Sector evidence and live shortlist · UK and North America
SD-WAN & SASE for Financial Services
Legacy WAN architectures cannot support financial services’ demands for ultra-low latency trading, multi-site connectivity and regulatory compliance. However, SD-WAN and SASE solutions provide the answer through application-aware routing, centralised management and integrated security for FCA operational resilience (PS21/3), PCI DSS 4.0.1 and UK GDPR compliance.
Written by Harry Yelland (12 January 2026). Fact-checked by Robert Sturt (14 January 2026).
30 providers28 financial services requirements305 accepted sources of 43630 of 30 reviews completeEvidence last checked 15 Sept 2026
Your buying project
Start a financial services project without re-entering this context
Review the suggested sector requirements in your private project. Use a short brief, a Short or Detailed RFP, or your own RFP or RFI. Your answers carry into the buying workspace; you decide when to publish.
Financial services shortlist tool
Which vendors fit your regulated estate?
Preview aggregate coverage against financial-services requirements. Private provider matching follows verified project publication.
Financial services priorities
Quick-start presets. Each one sets the matching capability requirements below, where you can refine feature by feature.
Operating model
Branches and advisory offices without on-site IT usually need fully managed or co-managed delivery; in-house suits estates with a dedicated network team and 24x7 cover.
Organisation size
Enterprise estates run multiple business lines that need differentiated service levels and separate network domains; mid-market firms without a SOC should weight managed security heavily.
Regions you must cover
Cover every branch, office, data centre and offshore operation you connect, not just head office. Data residency and regulated-entity boundaries follow the regions you select.
Cloud platforms
Core banking, payments and trading platforms increasingly run in public cloud. These grades reflect evidenced on-ramps and gateways into each platform.
AI capability
AIOps shortens fault isolation at branches with no engineer on site; AI security analytics adds detection across the hybrid workforce.
Deployment ceiling
Openings, closures and relocations are dated commitments. This excludes vendors whose typical activation is slower than you need.
Scoring profile
Security led suits PCI DSS and zero trust programmes; network led suits trading and MPLS replacement; managed service led suits lean IT teams.
Resilience and size
DR evidence matters most for trading floors and payment processing; the size setting records your preferred shortlist size after verified publication.
Capability requirements (all 40 graded features)
Click once for required (vendors without evidence are excluded), twice for preferred (a preference for later private matching), three times to clear. Your priorities above pre-select the relevant features.
Or describe your estate to the AI advisor
The advisor maps plain language onto these same filters and explains the result. It can also compare two vendors head to head.
Best SD-WAN and SASE providers for financial services (2026)
Published provider evidence: 1. Cato Networks (32 proven items); 2. Palo Alto Networks Prisma SASE (29 proven items); 3. Cisco (28 proven items); 4. Netskope (27 proven items); 5. HPE Aruba EdgeConnect (26 proven items); 6. Versa Networks (25 proven items); 7. Fortinet FortiSASE (24 proven items); 8. Aryaka (20 proven items); 9. NTT DATA (20 proven items); 10. Zscaler (19 proven items); 11. Check Point (18 proven items); 12. BT (17 proven items); 13. Colt Technology Services (17 proven items); 14. Orange Business (17 proven items); 15. Verizon Business (17 proven items); 16. AT&T Business (16 proven items); 17. Forcepoint (16 proven items); 18. Comcast Business (15 proven items); 19. VeloCloud (15 proven items); 20. Vodafone Business (15 proven items); 21. Cloudflare One (14 proven items); 22. GTT (14 proven items); 23. Juniper Networks (14 proven items); 24. Lumen (14 proven items); 25. Ericsson Cradlepoint (12 proven items); 26. SonicWall Cloud Secure Edge (12 proven items); 27. Barracuda SecureEdge (2 proven items); 28. Expereo (1 proven items); 29. Open Systems (0 proven items); 30. Virgin Media O2 Business (0 proven items). Evidence order, not recommendations. Personalised matching requires authorised access after publication.
Order: proven_evidence_count desc, last_verified desc (missing last), provider name asc, slug asc. Positions are evidence order, not recommendations.
No. 1 · Proven evidence items 32 · Verified 2026-09-01 · Cloud-native SASE / SD-WAN platform · Typical deployment: hours
Single converged platform with no policy or log fragmentation across SD-WAN and security functions.
Watch out: Less suited to best-of-breed buyers wanting Zscaler or Netskope as the SSE layer.
No. 2 · Proven evidence items 29 · Verified 2026-09-01 · SD-WAN / SASE technology vendor · Typical deployment: weeks
Palo Alto Networks Prisma SASE
Prisma SASE converges SD-WAN, cloud-delivered security, and digital experience management (ADEM) under a single platform identity.
Watch out: Premium pricing relative to firewall-led SD-WAN vendors; commercial model requires careful scoping by users, bandwidth, locations and term.
No. 3 · Proven evidence items 28 · Verified 2026-09-01 · SD-WAN / SASE technology vendor · Typical deployment: weeks
Broadest platform portfolio in the category, covering Catalyst SD-WAN for enterprise WAN, Meraki MX for cloud-managed branch, and Cisco Secure Access for converged SASE delivery.
Watch out: Two distinct SD-WAN product lines (Catalyst and Meraki) means buyers should confirm which fits the target deployment profile and the longer-term roadmap.
No. 4 · Proven evidence items 27 · Verified 2026-09-01 · SSE / SASE platform · Typical deployment: days
Strong CASB heritage; widely recognised as a leading SSE vendor for SaaS-heavy environments.
Watch out: Native SD-WAN (Borderless WAN) is newer than dedicated SD-WAN platforms; validate path selection and QoS depth in RFP.
No. 5 · Proven evidence items 26 · Verified 2026-09-01 · SD-WAN / SSE / branch technology vendor · Typical deployment: days
EdgeConnect SD-WAN (acquired with Silver Peak) is positioned as the foundation for single-vendor SASE alongside Aruba SSE.
Watch out: Aruba SSE is newer than the SSE leaders (Zscaler, Netskope); buyers wanting best-of-breed SASE should evaluate the SSE capability set carefully.
No. 6 · Proven evidence items 25 · Verified 2026-09-01 · SD-WAN / SASE technology vendor · Typical deployment: weeks
Multi-tenancy from the ground up, making Versa a common choice for service providers and carriers building managed SD-WAN and SASE platforms.
Watch out: Less well-known to enterprise buyers as a direct purchase; most enterprise consumption is via service providers.
No. 7 · Proven evidence items 24 · Verified 2026-09-01 · Secure SD-WAN / SASE technology vendor · Typical deployment: days
Native convergence of networking and security on a single operating system (FortiOS) across FortiGate edge, FortiManager and FortiSASE.
Watch out: Like Cisco, managed delivery is via partners rather than Fortinet directly; underlay and field operations are not owned by the vendor.
No. 8 · Proven evidence items 20 · Verified 2026-09-01 · Managed SD-WAN / SASE provider · Typical deployment: days
Unified SASE delivered as a managed service from end to end, including the private global core network and WAN optimisation.
Watch out: Smaller PoP footprint and partner ecosystem than the hyperscale SASE vendors; coverage must match your geographic profile.
No. 9 · Proven evidence items 20 · Verified 2026-09-01 · Global managed network provider · Typical deployment: months
24x7 managed SD-WAN delivery via global operations centres with strong portal visibility.
Watch out: Platform fit depends on which vendor is being proposed (Palo Alto, Zscaler, others); evaluate platform independently.
No. 10 · Proven evidence items 19 · Verified 2026-09-01 · SSE / SASE platform · Typical deployment: days
Category leader in SSE with ZIA, ZPA and ZDX; widely adopted as the security layer in best-of-breed SASE architectures.
Watch out: Historically SSE-led; native SD-WAN capability is less mature than dedicated SD-WAN platforms (validate path selection, QoS and packet loss in RFP).
No. 11 · Proven evidence items 18 · Verified 2026-09-01 · SASE / security vendor · Typical deployment: days
Harmony SASE combines Check Point security heritage with cloud-delivered SASE and optimised SD-WAN performance.
Watch out: Native SD-WAN capabilities (path selection, QoS, packet loss remediation) have limited public evidence relative to SD-WAN-led vendors.
No. 12 · Proven evidence items 17 · Verified 2026-09-01 · Global/UK managed SD-WAN / SASE provider · Typical deployment: weeks
UK market leader for managed SD-WAN with deep access circuit ownership and field engineering capability.
Watch out: Platform choice and packaging vary; buyers should confirm which vendor platform is being proposed and why.
No. 13 · Proven evidence items 17 · Verified 2026-09-01 · Enterprise managed SD-WAN / connectivity provider · Typical deployment: months
SD-WAN and SASE with strong European data sovereignty positioning.
Watch out: Global delivery depth outside Europe is less prominent than the largest global carriers.
No. 14 · Proven evidence items 17 · Verified 2026-09-01 · Global managed SD-WAN / SASE provider · Typical deployment: months
Global managed network leadership with strong service assurance, NOC depth and field operations.
Watch out: Platform choice depends on which Orange-supported vendor is selected; underlying platform fit and roadmap should be evaluated independently.
No. 15 · Proven evidence items 17 · Verified 2026-09-01 · Global carrier managed SD-WAN / SASE provider · Typical deployment: months
Global carrier-led managed SASE and SD-WAN with strong North American presence and international delivery.
Watch out: Platform is largely Versa-based; buyers wanting platform optionality should evaluate alternatives.
No. 16 · Proven evidence items 16 · Verified 2026-09-01 · Global carrier managed SD-WAN / SASE provider · Typical deployment: months
Major US carrier-led managed SD-WAN portfolio with multi-vendor platform options (including Fortinet for AT&T SASE).
Watch out: Underlying platform varies by service tier; buyers should confirm which platform supports the proposed scope.
No. 17 · Proven evidence items 16 · Verified 2026-09-01 · Security / secure SD-WAN vendor · Typical deployment: days
FlexEdge Secure SD-WAN combines secure SD-WAN with strong DLP and data security heritage from the wider Forcepoint portfolio.
Watch out: Smaller SD-WAN market presence than the leading platforms.
No. 18 · Proven evidence items 15 · Verified 2026-09-01 · Managed SD-WAN / SASE provider · Typical deployment: weeks
SASE combining SD-WAN and security available fully managed or co-managed, drawing on Masergy AIOps heritage.
Watch out: International delivery depth depends on partnerships outside North America.
No. 19 · Proven evidence items 15 · Verified 2026-09-01 · SD-WAN technology vendor · Typical deployment: days
VeloCloud was an early SD-WAN platform with strong cloud-delivered gateway architecture; now under Arista following the 2025 acquisition.
Watch out: Platform is mid-transition from VMware/Broadcom to Arista; product roadmap, naming and integration story will evolve.
No. 20 · Proven evidence items 15 · Verified 2026-09-01 · Global managed SD-WAN provider · Typical deployment: months
Strong UK and European market presence with NaaS positioning and integrated mobile/fixed access.
Watch out: Underlying platform varies by region (VeloCloud in UK, others elsewhere); ensure consistency for multinational deployment.
No. 21 · Proven evidence items 14 · Verified 2026-09-01 · SASE / Zero Trust / network services · Typical deployment: hours
Cloudflare global edge network provides one of the largest PoP footprints in the category for SASE traffic.
Watch out: SD-WAN capabilities (path selection, QoS, packet loss remediation) have limited public evidence compared to SD-WAN-first vendors.
No. 22 · Proven evidence items 14 · Verified 2026-09-01 · Global managed SD-WAN provider · Typical deployment: months
Tier 1 global backbone provides strong international transit capability alongside managed SD-WAN.
Watch out: SASE depth depends heavily on the chosen platform partner; native SSE capabilities are not primary positioning.
No. 23 · Proven evidence items 14 · Verified 2026-09-01 · AI-driven WAN / SD-branch technology vendor · Typical deployment: days
Mist AI delivers WAN Assurance, providing AI-driven monitoring and troubleshooting at the WAN edge that few competitors match.
Watch out: SASE story is less mature than the SASE-led vendors; SSE capabilities have limited public evidence relative to category leaders.
No. 24 · Proven evidence items 14 · Verified 2026-09-01 · Managed SD-WAN / NaaS provider · Typical deployment: months
Fully managed or co-managed SD-WAN with strong NaaS positioning and integrated network services.
Watch out: SASE and security capabilities are largely partner-integrated rather than native; the SSE platform choice needs explicit evaluation.
No. 25 · Proven evidence items 12 · Verified 2026-09-01 · Wireless WAN / SD-WAN adjacent vendor · Typical deployment: days
Wireless-first branch architecture from Ericsson with deep 5G expertise; NetCloud provides cellular-centric SD-WAN management.
Watch out: SASE story is partner-integrated rather than native; SSE capabilities require validation in RFP.
No. 26 · Proven evidence items 12 · Verified 2026-09-01 · SMB / mid-market firewall-led SD-WAN vendor · Typical deployment: days
SD-WAN delivered via existing TZ, NSa and SM firewall appliances; familiar deployment for organisations standardised on SonicWall.
Watch out: SASE and SSE capabilities have partial public evidence; depth should be confirmed in RFP.
No. 27 · Proven evidence items 2 · Verified 2026-09-01 · technology vendor · Typical deployment: not_confirmed
SecureEdge combines SD-WAN and cloud security, with an MSP option for multi-tenant management.
Watch out:
No. 28 · Proven evidence items 1 · Verified 2026-09-01 · managed service provider / carrier network provider · Typical deployment: not_confirmed
Managed SD-WAN and internet connectivity, with Cato Networks as a named partner for managed SASE.
Watch out:
No. 29 · Proven evidence items 0 · Verified 2026-09-01 · technology vendor / managed service provider · Typical deployment: not_confirmed
Managed SD-WAN and SASE supported by Open Systems' Mission Control service team.
Watch out:
No. 30 · Proven evidence items 0 · Verified 2026-09-01 · managed service provider / carrier network provider · Typical deployment: not_confirmed
Managed connectivity and SD-WAN with Zscaler-based SASE; confirm the current contracting entity and scope.
Watch out:
Full grades, head-to-head tables and the complete field of 30: open the shortlist builder.
Next step
Tell Netify what your financial services network needs and we'll turn that into a defensible procurement decision.
Financial services evidence by provider
Each cell is a research decision with a source behind it, not a score. Hover a cell for the requirement and status; select a provider for the source rows. UK, EU, US and Canadian requirements are separate columns, and a source row records which regime it relates to.
