specific anti-fraud and identity verification mandates. These regulations often prescribe specific types of controls and detailed audit trails. One engineer might have an innovative, efficient idea for managing access, but if it doesn't produce the exact kind of evidence an auditor from the OCC or FFIEC expects to see, it’s a non-starter. This means engineers are often forced to implement systems that are not necessarily the most technologically elegant or user-friendly, but are the most defensible during a regulatory exam. The 'real reason' for a particular security choice is often not about being the most secure, but about being the most compliant.













