Login to profile

CREST Financial Services Hub

Financial Services Cyber Resilience

Guidance, standards and quality assurance that meet the highest demands of the critical infrastructure that underpin the global economy.

CREST whiteout logo

CREST and the Financial Services Sector

The Financial Services sector is one of the most critical infrastructure elements of national economies and global markets. As a highly regulated sector with significant societal impacts, it has invested earlier and more heavily in cyber resilience than many others.

 

CREST has specialised in supporting this sector for over a decade, co-developing standards with supervisors, accrediting service providers and setting the toughest individual certifications to prove skill and competence.

 

As we move rapidly into the era of frontier technologies, CREST is once again leaning in to support the continued evolution of best practice and standards that are uniquely impacting financial services.

The FS Cyber Resilience Eco-system Model

CREST has defined a financial sector ecosystem model consisting of three specific domains that contribute to cyber resilience. Identifying them, assessing them and maturing them in unison is paramount.

 

The weaknesses that adversaries exploit can often be found within the gaps between these domains, from the structures within single institutions through to differences in international regulations. The ecosystem approach seeks to narrow these gaps through a holistic view, common frameworks and a collective commitment to the highest standards.

 

 

Infographic illustrating the relationship between national cyber authorities, financial institutions, financial supervisors and cyber service providers in creating a resilient financial system. A banner across the top represents the national cyber authority and wider national resilience context. Three dashed lines connect the banner to the main diagram. On the left, a light-blue box labelled “Financial Institutions” states that they own risk and protect important business services, and must withstand and recover safely. On the right, a dark-blue box labelled “Financial Supervisors” states that they set proportionate expectations, supervise institutions and understand collective risk. At the centre is a circle labelled “Resilient Financial System”, connected by arrows to both groups. Beneath it, a green/teal box labelled “Cyber Service Providers” states that they provide specialist advice, independent assurance, testing and response capability. Arrows show the two-way relationships between the resilient financial system and the three stakeholder groups. A caption along the bottom reads, “Distinct accountabilities, shared evidence and coordinated improvement.”

Financial Institutions

Must build and maintain strong resilience within their organisations and across the critical business services on which customers and markets rely.

External consultancy and regulatory oversight do not transfer this responsibility.

 

 

 

 

See Buying Cyber Services below for how CREST supports Financial Institutions.

Financial Supervisors

Must establish proportionate expectations, supervise individual institutions and understand resilience collectively across the sector.

The model groups them for simplicity while recognising the need for clear roles and cooperation.

 

 

 

 

See Supervising the Financial Sector below for how CREST supports supervisors.

Cyber Service Providers

Must supply high-quality specialist advice, assessment, threat intelligence, testing and response capability, supported by demonstrable organisational quality and competent practitioners.

Given the kind of high-risk work these organisations perform, the strength and depth of this community is core to market resilience.

 

See Service Provider Support and Accreditations for how we help current and future members.

Buying Cyber Services

CREST supports those accountable for bringing in specialist cyber service providers by sharing purchasing guidance, implementation guides and more.

Supervising the Financial Sector

CREST has been working with leading financial services supervisors for over a decade, co-developing standards, delivering assurance frameworks and providing an engagement point for the cyber service provider community.

 

A number of national and regional supervisors have adopted CREST’s standards, rely on CREST accreditations and demand CREST qualified professionals for high risk engagements.

 

Supervisors looking to develop cyber resilience frameworks incorporating service provider and individual professional standards can contact CREST for support.

Service Provider Support and Accreditation

Individual Professional Recognition

Events, Resources and Useful Links

Support

Need support navigating cyber resilience in financial services? Whether you’re a financial services organisation, supervisor, regulator, cyber service provider or cybersecurity professional, CREST can help.