The financial sector has relied on digitalization for many years to work more efficiently and enhance collaboration. Increasingly, systems are being migrated to the cloud. While some less regulated actors are still at the beginning of this journey, one thing remains crucial for all: protecting sensitive personal and financial data is the top priority. Without robust IT system protection, serious consequences such as operational interruptions, data leaks, extortion, or severe reputational damage can occur.
The specialized Finance Consultant Team at Redguard AG combines industry and security expertise to deliver efficient and effective added value for companies in the financial and insurance sector. We understand the current challenges of the industry and support our clients in achieving their goals safely. In addition to extensive and diverse practical experience, we hold various certifications such as SWIFT, CISA, CISM, and CRISC.
Thanks to our industry specialists, we understand the challenges of the financial sector and know how to provide pragmatic and holistic support.
If you want to strengthen your security organization but currently lack sufficient management capacity, one of our experienced experts can serve as an (Chief) Information Security Officer on a mandate basis. They can act as an interim solution until you find your own CISO, support your current CISO as a sparring partner, or take over specific projects. On request, the CISO can also draw on additional Redguard resources to provide targeted project support.
Redguard supports you in the gap analysis for individual status determination, prioritization of identified areas for action, development of a comprehensive implementation plan, execution of a Threat-Led Penetration Test, as well as methodical and substantive support in the various areas for effective measure implementation and personnel support for efficient action planning. See blog post “Digital Operational Resilience Act (DORA)”.
Redguard conducts an assessment with you based on the current NIST standard. Alternatively, we also offer an assessment based on the ICT minimum standard.
Redguard supports you in identifying and assessing critical service providers and involved subcontractors, creating risk-based control points for the entire service chain, performing periodic monitoring audits of the service chain, and establishing effective monitoring and management reporting. See blog post “Monitoring of Service Providers in the Financial Sector”.
As part of the SWIFT Customer Security Programme (CSP), annual independent assessments must be carried out to confirm compliance with the Customer Security Controls Framework (CSCF). We support you in conducting an independent external assessment and, thanks to our extensive experience and certified auditors, can attest to CSCF compliance. The focus of the assessment is on the mandatory controls, which must be implemented without exception.
Redguard supports you in the gap analysis for individual status determination, including prioritization of identified areas for action and comprehensive implementation planning; in identifying critical functions and outsourcing; in monitoring outsourced functions and risks; in identifying risks for critical data and defining adequate protection measures; in defining roles, processes, procedures, and controls in handling critical data; in building management reporting; in strengthening employee awareness; in conducting internal audits; in developing and testing crisis management (BCM) and IT Service Continuity Management (ITSCM) plans; and in carrying out attack simulations or targeted penetration tests. See our blog post on FINMA Circular 2023/1.
Redguard assists you in stakeholder alignment, risk identification, design and management of key controls, coordination of periodic audits, and follow-up on audit results. See blog post “Financial Industry: Challenge IT General Controls”.
Redguard supports you as a security SPOC for cloud transformation projects – Modern Workplace – in defining and implementing security measures in the Azure / M365 context, for example with Microsoft Defender or Purview; in conducting cloud security assessments to identify risks in your current cloud setup; in defining and introducing cloud security governance; and in creating security concepts (e.g., classification, data loss prevention, etc.). See blog post “Cloud Security: Challenges in the Financial Industry”.
Based on experience from over a thousand penetration tests, Redguard supports you in deciding which systems should or must be tested. Together, we define an appropriate quarterly scope and plan the penetration tests with internal specialists and responsible parties. The results are documented in a detailed report generated efficiently using our in-house reporting engine. For long-term clients, we develop export interfaces to client systems (xls, Jira, etc.). See Success Story PostFinance.
Banks, insurance companies, payment service providers, and many other financial institutions develop their own software. To make this as secure as possible and apply “Security by Design” principles, we provide on-site training with hands-on exercises. In addition, we offer a wide range of security e-learnings for everyone involved in developing and maintaining web applications – developers, software architects, project managers, Scrum Masters, DevOps engineers, and administrators. We also help you optimize your container and Kubernetes security through training or by reviewing your current systems. Furthermore, we support you in the DevSecOps area – from setting up DevSecOps, reviewing existing setups, expanding your CI/CD pipeline, to conducting an OWASP SAMM assessment.
With our comprehensive industry experience, we advise financial service providers of all kinds: