Blog Categories | Ideem
Resources and insights
The latest industry news, interviews, technologies, and resources.
.png)
Mula-X Chooses Passkeys+ to Replace SMS OTPs Across Its Digital Wallet Platform
Mula-X is rolling out Ideem's Passkeys+ across its Thailand digital wallet platform, replacing SMS-based OTPs with biometric, device-bound authentication built on the FIDO standard.
Maranda Manning April 7, 2026 • 4 min read
PSR3 / PSD3 Implementation Update: Where Europe Stands in Mid-2026
The PSR/PSD3 package is out of trilogue with final compromise texts circulated April 23, 2026, putting EU banks on a roughly two-year runway to substantive application in 2028. The regulation ratifies the phishing-resistant, transaction-bound authentication architecture that was already the right answer on security grounds.
Toby Rush June 2, 2026 • 9 min read
MAS Notice 655 (Singapore): The Quiet Authentication Mandate Reshaping APAC
MAS Notice 655 (now FSM-N06) and the Technology Risk Management Guidelines set the cyber hygiene floor that drove Singapore's SMS OTP phase-out, the Shared Responsibility Framework, and the October 2025 ABS safeguards — and the same template is cross-pollinating across APAC via BSP Circular 1213, BNM's RMiT update, and HKMA's parallel work.
Maranda Manning June 2, 2026 • 9 min read
Qatar Central Bank's 2025 Data Handling Regulation: What It Signals for Bank Authentication
QCB announced its Data Handling and Protection Regulation in February 2025, joining a cybersecurity framework that mirrors the trajectory SAMA and UAE Central Bank are already on. What Qatari banks should be doing now to prepare for the inevitable authentication-specific directives.
Maranda Manning June 2, 2026 • 7 min read
NIST SP 800-63-4 and U.S. Bank Authentication: A 2026 Implementation Guide
NIST SP 800-63-4 is the most significant update to U.S. digital identity guidelines in nearly a decade. A practical guide for U.S. banks on what changed, where passkeys fit at AAL2 and AAL3, and how to build a 2026-2027 alignment program.
Greg Storm June 2, 2026 • 7 min read
PSD3 Strong Customer Authentication Requirements: 2026 Compliance Guide
PSD3 builds on PSD2's authentication foundation with tighter fraud prevention standards, reduced exemption thresholds, and explicit guidance on phishing-resistant methods. EU financial institutions should prepare for implementation starting 2027-2028.
Toby Rush May 6, 2026 • 8 min read
SAMA Authentication Requirements: Saudi Arabia Banks Move Beyond OTP
SAMA is advancing authentication requirements beyond traditional OTPs through the National Cybersecurity Authority's framework. Financial institutions should prepare for stricter standards prioritizing FIDO2 protocols and device-bound credentials.
Maranda Manning May 6, 2026 • 8 min read
BSP Circular 1213: 2026 Compliance Guide for Philippine Banks
The BSP has confirmed the June 2026 Circular 1213 deadline stands. Philippine banks face a tight window to phase out SMS and email OTPs, deploy real-time fraud management systems, and earn AFASA liability protection. Here is the practical playbook.
Toby Rush May 6, 2026 • 9 min read
Southeast Asia's Authentication Moment: Vietnam, the Philippines, and the ASEAN Wave
Vietnam and the Philippines have moved decisively on authentication reform. Thailand, Malaysia, and Singapore are close behind. Southeast Asia is quietly becoming one of the most active regulatory environments for authentication in the world — and financial institutions need to be paying attention.
Greg Storm March 6, 2026 • 8 min read
25+ Regulators Can't Be Wrong: The Global Shift to Phishing-Resistant Auth
More than 25 regulators worldwide have moved toward phishing-resistant authentication mandates. This isn't a trend — it's a wave. Here's what's driving the global convergence, which frameworks matter most, and what it means for financial institutions building authentication strategy today.
