DevCentral Connects - Open Finance Security Risks, Compliance And Architectures

F5 DevCentral CommunityAbout 6 min readAug 22, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

Open Finance, Open Banking, APIs, API Security, Data Monetization, Embedded Finance, Banking as a Service, Digital Transformation, Threat Vectors, Authentication, Authorization, API Discovery, Shadow APIs, Compliance, CFBB 1033, Dodd-Frank, OAuth 2.0, Mutual TLS, PQC (Post-Quantum Cryptography), Harvest Now Decrypt Later, Distributed Cloud, Customer Edge (CES), Equinix POPs, WAF (Web Application Firewall), API Protection, Regulatory Initiatives, Market Initiatives.

Open Finance: A Transformative Movement

The discussion centers around the evolution of open banking into open finance, a global movement driven by regulatory foundations and innovation. Initially focused on data sharing and consumer protection, it has expanded to encompass data monetization, embedded finance, and banking as a service. The current stage is heavily influenced by AI, leading to increased innovation and market initiatives aimed at streamlining and securing the customer journey.

Key Points:

  • Evolution: Open Banking -> Open Finance (Data Sharing -> Innovation-led)
  • Drivers: Regulatory Foundations, Innovation (Embedded Finance, Data Monetization, Banking as a Service)
  • Impact of AI: Amplified innovation, increased API traffic, new threat vectors.
  • Goal: Streamlined, secure customer experience.

The TwinBit Report: Global State of Open Finance 2025

F5 has partnered with TwinBit to produce a report analyzing the global state of open finance. This is the third iteration, evolving from a focus on open banking to the broader open finance landscape. The report evaluates 32 countries based on regulatory and market initiatives, categorizing them into quadrants (Champions, Enthusiasts, etc.) to assess their readiness and success in open finance.

Key Points:

  • Purpose: Understand open finance movement, innovations, and challenges.
  • Evolution: Tracks the transformation from open banking to open finance.
  • Country Evaluation: Assesses regulatory and market initiatives in 32 countries.
  • Quadrant Model: Categorizes countries based on their progress in open finance.

Growth Opportunities and Market Size

The open finance movement presents significant growth opportunities, particularly in the API market. The report highlights substantial increases in digital wallet spending and API market size, indicating the growing importance of secure and scalable APIs in the financial services sector.

Key Points:

  • Digital Wallet Spending: $15.7 trillion global digital wallet consumer and business spending in 2024.
  • API Market Growth: Projected 500% increase in API market size (from $37 billion to $720 billion).
  • Implication: Banks and financial firms will invest heavily in API security and scalability.

Buyer Pains and Marketing Messaging

Banks and financial institutions face challenges in navigating the complexities of open finance, particularly in securing APIs and managing data access. The primary concern is ensuring a streamlined and secure customer journey while addressing issues related to data ownership and usage rights.

Key Points:

  • Challenges: Securing APIs, managing data access, ensuring customer journey.
  • Concerns: Data ownership (bank vs. customer), usage rights.
  • Marketing Focus: Streamlined, secure customer experience.

Architectural Considerations and API Security

Open finance relies heavily on APIs, which introduces significant security risks. A robust API security strategy is essential, encompassing authentication, authorization, and threat mitigation. Solutions should be deployable across various environments (public cloud, on-prem, containers) and offer a single pane of glass for management.

Key Points:

  • API Security: Paramount due to increased exposure to the internet.
  • Authentication & Authorization: Critical for identifying users and controlling access to API endpoints.
  • Threat Vectors: OWASP Top 10, particularly Broken Object Level Authorization (BOLA).
  • Deployment Flexibility: Solutions should support various environments and form factors.

API Discovery and Shadow APIs

API discovery is crucial for identifying and managing all APIs within an organization, including shadow APIs (APIs that are not properly managed or secured). A comprehensive API inventory helps prevent vulnerabilities and ensures that all APIs are protected.

Key Points:

  • API Discovery: Essential for identifying and managing all APIs.
  • Shadow APIs: Unmanaged or unsecured APIs that pose a significant security risk.
  • Benefits: Prevents vulnerabilities, ensures comprehensive API protection.

Compliance and Regulations

Compliance with regulations such as CFBB 1033 (related to Dodd-Frank) is essential for open finance initiatives. These regulations mandate proper authentication and API security measures to protect customer data.

Key Points:

  • CFBB 1033: Open finance regulation derived from Dodd-Frank.
  • Customer Protection: Regulations focus on protecting customer data and ensuring secure API access.
  • Europe Leading: Europe is often at the forefront of regulations and standardizations.

F5 Solutions for Open Finance

F5 offers a range of solutions for securing and managing APIs in open finance environments, including:

  • Big IP: Provides API protection capabilities.
  • EngineX: Offers EngineX App Protect for containerized environments.
  • Distributed Cloud Platform: A holistic solution with API discovery, WAF, and single-pane-of-glass management.

Key Points:

  • Holistic Platform: F5 Distributed Cloud offers a comprehensive solution for API security and management.
  • API Discovery: Included in the base package of Distributed Cloud (for testing purposes).
  • Deployment Options: Software can be deployed in various environments, including Equinix POPs and customer data centers.

Post-Quantum Cryptography (PQC)

The discussion touches on the importance of post-quantum cryptography (PQC) to protect against future threats from quantum computers. The "harvest now, decrypt later" threat highlights the need to implement PQC ciphers to safeguard data transmitted over APIs.

Key Points:

  • PQC Importance: Protects against future quantum computing threats.
  • Harvest Now, Decrypt Later: Data captured today could be decrypted by quantum computers in the future.
  • F5 Support: F5 solutions like Distributed Cloud and Big IP can implement PQC ciphers.

Chase Abbott Article: API Security Basics

An article co-authored by Chase Abbott and Chad Davis outlines the basics of API security, including authentication, encryption, and access control. The article emphasizes the importance of OAuth 2.0, mutual TLS, and schema-based authorization.

Key Points:

  • Authentication: OAuth 2.0, mutual TLS.
  • Encryption: Protecting data in transit.
  • Access Control: Schema-based authorization, rate limiting.

Customer Edge (CES) Deployment

F5's Customer Edge (CES) allows customers to deploy F5's software in their own environments (e.g., Equinix POPs) while maintaining a single control plane through the Distributed Cloud Platform. This provides greater control over the data plane and allows for customized security configurations.

Key Points:

  • Control Plane vs. Data Plane: Customers can manage the control plane through F5's SaaS service while controlling the data plane in their own environment.
  • Deployment Flexibility: CES can be deployed in various environments, including Equinix POPs and customer data centers.
  • Mitigation Capabilities: CES can mitigate DDoS attacks and other threats.

Conclusion

The discussion emphasizes the importance of open finance as a transformative movement, highlighting the need for robust API security, compliance, and innovative solutions. F5 offers a range of products and services to help organizations navigate the complexities of open finance and secure their API ecosystems. The key takeaways include the importance of API discovery, comprehensive security strategies, and the need to prepare for future threats such as quantum computing.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.