• Home
  • News
  • How an ITU security lab advances trust in digital financial...
How an ITU security lab advances trust in digital financial services featured image

How an ITU security lab advances trust in digital financial services

Digital financial services have expanded rapidly around the world, especially as mobile money innovations bring financial services to millions of people for the very first time.

This growth in opportunities to save, make payments and take loans, however, has been accompanied by increasingly sophisticated fraud and cybersecurity threats.

Mobile money fraud continues to rise, driven by attack vectors such as identity fraud, social engineering, insider threats, and SIM swaps, where attackers redirect someone else’s phone number to their own SIM card.

Mobile money users in developing countries are the group most affected by such attacks, highlighting the need for stronger security controls and proactive risk management globally.

Current trends reinforce the importance of equipping regulators with the tools and expertise to identify vulnerabilities and ensure effective mitigation.

From principles to practice

Ongoing work by the International Telecommunication Union (ITU) and partners has helped make secure digital financial services a global reality, with an ITU lab initiative assisting growing numbers of developing countries with the practical aspects of digital financial service (DFS) security.

First, the Financial Inclusion Global Initiative (FIGI) ꟷ active from 2017 to 2021 ꟷ brought key regulatory, financial and telecom institutions together to accelerate digital financial inclusion, sparked by pioneering innovation in developing countries showing how mobile money could reach the unbanked.

FIGI provided an open framework for collaboration led by ITU, the World Bank Group, and the Committee on Payments and Market Infrastructures (CPMI), with support from the Gates Foundation.

The World Bank and CPMI helped to build a strong understanding of the policy considerations surrounding digital identity while incentivizing the use of electronic payments.

ITU’s work focused on security, infrastructure and trust – secure financial applications and services, reliable digital infrastructure, and the resulting trust that everyone’s money and digital identities are safe.

As that first initiative concluded, ITU opened its Digital Financial Services Security Lab (DFS Security Lab) to help implement FIGI’s findings.

Capacity building for regulators

The DFS Security Lab supports security and resilience through a structured approach to security audits of digital financial applications, helping regulators to strengthen oversight. It also promotes the adoption of international standards and collaboration on emerging DFS security risks.

From the outset, the DFS Security Lab has provided practical guidance and methodologies for countries to assess the security of DFS applications and infrastructure. However, many regulators lacked the technical capability to verify independently if mobile payment apps complied with established security standards.

The lab’s Knowledge Transfer Programme is designed to address this capacity gap. It equips regulators with practical skills to conduct security testing across Android, iOS, and USSD/STK platforms. It also provides a standardized methodology for identifying vulnerabilities, assessing risks, and validating compliance with international best practices.

Standards for security and resilience

ITU’s DFS security recommendations remain a core pillar of the DFS Security Lab.

This structured set of guidelines for regulators has been adopted by the Communications Regulators’ Association of Southern Africa (CRASA) and the East African Communications Organisation (EACO). Adoption is also under consideration by the Assembly of Telecommunications Regulators of Central Africa (ARTAC) and are currently at the draft stage with the West Africa Telecommunications Regulators Assembly (WATRA), with the aim of promoting harmonized approaches to DFS security across these regions.

The Caribbean is currently on course to do the same.

The security recommendations address multiple layers of the DFS ecosystem, drawing on established ITU standards and guidance in such areas as:

  • Signalling security (SS7) – addressing vulnerabilities in mobile network signalling that impact DFS (ITU standard Q.3066).
  • Security for SIM-related DFS security risks mitigating challenges like SIM swap fraud and unauthorized access (ITU standard X.1456).
  • Mobile app security best practices supporting secure design, development and deployment of DFS applications (ITU standard X.1150).
  • Model Memorandum of Understanding – providing a framework for coordination on DFS security between telecom regulators and central banks.
  • DFS consumer competency framework – strengthening user awareness and consumer protection.

The DFS Security Lab embeds these recommendations into practical testing and regulatory processes, enabling regulators to assess compliance and drive the consistent implementation of security controls across the DFS ecosystem.

More countries with more capacity

So far, the DFS Security Lab has assisted more than 20 countries across Africa, the Caribbean and Latin America, as well as the Universal Postal Union (UPU) at the global level.

Regulators for Antigua and Barbuda, Lesotho, Peru, Saint Lucia, Tanzania, The Gambia, Uganda and Zimbabwe, along with UPU, have completed the Knowledge Transfer Programme and now operate DFS security testing capabilities independently.

Programmes are currently underway in Burkina Faso, the Republic of the Congo, the Democratic Republic of the Congo, Eswatini, Ethiopia, Guinea, Haiti, Somalia and South Sudan, while Gabon, Ghana, Sierra Leone and Togo and are about to start.

Strengthening regulatory oversight

At the advanced stages of the Knowledge Transfer Programme, regulators conduct regular testing of DFS apps and review findings with DFS providers, with ongoing technical support from ITU.

When regulators gain sufficient capacity, they can conduct their own security testing, evaluate DFS apps, validate that the right security controls are in place, and engage directly with DFS providers when remedies are needed.

The aim is for each country to monitor and continuously improve its DFS security so that everyone can enjoy the benefits of electronic banking without fear of fraud and cyberattacks.

Interested? Contact the DFS Security Lab.

View testimonial videos from participating countries.

As part of the lab’s activities, ITU also organizes a webinar series on digital financial services, offering expert insights and practical discussions on DFS security and related developments. Explore previous and upcoming episodes here.

Header image credit: Envato

Related content