Autenticación contextual
Analysis

Contextual Defense: Why Spending More on Cybersecurity Doesn’t Reduce Fraud (Part 1) 

30 July, 2026 9 min
Javier Barrachina R&D Director

Organizations continue to invest more in cybersecurity, yet fraud keeps increasing. The problem is not always the technology itself, but how the different signals organizations already rely on to make decisions relate to one another. Contextual defense, built on a contextual authentication approach, connects identity, biometrics, behavior, device, channel, and transaction context to uncover patterns that would otherwise remain hidden.

Contextual defense is built on a simple principle: no risk signal should ever be interpreted in isolation. Contextual authentication is all about analyzing identity, biometrics, behavior, device, channel, and transaction context together to make decisions based on a complete, rather than fragmented, view.

This is the first of two articles in which I explore a concept that I believe will play a key role in the evolution of fraud prevention: contextual defense.

There is one statistic that comes up time and again in conversations with risk, fraud, and technology leaders: nine out of ten organizations have increased their cybersecurity spending over the past few years, yet seven out of ten still report fraud-related losses. These figures, highlighted in Gartner’s Information Security Spending & Fraud Detection Research, point to a reality that is difficult to ignore.

The most common reaction is to assume that organizations simply need to invest even more. However, that conclusion overlooks a critical issue.

Security technologies have evolved significantly and, in general, perform the functions they were designed for extremely well. The problem arises because each solution analyzes only the part of the process it is responsible for, while none has a complete view of the identity or the transaction it is evaluating.

9/10 7/10
organizations have increased their cybersecurity spending
Source: Gartner, 2025
still report fraud-related losses despite higher spending
Source: Gartner, 2025
$244.2B 87%
projected global information security spending in 2026
Source: Gartner, 2026
identify AI vulnerabilities as the fastest-growing risk
Source: Global Cybersecurity Outlook 2026, WEF/Accenture, January 2026

When we analyze fraud cases, one pattern appears time and again: the different solutions involved in a transaction usually perform their individual functions correctly, but their outputs are rarely interpreted together.

For example:

  • Document verification confirms that the identity document is genuine.
  • Biometric verification confirms that the person is who they claim to be.
  • The fraud engine determines that the transaction falls within normal parameters.

Each system reaches the right conclusion from its own perspective. The problem arises because no one connects those conclusions. The authenticity of the document has no influence on how the biometric result is interpreted, and the biometric data provides no additional context for the transaction analysis. Each decision is made independently.

The result is a set of effective technologies that nevertheless fail to detect patterns that only become visible when all signals are analyzed together.

I don’t believe this is a failure of the technology or of the work the industry has done over the past few years. Quite the opposite. It is a natural consequence of how these architectures were built: each solution was designed to solve a specific problem, and very few were designed to share context with the others.

In R&D, we’ve been encountering this same limitation in production environments for years. Every time we identify one of these blind spots, it eventually becomes a new product requirement. That’s one of the advantages of working with financial institutions of very different sizes and profiles across more than thirty countries: the use cases change, but the underlying patterns tend to repeat themselves.

That’s why I believe the industry’s next step is no longer just about improving each technology individually. It’s about enabling them to share context and interpret risk as a single, unified system.

“Fraud isn’t caused by a lack of technology. It happens when the signals behind each decision aren’t connected.”

What It Means to Contextualize Defense

When we talk about contextual defense, we’re not suggesting adding another solution to the security stack. The challenge is enabling the technologies already in place to share information and evaluate each transaction as a whole.

Today, that rarely happens.

In most financial institutions, document verification, biometric authentication, transaction analysis, and fraud detection systems still operate on separate datasets. Each makes decisions based only on the information it has available and rarely incorporates what the others already know. That limits the ability to detect certain types of attacks.

Consider a simple example. A customer opens an account and passes document verification without any issues. Two weeks later, they log in from a device they’ve never used before, in a different city than usual, and initiate a transfer to a new beneficiary for an amount far above their normal spending pattern. Taken individually, none of these signals is enough to trigger an alert: people change devices, they travel, and adding a new beneficiary is common in legitimate transactions. But taken together—a recently verified identity document, an unknown device, and a new beneficiary receiving an unusually large transfer—they describe a pattern that deserves closer scrutiny.

That’s the shift contextual defense proposes. It’s not about generating more signals; it’s about making better use of the ones we already have.

Understanding the Context Before Designing the Architecture 

Antes de hablar de capacidades técnicas conviene hacerse una pregunta más básica: ¿qué realidad tiene que proteger cada entidad? 

No existe un banco igual a otro. Tampoco existen dos entornos de fraude idénticos. 

Cada organización arrastra un legado tecnológico diferente, opera bajo marcos regulatorios distintos y trabaja con perfiles de clientes que poco tienen que ver entre sí. A eso se suman factores específicos de cada país: la calidad de las infraestructuras de identidad, el grado de digitalización o incluso incidentes como las filtraciones masivas de bases de datos nacionales, que modifican por completo el escenario de riesgo. 