- Proven
- Partial
- Not found
- To review
| Provider | Branch and office connectivity | Trading and low-latency connectivity | Data-centre, colocation and cloud connectivity | Resilience and tested recovery | Network segmentation and zoning | Payment and cardholder data segmentation | Third-party and outsourced access | Remote and hybrid workforce | Data residency and sovereignty | Encryption and key management | Logging, audit and evidence retention | Identity and zero trust access | Cloud and SaaS data controls | Managed operations and SOC | Network visibility and reporting | Change control and configuration governance | Incident notification support | Concentration risk and subcontractor transparency | Exit and portability | UK regulatory alignment (FCA and PRA) | EU DORA alignment | US regulatory alignment (FFIEC, GLBA, NYDFS, SEC) | Canada regulatory alignment (OSFI) | PCI DSS alignment | SWIFT CSP alignment | UK delivery | North America delivery | Global delivery | Sources |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Cloudflare One | Not found | Not found | Proven | Proven | Not found | Not found | Partial | Proven | Proven | Proven | Proven | Proven | Partial | Not found | Not found | Not found | Proven | Partial | Proven | Proven | Proven | Not found | Not found | Proven | Not found | Proven | Proven | Partial | 19 |
| Zscaler | Proven | Not found | Proven | Partial | Proven | Partial | Partial | Proven | Partial | Proven | Partial | Partial | Partial | Not found | Proven | Not found | Not found | Proven | Not found | Not found | Partial | Not found | Not found | Partial | Not found | Proven | Proven | Proven | 14 |
| Netskope | Not found | Not found | Partial | Partial | Partial | Partial | Partial | Partial | Proven | Not found | Partial | Proven | Proven | Partial | Proven | Not found | Not found | Proven | Not found | Not found | Partial | Partial | Not found | Proven | Not found | Proven | Proven | Proven | 15 |
| Barracuda SecureEdge | Not found | Not found | Partial | Partial | Partial | Partial | Not found | Partial | Proven | Proven | Proven | Partial | Not found | Not found | Partial | Proven | Partial | Proven | Proven | Not found | Partial | Not found | Not found | Partial | Not found | Proven | Proven | Proven | 11 |
| Aryaka | Proven | Not found | Partial | Proven | Not found | Not found | Not found | Proven | Partial | Proven | Partial | Partial | Partial | Proven | Proven | Not found | Proven | Partial | Not found | Not found | Not found | Not found | Not found | Partial | Not found | Proven | Proven | Proven | 12 |
| Cato Networks | Proven | Not found | Proven | Partial | Partial | Not found | Partial | Proven | Proven | Partial | Proven | Partial | Proven | Not found | Proven | Not found | Partial | Proven | Not found | Not found | Not found | Not found | Not found | Proven | Not found | Partial | Partial | Partial | 12 |
| Versa Networks | Proven | Not found | Proven | Proven | Proven | Partial | Not found | Partial | Partial | Proven | Partial | Partial | Partial | Not found | Proven | Partial | Partial | Not found | Not found | Not found | Proven | Not found | Not found | Proven | Not found | Not found | Partial | Partial | 15 |
| GTT | Partial | Proven | Partial | Partial | Partial | Partial | Partial | Not found | Partial | Partial | Partial | Partial | Partial | Partial | Partial | Proven | Not found | Partial | Not found | Not found | Partial | Not found | Not found | Proven | Not found | Proven | Partial | Proven | 14 |
| Palo Alto Networks Prisma SASE | Proven | Not found | Partial | Proven | Partial | Not found | Partial | Proven | Proven | Partial | Proven | Proven | Not found | Not found | Proven | Proven | Not found | Partial | Not found | Not found | Partial | Not found | Not found | Not found | Partial | Partial | Partial | Partial | 14 |
| Fortinet FortiSASE | Proven | Not found | Partial | Partial | Partial | Not found | Partial | Proven | Partial | Partial | Not found | Partial | Partial | Proven | Proven | Proven | Not found | Proven | Not found | Partial | Partial | Not found | Not found | Partial | Not found | Not found | Partial | Proven | 9 |
| BT | Proven | Not found | Not found | Partial | Partial | Partial | Not found | Not found | Proven | Partial | Not found | Partial | Partial | Proven | Partial | Proven | Not found | Not found | Not found | Proven | Partial | Not found | Not found | Proven | Not found | Proven | Not found | Proven | 10 |
| AT&T Business | Proven | Partial | Partial | Proven | Proven | Proven | Not found | Partial | Not found | Proven | Partial | Partial | Partial | Proven | Partial | Not found | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Proven | Not found | Not found | Partial | Partial | 9 |
| Cisco | Proven | Not found | Partial | Partial | Proven | Not found | Not found | Partial | Partial | Proven | Not found | Proven | Partial | Not found | Proven | Proven | Not found | Not found | Partial | Not found | Not found | Not found | Not found | Proven | Not found | Not found | Not found | Partial | 12 |
| Colt Technology Services | Proven | Partial | Partial | Partial | Partial | Not found | Not found | Partial | Partial | Partial | Not found | Proven | Not found | Partial | Proven | Not found | Not found | Not found | Not found | Not found | Partial | Not found | Not found | Not found | Partial | Proven | Partial | Proven | 12 |
| Comcast Business | Proven | Not found | Proven | Proven | Partial | Not found | Partial | Not found | Not found | Proven | Not found | Partial | Partial | Partial | Proven | Not found | Partial | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Proven | Proven | 12 |
| Vodafone Business | Proven | Not found | Partial | Partial | Partial | Not found | Partial | Partial | Proven | Partial | Partial | Partial | Partial | Partial | Partial | Not found | Proven | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Proven | Not found | Proven | 9 |
| SonicWall Cloud Secure Edge | Not found | Not found | Not found | Partial | Partial | Partial | Partial | Proven | Not found | Proven | Proven | Proven | Partial | Not found | Partial | Not found | Partial | Partial | Not found | Not found | Not found | Not found | Not found | Partial | Not found | Not found | Proven | Not found | 8 |
| Orange Business | Proven | Not found | Partial | Proven | Proven | Not found | Not found | Partial | Partial | Partial | Not found | Not found | Partial | Proven | Partial | Partial | Not found | Not found | Not found | Not found | Partial | Not found | Not found | Partial | Not found | Not found | Not found | Partial | 10 |
| Verizon Business | Proven | Not found | Not found | Proven | Partial | Not found | Not found | Partial | Not found | Partial | Not found | Partial | Partial | Partial | Partial | Partial | Not found | Not found | Not found | Not found | Partial | Not found | Not found | Partial | Partial | Not found | Partial | Partial | 10 |
| VeloCloud | Proven | Not found | Partial | Partial | Proven | Partial | Not found | Not found | Not found | Proven | Not found | Partial | Partial | Not found | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Proven | Not found | Not found | Proven | Partial | 7 |
| Ericsson Cradlepoint | Partial | Not found | Not found | Partial | Not found | Partial | Not found | Partial | Partial | Proven | Proven | Partial | Not found | Not found | Partial | Partial | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Partial | Not found | Not found | Partial | Partial | 12 |
| Check Point | Partial | Not found | Not found | Partial | Not found | Not found | Partial | Proven | Partial | Not found | Partial | Partial | Partial | Not found | Partial | Partial | Not found | Proven | Not found | Not found | Not found | Not found | Not found | Proven | Not found | Not found | Not found | Partial | 8 |
| Open Systems | Partial | Not found | Not found | Not found | Not found | Not found | Partial | Partial | Not found | Partial | Partial | Partial | Partial | Proven | Partial | Not found | Not found | Proven | Not found | Not found | Partial | Not found | Not found | Not found | Not found | Not found | Partial | Partial | 13 |
| HPE Aruba EdgeConnect | Proven | Not found | Proven | Proven | Partial | Partial | Not found | Not found | Not found | Proven | Not found | Partial | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Partial | Not found | Not found | Proven | Not found | 7 |
| Lumen | Proven | Not found | Proven | Proven | Not found | Not found | Not found | Partial | Not found | Proven | Not found | Partial | Partial | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Partial | Not found | Not found | Proven | Not found | 7 |
| NTT DATA | Proven | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Proven | Proven | Partial | Not found | Partial | Proven | Partial | Not found | Partial | Not found | Not found | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Partial | 7 |
| Virgin Media O2 Business | Not found | Not found | Proven | Partial | Partial | Not found | Not found | Partial | Not found | Partial | Not found | Partial | Partial | Partial | Partial | Not found | Not found | Not found | Not found | Partial | Partial | Not applicable | Not applicable | Not found | Not found | Proven | Not applicable | Not found | 5 |
| Juniper Networks | Proven | Partial | Proven | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Proven | Not found | Not found | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Partial | 9 |
| Expereo | Not found | Not found | Partial | Not found | Partial | Not found | Not found | Partial | Not found | Not found | Not found | Partial | Partial | Partial | Partial | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Partial | Partial | Partial | 8 |
| Forcepoint | Not found | Not found | Not found | Not found | Partial | Not found | Not found | Partial | Not found | Partial | Partial | Not found | Proven | Not found | Not found | Not found | Not found | Not found | Not found | Not found | Partial | Not found | Not found | Partial | Not found | Not found | Not found | Partial | 9 |
Machine-readable copy: data.json
Regulation to requirement map: UK, EU, US and Canada
What each regime expects of an SD-WAN or SASE service, which evidence columns it maps to, and what counts as evidence. A certification never makes a regulatory column Proven on its own; the source has to connect the named service to the regime.
| Regulation or standard | Applies to | What it expects of the network and security service | Evidence columns and current count | What counts as evidence |
|---|---|---|---|---|
| FCA SYSC 15A and PRA SS1/21: operational resilienceUK | Banks, building societies, insurers, investment firms, payment and e-money firms regulated by the FCA or PRA | Firms identify important business services, set impact tolerances and must be able to stay within them through severe but plausible disruption; the network is usually a mapped dependency. Full compliance was required by 31 March 2025. |
| A UK-regulated customer case naming the service and a resilience outcome; provider material on supporting impact-tolerance mapping or scenario testing; contractual recovery objectives published for FS customers.Does not count: A generic uptime percentage; an SLA page with no FS or resilience-testing context. |
| PRA SS2/21 and FCA SYSC 8: outsourcing and third-party riskUK | PRA and FCA regulated firms using material outsourcing, including managed network and security services | Due diligence, sub-outsourcing transparency, audit and access rights, data location, business continuity and documented exit plans for material outsourced services. |
| Published audit-rights or sub-processor lists; exit or data-return terms; a UK FS customer case that references outsourcing governance.Does not count: A statement that the provider "works with banks". |
| UK Critical Third Parties regime (FSMA 2023; PRA, FCA and Bank of England rules effective 1 January 2025)UK | Third parties designated by HM Treasury as critical to the UK financial system; indirectly relevant to any large network or cloud provider | Designated CTPs face direct oversight, resilience testing and incident reporting duties. Firms are expected to understand concentration in their own supply chains. |
| Provider statement on CTP readiness or designation; independent reporting of designation.Does not count: Assuming designation because the provider is large. |
| UK GDPR and Data Protection Act 2018 (international transfers via IDTA or UK Addendum)UK | Any organisation processing UK personal data | Lawful international transfers, security of processing, records of processing; where logs and inspection data are stored and by whom. |
| Stated UK or EU data residency for logs and management plane; transfer mechanism named; UK data-processing terms published.Does not count: A global privacy notice with no residency statement. |
| DORA: Regulation (EU) 2022/2554, applying from 17 January 2025EU (and UK groups with EU-regulated entities) | EU financial entities and their ICT third-party providers, including network and security providers | ICT risk management, major-incident reporting to the competent authority, resilience testing (threat-led testing for larger entities), register of ICT third parties, Article 30 contractual terms (service levels, data location, audit, exit) and oversight of critical ICT providers. |
| A provider DORA statement that names the service and the Article 30 contractual terms; an EU FS customer case referencing DORA; a DORA-aligned addendum.Does not count: A blog post saying DORA matters; ISO 27001 alone. |
| PCI DSS v4.0.1 (future-dated requirements mandatory from 31 March 2025)Global (card brands) | Any entity storing, processing or transmitting cardholder data, and service providers that can affect its security | Segmentation of the cardholder data environment, strong cryptography over public networks (Req 4), MFA (Req 8), logging and monitoring (Req 10), and a service-provider responsibility matrix (Req 12.8 and 12.9). |
| An Attestation of Compliance for the named service; a customer case that names PCI scope reduction or segmentation with the service; a published responsibility matrix.Does not count: The words "PCI compliant" with no scope or service named. |
| SWIFT Customer Security Programme (CSCF, annual attestation)Global | SWIFT users, mainly banks and market infrastructures | Segregation of the SWIFT secure zone, restricted access, MFA and logging for the SWIFT environment; attested annually. |
| A customer or provider statement naming the service in a SWIFT secure-zone design.Does not count: General segmentation claims with no SWIFT reference. |
| GLBA Safeguards Rule (16 CFR Part 314, FTC; amended rule effective June 2023, FTC breach notification from May 2024)US | Non-bank financial institutions under FTC jurisdiction (lenders, brokers, tax preparers, some fintechs) | Written information security programme with encryption in transit and at rest, MFA, access controls, logging, continuous monitoring or annual penetration testing, service-provider oversight, and notification of qualifying events. |
| A US non-bank FS customer case naming the service; provider material that maps the service to Safeguards Rule elements.Does not count: A general "compliance" page listing GLBA among twenty logos. |
| FFIEC IT Examination Handbook (Architecture, Infrastructure and Operations 2021; Information Security; Business Continuity Management)US | Banks, credit unions and their service providers examined by the federal banking agencies | Examiners expect network segmentation, secure remote access, resilience and recovery testing, third-party management and logging in line with the booklets. |
| A US bank or credit-union case naming the service; provider material written for FFIEC examinations.Does not count: A mention of FFIEC with no service named. |
| Interagency Guidance on Third-Party Relationships: Risk Management (OCC, Federal Reserve, FDIC, June 2023)US | Banking organisations supervised by the three agencies | Due diligence, contract terms, ongoing monitoring and termination planning for third parties, including network and security providers; attention to concentration and subcontracting. |
| Published subcontractor transparency, audit rights or termination assistance terms; a US bank case referencing third-party oversight.Does not count: Generic partner-programme material. |
| Computer-Security Incident Notification Rule (OCC, Federal Reserve, FDIC; effective April 2022)US | Banking organisations and their bank service providers | Banks notify their regulator within 36 hours of a notification incident; bank service providers must notify affected bank customers as soon as possible of an incident that has disrupted covered services for four or more hours. |
| A provider incident-notification commitment for bank customers, in contract terms or a published statement naming the service.Does not count: A status page. |
| NYDFS Cybersecurity Regulation, 23 NYCRR Part 500 (amended November 2023, phased dates to November 2025)US (New York) | Entities licensed by the New York Department of Financial Services, including many banks, insurers and money transmitters | Asset inventory, access privilege management, MFA across the estate, encryption, monitoring and logging, 72-hour incident notification, and a third-party service provider policy. |
| A NYDFS-regulated customer case naming the service; provider material mapping the service to Part 500 sections.Does not count: A list of US regulations on a compliance page. |
| SEC Regulation S-P amendments (adopted May 2024; compliance December 2025 for larger entities, June 2026 for smaller)US | Broker-dealers, investment companies, registered investment advisers and transfer agents | Incident response programme, customer notification within 30 days of becoming aware of unauthorised access, and oversight of service providers handling customer information. |
| A broker-dealer or adviser case naming the service; provider incident-notification terms.Does not count: A general security whitepaper. |
| SEC cybersecurity disclosure rules (Form 8-K Item 1.05; effective December 2023)US | US-listed public companies, including listed financial institutions | Disclosure of material cybersecurity incidents within four business days of determining materiality; the network provider must be able to supply timely incident facts. |
| Provider commitments on incident timelines and forensic log access.Does not count: Marketing about "full visibility". |
| Sarbanes-Oxley Act Section 404: IT general controlsUS | US-listed companies and their financial reporting systems | Change management, access control and logging for systems in financial reporting scope; the network is in scope where it carries or protects those systems. |
| Provider change-control and audit-log capability described for the named service; a SOC 1 or SOC 2 report scope naming the service.Does not count: A SOC 2 logo. |
| FINRA Rule 4370: business continuity plansUS | FINRA member broker-dealers | Documented business continuity and emergency contact plans covering critical systems and connectivity. |
| A broker-dealer case naming the service in a continuity design.Does not count: General failover claims. |
| OSFI Guideline B-13: Technology and Cyber Risk Management (effective 1 January 2024) and the Technology and Cyber Security Incident Reporting AdvisoryCanada | Federally regulated financial institutions (banks, insurers, trust companies) | Technology asset management, secure network architecture, resilience, cyber incident reporting to OSFI within 24 hours of determining an incident is reportable. |
| A Canadian FRFI case naming the service; provider material mapping to B-13.Does not count: A Canadian office address. |
| OSFI Guideline B-10: Third-Party Risk Management (effective 1 May 2024)Canada | Federally regulated financial institutions | Risk-based due diligence, contract provisions (data, audit, subcontracting, exit), concentration risk and ongoing monitoring of third parties. |
| Published subcontractor and exit terms; a Canadian FRFI case referencing third-party governance.Does not count: Partner-programme marketing. |
| PIPEDA and Quebec Law 25Canada | Private-sector organisations handling personal information in Canada; Quebec adds stricter rules and cross-border assessments | Safeguards proportionate to sensitivity, breach reporting, and assessment before transferring personal information outside Quebec. |
| Stated Canadian data residency for logs or management plane; Quebec-specific terms.Does not count: A global privacy notice. |
| ISO/IEC 27001, SOC 2 Type II, FIPS 140-2/140-3, Cyber Essentials Plus, FedRAMPCross-jurisdiction assurance | The provider's own platform and operations | Assurance over the provider's controls. FedRAMP is a US federal programme, not a financial services regulation. Cyber Essentials is UK government-backed baseline assurance. |
| A certificate or report with a scope that names the service; FIPS validation certificate numbers.Does not count: Proof for any regulatory column. A certification never makes a regulatory column Proven on its own. |
What sits behind a cell
Every provider opens to the source rows that support its statuses, with the exact wording, who wrote it, the regime it relates to, when it was published and when we last checked it.
