The Identity-First Bank: A Zero Trust Blueprint for APAC BFSI in the Agentic-AI Era
Financial services was the most-breached sector in the world for the second consecutive year in 2025, absorbing 739 reported data compromises and an average breach cost of USD 5.56 million (Identity Theft Resource Center, 2026; IBM Security, 2025). Ninety percent of incident-response engagements now trace back to an identity weakness, and roughly two-thirds of initial access is achieved through stolen or misused credentials rather than malware (CrowdStrike, 2025; IBM Security, 2025). In Asia Pacific, where cyber incidents account for approximately 34 percent of the global total, this concentration of identity-centered attacks collides with three regulatory forces - APRA's Prudential Standard CPS 234, the Monetary Authority of Singapore's Technology Risk Management Guidelines, and the Hong Kong Monetary Authority's Cybersecurity Fortification Initiative 2.0 - each of which now expects continuous, evidence-based control assurance rather than periodic attestations (APRA, 2025; MAS, 2024; HKMA, 2020, 2025).

Perimeter defense, built for a world of branches, data centers and human-speed attackers, cannot answer this environment. A durable response requires a shift to an identity-first, Zero Trust architecture: continuous verification of every user, workload and API call; least-privilege access enforced at the session level; and telemetry that lets a bank prove - to itself, to regulators and to a board - that only the right entity is doing the right thing at the right time. This paper offers APAC BFSI leaders a pragmatic blueprint, quantifies where the value sits, and outlines how sourceCode partners with institutions to move from strategy to engineered reality.
Why the Perimeter Failed the APAC Bank
For two decades, BFSI security relied on a trust boundary - inside was safe, outside was hostile. Three shifts have made that boundary indefensible.
Digital consumption exploded. APAC banks now process the majority of retail interactions through mobile apps and open APIs, and back-office workloads increasingly run on hyperscale cloud. The result is an attack surface that is distributed, ephemeral, and largely outside any legacy firewall.
Threat actors industrialized identity abuse. SpyCloud's 2026 Identity Exposure Report recovered 65.7 billion stolen identity records in 2025 alone, a 23 percent year-on-year increase, while Sophos X-Ops observed a 106 percent rise in dark-web credential sales between June 2024 and June 2025 (SpyCloud, 2026; Sophos, 2025). CrowdStrike now finds that 79 percent of attacks are malware-free, relying on valid credentials to move laterally (CrowdStrike, 2025).
Generative and agentic AI compressed attacker timelines. The World Economic Forum's Global Cybersecurity Outlook 2026, produced with Accenture, reports that 87 percent of organizations identify AI-related vulnerabilities as the fastest-growing category of cyber risk, with adversaries using AI to shrink attack chains "from weeks to hours" (World Economic Forum & Accenture, 2026). Visa's 2026 APAC risk outlook makes the same point in blunter terms: autonomous AI attacks and interconnected ecosystems are reshaping the regional threat landscape (Visa, 2026).
The Australian evidence is instructive. Optus (9.8 million customer records, unauthenticated API), Medibank (compromised third-party credentials) and Latitude Financial (approximately 14 million records, stolen user credentials) each began with an identity or trust failure, not a novel exploit (Lynch Meyer Lawyers, 2023; SecurityScorecard, 2023). None of these organizations lacked a firewall; each lacked continuous identity verification and segmentation.
The Regulatory Direction of Travel
APAC regulators have moved decisively from principles to prescription.
- Australia - APRA CPS 234 & CPS 230. CPS 234 binds all 680 APRA-regulated entities overseeing approximately AUD 9.8 trillion in assets and, in a 2025 letter, APRA explicitly cited weak identity and access management, incomplete multi-factor authentication (MFA) on critical systems and inadequate oversight of third parties (APRA, 2025). CPS 230 replaced the outsourcing standard on 1 July 2025, and the Financial Accountability Regime (FAR) now attaches personal liability to individual executives for these obligations (APRA, 2025).
- Singapore - MAS TRMG. Between July 2023 and December 2024, MAS issued 163 technology-related enforcement actions, including AUD-equivalent penalties exceeding SGD 15 million (MAS, 2025). MAS has publicly endorsed Zero Trust principles for the sector since 2021 and the Financial Services Industry Transformation Map 2025 embeds resilience and secure-by-design expectations across the ecosystem (MAS, 2021; MAS, 2024).
- Hong Kong - HKMA CFI 2.0. Since 1 January 2021, the Cyber Resilience Assessment Framework (C-RAF), Professional Development Programme and Cyber Intelligence Sharing Platform have set the operating baseline. The Protection of Critical Infrastructure (Computer System) Bill, expected to take effect in 2026, will expand cyber-resilience obligations beyond banks to a broader set of designated operators (HKMA, 2020; Legislative Council of Hong Kong, 2025).
