Markets We Serve
Markets
Financial
Healthcare
Education
Energy
Retail
Technology
 

NetSPI Financial Practice

Financial organizations are targets for fraud, intrusion, and information abuse. NetSPI has the experience and insight needed to establish and maintain enterprise security for financial organizations. We deliver proactive and responsive security services, reducing risk and increasing revenue while helping you meet compliance requirements such as GLBA, FFIEC, FTC, and PCI.

NetSPI Services to Financial Institutions

Application Security Assessment/Secure Code Review

  • Minimizing risk within applications through multi-layer testing:
    vulnerability, penetration, and code-level review.
  • Database and data warehouse security assessments.

Third-Party Risk Analysis

  • Assessing protection of confidential data in relationships with third-party service providers, partners, and data programs.
  • Evaluating third-party risk by reviewing programs, services, and technologies.

Process/Social Engineering Testing

  • Conducting mock email and web based phishing exercises to determine your organization's ability to detect and respond to an attack.
  • Phone-based social engineering and onsite premise penetration testing to identify weaknesses within your authorization and access processes.
  • Reviewing business processes and finance-related practices to identify potential exposure of confidential information.

Risk-Based Enterprise Security Assessment

  • Classifying assets based on criticality and process or storage of sensitive information.
  • Assessing organizational risk through program, compliance and technical review.
  • Evaluating program effectiveness, identifying gaps, and developing plans to reduce organizational risk related to information systems.
  • Incorporating infrastructure review and testing such as network architecture, firewall, IDS review and multi-layer penetration testing.

PCI Consulting and Audit

  • PCI pre– and post–audit consulting.
  • PCI PA-DSS auditing.
  • External (ASV) & internal vulnerability scanning, penetration testing, code review, and firewall rule-set reviews.
  • PCI audit data/report consolidation.