Global fintech and funding innovation ecosystem

Fintechs Face Rising SaaS Security Risks, JPMorgan CISO

Cybersecurity | May 14, 2025

Freepik DC Studio, Malware attack

Image: Freepik/DC Studio

Third-party Integration Flaws Are Exposing Fintechs to Spreading Attacks

Patrick Opet, JPMorgan Chase’s Chief Information Security Officer, has dropped a rare public warning that the modern SaaS (Software-as-a-service) model is enabling cyberattacks and embedding systemic risk into the global economy. His message is that the security architecture is breaking down, and software providers are not doing enough to fix it. Below are some urgent quotes from his discourse and why they matter for Canadian fintechs, investors, and regulators.

5 Select Quotes From Opet's Letter

1. “SaaS has become the default... embedding concentration risk into global critical infrastructure.”

Many fintechs are using the same core SaaS vendors for payments, data, and automation, exposing them to a single point of failure. If one of these vendors is compromised, the effects can spread fast like wild fire on a dry summer's night. For fintech startups, the risks may be inherited without full visibility.

See:  India Biometric Data Breach Highlights Cybersecurity Risks

2. “Over the past three years, our third-party providers experienced a number of incidents... requiring us to act swiftly and decisively.”

Canadian fintechs with lean security teams need contingency plans for third party supplier compromise and must monitoring vendor behaviour or risk the full wrath of a serious attack that will disrupt operations, result in data theft or leakage, fraud and financial loss, regulatory and legal exposure, reputational damage and even cascading or 'fourth party' risks. Even a global bank must isolate vendors during incidents.  Read OSFI's Guidance here: Third-Party Risk Management Guideline.

3. “Fierce competition among software providers has driven prioritization of rapid feature development over robust security.”

Security is often sacrificed for speed. Fintechs should require vendors to provide (1) strong and secure default settings, (2) regular third-party audits, and proof or evidence of strong internal security programs such as SOC 2 Type II or ISO/IEC 27001 certification.

See:  Perplexity’s Security Flaws A Red Flag for Industry

4. “Modern integration patterns dismantle essential boundaries... relying on overly simplified interactions between third-party services and firms’ sensitive internal resources.”

OAuth tokens and API integrations are often misused, allowing third and unwanted parties to access internal systems. Without strong segmentation and logging, attackers can move quickly once access is gained. Microsoft Threat Intelligence recently confirmed state actors are now targeting common SaaS apps to infiltrate customers.

5. “The most effective way to begin change is to reject these integration models without better solutions.”

Canadian fintechs should ensure procurement policies require secure integration design, advanced authorization models, and greater transparency from vendors. Startups should reference the Canadian Center for Cybersecurity Top 10 IT Security Actions for implementation guidance.

What This Means for Canadian Fintechs

SaaS brought convenience and speed but also concentrated risk across fintech infrastructure. For smaller Canadian firms who often lack internal security engineering, the consequences of a poorly or unsecured SaaS integration can be severe.  This warning should not be ignored.

See:  New Cyber Threats Financial Service Firms Need to Know

Fintech leaders should:

  • Audit all third-party SaaS integrations especially those with read or write access to sensitive systems. The CSA's Staff Notice 33-321 offers baseline expectations for registrants
  • Require vendors to support multi-factor authentication, token expiration, and role-based access controls
  • Push for data residency transparency and vendor dependency disclosures, including fourth-party services
  • Include security breach notification clauses in service agreements
  • Explore secure options such as customer-managed encryption keys, confidential computing, and bring your own cloud models

Final Thought

OSFI and the CSA have made it clear that third party oversight is now a priority, so fintechs can expect questions on cybersecurity controls and operational resilience during regular reviews.  SaaS is here to stay but without stronger default security and safer integrations and oversight, it'll remain a growing liability.

See:  Can Cloned Voices Crack Bank Security? Need to Know

Fintech startups and scale-ups cannot rely on vendors to leadSecurity must be a shared responsibility across the ecosystem, and it begins with better architecture, more transparency, and smarter procurement.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Leave a Reply

Your email address will not be published. Required fields are marked *