An examiner or audit finding
The most common trigger, and the one with a date attached. Start with the finding, map it to the control that failed, and fix the control rather than the finding.
Banks, credit unions and financial firms are the most-examined organizations there are, and privileged access to core banking, payments and trading systems is the prize. The hard part is rarely the policy. It is that the systems holding the money are often decades old, and the access controls examiners want were designed for systems built this century.
Not a clever exploit. A credential that was valid, privileged and unwatched.
Earlier in 2025, an IT employee at C&M Software — a firm that connects Brazilian financial institutions to the central bank's PIX payment system — sold his login credentials for roughly $2,700. On 30 June 2025, attackers used them to run fraudulent transfers across six financial institutions. Public reporting puts the loss at around $100 million, with some estimates higher. There was no software vulnerability. There was a vendor credential with more reach than anyone had checked, and nobody watching it at the hour it was used.
That is the shape of most financial-sector incidents: not a clever exploit, but a credential that was valid, privileged and unwatched. It is also why the four things that matter in this sector are the four things below.
Free brief. No cost, no obligation.
SOX Section 404 requires proof that only the right people can reach financial reporting systems, and that the controls around them operate. This is what releases budget, and saying so plainly is more useful than listing five frameworks. The CEO and CFO sign personally and carry personal liability for it. The audit committee oversees. The CISO runs the program day to day. An external auditor verifies annually.
Three things follow for identity specifically. Separation of duties has to be provable, not asserted — the person who can create a vendor cannot be the person who can pay one. Access reviews have to complete, with evidence that a manager actually looked rather than clicked approve. And privileged sessions on financial reporting systems have to be recorded, because "who changed this and when" is the first question an examiner asks.
Alongside SOX: PCI-DSS where cards are handled, GLBA and its Safeguards Rule, NYDFS 23 NYCRR 500 for institutions doing business in New York, and FFIEC examiner expectations. Institutions with European or cross-border exposure add DORA and SWIFT CSP. The overlap is large, and most of the identity work is shared. Where an examiner finding is the trigger, that starts with a compliance readiness assessment; where the underlying problem is a governance one, it becomes an IGA implementation.
Only the right people can reach financial reporting systems, and the controls around them operate.
Core banking platforms including FIS, Fiserv, Jack Henry and Temenos. Payment and cardholder systems. Trading and capital markets platforms. Financial reporting and ERP on Oracle and SAP. Mainframe and legacy environments including RACF. Directories and cloud. Platform names are trademarks of their respective owners.
The most common trigger, and the one with a date attached. Start with the finding, map it to the control that failed, and fix the control rather than the finding.
Reviews that come back empty, late or rubber-stamped are a governance problem, and the answer is usually automation rather than more reminders. See IGA implementation.
Vendor credentials brought under control first, through brokered sessions rather than VPN and shared passwords. See PAM implementation and CyberArk implementation.
Where the finding involves cardholder systems, PCI penetration testing is usually required alongside the access work. And because the initial compromise is so often a phishing email to someone in finance, email security sits closer to this sector than most.
Controls drift the moment a project ends — new accounts, new vendors, missed reviews.
Banking group. Privileged access was being approved against change requests that had already expired: an audit finding waiting to happen and a control that looked fine on paper. Our engineers built a custom integration validating every request against its change ticket automatically. 20,000 requests a day are now checked, and approval time fell from 15–20 minutes to under five. How the change-validation integration works
By making the controls produce the evidence themselves. Session recordings, completed access reviews and separation-of-duties reports come out of the platform on demand, rather than being reconstructed from spreadsheets the week before the exam. Where a framework deadline is the driver, a compliance readiness assessment maps every gap to the clause it fails.
Yes, and it is usually the reason we are called. Privileged sessions to legacy systems are brokered and recorded even where the system itself cannot integrate, and credentials are vaulted and rotated through connectors built for the platform in question. This is the part most rollouts stall on, and it is the part we plan first.
Brokered sessions with recording, credentials the vendor never sees, expiry set at grant rather than discovered at audit, and offboarding that actually runs. The Brazil case happened because a vendor credential had standing reach and nobody was watching. Neither of those has to be true.
Who has privileged access to financial reporting systems, who approved it, when it was last reviewed, and what they did with it. Four questions, and every one of them is answerable from a properly deployed platform in minutes.
It can, but it gets more expensive. Every acquisition adds a directory and a set of orphaned accounts. Bringing privileged access under control before the integration means the new estate is onboarded into a working model rather than adding to an ungoverned one.

Most CyberArk PAM comparisons are written by vendors selling against it. Here is what actually differs, from a team that deploys these platforms.
Aug 25, 2026
PAM secures the accounts with the most system power. Here's what privileged access management does and why attackers go after these credentials first.
Jul 28, 2026
Owning PAM and IGA is not the same as knowing your identity risk. What identity security posture management actually measures.
Jul 27, 2026A free audit is a 30-minute review of your privileged accounts by a certified engineer, with the findings in writing. The Finance blind spot brief covers three recent financial-sector breaches and the access gap behind each.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.