CREST Financial Services Hub
Financial Services Cyber Resilience
Guidance, standards and quality assurance that meet the highest demands of the critical infrastructure that underpin the global economy.
CREST and the Financial Services Sector
The Financial Services sector is one of the most critical infrastructure elements of national economies and global markets. As a highly regulated sector with significant societal impacts, it has invested earlier and more heavily in cyber resilience than many others.
CREST has specialised in supporting this sector for over a decade, co-developing standards with supervisors, accrediting service providers and setting the toughest individual certifications to prove skill and competence.
As we move rapidly into the era of frontier technologies, CREST is once again leaning in to support the continued evolution of best practice and standards that are uniquely impacting financial services.
The FS Cyber Resilience Eco-system Model
CREST has defined a financial sector ecosystem model consisting of three specific domains that contribute to cyber resilience. Identifying them, assessing them and maturing them in unison is paramount.
The weaknesses that adversaries exploit can often be found within the gaps between these domains, from the structures within single institutions through to differences in international regulations. The ecosystem approach seeks to narrow these gaps through a holistic view, common frameworks and a collective commitment to the highest standards.

Financial Institutions
Must build and maintain strong resilience within their organisations and across the critical business services on which customers and markets rely.
External consultancy and regulatory oversight do not transfer this responsibility.
Financial Supervisors
Must establish proportionate expectations, supervise individual institutions and understand resilience collectively across the sector.
The model groups them for simplicity while recognising the need for clear roles and cooperation.
Cyber Service Providers
Must supply high-quality specialist advice, assessment, threat intelligence, testing and response capability, supported by demonstrable organisational quality and competent practitioners.
Given the kind of high-risk work these organisations perform, the strength and depth of this community is core to market resilience.
Buying Cyber Services
CREST supports those accountable for bringing in specialist cyber service providers by sharing purchasing guidance, implementation guides and more.
Accreditations to ask for (and you may consider aligning to them for your own internal teams):
Supervising the Financial Sector
CREST has been working with leading financial services supervisors for over a decade, co-developing standards, delivering assurance frameworks and providing an engagement point for the cyber service provider community.
A number of national and regional supervisors have adopted CREST’s standards, rely on CREST accreditations and demand CREST qualified professionals for high risk engagements.
Supervisors looking to develop cyber resilience frameworks incorporating service provider and individual professional standards can contact CREST for support.
Supervisor Frameworks
Other Sector Specific Resources
Service Provider Support and Accreditation
Individual Professional Recognition
Events, Resources and Useful Links
Recent and Upcoming Events
Support
Need support navigating cyber resilience in financial services? Whether you’re a financial services organisation, supervisor, regulator, cyber service provider or cybersecurity professional, CREST can help.
