Detecting and Preventing Real-Time Deepfake Impersonation

If you are concerned about the growing threat of deepfakes, you are not alone. The spread of deepfakes is closely tied to the question of what is real and what is fake, as well as the growing erosion of digital trust. So, what exactly are deepfakes, and how can we detect and prevent them? Let’s explore these questions in today’s article. 1. What Are Deepfakes? Deepfakes are highly realistic forms of synthetic media, typically in the form of video or audio, created using AI to manipulate or fabricate content, making viewers believe that someone said or did something they never actually said or did. As a result, deepfakes are increasingly being used to facilitate financial fraud, undermine user trust, and create risks for legal systems. However, like many other AI technologies, deepfakes also have positive applications, including online education, digital content creation, and enhanced film production. Nevertheless, the risks associated with deepfakes are increasingly beginning to outweigh their potential benefits. 2. How to Detect Deepfakes Deepfakes affect users in three primary ways: by manipulating personal data or images; deceiving viewers into believing that fake content is real; and causing genuine content to be mistakenly identified as fake. So, how can we determine whether content is a deepfake? Below are four key techniques that can help. 2.1 Manual Inspection Using the Naked Eye 2.2 Contextual Checks 2.3 Technical Detection Tools The rapid development of AI technology is making the detection and prevention of deepfakes increasingly challenging. To mitigate and prevent these threats, technology providers, users, and regulators must work together. From a technology perspective, capabilities such as Blockchain-based content provenance and verification need to be strengthened to help establish the origin and integrity of digital content. Users need to develop stronger media literacy, verify content before sharing it or carrying out requested transactions, and report suspicious content. Finally, regulators need to strengthen platform policies and enforcement mechanisms, establish proactive content moderation systems, clearly label deepfake and AI-generated content, introduce effective deterrents against the malicious use of deepfakes, mandate greater transparency for AI-generated content, and work toward global standards for digital integrity. By bringing these efforts together, we have a real opportunity to restore digital trust and give users greater confidence and security in the online environment. Contact SAVYINT’s experts today for consultation on digital fraud detection solutions HERE.
Singapore’s Singpass Introduces Passkeys to Strengthen National Digital Identity

The Government Technology Agency of Singapore (GovTech Singapore) announced the rollout passkey on Jun 30, 2026 as a new login method for Singpass, Singapore’s national digital identity platform. Singpass is every Singapore resident’s trusted digital identity to prove who we are when performing everyday transactions like checking our CPF balance, booking medical appointments, renewing insurance and more. Access over 2,700 services across 800 government agencies and businesses, simply by authenticating with your biometrics or SMS Two-Factor Authentication (2FA). Created by GovTech as a key enabler of Singapore’s digital economy, Singpass facilitates over 41 million transactions every month. Out of 5 million Singpass users, more than 4.2 million people use the Singpass app to easily log in to services, prove their identity over counters, digitally sign documents and do more on the go. Passkeys add to existing authentication methods such as QR login, Face Verification, and SMS One-Time Passwords (OTPs). Passkeys are a secure, password-free way to log in to services with Singpass. They are phishing resistant and use device-based authentication such as facial recognition, fingerprint, or app passcode to verify your identity. If a device is lost or stolen, the Singpass app and passkey on it will be automatically deactivated when the user sets up Singpass on another device. What is a Passkey? A passkey is a cryptographic key designed to replace passwords. As old passwords could easily be stolen, hacked, or even guessed, passkeys would work on a completely different level, with public-private key pairs authentication. Unlike a password, passkeys cannot be shared, remembered, or written down. This makes it far less vulnerable to the types of attacks that commonly target password-based systems. While early biometric authentication technologies laid the foundation for identity verification, the journey toward passkeys began in 2012 with the establishment of the FIDO Alliance, with the mission of eliminating passwords. The passkey revolution began in 2021, when major technology companies adopted the FIDO2 and WebAuthn standards, enabling passwordless authentication. Today, passkeys have become an authentication method accessible to billions of users worldwide. A significant milestone in the evolution of passkeys was the National Institute of Standards and Technology (NIST) formally recognizing synced passkeys in its supplement to the SP 800-63B guidelines. NIST SP 800-63B Supplement This recognition highlights the phishing-resistant nature of passkeys, while demonstrating their potential to replace traditional passwords with