Toby Rush March 6, 2026 • 8 min read
BSP Circular 1213 in 2026: Is Philippine Banking Compliant Yet?
BSP Circular 1213 raised the authentication bar for Philippine financial institutions. More than two years on, compliance across the sector is uneven. Here's an honest assessment of the gaps, what full compliance actually looks like, and why the BSP's direction of travel won't reverse.
Greg Storm March 6, 2026 • 8 min read
India's Digital Payments Evolution: How RBI and Banks Are Securing the World's Fastest-Growing Ecosystem
India's UPI processes billions of transactions monthly across vastly different devices, literacy levels, and connectivity conditions. Explore how RBI and Indian financial institutions are pioneering authentication approaches that serve both security and inclusion.
Greg Storm February 10, 2026 • 9 min read
How SAMA Became the Global Gold Standard for Authentication Regulation
Saudi Arabia's central bank built one of the most actionable authentication regulatory frameworks in global financial services. Explore what SAMA got right — specificity, collaboration, and measurable outcomes — and why regulators worldwide are now studying its approach.
Toby Rush February 10, 2026 • 8 min read
How RBI’s New 2FA Mandate Impacts India’s Digital Payments
- Toby Rush December 22, 2025 • 4 min
What the UAE’s 2025 Licensing and Data-Sharing Regime Means for Wallets, Merchants & Fintechs
- Toby Rush November 26, 2025 • 5 min
Regulatory Adaptation: Keeping Pace with Compliance Needs as Fraud Evolves
- Toby Rush November 26, 2025 • 4 min
Philippine Payments and Checkout Friction: Turning BSP Compliance into a Competitive Edge
- Toby Rush November 26, 2025 • 2 min
How the UAE’s Digital Payment Rules Are Driving a Shift Beyond OTP Authentication
- Toby Rush November 26, 2025 • 5 min
From OTP to Passkeys: How RBI’s Framework Drives Better Checkout
- Toby Rush November 26, 2025 • 3 min
Device Binding and BSP Circular 1213: How Authentication Is Changing in the Philippines
- Toby Rush November 26, 2025 • 4 min
RBI’s Authentication Update: Why Cross-Border Payments Must Evolve
- Toby Rush November 26, 2025 • 6 min
Thailand’s AI-Powered Scam Block Law: Lessons for Financial Platforms
- Greg Storm September 16, 2025 • 5 min
.jpg)
Microsoft Deletes Billions of Passwords: The Future of Login
- Greg Storm August 25, 2025 • 3 min
UAE Central Bank OTP Directive
- Greg Storm November 26, 2025 • 5 min
BSP Circular 1213: What It Means for Authentication
- Greg Storm July 16, 2025 • 5 min
Beyond Passwords: How PSD3 Could Reshape the Future of Digital Identity in European Finance
Europe’s digital payments landscape is evolving—again. With the introduction of PSD3 and its companion regulation (PSR), the European Union is not only responding to rising fraud but also setting the stage for a more secure and inclusive financial future. At the heart of this shift lies a reimagining of Strong Customer Authentication (SCA) and the role that modern, passwordless solutions like passkeys might play in it.
Greg Storm May 19, 2025 • 5 min read
What Is Strong Customer Authentication (SCA) and Why the Status Quo Still Falls Short
In the ongoing battle against fraud and digital identity theft, Strong Customer Authentication (SCA) has emerged as a critical safeguard. Mandated in regions like the EU under the PSD2 directive and gaining traction globally, SCA aims to ensure that users are who they say they are before transactions are approved or sensitive information is accessed.
Greg Storm May 9, 2025 • 3 min read
BSP’s 2FA Mandate: A Catalyst for Secure, Frictionless Digital Banking
- Greg Storm August 11, 2025 • 2 min
New BSP 2FA Regulations: 3 Easy Steps to Compliance
- Greg Storm August 11, 2025 • 1 min