Customers and regulators expect your important business services to stay available, whatever happens. We build, secure and evidence the technology behind them for banks, insurers, wealth managers, payment firms and fintechs.
- Mapped to important business services
- Audit-ready evidence
- AI with governance built in

803 hrs
of unplanned IT outages at nine major UK banks and building societies in two years (Treasury Committee, 2025)
The sector today
Resilience is now a regulatory requirement
Since March 2025, UK firms have had to show they can stay within impact tolerances for their important business services through severe but plausible disruption.

Financial services run on trust, and trust depends on technology working. Customers expect to pay, trade and check balances at any hour. The Financial Conduct Authority and Prudential Regulation Authority expect firms to have identified their important business services, set impact tolerances for each, mapped the people, systems and suppliers behind them, and tested that they can recover within tolerance. Firms with business in the European Union face parallel duties under the Digital Operational Resilience Act, which has applied since January 2025. Meeting those expectations is as much an engineering challenge as a compliance one, because many services still depend on ageing core systems and a long chain of third parties.
The threats keep evolving too. Fraudsters use social engineering, account takeover and, increasingly, AI-generated content to deceive customers and staff. Regulators are paying close attention to concentration risk in cloud and other critical third parties, and to how firms govern the AI models they now use for everything from fraud detection to customer service. Anthrasec helps financial services firms design resilient infrastructure, detect and respond to threats, manage third-party and cloud risk, and adopt AI with the documentation, testing and human oversight that model risk and Consumer Duty expectations call for.
£1.28bn
stolen through payment fraud in the UK in 2025, while banks prevented a further £1.68bn of unauthorised fraud
£576.4m
lost to authorised push payment fraud in 2025, a rise of 19% on the year before
46%
of financial firms say they have only a partial understanding of the AI technologies they use
Source: Bank of England and FCA, AI in UK financial services 2024
53%
of finance and insurance businesses have a formal cyber incident response plan: the highest of any sector, yet barely half
AI is already mainstream across financial services
Three in four firms use AI, led by insurers and international banks. A third of AI use cases are bought in from third parties, which makes supplier oversight and explainability essential.
Source: Bank of England and FCA, AI in UK financial services 2024
| Sector | Share |
|---|---|
| Insurance | 95% |
| International banks | 94% |
| All firms | 75% |
| Market infrastructure | 57% |
Who we help
Support across financial services
Firms of every size answer to the same regulators. We shape our services to your scale and risk.
Banks and building societies
Resilient infrastructure, threat detection and evidence mapped to your important business services.
Insurers and brokers
Secure platforms for policy, claims and broker portals, with third-party risk kept in view.
Wealth and asset managers
Protection for client data and portfolios, and modern, secure working for advisers.
Payment and e-money firms
Always-on payment platforms, PCI DSS support and safeguards against fraud.
Fintechs and challengers
Secure-by-design engineering and the assurance evidence partner banks and investors ask for.
Advisers and outsourcers serving finance
The security standards your regulated clients now require of their suppliers.
The pressures
Six risks financial services leaders ask us about
Each one is manageable with the right controls. Here is what's at stake, and how we respond.
Operational resilience
- The risk
- Regulators expect important business services to stay within impact tolerances through severe but plausible disruption.
- Our response
- Service mapping, resilient architecture and scenario testing, with evidence your board can sign off.
Third-party and cloud concentration
- The risk
- A single supplier or cloud region failing can take down services across the firm.
- Our response
- Supplier risk assessment, exit and substitution plans, and multi-region design where it matters.
Fraud and account takeover
- The risk
- Criminals use stolen credentials and social engineering to take over accounts and trick customers into paying.
- Our response
- Strong authentication, behavioural detection and monitoring across web, mobile and contact-centre channels.
Legacy core systems
- The risk
- Ageing platforms are costly to change and a leading cause of outages during upgrades.
- Our response
- Staged modernisation, careful change management and a tested rollback for every release.
