Fintech / Financial services

IT, cyber security and governance for fintech

Prepare your technology and evidence for partner reviews, investment and the requirements that apply to your business.

From AWS access controls and recovery planning to ISO 27001 and SOC 2 readiness. We work with your technical team and compliance advisers on an agreed scope.

Two colleagues discussing a plan together at a glass whiteboard.
Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber Essentials & PlusCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor scheme CISSPHeld by Daniel McClure Fisher

Partner and regulatory reviews

Define the review before building the evidence

A partner questionnaire, certification requirement and regulatory review are different starting points. Confirm what applies and who makes the decision.

ISO 27001 concerns the information security management system and its scope. SOC 2 is an independent attestation of the defined control environment. We support readiness; we do not issue ISO certificates or SOC 2 reports.

For firms within scope of the FCA’s operational resilience rules, technology mapping, recovery planning and testing support the organisation’s work on important business services and impact tolerances.

Other requirements to confirm

PCI DSS where card data is involved. DORA-related requirements from EU partners or applicable regulation. PSD2 and open banking obligations. Your compliance advisers establish applicability; the technical plan records the systems, owners and evidence within scope.

Review outputs

A record your team can maintain

Systems and dependencies

Cloud services, corporate devices, SaaS, critical suppliers and the links to the business services they support.

Controls and owners

Access, protection, monitoring and recovery arrangements, with the person responsible for each action and approval.

Evidence and actions

Dated review and test records, outstanding risks, agreed remediation and a way to keep the evidence current.

Services

Technical work alongside your team

Secure

Corporate identity, endpoints and SaaS

Review employee and contractor access, administrative permissions and device coverage. Existing EDR and SIEM tools are considered alongside the people responsible for investigating and acting on alerts.

Prove

ISO 27001 and SOC 2 preparation

Review the ISMS scope, applicable Annex A controls, responsibilities and existing evidence. Agree a readiness plan and the route to the independent certification or attestation organisation.

Build

Governed automation and AI

Assess a defined workflow before adding automation or AI. Agree data use, access, human review, logging and acceptance criteria with your business and compliance owners.

Our appointments and certification An appointed certification body for Cyber Essentials and Cyber Essentials Plus. Assured under the NCSC Cyber Advisor scheme. ISO 27001 certified by a UKAS-accredited certification body.

Working arrangements

Scope, access and ongoing responsibility

Our UK-based team works from Reading, Berkshire, in the Thames Valley. Engagements can be a review, a remediation project or continuing support.

Agree which cloud accounts, corporate systems and third parties are included. Where Okta, Auth0 or Cognito is used, review the relationship between product identity and the corporate identity provider.

Document hosting and backup locations, privileged access and subcontracted services. UK-hosted options can be considered for the systems we manage, with actual processing and support arrangements reviewed.

Technology controls support your compliance work. Your organisation and advisers retain regulatory decisions, risk acceptance and formal submissions. Product development, managed support and independent assessment have separate responsibilities.

Questions

Before you start

A partner bank is asking for ISO 27001. Can you help?

We can review your scope and current controls, then plan the ISMS, evidence and internal review work needed for readiness. Formal certification is performed by an appropriately appointed independent certification body. DSC holds its own ISO 27001 certification via a UKAS-accredited body.

We already have an EDR and a SIEM. What should we review?

Review coverage, configuration and responsibility. Confirm which devices, identities and services send the expected data, who investigates alerts, and which response actions are authorised. A tool being installed does not by itself establish the operating process.

Can you audit our AWS environment?

We can scope a technical review of the agreed AWS accounts and services, including IAM, KMS, S3, logging and recovery. We work with your DevOps team on findings and remediation. Production changes need agreed approval and testing.

Do you handle SOC 2 as well as ISO 27001?

We support the preparation and operation of relevant controls and evidence. The frameworks can share some work, but their scope and assessment requirements differ. A separate audit firm performs the SOC 2 attestation; ISO certification is also independently assessed.

How does this fit FCA operational resilience?

For firms within scope, we support technology dependency mapping, recovery planning, testing and supplier evidence. The organisation sets its important business services, impact tolerances and regulatory approach with its compliance advisers. Our engagement defines the technical work and reporting we own.

Next step

Start with the review you need to complete

Tell us who is asking, which systems are involved and when the review is due. We can scope a gap review, remediation project or ongoing support.

0118 359 2220 · Reading, Berkshire