01Cloudflare One
14 of 28 proven19 of 23 sourcesOpenClose
Cloudflare One on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Cloudflare One has documented, product-named evidence for data residency (Data Localization Suite), encryption and key management, log retention, PCI DSS 4.0 scope, EU DORA Article 30 contractual mapping and UK PRA/FCA operational resilience alignment (SS1/21, SS2/21, the Critical Third Parties regime). Named financial services customers exist in three regions: Bank of Cyprus (EU, DDoS resilience and network interconnect), Moneybox (UK, Zero Trust remote workforce access) and Luana Savings Bank (US, Zero Trust and Browser Isolation, six branches, 100% uptime). The strongest named customer for delivery evidence is Luana Savings Bank in the US and Moneybox in the UK, both explicit financial services firms using Cloudflare Access or Zero Trust. The main limitation is that none of the case studies describe a branch network, trading floor or data-centre SD-WAN deployment specifically using Magic WAN or Cloudflare One for a named financial institution; the available named-customer evidence is concentrated in Zero Trust/Access identity and application security, not core SD-WAN branch connectivity. US regulatory alignment (FFIEC, GLBA, NYDFS, SEC), Canadian OSFI alignment and SWIFT CSP alignment have no supporting evidence at all.
Gaps and unknowns: No evidence was found for branch and office connectivity, trading and low-latency connectivity, network segmentation and zoning, payment and cardholder data segmentation, managed operations and SOC, network visibility and reporting, or change control and configuration governance for a named financial institution; a named case study describing Magic WAN or Cloudflare One WAN connectors in an FS branch or trading context would close these. US regulatory alignment (FFIEC, GLBA, NYDFS Part 500, SEC Reg S-P), Canadian OSFI alignment and SWIFT CSP alignment are also unevidenced; a Cloudflare compliance statement or named US/Canadian FS customer citing these specific regimes would be needed.
- Branch and office connectivity
- Not found
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Proven
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Not found
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Proven
- Data residency and sovereignty
- Proven
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Proven
- Identity and zero trust access
- Proven
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Not found
- Change control and configuration governance
- Not found
- Incident notification support
- Proven
- Concentration risk and subcontractor transparency
- Partial
- Exit and portability
- Proven
- UK regulatory alignment (FCA and PRA)
- Proven
- EU DORA alignment
- Proven
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Proven
- North America delivery
- Proven
- Global delivery
- Partial
Sources (22)
- FIN-192AcceptedProvider-authoredFinancial services solution page
Cloudflare for Financial Services
- Named service:
- Cloudflare (Bot Management, API Shield, WAF, DDoS protection, Workers AI, AI Gateway)
- Regulatory regime:
- Not stated
Cloudflare empowers over 1,700 financial services organizations to deliver secure digital experiences
Cloudflare states it serves over 1,700 financial services organisations and lists application security products; no SD-WAN/SASE product is named on this page and no individual customer is described.
Does not prove: Generic industry solutions page with no named customer and no Cloudflare One/Magic WAN/Access naming; does not prove any deployment, only market presence and a generic sovereignty mention.
cloudflare.com · Checked 12 Sept 2026 · Supports: Data residency and sovereignty
- FIN-193AcceptedCustomer-authoredNamed customer case study
Investec & Cloudflare | Case Study | Cloudflare
- Named financial institution:
- Investec
- Named service:
- Cloudflare Workers, Cloudflare Access, Cloudflare Application Services
- Countries, regions:
- South Africa, United Kingdom
- Regulatory regime:
- Multiple
- Outcome:
- Cloudflare makes us proactive rather than reactive
Cloudflare makes us proactive rather than reactive - we can take a long-term strategic approach to security while remaining nimble
Investec, an international bank operating from South Africa and the UK, uses Cloudflare Access and Workers to secure its Programmable Banking platform and open banking APIs.
Does not prove: This is an application security and API case study, not a branch network, SD-WAN or Magic WAN deployment; it does not evidence trading connectivity, branch connectivity or resilience testing.
cloudflare.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access, UK delivery
- FIN-194AcceptedProvider-authoredCompliance attestation or statement
Cloudflare Trust Hub | Cloudflare
- Named service:
- Cloudflare platform
- Standard or regulation:
- ISO 27001, ISO 27701, PCI DSS, SOC 2 Type II
- Regulatory regime:
- Not stated
Cloudflare protects our customers and their users by complying with a wide range of important security certifications. Explore our posture around ISO 27001, ISO 27701, PCI DSS, SOC 2 Type II, and others.
Cloudflare's Trust Hub landing page lists the certifications it holds and links to detail pages, without naming individual products against each certification on this page.
Does not prove: A certification list without a named product or FS customer; supports Partial evidence only for regulatory columns on its own, superseded by the dedicated PCI DSS page for column 24.
cloudflare.com · Checked 12 Sept 2026 · Supports: PCI DSS alignment
- FIN-195AcceptedCustomer-authoredNamed customer case study
Bank of Cyprus & Cloudflare | Customer Story
- Named financial institution:
- Bank of Cyprus
- Named service:
- Magic Transit, Network Firewall, Cloudflare Network Interconnect
- Countries, regions:
- Cyprus
- Regulatory regime:
- EU
- Outcome:
- Automatic DDoS mitigation in ~5 seconds; large-scale attacks blocked in 3 months without manual intervention
The peace of mind is priceless, and our experience with Cloudflare and Parsectix has contributed significantly to achieving that.
Bank of Cyprus, supervised directly by the European Central Bank, uses Magic Transit, Network Firewall and Cloudflare Network Interconnect to mitigate DDoS attacks automatically and maintain service continuity.
Does not prove: Evidences network interconnect and DDoS resilience, not SD-WAN branch connectivity, trading connectivity, segmentation or RTO/RPO-style disaster recovery testing.
cloudflare.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Resilience and tested recovery
- FIN-197AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Cloudflare (Application Security, Application Performance, Zero Trust Services, Network Services, Developer Platform)
- Standard or regulation:
- PCI DSS 4.0
- Regulatory regime:
- Not stated
Cloudflare maintains PCI DSS Level 1 compliance for certain products
Cloudflare documents PCI DSS Level 1 compliance, audited annually since 2014, and lists Zero Trust Services (Access, Gateway, Tunnel), Network Services (WAN, Magic Transit, Network Firewall) and other product groups as in scope.
Does not prove: Confirms PCI DSS scope for named product categories but does not describe cardholder data environment segmentation and does not name an FS customer using it.
cloudflare.com · Checked 12 Sept 2026 · Supports: PCI DSS alignment
- FIN-198AcceptedProvider-authoredFinancial services solution page
Magic WAN | Any-to-any connectivity | Cloudflare
- Named service:
- Cloudflare WAN (Magic WAN)
- Regulatory regime:
- Not stated
Facilitate site-to-site connectivity across network locations like branch offices, retail locations, and factory floors with Cloudflare WAN connectors.
Cloudflare's Magic WAN (SD-WAN) product page describes branch site-to-site connectivity and hybrid/multi-cloud routing, listing named customers such as RATP, Japan Airlines and JetBlue but no financial services customer.
Does not prove: No named financial institution uses Magic WAN on this page, so it is Partial-strength generic product evidence only, not proof of an FS deployment.
cloudflare.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Branch and office connectivity
- FIN-200AcceptedProvider-authoredCompliance attestation or statement
UK Operational Resilience FAQs | Cloudflare
- Named service:
- Cloudflare's connectivity cloud platform
- Countries, regions:
- United Kingdom
- Standard or regulation:
- SS1/21, SS2/21, UK Critical Third Parties (CTP) regime
- Regulatory regime:
- UK
While Cloudflare, a technology provider, is not directly regulated by the PRA, Cloudflare designs its network and services with resilience, transparency, and security to help its customers meet their regulatory obligations.
Cloudflare's compliance page explains the FCA/PRA operational resilience regime (SS1/21, SS2/21) and the UK Critical Third Parties regime and states how Cloudflare's platform and contractual model relate to them.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Underlying content present but as three separate distinct sentences in FAQ, not as a single combined quote with ellipses.). Re-quote verbatim. Discusses the regime and Cloudflare's platform generically rather than naming Cloudflare One or Magic WAN specifically, and does not cite a named FS customer applying it. [2026-09-15] Re-quoted verbatim from live page.
cloudflare.com · Checked 15 Sept 2026 · Supports: UK regulatory alignment (FCA and PRA)
- FIN-201AcceptedProvider-authoredCompliance attestation or statement
Cloudflare Data Localization Suite | Cloudflare
- Named service:
- Cloudflare Data Localization Suite (Customer Metadata Boundary, Keyless SSL, Geo Key Manager, Regional Services)
- Regulatory regime:
- Not stated
Keyless SSL and Geo Key Manager store private SSL keys in a user-specified region. / Customer Metadata Boundary ensures that logs do not leave the specified region.
Cloudflare's Data Localization Suite names specific products (Customer Metadata Boundary, Keyless SSL, Geo Key Manager) that keep logs and private keys within a chosen region, covering Zero Trust, Network Services and other product families.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Both clauses present individually as separate bullet points, in reverse order, not combined as one sentence.). Re-quote verbatim. Confirms the mechanism and named products but this page does not itself list which specific regions (UK, EU, US, Canada) are supported, directing readers to the Trust Hub instead. [2026-09-15] Re-quoted verbatim as two separate bullet points from the live page, matching the checker's finding.
cloudflare.com · Checked 15 Sept 2026 · Supports: Data residency and sovereignty, Encryption and key management
- FIN-202AcceptedProvider-authoredCompliance attestation or statement
EU - Digital Operational Resilience Act (DORA) mapping
- Named service:
- Cloudflare Enterprise Subscription Services
- Standard or regulation:
- DORA (Article 30)
- Regulatory regime:
- EU
This document is designed to help Cloudflare customers who are a financial entity according to the EU Regulation 2022/2554 Digital Operational Resilience Act ("DORA")... to understand how Cloudflare's Enterprise Subscription Terms of Service ("ToS") and its appendices address the key contractual provisions stated under Article 30 of the DORA.
Cloudflare's DORA mapping document walks through Article 30(1)-(3) contractual requirements and matches them to its Enterprise Subscription Terms, SLA availability commitment, breach notification and annual business continuity framework maintenance.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Two related but separate sentences exist; combined quote omits 'of the breach' and post-incident assessment language, and business continuity sentence is separa). Re-quote verbatim. Maps the contract terms to DORA Article 30 but does not name Cloudflare One or Magic WAN specifically and is not tied to a named EU financial institution customer. [2026-09-15] Re-quoted verbatim from the live PDF's opening paragraph, which maps specific ToS sections clause-by-clause to Article 30 sub-provisions.
cf-assets.www.cloudflare.com · Checked 15 Sept 2026 · Supports: Incident notification support, EU DORA alignment
- FIN-203AcceptedProvider-authoredCompliance attestation or statement
Enterprise Subscription Service Level Agreement | Cloudflare
- Named service:
- Cloudflare Enterprise Subscription
- Regulatory regime:
- Not stated
The Service will serve Customer Content globally 100% of the time.
Cloudflare's Enterprise SLA commits to 100% availability with service credits up to six months of fees, and sets P1 response times of under 1 hour for Premium Support and 30 minutes for Technical Account Management.
Does not prove: General enterprise contractual SLA, not specific to Magic WAN or Cloudflare One, and not tied to a named FS customer or a tested DR/RTO-RPO exercise.
cloudflare.com · Checked 12 Sept 2026 · Supports: Resilience and tested recovery, Incident notification support
- FIN-204AcceptedProvider-authoredOther
Enabling log retention - Cloudflare Logs docs
- Named service:
- Cloudflare Logpull API
- Regulatory regime:
- Not stated
By default, your HTTP request logs are not retained.
Cloudflare documents that HTTP request log retention via Logpull must be explicitly enabled and is off by default, without stating a specific retention period on this page.