a more secure, convenient, and user-friendly authentication method. With NIST’s recognition, passkeys are well positioned for widespread adoption, particularly in highly regulated industries such as banking and healthcare. This is expected to drive the next phase of secure digital identity verification. The Difference Between Passkeys and Passwords Types of Passkeys There are two main types of passkeys, designed for different use cases and, more importantly, different security requirements. Within the digital security ecosystem, the two primary categories are Multi-Device Passkeys and Device-Bound Passkeys. Let’s explore the differences between them. Multi-Device Passkeys Multi-Device Passkeys, also known as Synced Passkeys, are well suited for personal use. They can be seamlessly synchronized across multiple devices, such as smartphones, tablets, and laptops, provided those devices are linked to an Apple, Google, or Microsoft account. This flexibility allows users to access their accounts from any trusted device without having to remember or enter a password. Device-Bound Passkeys In contrast, Device-Bound Passkeys can be viewed as a “security shield” for enterprise environments. Because they are bound to a single device and cannot be copied, this type of passkey provides an additional layer of security that is particularly valuable for organizations with strict data protection and access control requirements. In other words, Multi-Device Passkeys prioritize convenience and flexibility, while Device-Bound Passkeys prioritize stronger control and security. Benefits of Passkeys Benefits for Users Benefits for Developers As these technologies continue to evolve, more people are asking: What is a passkey, and how does it work? Growing interest in passkeys is encouraging technology innovators to invest significant resources in researching, developing, and advancing this technology. Passkeys are set to bring profound changes to security and digital identity while shaping how future generations interact with the digital world. Reference source: https://www.passkeys.com/ Contact us HERE to explore Savyint’s most advanced and secure solutions for authentication and digital identity.
eIDAS 2.0 – Reshaping a Safer and More Trusted Digital Future for Europe

Building on the foundation of eIDAS – the European framework for “Electronic Identification, Authentication and Trust Services” in the European Single Market – eIDAS 2.0 was introduced to strengthen the region’s digital infrastructure, promising greater efficiency and higher levels of trust in the digital economy. eIDAS – The Regulation on Electronic Identification, Authentication and Trust Services Approved in September 2014, the Regulation on “Electronic Identification, Authentication and Trust Services” for the European Single Market, known as eIDAS, became fully applicable in September 2018. Under eIDAS, European citizens and businesses can use nationally issued electronic identification systems to verify their identities when accessing public services or carrying out cross-border electronic transactions. eIDAS focuses on two key areas: Importantly, eIDAS applies not only to public authorities but also to private-sector organizations that use electronic identification or trust services, including those in the financial services, insurance, healthcare, and e-commerce sectors. As such, eIDAS serves as a unified digital trust infrastructure for cross-border electronic transactions across Europe. Why is eIDAS 2.0 Needed? Although eIDAS significantly improved Europe’s electronic identification and trust services infrastructure, several limitations remained. The emergence of new electronic identification services and models has resulted in a fragmented market. The scope of the existing legal framework no longer fully reflects the way electronic identification and trust services are being used in practice. Today, private companies also provide eID solutions, but these solutions do not necessarily follow a unified standard offering the same high levels of security, assurance, and transparency as eID schemes recognized under eIDAS. While eIDAS-compliant eID solutions are secure, their adoption and usability in the private sector have remained relatively limited. Challenges also exist in areas such as identity verification, data management, and user control. Today’s users expect a seamless and secure online experience. They want to access both public and private services such as healthcare and banking through a single, convenient digital identity or Single Sign-On (SSO) experience. However, the original eIDAS framework focused primarily on cross-border access to public services, while giving less attention to the needs of the private sector. Even for public services, barriers remain that prevent many citizens from accessing trusted electronic identification solutions. Social media platforms and private technology companies already offer login options based on existing accounts, such as Facebook, Microsoft, or Google. However, these solutions raise concerns regarding data control and security. They often lack robust real-world identity verification processes, potentially making systems more vulnerable. In addition, using these platforms across multiple services may result in non-transparent data sharing and privacy concerns. What is eIDAS 2.0? eIDAS 2.0 – officially known as the European Digital Identity