Explore AI Summary

Share post on:

Closing the Gap Between Fraud and Security

Part 3: An Operating Model for What Happens After the Login

Shared accountability, shared telemetry, shared decisioning, shared playbooks, shared metrics. Five…

Sift Author Logo
Beau Roberts
black-dot
Press-Release-Tile-Image-Color-Pills_Blue

Part 3: An Operating Model for What Happens After the Login

Shared accountability, shared telemetry, shared decisioning, shared playbooks, shared metrics. Five parts, and no reorg required on day one.

If you’re joining here, a quick recap. Part 1 argued that account takeover (ATO) is a security failure and a fraud event at the same time, and that most companies are organized so neither team owns the whole attack. Part 2 walked through the same compromise from inside each function: the CISO and the fraud leader each see a real but partial picture, and the stretch between containment and monetization belongs to no one. This final article is about what to do about it.

Closing that gap requires an operating model, not just a better alert.

For account takeover, the practical model has five parts: shared accountability, shared telemetry, shared decisioning, shared playbooks, and shared metrics. Security does not need to become fraud operations. Fraud does not need to run the Security Operations Center (SOC). But both teams need one view of the attack path from credential abuse to cash-out, and one response model for what happens after access succeeds.

closing the gap between fraud and security ops

Gartner® reaches the same conclusion from the threat side: “The entire organization must work together to fight against supply chain attacks, ransomware and evolving account takeover threats targeting humans and machine identities” (Gartner, “Update Your Cybersecurity Priorities in a Shifting Threat Landscape,” September 2025). The last clause matters: machine identities. Service accounts, automations, and increasingly AI agents are part of the same attack surface, which makes single-team ownership even less tenable.

Shared accountability means ATO is treated as a joint risk from day one. Ownership assigns the work. Accountability attaches the incentives that make the work happen and aligns it with business outcomes. Security owns compromise detection. Fraud owns monetization patterns. Identity owns access controls. Customer operations own the recovery experience. The failure mode is not that any one team lacks expertise; it’s that each team can be right about its slice while the business stays wrong about the whole incident.

Shared telemetry means the login signal is connected to what follows: device changes, profile edits, payout updates, transaction velocity, loyalty redemptions, refund behavior, support contacts, and disputes. A credential-stuffing spike may look contained once the login defense holds, but the accounts that slip through can sit quietly for days before changing recovery details, testing small transactions, or draining stored value. That’s where post-login risk becomes visible.

Shared decisioning means risk travels with the session. A suspicious login should not trigger only a binary allow-or-block decision. It should inform whether the user is allowed through, challenged, limited, monitored, queued for review, or denied later when behavior changes. The market already reflects the overlap. Identity and fraud vendors increasingly argue that the old controls, including CAPTCHA, static rules, and even multi-factor authentication (MFA), cannot stop ATO on their own, because modern attacks don’t just test access controls; they test how well identity, fraud, and risk signals work together once a session is live. A real-time risk score feeding the authentication decision (as integrations like Sift’s partnership with Ping Identity demonstrate) means a borderline login can be allowed, challenged with step-up MFA, or denied based on risk rather than a static rule. The same risk context should follow the account into money movement, checkout, support, and recovery workflows.

Shared playbooks and shared metrics close the loop. The playbook defines who acts when an account shifts from suspicious access to probable abuse. The metrics show whether the response protected the business, not just whether an alert was closed: fraud loss after compromise, account recovery time, customer churn after ATO, false-positive rate, support burden, approval rate, and trusted-user friction.

So what should companies do differently?

Treat account takeover as shared from day one. Park ATO only in fraud, and security loses visibility into a major class of account attacks. Park it only in security, and the business misses the monetization and customer harm that define the actual damage. Shared accountability does not demand a reorg on day one. It demands shared language, shared telemetry, and shared response playbooks.

Connect identity to what happens after login. The login is a single data point. Profile changes, payout edits, transaction velocity, redemption behavior, and support contacts often expose the abuse a clean login hides. The strongest detection blends authentication, behavior, device reputation, and downstream activity instead of treating each as a separate gate.

Measure business impact, not just the technical event. If the dashboard reports “contained in minutes” while the same accounts bled losses for days, the scorecard is too narrow. Keep the security metrics. Put trust, loss, and customer-harm measures right next to them. The audience for those measures already exists: in Gartner research, 93% of non-executive directors see cyber risk as a threat to shareholder value. Yet less than 40% of them are confident or very confident in the ability of CIOs/CTOs (38%) and CISOs (37%) to protect enterprises from cyber threats. Boards think in business outcomes. Reporting operational outcomes to them is part of how that confidence gap formed.

Pressure-test the org chart itself. Attackers win when fraud, identity, security, and support each see only a slice. The fix isn’t always a single platform, but it’s almost always better orchestration. The Gartner Cyber-Fraud Fusion framing is useful precisely because the control surface has already outgrown the old team boundaries.

Some organizations have already collapsed the two roles into one. Christopher Mascaro holds the title of chief cyber and fraud officer at payments processor North, and he argues the differentiator is not tooling: “The real competitive advantage in fraud isn’t your AI stack. It’s leadership’s clarity to unify risk disciplines that everyone else keeps in separate departments.”

The stakes are not only operational. These attacks resurface as churned customers, higher support volume, reputational damage, and stalled growth. Sift’s Q2 2026 Digital Trust Index puts numbers on the damage: after an ATO, 11% of consumers stop using the platform permanently and another 35% stay with less trust. After payment fraud, 27% leave for good. The one response that reliably repairs the damage is speed, with 82% of consumers saying quick resolution improves their perception of a company after a fraud incident. Sift frames fraud prevention as protecting the customer experience, not just blocking bad actors, and scores more than a trillion events a year to separate real customers from attackers. That framing resonates because sophisticated security leaders know that in a digital business, protection and experience are the same conversation.

The implication is clear. Fraud isn’t something that happens after cybersecurity ends. In a digital business, it’s how cyber risk becomes business loss.

Security teams are accountable for protecting the enterprise. Fraud teams are accountable for protecting the transaction. Account takeover forces a question neither one owns: who’s accountable for protecting trust when the attacker looks exactly like your customer?

The organizations that answer this question first will be the ones that stop treating ATO as someone else’s problem, and start measuring what happens after the login succeeds.

Part 1 of this series made the case that the gap between security and fraud is the attack surface. Part 2 showed the same compromise through both leaders’ eyes. The operating model above is where the work starts.

Gartner, Update Your Cybersecurity Priorities in a Shifting Threat Landscape, By Jeremy D’Hoinne, John Watts, 18 September 2025. Gartner is a trademark of Gartner, Inc. and/or its affiliates.

Dare to grow differently.

Flip the switch on fraud-fueled fear. Make risk work for your business and scale securely into new markets with Sift’s AI-powered platform.

see sift in action
  • remitly
  • swan
  • yelp-white
  • taptap
  • remitly
  • swan
  • yelp-white
  • taptap