Financial services cybersecurity: built to be shown, not described
In financial services the hard part is no longer being secure. It is proving it on the day somebody asks, for your own systems and for the suppliers plugged into them. QS-WAN produces that evidence while you work, and keeps supplier access to one path you can switch off.
Each one is a screen in the console rather than a week of collecting.
Demonstration is the deliverable
Regulated finance has always had controls. What changed with DORA is the burden of showing them: operational resilience has to be evidenced, tested and reported, and the obligation follows the third parties you depend on rather than stopping at your own perimeter.
That turns an internal question into an external one. It is not enough for access to be correct. Somebody outside your organisation has to be able to see that it is correct, at a moment you do not choose, without your team spending a fortnight assembling screenshots.
And there is a quieter control that auditors in finance ask about more than most: who is allowed to watch a colleague’s screen. Remote support is the tool that gets used at the worst moment, on the machine with the most sensitive thing open on it.
Suppliers are in scope
Payment processors, core banking vendors and analytics providers all hold a connection. Each one is a third party you have to describe, monitor and be able to cut off.
Evidence ages badly
A screenshot proves what a screen showed once. The question is whether the control held for the whole period, which is an argument about records rather than configuration.
Confidentiality outlives the transaction
Contracts, positions and client files stay sensitive for years. Traffic captured today can be stored and opened later, which makes key establishment a long horizon decision.
Access as a drawing, support as a record
QS-WAN runs a private network from one console, and QNova Client puts it on the device. For a regulated firm, three parts carry most of the weight.
Every path is an edge you can point at
A permitted connection between two segments is an edge in the Network Map: on, off, one way or zero trust. That is the same picture you show an examiner and the one your team works from, so the diagram cannot drift away from the configuration.
A supplier holds one certificate, not a password
Each device carries a certificate per gateway membership. A third party gets exactly one, scoped to one segment, and ending the relationship is a revocation in the console rather than a request that somebody change a shared credential.
Remote support that leaves a trail
Remote support is part of the same signed agent, under the same company policy, so who may start a session is a policy decision rather than a habit. We describe it as a capability in integration rather than a finished product, because that is what it is today.
Post-quantum by default
Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design, with the cryptographic inventory documented by subsystem.
Runs where you decide
License QS-WAN onto your own infrastructure, take a gateway we ship configured, or let us host it. Firms that keep everything inside the boundary keep the console there too.
Four questions, four screens
Examiners, clients running due diligence and your own second line ask the same things. Here is where each answer already lives.
Who can reach this system, today?
User profiles, their devices and one certificate per gateway membership, exportable as CSV for the file.
What can each supplier reach?
The edges in the Network Map for that gateway, each one way, two way, disabled or zero trust, plus the firewall rules set per gateway and per user.
Is the control tested or only written?
Assessments return pass, fail, partially satisfied or not tested, with a risk score built from 19 indicators. More on being ready for the audit.
What happened on that device?
The detection history is kept and paginated by the service, counted by category, rather than summarised into a single number that hides the shape.
A caveat worth putting in the report. A green confirmation means the intention was recorded. A gateway or device that was offline applies it on reconnect, so check they are online before calling a control effective.
What this does not claim
Financial services buyers are told a lot of things. These are the limits, stated before you ask.
It does not make you compliant
The platform produces evidence that helps you answer DORA and similar questions. Whether it is sufficient is decided by your regulator and your auditor, not by us.
It is not a SOC
Nobody at QuantumNova monitors your network or reads your alerts. The console is yours, and so is everything it records.
It does not touch the core
Core banking, payments and trading systems stay where they are. This controls the network around them and the devices that reach them.
Remote support is a capability, not a product
It works, it sits inside the signed agent, and it is still in integration. We would rather say that than let a procurement pack imply otherwise.
Pick the request you dread most
Usually it is the supplier inventory or the access review. Bring that one to a demonstration, which is free, and we will show you where the answer would live.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.