Version 1 - Primary Nav Search
2 people looking at a pc screen

9 min read

Key takeaways

  • Payment security extends across the people, processes, systems and providers involved in moving money.
  • Cyber resilience includes prevention and detection as well as the ability to withstand disruption, respond and recover trusted operations.
  • Understanding the payment stack helps organizations identify where fraud, cyber threats and operational failures can enter.

As payments become faster and more connected, security increasingly depends on every identity, system, workflow and provider involved in moving money. A disruption at any point can affect payment execution, liquidity, supplier relationships and customer trust.

Cyber-resilient payments are designed to protect trusted activity across the full payment lifecycle by combining payment security and payment fraud prevention with the ability to withstand disruption, respond effectively, recover trusted operations and apply what teams learn.

Payments rarely move through just one system from start to finish. A supplier request may pass through email, an enterprise resource planning (ERP) platform, a treasury management system and an API before reaching a payment provider. Clearing, settlement and reconciliation add further dependencies.

Compromised credentials or altered payment instructions can redirect activity, while an application failure or third-party outage can interrupt processing even when internal systems continue to work.

What are cyber-resilient payments

Cyber resilience combines prevention and detection with the ability to withstand disruption, respond effectively and restore trusted payment operations. It connects disciplines that often sit with different teams across an organization.

Cybersecurity protects systems, identities and data. In payments, that includes controls around access, applications and infrastructure.

Payment fraud prevention focuses on the legitimacy of payment activity: whether the person making a request is authorized, whether payment information has changed or whether activity requires further review.

Operational resilience considers how critical payment activity continues during a disruption and how operations return to a trusted state.

Together, these disciplines help payment, technology and risk teams assess exposure and prepare for disruption across the payment lifecycle.1

Why is perimeter security no longer enough? 

Payment systems depend on connections that extend beyond an organization’s internal network. Employees communicate with vendors through email, ERP and treasury platforms connect with external applications, and APIs carry payment instructions and data between systems.

Those connections create additional exposure. Credential theft can give an attacker access through a legitimate account, while business email compromise, vendor impersonation or social engineering can introduce fraudulent instructions into a familiar process. AI is also changing the threat landscape, letting attackers automate impersonation, credential theft and social engineering at greater scale.2

External dependencies also affect availability. A cloud service or payment processing outage can interrupt activity even when internal systems remain secure.

Third-party dependencies can also affect payment security and resilience. Visibility into the external services supporting payment activity can help organizations understand where a disruption could affect the flow of funds.

For more on common fraud risks and controls, see the Payments Fraud Education Guide.

What does the payment stack include?

For purposes of this article, the payment stack includes the people, processes, systems, data and external services involved in moving a payment from instruction through reconciliation.

For an enterprise, viewing payments through the stack can help teams understand where disruption could occur, how risk can propagate and where controls may have the greatest impact.

One way to organize that stack is across seven connected layers:

  1. Identity and access Employees, administrators and service accounts, and the controls that determine who can access systems and perform payment-related actions. 
  2. Vendors, payees and payment instructions Counterparties, account information and the processes used to establish or change payment details. 
  3. Business applications and workflows ERP platforms, treasury management systems and other applications used to create, review or approve payment activity. 
  4. APIs, integrations and payment data Connections that move payment instructions between systems and the data used to execute or verify them.
  5. Payment initiation and processing Channels and infrastructure used to submit payments for execution. 
  6. Clearing, settlement and reconciliation Processes that move funds through the financial system and allow organizations to confirm that activity completed as expected. 
  7. Providers, infrastructure and recovery dependencies External services, technology infrastructure and continuity arrangements that support payment operations. 

A problem in one layer can affect activity elsewhere, especially when systems or providers depend on one another.

“The strength of a payment environment depends on how well its layers hold together when something goes wrong.”

Where are the critical risks across the payment lifecycle?

Risk can enter at different points in the payment lifecycle—through compromised credentials, fraudulent instructions or failures in applications, data or third-party providers.

Looking across the payment stack can help teams connect each area of exposure with the controls designed to address it. The examples below are illustrative and are not intended to represent every potential risk, impact or control.

