People

Five fraud prevention strategies to strengthen payment resilience 

Jacob Coan
26 August 2026 Published: 26.08.26, Modified: 27.08.2026 11:08:03

Insights for Organisations   Financial Services   Cybersecurity

Five fraud prevention strategies to strengthen payment resilience

Jacob Coan
26 August 2026
Headshot - Jacob Coan

The financial industry is changing more rapidly than ever, and this is evident in our everyday lives. With the introduction of real-time payments and digital currencies, the way in which money is transferred and the way we deal with our banks has been permanently altered. At the same time that payments are becoming faster, the dangers also increase.

If fraud is not properly managed then payment flows may come to a halt, user trust may be lost, and business continuity may be jeopardised.

Secure payments require a strong infrastructure, a properly organised regulatory framework, and the appropriate talent in order to achieve the necessary transformation in the sector.

Cybercriminals are nowadays more and more using AI in order to target weaknesses in the payment lifecycle. In the article Jacob Coan, Head of Sales at FDM NA, outlines five practical strategies which organisations should put into place in order to reduce fraud risks and enhance their cyber resilience.

Why fraud prevention starts with being resilient

The Federal Trade Commission (FTC) stated that in 2025 U.S. consumers filed 3 million fraud reports and suffered losses amounting to $15.9 billion, which is an increase from the more than $12 billion in losses reported in 2024. The FTC also mentioned that the greatest total losses were caused by consumers making payments by means of bank transfers, after which came losses relating to cryptocurrency.

The damage that scams and cyberattacks can cause to brands may last for years, leading to delayed payments, a loss of business opportunities and unhappy customers.

This is so because financial institutions have to work together to build resilience and introduce proactive measures in order to prevent fraud at every level of their payment operations.

Payment continuity and fraud resilience are nowadays two aspects of the same thing.

Where fraud and cyber risks meet

FBI’s Internet Crime Report 2025 states that the amount of money reported to it in 2025 exceeded $20 billion, with phishing and investment fraud being among the biggest categories. The report also mentions business email compromise (BEC) losses amounting to just over $3 billion and has an “AI related” entry which amounts to $893 million in reported losses.

The Association for Financial Professionals (AFP) 2026 Payments Fraud and Control Survey Report states that “fraud through email continues to be common since email is still the primary means of communication within organisations, making it a favourite target for cybercriminals.”

At present, fraudsters are finding new methods of using automation to spot vulnerabilities and get around simple controls by means of deepfake technologies and false identities.

This year, a major US payment gateway provider was the victim of an attack and as a result the service was disrupted, with effects felt by merchants and payments across the network.

Distributed denial-of-service (DDoS) attacks can cause serious difficulties for banking services and result in outages which interfere with the entire payment process. In order to counter this, banks must closely monitor events in real time in order to detect fraud, maintain solid contingency plans to ensure their resilience, and make certain that they accurately report any incidents. Only then can they reduce the damage and keep their services operating smoothly.

Building financial resilience in practice

Then how can financial institutions increase their resilience?

1. Introduce controls that are based on risk at once

In order to deal with fraud threats that are becoming more and more sophisticated, organisations must combine the use of automated monitoring tools with human expertise so that suspicious behaviour can be identified and action is taken before losses take place.

  • Use transaction monitoring tools such as Senseon to identify suspicious payment patterns or sudden changes in customer behaviour.
  • Enable real-time payment intervention so that teams can pause and examine high-risk transactions before they are settled.
  • Always check the fraud rules to make sure that the controls remain effective in the face of changing threats.

2. Invest in people and skills

Our research shows that 32% of businesses identify a lack of specialist skills as a major obstacle to technology adoption.

It is important to train teams in the most recent fraud and cyber techniques if criminal activity is to be stopped, since criminals are increasingly using AI, automation and social engineering methods to get around existing controls.

Organisations should focus on building practical capabilities including:

  • Training fraud, cyber and payments teams about emerging threats, such as those enabled by AI, deepfakes, fraud involving authorized push payments (APP) and account takeover attacks.
  • Regular practice sessions involving payment fraud scenarios similar to real-world cases help teams to see how they make decisions when under pressure.
  • Ensuring that there are clear escalation procedures so that employees know when and how to take action if they detect suspicious activity.
  • By studying your mistakes and then using that knowledge to enhance your defences over time, you can remain a step ahead of possible threats and continue to become stronger.

