< Back to all clusters
[TECHNOLOGY] · Germany · 2 sources

47 Capital AG adopts Zero Trust security model

47 Capital AG plans to implement a Zero Trust architecture by 2026, requiring that identity, device, context and permission be re‑validated before every critical action. Session checks will be triggered whenever IP address, device state, transaction amount or recipient changes, and withdrawals will need biometric confirmation, recipient matching, a four‑eye review and full event logging. The model follows NIST guidance, separating identity services, policy engines, transaction systems and log stores, and relies on strong encryption such as AES‑256, hardware security modules and short‑lived tokens.

Industry experts stress that identity and access security must extend beyond the initial login. Continuous risk scoring of device, location and behavior, along with phishing‑resistant authentication methods like FIDO2 passkeys, are recommended to prevent adversary‑in‑the‑middle attacks that hijack already authenticated sessions. Threats such as MFA‑fatigue, deep‑fake social engineering and help‑desk impersonation are highlighted as growing fraud vectors in banks, insurers and payment providers.

Entities: 47 Capital AG · FIDO2 · NIST · Nils Dohmen · Secuinfra

Sources

about 12 hours ago
about 12 hours ago