Una entidad con presencia en México, Colombia y Emiratos Árabes Unidos no gestiona un único modelo de fraude, sino tres realidades diferentes. Los vectores de ataque cambian, las restricciones regulatorias también y las señales disponibles para tomar decisiones no siempre son las mismas. 

Por eso una defensa contextualizada no puede partir de una configuración estándar. Antes necesita entender el contexto sobre el que va a operar. 

Three Capabilities That Are Stronger Together 

If the goal is to interpret risk from a complete perspective, three capabilities need to operate as a single, unified system:

1. Continuous Identity History

Every interaction with a customer generates information that, today, often remains confined to the module that produced it. Document verification doesn’t communicate with the biometric engine. The biometric engine doesn’t communicate with the transaction monitoring system. Contextual defense requires a continuous identity record—not a one-time verification event, but a living signal that accumulates context throughout the entire customer relationship.

2. Context-Based Orchestration

Collecting information isn’t enough if it’s not interpreted correctly. Contextual authentication must be able to consider variables such as the channel, country, device, customer profile, and the fraud vectors active at that moment in order to adjust the risk assessment.

The same biometric signal can have very different implications during a mobile onboarding process in Mexico than during an in-person authentication in the United Arab Emirates. Context changes how the signal is interpreted—and therefore how the system should respond.

3. Continuous Evaluation Throughout the Customer Lifecycle

Fraud doesn’t always reveal itself during onboarding. More often, it develops over weeks or even months. An account may pass the initial KYC process without issue and still become a fraud vector six months later.

Contextual defense doesn’t close the case once onboarding is complete. Instead, it keeps evaluating the full pattern throughout the customer’s entire lifecycle with the institution.

From Protecting Accounts to Protecting the System

So far, we’ve focused on how financial institutions can make better decisions by interpreting signals together. But there’s an even more important implication.

Fraud has never been a problem confined to a single bank. Attackers look at the entire ecosystem and target the institutions where they have the highest chance of success. If they identify an organization with weaker controls or a more limited ability to connect signals, that’s where they’ll strike. Today, that advantage still lies with them.

Contextual defense changes that dynamic. When institutions are able to share intelligence under appropriate governance frameworks, attack patterns no longer remain confined to a single organization. A signal detected by one institution can help anticipate an attack against another.

The goal is to ensure that the financial system as a whole learns faster than those trying to attack it.

“Attackers don’t target a bank. They target the weakest point in the entire system. Defending isolated points means defending against the wrong problem.”

Where Should You Start? 

A good place to start is by reviewing how signals flow across your security architecture today. In many organizations, each system still operates with its own data, its own thresholds, and its own decision logic.

Three questions can quickly help assess your current level of maturity:

  • Do your identity, biometric, and fraud solutions exchange information in real time?
  • Does your risk assessment adapt based on the country, channel, or transaction context?
  • Does identity continue to be evaluated after onboarding, or does the analysis end with KYC?

If the answer to most of these questions is still no, the challenge probably isn’t adding another tool. It’s building an architecture capable of connecting the ones you already have.

In the second part of this series, we’ll explore why precision medicine offers a surprisingly useful framework for understanding this paradigm shift—and what the financial industry can learn from a discipline that has been using context as its primary decision-making tool for years.

Increasing security spending doesn’t reduce fraud when each component of the security architecture operates without awareness of the others. The document verification engine, the biometric module, and the fraud detection system each reach their own conclusion and close the case, but none sees the complete pattern. Fraud slips through the gaps between disconnected systems—not because any individual technology has failed.

Contextual authentication verifies identity by evaluating the context of each interaction, including the device, location, channel, user history, and the fraud threats active in that region. The same biometric signal can have very different implications during a mobile onboarding process in Mexico than during an in-person authentication in the UAE. Risk decisions are adjusted in real time based on those contextual factors.

A traditional security stack is made up of products that operate independently. Each evaluates the current event without access to historical patterns or the context provided by the other systems. By contrast, a contextual defense maintains a continuous identity signal that accumulates context throughout the entire customer relationship, together with an orchestration layer that evaluates all those signals collectively rather than producing a series of isolated decisions.

Fraud rarely reveals itself during onboarding. More often, it develops over weeks or even months. An account may pass the initial KYC process without issue—only to become a mule account used to receive fraudulent transfers six months later. Contextual defense doesn’t close the case once onboarding is complete; it continues evaluating the full pattern throughout the customer’s entire lifecycle.

Each country has its own technological legacy, regulatory framework, and identity infrastructure. A financial institution operating in Mexico, Colombia, and the United Arab Emirates isn’t dealing with a single fraud model—it’s dealing with three distinct realities, each with its own attack vectors, regulatory constraints, and available signals. Contextual defense begins with that understanding before any architecture is designed.

Ready to protect your users?

Discover how Facephi's biometric technology can safeguard your identity verification process.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook
Secret Link