Financial services & insurance
Protect the payment rails without slowing them down
Banks, insurers, payment processors and market infrastructure operators run the two hardest security problems at once: an adversary who is funded and patient, and a regulator who wants the evidence in writing. Guardian Sentinel converges fraud and threat telemetry into one decision engine that contains intrusions in seconds and produces the audit trail as a by-product.
- PCI DSS 4.0
- DORA
- SOX ITGC
- NYDFS Part 500
- GLBA Safeguards
- SWIFT CSP
Regulatory pressure
Six frameworks, one control set, zero screenshot archaeology
Financial institutions do not fail audits because controls are missing. They fail because nobody can prove the control was operating on the third Tuesday of last quarter. Guardian evaluates every control continuously and stamps each detection, response action and configuration change with the framework references it satisfies.
| Framework | Requirement | Guardian control | Evidence generated |
|---|---|---|---|
| PCI DSS 4.0 | Req. 1.3, 5.2, 10.7, 11.5 — CDE segmentation, malware defence, failure detection and change monitoring | Micro-segmentation with continuous CDE boundary verification; behavioural malware prevention; file integrity monitoring on in-scope systems | Quarterly segmentation validation report, control-failure alerting with timestamped remediation |
| DORA | Art. 9–11, 17, 24 — ICT protection, detection, response, incident classification and resilience testing | Cross-surface detection with automatic severity classification against DORA criteria; threat-led penetration testing support | Pre-filled major-incident notification within the 4-hour initial window; TLPT artefacts |
| SOX (ITGC) | Change management, logical access and privileged activity over financial reporting systems | Identity analytics on SAP, Oracle Financials and core banking; unauthorised change detection on in-scope hosts | Immutable privileged-session record and quarterly access-review attestation export |
| NYDFS Part 500 | §500.02, 500.06, 500.14, 500.17 — programme, audit trail, monitoring and 72-hour notification | Continuous monitoring with 7-year immutable retention; automated superintendent notification drafting | CISO annual certification pack with control-by-control operating evidence |
| GLBA Safeguards Rule | §314.4(c) — access controls, encryption, monitoring and multi-factor authentication | Customer-data discovery and classification, continuous MFA posture assessment, egress monitoring | Written risk assessment inputs and qualified-individual reporting extract |
| SWIFT CSP | Controls 1.1–2.11, 6.4 — secure zone isolation, integrity and logging | Dedicated policy for the SWIFT secure zone with operator-terminal behavioural baselining | Annual attestation evidence bundle keyed to CSCF control identifiers |
Scroll the table sideways to see every column.
Guardian maintains framework mappings as regulation changes. PCI DSS 4.0 future-dated requirements and the DORA regulatory technical standards are already implemented in the shipping control set.
Evidence, not screenshots
Every control produces signed, machine-readable evidence with chain of custody. Exports in PDF, CSV and OSCAL for GRC ingestion.
Retention that outlives the auditor
Seven-year immutable retention as standard for regulated estates, with WORM storage and legal-hold support.
Residency by jurisdiction
Fourteen sovereign regions with routing enforced at ingest, so EU telemetry never transits a non-EU region.
Fraud and threat convergence
Your fraud team and your SOC are chasing the same attacker
An account takeover is a fraud event to one team and an identity compromise to the other. Because the two toolchains never share state, the attacker gets a second attempt from a different angle. Guardian resolves fraud signals and security telemetry to the same entity — the person, the device, the session — and acts once, on the whole picture.
What converged detection catches that siloed tools miss
- Authorised-push-payment fraud with a compromised endpoint upstream. The payment looks legitimate because the customer really did approve it — after a remote-access tool was installed forty minutes earlier.
- Session hijack that never triggers a login alert. A stolen session token produces no authentication event; only the behavioural mismatch between session and device reveals it.
- Insider beneficiary manipulation. A privileged operator changing standing settlement instructions outside their normal pattern, on a host with newly disabled logging.
- Mule-network onboarding at scale. Hundreds of new accounts sharing device fingerprints, automation signatures and identical KYC document templates.
How the two teams share one workflow
Guardian does not ask you to merge your fraud and security functions. It gives each team its own view of the same underlying entity, with the handover made explicit.
| Signal origin | Owns the decision | Automatic hand-off |
|---|---|---|
| Payment anomaly only | Fraud operations | None required |
| Endpoint or identity only | Security operations | None required |
| Both, same entity | Joint case, single timeline | Yes — under 1 s |
| Both, same device fleet | Security leads, fraud advises | Yes — campaign view |
Case state, evidence and comments synchronise bidirectionally with ServiceNow, Jira and Archer through the Guardian integration layer.
Real-time transaction protection
Inline decisions inside the authorisation budget
Card authorisation is a hard real-time problem. If a security control cannot return a verdict in single-digit milliseconds, it will be deployed in monitor-only mode and it will never stop anything. Guardian's inline decision path is engineered to the same budget as your fraud engine.
-
Signal arrives before the transaction does
The endpoint sensor, identity connector and network sensor stream state changes continuously, so by the time an authorisation request appears the entity already carries a current risk score. No synchronous lookup, no cold start.
-
The decision is a lookup, not a computation
Risk is precomputed and held in an in-memory graph replicated to every processing region. The inline call resolves an entity key and returns a verdict with a reason code — a p50 of 3.4 ms and a p99 under 6 ms.
-
Response is proportionate, not binary
Verdicts range from allow-and-log through step-up authentication to pre-settlement hold and full identity containment. Thresholds are yours, versioned, and testable against replayed production traffic before they go live.
