Financial services & insurance

Protect the payment rails without slowing them down

Banks, insurers, payment processors and market infrastructure operators run the two hardest security problems at once: an adversary who is funded and patient, and a regulator who wants the evidence in writing. Guardian Sentinel converges fraud and threat telemetry into one decision engine that contains intrusions in seconds and produces the audit trail as a by-product.

  • PCI DSS 4.0
  • DORA
  • SOX ITGC
  • NYDFS Part 500
  • GLBA Safeguards
  • SWIFT CSP
$6.08M Average cost of a breach in financial services 28% above the cross-industry mean
72h DORA major-incident reporting deadline Initial notification within 4 hours
3.2× More credential-based intrusion attempts than any other sector Guardian Labs, 2026 landscape data
41 min Median adversary breakout time Down from 62 minutes in 2024

Regulatory pressure

Six frameworks, one control set, zero screenshot archaeology

Financial institutions do not fail audits because controls are missing. They fail because nobody can prove the control was operating on the third Tuesday of last quarter. Guardian evaluates every control continuously and stamps each detection, response action and configuration change with the framework references it satisfies.

Regulatory requirement mapped to the Guardian Sentinel control that satisfies it and the evidence it produces.
Framework Requirement Guardian control Evidence generated
PCI DSS 4.0 Req. 1.3, 5.2, 10.7, 11.5 — CDE segmentation, malware defence, failure detection and change monitoring Micro-segmentation with continuous CDE boundary verification; behavioural malware prevention; file integrity monitoring on in-scope systems Quarterly segmentation validation report, control-failure alerting with timestamped remediation
DORA Art. 9–11, 17, 24 — ICT protection, detection, response, incident classification and resilience testing Cross-surface detection with automatic severity classification against DORA criteria; threat-led penetration testing support Pre-filled major-incident notification within the 4-hour initial window; TLPT artefacts
SOX (ITGC) Change management, logical access and privileged activity over financial reporting systems Identity analytics on SAP, Oracle Financials and core banking; unauthorised change detection on in-scope hosts Immutable privileged-session record and quarterly access-review attestation export
NYDFS Part 500 §500.02, 500.06, 500.14, 500.17 — programme, audit trail, monitoring and 72-hour notification Continuous monitoring with 7-year immutable retention; automated superintendent notification drafting CISO annual certification pack with control-by-control operating evidence
GLBA Safeguards Rule §314.4(c) — access controls, encryption, monitoring and multi-factor authentication Customer-data discovery and classification, continuous MFA posture assessment, egress monitoring Written risk assessment inputs and qualified-individual reporting extract
SWIFT CSP Controls 1.1–2.11, 6.4 — secure zone isolation, integrity and logging Dedicated policy for the SWIFT secure zone with operator-terminal behavioural baselining Annual attestation evidence bundle keyed to CSCF control identifiers

Scroll the table sideways to see every column.

Guardian maintains framework mappings as regulation changes. PCI DSS 4.0 future-dated requirements and the DORA regulatory technical standards are already implemented in the shipping control set.

Evidence, not screenshots

Every control produces signed, machine-readable evidence with chain of custody. Exports in PDF, CSV and OSCAL for GRC ingestion.

Retention that outlives the auditor

Seven-year immutable retention as standard for regulated estates, with WORM storage and legal-hold support.

Residency by jurisdiction

Fourteen sovereign regions with routing enforced at ingest, so EU telemetry never transits a non-EU region.

Fraud and threat convergence

Your fraud team and your SOC are chasing the same attacker

An account takeover is a fraud event to one team and an identity compromise to the other. Because the two toolchains never share state, the attacker gets a second attempt from a different angle. Guardian resolves fraud signals and security telemetry to the same entity — the person, the device, the session — and acts once, on the whole picture.

FRAUD SIGNALS SECURITY TELEMETRY Transaction velocity anomaly Device and IP reputation Beneficiary change pattern Session token anomaly Endpoint process behaviour Privilege and directory change UNIFIED ENTITY RISK GRAPH One customer. One session. Allow, log, learn Step-up auth Block transaction Contain identity No customer friction Risk-scored challenge Pre-settlement hold Sessions revoked, host isolated Median decision latency across the graph: 3.4 ms
Fraud and security signals resolve to one entity, producing a single proportionate decision.

