Cybersecurity Solutions features explained
for IT and Infrastructure
Every feature we track for Cybersecurity Solutions products, with a description of what each one means.
Access Control
Features that enforce restrictions on access to banking systems, data, and infrastructure, ensuring only authorized users and devices can interact with sensitive assets.
- API Key Management
- Secures and controls access to APIs.
- Access Logging
- Records all access attempts for audit trails.
- Device Whitelisting
- Restricts access to approved devices only.
- Geolocation-based Access Restrictions
- Limits access based on user's physical or network location.
- Granular Permission Levels
- Supports fine-grained permissions per function.
- Multi-factor Authentication
- Requires multiple forms of verification before granting access.
- Number of Supported Authentication Methods
- The total number of different authentication methods available (e.g., biometric, SMS OTP, hardware key, etc.).
- Privileged Account Management
- Controls and monitors elevated permissions.
- Role-Based Access Control
- Grants permissions based on user roles and responsibilities.
- Single Sign-On (SSO)
- Allows users to authenticate once for multiple applications.
- User Session Timeout
- Automatically terminates inactive sessions.
Application Security
Mechanisms to secure web, mobile, and desktop banking applications from vulnerabilities and attacks.
- API Security Controls
- Protects and monitors API endpoints.
- Automated Patch Deployment
- Deploys application security patches automatically.
- Code Obfuscation
- Makes application source code harder to reverse-engineer.
- Dynamic Application Security Testing (DAST) Integration
- Integrates tools for runtime security testing of applications.
- Number of Supported Programming Languages
- The range of programming frameworks or languages natively supported for secure app development.
- Regular Penetration Testing
- Conducts simulated attacks to find weaknesses.
- Secure Coding Standards Enforcement
- Ensures adherence to secure development practices.
- Session Management Security
- Protects active user sessions against hijacking.
- Vulnerability Scanning
- Regularly scans for known security weaknesses.
- Web Application Firewall (WAF)
- Protects web applications from common exploits.
Data Protection
Measures to safeguard sensitive banking data at rest, in transit, and in use, ensuring confidentiality and integrity.
- Audit Logging
- Maintains comprehensive logs of data access and changes.
- Automated Key Rotation
- Automatically rotates cryptographic keys at defined intervals.
- Data Backup Frequency
- Frequency at which backups of critical data are performed.
- Data Loss Prevention (DLP)
- Prevents unauthorized data transfer or loss.
- Data Masking
- Obfuscates sensitive data in non-production environments.
- Database Encryption
- Encrypts stored data in databases.
- End-to-End Encryption
- Encrypts data during all states and transfers.
- File Integrity Monitoring
- Detects unauthorized changes to critical files.
- Retention Policy Management
- Controls how long data is kept and when it is deleted.
- Tokenization
- Replaces sensitive information with random tokens.
Endpoint Security
Measures for securing user devices (workstations, laptops, mobile devices, ATMs) that connect to the banking system.
- Anti-malware Protection
- Prevents malicious software from infecting endpoints.
- Application Whitelisting/Blacklisting
- Controls which applications can be installed or run.
- Device Control
- Restricts usage of external devices like USB drives.
- Endpoint Detection and Response (EDR)
- Monitors endpoints for threats and suspicious activity.
- Endpoint Isolation
- Allows quick quarantine of compromised devices.
- Endpoint Policy Enforcement
- Automatically enforces security policies on all endpoints.
- Mobile Device Management (MDM)
- Secures and manages mobile endpoints.
- Number of Devices Supported
- Maximum number of endpoints protected by the solution.
- Patch Management
- Automates the distribution of security updates.
- Remote Wipe Capability
- Erases data from lost or stolen devices remotely.
Fraud Detection and Prevention
Features aimed at detecting and preventing unauthorized or fraudulent banking activities.
- Behavioral Analytics
- Analyzes user behavior for anomalies indicative of fraud.
- Case Management
- Tracks fraud investigation from detection to closure.
- Detection Speed
- Average time taken to detect suspicious activities.
- Device Fingerprinting
- Identifies repeat or suspicious devices.
- False Positive Rate
- Percentage of transactions erroneously flagged as fraud.
- Geolocation Verification
- Checks if transactions originate from expected regions.
- Integration with Core Banking Systems
- Supports real-time integration with existing banking infrastructure.
- Machine Learning Models
- Uses AI models to identify emerging fraud techniques.
- Rule-based Alerts
- Generates alerts based on pre-set fraud rules.
- Transaction Monitoring
- Monitors transactions in real time for suspicious patterns.
Identity and Access Management (IAM)
Solutions that centralize the management of user identities, authorizations, and credentials.
- Access Certification
- Regularly reviews and certifies user privileges.
- Centralized User Directory
- Maintains a single source of truth for user authentication.
- Credential Encryption
- Ensures user credentials are encrypted at rest and in transit.