Framework under Regulation (EU) 2024/1183 – is the updated version of the European Union’s framework for electronic identification, authentication, and trust services. The updated framework is designed to improve the efficiency of cross-border services while supporting secure electronic identification solutions for both the public and private sectors. eIDAS 2.0 represents a structural evolution of Europe’s digital identity and trust services framework. It addresses limitations in the original framework, expands the range of regulated trust services, strengthens security and governance requirements, and, most notably, introduces the European Digital Identity Wallet (EUDI Wallet) as a core component of Member States’ digital identity ecosystems. Key Changes Introduced by eIDAS 2.0 The transition from eIDAS to eIDAS 2.0 introduces two major developments aimed at strengthening Europe’s legal and regulatory framework for electronic identification and trust services. Expanded Trust Services eIDAS 2.0 further develops the regulatory framework for Qualified Trust Service Providers (QTSPs), with particular emphasis on identity verification processes for individuals and legal entities when qualified certificates are issued. The objective is to ensure greater consistency and harmonization across Europe. In addition, new qualified trust services – including electronic archiving, electronic ledgers, and the management of remote electronic signature devices – have been introduced under eIDAS 2.0. European Digital Identity Wallet (EUDI Wallet) One of the most significant innovations introduced by eIDAS 2.0 is the European Digital Identity Wallet (EUDI Wallet). The EUDI Wallet is a secure, user-controlled digital wallet that enables individuals to store, manage, and selectively share their identity data, credentials, and other personal information, as well as verified legal documents such as driving licences, educational qualifications, professional certificates, or bank account information. The Wallet can be used for both online and offline services, allowing users to conveniently share verified credentials with relying parties including government authorities and private-sector organizations for purposes such as identity verification or electronic signing. Under the original eIDAS framework, EU Member States had the discretion to decide whether to develop or notify official national electronic identification schemes. This resulted in significant differences in adoption rates among Member States and inconsistencies in cross-border interoperability. eIDAS 2.0 replaces this approach with a more unified and mandatory framework. By the end of 2026, each EU Member State is required to make at least one European Digital Identity Wallet (EUDI Wallet) available to its citizens and residents. Conclusion The adoption of eIDAS 2.0 marks a significant step toward a secure, interoperable, and trusted ecosystem for electronic identification and trust services across the European Union. By emphasizing user-friendly experiences, strong security mechanisms, and streamlined processes, eIDAS 2.0 is expected to deliver tangible benefits for citizens, businesses, and government institutions alike. While the detailed implementation roadmap is still being developed, the foundations have now been established for a safer, more inclusive, and more trusted digital future for people across Europe.
Strengthening Authentication, Fraud Prevention and Risk Governance Become Top Priorities for Philippine Banks

To strengthen fraud prevention, the Bangko Sentral ng Pilipinas (BSP), under Circular No. 1213, requires institutions to adopt enhanced authentication methods in place of SMS and email OTPs, while also strengthening automated fraud management systems. According to BSP Circular No. 1213, issued in May 2025, the central bank requires BSP-supervised financial institutions to replace SMS- and email-based OTPs with stronger authentication methods such as biometrics, behavioural authentication, adaptive authentication, or passwordless authentication by 25 June 2026. In addition, the circular sets out specific requirements for strengthening automated fraud monitoring. This directive applies to banks and e-wallet operators with average online transaction revenues of more than PHP 75 million per month, including most commercial banks, digital banks, cooperative banks, and rural banks. Banks that fail to comply must reimburse customers for funds lost due to fraud. 1. Authentication and Compliance Requirements Circular 1213 requires institutions to move away from authentication mechanisms that can be shared with or intercepted by third parties. SMS and email OTPs fall under this definition. By 30 June 2026, high-risk transactions and critical account changes must use phishing-resistant, device-bound alternatives, such as server-side biometrics authenticated against templates stored by the bank, or FIDO2/WebAuthn passkeys with device authentication. OTPs may only be used to confirm ownership of a registered mobile phone number. Biometrics BSP requires financial institutions to adopt server-side biometric authentication, where customer identity is verified within the bank’s secure backend system based on biometric templates stored on the bank’s server. The use of biometrics is expected to reduce the risks of account takeover, device compromise, spoofing, and unauthorized changes to authentication