Industries · Banking, insurance and payments

Financial services cybersecurity: built to be shown, not described

In financial services the hard part is no longer being secure. It is proving it on the day somebody asks, for your own systems and for the suppliers plugged into them. QS-WAN produces that evidence while you work, and keeps supplier access to one path you can switch off.

Three requests that arrive without warning
01
Show who can reach this system
02
Show what your supplier can reach
03
Show that support session, later

Each one is a screen in the console rather than a week of collecting.

The constraint

Demonstration is the deliverable

Regulated finance has always had controls. What changed with DORA is the burden of showing them: operational resilience has to be evidenced, tested and reported, and the obligation follows the third parties you depend on rather than stopping at your own perimeter.

That turns an internal question into an external one. It is not enough for access to be correct. Somebody outside your organisation has to be able to see that it is correct, at a moment you do not choose, without your team spending a fortnight assembling screenshots.

And there is a quieter control that auditors in finance ask about more than most: who is allowed to watch a colleague’s screen. Remote support is the tool that gets used at the worst moment, on the machine with the most sensitive thing open on it.

If you cannot show it in an afternoon, in practice you cannot show it.
Where the effort actually goes
01

Suppliers are in scope

Payment processors, core banking vendors and analytics providers all hold a connection. Each one is a third party you have to describe, monitor and be able to cut off.

02

Evidence ages badly

A screenshot proves what a screen showed once. The question is whether the control held for the whole period, which is an argument about records rather than configuration.

03

Confidentiality outlives the transaction

Contracts, positions and client files stay sensitive for years. Traffic captured today can be stored and opened later, which makes key establishment a long horizon decision.

How QS-WAN makes it showable

Access as a drawing, support as a record

QS-WAN runs a private network from one console, and QNova Client puts it on the device. For a regulated firm, three parts carry most of the weight.

01

Every path is an edge you can point at

A permitted connection between two segments is an edge in the Network Map: on, off, one way or zero trust. That is the same picture you show an examiner and the one your team works from, so the diagram cannot drift away from the configuration.

02

A supplier holds one certificate, not a password

Each device carries a certificate per gateway membership. A third party gets exactly one, scoped to one segment, and ending the relationship is a revocation in the console rather than a request that somebody change a shared credential.

03

Remote support that leaves a trail

Remote support is part of the same signed agent, under the same company policy, so who may start a session is a policy decision rather than a habit. We describe it as a capability in integration rather than a finished product, because that is what it is today.

Underneath, the same everywhere

Post-quantum by default

Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design, with the cryptographic inventory documented by subsystem.

Runs where you decide

License QS-WAN onto your own infrastructure, take a gateway we ship configured, or let us host it. Firms that keep everything inside the boundary keep the console there too.

What you can show

Four questions, four screens

Examiners, clients running due diligence and your own second line ask the same things. Here is where each answer already lives.

Q1

Who can reach this system, today?

User profiles, their devices and one certificate per gateway membership, exportable as CSV for the file.

Q2

What can each supplier reach?

The edges in the Network Map for that gateway, each one way, two way, disabled or zero trust, plus the firewall rules set per gateway and per user.

Q3

Is the control tested or only written?

Assessments return pass, fail, partially satisfied or not tested, with a risk score built from 19 indicators. More on being ready for the audit.

Q4

What happened on that device?

The detection history is kept and paginated by the service, counted by category, rather than summarised into a single number that hides the shape.

A caveat worth putting in the report. A green confirmation means the intention was recorded. A gateway or device that was offline applies it on reconnect, so check they are online before calling a control effective.

Where it stops

What this does not claim

Financial services buyers are told a lot of things. These are the limits, stated before you ask.

It does not make you compliant

The platform produces evidence that helps you answer DORA and similar questions. Whether it is sufficient is decided by your regulator and your auditor, not by us.

It is not a SOC

Nobody at QuantumNova monitors your network or reads your alerts. The console is yours, and so is everything it records.

It does not touch the core

Core banking, payments and trading systems stay where they are. This controls the network around them and the devices that reach them.

Remote support is a capability, not a product

It works, it sits inside the signed agent, and it is still in integration. We would rather say that than let a procurement pack imply otherwise.

Pick the request you dread most

Usually it is the supplier inventory or the access review. Bring that one to a demonstration, which is free, and we will show you where the answer would live.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top