Common to all three regimes is a shift from point-in-time to continuous control assurance. Zero Trust is the architecture that makes continuous assurance a by-product of daily operations rather than an audit-season scramble.
Zero Trust, Precisely Defined
Zero Trust is often marketed as a product. It is not. NIST SP 800-207 defines it as a set of principles: never trust, always verify; enforce least privilege; assume breach; make access decisions per session, using device posture, identity strength and context (National Institute of Standards and Technology, 2020). CISA's Zero Trust Maturity Model organizes those principles across five pillars - Identity, Devices, Networks, Applications & Workloads, and Data -supported by cross-cutting capabilities in visibility and analytics, automation and governance (Cybersecurity and Infrastructure Security Agency, 2023).

For an APAC bank, the operative definition is more concrete: every access request, whether from a customer, employee, service account or AI agent, is authenticated with strong identity, authorized against fine-grained policy, evaluated against real-time signals, and logged for later reconstruction.
This is more than "buying ZTNA." Gartner reports that over 70 percent of new remote access deployments in 2025 use Zero Trust Network Access rather than legacy VPN, and the standalone ZTNA market is projected to grow from USD 1.34 billion in 2025 to USD 4.18 billion by 2030 at a 25.5 percent CAGR (Gartner, 2024; MarketsandMarkets, 2025). But ZTNA is a doorway, not the house. The house is built on identity governance, workload identity, micro segmentation, session-level policy and identity threat detection and response (ITDR).
Current Challenges Facing APAC BFSI
Five obstacles recur in our engagements with regional banks and insurers.
Identity sprawl. A typical Tier-1 APAC bank operates 200+ business applications, tens of thousands of privileged accounts and a proliferation of non-human identities - service accounts, robotic process automation bots, and, increasingly, AI agents that call APIs autonomously. Non-human identities frequently outnumber human identities by an order of magnitude and are the least governed.
Legacy authentication debt. MFA coverage on customer-facing channels is broadly mature; on internal, admin and third-party channels it is not. APRA's 2025 letter singled out this gap, echoing what the Medibank and Latitude incidents demonstrated (APRA, 2025).
Flat internal networks. Core banking, general ledger, payments and data platforms often share the same L3 network domains. Once inside, an attacker moves laterally with ease - the pattern documented in the ITRC 2025 breach report (Identity Theft Resource Center, 2026).
Third-party opacity. More than half of material incidents in APAC BFSI over the past 24 months began outside the institution's own perimeter - at a payment processor, KYC vendor or IT managed service provider. CPS 230, MAS TRM and HKMA supervisory guidance now expect banks to extend their control envelope over these providers.
Detection lag. IBM reports that identity-based intrusions take longer than 181 days on average to detect and contain - three financial quarters in which attackers monetize data, extort funds or manipulate transactions (IBM Security, 2025).
Strategic Analysis: Where Zero Trust Creates Value
Zero Trust is not primarily a compliance play - it is an economic one.
Loss avoidance. Applying a plausible 15-25 percent reduction in identity-driven breach probability (consistent with the delta IBM reports between organizations with mature security AI and automation versus those without) to a baseline USD 5.56 million financial-services breach cost implies USD 830K-1.4M in expected loss avoidance per breach event, before regulatory penalties and reputational impact (IBM Security, 2025).
Regulatory drag reduction. In our experience, remediating an APRA or MAS technology-risk finding costs 3-6× more than engineering the control correctly the first time. Continuous, evidence-generating Zero Trust controls collapse audit-preparation timelines from months to weeks.
Operational efficiency. Consolidating overlapping IAM, VPN, network segmentation and CASB tooling into a converged SASE + ITDR + micro segmentation stack typically retires 15-30 percent of security operating costs in Year 2, while reducing the change-failure rate on network and identity changes.
AI enablement. As banks deploy generative and agentic AI, the security model must support autonomous entities that authenticate, invoke APIs and act on data. Identity-first Zero Trust is the only control model that scales to workloads and agents; perimeter models cannot express the required policies.
Customer trusts. The Asian Banker notes that APAC banks that modernize infrastructure without eroding their trust advantage will define the next decade of competition - trust, in this context, is engineered, not asserted (The Asian Banker, 2026).
Key Trends Shaping the 2026-2028 Roadmap
Four trends will define Zero Trust delivery in the region over the next 24 months.
Convergence of ZTNA, SASE and SSE. Standalone ZTNA is collapsing into secure-access platforms that unify remote access, CASB, SWG and DLP. This simplifies policy administration and closes the seams attackers exploit.