Does not prove: Explains the retention toggle mechanism only; it does not state a specific retention duration in days, so on its own it only Partially supports the logging/retention column.
developers.cloudflare.com · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention
- FIN-205AcceptedProvider-authoredCompliance attestation or statement
Cloudflare Sub-Processors | Cloudflare
- Named service:
- Cloudflare services and professional services
- Regulatory regime:
- Not stated
Any sub-processor that processes our customers' personal data undergoes a thorough information security and privacy review process.
Cloudflare publishes separate sub-processor lists for its services and for professional services, and states each sub-processor undergoes a security and privacy review.
Does not prove: Confirms a published sub-processor list exists but this landing page does not itself show the list, a change-notification process, or customer audit rights, and is not FS-specific.
cloudflare.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency
- FIN-206AcceptedProvider-authoredCompliance attestation or statement
Cloudflare Data Processing Addendum | Cloudflare
- Named service:
- Cloudflare Services (Data Processing Addendum)
- Regulatory regime:
- Not stated
following termination or expiry of the Main Agreement or completion of the Service, at the choice of Customer, delete or return all Personal Data (including copies thereof) processed pursuant to this DPA
Cloudflare's DPA commits to deleting or returning customer personal data at the customer's choice on termination, and separately authorises Cloudflare Group entities and named categories of third parties to act as sub-processors.
Does not prove: Data return/deletion clause is contractual and generic across all customers, not FS-specific; sub-processor authorisation language does not describe FS-specific third-party or contractor access controls.
cloudflare.com · Checked 12 Sept 2026 · Supports: Third-party and outsourced access, Exit and portability
- FIN-208AcceptedCustomer-authoredNamed customer case study
Moneybox | Case Study | Cloudflare
- Named financial institution:
- Moneybox
- Named service:
- Cloudflare Access, Cloudflare Zero Trust
- Sites, branches, users:
- 300+ employees
- Countries, regions:
- United Kingdom
- Regulatory regime:
- UK
- Outcome:
- Least privilege access to applications they need to do their job
The Cloudflare Zero Trust platform delivers the high level of security required by a company operating in the financial services space.
Moneybox, a UK digital wealth management platform with over 750,000 customers, uses Cloudflare Access and Zero Trust to give its 300+ staff least-privilege remote access, moving all employees to secure remote work during the pandemic.
Does not prove: Covers workforce identity and remote access only; does not evidence branch connectivity, trading connectivity, segmentation or DR testing.
cloudflare.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Remote and hybrid workforce, UK delivery
- FIN-209AcceptedCustomer-authoredNamed customer case study
Luana Savings Bank & Cloudflare | Case Study
- Named financial institution:
- Luana Savings Bank
- Named service:
- Cloudflare Browser Isolation, Cloudflare Zero Trust
- Sites, branches, users:
- six branches, 100+ employees, approximately $2 billion in assets
- Countries, regions:
- United States (Iowa)
- Regulatory regime:
- US
- Outcome:
- Zero malware infections for seven years; 100% uptime with Cloudflare, up from 96% with the previous provider
Malicious code doesn't hit our computers. Browser Isolation is the quickest and easiest way we can deal with malware issues.
Luana Savings Bank, a $2 billion Iowa bank with six branches, uses Cloudflare Browser Isolation and Zero Trust, reporting zero malware infections for seven years and 100% uptime, up from 96% previously.
Does not prove: The six branches are named but Cloudflare's role is endpoint/browser isolation, not a branch network SD-WAN connectivity product, so it is not usable for the branch connectivity column.
cloudflare.com · Checked 12 Sept 2026 · Supports: Resilience and tested recovery, Identity and zero trust access, North America delivery
- FIN-210AcceptedProvider-authoredOther
FIPS 140 level 3 compliance with Cloudflare Application Services
- Named service:
- Cloudflare Keyless SSL, Cloudflare Tunnel
- Standard or regulation:
- FIPS 140 Level 3
- Regulatory regime:
- Not stated
This document outlines a reference architecture for achieving Federal Information Processing Standard (FIPS) 140 Level 3 compliance using Cloudflare's Application Services.
Cloudflare's reference architecture shows how Keyless SSL and Tunnel can be combined with a customer-managed, third-party validated HSM (AWS CloudHSM, Azure Key Vault or Google Cloud KMS) so the private key never leaves the FIPS 140 Level 3 validated hardware.
Does not prove: The FIPS 140 Level 3 validation belongs to the third-party HSM, not to a Cloudflare-owned cryptographic module, so this is architecture guidance rather than a Cloudflare FIPS certification.
developers.cloudflare.com · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-211AcceptedProvider-authoredOther
- Named service:
- Cloudflare One
- Regulatory regime:
- Not stated
Cloudflare stores Zero Trust logs for different periods of time based on the service and plan type. Admin logs: 18 months (all plans).
Cloudflare One documentation states Gateway DNS, HTTP, Network and Access log retention ranges from 24 hours up to 180 days depending on plan (180 days on Enterprise), with Admin/audit logs retained for 18 months across all plans, and supports Logpush export.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page phrasing is 'Cloudflare stores Zero Trust logs for different periods...' plus a table showing Admin logs = 18 months; not phrased as the quoted ellipsis se). Re-quote verbatim. Confirms named-product (Cloudflare One) retention periods and Logpush export, but is generic documentation, not tied to a named FS customer's actual retention configuration. [2026-09-15] Re-quoted verbatim from the live developer docs page and its retention table.
developers.cloudflare.com · Checked 15 Sept 2026 · Supports: Logging, audit and evidence retention
- FIN-212AcceptedProvider-authoredOther
Cloudflare Data Loss Prevention (DLP) | Secure sensitive data | Cloudflare
- Named service:
- Cloudflare DLP, CASB (Cloudflare One)
- Regulatory regime:
- Not stated
works together with CASB to scan connected SaaS applications and cloud storage environments to identify exposed sensitive data at rest
Cloudflare's DLP product, part of the SASE/Zero Trust family, works with CASB to scan SaaS applications and outbound traffic for sensitive data such as PII, with no financial services context on this page.
Does not prove: Generic product capability page with no financial services customer or PCI/PII-specific compliance claim, so it only Partially supports the cloud and SaaS data controls column.
cloudflare.com · Checked 12 Sept 2026 · Supports: Cloud and SaaS data controls
- FIN-196RejectedCustomer-authoredNamed customer case study
NYC Government Financial Agency & Cloudflare | Customer Story | Cloudflare
- Named service:
- Cloudflare WAF, DDoS Protection
- Sites, branches, users:
- 300,000+ community members served
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- Attack volume reduced by over 90% immediately; blocks approximately 500 million malicious requests monthly
Zero Trust is the only way to achieve a manageable level of security assurance.
An unnamed NYC government financial agency used Cloudflare WAF and DDoS protection to stop a credential-stuffing attack and is exploring Cloudflare Access and Cloudflare One Client.
Does not prove: The institution is anonymised (a public-sector agency, not a named financial institution), the case study is about web application attack mitigation, and Cloudflare One/Access adoption is only described as being explored, not implemented; not usable for any of the 28 columns.
cloudflare.com · Checked 12 Sept 2026
- FIN-199RejectedProvider-authoredFinancial services solution page
DORA compliance: Fortifying financial security and resilience with Cloudflare
- Named service:
- Cloudflare
- Standard or regulation:
- DORA
- Regulatory regime:
- Not stated
Mapping DORA requirements to Cloudflare capabilities - See how Cloudflare's solutions align with DORA's five key pillars and multitude of requirements.
A gated landing page promoting a DORA whitepaper; the substantive DORA-to-product mapping is contained in a separate downloadable PDF, not in the page content itself.
Does not prove: No specific product names, article references or facts are present on the page itself; the actual DORA mapping evidence comes from the separate PDF document, which is recorded as its own source row.
cloudflare.com · Checked 12 Sept 2026
- FIN-207RejectedProvider-authoredFinancial services solution page
theNET | Digital transformation in banking & financial services | Cloudflare
- Named service:
- Cloudflare connectivity cloud
- Standard or regulation:
- GDPR, PSD2
- Regulatory regime:
- Not stated
The Payment Services Directive (PSD2) are encouraging banks to adopt digital solutions
An industry thought-leadership article discussing threats to banks (citing breaches at TD Bank, Santander, DBS Bank and others as third-party incidents, not Cloudflare customers) and referencing GDPR and PSD2 generically.
Does not prove: The named institutions are breach examples unrelated to Cloudflare, not Cloudflare customers; no Cloudflare One, Magic WAN or Access product is named, so this cannot support any of the 28 columns.
cloudflare.com · Checked 12 Sept 2026
- FS-021SupersededProvider-authoredExisting source lead
Cloudflare | The agile SASE platform (Cloudflare One SASE product page)
- Named service:
- Cloudflare One
Cloudflare empowers over 1,700 financial services organizations to deliver secure digital experiences while meeting data sovereignty, regulatory, and resiliency requirements.
Dedicated financial services industry page with a quantified customer count and named financial logos (Visa, SoFi, NCR Voyix, Stripe). The 1,700 figure is vendor self reported and unaudited. No SASE specific financial services case study was found; the named testimonial on the page is from Shopify, a commerce platform rather than a bank.
Does not prove: Tier 1 supplier page. Primary SASE positioning page named in the brief. Carries the 300+ cities SASE delivery claim, the single global per-seat pricing claim and a large customer logo wall. Logo wall carries no sector labels, so it supports named customers but not sector grading on its own. | New Source: https://www.cloudflare.com/solutions/financial-services
cloudflare.com · Checked 29 Jul 2026
02Zscaler
10 of 28 proven14 of 18 sourcesOpenClose
Zscaler on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Zscaler has strong, named evidence of financial services customers using its SASE platform (ZIA, ZPA, ZDX, Zero Trust Exchange) for branch and campus connectivity, cloud/data-centre on-ramps, zero trust segmentation and remote workforce access, with Hastings Direct as the strongest UK case and Fannie Mae and OneMain Financial as the strongest US cases. Encryption (FIPS 140-2 for ZIA/ZPA) and data residency architecture are documented at the platform level, and a sub-processor list is published with notification and objection rights. The main limitation is regulatory: no page connects the named service to FCA/PRA rules, US banking-specific regimes (FFIEC, GLBA, NYDFS, SEC), or OSFI, and the one DORA reference concerns a separate DSPM product without a named EU institution. There is also no evidence of trading/low-latency use, managed SOC service, incident notification commitments, or exit/portability terms for financial services customers. An IT decision maker in a regulated FS firm would need to request FCA/DORA/NYDFS-specific compliance statements and a PCI DSS Attestation of Compliance directly from Zscaler, as none were found published for the named service in this evidence set.
Gaps and unknowns: No evidence was found for trading/low-latency connectivity, managed operations/SOC, change control governance, incident notification timelines, exit and portability terms, or any of the UK, US, or Canada regulatory alignment columns; closing these would need direct FCA/PRA, FFIEC/NYDFS/SEC and OSFI compliance statements from Zscaler naming the service, an incident-notification clause from its contract or DPA, and a named FS customer case describing a managed SOC or tested DR/failover exercise. PCI DSS alignment and EU DORA alignment are only Partial and would need a PCI DSS Attestation of Compliance naming ZIA/ZPA/Zero Trust Exchange, and a DORA statement or EU FS case naming that same core service rather than the separate DSPM product.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Proven
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Proven
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Proven
- Data residency and sovereignty
- Partial
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Proven
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Proven
- North America delivery
- Proven
- Global delivery
- Proven
Sources (16)
- FIN-473AcceptedProvider-authoredFinancial services solution page
Zscaler for Financial Services
- Named service:
- Zscaler Zero Trust Exchange
- Countries, regions:
- Multiple (customers named include UK, US, South Africa, India)
- Regulatory regime:
- Multiple
Compliance mandates like GDPR, PCI DSS, and SOX put friction on innovation
Zscaler's financial services industry page names Fannie Mae, Hastings Direct, Capitec and L&T Financial Services as customers and lists Zero Trust Exchange, ZIA, ZPA, Zero Trust Branch and other products, but gives no per-institution deployment detail on this page itself.
Does not prove: Generic industry page; does not itself prove any single capability with FS-specific detail beyond naming customers across UK, US, South Africa and India, which is used only as supporting evidence for global spread of named FS deployments.
zscaler.com · Checked 12 Sept 2026 · Supports: Global delivery
- FIN-474AcceptedProvider-authoredNamed customer case study
Hastings Direct Case Study | Customer Stories | Zscaler
- Named financial institution:
- Hastings Direct
- Named service:
- Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX)
- Sites, branches, users:
- 3.9 million policyholders; 4,500 employees and outsource partners
- Countries, regions:
- United Kingdom (East Sussex)
- Regulatory regime:
- UK
- Outcome:
- 2.5 billion transactions processed and 45 million policy violations prevented in a single quarter; 14,000+ threats blocked including 4,500 hidden in encrypted traffic
no matter when or where our colleagues choose to work
Hastings Direct, a UK insurer with 3.9 million policyholders, replaced legacy VPNs and proxies with ZIA, ZPA and ZDX, using ZPA to give users microsegmented access only to authorised resources.
Does not prove: Does not mention branch/office count, trading, PCI, DR/RTO-RPO testing, or any UK regulator (FCA/PRA) by name.
zscaler.com · Checked 12 Sept 2026 · Supports: Network segmentation and zoning, Remote and hybrid workforce, UK delivery
- FIN-475AcceptedProvider-authoredNamed customer case study
Fannie Mae Case Study | Customer Stories | Zscaler
- Named financial institution:
- Fannie Mae
- Named service:
- Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange
- Sites, branches, users:
- 7,400+ US employees; 10,000 employees targeted for direct-to-internet access
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- Reduced IT complexity from 38 data replication models to 2; eliminated network backhauling with local internet breakouts
When you make that shift to Microsoft 365 while still backhauling everyone's traffic to HQ, the bandwidth usage goes through the roof.
Fannie Mae, described as part of the nation's critical financial infrastructure, used ZIA to give employees direct internet access to Microsoft 365 and is migrating security infrastructure toward AWS.
Does not prove: No RTO/RPO or tested DR outcome stated; no named US regulation (FFIEC, GLBA, NYDFS, SEC) referenced; segmentation and PCI not discussed.
zscaler.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, North America delivery
- FIN-476AcceptedProvider-authoredNamed customer case study
Capitec Bank Limited | Zscaler
- Named financial institution:
- Capitec Bank Limited
- Named service:
- Zscaler Zero Trust Exchange, Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Cloud Connector
- Sites, branches, users:
- 17,000 users protected; 860 branches; 15,450 employees; 21 million bank customers
- Countries, regions:
- South Africa
- Regulatory regime:
- Multiple
- Outcome:
- 744,758 security threats blocked and 125 million policy violations prevented annually; banking application migrated to AWS in 3 seconds with zero downtime
users are never placed on the corporate network, which reduces the attack surface
Capitec, South Africa's largest retail bank, used Zscaler Cloud Connector and ZPA/ZIA to migrate its banking application to AWS and to remove users from the corporate network as part of a zero trust rollout.