AI and model risk
- The risk
- Models that can't be explained, tested or monitored create regulatory risk and customer harm.
- Our response
- Model inventories, validation, monitoring and human oversight, aligned to the principles in SS1/23.
Regulatory evidence
- The risk
- Audits, regulator requests and due diligence consume specialist time and expose gaps.
- Our response
- Controls documented as they are built, with reporting that maps directly to each framework.
What we deliver
Our services, applied to financial services
One team covers security, cloud, infrastructure, software and AI, so nothing falls between suppliers.

01
Managed Cybersecurity
Detection, testing and evidence for regulated firms.
- 24/7 threat monitoring and response
- Penetration testing of applications and infrastructure
- Third-party and supply chain risk reviews
- Reporting for boards, auditors and regulators
02
Cloud Platforms
Well-governed cloud with a clear way out.
- Landing zones with policy enforced as code
- Multi-region resilience and tested failover
- Exit and portability planning
- Encryption and key management
03
Enterprise Infrastructure
Hardened platforms behind your important business services.
- Mapping of systems to important business services
- High-availability network and data centre design
- Immutable backups and recovery testing
- Change management and release control
04
Application Development
Secure software for customers and staff.
- Customer portals and mobile apps
- API and Open Banking integrations
- Secure development with code review and testing
- Legacy application modernisation
05
Modern Workplace
Secure, compliant working for regulated teams.
- Microsoft 365 with data loss prevention
- Managed, encrypted devices
- Retention and information protection policies
- Conditional access and privileged identity controls
06
AI & Automation
AI you can explain to a regulator.
- Fraud and anomaly detection
- Document processing for onboarding and KYC
- Assistants for customer service and operations
- Model documentation, testing and monitoring
AI in financial services
AI that stands up to regulatory scrutiny
Three in four UK financial firms already use AI. What separates a pilot from a production system is governance: knowing what a model does, how it was tested and who answers for it.
55%
of AI use cases in UK financial services involve some degree of automated decision-making, though only 2% are fully autonomous
Source: Bank of England and FCA, AI in UK financial services 2024
Fraud and anomaly detection
Scoring payments and sign-ins in real time to stop fraud while letting genuine customers through.
Safeguard: Thresholds are tested for bias and false positives, and people review blocked customers.
Onboarding and KYC
Extracting and checking data from identity and company documents to shorten onboarding.
Safeguard: Exceptions go to trained staff, and every decision leaves an audit trail.
Customer service
Assistants that help staff find policy and product answers quickly, and summarise long case histories.
Safeguard: Kept to approved content, with outcomes monitored under the Consumer Duty.
Operations and reporting
Automating reconciliations, reporting packs and control testing.
Safeguard: Outputs are sampled and checked, and every model is recorded in your inventory.
When it matters most
A critical supplier fails on payday: staying within tolerance
Regulators expect firms to plan for severe but plausible disruption. This is how a prepared firm, supported by our team, works through one.
Illustrative scenario showing how our service is designed to work. Response times are agreed with each client and set out in their service agreement.
06:40
Detect
Monitoring shows payment messages queuing. A third-party gateway has stopped responding.
06:50
Assess
The incident lead confirms that an important business service is affected, and starts the clock against its impact tolerance.
07:05
Switch
Traffic moves to the secondary route designed and tested for this scenario. Payments begin to flow again.
07:30
Communicate
Customers see a clear status message. The board receives a factual update, as does the regulator where reporting thresholds are met.
Same day
Recover
The primary route is restored and transactions are reconciled, so no payment is lost or duplicated.
Within a week
Evidence
A written review records timings against tolerance, lessons learned and actions, ready for audit.
Regulation and standards
The frameworks financial services are measured by
We help you build the controls and evidence each one asks for. Accountability for compliance stays with your firm and its senior managers.
FCA and PRA operational resilience
What it asks forIdentify important business services, set impact tolerances, map dependencies and test against severe but plausible scenarios.
