Prevent · Authenticate · Discourage
Reduce opportunities for fraudulent exploitation by strengthening transaction security, communication authenticity, identity context and trust checks before a sensitive action.
How TAA SECO works
A cyberattack does not necessarily end when the compromised system is restored. Stolen customer, employee, partner or user data can later be used for impersonation, social engineering and fraudulent instructions. TAA SECO is designed to add a further trust layer before an incident and after information has already been exposed.
Before & after compromise
TAA SECO complements existing cybersecurity by protecting the trust relationships that attackers may try to exploit around identities, communications, transactions and authorized interactions.
Reduce opportunities for fraudulent exploitation by strengthening transaction security, communication authenticity, identity context and trust checks before a sensitive action.
When real information has already been copied or disclosed, reinforce checks so possession of that information alone is not treated as sufficient proof of legitimacy.
An organization may introduce the protection layer before an incident or after a compromise, when confidence in identities, communications and counterparties needs to be rebuilt.
Core principle
An attacker may know a customer’s name, telephone number, address, bank, employer or other real details. Those facts can make a false story more convincing, but they do not prove that the caller, sender, website, representative or transaction destination is legitimate.
TAA SECO is designed to introduce additional references and trust checks around the identity, communication, recipient or context the user believes to be authentic.
Beyond strong authentication
Strong authentication primarily answers: is this really the user performing the operation? That protection is essential, but a legitimate user may still authorize a fraud if they have been deceived about who they are dealing with or what they are authorizing.
Within the combined TAA-TPV framework, SECO can add a separate verification reference around the identity, recipient or context the user believes is legitimate. TAA adds a further concern for situations where the legitimate user may be under pressure or coercion.
The architecture in practice
The first invention adds protection around sensitive transactions, communications and situations involving manipulation or coercion.
The second invention supports trust decisions when dealing with unknown or not personally known counterparties and can provide controlled identity-status context.
SECO is a public security reference derived from the TAA framework and intended to help compare an apparent identity or destination with a separate trusted reference.
AOM uses the TAA/SECO infrastructure to support verification of organizational affiliation and, where applicable, the authenticity or status of a claimed mission or authorization.
What is SECO?
SECO — Secure External Code is a public security-identification code derived from the TAA framework. Depending on the service, it may be associated with a telephone number, email address, website, application, digital account, financial identifier, business, company, institution, product, service or another compatible element.
The objective is not to replace existing identifiers. It is to give users another reference to compare before deciding whether the visible identity or destination is consistent with trusted information.
For organizations
The precise verification criteria depend on the identity or service concerned and on the applicable deployment framework.
Physical interactions
Not every impersonation attempt happens online. A person may appear as a technician, employee, institutional representative, delivery person or other supposedly authorized agent while using real information to make the story credible.
AOM is designed to add a verification layer around organizational affiliation and, where the deployment supports it, the existence, validity, expiry or revocation of a mission or authorization.
Reducing the burden on users
Advice such as “do not click,” “verify the number,” “call us before acting” or “be cautious with unexpected visitors” remains important. But people may need to decide under stress, urgency or fear. TAA SECO is intended to add system-level indications and controls rather than leaving the entire decision to human judgment alone.
A layer of protection, not an absolute promise
TAA SECO is intended to complement — rather than replace — banking controls, telecommunications security, identity systems, strong authentication, cybersecurity measures and appropriate human verification. Its objective is to reduce the exploitability of compromised information and strengthen trust decisions around identities, communications, transactions and missions.
Production use remains subject to technical feasibility, institutional integration, governance, privacy and applicable regulation. Protected implementation details remain outside the public disclosure layer.
Legal & public disclosureAlready experienced a compromise?
An organization may evaluate TAA SECO after a breach or data exposure to strengthen subsequent protection of clients, employees, partners or users against impersonation and social-engineering attempts.
Discuss a post-compromise protection context →