CIO Influence
Analytics Automation CIO Influence Interviews IT and DevOps Machine Learning Security

CIO Influence Interview with Ashish Jain, Chief Technology Officer at OneSpan

CIO Influence Interview with Ashish Jain, Chief Technology Officer at OneSpan

Ashish Jain, Chief Technology Officer at OneSpan shares more on why authentication security and identity is no longer just the front door to a digital business but part of the foundation on which an entire digital business operates:

___________

What aspect of today’s state of authentication security would you like to draw attention to?

Authentication is a cornerstone of digital trust, but it is also one of the most frequently targeted parts of the customer journey. Organizations are constantly trying to strike the right balance between stronger security and a user experience people will actually accept.

Passwords remain the most common authentication method, yet they are also a major source of phishing, credential stuffing, account takeover, and fraud.

Passkeys offer a much better balance. They are phishing-resistant, easier for users, and broadly supported across major operating systems, browsers, and platforms. Their maturity is the result of more than a decade of work across the identity industry, the FIDO Alliance, and companies such as Apple, Google, and Microsoft.

The technology problem is largely solved. The deployment problem is not.

The challenge is that deploying modern authentication at scale is rarely as simple as replacing one method with another.

When an organization serves millions of users, there is rarely a single authentication method that works for everyone. What looks like an edge case can quickly represent tens or hundreds of thousands of customers. Different devices, accessibility needs, recovery scenarios, regulatory requirements, and levels of risk all have to be considered.

That is why successful modernization cannot simply mean ripping out existing systems and replacing them overnight. Organizations need a bridge between existing and emerging authentication methods. They need to introduce passkeys and other modern approaches while allowing current methods to coexist during the transition.

Ultimately, stronger authentication only delivers value when customers are willing and able to use it. The goal should not be modernization for its own sake. It should be better security, less friction, and a practical path forward for every user.

Also Read: CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight

How is AI impacting overall authentication and online security standards?

AI is accelerating the need for phishing-resistant authentication and more adaptive security controls.

It dramatically lowers the cost and increases the scale of phishing campaigns, credential attacks, social engineering scams, and deepfake-enabled fraud. Attackers can create more convincing messages, personalize scams, automate interactions, and adapt their tactics far faster than before. Signals that organizations once treated as reasonably trustworthy—such as a familiar voice, a realistic video, or a convincing conversation—can no longer be accepted at face value.

That makes stronger, phishing-resistant authentication more important than ever. It also reinforces the need to move beyond identity systems that depend heavily on passwords, knowledge-based questions, or other signals that can be stolen, replicated, or manipulated.

In parallel, trusted digital identity and verifiable credentials are becoming increasingly important. Initiatives such as the EU Digital Identity Wallet are helping establish frameworks through which individuals can securely prove specific attributes about themselves without repeatedly sharing unnecessary personal information. For financial institutions, this creates an opportunity to improve security and customer trust while also reducing friction across onboarding, authentication, and account recovery.

The next major shift will come from agentic AI. AI agents will increasingly interact with financial institutions on behalf of customers, alongside existing channels such as branches, websites, and mobile applications. They may check balances, move money, manage accounts, or initiate more complex transactions.

In that environment, organizations will need to establish not only who the customer is, but also which agent is acting, what it has been authorized to do, and whether a particular transaction should be allowed. Authentication, authorization, consent, auditing, and governance will all have to work together.

AI is therefore raising the stakes on both sides: it gives attackers more powerful tools while creating an entirely new channel that institutions must learn to trust and govern.

Tell us a little about OneSpan’s newest innovations?

One of our most significant recent innovations is DigipassONE, our new unified authentication platform. DigipassONE represents a shift from managing authentication as a collection of separate solutions to managing it as a unified platform. It is designed to help organizations modernize progressively while simplifying how their existing and emerging capabilities are deployed and managed.

Most organizations today are juggling multiple authentication methods, evolving regulatory requirements, digital credential initiatives, new security threats, and growing expectations for seamless user experiences. These capabilities have often been introduced separately, creating additional operational complexity each time something new is added.

DigipassONE brings together authentication and transaction security, digital credentials, mobile application protection, and analytics-driven insights through a shared platform foundation. This gives organizations, particularly financial institutions, a more complete view of their authentication and security environment and makes it easier to introduce new capabilities without creating yet another silo.

It also allows organizations to support different authentication methods and user populations during the modernization journey. They can introduce technologies such as passkeys and digital credentials while continuing to support existing methods where they are still required. That flexibility is essential because modernization rarely happens through a single, clean cutover.

DigipassONE also establishes the foundation for where authentication is heading next. As digital identity ecosystems mature and AI agents begin interacting with institutions on behalf of customers, organizations will need to support new trust models and use cases without repeatedly rebuilding their underlying infrastructure.

We built DigipassONE to help customers strengthen security and simplify operations today, while giving them the flexibility to adopt what comes next.

For organizations looking to fast track modernization of their digital systems and authentication workflows: what top tips would you share?

The first thing I would emphasize is that modernization is not simply about deploying newer technology. It is about improving security in a way that customers can adopt and organizations can operate at scale.