Does not prove: South Africa is outside the UK/North America scope of this evidence page so used only as global-delivery and general capability evidence, not for UK or NA delivery columns; no PCI or specific regulator named.
zscaler.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Network segmentation and zoning, Remote and hybrid workforce, Global delivery
- FIN-477AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Zscaler Zero Trust Exchange platform
- Standard or regulation:
- SOC 2 Type 2; ISO/IEC 27001; ISO/IEC 27018:2019; PCI DSS; FIPS 140-2; FIPS 140-3; CSA STAR Level 2
- Regulatory regime:
- Not stated
SOC 2 Type 2; SOC 3; ISO/IEC 27001; ISO/IEC 27018:2019; FIPS 140-2; FIPS 140-3; CSA STAR Level 2; PCI DSS
Zscaler's compliance portal lists certifications and attestations held by the company, including SOC 2, ISO 27001/27018, PCI DSS, FIPS 140-2/140-3 and CSA STAR, without stating which specific product each certificate scopes.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (All listed certifications individually confirmed on page but presented as separate list items/links, not as one semicolon-joined string.). Re-quote verbatim. Certificates are listed at company level without naming which service (ZIA/ZPA/Zero Trust Exchange) each attestation covers, and full certificate documents sit behind an authenticated portal not accessible here; not sufficient alone to prove PCI DSS AoC scope for a named service. [2026-09-15] Playwright fetch attempt 2026-09-15 was itself blocked by a Cloudflare bot-verification challenge ('Performing security verification') - this is not a script-rendering issue but active bot protection that a headless browser cannot pass. Manually opening this URL in a normal logged-in browser session is the only way to read it. [2026-09-14, Harry] Personally opened and confirmed live by Harry Yelland - the recorded wording matches the page/document exactly. This was previously unreachable by automation (bot-verification wall or unfetchable PDF).
compliance.zscaler.com · Checked 14 Sept 2026 · Supports: Encryption and key management, PCI DSS alignment
- FIN-478AcceptedProvider-authoredCompliance attestation or statement
How Zscaler DSPM Helps Europe's Financial Sector Achieve DORA Compliance
- Named service:
- Zscaler DSPM
- Countries, regions:
- European Union
- Standard or regulation:
- DORA
- Regulatory regime:
- EU
DORA emphasizes the importance of reducing risks introduced by third-party ICT service providers. Zscaler DSPM amplifies transparency
A Zscaler blog post connects the Zscaler DSPM product to DORA's third-party ICT risk requirements, using a hypothetical EU financial institution rather than a named customer.
Does not prove: No named EU financial institution; the product discussed (DSPM) is a data security posture management add-on, not the core ZIA/ZPA/Zero Trust Exchange/Zero Trust SD-WAN service; does not cite specific DORA Article 30 contractual terms.
zscaler.com · Published 30 Jul 2025 · Checked 12 Sept 2026 · Supports: EU DORA alignment
- FIN-479AcceptedProvider-authoredCompliance attestation or statement
Zscaler SLA Support | Service Level Agreement Documentation
- Named service:
- Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Zscaler Zero Trust Branch
- Regulatory regime:
- Not stated
99.999% of Customer's Transactions and Sessions during every month
Zscaler publishes SLA uptime commitments of 99.999% for ZIA, ZPA, ZDX and Zero Trust Branch, with tiered service credits and support response times ranging from 15 minutes to 48 hours depending on severity and plan.
Does not prove: This is an uptime/service-credit SLA, not a tested DR/failover outcome or RTO/RPO commitment, and it is not FS-specific; support response times are for support tickets, not security incident notification.
zscaler.com · Checked 12 Sept 2026 · Supports: Resilience and tested recovery
- FIN-480AcceptedProvider-authoredCompliance attestation or statement
Zscaler Sub-Processors: Security & Privacy Standards
- Named service:
- Zscaler Zero Trust Exchange platform
- Regulatory regime:
- Not stated
On this page, we maintain a current list of Sub-Processors authorized to process Customer Data
Zscaler publishes a list of sub-processors including AWS, Azure, Google Cloud, Snowflake and Databricks, states it performs due diligence on them, and allows customers to register for change notices and to object to new sub-processors.
Does not prove: Generic company-wide sub-processor disclosure, not FS-specific; no explicit audit-rights clause quoted; does not name concentration-risk or multi-region independence statements beyond the sub-processor list itself.
zscaler.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency, Third-party and outsourced access
- FIN-481AcceptedProvider-authoredCompliance attestation or statement
Understanding Digital Sovereignty in the Modern Era
- Named service:
- Zscaler Zero Trust Exchange
- Countries, regions:
- United States, European Union, and other regions via Private Service Edges
- Standard or regulation:
- FedRAMP
- Regulatory regime:
- Multiple
pseudonymized local logging through public hub sites for regional or in-country requirements
Zscaler describes over 160 global data centres, a FedRAMP-authorised US GovCloud, an EU ZSCloud, and options for pseudonymised local logging, private on-premises logging infrastructure and sovereign sites, plus a 90-day emergency disconnect from the global cloud.
Does not prove: Does not explicitly name UK or Canada data residency regions; not FS-specific; describes architecture options rather than a guaranteed default residency for all customer log and management-plane data.
zscaler.com · Published 1 Jul 2025 · Checked 12 Sept 2026 · Supports: Data residency and sovereignty
- FIN-482AcceptedProvider-authoredCompliance attestation or statement
Zscaler Security Cloud Receives FIPS 140-2 Validation for Encryption
- Named service:
- Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA)
- Standard or regulation:
- FIPS 140-2
- Regulatory regime:
- Not stated
Zscaler, Inc. (NASDAQ: ZS), an industry leader in cloud security, is proud to announce the immediate availability of FIPS 140-2 validated encryption within Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA).
Zscaler announced FIPS 140-2 validated encryption modules (Zscaler Mobile Cryptographic Module, certificate #3154, and Zscaler Crypto Module, certificate #3159) for ZIA and ZPA.
Does not prove: Press release is from 2018; does not confirm current FIPS 140-3 status of the present-day service, and is not FS-specific.
ir.zscaler.com · Published 11 Apr 2018 · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-484AcceptedProvider-authoredFinancial services solution page
SASE Solutions for PCI DSS 4.0 Compliance & Enhanced Security
- Named service:
- Zscaler Private Access (ZTNA)
- Standard or regulation:
- PCI DSS 4.0
- Regulatory regime:
- Not stated
With Zero Trust Network Access (ZTNA), Zscaler enforces least-privileged access and isolates payment systems from other business applications, minimizing unauthorized access.
Zscaler's PCI DSS 4.0 page states that its ZTNA capability isolates payment systems from other business applications, but does not reference a PCI DSS Attestation of Compliance for a named service or cite a customer.
Does not prove: No named financial institution or PCI scope reduction outcome; no Attestation of Compliance referenced for ZIA/ZPA/Zero Trust Exchange; generic marketing-style compliance page.
zscaler.com · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation
- FIN-485AcceptedProvider-authoredNamed customer case study
OneMain Financial Case Study | Customer Stories | Zscaler
- Named financial institution:
- OneMain Financial
- Named service:
- Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange, Zscaler Client Connector
- Sites, branches, users:
- 8,000+ employees across 1,400 branches in 44 states
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- 96% of traffic experiences under 1ms latency with zero employee complaints post-migration; full SSL inspection of 96% of encrypted traffic
Using Zscaler now gives us the capability to route things directly out through the internet in our branches and campus location.
OneMain Financial, a US consumer lender with 1,400 branches across 44 states, replaced Broadcom/Blue Coat proxy appliances with ZIA to give branch and campus locations direct internet breakout and centralised policy administration.
Does not prove: No PCI, segmentation detail, RTO/RPO, or US regulator (FFIEC, GLBA, NYDFS, SEC) named on this page.
zscaler.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Branch and office connectivity, Remote and hybrid workforce, North America delivery
- FIN-486AcceptedProvider-authoredNamed customer case study
ABANCA Case Study | Customer Stories | Zscaler
- Named financial institution:
- ABANCA
- Named service:
- Zscaler Digital Experience (ZDX), Zscaler Internet Access (ZIA), Zscaler Zero Trust Exchange
- Sites, branches, users:
- 6,000+ employees
- Countries, regions:
- Spain and 11 countries
- Regulatory regime:
- EU
- Outcome:
- Comprehensive global visibility into network traffic patterns and stronger controls for mission-critical applications
Zscaler is clearly giving us an opportunity to model new capabilities and new architectures, while reducing complexity.
ABANCA, a Spanish bank operating in 11 countries, deployed ZDX, ZIA and Zero Trust Exchange for global network visibility and detection of application-specific risk.
Does not prove: No DORA, branch count, PCI, or segmentation detail stated on this page; EU DORA alignment is not mentioned despite ABANCA being an EU bank.
zscaler.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Global delivery
- FIN-487AcceptedProvider-authoredCompliance attestation or statement
Zscaler Nanolog Streaming Service data sheet
- Named service:
- Zscaler Nanolog Streaming Service (NSS)
- Regulatory regime:
- Not stated
Transmit logs from all users and locations to the SIEM in real time
The Nanolog Streaming Service data sheet describes real-time streaming of web and firewall logs to up to eight SIEM destinations with customer-chosen filters and formats, and refers to historical log analysis beyond six months, but does not state a fixed Zscaler-side log retention period.
Does not prove: No explicit fixed log retention period stated; log storage location is described as customer-determined rather than a documented Zscaler data residency commitment; not FS-specific.
zscaler.com · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention
- FIN-483RejectedProvider-authoredFinancial services solution page
- Named service:
- Zscaler Zero Trust SD-WAN
- Regulatory regime:
- Not stated
Zscaler Zero Trust SD-WAN securely connects users, devices, and workloads across branches, data centers, and the cloud.
The Zero Trust SD-WAN product page describes generic branch connectivity, segmentation and dynamic path selection capabilities, citing real-estate, manufacturing and media customers, with no financial services customer named.
Does not prove: No financial institution named as a Zero Trust SD-WAN customer, so this page cannot support any of the 28 FS columns on its own; rejected as a standalone FS evidence source, retained only for background on the product.
zscaler.com · Checked 12 Sept 2026
- FS-081RejectedProvider-authoredExisting source lead
Zscaler digital transformation for the banking sector
- Named service:
- Zscaler Zero Trust Exchange
- Regulatory regime:
- Multiple
We embraced security as a journey that ran in parallel with our exploration of our applications, data, and transaction processing.
Quote is attributed to Fannie Mae on the dedicated financial services page. Four named customers across three continents: Fannie Mae (US), Hastings Direct (UK insurance), Capitec (South Africa) and L&T Financial Services (India). A second banking landing page corroborates the same set. Regulatory frameworks named on the page include PCI DSS, SOX, NIST CSF and ISO 27001.
Does not prove: Supplier's own banking landing page, linked from the industries index. Corroborates the same four named financial services customers as source 4. | Confirmed - exact match [2026-09-15, flagged per Robert's check] Duplicate of FS-080's generic narrative for a different page - same limitation. Changed from Accepted to Needs review since no specific capability can be honestly assigned - recommend Harry/Robert decide whether to Reject or find a genuine capability fit. Rejected 2026-09-15 (final pass). Same generic transformation narrative as FS-080, reused on a different Zscaler page - no named institution, no specific technical claim tied to a capability column.
zscaler.com · Checked 15 Sept 2026
03Netskope
9 of 28 proven15 of 20 sourcesOpenClose
Netskope on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Netskope has documented compliance certifications including ISO 27001, SOC 2 Type 2, PCI DSS v4.0.1 and FedRAMP High, and its own documentation names configurable data residency options covering the UK, EU, US and several other regions through the NewEdge network. Two named financial services institutions, Apex Group and Ascensus, are evidenced using Netskope's SSE components, CASB, DLP, ZTNA and Advanced Analytics, for cloud and SaaS data control, identity and zero trust access, and network visibility, with Apex Group's case spanning 42 countries. No evidence was found of a named financial institution using Netskope's SD-WAN or SASE Branch product for branch, office, trading floor or data centre connectivity, and no source connects the service to FCA/PRA, NYDFS, FFIEC, SEC or OSFI regime requirements for a named customer. DORA is mentioned on Netskope's own financial services and compliance pages, but only as a generic regulation it can help address, without contractual detail or a named EU customer case. For a UK or North American IT decision maker, the strongest evidence is the Apex Group case study, a global financial services group using SSE and ZTNA, and the main limitation is the absence of any named FS customer proof point for Netskope's SD-WAN or branch connectivity capability.
Gaps and unknowns: No evidence was found for branch or office SD-WAN connectivity, trading or low-latency workloads, encryption and FIPS validation, log retention periods, incident notification timelines, exit and portability terms, SWIFT CSP alignment, or Canada/OSFI and UK FCA/PRA alignment for the named service. Closing these gaps would require access to the gated Netskope Trust Portal and Compliance Center documents (security whitepaper, DPA, SLA and SOC 2 report), which need registration or an NDA, plus a named UK or Canadian financial services customer case for the SD-WAN or SASE Branch product, none of which was found on the public site during this research.
- Branch and office connectivity
- Not found
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Proven
- Encryption and key management
- Not found
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Proven
- Cloud and SaaS data controls
- Proven
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Proven
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Partial
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Proven
- North America delivery
- Proven
- Global delivery
- Proven
Sources (18)
- FIN-334AcceptedProvider-authoredFinancial services solution page
Securing Financial Services in the Cloud and AI Era
- Named service:
- Netskope One SASE
- Standard or regulation:
- DORA, GDPR, NIS 2, PCI
- Regulatory regime:
- Multiple
- Outcome:
- helping reduce the risk of a severe breach by up to 80%
Support regulatory compliance across DORA, GDPR, NIS 2, PCI, and many other important regulatory requirements and data privacy regulations
Netskope's financial services industry page states that its platform helps customers meet several named regulations including DORA and PCI, and claims three of the five largest Fortune 100 financial services companies use its SASE platform, without naming them.
Does not prove: Generic financial services industry page with no named financial institution; the DORA reference is a capability claim rather than a compliance statement, Article 30 contractual term or named EU customer case, so it does not establish full DORA alignment.
netskope.com · Checked 12 Sept 2026 · Supports: EU DORA alignment
- FIN-335AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Netskope platform
- Standard or regulation:
- ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, SOC 2 Type 2, PCI DSS, FedRAMP High, CSA STAR
- Regulatory regime:
- Not stated
PCI DSS - global security standard for all entities that store, process, or transmit cardholder data
Netskope's compliance page lists corporate-wide certifications including ISO 27001, SOC 2 Type 2, PCI DSS, FedRAMP High and CSA STAR, and links to the Trust Portal for further documents.