- Federated Identity Support
- Allows use of external identity providers (SAML, OAuth, etc.).
- Group Management
- Supports management of user groups and access policies.
- Identity Federation Integrations
- Number of external identity federations supported.
- Password Policy Enforcement
- Automatically applies strong password requirements.
- Self-service Password Reset
- Allows users to reset passwords without admin assistance.
- User Access Review Automation
- Automates periodic reviews of user access rights.
- User Provisioning and Deprovisioning
- Automates onboarding and offboarding staff access.
Monitoring and Reporting
Features that provide visibility into system health, security events, and compliance through dashboards and reports.
- Alert Threshold Customization
- Enables setting of specific alert thresholds.
- Audit Log Integration
- Centralizes logs from various sources.
- Automated Reporting Frequency
- How often reports are automatically generated.
- Custom Alert Channels
- Supports multiple channels for alerting (email, SMS, app).
- Customizable Reports
- Allows users to define and schedule security and compliance reports.
- Historical Data Retention
- Keeps historical security data for analysis.
- Real-time Dashboards
- Visualizes live security and system data.
- Report Retention Period
- Length of time reports are stored and accessible.
- Third-party Log Integration
- Integrates with external log and monitoring providers.
- User Activity Monitoring
- Tracks user activities for policy violations.
Network Security
Tools and mechanisms to protect internal and external banking network communications from unauthorized access and cyber threats.
- Bandwidth Monitoring
- Monitors bandwidth utilization for anomalies.
- Deep Packet Inspection
- Examines traffic for threats beyond simple packet headers.
- Distributed Denial of Service (DDoS) Protection
- Detects and mitigates DDoS attacks.
- Encrypted Network Traffic
- Ensures all internal and external communication is encrypted.
- Firewall
- Provides perimeter security by filtering incoming and outgoing network traffic.
- Intrusion Detection System (IDS)
- Monitors and detects malicious network activity.
- Intrusion Prevention System (IPS)
- Blocks and prevents detected threats.
- Network Segmentation
- Divides the network into separate zones for better security.
- Network Traffic Analysis Capability
- The number of simultaneous connections that can be analyzed.
- Virtual Private Network (VPN)
- Secures remote access to banking resources.
Regulatory Compliance
Assists banks in maintaining alignment with legal and regulatory cybersecurity standards such as PCI DSS, GDPR, and FFIEC.
- Audit Trail Management
- Maintains immutable logs for audit purposes.
- Automated Policy Management
- Automates the application and monitoring of compliance policies.
- Compliance Workflow Automation
- Automates workflows to meet compliance requirements.
- Data Residency Controls
- Specifies where data can be stored based on regulations.
- Prebuilt Compliance Reporting
- Offers reports tailored for key banking regulations.
- Regulatory Change Monitoring
- Tracks changes in relevant regulations and standards.
- Regulatory Coverage
- Number of major regulations covered out-of-the-box.
- Retention Policy Automation
- Automatically applies data retention and deletion policies.
- Secure Document Management
- Secure storage and retrieval of compliance documentation.
- Self-assessment Tools
- Allows internal audits for compliance readiness.
Resilience and Recovery
Capabilities that enable continuous banking operations and effective recovery from cyber incidents and system failures.
- Automated System Failover
- Automatically switches to backup systems on failure.
- Automated System Health Checks
- Monitors backup and resilience readiness automatically.
- Backup and Restore Automation
- Automates data and system backup/restore processes.
- Business Continuity Management
- Ensures continued operations during disruptions.
- Disaster Recovery Planning
- Provides tools for planning and testing disaster recovery.
- Ransomware Recovery
- Supports fast recovery from ransomware attacks.
- Recovery Point Objective (RPO)
- Maximum acceptable amount of data loss after an incident.
- Recovery Time Objective (RTO)
- Target time to restore function after disruption.
- Resilience Testing Support
- Enables regular testing of resilience and recovery plans.
- Service Level Agreement (SLA) Monitoring
- Tracks compliance with recovery SLAs.
Threat Detection and Response
Capabilities that identify, analyze, and respond to potential cyber threats across the banking IT ecosystem.
- Automated Compliance Reporting
- Generates regulatory and incident response reports automatically.
- Automatic Threat Remediation
- Responds to detected threats without manual intervention.
- False Positive Rate
- The percentage of security alerts that are determined to be benign.
- Incident Response Playbooks
- Provides pre-defined procedures for common security incidents.
- Real-time Alerting
- Notifies security personnel immediately upon threat detection.
- Security Information and Event Management (SIEM)
- Aggregates, analyzes, and alerts on security events.
- Threat Intelligence Integration
- Ingests external threat intelligence feeds.
- Threat Simulation and Red Team Testing
- Supports simulated attacks for evaluation.
- Time to Detect
- Average time between threat occurrence and detection.
- Time to Respond
- Average time between detection and mitigation.