
Why Zero Trust Is Critical in Open Banking
The cyber risks within Open Banking are systemic — and rising fast. Industry research shows API-related breaches are growing by more than 30% each year, with financial services among the top targets. Gartner predicts (March 2025) that by 2025, 60% of institutions will treat Zero Trust as a baseline for digital ecosystems. Regulators are aligned too. Globally and in the MENA region frameworks mandate rigorous identity controls, monitoring, and third-party oversight.
The principle of open banking is to allow the account holders to securely share their data with relevant service providers such as lenders, budgeting tools, and wealth management. In return, these service providers provide them innovative and tailored financial services.
Zero Trust, hence in open banking, is unavoidable to due to several realities such as
- Expanded attack surface: Every new API endpoint opens a potential opportunity for attackers.
- Third-party dependencies: Each integrated fintech, vendor or partner introduces risk.
- Credential abuse: The most common cause for data breaches is due to identity and credential theft.
- Customer trust: A single breach could undermine confidence in open banking adoption, a risk no provider, regulator or the eco-system can afford.
In short, the archaic perimeter defences alone cannot cope. Every request, every device, and every user must be continuously verified.
From Principle to Practice: Spare’s Example
At Spare, Zero Trust is not a theory but a philosophy that shapes everyday operations. Spare applies layered identity and access controls, continuous visibility into critical environments, and strict vendor supervision to ensure every transaction, every API call is verified and authorised.
Environments such as development, testing, and production are segregated to limit risk. Employee and partner access is governed through multi-factor authentication and regular reviews. Endpoints and applications are monitored for compliance, while third-party providers must meet defined security standards before integration.
These measures, aligned with local regulatory requirements, illustrate our pragmatic Zero Trust approach that balances innovation with resilience.
Raising the Bar for the Region
Open banking will only thrive if customers feel confident that their most sensitive financial data is safe. Zero Trust provides that confidence by replacing assumption with verification, static controls with continuous monitoring, and siloed defences with an ecosystem-wide mindset.
In open banking, Zero Trust is less a competitive edge than a baseline necessity. Put simply: Zero Trust is now the standard for securing financial innovation.
About the Contributor
Saurabh Shah – COO and Co-Founder of Spare
Saurabh’s background includes Strategy Consulting and Advanced Analytics. Saurabh started his career with Mu Sigma, a data and analytics service company which became one of the first unicorns to come out of India. Prior to joining Spare, Saurabh was a Partner in the London office of Boston Consulting Group. At BCG, Saurabh focused on Financial Services and Utilities industries. Within these sectors, Saurabh has worked significantly on large scale technology and operations transformations. Saurabh also holds an MBA from INSEAD Business School.