credentials. FIDO2 Passkey FIDO2/WebAuthn is a passwordless authentication standard designated by BSP as a mandatory solution for high-risk transactions and critical account changes, which must use phishing-resistant and device-bound alternatives. Smart OTP As mentioned above, Smart OTP is used for one purpose only: confirming ownership of a registered mobile phone number. It must not be used for transaction authentication. This is an important distinction that banks should note to avoid confusion with traditional OTPs. 2. Fraud Prevention and Management Requirements In addition to strong authentication methods, Circular 1213 also requires financial and banking institutions to strengthen their proactive fraud monitoring and detection capabilities by identifying suspicious transactions, unfamiliar devices, and abnormal customer behaviour before financial losses occur. Accordingly, fraud management systems must operate in real time and be capable of: BSP emphasizes that batch processing or end-of-day reconciliation does not meet this standard. 3. AI-Powered Strong Authentication and Fraud Prevention Solutions from Savyint With extensive experience working with and supporting financial institutions, SAVYINT provides a security and fraud prevention solution suite that supports compliance with AFASA and BSP Circulars 1213, 1214, and 1215. The solution suite is built around four pillars: strong and passwordless authentication; AI-powered fraud management; security, data encryption, and application protection; and risk management and compliance with local and international regulatory requirements. It ensures end-to-end protection across the entire customer journey, from registration, login, and transaction authentication to post-transaction monitoring. Key differentiators of the SAVYINT solution suite include: In particular, Savyint’s solution suite supports compliance with regulatory requirements in multiple countries, including the Philippines, such as AFASA and BSP Circulars 1213-1215; Vietnam, such as Circulars 50, 64, and 77 of the State Bank of Vietnam; and Singapore, such as MAS requirements. It also aligns with international security standards including FIDO2, PSD2/PSD3, eIDAS, GDPR, PCI DSS,… Connect with our experts today to quickly achieve compliance with AFASA and BSP Circulars 1213-1215.
Savyint wins two Sao Khue 2026 Awards, with Savyint Digital Trust rated 5 stars

In its second year participating in the Sao Khue Awards, Savyint continues to stay committed to its mission of strengthening cybersecurity and digital trust, with two technology solutions honored at the Sao Khue Awards 2026: Savyint Digital Trust and SAM Appliance. Notably, Savyint Digital Trust received a 5-star rating in the Application and Data Security category. On May 28, the Sao Khue Awards 2026 Ceremony was solemnly held in Hanoi by the Vietnam Software and IT Services Association (VINASA), under the patronage of the Ministry of Science and Technology. Entering its 23rd year, Sao Khue 2026 marks an important transformation as it is redesigned under the “new-generation Sao Khue” model—not only as an event honoring outstanding digital technology products and services, but also as a system for evaluating, validating and positioning the digital technology capabilities of Vietnamese enterprises. After rigorous assessment rounds, the Final Jury of the Sao Khue Awards 2026 selected 123 outstanding digital platforms, services and solutions. These recognized solutions clearly reflect the strong shift in technology trends toward platforms capable of solving practical problems, optimizing operations, protecting data, enhancing transaction security and building trust in the digital environment. This year, Savyint’s award-winning solutions at Sao Khue demonstrate the company’s research, development and mastery of core technologies in cybersecurity, cryptography, electronic identification, digital signatures and online fraud prevention through Savyint Digital Trust and SAM Appliance. In particular, Savyint Digital Trust received a 5-star rating for its relevance and ability to keep pace with global fraud prevention trends. Savyint Digital Trust – A comprehensive security and fraud prevention platform In response to the growing need for proactive fraud prevention and increasingly stringent international regulatory requirements, Savyint Digital Trust is a unified security platform designed to protect the entire digital journey of users and transactions. Built on a Zero Trust security architecture powered by cryptography, Savyint Digital Trust helps organizations strengthen security, enhance user experience and build sustainable digital trust. The solution integrates key capabilities, including: With high scalability and flexible integration with internal enterprise systems, Savyint Digital Trust is suitable for various sectors, including digital banking, fintech, e-wallets, payments, e-commerce, enterprises, government, public services and systems that process sensitive data. SAM Appliance – An all-in-one solution for data encryption, digital signature authentication and mobile identification Alongside Savyint Digital Trust, SAM Appliance is also one of SAVYINT’s two solutions honored at Sao Khue 2026. It is an all-in-one solution for data encryption, digital signature authentication and mobile identity, built on a Cloud HSM platform. The solution ensures compliance with standards