The financial sector has relied on digitalization for many years to work more efficiently and enhance collaboration. Increasingly, systems are being migrated to the cloud. While some less regulated actors are still at the beginning of this journey, one thing remains crucial for all: protecting sensitive personal and financial data is the top priority. Without robust IT system protection, serious consequences such as operational interruptions, data leaks, extortion, or severe reputational damage can occur.

Information Security Specialists for Financial Service Providers

The specialized Finance Consultant Team at Redguard AG combines industry and security expertise to deliver efficient and effective added value for companies in the financial and insurance sector. We understand the current challenges of the industry and support our clients in achieving their goals safely. In addition to extensive and diverse practical experience, we hold various certifications such as SWIFT, CISA, CISM, and CRISC.

Familiar with the Challenges of the Financial Services Industry – Security & Data Protection

Thanks to our industry specialists, we understand the challenges of the financial sector and know how to provide pragmatic and holistic support.

Selected References on This Topic

Popular Among Our Financial Services Clients

CISO Advisory

If you want to strengthen your security organization but currently lack sufficient management capacity, one of our experienced experts can serve as an (Chief) Information Security Officer on a mandate basis. They can act as an interim solution until you find your own CISO, support your current CISO as a sparring partner, or take over specific projects. On request, the CISO can also draw on additional Redguard resources to provide targeted project support.

DORA & Threat-Led Penetration Testing

Redguard supports you in the gap analysis for individual status determination, prioritization of identified areas for action, development of a comprehensive implementation plan, execution of a Threat-Led Penetration Test, as well as methodical and substantive support in the various areas for effective measure implementation and personnel support for efficient action planning. See blog post “Digital Operational Resilience Act (DORA)”.

NIST Assessment

Redguard conducts an assessment with you based on the current NIST standard. Alternatively, we also offer an assessment based on the ICT minimum standard.

3rd Party Risk Management

Redguard supports you in identifying and assessing critical service providers and involved subcontractors, creating risk-based control points for the entire service chain, performing periodic monitoring audits of the service chain, and establishing effective monitoring and management reporting. See blog post “Monitoring of Service Providers in the Financial Sector”.

SWIFT

As part of the SWIFT Customer Security Programme (CSP), annual independent assessments must be carried out to confirm compliance with the Customer Security Controls Framework (CSCF). We support you in conducting an independent external assessment and, thanks to our extensive experience and certified auditors, can attest to CSCF compliance. The focus of the assessment is on the mandatory controls, which must be implemented without exception.

FINMA Requirements

Redguard supports you in the gap analysis for individual status determination, including prioritization of identified areas for action and comprehensive implementation planning; in identifying critical functions and outsourcing; in monitoring outsourced functions and risks; in identifying risks for critical data and defining adequate protection measures; in defining roles, processes, procedures, and controls in handling critical data; in building management reporting; in strengthening employee awareness; in conducting internal audits; in developing and testing crisis management (BCM) and IT Service Continuity Management (ITSCM) plans; and in carrying out attack simulations or targeted penetration tests. See our blog post on FINMA Circular 2023/1.

IT General Controls

Redguard assists you in stakeholder alignment, risk identification, design and management of key controls, coordination of periodic audits, and follow-up on audit results. See blog post “Financial Industry: Challenge IT General Controls”.

Cloud Security

Redguard supports you as a security SPOC for cloud transformation projects – Modern Workplace – in defining and implementing security measures in the Azure / M365 context, for example with Microsoft Defender or Purview; in conducting cloud security assessments to identify risks in your current cloud setup; in defining and introducing cloud security governance; and in creating security concepts (e.g., classification, data loss prevention, etc.). See blog post “Cloud Security: Challenges in the Financial Industry”.

PCI DSS

Based on experience from over a thousand penetration tests, Redguard supports you in deciding which systems should or must be tested. Together, we define an appropriate quarterly scope and plan the penetration tests with internal specialists and responsible parties. The results are documented in a detailed report generated efficiently using our in-house reporting engine. For long-term clients, we develop export interfaces to client systems (xls, Jira, etc.). See Success Story PostFinance.

Secure Software Development

Banks, insurance companies, payment service providers, and many other financial institutions develop their own software. To make this as secure as possible and apply “Security by Design” principles, we provide on-site training with hands-on exercises. In addition, we offer a wide range of security e-learnings for everyone involved in developing and maintaining web applications – developers, software architects, project managers, Scrum Masters, DevOps engineers, and administrators. We also help you optimize your container and Kubernetes security through training or by reviewing your current systems. Furthermore, we support you in the DevSecOps area – from setting up DevSecOps, reviewing existing setups, expanding your CI/CD pipeline, to conducting an OWASP SAMM assessment.

