All sectors

Information security for financial services

In a financial organisation an attacker is not after information but access: to an account, to a payment system, to a user who can approve a transaction. At the same time, sector supervision expects the organisation to be able to explain how it manages that risk and what it did when an incident occurred. Both point at the same requirement: real visibility into the systems, and a record that can be produced.

What is at stake

  • Customer data and account details
  • Payment and transfer systems
  • Identities holding approval permissions
  • Interfaces to suppliers and clearing systems

The incidents that matter here

  • Takeover of a user account holding approval rights, rather than a random endpoint
  • Transfer fraud that abuses a legitimate business process instead of a technical flaw
  • Intrusion through a supplier or an external interface connected to the environment
  • Long, quiet dwell time in the network before the act itself

Obligations that shape the work

Financial organisations in Israel are subject to sector supervision covering cyber risk management, controls and incident reporting, as well as to privacy law and its Amendment 13. The precise requirements vary with the type of organisation and its regulator, so a risk assessment starts by mapping what the organisation is obliged to demonstrate, and only then moves to the technical examination.

This is general information, not legal or regulatory advice. The obligations that apply to a particular organisation depend on its activity and its regulator.

How we approach it

  • Continuous monitoring weighted to identities, permissions and unusual activity in core systems
  • A defined response and reporting path, so an incident can be presented to a supervisor
  • A risk assessment that produces a document fit for audit, not only a technical findings list
  • Training aimed at the people holding approval rights, who are the actual target

// next step

Not sure what the right next step is?

Use the short assessment to identify the areas worth reviewing, or tell us what changed and we will start from there.

Do not send passwords, credentials, API keys, logs or sensitive incident material through the web form.