Skip to content

Financial services

Security operations that survive a regulator's questions.

You are targeted more, regulated harder, and asked to evidence more than most. Every action needs to be attributable and every number defensible.

The pressure

Pressures specific to this sector

Every sector has pressures. These are the ones that change what a security programme is allowed to do here.

  1. Multiple overlapping regulatory regimes, each wanting its own evidence.

    The same control gets evidenced three times, because nothing maps one answer onto three frameworks.

  2. Identity is the primary target, and privileged access is everywhere.

    A signal that is routine on a shared mailbox is an incident on a trading desk account, and most tooling scores them identically.

  3. Third-party and concentration risk is a supervisory expectation, not a nice-to-have.

    You are asked about suppliers you do not directly monitor, on a cadence you do not set.

  4. Every automated action must be attributable to a person or a policy.

    An action nobody can attribute is worse than an action that never ran.

The constraint

The constraint

Nothing is allowed to happen here that you could not later reconstruct for somebody who was not in the room.

Frameworks

What you are measured against, and what we actually do about it.

Two states, and they are not the same thing. The cards say which is which rather than listing every framework at the same weight.

  • NIST CSF 2.0

    Scored

    All 106 controls across six functions, scored control by control, with the method that answered each one recorded on it.

  • CIS Controls v8

    Scored

    Safeguard-level scoring scoped by implementation group, sharing the same engine, evidence handling and gaps queue.

  • SOC 2

    Evidenced

    No agent assesses the Trust Services Criteria today. The evidence the two assessments collect is largely the evidence a TSC review asks for.

  • PCI DSS

    Evidenced

    No agent assesses it. What the platform contributes is the audit trail: every action with its actor, every decision with its reasoning.

  • DORA

    Evidenced

    No agent assesses it. The operational-resilience record it asks for, incident timelines, response times, approvals, is produced by running the agents.

  • NIS2

    Evidenced

    No agent assesses it. Incident records and their reporting timeline come out of the audit trail rather than being reconstructed.

Scored means an agent assesses that framework control by control and produces a maturity score and a gap register. Evidenced means no agent assesses it: what the platform contributes is the audit trail and the control evidence a reviewer asks to see. Neither is a compliance certification, and framework mapping is a control-evidence aid rather than a legal opinion.

The answer

How the platform works around it.

Three movements, in order. The constraint above is restated in each of them, because it is what makes this sector's version different.

  1. See

    Everything, recorded

    Every signal, decision and action written to an audit trail built for scrutiny, with the actor named on every state transition: analyst, engine, or automation.

  2. Decide

    Attributable decisions

    Each decision carries its reasoning, its confidence and whoever approved it. Privilege weighting means an executive account is not scored like a shared mailbox.

  3. Act

    Evidence as a by-product

    Operating the platform produces the evidence. Framework scoring runs continuously rather than as a separate project each time a supervisor asks.

Questions

The things this sector asks first.

  • Can I show a regulator who approved an automated action?

    Yes. Every state transition records its actor, whether that is an analyst, the scoring engine, or an automation, along with the timestamp, the action and the result. On the remediation side an approval is bound to the exact artifact that ran, so what was reviewed is provably what executed.

  • What stops an agent acting on a privileged account by itself?

    Privilege is an input to the score, not an exception to it: Finance, Exec, Admin and HR accounts carry extra weight, so the same signal reaches a review gate sooner. Anything uncertain waits for a person, and the identity gate does not contain on timeout.

  • Does the platform cover third-party risk?

    Not as its own agent. Third-Party Risk is scoped and documented but has not shipped, so it is named on this page and nothing more. Supplier oversight is currently evidenced through the framework assessments rather than monitored continuously.

  • How much of our reporting is defensible without rework?

    The assessments export with the scoping decisions recorded, so a reader can see what was considered out of scope and why. Where a data source is offline, panels timestamp the cached figure rather than presenting it as current.