for remote signing, blockchain, crypto assets, mobile payment, data encryption, transaction encryption, timestamping, security, system authentication, IoT, Car2X and more. SAM Appliance includes: SAM Appliance confidently complies with regional technical standards as well as international legal and regulatory requirements such as FIPS 140-2 Level 3, ISO 9001:2015, ISO 14001:2015, ISO 27001:2022, GDPR, SOC 2 Type II, HIPAA and PCI DSS. Notably, SAM Appliance supports Post-Quantum algorithms such as ML-KEM, ML-DSA and SLH-DSA, helping shape organizations’ security strategies in the quantum era. The Sao Khue Awards 2026 are not only a recognition of SAVYINT’s innovation efforts, but also a motivation for the company to continue researching, improving and bringing to market more comprehensive solutions for security, identity and digital trust, contributing to the development of a safe, reliable and sustainable digital infrastructure for Vietnam and international markets. Two consecutive years of participation and two consecutive awards at Sao Khue stand as proof of the steadfast journey the company has pursued from the very beginning: strengthening security and building digital trust. Savyint will continue contributing to the development of a secure, trusted and sustainable digital infrastructure for Vietnam and the global market. Some snapshots from the event:
From PSD3 and eIDAS 2.0 to Zero Trust: A New Security Strategy for the Finance and Banking Sector

The financial sector is entering a period of profound transformation. Amid the rapid increase in both the frequency and financial impact of scams and payment fraud – alongside emerging risks from quantum computing and tighter regulatory requirements under PSD3 and eIDAS 2.0, financial institutions need a well-structured, proactive, flexible, and future-ready security strategy. From PSD1, PSD2 to PSD3: A new standard for digital payments and fraud prevention In 2007, the European Union’s first Payment Services Directive, PSD1, established a unified payments market, improved transparency, and enabled cross-border e-commerce. A decade later, PSD2 was introduced, driving competition through open banking, requiring Strong Customer Authentication (SCA), and creating a legal foundation for third-party access to payment accounts. By November 2025, the European Parliament and the Council of the European Union reached a provisional political agreement on PSD3, addressing emerging challenges in digital payments, open banking, and fraud prevention. One of the most notable aspects of PSD3 is the strengthened requirement for Strong Customer Authentication. SCA is no longer limited to payment authentication, but is also extended to a wider range of customer actions, such as changing transaction limits, updating contact information, restoring devices, setting up authorization, or changing authentication methods. Strong authentication is becoming an integral layer across the entire customer journey. Under the latest directive, PSD3 also reinforces the responsibility of payment service providers in fraud prevention. When incidents occur involving authentication failures or suspicious transactions, legal liability must be clearly defined. This is a key driver for financial institutions to invest more heavily in multi-layered authentication, risk analytics, transaction monitoring, and digital identity protection. In addition, PSD3 continues to promote API standardization in open banking, compliance with FAPI, and greater consistency, interoperability, and service quality among banks, fintech companies, and third-party providers. If PSD3 raises the question of how to strengthen customer authentication, reduce fraud, and ensure accountability in digital payments, then eIDAS 2.0 provides part of the answer – by positioning digital identity and electronic identity wallets as a trusted, standardized, and cross-border foundation for user verification. eIDAS 2.0: Digital identity as the foundation of digital trust While PSD3 focuses heavily on payments and financial services, eIDAS 2.0 places electronic identity and trust services at its core. One of the most prominent elements of eIDAS 2.0 is the European Digital Identity Wallet, or EUDI Wallet. The EU DI Wallet enables individuals and businesses to store, manage, and use their digital identity across a wide range of services. When integrated into the financial sector, digital identity wallets can become a powerful authentication method, helping customers access banking services, verify their identity, and conduct transactions more securely. Beyond promoting the EUDI Wallet, eIDAS 2.0 also introduces stricter requirements for Trust Service Providers, or TSPs, in areas such as governance, risk management, and auditability. In particular, crypto-agility and readiness for Post Quantum Cryptography, or PQC, are identified as critical factors to ensure the long-term resilience of trust services. The requirements under PSD3 and eIDAS 2.0 reflect a clear trend: financial security is becoming inseparable from digital identity. A secure transaction requires not only a protected payment system, but also a trusted and verifiable identity authentication foundation. For banks and fintech companies, this creates an urgent need to prepare modern authentication infrastructure that can integrate with digital identity wallets, support passwordless authentication, manage the identity