Financial services
Security operations that survive a regulator's questions.
You are targeted more, regulated harder, and asked to evidence more than most. Every action needs to be attributable and every number defensible.
- NIST CSF 2.0Scored
- CIS Controls v8Scored
- SOC 2Evidenced
- PCI DSSEvidenced
- DORAEvidenced
- NIS2Evidenced
The pressure
Pressures specific to this sector
Every sector has pressures. These are the ones that change what a security programme is allowed to do here.
Multiple overlapping regulatory regimes, each wanting its own evidence.
The same control gets evidenced three times, because nothing maps one answer onto three frameworks.
Identity is the primary target, and privileged access is everywhere.
A signal that is routine on a shared mailbox is an incident on a trading desk account, and most tooling scores them identically.
Third-party and concentration risk is a supervisory expectation, not a nice-to-have.
You are asked about suppliers you do not directly monitor, on a cadence you do not set.
Every automated action must be attributable to a person or a policy.
An action nobody can attribute is worse than an action that never ran.
The constraint
The constraint
Nothing is allowed to happen here that you could not later reconstruct for somebody who was not in the room.
Frameworks
What you are measured against, and what we actually do about it.
Two states, and they are not the same thing. The cards say which is which rather than listing every framework at the same weight.
NIST CSF 2.0
ScoredAll 106 controls across six functions, scored control by control, with the method that answered each one recorded on it.
CIS Controls v8
ScoredSafeguard-level scoring scoped by implementation group, sharing the same engine, evidence handling and gaps queue.
SOC 2
EvidencedNo agent assesses the Trust Services Criteria today. The evidence the two assessments collect is largely the evidence a TSC review asks for.
PCI DSS
EvidencedNo agent assesses it. What the platform contributes is the audit trail: every action with its actor, every decision with its reasoning.
DORA
EvidencedNo agent assesses it. The operational-resilience record it asks for, incident timelines, response times, approvals, is produced by running the agents.
NIS2
EvidencedNo agent assesses it. Incident records and their reporting timeline come out of the audit trail rather than being reconstructed.
Scored means an agent assesses that framework control by control and produces a maturity score and a gap register. Evidenced means no agent assesses it: what the platform contributes is the audit trail and the control evidence a reviewer asks to see. Neither is a compliance certification, and framework mapping is a control-evidence aid rather than a legal opinion.
The answer
How the platform works around it.
Three movements, in order. The constraint above is restated in each of them, because it is what makes this sector's version different.
See
Everything, recorded
Every signal, decision and action written to an audit trail built for scrutiny, with the actor named on every state transition: analyst, engine, or automation.
Decide
Attributable decisions
Each decision carries its reasoning, its confidence and whoever approved it. Privilege weighting means an executive account is not scored like a shared mailbox.
Act
Evidence as a by-product
Operating the platform produces the evidence. Framework scoring runs continuously rather than as a separate project each time a supervisor asks.
Who does the work
The agents this sector leans on.
You can turn one on and add the others later. A connector configured for one is available to the rest.
- Detect and RespondIdentity CompromiseCatches impossible travel, MFA fatigue, and credential stuffing, and contains the account before it becomes lateral movement.
- Detect and RespondAlert NavigatorReads every alert your SIEM raises, classifies it, groups what belongs together, and hands your analysts a queue worth working.
- Assess and ComplyNIST CSF 2.0 AssessmentScores your maturity across all six CSF 2.0 functions, tracks every gap to an owner, and produces the report your board asked for.
Also named for this sector
Third-Party Risk
Vendor risk scoring, questionnaire automation, and continuous supply-chain monitoring.
Questions
The things this sector asks first.
Can I show a regulator who approved an automated action?
Yes. Every state transition records its actor, whether that is an analyst, the scoring engine, or an automation, along with the timestamp, the action and the result. On the remediation side an approval is bound to the exact artifact that ran, so what was reviewed is provably what executed.
What stops an agent acting on a privileged account by itself?
Privilege is an input to the score, not an exception to it: Finance, Exec, Admin and HR accounts carry extra weight, so the same signal reaches a review gate sooner. Anything uncertain waits for a person, and the identity gate does not contain on timeout.
Does the platform cover third-party risk?
Not as its own agent. Third-Party Risk is scoped and documented but has not shipped, so it is named on this page and nothing more. Supplier oversight is currently evidenced through the framework assessments rather than monitored continuously.
How much of our reporting is defensible without rework?
The assessments export with the scoping decisions recorded, so a reader can see what was considered out of scope and why. Where a data source is offline, panels timestamp the cached figure rather than presenting it as current.
The other sectors
- HealthcarePatient data, legacy systems that cannot be patched on demand, and clinical uptime.
- Public sectorMandated frameworks, procurement scrutiny, and constrained headcount.
- Technology and SaaSCloud-native estates, fast shipping, and customers who ask hard security questions.
- Manufacturing and OTComing soonProduction uptime, flat networks, and equipment that predates the security model.