Does not prove: Certification list is corporate-wide and not tied to a named financial services customer or to the SD-WAN/SASE Branch product specifically; does not itself demonstrate FCA/PRA, NYDFS, DORA or OSFI regime alignment; no data residency, FIPS, encryption or log retention detail was found on this page.
netskope.com · Checked 12 Sept 2026 · Supports: PCI DSS alignment
- FIN-336AcceptedProvider-authoredOther
- Named service:
- NewEdge Network
- Countries, regions:
- 80+ regions, 220+ countries and territories
- Regulatory regime:
- Not stated
- Outcome:
- <10ms Industry-best traffic processing latency SLAs
"120+ data centers in 80+ regions globally - including Mainland China." / "Route Control: Automatically routes traffic in real time over optimal paths from NewEdge data centers to address micro-outages or congestion, maintaining service continuity and low latency - even during ISP issues, or 'black swan' events."
Netskope describes its NewEdge network as having over 120 full-compute data centres in more than 80 regions, with automatic failover (GSLB and Auto Failout) and dynamic routing to maintain performance during disruptions.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Both facts (120+ data centers/80+ regions incl. Mainland China; Dynamic Route control) present but in separate sections, not combined as quoted.). Re-quote verbatim. General network infrastructure page not tied to a named financial institution, so it does not prove resilience or tested recovery for an FS customer specifically; no RTO/RPO figures or DR test outcomes are given. [2026-09-15] Re-quoted verbatim from the current live NewEdge datasheet (2026-03 edition), as two separate sentences matching the checker's finding.
netskope.com · Checked 15 Sept 2026 · Supports: Resilience and tested recovery, Global delivery
- FIN-337AcceptedProvider-authoredNamed customer case study
Apex Group Case Study | Netskope
- Named financial institution:
- Apex Group
- Named service:
- Netskope One SSE (Next Gen Secure Web Gateway, CASB, DLP, Threat Protection), Netskope Private Access, Cloud Firewall, Advanced Analytics
- Sites, branches, users:
- 13,000+ employees, 34 companies
- Countries, regions:
- 42 countries and legal jurisdictions
- Regulatory regime:
- Multiple
- Outcome:
- Consolidated from 40+ point-solutions to 8 technologies; automated level-one tier of global Security Operations Center; project completed 3 months ahead of schedule
Netskope provides us with the tools and capabilities to securely embrace cloud technologies while maintaining control and compliance
Apex Group, a global financial services provider operating 34 companies across 42 countries, deployed Netskope SSE, Private Access (ZTNA), Cloud Firewall and Advanced Analytics to consolidate security tooling, automate tier-one SOC work and gain visibility into cloud usage and risk.
Does not prove: Case study demonstrates SSE, ZTNA and CASB/DLP use by a named FS group, not SD-WAN, branch, trading or data-centre connectivity; it does not name a specific regulation, and describes internal group-company access rather than third-party/contractor access or explicitly remote/hybrid working.
netskope.com · Checked 12 Sept 2026 · Supports: Third-party and outsourced access, Network visibility and reporting, Identity and zero trust access, Cloud and SaaS data controls, Remote and hybrid workforce, Managed operations and SOC
- FIN-338AcceptedProvider-authoredOther
Secure SD-WAN | Netskope One SASE Branch | Netskope
- Named service:
- Netskope One SASE Branch (Secure SD-WAN)
- Countries, regions:
- 75+ regions
- Regulatory regime:
- Not stated
Extend VRF-based segmentation across branches, data centers, and cloud
Netskope's SASE Branch (Secure SD-WAN) product page describes VRF-based segmentation, sub-second failover, active-active links and multi-cloud on-ramps to AWS, Azure and Google Cloud WAN.
Does not prove: Product capability page only; no named financial institution or FS material links these SD-WAN segmentation, resilience or cloud on-ramp features to an actual deployment.
netskope.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Network segmentation and zoning, Resilience and tested recovery
- FIN-339AcceptedProvider-authoredCompliance attestation or statement
Data Transfer at Netskope | Netskope
- Named service:
- Netskope
- Countries, regions:
- United States, EU, UK, Australia, Saudi Arabia, Switzerland, Singapore
- Regulatory regime:
- Multiple
Customers' log transaction data are stored in the management plane designated by each customer. Currently, management planes are available in the United States, the EU, the UK, Australia, Saudi Arabia, Switzerland, and Singapore.
Netskope documents that customers can choose the management plane region for their log/transaction data, currently offered in the US, EU, UK, Australia, Saudi Arabia, Switzerland and Singapore, plus configurable country- and region-specific data processing zones for traffic in motion.
Does not prove: Documents residency options generically across the whole customer base, not for a named financial institution; Canada is not listed as a distinct management plane region (only a broader 'North America Zone' for traffic processing); does not cover end-user content data, which Netskope states it does not store.
netskope.com · Checked 12 Sept 2026 · Supports: Data residency and sovereignty, North America delivery, UK delivery
- FIN-340AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Netskope platform
- Standard or regulation:
- PCI DSS v4.0.1, DORA, SOC 2 Type 2, ISO/IEC 27001, FedRAMP High, CSA STAR Level 2
- Regulatory regime:
- Multiple
PCI DSS v4.0.1
Netskope's Compliance Center lists PCI DSS v4.0.1 among its achieved certifications and lists DORA among the compliance frameworks or mappings it makes available, alongside SOC 2 Type 2, ISO 27001, FedRAMP High and CSA STAR.
Does not prove: The underlying documents (including the DORA mapping) sit behind a gated 'Get access' portal that was not opened; the page confirms the certification and DORA framework mapping exist but not their detailed contractual or FS-specific content.
compliance.netskope.com · Checked 12 Sept 2026 · Supports: EU DORA alignment, PCI DSS alignment
- FIN-341AcceptedProvider-authoredFinancial services solution page
PCI-DSS Cloud Compliance | Netskope
- Named service:
- Netskope CASB, DLP, Next Gen Secure Web Gateway, ZTNA
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
Apply DLP and/or encryption policies to ensure that data containing PCI does not get into the wrong hands.
Netskope's PCI-DSS solution page describes how CASB, DLP, secure web gateway and ZTNA can inspect and control content containing cardholder data and support audit visibility, citing a Fortune 500 retailer SOC analyst quote.
Does not prove: Generic solution page; no named cardholder data environment, no named financial institution, and no PCI DSS Attestation of Compliance is referenced on this specific page.
netskope.com · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation
- FIN-342AcceptedProvider-authoredFinancial services solution page
GLBA Cloud Compliance | Netskope
- Named service:
- Netskope CASB
- Countries, regions:
- United States
- Standard or regulation:
- GLBA
- Regulatory regime:
- US
GLBA has specific compliance requirements tied to security and confidentiality, privacy, and safeguards.
Netskope's GLBA solution page names the regulation and its CASB product together, with a supporting quote from the CIO of Dana Foundation about assessing cloud application risk.
Does not prove: The only customer quoted, Dana Foundation, is a non-profit foundation rather than a bank, insurer or other regulated financial institution; the page does not cite the GLBA Safeguards Rule by name or any FFIEC, NYDFS or SEC alignment.
netskope.com · Checked 12 Sept 2026 · Supports: US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- FIN-344AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Netskope
- Regulatory regime:
- Not stated
This is our updated list of third-party Sub-processors. For additional queries, please contact the Netskope Privacy team
Netskope publishes a downloadable, dated sub-processor list (referenced as a September 2026 PDF) and invites customer queries to its privacy team.
Does not prove: Confirms the practice of publishing an updated sub-processor list, but the linked PDF itself, containing the named sub-processors and any multi-region independence statement, was not opened as part of this research.
netskope.com · Published 1 Sept 2026 · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency
- FIN-347AcceptedProvider-authoredOther
- Named service:
- Netskope
- Regulatory regime:
- Not stated
We are a global team and operate 24/7/365
Netskope states its support team operates 24/7/365, with Premium and Premium Plus paid tiers offering full 24/7 phone and on-call coverage above the basic business-hours tier.
Does not prove: Generic corporate support-tier page, not FS-specific; gives no RTO/RPO or incident notification timelines, and full 24/7 phone coverage requires a paid Premium or Premium Plus tier rather than being included by default.
netskope.com · Checked 12 Sept 2026 · Supports: Managed operations and SOC
- FIN-348AcceptedProvider-authoredNamed customer case study
Ascensus Case Study | Netskope
- Named financial institution:
- Ascensus
- Named service:
- Netskope CASB, DLP, Next Gen Secure Web Gateway
- Sites, branches, users:
- 5,000+ employees; serves 15 million+ people
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- CASB configured and operational within one hour; SWG deployed within five minutes for rule setup
We can protect our data and applications without ever just telling users 'no.'
Ascensus, a US-based retirement, education and healthcare savings recordkeeping and third-party administration provider serving over 15 million people, deployed Netskope CASB, DLP and NG-SWG to gain visibility and control over more than 2,000 cloud applications.
Does not prove: Case study covers cloud application visibility and DLP after a Microsoft 365 migration; it does not mention GLBA, FFIEC, SEC or any other specific financial regulation, and does not cover branch, SD-WAN, trading or data-centre connectivity.
netskope.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Cloud and SaaS data controls, North America delivery
- FIN-508AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Netskope One (unified SASE platform)
- Standard or regulation:
- DORA - dedicated compliance guide mapping DORA's requirements to the Netskope One platform
- Regulatory regime:
- EU
"We've summarised and mapped the 79 pages of DORA to our industry leading platform to save you time... helps these organisations follow DORA's rules, applying zero trust principles to protect data and defend against cyber threats."
Netskope's own dedicated DORA compliance guide, verified live 2026-09-15. This is a genuine mapping document (not just a passing mention), addressing incident management, classification and reporting under DORA specifically - stronger than a blog aside, but it doesn't name Netskope One's Article 30 contractual terms specifically or a named EU financial customer, so graded Partial rather than Proven.
Does not prove: Added 2026-09-15 per item 6 (thin regulatory columns) research pass. A genuine compliance-mapping resource, not a certification list, but stops short of the Article 30 contractual-terms bar for Proven.
netskope.com · Checked 15 Sept 2026 · Supports: EU DORA alignment
- FIN-509AcceptedProvider-authoredCompliance attestation or statement
Fortune 500 Financial Services Company Meets NYDFS Cybersecurity Regulations (Netskope + Unisys)
- Named financial institution:
- Not named ("a Fortune 500 financial services company")
- Named service:
- Netskope CASB
- Countries, regions:
- United States (New York)
- Standard or regulation:
- NYDFS Cybersecurity Regulation (23 NYCRR Part 500)
- Regulatory regime:
- US
"When taking a look at how to achieve NYDFS security compliance, you need to look at CASB solutions."
Netskope's own blog post, verified live 2026-09-15, co-authored with partner Unisys, explicitly addressing NYDFS compliance via Netskope CASB. The customer is anonymised ('a Fortune 500 financial services company'), so this cannot support a named-customer Proven claim, but per the Regulations tab's own evidence bar ('provider material mapping the service to Part 500 sections'), this is genuine provider material connecting Netskope's product to NYDFS - graded Partial given the mapping is general rather than section-by-section.
Does not prove: Added 2026-09-15 per item 6 research pass. Anonymised customer; general NYDFS/CASB framing rather than a detailed Part 500 section mapping.
netskope.com · Checked 15 Sept 2026 · Supports: US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- FIN-343RejectedProvider-authoredFinancial services solution page
Maintain Compliance | Netskope
- Named service:
- Netskope One SSE, DLP, Advanced Analytics
- Standard or regulation:
- PCI-DSS, HIPAA, GDPR
- Regulatory regime:
- Not stated
- Outcome:
- Stronger compliance across global operations. Seamless M&A integration, improving operational consistency.
Stronger compliance across global operations. Seamless M&A integration, improving operational consistency.
Netskope's compliance solutions page cites an anonymised financial services customer using SSE, DLP and Advanced Analytics for compliance and M&A integration, alongside a claim of 40+ pre-configured compliance templates.
Does not prove: Customer is anonymised as 'financial services' with no name given, so under the grading rules it cannot support a Proven status for any column; kept only as background context, not cited in any status.
netskope.com · Checked 12 Sept 2026
- FIN-345RejectedProvider-authoredOther
- Named service:
- Netskope Trust Portal
- Regulatory regime:
- Not stated
You need to enable JavaScript to run this app
Netskope's Trust Portal is a JavaScript application; the fetch tool could only retrieve the page shell and metadata, not the actual real-time or historical trust/performance content.
Does not prove: No compliance, uptime or performance content was retrievable; cannot be used as evidence for any column despite being the provider's named trust portal.
trust.netskope.com · Checked 12 Sept 2026
- FIN-346RejectedProvider-authoredOther
- Named service:
- Netskope One CASB, Private Access, NG-SWG, NewEdge
- Sites, branches, users:
- 8,000+ employees
- Countries, regions:
- Global
- Regulatory regime:
- Not stated
- Outcome:
- Network availability improved from 98.5% to 99.9%
We can control the data that our applications are accessing. Granularity and visibility are the real benefits.
BDO, the world's fifth-largest accountancy, consultancy and assurance firm, deployed Netskope CASB, Private Access and NG-SWG to replace legacy VPN and improve network availability.
Does not prove: BDO is an accounting and professional services firm, not a bank, insurer, payments or asset management company, so it does not qualify as a named financial institution under this brief despite quantified outcomes.
netskope.com · Checked 12 Sept 2026
- FS-053RejectedProvider-authoredExisting source lead
More than 4,000 customers, including three of the five largest financial services companies on the Fortune 100, trust our unified secure access service edge (SASE) platform, Netskope One.
The best evidenced sector by a clear margin. Four named customer stories on the industry page (Apex Group, JLL, RSM Australia, Ascensus), plus BMO and The Auto Club Group as logos, plus explicit DORA, GDPR, NIS 2 and PCI references. The Fortune 100 claim is a vendor claim and is not independently verified here.
Does not prove: Investor relations site of a NASDAQ listed company (NTSK). Statements here carry securities law accountability, so the Fortune 100 customer claim is more reliable than ordinary marketing copy. | Not found on page
investors.netskope.com · Checked 29 Jul 2026
04Barracuda SecureEdge
9 of 28 proven11 of 17 sourcesOpenClose
Barracuda SecureEdge on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Barracuda documents solid baseline platform facts for SecureEdge: named data centre regions in the UK, EU, US and Canada, 30 day log retention, encryption in transit and at rest, a 99.5% monthly availability commitment, and a published sub-processor list. A separate CloudGen Firewall whitepaper explicitly connects the product to PCI DSS cardholder data segmentation. However no named bank, credit union, insurer or asset manager using SecureEdge or CloudGen Firewall SD-WAN was found on any page opened, so branch connectivity, trading connectivity, resilience testing and remote workforce claims all lack a financial services deployment example. There is no evidence connecting the named service to FCA, PRA, DORA, FFIEC, GLBA, NYDFS, OSFI or SWIFT CSP regimes, and PCI DSS is listed as in-progress rather than certified. An IT decision maker in financial services would need to treat the platform facts as credible but unproven in an FS operating context, and would need to request references directly from Barracuda.
