For most of digital banking's history, the fraud perimeter was easy to draw: the card, the account. Protect those two things and you'd protected the customer. That perimeter has quietly expanded, and most institutions are still monitoring the old boundary.
The Old Perimeter vs. the New One
The old perimeter was Card and Account. The new one is considerably wider: mobile number, device, credentials, behaviour, session, beneficiary, and transaction — each a point an attacker can compromise independently of the card or account itself, and each one now routinely exploited.
- Account takeover via credential theft or SIM swap, bypassing the card entirely.
- Device changes that precede fraud without any card data ever being touched.
- Social engineering that compromises judgement rather than any system.
- Session and behavioural anomalies that only appear once you're watching the right layer.
Why This Matters Now
An FRM system still built around card and account risk is defending a perimeter that no longer matches where the actual attacks land. Digital identity — the sum of a customer's device, credentials, behaviour and session — is where the real exposure now sits, and it needs to be monitored as directly as the card number always was.
If your fraud monitoring can tell you everything about a card and very little about the device, session and behaviour behind it, the perimeter you're defending isn't the one being attacked.