Whitepapers

|

The Session Gap After Login | Banking Whitepaper

Get the Document

The Session Gap After Login

How continuous identity assurance helps banks protect high-risk digital journeys.

Banks have invested heavily in KYC, onboarding and strong authentication to establish who a customer is before granting access. What that investment doesn't cover is what happens next: a valid login doesn't prevent account takeover, session hijacking, unattended-device use, or another person operating an already-trusted session. The UK's APP scam reimbursement requirement, in force since October 2024, has already seen £316 million reimbursed in its first 18 months, at up to £85,000 per claim — a real cost sitting in the gap after login, not before it. This whitepaper looks at where that gap opens, what banks and regulators are starting to expect in response, and how continuous, on-device identity verification closes it without replacing any of the controls already in place.

What's inside:

  • Why a successful login doesn't mean the bank still knows who's there — and how account takeover, session hijacking and unattended-device use slip through a gap authentication alone was never built to close.

  • Where continuous identity assurance fits alongside the controls banks already run — device intelligence, behavioural biometrics, transaction monitoring — and the specific attack patterns none of them fully cover on their own.

  • What UK, US and Middle East regulators are already asking for, from the FCA's Consumer Duty to APP scam reimbursement rules, and how session-level evidence supports it.

  • Why one-time codes carry their own cost and attack surface, and how passive, on-device verification reduces reliance on them without adding friction for genuine customers.

  • How on-device processing keeps biometric data off YEO's servers entirely, so continuous assurance doesn't create a new data-governance problem.

  • A practical framework banks can use to evaluate continuous identity assurance against their own risk, customer experience, technology and governance priorities.

About us

We stopped asking "who logged in." We started asking "who's still there." YEO began as a secure messaging app. Today we build the patented continuous identity verification infrastructure that regulated industries trust to prove who's really there.

© 2026 YEO messaging Ltd is registered in England and Wales 10785061.

🇺🇸 US Patent No: 10,607,035 (Granted March 31, 2020)
🇬🇧 GB patent No: 1713943.7 (Granted February 2022)
🇨🇳 Chinese patent 201880071020.4 (Granted April 2nd 2024)
🇪🇺 EU patent No: PCT/EP2018/073464 (Granted July 2026)

© 2026 YEO messaging Ltd is registered in England and Wales 10785061.

🇺🇸 US Patent No: 10,607,035 (Granted March 31, 2020)
🇬🇧 GB patent No: 1713943.7 (Granted February 2022)
🇨🇳 Chinese patent 201880071020.4 (Granted April 2nd 2024)
🇪🇺 EU patent No: PCT/EP2018/073464 (Granted July 2026)

© 2026 YEO messaging Ltd is registered in England and Wales 10785061.

🇺🇸 US Patent No: 10,607,035 (Granted March 31, 2020)
🇬🇧 GB patent No: 1713943.7 (Granted February 2022)
🇨🇳 Chinese patent 201880071020.4 (Granted April 2nd 2024)
🇪🇺 EU patent No: PCT/EP2018/073464 (Granted July 2026)