lifecycle, and provide compliance evidence when required. Zero Trust Security Architecture: Never trust by default, always verify Zero Trust is one of the most widely discussed security architectures today, thanks to its strong security posture and core principles: Instead of assuming that users, devices, or applications inside the system are secure, the Zero Trust model starts from the principle that no user, device, or application should be trusted by default. As a result, every access request must be continuously verified, rather than checked only once at login. For the Finance and Banking sector – where sensitive data, high-value transactions, and multiple third-party connection points are involved – a well-implemented Zero Trust security architecture can help organizations reduce the risk of unauthorized access, minimize potential damage when incidents occur, and strengthen control over activities across the entire system. Further reading on Zero Trust: Savyint Group: A trusted partner in building digital trust Bringing together leading experts in open banking, data encryption, and payment security, Savyint is ready to accompany enterprises and global partner ecosystems throughout the journey – from assessment and roadmap consulting to testing and implementation of Zero Trust-aligned security solutions. These solutions are designed to meet stringent international standards such as PSD3, eIDAS 2.0, PCI DSS,… and to prepare organizations for the Post Quantum era. Savyint’s comprehensive security and fraud prevention solution suite, built on a Zero Trust architecture, addresses multiple critical challenges at once: Notably, Savyint is also the first organization to announce a PQC Lab in Vietnam. The lab enables organizations to explore NIST-approved PQC algorithms, address real-world challenges in the Finance sector, and assess compatibility, performance, and impact – without disrupting existing infrastructure or operational systems. Through this testing environment, organizations can reduce migration risks, select suitable technologies, and systematically build internal capabilities. In addition to its deep expertise, Savyint is also a global technology partner of major industry leaders such as Entrust, Keyfactor, Crypto4A, Kryptus, Futurex, Thales,… Connect with Savyint’s experts today to stay ahead of the next wave of security innovation.
RMiT 2025 Tightens Strong Authentication Requirements in Malaysia and Savyint’s Compliance Solutions for Financial Institutions

In November 2025, Bank Negara Malaysia (BNM) officially issued an updated version of its Risk Management in Technology (RMiT) policy, introducing stricter requirements for enhanced identity verification, device binding, and fraud prevention across Malaysia’s financial sector. 1. About BNM’s RMiT Policy Risk Management in Technology (RMiT) is Bank Negara Malaysia’s central policy framework for managing technology risk and cybersecurity risk in the financial sector. The policy sets out minimum requirements for financial institutions to strengthen governance, cybersecurity, technology operations, digital services, third-party risk management, cloud adoption, fraud detection, and customer protection. Its objective is to ensure that financial institutions can maintain secure, stable, and trusted digital services amid increasingly complex cyber threats. RMiT applies to all financial institutions regulated by BNM, ranging from banks to insurers and reinsurers, electronic money issuers, payment system operators, financial institutions, and money transfer intermediaries. 2. The November 2025 RMiT Update The RMiT policy issued in June 2023 introduced several authentication-related requirements, including multi-factor authentication, access management, and digital service controls. However, these requirements remained largely guidance-based rather than mandatory standards. In November 2025, the updated RMiT policy was issued, marking a significant turning point in strong authentication by introducing clearer mandatory requirements on how organizations must authenticate users and protect digital services. Below are the key changes. a. One Device per User by Default One of the most important changes is the default requirement to use only one device, aimed at preventing SIM-swap fraud and account takeover. Financial institutions must ensure secure device binding and unbinding processes, while limiting digital service transaction authentication by default to one mobile device per account holder. Users may register additional devices, but they must actively request this and accept the associated risks. Financial institutions are not allowed to make multiple devices the default option. The process must include: b. Stronger Verification for Mobile Number Changes Previously, many banking applications allowed users to update their mobile phone numbers by confirming an OTP sent to the existing number. However, this approach is no longer considered secure if the number has already been compromised or affected by SIM swapping. Therefore, under the latest RMiT update, organizations are required to adopt stronger authentication mechanisms, such as: c. Cooling-Off Periods and Transaction Limits for Newly Registered Devices RMiT requires appropriate verification and cooling-off periods in the following cases: Accordingly, newly registered devices should not be granted full transaction privileges