CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Industries/Financial services

Sector pack

Financial services

The most heavily supervised sector in every market we operate in, and the one where operational resilience has moved from a continuity exercise to a supervisory expectation with impact tolerances attached.

SECTOR PACK ADDS
Regulation, loss scenarios, indicators and control emphasis
SCENARIOS IN THIS PACK
6 quantifiable loss scenarios
BUILT ON
The same control library and the same five pillars

What makes this sector different

The platform does not change. The regulation, the scenarios and the emphasis do.

  • Two regulators, minimum. A national cyber authority and a central bank, each with its own control set, maturity model and examination cycle.
  • Resilience is now supervised. Important business services, impact tolerances and severe but plausible testing are examined, not merely documented.
  • Outsourcing and cloud are gated. Notification, approval and exit requirements apply before a migration, not after it.
  • Concentration is the new question. Supervisors ask how much of the sector depends on the same handful of providers, and expect firms to know their own position.
  • Payment rails carry their own regime. Card standards and messaging network security requirements sit on top of everything else.

Regulation and standards in scope

Indicative, and additional to the market pack for the jurisdictions you operate in. Applicability is confirmed per client during scoping.

  • SAMA Cyber Security Framework
  • SAMA BCM Framework
  • CBUAE information security requirements
  • Qatar Central Bank technology risk circulars
  • Central Bank of Oman requirements
  • CBB Rulebook operational risk and cyber modules
  • Central Bank of Kuwait framework
  • FCA PS21/3 and PRA SS1/21
  • UK critical third parties regime
  • PCI DSS 4.0
  • SWIFT Customer Security Programme
  • NCA ECC-2:2024
  • ISO 22301

Market packs by jurisdiction

Loss scenarios in the sector pack

Each arrives with FAIR parameters and calibration guidance, so it can be quantified in USD rather than described.

Core banking platform outage

Availability loss on the service customers judge you by, with an impact tolerance breach and supervisory notification following within hours.

Ransomware with data exfiltration

Dual exposure: operational disruption and a notifiable personal data breach under two or three privacy regimes at once.

Third-party processor failure

A payment or core provider fails and substitutability turns out to be theoretical. Concentration risk realised.

Payment fraud at scale

Authorised and unauthorised fraud losses modelled as loss magnitude rather than described as a control gap.

Insider data exfiltration

Privileged access misuse in a business with high-value customer data and a low tolerance for it becoming public.

Cloud region loss

A migration that concentrated several important business services into one region, tested for the first time by an outage.

How quantification works

Where the emphasis falls

Impact tolerances and dependency mapping in Withstand; concentration and third-party analysis in Anticipate; maturity tracking and examination workspaces in Comply; and combined assurance across internal audit, second line and external assurance in Assure.

How sector packs sit in the architecture  ·  How it reaches the business

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.