Micro segmentation moves from optional to expected. CISA's July 2025 micro segmentation guidance describes it as "foundational" to Zero Trust, and Forrester's 2024 Micro segmentation Solutions Wave documented material advances in identity-based segmentation (Cybersecurity and Infrastructure Security Agency, 2025; Forrester Research, 2024). The global micro segmentation market is projected to expand from USD 8.2 billion in 2025 to more than USD 41 billion by 2034 (Elisity, 2025).
Identity Threat Detection and Response (ITDR) becomes core. ITDR consolidates identity-plane telemetry - abnormal authentication, token abuse, entitlement drift - with response automation. Given that identity is the initial vector in most breaches, ITDR is now a peer capability to EDR.
Non-human identity governance emerges as a distinct discipline. Service accounts, workload identities, and AI agents require lifecycle management, credential rotation and behavioral baselines. Banks that fail to govern non-human identities in 2026 will find that Zero Trust ends at the human user.
Real-World Examples
Commonwealth Bank of Australia has publicly described a multi-year journey toward identity-centric security, incorporating phishing-resistant authentication, device trust and passwordless customer experiences. Its approach is instructive because it treats identity as a product function jointly owned by security and customer-experience teams (Commonwealth Bank of Australia, 2025).
DBS Bank in Singapore has aligned its cloud modernization with MAS TRM expectations by embedding policy-as-code, workload identity and continuous compliance evidence into its delivery pipelines, so that every deployment produces the artefacts regulators expect (DBS Group Holdings, 2024).
Regional insurers operating across ASEAN have used microsegmentation to isolate core policy administration, claims and data-lake environments, materially reducing the blast radius of the 2024-2025 wave of ransomware incidents targeting the sector.
Common to all three is a delivery model that treats Zero Trust as an engineering programme owned jointly by security, platform and application teams - not a project owned solely by the CISO.
Actionable Recommendations for the Next 12 Months
We recommend BFSI leadership teams structure the 12-month agenda around six moves.

1. Baseline against the CISA Zero Trust Maturity Model and translate the gap into a two-year, board-approved roadmap. Anchor the roadmap to APRA, MAS and HKMA control catalogues so compliance is a by-product.
2. Complete phishing-resistant MFA for all privileged and third-party access - FIDO2 or hardware-bound passkeys, not SMS. Close the specific gap APRA flagged in 2025.
3. Deploy ZTNA and retire legacy remote-access VPN on a defined timeline. Converge into a SASE platform where the operating model supports it.
4. Implement identity-based micro segmentation starting with the most sensitive workloads - payments, core banking, GL, customer data platforms - before generalizing.
5. Stand up ITDR as a peer to EDR. Instrument IdP logs, entitlement changes and privileged sessions; automate response for high-confidence signals.
6. Establish a non-human identity governance programme covering service accounts, RPA bots and AI agents, with lifecycle, secret rotation and behavioral monitoring.
Sequencing matters. Institutions that attempt all six in parallel typically stall on integration debt; those that sequence identity → segmentation → detection → automation over four quarters deliver faster and more defensibly.
The sourceCode Perspective
sourceCode partners with APAC banks, insurers and financial-services platforms to engineer Zero Trust into the fabric of their technology estate rather than bolt it on. Our teams combine deep enterprise architecture, cloud, data and platform engineering expertise with delivery muscle in Australia, Singapore and Southeast Asia. We work with clients across four capabilities relevant to this agenda: modern application engineering (secure-by-design services and APIs), cloud and platform engineering (policy-as-code, workload identity and landing zones aligned to APRA, MAS and HKMA), data engineering (fine-grained access controls, tokenization and lineage), and AI engineering (identity models for agentic workloads and controls that keep GenAI within policy). Because the same teams design, build and run, control evidence is generated continuously - not reconstructed at audit time.
Conclusion
The perimeter is not coming back. Regulators are moving to continuous assurance. Attackers have industrialized identity abuse and are compressing timelines with AI. In this environment, Zero Trust is not a security fashion - it is the operating model that lets an APAC bank or insurer say, with evidence, that only the right entities are doing the right things. The institutions that engineer it in over the next 24 months will find that resilience, regulatory posture, operating cost and AI-readiness all improve together. Those that defer will discover that each of those four dimensions has degraded independently - and simultaneously.
Considering how to accelerate a Zero Trust programme without disrupting the customer experience or your delivery velocity? Talk with sourceCode about building an identity-first architecture that scales from your first ZTNA deployment to enterprise-wide micro segmentation and AI-agent governance.