What converged detection catches that siloed tools miss

  • Authorised-push-payment fraud with a compromised endpoint upstream. The payment looks legitimate because the customer really did approve it — after a remote-access tool was installed forty minutes earlier.
  • Session hijack that never triggers a login alert. A stolen session token produces no authentication event; only the behavioural mismatch between session and device reveals it.
  • Insider beneficiary manipulation. A privileged operator changing standing settlement instructions outside their normal pattern, on a host with newly disabled logging.
  • Mule-network onboarding at scale. Hundreds of new accounts sharing device fingerprints, automation signatures and identical KYC document templates.

How the two teams share one workflow

Guardian does not ask you to merge your fraud and security functions. It gives each team its own view of the same underlying entity, with the handover made explicit.

Signal origin Owns the decision Automatic hand-off
Payment anomaly only Fraud operations None required
Endpoint or identity only Security operations None required
Both, same entity Joint case, single timeline Yes — under 1 s
Both, same device fleet Security leads, fraud advises Yes — campaign view

Case state, evidence and comments synchronise bidirectionally with ServiceNow, Jira and Archer through the Guardian integration layer.

Real-time transaction protection

Inline decisions inside the authorisation budget

Card authorisation is a hard real-time problem. If a security control cannot return a verdict in single-digit milliseconds, it will be deployed in monitor-only mode and it will never stop anything. Guardian's inline decision path is engineered to the same budget as your fraud engine.

END-TO-END CARD AUTHORISATION BUDGET — 180 ms Guardian Sentinel — 3.4 ms 1.9% of the budget, p99 under 6 ms 0 ms 45 90 135 180 Existing authorisation path Guardian inline decision Acquirer 22 ms · Fraud scoring 41 ms · Issuer authorisation 96 ms · Terminal response 17.6 ms
Measured on a tier-one acquirer processing 41,000 authorisations per second at peak. Guardian's decision runs concurrently with fraud scoring where the platform supports it.
  1. Signal arrives before the transaction does

    The endpoint sensor, identity connector and network sensor stream state changes continuously, so by the time an authorisation request appears the entity already carries a current risk score. No synchronous lookup, no cold start.

  2. The decision is a lookup, not a computation

    Risk is precomputed and held in an in-memory graph replicated to every processing region. The inline call resolves an entity key and returns a verdict with a reason code — a p50 of 3.4 ms and a p99 under 6 ms.

  3. Response is proportionate, not binary

    Verdicts range from allow-and-log through step-up authentication to pre-settlement hold and full identity containment. Thresholds are yours, versioned, and testable against replayed production traffic before they go live.

  4. Fail-open is a deliberate, audited choice

    If Guardian cannot answer inside your configured budget, the transaction proceeds and the event is flagged for asynchronous review. Availability of the payment rail is never subordinated to a security control.

Zero authorisation timeouts attributable to Guardian across 14.2 billion inline decisions in the last twelve months, including four Black Friday peaks and two exchange volatility events.

Throughput at institutional scale

41k/sPeak inline decisions
3.4 msp50 decision latency
5.9 msp99 decision latency
99.995%Decision-path availability

Where the inline path is deployed

Guardian integrates at the authorisation switch, the online banking session layer, the payment initiation API and the SWIFT operator terminal — wherever a decision must be made before value moves.

See supported integrations

Coverage

Every part of the institution has a different failure mode

A trading desk cannot tolerate a 200 ms agent pause. A branch network cannot tolerate an analyst on site. Core banking cannot tolerate an unplanned reboot. Guardian ships a distinct operating profile for each.

Trading, markets and low-latency infrastructure

The sensor runs in a latency-pinned profile with CPU affinity, deferred scanning and no synchronous file-system interception on market-data paths. Measured jitter contribution on a co-located matching engine is under 40 microseconds at p99.

Detection focuses on unauthorised algorithm deployment, configuration drift on FIX gateways, and privileged access to strategy repositories. Response is alert-and-isolate-network rather than process termination, so a running algorithm is never killed mid-order without a human decision.

