Skip to main content
Anthrasec

Customers and regulators expect your important business services to stay available, whatever happens. We build, secure and evidence the technology behind them for banks, insurers, wealth managers, payment firms and fintechs.

  • Mapped to important business services
  • Audit-ready evidence
  • AI with governance built in
Office towers at Canary Wharf in London, with a train crossing a bridge over the dock

803 hrs

of unplanned IT outages at nine major UK banks and building societies in two years (Treasury Committee, 2025)

The sector today

Resilience is now a regulatory requirement

Since March 2025, UK firms have had to show they can stay within impact tolerances for their important business services through severe but plausible disruption.

A person reviewing a price chart on a laptop beside a window

Financial services run on trust, and trust depends on technology working. Customers expect to pay, trade and check balances at any hour. The Financial Conduct Authority and Prudential Regulation Authority expect firms to have identified their important business services, set impact tolerances for each, mapped the people, systems and suppliers behind them, and tested that they can recover within tolerance. Firms with business in the European Union face parallel duties under the Digital Operational Resilience Act, which has applied since January 2025. Meeting those expectations is as much an engineering challenge as a compliance one, because many services still depend on ageing core systems and a long chain of third parties.

The threats keep evolving too. Fraudsters use social engineering, account takeover and, increasingly, AI-generated content to deceive customers and staff. Regulators are paying close attention to concentration risk in cloud and other critical third parties, and to how firms govern the AI models they now use for everything from fraud detection to customer service. Anthrasec helps financial services firms design resilient infrastructure, detect and respond to threats, manage third-party and cloud risk, and adopt AI with the documentation, testing and human oversight that model risk and Consumer Duty expectations call for.

AI is already mainstream across financial services

Three in four firms use AI, led by insurers and international banks. A third of AI use cases are bought in from third parties, which makes supplier oversight and explainability essential.

Share of UK financial services firms currently using AI, by sector

Source: Bank of England and FCA, AI in UK financial services 2024

SectorShare
Insurance95%
International banks94%
All firms75%
Market infrastructure57%

Who we help

Support across financial services

Firms of every size answer to the same regulators. We shape our services to your scale and risk.

  • Banks and building societies

    Resilient infrastructure, threat detection and evidence mapped to your important business services.

  • Insurers and brokers

    Secure platforms for policy, claims and broker portals, with third-party risk kept in view.

  • Wealth and asset managers

    Protection for client data and portfolios, and modern, secure working for advisers.

  • Payment and e-money firms

    Always-on payment platforms, PCI DSS support and safeguards against fraud.

  • Fintechs and challengers

    Secure-by-design engineering and the assurance evidence partner banks and investors ask for.

  • Advisers and outsourcers serving finance

    The security standards your regulated clients now require of their suppliers.

The pressures

Six risks financial services leaders ask us about

Each one is manageable with the right controls. Here is what's at stake, and how we respond.

  • Operational resilience

    The risk
    Regulators expect important business services to stay within impact tolerances through severe but plausible disruption.
    Our response
    Service mapping, resilient architecture and scenario testing, with evidence your board can sign off.
  • Third-party and cloud concentration

    The risk
    A single supplier or cloud region failing can take down services across the firm.
    Our response
    Supplier risk assessment, exit and substitution plans, and multi-region design where it matters.
  • Fraud and account takeover

    The risk
    Criminals use stolen credentials and social engineering to take over accounts and trick customers into paying.
    Our response
    Strong authentication, behavioural detection and monitoring across web, mobile and contact-centre channels.
  • Legacy core systems

    The risk
    Ageing platforms are costly to change and a leading cause of outages during upgrades.
    Our response
    Staged modernisation, careful change management and a tested rollback for every release.
  • AI and model risk

    The risk
    Models that can't be explained, tested or monitored create regulatory risk and customer harm.
    Our response
    Model inventories, validation, monitoring and human oversight, aligned to the principles in SS1/23.
  • Regulatory evidence

    The risk
    Audits, regulator requests and due diligence consume specialist time and expose gaps.
    Our response
    Controls documented as they are built, with reporting that maps directly to each framework.

What we deliver

Our services, applied to financial services

One team covers security, cloud, infrastructure, software and AI, so nothing falls between suppliers.

A desk with market charts on a laptop, a monitor, a tablet and a phone

AI in financial services

AI that stands up to regulatory scrutiny

Three in four UK financial firms already use AI. What separates a pilot from a production system is governance: knowing what a model does, how it was tested and who answers for it.

55%

of AI use cases in UK financial services involve some degree of automated decision-making, though only 2% are fully autonomous

Source: Bank of England and FCA, AI in UK financial services 2024

  • Fraud and anomaly detection

    Scoring payments and sign-ins in real time to stop fraud while letting genuine customers through.

    Safeguard: Thresholds are tested for bias and false positives, and people review blocked customers.

  • Onboarding and KYC

    Extracting and checking data from identity and company documents to shorten onboarding.

    Safeguard: Exceptions go to trained staff, and every decision leaves an audit trail.

  • Customer service

    Assistants that help staff find policy and product answers quickly, and summarise long case histories.

    Safeguard: Kept to approved content, with outcomes monitored under the Consumer Duty.