immediately. Organizations need to establish time-based limits and transaction frequency controls. Transaction rights should be gradually expanded as the device and user behavior build a trusted history. Combined with fraud detection standards that require behavioral analytics and real-time risk scoring, RMiT requires the authentication layer to understand context, not merely verify login credentials. d. Multi-Factor Authentication and Passwordless Authentication to Reduce Dependence on SMS OTP The most important change in the RMiT update is the requirement to use MFA and passwordless authentication methods. MFA must be resistant to interception or manipulation by third parties throughout the authentication process. Examples of passwordless authentication methods include biometric authentication, device binding, cryptographic key-based authentication, and risk-based step-up authentication. In addition, “transaction linking” requires the authentication code to be bound to specific transaction details, including the recipient and transaction amount, rather than being linked only to the login session. 3. Savyint – A Global Expert in Strong Payment Authentication and Risk Prevention Amid rising security requirements, Savyint provides a comprehensive security ecosystem that helps banks and financial institutions comply with BNM’s RMiT regulations while enhancing their overall security and risk management capabilities. Built on a Zero Trust architecture and centered around four key pillars – Secure Payment, Open Banking, Secure Data, and Digital Trust – Savyint’s RMiT compliance solution enables financial institutions to: This solution is designed in strict compliance with international standards such as FIDO2, PSD2/PSD3 eIDAS, GDPR, PCI DSS,… ensuring rapid deployment, compatibility with existing infrastructure, and the highest level of security. Connect with Savyint experts today to build a secure and compliant payment ecosystem.
Top 6 Benefits of Zero Trust Security Architecture

As cyberattacks become increasingly sophisticated, traditional security models such as firewalls, VPNs, or trusted internal networks are no longer sufficient to protect modern enterprises. Zero Trust Architecture has emerged as a critical approach in today’s cybersecurity landscape, helping organizations strengthen protection across users, devices, applications, data, and digital transactions. What is Zero Trust Architecture? Zero Trust Architecture is a modern security model built on the principle of “never trust, always verify.” It is designed for today’s complex, distributed, and increasingly cloud-based IT environments. Unlike traditional security models, Zero Trust requires every access request to be continuously verified, whether it originates from inside or outside the organization. Zero Trust Architecture typically combines multiple security technologies, including: Key Benefits of Zero Trust Security Architecture Implementing Zero Trust can bring significant benefits to enterprises and organizations, including: 1. Strengthening Comprehensive Security Against Advanced Threats Zero Trust helps organizations defend against threats such as ransomware, phishing, compromised accounts, and insider risks. By enforcing least-privilege access and continuous verification, businesses can significantly reduce the risk of attackers exploiting exposed credentials to access sensitive systems and data. 2. Reducing the Risk of Data Breaches Since every access request must be verified, attackers cannot easily reach sensitive data even if they manage to compromise an account or device. This helps limit unauthorized access, reduce lateral movement within the system, and minimize the potential impact of security incidents. 3. Improving Monitoring and Incident Detection Zero Trust enables organizations to monitor user behavior, devices, applications, and access activities in real time. With stronger visibility across the digital environment, businesses can detect unusual activities earlier, respond to risks more quickly, and improve their overall incident response capability. 4. Supporting Remote Work, Cloud, and Hybrid Infrastructure With Zero Trust, users can securely access enterprise resources from anywhere, as long as their identity, device, and access permissions are properly verified. This is especially valuable for remote and hybrid work models, where employees may access corporate systems from different locations, networks, and personal devices. 5. Enhancing Regulatory Compliance Zero Trust provides a unified governance framework for enforcing security policies, authenticating users, managing access rights, and maintaining activity logs. This allows organizations to better meet data protection and information security requirements in highly regulated sectors such as finance, banking, healthcare, telecommunications, and government. 