Core banking, payments and settlement

Mainframe-adjacent Linux and AIX systems, payment hubs, and SWIFT secure zones run in a change-controlled profile: no automatic remediation, full behavioural detection, and every proposed action queued for approval inside your existing change process.

Guardian baselines the batch calendar, so a settlement job that runs at an unusual hour or transfers an unusual volume is surfaced as an anomaly rather than lost in expected noise.

Branch, ATM and self-service estates

Thousands of low-bandwidth, physically exposed endpoints with no local IT presence. The sensor operates fully offline for up to 30 days, enforces USB and peripheral policy at the kernel level, and detects jackpotting and cash-dispenser manipulation through process and device-tree behaviour rather than signatures.

Bandwidth ceiling is configurable per site; the default profile consumes under 6 MB per endpoint per day.

Cloud, digital banking and customer-facing APIs

Full CNAPP coverage across AWS, Azure and Google Cloud: posture management, IaC scanning, container runtime protection and Kubernetes admission control. Findings are ranked by exploitability against your actual network reachability, not by theoretical CVSS.

API abuse detection covers credential stuffing, enumeration and business-logic abuse against open banking and PSD2 endpoints, with rate decisions returned inline. See cloud security.

Third parties, outsourcers and the DORA register

Every third-party identity is scoped to an access envelope derived from its contracted purpose. Deviation is contained automatically and reported to the relationship owner and to your ICT third-party register.

Guardian generates the DORA Article 28 register extract — provider, function supported, criticality, substitutability and concentration exposure — from observed access rather than from a spreadsheet somebody updated last year.

Insurance, wealth and advisory platforms

Claims platforms, policy administration and adviser portals hold dense personal and health data with comparatively light monitoring. Guardian's data classification engine locates and tags this material automatically, then monitors bulk access patterns from adviser and broker accounts.

Common catch: an intermediary exporting a full book of business in the fortnight before moving firms. See data protection.

Customer proof

Northbank Financial Group

A universal bank with 31,000 endpoints, 12,400 staff and operations in eleven countries, running under DORA, PCI DSS and three national supervisory regimes simultaneously.

The problem

Six overlapping security products, four consoles and a fraud platform that shared nothing with the SOC. Mean time to contain sat at six hours. The DORA four-hour initial notification window was, in the group CISO's words, "arithmetically impossible" with the existing toolchain.

What changed

Guardian Sentinel deployed in detect-only mode across all eleven countries in nineteen weeks, running in parallel with the incumbent EDR and NDR products. Fraud telemetry was joined to the entity graph in week eight. Autonomous containment was enabled tier by tier from week fourteen.

Where it stands

Five products decommissioned. Mean time to contain at eleven minutes. The most recent supervisory examination closed with no findings against the ICT risk management chapter — the evidence pack was produced in two days rather than the six weeks budgeted.

The number that convinced our board was not the licence saving. It was that we found two live intrusions during the parallel run — one of them eleven months old — while our incumbent tools sat green. You cannot un-see that.

Marta Oyelaran
Group CISO, Northbank Financial Group
6h → 11 min Mean time to contain, measured over 12 months 97% reduction against baseline
5 Security products decommissioned EDR, NDR, CSPM, UEBA and a log-forwarding tier
$4.1M Annual run-rate saving on licences and operations Verified by group finance in year two
2 days To produce the supervisory evidence pack Previously a six-week programme
Read the full case study

Sector benchmarks

What financial services customers report at month twelve

Medians across 214 banking, insurance and payments deployments, measured against each institution's own pre-deployment baseline.

-74% Reduction in mean time to contain
-71% Fewer alerts escalated to a human analyst
+4.7× More true-positive account-takeover detections
-63% Lower fraud loss on targeted attack typologies
-38% Reduction in total security tooling spend
100% Of DORA initial notifications filed inside 4 hours
0 Successful ransomware encryption events
19 wks Median full deployment across a multinational estate

Want these numbers modelled on your estate? Guardian's value engineering team builds a sector-specific business case using your endpoint counts, incident history and current licence stack. Request a business case review or see how pricing works.

Bring your hardest control objective to the demo

DORA Article 17 timelines, a PCI DSS 4.0 gap, a fraud typology you cannot catch, or a consolidation business case that has to survive procurement. We will show you the console doing it, on data that looks like yours.