FAQ
What is Zero Trust in the context of banking? Zero Trust is an architecture in which every access request - from a person, workload, API or AI agent - is verified with strong identity, authorised against fine-grained policy, evaluated against real-time context, and logged. It replaces perimeter trust with per-session verification.
Is Zero Trust required by APRA, MAS or HKMA? None of the three regulators mandates a specific architecture, but each expects controls that Zero Trust operationalizes: strong identity, least privilege, continuous monitoring, third-party control and evidence-based assurance. APRA's 2025 letter explicitly cited identity and MFA weaknesses (APRA, 2025).
How much does an identity-related breach cost an APAC bank? The 2025 average breach cost in financial services globally was USD 5.56 million, with stolen-credential breaches at USD 4.50 million and detection lags exceeding six months (IBM Security, 2025).
How long does a Zero Trust programme take? A realistic two- to three-year horizon delivers measurable maturity gains, with meaningful improvements in the first 6-12 months from phishing-resistant MFA, ZTNA and initial micro segmentation.
What is ITDR and why does it matter now? Identity Threat Detection and Response consolidates identity-plane signals - abnormal authentication, token abuse, entitlement drift - with automated response. Since identity is the initial vector in the majority of breaches, ITDR is now a foundational capability alongside EDR.
References
APRA (2025) Cyber security - Prudential Standard CPS 234 and related guidance. Sydney: Australian Prudential Regulation Authority. Available at: https://www.apra.gov.au/cyber-security (Accessed: 27 July 2026).
Commonwealth Bank of Australia (2025) Annual Report 2025. Sydney: Commonwealth Bank of Australia.
CrowdStrike (2025) 2025 Global Threat Report. Austin: CrowdStrike Holdings.
Cybersecurity and Infrastructure Security Agency (2023) Zero Trust Maturity Model, Version 2.0. Washington DC: CISA.
Cybersecurity and Infrastructure Security Agency (2025) Microsegmentation in Zero Trust Architectures. Washington DC: CISA.
DBS Group Holdings (2024) DBS Technology and Operations Review 2024. Singapore: DBS.
Elisity (2025) Microsegmentation Market Outlook 2025-2034. San Jose: Elisity Inc.
Forrester Research (2024) The Forrester Wave™: Microsegmentation Solutions, Q3 2024. Cambridge, MA: Forrester Research.
Gartner (2024) Emerging Technology: Zero Trust Network Access Forecast. Stamford: Gartner Inc.
HKMA (2020) HKMA launches Cybersecurity Fortification Initiative 2.0. Hong Kong: Hong Kong Monetary Authority. Available at: https://www.hkma.gov.hk/eng/news-and-media/press-releases/2020/11/20201103-4/ (Accessed: 27 July 2026).
HKMA (2025) Cybersecurity Fortification Initiative - Overview. Hong Kong: Hong Kong Monetary Authority.
IBM Security (2025) Cost of a Data Breach Report 2025. Armonk: IBM Corporation.
Identity Theft Resource Center (2026) 2025 Data Breach Report. El Cajon: ITRC.
Legislative Council of Hong Kong (2025) Protection of Critical Infrastructure (Computer System) Bill. Hong Kong SAR.
Lynch Meyer Lawyers (2023) A tale of two cyber-attacks - Lessons learnt from the Medibank and Optus data breaches. Adelaide: Lynch Meyer.
MAS (2021) Monetary Authority of Singapore supports "zero trust" cyber security principles for the finance sector. Singapore: Monetary Authority of Singapore.
MAS (2024) Financial Services Industry Transformation Map 2025. Singapore: Monetary Authority of Singapore.
MAS (2025) Enforcement Report 2023-2024. Singapore: Monetary Authority of Singapore.
MarketsandMarkets (2025) Zero Trust Network Access Market - Global Forecast to 2030. Pune: MarketsandMarkets Research.
National Institute of Standards and Technology (2020) Zero Trust Architecture (SP 800-207). Gaithersburg: NIST.
SecurityScorecard (2023) 5 Lessons from the Optus Data Breach for Telecom and Third-Party Risk. New York: SecurityScorecard.
Sophos (2025) Sophos X-Ops 2025 Threat Report. Abingdon: Sophos Ltd.
SpyCloud (2026) 2026 Identity Exposure Report. Austin: SpyCloud Inc.
The Asian Banker (2026) Asia Pacific banks must modernise infrastructure without surrendering their trust advantage. Singapore: The Asian Banker.
Visa (2026) From autonomous AI attacks to interconnected systems: Five forces reshaping cyber risk in Asia Pacific. Singapore: Visa Asia Pacific.
World Economic Forum & Accenture (2026) Global Cybersecurity Outlook 2026. Geneva: World Economic Forum.