6. Optimizing Long-Term Security Costs While Zero Trust implementation may require initial investment, it can help optimize security costs in the long run. By consolidating security controls, reducing the likelihood of data breaches, and limiting damage when incidents occur, Zero Trust helps organizations build a more sustainable and cost-effective cybersecurity strategy. A Comprehensive Zero Trust-Based Security and Fraud Prevention Solution for BFSI Organizations With deep experience in the Finance and Banking sector and a proven track record of implementing projects for major banks, SAVYINT introducs e a comprehensive security and fraud prevention solution built on Zero Trust Architecture. Aligned with the core pillars of modern Zero Trust, SAVYINT’ solution enables end-to-end protection across users, devices, applications, data, and digital transactions: + Identity verification and user access control + Establish device trust + Real-time application protection with RASP+ + API security and third-party connectivity + Consent management and personal data protection + AI/ML integration, transaction risk assessment, and real-time fraud prevention + Automated compliance reporting + Support compliance with Vietnamese regulations, including Circular 50, Circular 64, Circular 77 of the State Bank of Vietnam, Decree 356, the Data Protection Law, and the Cybersecurity Law,…; international standards such as eIDAS, GDPR, and PCI-DSS…; and regional regulations such as Malaysia’s PDPA and RMiT, and the Philippines’ AFASA and BSP 1213–1215… Connect with SAVYINT experts today to take the lead in enterprise-wide security and fraud prevention! Read more: Zero Trust – A Next-Gen Security Architecture for Vietnamese Banks Amid Increasingly Stringent Regulations
Savyint Advances Cooperation in Cybersecurity, Artificial Intelligence and High Technology in India

May 6, 2026, Savyint Group participated in the Vietnam – India Innovation Forum in New Delhi, India. The event was jointly organized by Vietnam’s Ministry of Science and Technology and India’s Ministry of Electronics and Information Technology, as part of the State visit to India by H.E. To Lam, The General Secretary, President of the Socialist Republic of Viet Nam. Taking place from May 5 to 7, 2026, the State visit by General Secretary, President To Lam was made at the invitation of Indian Prime Minister Narendra Modi, with the participation of a high-level Vietnamese delegation and a business delegation. The visit also coincided with the 10th anniversary of the elevation of Viet Nam-India relations to a Comprehensive Strategic Partnership, while opening new momentum for cooperation in areas that are fundamental to future growth, including science and technology, innovation, digital transformation, cybersecurity, artificial intelligence, semiconductors, energy and high-quality human resource development. Under the theme “Cooperation in Human Resource Development, Science and Technology, Innovation and Digital Transformation,” the Vietnam-India Innovation Forum brought together senior leaders, ministries, government agencies, research institutes, universities, associations, digital technology corporations, and innovation-driven enterprises from both countries. At the forum, General Secretary and President To Lam emphasized the need for Viet Nam and India to strengthen strategic information sharing and expand cooperation in cybersecurity, digital infrastructure protection, the prevention of high-tech crime, and capacity building to respond to non-traditional security challenges. The forum served as an important platform to promote substantive cooperation between the Vietnamese and Indian technology communities, particularly in fast-growing sectors across the Asia-Pacific region. Amid the rapid growth of the digital economy, data security, digital identity protection, and cyber resilience have become strategic requirements for governments, financial institutions, large enterprises, and critical infrastructure operators. As a Vietnamese technology company focused on digital safety, data protection, digital trust, and risk governance in digital environments, Savyint joined the forum with the aim of expanding international cooperation, connecting Vietnamese technology capabilities with India’s technology ecosystem, and supporting the development of platforms and solutions that meet the increasingly demanding requirements of regional markets. At the event, Savyint Group and Vantageo Pvt. Ltd. exchanged a technology cooperation agreement, opening new directions for collaboration in development, integrated design, joint research and co-production. The partnership aims to combine the strengths of both companies to deliver solutions and products in areas such as cybersecurity, AI Security, Data Safe, Quantum Safe, Zero Trust Network, HPC platforms, AI accelerators, and GPU platforms for Viet Nam, India, the APAC region and SAARC region. The cooperation agreement goes beyond connecting the capabilities of the two companies. It also reflects a shared orientation toward co-developing secure technology platforms that can be localized to meet the requirements of each market, while aligning with international standards for security, compliance, and operational reliability. Mr. Steve Huang, Executive Chairman of Savyint Group, shared: “India is one of the world’s fastest-growing technology hubs. By participating in the Vietnam-India Innovation Forum, Savyint aims to connect with like-minded partners and jointly develop secure, trusted, and widely applicable technology solutions for enterprises and organizations in Viet Nam, India, and the wider region.” As Viet Nam-India relations enter a new phase of deeper and broader cooperation, Savyint’s presence at the forum affirms its commitment to accompanying Viet Nam’s national digital transformation journey, while promoting “Make-in Vietnam” technology solutions to regional and global markets. The event through media coverage: