Step-Up Authentication on Sensitive Actions
First login of the day triggers a standard MFA challenge. Subsequent sensitive actions — wire release above threshold, user provisioning, password reset, adding an ACH payee — re-prompt for authentication through step-up MFA. RSA SecurID hardware tokens provide phishing-resistant codes for the highest-privilege roles. Administrators can require token-only MFA for wire approvers while allowing SMS MFA for read-only accountants. See Security for the full threat model and response procedures.
Push approval via the mobile app replaces manual code entry — the online banking portal displays a challenge, the mobile app raises a notification, and the user approves with biometrics. Push approval also surfaces contextual detail (device, geolocation, action type) that static codes cannot.