RiskPotential impactControls to consider
Compromised credentials or account takeoverUnauthorized access to payment systems or workflowsIdentity and access management, multi-factor authentication (MFA) and least-privilege access
Fraudulent payment instructionsPayments sent to an unintended accountDual approval, account validation and payee verification
Application or API compromiseUnauthorized activity, altered instructions or unavailable servicesAuthentication, access controls, logging and change management
Payment data compromiseIncorrect, altered or exposed payment informationData protection, integrity controls and tokenization where appropriate
Third-party disruptionDelayed or unavailable payment servicesVendor risk management, continuity planning and escalation procedures
Processing outage or ransomwareInterrupted payment activity and reconciliation challengesIncident response, continuity testing, recovery procedures and reconciliation controls

For many organizations, the impact extends beyond financial loss to include operational disruption, customer trust and business growth. Controls will vary by organization. What matters is whether they can detect compromise, limit its impact and support recovery.

Additional guidance on payment fraud protection is available in Payment Fraud Controls.

How can organizations build resilience across the payment stack?

Payment cyber resilience can be viewed across five stages: prevent, detect, withstand, respond and recover.

  • true

    Prevent

    Prevention starts with controlling access, validating payment instructions and leveraging solutions that tokenize payments data. Identity and access management, multi-factor authentication and least-privilege access can reduce unauthorized activity, while dual approval, account validation, payee verification and payment authentication can add checks before funds move.

    Working with a trusted provider to reduce the need to store and maintain payment data can also help limit the repercussions of a cyberattack.

  • warning icon

    Detect

    Payment fraud detection and transaction monitoring can identify activity outside expected patterns. System logs and audit trails add context, particularly when a payment change follows unusual access or involves a new payee.

  • clipboard

    Withstand

    Organizations can benefit from understanding which payment services are critical, which dependencies support them and where an outage could interrupt activity. Payment continuity planning and testing can help teams prioritize critical payments and identify gaps before disruption occurs.

  • chat icon

    Respond

    Clear decision rights can support incident response by establishing who can pause activity, where concerns are escalated and which functions or providers may need to be involved. Teams can also benefit from enough context to determine what is affected and what remains trustworthy.

  • circular arrows

    Recover

    Recovery means restoring payment operations with confidence in the systems, data and instructions supporting them. Teams may need to confirm which transactions were processed, reconcile activity and validate information before normal workflows resume. An incident can also expose gaps that should be addressed before the next disruption occurs.

    Together, these capabilities help organizations move beyond reactive defense and toward a more proactive model for staying ahead of evolving fraud and cybersecurity threats.

Who owns payment cyber resilience?

Payment cyber resilience is a shared responsibility—no single function owns the entire payment stack. Treasury and payment operations understand payment flows and the business impact of disruption, while cybersecurity and technology teams manage many of the controls around identities, applications and infrastructure.

Payment resilience increasingly spans treasury, payments and technology teams as organizations consider payment-related risk, technology dependencies and continuity planning.3

Procurement, risk, business continuity, accounts payable, compliance and audit may also own important parts of the process. What matters is whether responsibility is clear where those functions meet.

Payment security governance can help clarify who monitors each part of the stack, how concerns are escalated and who can make decisions during an incident. Continuity exercises, crisis simulations, threat intelligence and audit trails can help teams test those responsibilities as risks change.

What should organizations ask a payment provider?

A payment provider is part of the broader payment stack. Its security and resilience approach should fit the organization’s operating model.

Useful questions include:

  • How is access to payment services protected?
  • What capabilities support payment fraud protection, account validation and payment authentication?
  • Who manages and stores payment data? Is that data secure?
  • How is payment activity monitored for unusual behavior?
  • Which material third-party dependencies support the service?
  • How are service disruptions managed and what continuity measures support critical payment activity?
  • What incident response, recovery and reconciliation support is available?

The answers can help organizations understand how provider controls connect with their own and where responsibility remains with internal teams.

A broader view of security, fraud and resilience is available through Payments Security & Trust.

 

Frequently asked questions

For purposes of this article, payment security includes controls designed to help protect payment systems, data, access and transactions from unauthorized activity, fraud or compromise, including access controls, payment authentication, transaction monitoring and payment data protection.

A payment stack is the collection of people, workflows, applications, connections, data, providers and financial infrastructure involved in moving a payment from instruction through processing, settlement and reconciliation.