Experience with All Types of Financial Service Providers

With our comprehensive industry experience, we advise financial service providers of all kinds:

Insurance Companies

Private Banks

Asset Managers

Finance-specific partnerships

Swift

Finance Security Blog Posts

Swift CSP CSCF v2026 – Ein Fahrplan für die Backoffice-Sicherheit
28. Apr 2026

Swift CSP CSCF v2026 – Ein Fahrplan für die Backoffice-Sicherheit

Cyber-Angriffe werden raffinierter, und Swift zieht die Zügel an: Mit der neuen Version CSCF v2026 wird die Absicherung...
FinTech-Regulierung in der Schweiz (und EU)
18. Nov 2025

FinTech-Regulierung in der Schweiz (und EU)

Lesen Sie, was Schweizer FinTechs jetzt konkret tun sollten, um die regulatorischen Verpflichtungen in der Schweiz (und...
PSD2, Open Banking & API‑Security – Als Schweizer Institut prüfungssicher Systeme betreiben
10. Nov 2025

PSD2, Open Banking & API‑Security – Als Schweizer Institut prüfungssicher Systeme betreiben

Erfahren Sie in diesem Artikel, welche Anforderungen das PSD2 und Schweizer Behörden an die API-Sicherheit stellen und...
Swift CSP CSCF v2025 – Was Finanzinstitute jetzt wissen müssen
28. Apr 2025

Swift CSP CSCF v2025 – Was Finanzinstitute jetzt wissen müssen

Architekturtyp-Änderung & Advisory Controls: Jetzt handeln, um Compliance sicherzustellen.
FINMA: KI – Balanceakt zwischen Chance und Risiko
04. Apr 2025

FINMA: KI – Balanceakt zwischen Chance und Risiko

Was bedeutet die FINMA Aufsichtsmitteilung 08/2024 zum Thema KI für Finanzunternehmen? Governance, Datenqualität, Test...
Cyber Security im FINMA-Risikomonitor 2024 – eine Zusammenfassung
22. Nov 2024

Cyber Security im FINMA-Risikomonitor 2024 – eine Zusammenfassung

Der FINMA-Risikomonitor 2024 hebt Cyber Security als eines von neun Hauptrisiken hervor – ein Thema, das bereits in der...
KI-Gesetz (AI Act) der EU tritt in Kraft
27. Sep 2024

KI-Gesetz (AI Act) der EU tritt in Kraft

Der von der Europäischen Union erlassene Artificial Intelligence Act (Verordnung 2024/1689 zur Festlegung harmonisierter...
Threat-Led Penetration Testing gemäss DORA
24. Jul 2024

Threat-Led Penetration Testing gemäss DORA

In der immer stärker digitalisierten Welt stehen Finanzinstitute vor einer Vielzahl an Herausforderungen. Ein wichtiger...
Digital Operational Resilience Act (DORA)
19. Jul 2024

Digital Operational Resilience Act (DORA)

In einer zunehmend digitalisierten Welt spielt die Gewährleistung der Betriebssicherheit eine entscheidende Rolle für...
Finanzbranche: Challenge IT General Controls
30. May 2024

Finanzbranche: Challenge IT General Controls

Im Rahmen des IT Risk Managements werden auf Basis identifizierter Risiken adäquate Schutzmassnahmen (Controls) zur...
FINMA-Rundschreiben «2023/1 Operationelle Risiken und Resilienz – Banken»: Jetzt Überblick verschaffen
24. May 2024

FINMA-Rundschreiben «2023/1 Operationelle Risiken und Resilienz – Banken»: Jetzt Überblick verschaffen

Seit dem 1. Januar 2024 ist das totalrevidierte FINMA-Rundschreiben 2023/1 zum Management der Operationellen Risiken und...
Cloud Security: Herausforderung in der Finanzbranche
22. Apr 2024

Cloud Security: Herausforderung in der Finanzbranche

In der dynamischen Welt der Finanzbranche ist die Nutzung von Cloud-Services ein unverzichtbarer Bestandteil für...
Überwachung eingesetzter Dienstleister in der Finanzbranche
08. Apr 2024

Überwachung eingesetzter Dienstleister in der Finanzbranche

Der zunehmende Einsatz von Dienstleistern in der Wertschöpfungskette und in Unterstützungsprozessen führt zu einer...