Gaps and unknowns: No named financial services customer case study exists for SecureEdge or CloudGen Firewall SD-WAN, leaving branch/office connectivity, trading connectivity, resilience/DR testing, third-party access control, managed SOC and network visibility for FS customers unevidenced. All four named regulatory regime columns (UK FCA/PRA, EU DORA, US FFIEC/GLBA/NYDFS/SEC, Canada OSFI) and SWIFT CSP alignment are unevidenced; closing these would require a published compliance statement or an FS customer reference naming the regime. CASB/DLP and a completed (rather than in-progress) PCI DSS attestation for the named service are also missing.
- Branch and office connectivity
- Not found
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Proven
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Proven
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Not found
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Proven
- Incident notification support
- Partial
- Concentration risk and subcontractor transparency
- Proven
- Exit and portability
- Proven
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Proven
- North America delivery
- Proven
- Global delivery
- Proven
Sources (17)
- FIN-125AcceptedProvider-authoredCompliance attestation or statement
Barracuda Trust Centre - Certifications page
- Named service:
- Barracuda (company-wide)
- Standard or regulation:
- SOC 2; ISO 27001; PCI DSS; FIPS
- Regulatory regime:
- Not stated
PCI DSS (SAQ-D attestation in progress)
Barracuda lists PCI DSS SAQ-D attestation as an in-progress certification for the company generally; it is not shown as achieved and is not tied to SecureEdge or CloudGen Firewall by name.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page text reads 'PCI DSS (SAQ-D attestation in progress)' - quote omitted 'in progress' qualifier). Re-quote verbatim. This is a company-wide certification list, not product-specific to SecureEdge or CloudGen Firewall, and PCI DSS is listed as in-progress rather than achieved. Does not prove an AoC for the named service. [2026-09-15] Re-quoted verbatim using the checker's own already-confirmed page wording - no fresh fetch needed, the exact sentence was already recorded in the check note.
· Published 10 Jun 2026 · Checked 15 Sept 2026 · Supports: PCI DSS alignment
- FIN-128AcceptedProvider-authoredCompliance attestation or statement
Data Center Locations - Barracuda Trust Center
- Named service:
- Barracuda SecureEdge
- Countries, regions:
- UK, EU (multiple), US, Canada, and other global regions
- Regulatory regime:
- Multiple
West Europe (westeurope); Austria East (austriaeast); Germany West Central (germanywestcentral); France Central (francecentral)
Barracuda's data centre locator names SecureEdge specifically against a list of Azure/AWS regions that includes UK South, Canada Central and US regions alongside multiple EU regions.
Does not prove: Confirms hosting regions for SecureEdge but does not name a UK, US or Canadian financial services customer, and does not state which customer data types map to which region.
trust.barracuda.com · Checked 12 Sept 2026 · Supports: Data residency and sovereignty, North America delivery, Global delivery, UK delivery
- FIN-129AcceptedProvider-authoredCompliance attestation or statement
Security - Barracuda Trust Center
- Named service:
- Barracuda (all products)
- Regulatory regime:
- Not stated
Barracuda will promptly (1) notify the relevant Customer of the Security Incident; (2) investigate the Security Incident; and (3) take reasonable steps to contain and mitigate the effects of the Security Incident.
Barracuda commits to promptly notify, investigate and mitigate security incidents, but does not state a specific notification timeframe such as a number of hours or days.
Does not prove: No defined timeframe (only 'promptly'), and the commitment is company-wide rather than SecureEdge-specific.
trust.barracuda.com · Checked 12 Sept 2026 · Supports: Incident notification support
- FIN-132AcceptedProvider-authoredOther
Zero Trust Network Access Solution & Security Platform | Barracuda Networks
- Named service:
- Barracuda SecureEdge Access
- Regulatory regime:
- Not stated
SecureEdge Access supports SSO with access credentials from Microsoft Entra ID, Google Workspace, Okta, Okta Workforce, OpenID Connect, any other SAML-compatible services, and even generic email code sign-on.
SecureEdge Access documents ZTNA with SSO/IdP integration (Entra ID, Okta, Google Workspace, SAML) and SCIM provisioning, and describes remote access to applications from any client without bandwidth limits.
Does not prove: General product documentation, not financial-services specific; no named financial customer or FS-specific remote-workforce outcome.
barracuda.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Remote and hybrid workforce
- FIN-133AcceptedProvider-authoredCompliance attestation or statement
PCI DSS Compliance with Barracuda CloudGen Firewall
- Named service:
- Barracuda CloudGen Firewall
- Standard or regulation:
- PCI DSS 3.2.1
- Regulatory regime:
- Not stated
Barracuda CloudGen Firewall can help your organization satisfy every specific requirement of PCI DSS compliance version 3.2.1
Barracuda's own whitepaper explains how CloudGen Firewall can be used as a network segmentation gateway to isolate a cardholder data environment and to extend segmentation policy into AWS, Azure and Google Cloud, mapped against PCI DSS 3.2.1 requirements.
Does not prove: This is compliance-mapping guidance for customers to achieve PCI DSS themselves, not a PCI DSS Attestation of Compliance or certification for the CloudGen Firewall service itself, and it names no financial institution.
assets.barracuda.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Payment and cardholder data segmentation, Network segmentation and zoning, PCI DSS alignment
- FIN-135AcceptedProvider-authoredOther
Barracuda SecureEdge: Features | Barracuda Networks
- Named service:
- Barracuda SecureEdge
- Regulatory regime:
- Not stated
Set role and attribute-based controls to grant contextual access to trusted users and devices
SecureEdge documents role- and attribute-based access controls and a dashboard for monitoring users, threats and infrastructure status, but does not describe CASB, DLP, SOC or a formal change-management/audit process.
Does not prove: No financial services context; RBAC is documented but a full change-control/configuration-audit process is not described on this page.
barracuda.com · Checked 12 Sept 2026 · Supports: Change control and configuration governance, Network visibility and reporting
- FIN-136AcceptedProvider-authoredCompliance attestation or statement
Product & Service Description - SecureEdge Appliances and SaaS Service
- Named service:
- Barracuda SecureEdge
- Countries, regions:
- US, EMEA (West Europe), plus additional PoPs across Europe, Middle East, Americas and APAC
- Regulatory regime:
- Multiple
- Outcome:
- 99.5% monthly availability commitment for SecureEdge and the SecureEdge Manager
During a subscription period, Barracuda keeps data in the Service for 30 days
Barracuda's SecureEdge product and service description states a 99.5% monthly availability commitment, that log and configuration data is encrypted in transit and at rest, that data is retained for 30 days during the subscription and up to 30 days after termination for the customer to download, and that reporting data resides in named Azure regions (US East for US data, West Europe for EMEA and global manager data).
Does not prove: This is a general commercial terms document, not financial-services specific; it names no financial customer, no FIPS validation, and the 99.5% figure is an availability commitment rather than a tested RTO/RPO or DR test result.
assets.barracuda.com · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention, Resilience and tested recovery, Data residency and sovereignty, Encryption and key management, Exit and portability, Global delivery
- FIN-137AcceptedProvider-authoredOther
Barracuda SecureEdge Access: Features | Barracuda Networks
- Named service:
- Barracuda SecureEdge Access
- Regulatory regime:
- Not stated
Integration with your existing Azure Active Directory
SecureEdge Access documents Azure Active Directory integration and role- and attribute-based access controls; no CASB, DLP, SOC or MFA-specific claims appear on this page.
Does not prove: No financial services context; MFA, CASB and DLP are not mentioned on this page.
barracuda.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access
- FIN-139AcceptedProvider-authoredCompliance attestation or statement
Supplier Information - Barracuda Trust Center
- Named service:
- Barracuda (all products)
- Regulatory regime:
- Not stated
Sub-Processors and Critical Vendors View online
Barracuda's trust centre links to a published sub-processors and critical vendors list.
Does not prove: Index page pointing to the actual sub-processor list; company-wide, not SecureEdge-specific.
trust.barracuda.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency
- FIN-140AcceptedProvider-authoredCompliance attestation or statement
Sub-Processors and Critical Vendors - Barracuda Trust Center
- Named service:
- Barracuda (all products)
- Regulatory regime:
- Not stated
The following colocation data centers provide physical and environmental security to the Barracuda infrastructure; they don't have logical access.
Barracuda publishes a named list of sub-processors and critical vendors (including AWS, Microsoft Azure, Equinix, Redcentric, CoreSite, Canada15Edge and others) and distinguishes colocation providers with no logical data access from data-processing vendors.
Does not prove: This is a company-wide sub-processor list, not filtered to SecureEdge specifically, and contains no explicit multi-region independence statement beyond the colocation distinction.
trust.barracuda.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency
- FIN-528AcceptedProvider-authoredCompliance attestation or statement
Barracuda Trust Center Product Guide
- Named service:
- Barracuda's DORA Article 30 Amendment (Trust Center product guide)
- Standard or regulation:
- DORA Article 30
- Regulatory regime:
- EU
Product guide lists a 'DORA Article 30 Amendment' as an available legal document, alongside a dedicated DORA compliance category.
Harry personally verified this live 2026-09-15. Confirms and strengthens the earlier finding (FS-107/FIN-107) of a named DORA Article 30 Amendment document, now located within Barracuda's structured product guide rather than just the Trust Center navigation. Still platform-wide rather than confirmed SecureEdge-specific, and the amendment's actual terms were not read, so kept at Partial.
Does not prove: Added 2026-09-15, Harry-verified. Corroborates and locates precisely the DORA Article 30 Amendment already noted for Barracuda earlier in this project.
trust.barracuda.com · Checked 15 Sept 2026 · Supports: EU DORA alignment
- FIN-126RejectedProvider-authoredFinancial services solution page
Financial Services Cybersecurity: Cybersecurity in Financial Sector | Barracuda Networks
- Named service:
- Barracuda (general)
- Regulatory regime:
- Not stated
Financial services are a prime target for cyber attacks. Learn how Barracuda can help.
The page is a generic financial services landing page that links to SecureEdge, CloudGen Firewall and SD-WAN in navigation menus but does not discuss them or name any customer, regulation or capability on the page itself.
Does not prove: No named customer, no named regulation, no discussion of SecureEdge/CloudGen/SD-WAN capabilities on the page itself; only navigation links. Does not support any column.
barracuda.com · Checked 12 Sept 2026
- FIN-127RejectedProvider-authoredOther
Trust Center | Barracuda Networks
- Named service:
- Barracuda (all products)
- Regulatory regime:
- Not stated
Barracuda cloud-based SaaS offerings, and associated customer data (if applicable), are available in the Data center locator
This is an index page pointing to separate data residency, privacy, incident notification and sub-processor pages, which were opened and cited individually.
Does not prove: Index/navigation page only; no product-specific or capability-specific facts of its own beyond links, so the specific subpages are cited instead.
trust.barracuda.com · Checked 12 Sept 2026
- FIN-130RejectedProvider-authoredOther
SASE Platform & Cloud-First SASE Solution | Barracuda SecureEdge | Barracuda Networks
- Named service:
- Barracuda SecureEdge
- Regulatory regime:
- Not stated
SASE is an integrated service that provides comprehensive secure access for modern computing environments, reduces complexity and costs
General marketing description of SecureEdge as a SASE platform covering SD-WAN, ZTNA and Firewall-as-a-Service, with no customer names or measurable claims.
Does not prove: Generic marketing content only; no financial services context, no named customer, no specific figures.
barracuda.com · Checked 12 Sept 2026
- FIN-131RejectedProvider-authoredOther
SecureEdge Logs | Barracuda Campus
- Named service:
- Barracuda SecureEdge
- Regulatory regime:
- Not stated
Not applicable - page describes log types and filtering only
This product documentation page describes the types of logs available in SecureEdge and how to filter them, but does not state a retention period or SIEM export detail.
Does not prove: Does not state retention period or SIEM export; the retention fact was instead found in the Product and Service Description document.
documentation.campus.barracuda.com · Checked 12 Sept 2026
- FIN-134RejectedProvider-authoredOther
Barracuda SecureEdge - Specifications
- Named service:
- Barracuda SecureEdge
- Regulatory regime:
- Not stated
For information on mandatory and optional service/feature subscription, see SecureEdge Licensing documentation
This datasheet covers hardware form factors, throughput and physical specifications for SecureEdge appliances; it does not cover SLA, encryption, MFA, CASB, DLP, SOC or reporting.
Does not prove: Hardware specification sheet only; no SLA, security control or compliance detail relevant to any of the 28 columns.
assets.barracuda.com · Checked 12 Sept 2026
- FIN-138RejectedProvider-authoredOther
Barracuda SecureEdge: Resources | Barracuda Networks
- Named service:
- Barracuda SecureEdge
- Regulatory regime:
- Not stated
Not applicable - resource hub with filters only, no case studies rendered in fetched content
This is a filterable resource hub for SecureEdge; no individual case studies, and no financial services or named customer content, were present in the fetched page content.
Does not prove: No case study content retrievable from this page; searches for named financial institution case studies using SecureEdge or CloudGen Firewall found none.
barracuda.com · Checked 12 Sept 2026
05Aryaka
10 of 28 proven12 of 16 sourcesOpenClose
Aryaka on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Aryaka has one substantive named financial services customer found in this research, Calypso Technology, a financial software company that connected more than 20 offices across 18 countries and over 35,000 users on Aryaka's service, evidenced by a 2013 press release and an undated case study. General platform compliance documentation, including ISO 27001, SOC 2 Type II, encrypted transport and Universal ZTNA with SAML and MFA, is proven for the platform overall but is not linked to Calypso or any other named financial institution. No evidence was found connecting Aryaka's named service to UK FCA or PRA rules, EU DORA, US FFIEC, GLBA, NYDFS or SEC rules, Canadian OSFI rules, PCI DSS certification, or SWIFT CSP, and Aryaka's own FIPS page confirms the service is not FIPS 140-2 or 140-3 certified. UK and North American delivery is evidenced through Aryaka's published point of presence list, covering London, ten US cities and Toronto, rather than through named financial customers based there. Overall, Aryaka's evidence for financial services IT decision makers rests on general security certifications and one dated fintech customer story rather than on regime-specific regulatory proof.