How we helpDependency mapping, resilient design, scenario testing and the supporting evidence.
Outsourcing and third-party risk (PRA SS2/21)
What it asks forDue diligence, contractual rights, exit plans and oversight for material outsourcing, including cloud.
How we helpSupplier assessments, exit and portability planning, and cloud controls.
Model risk management (PRA SS1/23)
What it asks forGovernance, validation and monitoring of models, including AI. Written for banks, and widely used as good practice.
How we helpModel inventories, documentation, testing and monitoring pipelines.
Digital Operational Resilience Act (DORA)
What it asks forICT risk management, incident reporting, resilience testing and third-party oversight for firms operating in the EU.
How we helpGap analysis against DORA's requirements and remediation of technical controls.
Consumer Duty
What it asks forGood outcomes for retail customers, including in digital journeys and automated decisions.
How we helpAccessible, well-tested journeys and monitoring of outcomes from automated systems.
PCI DSS v4.0.1
What it asks forProtection of card data for issuers, acquirers and payment firms.
How we helpScope reduction, gap analysis and remediation ahead of assessment.
Our approach
Your first 90 days with Anthrasec
A typical first engagement for a financial services firm. You see progress every fortnight, and you own everything we produce.

Weeks 1–2
Discover
We review your important business services, the systems and suppliers behind them, and your current evidence.
You get: A map of services, dependencies and gaps
Weeks 3–6
Secure the basics
Identity, privileged access, patching, backups and monitoring are strengthened where risk is highest.
You get: Priority gaps closed and monitoring live
Weeks 7–10
Build and test
We deliver the first agreed improvement and run a scenario test against an impact tolerance.
You get: A tested improvement with documented results
Weeks 11–13
Evidence and plan
We package the evidence for your board and auditors, and agree a 12-month roadmap with costs.
You get: A board-ready evidence pack and a costed roadmap
For your team
What each leader gets from working with us
Resilience involves technology, risk and compliance teams together. We make sure each has what it needs.
Chief information and technology officers
Resilient platforms, controlled change and one partner accountable across infrastructure, cloud and software.
Chief information security officers
Continuous detection and response, tested plans and reporting your board can rely on.
Operational resilience and risk leads
Dependency maps, scenario test results and evidence aligned to regulatory expectations.
Compliance and audit teams
Controls documented as they are built, with clear ownership and traceability.
Common questions
Financial services IT and security, answered
Can you help us meet FCA and PRA operational resilience requirements?
Yes. We help you map the systems and suppliers behind each important business service, design them to recover within tolerance, run scenario tests and document the results. Accountability for compliance stays with your firm's senior managers.
Do you support DORA compliance?
Yes. For firms operating in the EU, we assess your ICT risk management, incident reporting, testing and third-party oversight against DORA's requirements, and help close the technical gaps.
How do you handle regulated and confidential data?
We agree data handling terms before work begins, keep access to the minimum needed, work inside your environment wherever possible and record what we do, so you have an audit trail.
Can we use AI in a regulated firm?
Yes, with governance in place. We help you keep an inventory of models, document how each one works and was tested, monitor it in production and keep people accountable for important decisions, in line with regulators' expectations on model risk and the Consumer Duty.
Do you work with smaller firms and fintechs?
Yes. Smaller firms face the same regulators and the same due diligence from partner banks and investors. We offer proportionate support, from secure-by-design engineering to ISO 27001 and SOC 2 readiness.
Can you work alongside our internal IT team and existing suppliers?
Yes. Most firms have both. We agree clear responsibilities, share documentation and report in a way that fits your existing governance.
More sectors
Explore our other sectors
Work with us
Ready to work with Anthrasec?
Let's schedule a meeting.
Pick a time that suits you and tell us a little about what you need. We'll come prepared, with the right people in the room.
Step 1 of 4
Choose a date and time
October 2026
Checking availability…
Times are shown in UK time (London). Meetings are held on Microsoft Teams.
Available times
Choose a date to see available times.