3. Promote cross-departmental collaboration

Fraud, cyber, risk, and payments teams  should work as a single unit. When the various silos are broken down it is possible to respond more quickly to incidents, carry out more effective root-cause analysis, and gain a comprehensive view of risk.

It is essential to have regular response exercises and well-established playbooks which specify the roles and escalation procedures in cases of fraud or cyber incidents if the various departments of the organisation are to cooperate with one another.

4. Test, learn, and adapt

Resilience is a continuous process and not something you can deal with in a single attempt. Since fraud is becoming more sophisticated, closely interconnected and aided by technology, organisations must extend beyond just preventing incidents and instead work on building resilience.

It is important for companies to treat fraud as a top concern at the board level, which involves establishing clear lines of ownership and accountability throughout the organisation rather than putting the responsibility on a single team.

Katrina Gallagher, who is Head of Privacy at FDM, says that the main thing to do is to make fraud a matter that affects the board, with well-defined ownership, accountability and supervision throughout the organization rather than having the responsibility concentrated in one department. Executives ought to support their staff by eliminating the barriers between different parts of the organization and should allow the teams to share intelligence, test their assumptions and collectively respond to emerging threats. Just as important as the technology employed to detect fraud are solid governance, clear decision-making and having access to the correct data.

5. Enhance governance and accountability

In order to develop resilience, companies must keep their boards regularly informed by providing them with clear reports, ensuring that their decisions are easy to understand, and keeping them up to date on matters relating to fraud and cyber risks. With the boards involved, they can verify that resources are being used properly and that the plans are being adjusted in response to new threats and technological developments. As a result, the companies are able to remain strong and capable of dealing with difficulties.

Cyberattacks can seriously affect the way payments are made. Think about the major ransomware attack that hit the world’s largest banks—it halted trading and created problems across the $26 trillion U.S. Treasury market. The bank’s communication systems broke down and billions of dollars were at risk. This event revealed some major flaws in the way global banks function. In the real-time payments networks currently in use, even a brief disruption can have huge consequences.

Having ISO 9001 and ISO 27001 standards in place is a positive development, but what is really important is the way in which they affect how people work together. These international standards enable companies to make better decisions on a daily basis by incorporating good governance, accountability, and a commitment to continuous improvement. As a result, companies are able to adapt swiftly, manage risks, and consistently provide good results for their clients. When businesses adhere to these frameworks, they can develop a culture that places a strong emphasis on ongoing improvement and responsibility, a factor which is vital for long-term success.

The Federal Reserve states that ISO 20022 can actually be of great use in detecting fraud, since it provides more detailed information regarding who is making the payment, who is receiving it, and the purpose of the payment. As a result, it becomes easier to quickly and accurately identify suspicious patterns.

We were successful in renewing our ISO 9001 and ISO 27001 certifications at FDM, which shows our continued commitment to these internationally recognised standards.

Payment visibility is key

Banks and payment providers must strike a balance between offering smooth and hassle-free payment experiences and maintaining strong controls which prevent and detect fraud. Getting this balance requires constant alertness, the intelligent use of technology, and an approach that is focused on the customer.

By letting users know about fraud threats, the resilience measures in place, and the steps that the institutions are taking to guard their payments, companies will be able to earn the trust of customers and enable them to take an active role in securing their own payments.

How FDM can support

FDM helps organizations to develop resilient defenses against AI-powered threats by using a multi-tiered method.

Consultants in our IT Operations and Risk, Regulation & Compliance Practices are up-to-date about the most recent cyber security technologies and techniques that are relevant to our clients. They are aware of the possible threats and of the changing situation in the industry, which allows them to offer our customers the best possible solutions.

Companies which adopt people-driven and forward-thinking strategies will not only be able to keep ahead of changing fraud techniques but also safeguard their organizations against both financial and reputational harm.

Find out how FDM can help build your payments resilience.

Contact me.

Yes
No