  • Operations and reporting

    Automating reconciliations, reporting packs and control testing.

    Safeguard: Outputs are sampled and checked, and every model is recorded in your inventory.

When it matters most

A critical supplier fails on payday: staying within tolerance

Regulators expect firms to plan for severe but plausible disruption. This is how a prepared firm, supported by our team, works through one.

Illustrative scenario showing how our service is designed to work. Response times are agreed with each client and set out in their service agreement.

  1. 06:40

    Detect

    Monitoring shows payment messages queuing. A third-party gateway has stopped responding.

  2. 06:50

    Assess

    The incident lead confirms that an important business service is affected, and starts the clock against its impact tolerance.

  3. 07:05

    Switch

    Traffic moves to the secondary route designed and tested for this scenario. Payments begin to flow again.

  4. 07:30

    Communicate

    Customers see a clear status message. The board receives a factual update, as does the regulator where reporting thresholds are met.

  5. Same day

    Recover

    The primary route is restored and transactions are reconciled, so no payment is lost or duplicated.

  6. Within a week

    Evidence

    A written review records timings against tolerance, lessons learned and actions, ready for audit.

Regulation and standards

The frameworks financial services are measured by

We help you build the controls and evidence each one asks for. Accountability for compliance stays with your firm and its senior managers.

  • FCA and PRA operational resilience

    What it asks forIdentify important business services, set impact tolerances, map dependencies and test against severe but plausible scenarios.

    How we helpDependency mapping, resilient design, scenario testing and the supporting evidence.

  • Outsourcing and third-party risk (PRA SS2/21)

    What it asks forDue diligence, contractual rights, exit plans and oversight for material outsourcing, including cloud.

    How we helpSupplier assessments, exit and portability planning, and cloud controls.

  • Model risk management (PRA SS1/23)

    What it asks forGovernance, validation and monitoring of models, including AI. Written for banks, and widely used as good practice.

    How we helpModel inventories, documentation, testing and monitoring pipelines.

  • Digital Operational Resilience Act (DORA)

    What it asks forICT risk management, incident reporting, resilience testing and third-party oversight for firms operating in the EU.

    How we helpGap analysis against DORA's requirements and remediation of technical controls.

  • Consumer Duty

    What it asks forGood outcomes for retail customers, including in digital journeys and automated decisions.

    How we helpAccessible, well-tested journeys and monitoring of outcomes from automated systems.

  • PCI DSS v4.0.1

    What it asks forProtection of card data for issuers, acquirers and payment firms.

    How we helpScope reduction, gap analysis and remediation ahead of assessment.

Our approach

Your first 90 days with Anthrasec

A typical first engagement for a financial services firm. You see progress every fortnight, and you own everything we produce.

A team working at laptops in front of a whiteboard covered in sticky notes
  1. Weeks 1–2

    Discover

    We review your important business services, the systems and suppliers behind them, and your current evidence.

    You get: A map of services, dependencies and gaps

  2. Weeks 3–6

    Secure the basics

    Identity, privileged access, patching, backups and monitoring are strengthened where risk is highest.

    You get: Priority gaps closed and monitoring live

  3. Weeks 7–10

    Build and test

    We deliver the first agreed improvement and run a scenario test against an impact tolerance.

    You get: A tested improvement with documented results

  4. Weeks 11–13

    Evidence and plan

    We package the evidence for your board and auditors, and agree a 12-month roadmap with costs.

    You get: A board-ready evidence pack and a costed roadmap

For your team

What each leader gets from working with us

Resilience involves technology, risk and compliance teams together. We make sure each has what it needs.

Common questions

Financial services IT and security, answered

Can you help us meet FCA and PRA operational resilience requirements?

Yes. We help you map the systems and suppliers behind each important business service, design them to recover within tolerance, run scenario tests and document the results. Accountability for compliance stays with your firm's senior managers.

Do you support DORA compliance?

Yes. For firms operating in the EU, we assess your ICT risk management, incident reporting, testing and third-party oversight against DORA's requirements, and help close the technical gaps.

How do you handle regulated and confidential data?

We agree data handling terms before work begins, keep access to the minimum needed, work inside your environment wherever possible and record what we do, so you have an audit trail.

Can we use AI in a regulated firm?

Yes, with governance in place. We help you keep an inventory of models, document how each one works and was tested, monitor it in production and keep people accountable for important decisions, in line with regulators' expectations on model risk and the Consumer Duty.

Do you work with smaller firms and fintechs?

Yes. Smaller firms face the same regulators and the same due diligence from partner banks and investors. We offer proportionate support, from secure-by-design engineering to ISO 27001 and SOC 2 readiness.

Can you work alongside our internal IT team and existing suppliers?

Yes. Most firms have both. We agree clear responsibilities, share documentation and report in a way that fits your existing governance.

More sectors

Explore our other sectors

Compare all sectors

Work with us

Ready to work with Anthrasec?

Let's schedule a meeting.

Pick a time that suits you and tell us a little about what you need. We'll come prepared, with the right people in the room.

Step 1 of 4

Choose a date and time

October 2026

Checking availability…

Times are shown in UK time (London). Meetings are held on Microsoft Teams.

Available times

Choose a date to see available times.