First, pay attention to industry standards and participate in their development. Authentication works best when vendors, financial institutions, platform providers, and standards bodies collaborate around interoperable approaches and best practices. Open standards also give organizations greater flexibility and reduce the risk of locking themselves into a single technology or provider.

Second, design for transition rather than replacement. Most organizations cannot simply rip out their existing authentication infrastructure. Build progressive migration paths that allow new and existing methods to coexist, giving customers time to adopt without disrupting critical services.

Third, treat user experience as a security requirement, not an afterthought. A stronger authentication method delivers little value if customers avoid it, abandon enrollment, or overwhelm the support organization. Adoption, usability, and accessibility need to be considered from the beginning.

Fourth, look at the entire identity lifecycle—not just login. That includes registration, device enrollment, authentication, transaction approval, credential management, and account recovery. Strengthening the login flow while leaving recovery vulnerable simply moves the attack to the weakest part of the journey.

Fifth, establish clear business and security metrics. These should include adoption and conversion rates, sign-in time, enrollment abandonment, support costs, and credential-recovery volume, alongside risk measures such as phishing attempts, account takeover, fraud losses, and chargebacks. If you cannot measure the impact, you cannot determine whether modernization is actually working.

Finally, roll out in phases. Start with a specific customer segment, geography, use case, or channel—such as web versus mobile, or iOS versus Android. Learn from the data, refine the experience, and then expand. A controlled rollout makes it easier to identify issues, improve the experience, and expand across the broader customer population with confidence.

The goal is not modernization for its own sake. It is sustained customer adoption, measurable risk reduction, and an authentication foundation that can continue to evolve.

Five best practices you’d leave with our CIO and CISO readers before we wrap up?

First, make sure security has a seat at the table when business decisions are being made. Authentication, identity, and fraud prevention are no longer purely technology concerns. They directly affect customer experience, operational efficiency, compliance, and business performance. CIOs and CISOs should be involved from the beginning, not brought in after the strategy, architecture, or customer journey has already been defined.

Second, build for flexibility. The authentication landscape will continue to evolve, whether through passkeys, verifiable credentials, digital wallets, new regulations, or emerging threats. Organizations should not design only for today’s requirements. They need an architecture that can adapt as technologies, customer expectations, and business needs change.

Third, modernize progressively. Most organizations have significant investments in existing infrastructure, integrations, and customer workflows. Successful modernization usually means creating a practical transition path rather than forcing a disruptive rip-and-replace program. New and existing capabilities will need to coexist, sometimes for longer than anyone would ideally like.

Fourth, prepare for AI agents as a new digital channel. Customers currently interact with financial institutions through branches, websites, and mobile applications. AI agents will increasingly become another channel for checking balances, managing accounts, and initiating transactions. Organizations need to determine how those agents will be identified, authenticated, authorized, monitored, and governed—and how customer consent will be established and audited.

Finally, treat trust as continuous, not as a decision made once at login. A legitimate user can still operate from a compromised device, encounter malware, or initiate an unusual transaction. Organizations need to continuously evaluate signals across the user, device, application, session, and transaction, and adjust the level of assurance when risk changes.

Catch more CIO Insights: How Are CIOs Aligning Technology with Workforce Agility?

[To share your insights with us, please write to psen@itechseries.com ]

OneSpan helps organizations build secure, seamless, and trusted digital experiences through two solution portfolios: Cybersecurity and Digital Agreements. Our cybersecurity solutions protect identities, secure mobile apps, and safeguard access through advanced high-assurance authentication, threat intelligence, fraud prevention, and robust mobile app protection, defending users, devices, and applications against sophisticated attacks. Our digital agreements solutions streamline agreement workflows with secure e-signatures, identity verification, and smart digital forms, built to enable speed, compliance, and exceptional customer experiences. Trusted by leading global enterprises, including more than 60% of the world’s 100 largest banks, OneSpan processes over 100 million digital agreements and billions of secure authentication transactions across more than 120 countries each year.

Ashish Jain is OneSpan’s Chief Technology Officer. Widely regarded as one of the top digital identity experts in the industry, Ashish brings over two decades of experience leading product management, engineering, and operations teams at global organizations. He most recently served as Chief Product Officer at Arkose Labs, an enterprise fraud management and account security company where he led the development of the platform to help address consumer fraud and identity challenges for many Fortune 1000 companies. Prior to his role at Arkose Labs, Ashish served as Head of Identity at eBay, where he led the global engineering team to build the identity, risk, and trust platform to support onboarding, authentication, KYC, fraud, and abuse protection for 180+ million eBay customers and third-party developers. Before joining eBay, Ashish was Vice President of Workspace ONE at VMware, where he spearheaded the development and patenting of a solution that integrated identity and mobile device management, one of the core tenets of Zero Trust Security. Ashish received a Bachelor of Engineering degree from BITS, Pilani, India, and a Master of Business Administration from the University of Denver’s Daniels College of Business.

Related posts

Cambridge Quantum Computing Pioneers Quantum Machine Learning Methods for Reasoning

CIO Influence News Desk

StackGen’s Generative Infrastructure from Code (IfC) Now Available in AWS Marketplace

PR Newswire

Oasis Advances Protection of Remote Work through Partnership with SecureReview

ITech Analysts