-
Fail-open is a deliberate, audited choice
If Guardian cannot answer inside your configured budget, the transaction proceeds and the event is flagged for asynchronous review. Availability of the payment rail is never subordinated to a security control.
Zero authorisation timeouts attributable to Guardian across 14.2 billion inline decisions in the last twelve months, including four Black Friday peaks and two exchange volatility events.
Throughput at institutional scale
Where the inline path is deployed
Guardian integrates at the authorisation switch, the online banking session layer, the payment initiation API and the SWIFT operator terminal — wherever a decision must be made before value moves.
See supported integrationsCoverage
Every part of the institution has a different failure mode
A trading desk cannot tolerate a 200 ms agent pause. A branch network cannot tolerate an analyst on site. Core banking cannot tolerate an unplanned reboot. Guardian ships a distinct operating profile for each.
Trading, markets and low-latency infrastructure
The sensor runs in a latency-pinned profile with CPU affinity, deferred scanning and no synchronous file-system interception on market-data paths. Measured jitter contribution on a co-located matching engine is under 40 microseconds at p99.
Detection focuses on unauthorised algorithm deployment, configuration drift on FIX gateways, and privileged access to strategy repositories. Response is alert-and-isolate-network rather than process termination, so a running algorithm is never killed mid-order without a human decision.
Core banking, payments and settlement
Mainframe-adjacent Linux and AIX systems, payment hubs, and SWIFT secure zones run in a change-controlled profile: no automatic remediation, full behavioural detection, and every proposed action queued for approval inside your existing change process.
Guardian baselines the batch calendar, so a settlement job that runs at an unusual hour or transfers an unusual volume is surfaced as an anomaly rather than lost in expected noise.
Branch, ATM and self-service estates
Thousands of low-bandwidth, physically exposed endpoints with no local IT presence. The sensor operates fully offline for up to 30 days, enforces USB and peripheral policy at the kernel level, and detects jackpotting and cash-dispenser manipulation through process and device-tree behaviour rather than signatures.
Bandwidth ceiling is configurable per site; the default profile consumes under 6 MB per endpoint per day.
Cloud, digital banking and customer-facing APIs
Full CNAPP coverage across AWS, Azure and Google Cloud: posture management, IaC scanning, container runtime protection and Kubernetes admission control. Findings are ranked by exploitability against your actual network reachability, not by theoretical CVSS.
API abuse detection covers credential stuffing, enumeration and business-logic abuse against open banking and PSD2 endpoints, with rate decisions returned inline. See cloud security.
Third parties, outsourcers and the DORA register
Every third-party identity is scoped to an access envelope derived from its contracted purpose. Deviation is contained automatically and reported to the relationship owner and to your ICT third-party register.
Guardian generates the DORA Article 28 register extract — provider, function supported, criticality, substitutability and concentration exposure — from observed access rather than from a spreadsheet somebody updated last year.
Insurance, wealth and advisory platforms
Claims platforms, policy administration and adviser portals hold dense personal and health data with comparatively light monitoring. Guardian's data classification engine locates and tags this material automatically, then monitors bulk access patterns from adviser and broker accounts.
Common catch: an intermediary exporting a full book of business in the fortnight before moving firms. See data protection.
Customer proof
Northbank Financial Group
A universal bank with 31,000 endpoints, 12,400 staff and operations in eleven countries, running under DORA, PCI DSS and three national supervisory regimes simultaneously.
The problem
Six overlapping security products, four consoles and a fraud platform that shared nothing with the SOC. Mean time to contain sat at six hours. The DORA four-hour initial notification window was, in the group CISO's words, "arithmetically impossible" with the existing toolchain.
What changed
Guardian Sentinel deployed in detect-only mode across all eleven countries in nineteen weeks, running in parallel with the incumbent EDR and NDR products. Fraud telemetry was joined to the entity graph in week eight. Autonomous containment was enabled tier by tier from week fourteen.
Where it stands
Five products decommissioned. Mean time to contain at eleven minutes. The most recent supervisory examination closed with no findings against the ICT risk management chapter — the evidence pack was produced in two days rather than the six weeks budgeted.
The number that convinced our board was not the licence saving. It was that we found two live intrusions during the parallel run — one of them eleven months old — while our incumbent tools sat green. You cannot un-see that.
Sector benchmarks
What financial services customers report at month twelve
Medians across 214 banking, insurance and payments deployments, measured against each institution's own pre-deployment baseline.
Want these numbers modelled on your estate? Guardian's value engineering team builds a sector-specific business case using your endpoint counts, incident history and current licence stack. Request a business case review or see how pricing works.
Keep reading
Related platform capabilities and services
Identity protection
Session-level analytics that stop account takeover before the second authenticated action.
Data protection
Find, classify and monitor cardholder and customer data wherever it has been copied.
Compliance advisory
DORA readiness, PCI DSS 4.0 gap assessment and threat-led penetration testing.
Incident response
Retainer-backed containment with regulator notification support in every major jurisdiction.
Retail & e-commerce
The acquiring side of the same problem: PCI scope, checkout integrity and POS fleets.
All solutions
Browse every industry, use case and organisation size Guardian supports.
Bring your hardest control objective to the demo
DORA Article 17 timelines, a PCI DSS 4.0 gap, a fraud typology you cannot catch, or a consolidation business case that has to survive procurement. We will show you the console doing it, on data that looks like yours.