Industry

Financial Services

Everything here is examined, and the examination assumes somebody senior owns the answer.

Financial services organizations operate under continuous examination rather than periodic certification. Regulators, auditors and partner institutions all expect a named owner, a documented program, and evidence that the board is engaged with technology risk rather than briefed about it.

The technology position is usually the harder half: a core platform that cannot be taken down, integrations accumulated over decades, and a modernization program that has to run without dropping a transaction.

The pressure

What this sector is actually under

Examination expects an owner

Examiners and auditors ask who is accountable, what the program says, and what evidence supports it. An organization where technology risk is everybody’s concern and nobody’s role struggles with the first question.

Board-level technology risk

Boards are expected to be engaged with technology and security risk, which means somebody has to present it in terms a board can act on rather than a status report nobody challenges.

Migrations with no maintenance window

Core platform and digital channel migrations where the acceptable amount of member or customer disruption is approximately none, and the rollback plan is as important as the plan.

Third and fourth party risk

Core processors, digital channel vendors and their subprocessors. Oversight obligations extend past your direct suppliers, and the evidence has to come from somewhere other than their marketing.

Legacy systems with compliance debt

Platforms that predate current requirements and cannot simply be replaced. What matters is a defensible sequence, not a declaration that everything will be modern eventually.

Data, analytics and where it went

Analytics programs move sensitive data into new systems quickly. The governance question follows later, and it follows harder in this sector than in most.

Where to start

Which side of the practice you need

If the pressure is an examination, an audit finding or vendor oversight, that is the fractional CISO side.

If it is a migration, a platform decision or a roadmap the board does not trust, that is the CTO side.

The two pillars

Where this usually starts

Common questions

Questions I get asked first

Can you present to our board?

Yes, and it is part of the role rather than an add-on. The job is translating technology and security posture into the decisions and the money a board needs to act on, in language that survives contact with people who are not engineers.

We are mid-migration and it has stalled. Is that this?

Usually yes. Stalled migrations are rarely stalled for technical reasons alone, and the useful first step is an honest read of what is actually blocking it rather than a new plan layered on the old one.

Do you do PCI DSS?

I have built PCI DSS-compliant systems and can work to it as a requirement set. I am not a QSA and I do not perform assessments, so the certification itself belongs with an assessor.

Related reading

Written on this

Start with a conversation

Tell me what’s going on. I will tell you which of these it actually is, and whether you need me for it.

Bring your FDA letter, pen test report, audit deadline, or architecture problem. You'll talk to me, not a sales rep.

Not ready for a call? Send a message instead.

For companies looking to engage BATO. Vendors, please email.