Optiri Insights

Members Aren't Asking for Less Security

Written by Barry Lewis | Sep 2, 2026

Why protection and experience are the same objective, and what it costs to treat them as opposites

The Tightrope Walk, Part 1 of 4

 

In more than twenty-seven years in information technology and security, I have watched the relationship between security and user experience move from an afterthought to one of the most consequential strategic conversations in financial services. Nowhere is that conversation more personal than inside a credit union.

Credit unions are not banks, and the distinction matters here more than almost anywhere else. A credit union is owned by its members. Every person who deposits a paycheck or opens a certificate is simultaneously a customer and a shareholder. When we add friction to the online banking experience, we are not inconveniencing a customer; we are imposing that inconvenience on an owner of the institution. And when we fail to protect the institution, we fail the people whose trust and deposits make it possible.

That duality is why I have never accepted the framing of security versus user experience as a tradeoff to be optimized. It is not a dial with protection at one end and convenience at the other. It is one objective viewed from two angles, and treating the two as opposed produces worse outcomes on both.

The evidence for that claim is no longer theoretical, which is what prompted this series.

Members are Asking for Better Security, Not Less of It

Start with what members actually say they want. When PYMNTS Intelligence asked credit union members what area they most wanted their institution to innovate in over the next three years, twenty-seven percent chose security and trust — a higher share than any other feature or capability category.[1]

Members are not lobbying for weaker protection. They are asking us to protect them competently, which is a different request entirely and one we have failed in the past. That distinction should shape how we frame internal conversations about authentication and fraud controls, and in my experience it rarely does.

The Cost of Getting the Experience Side Wrong

The competitive picture has turned in a way that should concern anyone in this industry.

In J.D. Power's 2026 U.S. Credit Union Satisfaction Study, overall member satisfaction came in at 725 on a 1,000-point scale, a four-point decline from 2025. More telling than the drop itself is what happened to the gap: the credit union advantage over retail banks narrowed from seventy-four points to sixty-eight.[2] We are still ahead. We are not as far ahead as we were.

The study's central finding is the one I would put in front of a board. J.D. Power calls it soft switching: more than half of credit union members now hold checking (fifty-nine percent) and savings (fifty-six percent) accounts at other institutions, up two percentage points over two years.[2]

Members are not leaving. They are quietly relocating the parts of their financial life that are easiest to move — which is to say, the parts that live in the digital channel, where friction is measured in seconds and the alternative is one app download away.

This is the slow bleed. It does not show up as attrition in a monthly report. It shows up years later as a primary financial institution relationship that quietly became a secondary one, and by then the cause is unrecoverable.

The Part Most Security Professionals Get Backwards

Everything above describes how security affects experience. That direction is well understood, even if we implement it poorly. Every authentication step, every transaction limit, every session timeout is a small barrier between a member and what they are trying to do. Security controls introduce friction by their nature. The question is never whether security will affect the member experience — it always will. The question is whether we are introducing the right friction in the right places for the right reasons.

What gets far less attention is that the relationship runs in both directions. Poor member experience does not merely coexist with good security. It actively undermines it.

This is the argument I most often find missing from the conversation, so it is worth working through the mechanisms carefully.

Workarounds Move Risk to Where You Cannot See It

When security controls are too cumbersome, people do not become more secure; they become more creative.

Members write passwords down. They share credentials with a spouse or an adult child. They disable notifications because the volume became noise. They call the branch and ask staff to perform transactions on their behalf, bypassing the digital controls entirely.

Every one of those workarounds is a new vulnerability, and every one is a rational response to a control we designed. We made the front door hard to open, so people started using the window. The institution ends up less safe, not more, because behavior has moved to channels we cannot monitor, log or protect.

A control that is routinely circumvented has become a false assurance, which is worse than no control at all, because we stop looking.

Confusing Experiences Train Members to Fall for Fraud

This one is subtle and I think it is the most important.

Members who are accustomed to confusing, friction-heavy interactions with their credit union are less equipped to recognize fraud. If the normal experience involves unexpected verification requests, unexplained holds and authentication flows that change without warning, then a phishing message that mimics those patterns does not feel anomalous. It feels like Tuesday.

A clean, consistent, predictable member experience is itself a security control, because it makes fraudulent contact obviously out of place. When members know what a legitimate contact from their credit union looks like, an illegitimate one has to work much harder.

Consider the scale. Americans reported losing about $16 billion to fraud in 2025, the highest on record and an increase of roughly twenty-five percent over 2024.[3] Within that, imposter scams accounted for $3.5 billion and were the most-reported fraud category for the fifth consecutive year. Bank impersonators drove the highest losses of any business-impersonation category, roughly $1 billion.[3]

Criminals are successfully impersonating financial institutions at a scale of a billion dollars a year. Every inconsistency in how we contact our own members makes that job easier.

Friction Rolls Downhill onto Your Staff

The third mechanism is the one that shows up in operational metrics before anyone connects it to security.

When members cannot accomplish tasks through self-service because the security experience is too burdensome, they call or visit. Frontline staff, under pressure to resolve issues quickly and keep members happy, begin taking shortcuts — relaxing verification for a member they recognize, sharing information over channels that were not designed for it, granting access based on familiarity rather than authentication.

The risk did not disappear when we hardened the digital channel. It migrated to the human channel, which is less controlled, less logged and considerably harder to audit. And it is now carried by employees who are absorbing member frustration all day, which is neither fair to them nor stable over time.

What It Looks Like When This Works

None of this is an argument for less security. It is an argument that the two objectives are the same objective, and there is now a clean demonstration of what that looks like in practice.

Michigan State University Federal Credit Union deployed AI-powered deepfake detection in its call center in August 2024. In its first year, the system identified more than 220 fraudulent calls representing $2.57 million in fraud exposure.[4]

The security result is good. The rest is the point.

Over the same period, the credit union's Net Promoter Score rose from 57 to 63. Average authentication time per call dropped by fifty-eight seconds — a change valued at $723,840 in annual operating savings.[4]

A security investment produced a measurable improvement in member satisfaction, reduced handle time and paid for itself in operating savings. The system protected members while actively improving their experience, which is the outcome most of us have been told to stop expecting.

These figures come from a case study published by the technology vendor, so treat them with the appropriate discount. But the credit union has spoken about the results publicly and independent trade coverage exists.[4] Directionally, this is real, and it is the model.

The Asymmetry That Governs Everything Else

I want to close with the principle that should govern how any of this gets prioritized, because it is where I part company with the more enthusiastic versions of this argument.

The two failure modes are not symmetric.

Overweighting security at the expense of experience causes gradual erosion — a slow bleed of satisfaction, competitive position and growth. Soft switching is exactly this. It is painful, it compounds and it is generally recoverable.

Overweighting experience at the expense of security creates the conditions for catastrophic failure — a single event that can undo years of institutional progress, invite formal enforcement and consume leadership attention for years.

This does not mean security always wins the argument. It means the minimum security threshold is not negotiable, and experience optimization happens within and above that threshold, never below it. Where that threshold sits is a business decision, made against a defined risk tolerance, owned by the board. It is not a technical decision and it should never be made by default.

Everything I have described here — the workarounds, the fraud susceptibility, the staff burden — happens above that threshold. That is the space where security and experience stop competing and start reinforcing each other, and where I would spend my next dollar.

 

Part 2 examines third-party risk: why roughly seven in ten reported credit union cyber incidents originate with a vendor, and why 2026 moved that burden squarely onto the credit union.

 

Sources

  • PYMNTS Intelligence, credit union member research, 2024–2025.
  • J.D. Power, 2026 U.S. Credit Union Satisfaction Study, released March 31, 2026; 2025 U.S. Credit Union Satisfaction Study, April 2025.
  • Federal Trade Commission, "FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025," June 15, 2026; FTC, "New FTC Data Show Big Jump in Reported Losses to Fraud to $12.5 Billion in 2024," March 10, 2025.
  • Pindrop, One Year Later: Michigan State University Federal Credit Union Minimizes Fraud Exposure by Millions, 2025; American Banker, "Michigan credit union blocks fraud with deepfake detection," December 2025.

The views expressed in this article reflect the author's professional experience and do not represent the official position of any specific institution.