Skip to content
BritonOne Technology
CybersecurityWealth Management

Customer identity rebuild for a wealth platform

Passwordless identity cut account-takeover 22% and sign-in friction at a wealth platform.

22%
Auth0WebAuthnFIDO2Node.js
Customer identity rebuild for a wealth platform
IndustryWealth Management
DisciplineIAM & Zero Trust
CountrySwitzerland
Headline result22%
The story

Problem, approach, and the outcome

About the client

The client is a Swiss wealth platform serving high-net-worth clients, where both security and a frictionless experience are part of the promise. For this client base, a breach and a clumsy sign-in both erode the trust the relationship depends on.

Passwords were driving account-takeover fraud on one side and onboarding drop-off on the other, hurting the platform in two directions at once.

The challenge

Passwords were driving two problems at once: account-takeover fraud against a high-net-worth client base, and onboarding drop-off as clients wrestled with credentials and resets. One weakness was causing damage on two fronts.

For a wealth platform, both a breach and a clumsy sign-in erode the trust the relationship is built on. Neither could be tolerated.

The rebuild had to cut fraud and friction together, not trade one for the other. Improving security at the cost of experience, or vice versa, would have missed the point.

Our approach

We rebuilt customer identity around passkeys, removing the shared secret that account-takeover attacks exploit. Eliminating the password removes the root cause of both the fraud and much of the friction.

Risk-based step-up meant genuine clients sail through low-risk journeys while unusual sign-ins face additional verification proportionate to the risk. Friction is applied only where risk warrants it, so honest clients are not punished.

We migrated existing clients gradually with a fallback path, so nobody was locked out during the transition, and measured fraud and conversion side by side to confirm both moved the right way. Security and experience improved together.

Results
  • 22% cut in account-takeover
  • Passwordless sign-in for most journeys
  • Step-up only where risk warrants it
  • Existing clients migrated with no lock-outs
Next step

Get a senior architect on the call, first time, every time.

No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.