Cyber resilience in payments is the ability to help protect payment activity while preparing for cyber incidents or disruption. It includes prevention, detection, the ability to withstand an event, response and recovery.

Secure payment systems use layered controls across access, payment instructions, applications, data and transactions. Resilience also requires continuity planning, incident response and recovery capabilities to manage payment operations when a system or dependency is affected.

Payment continuity generally refers to maintaining critical payment activity during a disruption or restoring it within an acceptable period. It depends on understanding critical services, technology dependencies, provider relationships and recovery procedures.4

Speak with a payments specialist about securing and strengthening your payment operations. 

Contact us

This field is required.

This field is required.

This field is required.

This field is required.

This field is required.

Please enter a valid business email. This field is required.

Please enter a valid business email. This field is required.

Please enter a valid business email. This field is required.

By checking the box below I consent to JPMorganChase using the information I have provided to send me:

Learn more about our data practices in our privacy policy.

Disclaimer

J.P. Morgan, JPMorganChase, Chase, Chase Merchant Services, and Chase Payment Solutions are marketing names for certain businesses of JPMorganChase and its subsidiaries worldwide (collectively, “JPMorganChase”). Products or services may be marketed and/or provided by commercial banks such as JPMorgan Chase Bank, N.A., securities or other non-banking affiliates or other JPMorganChase entities. JPMorganChase contact persons may be employees or officers of any of the foregoing entities and the terms “J.P. Morgan”, “JPMorganChase”, “Chase”, “Chase Merchant Services” and “Chase Payment Solutions” if and as used herein include as applicable all such employees or officers and/or entities irrespective of marketing name(s) used. Nothing in this material is a solicitation by JPMorganChase of any product or service which would be unlawful under applicable laws or regulations.

In preparing this material, we have relied upon and assumed, without independent verification, the accuracy and completeness of all information available from public sources or which was provided to us or which was otherwise reviewed by us. This material is for discussion purposes only and is incomplete without reference to any other applicable briefings provided by JPMorganChase. Neither this material nor any of its contents may be disclosed or used for any other purpose without the prior written consent of JPMorganChase.

This material is not intended to provide legal, tax, investment, accounting, financial, business, real estate, technology or other advice, and should not be used for or relied upon for these purposes. The views, opinions, estimates and strategies expressed in this material are those of the respective individual contributors, authors or speakers, and may differ from those of JPMorganChase, or its employees and affiliates. Any market and/or economic commentary in this material in no way constitutes JPMorganChase research and should not be treated as such. Further, the views expressed in this content may differ from those contained in JPMorganChase research reports. The content in this material has been obtained from sources deemed to be reliable, but JPMorganChase makes no representation or warranty as to its accuracy or completeness. In no event shall JPMorganChase nor any of its directors, officers, employees or agents be liable for any use of, for any decision made or action taken in reliance upon, or for any inaccuracies or errors in or omissions from, this material.

The information in this document may be based upon management forecasts supplied to us and reflects prevailing conditions and our views as of this date, all of which are accordingly subject to change. JPMorganChase’s opinions and estimates constitute J.P. Morgan’s judgment and should be regarded as indicative, preliminary and for illustrative purposes only. 

Not all products and services are available in all geographic areas. Eligibility for particular products and services is subject to final determination by JPMorganChase and or its affiliates. This material does not constitute a commitment by any JPMorganChase entity to extend or arrange credit or to provide any other products or services and JPMorganChase reserves the right to withdraw at any time. All products and services are subject to applicable laws, regulations, and applicable approvals and notifications.

Any mentions of third-party trademarks, brand names, products and services are for referential purposes only and any mention thereof is not meant to imply any sponsorship, endorsement, or affiliation.

Notwithstanding anything to the contrary, the statements in this material are not intended to be legally binding. Any products, services, terms or other matters described herein (other than in respect of confidentiality) are subject to, and superseded by, the terms of separate legally binding documentation and/or are subject to change without notice. 

JPMorgan Chase Bank, N.A. Member FDIC. Deposits held in non-U.S. branches are not FDIC insured. Non-deposit products are not FDIC insured.

JPMorgan Chase Bank, N.A., organized under the laws of U.S.A. with limited liability.

© 2026 JPMorgan Chase & Co. All Rights Reserved.