Gaps and unknowns: No evidence was found for trading or low-latency workloads, network segmentation, cardholder data segmentation, third-party or subcontractor access controls, change control governance, subcontractor transparency, exit and portability terms, or any of the four named regulatory regimes (FCA/PRA, DORA, US federal and state rules, OSFI), and PCI DSS and SWIFT CSP alignment remain unproven. These gaps would be closed by a current, dated financial services case study naming a bank, insurer or asset manager, a published sub-processor list, a PCI DSS Attestation of Compliance for the named service, and an explicit statement mapping the service to FCA SYSC 15A, DORA Article 30, US FFIEC or NYDFS Part 500, or OSFI B-13.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Not found
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Proven
- Data residency and sovereignty
- Partial
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Proven
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Not found
- Incident notification support
- Proven
- Concentration risk and subcontractor transparency
- Partial
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Proven
- North America delivery
- Proven
- Global delivery
- Proven
Sources (15)
- FIN-101AcceptedProvider-authoredNamed customer case study
Calypso Technology SD-WAN Case Study
- Named financial institution:
- Calypso Technology
- Named service:
- Aryaka SmartServices
- Sites, branches, users:
- 20+ global sites; 35,000 users in 60+ countries; 800+ employees managed by IT
- Countries, regions:
- 18 countries (offices); 60+ countries (users)
- Regulatory regime:
- Not stated
- Outcome:
- 100% 24/7 availability, reliable network performance and reduced WAN management overhead for a lean IT team
"The saving grace of Aryaka is that it allows us to manage the WAN and our IT with such a lean staff." - Russell Wong, Global Director - IT, Calypso Technology
Calypso Technology, a global financial software company, deployed Aryaka SmartServices to connect more than 20 offices in 18 countries serving over 35,000 users, achieving 100% 24/7 availability and letting a lean IT team rely on Aryaka's proactive monitoring and support.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (PDF loaded ok; near-exact match but actual wording is 'Seeing an alert before I go to bed at night and knowing that Aryaka is already diving into it, so that wh). Re-quote verbatim. No publication date is shown; does not mention trading-floor latency, PCI or cardholder data, network segmentation, encryption specifics, or any named regulatory regime; the SmartServices branding reflects Aryaka's legacy product naming. [2026-09-15] Re-quoted 2026-09-15 from the live webpage version of this case study (aryaka.com/?p=26019) rather than the original PDF URL, which could not be re-fetched directly - content matches (same customer, same Russell Wong quote source), so treated as equivalent.
aryaka.com · Checked 15 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Network visibility and reporting, Branch and office connectivity, Resilience and tested recovery, Remote and hybrid workforce, Managed operations and SOC, Global delivery
- FIN-102AcceptedProvider-authoredContract award
Global Financial Leader Calypso Technology Trades Up to Aryaka for WAN Optimization
- Named financial institution:
- Calypso Technology
- Named service:
- WAN Optimization as-a-Service, Network as-a-Service, Application Delivery as-a-Service
- Sites, branches, users:
- Distributed teams and remote employees around the world
- Countries, regions:
- Global (specific countries not stated)
- Regulatory regime:
- Not stated
- Outcome:
- SCP over SSH ran 20 times faster; SVN source-code checkout ran 13 times faster; deployment completed in hours; bandwidth burst to 140% of subscribed levels
SCP over SSH runs 20X faster over Aryaka. SVN source-code checkout runs 13X faster.
A 2013 wire press release states that Calypso Technology, described as a global financial and software services company serving banks, prime brokers and buy-side firms, adopted Aryaka's WAN optimization, network and application delivery as-a-service for distributed teams and remote employees.
Does not prove: Dated 2013, predates Aryaka's current SD-WAN/SASE branding; does not mention trading-floor latency, PCI, segmentation, or any regulatory regime; Calypso is a financial software vendor to banks rather than a bank itself.
globenewswire.com · Published 11 Mar 2013 · Checked 12 Sept 2026 · Supports: Branch and office connectivity, Remote and hybrid workforce
- FIN-105AcceptedProvider-authoredCompliance attestation or statement
Aryaka Service Level Agreement: Definitions And Details
- Named service:
- Aryaka PrivateCore, L3EnhancedCore, ANAP High Availability, SmartCDN, Hosted Firewall
- Regulatory regime:
- Not stated
- Outcome:
- 99.999% uptime for PrivateCore services; ANAP failover in under 5 minutes; Tunnel Down notification within 30 minutes
Failover to the Standby ANAP in less than 5 minutes
Aryaka's published SLA commits to failover from a primary to standby ANAP appliance in under five minutes, tunnel-down notification to customers within 30 minutes, and uptime targets of up to 99.999% for PrivateCore services, with service credits for missed targets.
Does not prove: Not specific to financial services customers; states contractual failover and notification timings but no RTO/RPO terminology or DR test evidence, and no named FS customer.
aryaka.com · Checked 12 Sept 2026 · Supports: Resilience and tested recovery, Incident notification support
- FIN-106AcceptedProvider-authoredContradiction
FIPS Compliance Readiness For Federal Customers
- Named service:
- Aryaka security services
- Standard or regulation:
- FIPS 140-2 / FIPS 140-3
- Regulatory regime:
- Not stated
Aryaka is not currently FIPS 140-2 or 140-3 certified across the full product stack.
Aryaka states it is not currently FIPS 140-2 or 140-3 certified across its full product stack, but claims a FIPS-aligned posture using FIPS-validated cryptographic modules and restricted TLS 1.2/1.3 cipher suites, with formal certification under evaluation for federal and defence demand.
Does not prove: Confirms that formal FIPS validation is not in place; used only as a limitation on the encryption and key management column, not as positive proof of certification, and is not financial-services specific. [2026-09-15, capability assigned per Robert's check] This is DISCONFIRMING evidence: the source states Aryaka is NOT currently FIPS 140-2/140-3 certified across the full product stack. Accepted as an accurate absence-of-certification finding, not as support for a Proven/Partial claim - should not be used to justify any positive rating.
aryaka.com · Published 29 Sept 2025 · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-107AcceptedProvider-authoredCompliance attestation or statement
Security FAQs | Universal ZTNA, AI Secure & Next-Gen DLP | Aryaka
- Named service:
- Aryaka Universal ZTNA; Aryaka Next-Gen DLP
- Standard or regulation:
- GDPR; HIPAA; PCI (referenced generically for DLP audit packs)
- Regulatory regime:
- Not stated
Standards-based SAML with major IdPs (e.g., Okta, Entra ID, etc.); we inherit MFA/SSO and can apply step-up based on risk/posture.
Aryaka's security FAQ states that Universal ZTNA integrates with SAML identity providers such as Okta and Entra ID, inheriting MFA/SSO with risk-based step-up, and that Next-Gen DLP provides retention controls, RBAC and SIEM-exportable audit logs, with audit packs mapped to GDPR, HIPAA and PCI; it also notes that data residency options must be confirmed per customer region.
Does not prove: General FAQ content, not tied to a named financial services customer; the PCI reference is only that DLP audit packs are mapped to PCI, not a PCI DSS Attestation of Compliance for the service; data residency answer is vague rather than a firm regional commitment.
aryaka.com · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention, Data residency and sovereignty, Identity and zero trust access, Encryption and key management, Cloud and SaaS data controls, PCI DSS alignment
- FIN-108AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Aryaka
- Standard or regulation:
- GDPR; CCPA/CPRA; VCDPA; CPA; CTDPA
- Regulatory regime:
- Not stated
Your Personal Information may be stored and processed in any country or region where we have facilities or engage service providers
Aryaka's privacy policy states personal information may be stored and processed in any country or region where Aryaka or its service providers have facilities, including the United States, and uses standard contractual clauses for EU/UK transfers, with retention tied to business need rather than a fixed period.
Does not prove: Shows that Aryaka does not commit to regional data residency for personal data by default; does not name a financial services customer or a specific management-plane residency guarantee for the UK, EU, US or Canada.
aryaka.com · Checked 12 Sept 2026 · Supports: Data residency and sovereignty
- FIN-109AcceptedProvider-authoredIndependent analysis
- Named service:
- Aryaka Managed SD-WAN
- Sites, branches, users:
- Survey of 250 UK financial services IT/business decision makers (50+ employees, ~GBP 8m average IT procurement budget)
- Countries, regions:
- UK
- Regulatory regime:
- UK
- Outcome:
- 52% of UK financial services firms lack confidence in meeting regulatory obligations; 58% say their cloud security posture needs improvement
"This research demonstrates that now is a crucial time for the UK's financial services sector to move to the cloud." - Ian McEwan, Senior Vice President of International Sales, Aryaka
A joint Aryaka and Cloud Industry Forum survey of 250 UK financial services IT and business decision makers found high cloud adoption alongside gaps in confidence around regulatory compliance and cloud security posture, with an Aryaka SVP commenting that cloud migration must not compromise security and regulatory requirements.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page loaded; actual text reads 'how they achieve this is more relevant than ever and it is critical that the move to the cloud does not compromise security, reg). Re-quote verbatim. No named financial institution or deployment; general survey commentary rather than a connection of Aryaka's product to a specific FS regulatory outcome; does not name FCA, PRA or DORA. [2026-09-15] Re-quoted verbatim, live-verified. This is a Cloud Industry Forum/Aryaka survey of the UK FS sector generally, not a named institution or product deployment - correctly stays sector-context evidence, not named-customer proof.
aryaka.com · Checked 15 Sept 2026 · Supports: UK delivery
- FIN-110AcceptedProvider-authoredOther
Aryaka Global Points-of-Presence (PoPs)
- Named service:
- Aryaka Unified SASE
- Countries, regions:
- US: Ashburn, Atlanta, Chicago, Dallas, Denver, Los Angeles, Miami, Newark, San Jose, Seattle; Canada: Toronto; UK: London; plus EMEA and APAC PoPs
- Regulatory regime:
- Not stated
fast and reliable cloud and SaaS access from any location in the world
Aryaka lists points of presence including ten US cities, Toronto in Canada, and London in the UK, alongside EMEA and APAC coverage, as part of its global network delivery footprint.
Does not prove: Confirms geographic PoP footprint only; does not name any financial services customer using these PoPs and does not describe UK-based support or a UK data centre beyond the London PoP.
aryaka.com · Checked 12 Sept 2026 · Supports: North America delivery, Global delivery, UK delivery
- FIN-111AcceptedProvider-authoredOther
Aryaka High Availability: Resilient, Secure, And Seamless Connectivity
- Named service:
- Aryaka High Availability (ANAP)
- Regulatory regime:
- Not stated
Virtual ANAP Redundancy Protocol (VARP)
Aryaka's High Availability datasheet describes dual-ISP redundancy, active-active SMARTlink link usage and ANAP failover using VARP, without quantified RTO or RPO metrics.
Does not prove: No RTO/RPO figures, no DR test evidence, and no named financial services customer; a general architecture datasheet only.
aryaka.com · Checked 12 Sept 2026 · Supports: Resilience and tested recovery
- FIN-524AcceptedProvider-authoredCompliance attestation or statement
Aryaka Trust Center | Powered by SafeBase
- Named service:
- Aryaka Unified SASE / SD-WAN
- Standard or regulation:
- SSAE-18 SOC 2 Type II; ISO 27001
SafeBase-hosted Trust Center describing Aryaka's security programme, customer-data protection, SSAE-18 SOC 2 Type II, ISO 27001, encrypted IPsec, and compliance/assurance documentation.
Harry personally verified this live 2026-09-15. A structured Trust Center exists with real certifications, but the landing page alone doesn't connect Aryaka's named service to a specific SLA-backed incident-notification commitment or a detailed subprocessor list with audit/objection rights - graded Partial pending the underlying documents themselves.
Does not prove: Added 2026-09-15, Harry-verified. Trust Center landing page only - underlying detailed documents not individually opened.
trustcenter.aryaka.com · Checked 15 Sept 2026 · Supports: Concentration risk and subcontractor transparency, Incident notification support
- FS-005AcceptedProvider-authoredExisting source lead
Resources | Aryaka SD-WAN & SASE
Financial Services Company Calypso
Graded yes on a named customer (Calypso, a capital markets software firm) presented by Aryaka explicitly as a financial services company, plus 'Banking/Financial Services' being one of only six labels in Aryaka's own published industry filter. Confidence is medium not high because the evidence is an undated video testimonial rather than a written case study, there is no dedicated financial services industry page to sit alongside manufacturing, transport and professional services, and no banking accreditation or regulatory framework was found.
Does not prove: Supplier's own resource library. Its 'By Industries' filter is the authoritative published list of the sectors Aryaka itself indexes: Manufacturing, Banking/Financial Services, Transportation & Logistics, Business Services, Energy, Retail. Useful as a negative check for the four sectors absent from it. | Confirmed - exact match [2026-09-15, capability assigned per Robert's check] Calypso resource listing page - same underlying customer as FIN-101; weak on its own, corroborative only.
aryaka.com · Checked 29 Jul 2026 · Supports: Branch and office connectivity
- FS-007AcceptedProvider-authoredExisting source lead
Financial Services Company Calypso On Aryaka's Customer Support
Financial Services Company Calypso
Graded yes on a named customer (Calypso, a capital markets software firm) presented by Aryaka explicitly as a financial services company, plus 'Banking/Financial Services' being one of only six labels in Aryaka's own published industry filter. Confidence is medium not high because the evidence is an undated video testimonial rather than a written case study, there is no dedicated financial services industry page to sit alongside manufacturing, transport and professional services, and no banking accreditation or regulatory framework was found.
Does not prove: Supplier's own customer video page. The only named financial services customer found. Undated video testimonial rather than a written case study, hence medium confidence. | Confirmed - exact match [2026-09-15, capability assigned per Robert's check] Support-specific angle on the same Calypso case.
aryaka.com · Checked 29 Jul 2026 · Supports: Managed operations and SOC
- FIN-112RejectedProvider-authoredFinancial services solution page
The Financial Case For Unified SASE As A Service: Cut Costs & Accelerate ROI | Aryaka
- Named service:
- Aryaka Unified SASE as a Service
- Regulatory regime:
- Not stated
Discover how Aryaka's Unified SASE helps enterprises cut costs, reduce CapEx, and boost ROI
This page is a general financial and ROI ebook about Unified SASE as a Service, not a case study naming a financial services sector customer.
Does not prove: Despite its URL and title referencing 'financial', this is a cost/ROI business case document, not evidence about the financial services industry or any named financial institution.
aryaka.com · Checked 12 Sept 2026
- FIN-113RejectedProvider-authoredOther
Aryaka Customer Case Studies: Real-World SD-WAN & SASE Success Stories
- Named service:
- Aryaka Unified SASE / SD-WAN
- Regulatory regime:
- Not stated
This URL, expected to be the Calypso case study, instead rendered as a general case studies listing page naming other customers (Thetford, Lauridsen Group, AL-KO, Albemarle, Hubbell) and no financial services company.
Does not prove: Content did not match the expected Calypso case study; no financial services evidence found on this specific URL, so it is not used as a source (the separate Calypso PDF was used instead).
aryaka.com · Checked 12 Sept 2026
- FS-006SupersededProvider-authoredExisting source lead
See Why Customers Rank Aryaka #1 In SD-WAN On G2 Summer 2026
- Named service:
- Aryaka Unified SASE / SD-WAN
Financial Services Company Calypso
Graded yes on a named customer (Calypso, a capital markets software firm) presented by Aryaka explicitly as a financial services company, plus 'Banking/Financial Services' being one of only six labels in Aryaka's own published industry filter. Confidence is medium not high because the evidence is an undated video testimonial rather than a written case study, there is no dedicated financial services industry page to sit alongside manufacturing, transport and professional services, and no banking accreditation or regulatory framework was found.
Does not prove: Supplier's own review round-up page. Names Cathay, World Kinect, Hubbell, NVIDIA, Makino and Pilot, and states the industries customers span. Vendor-curated selection of third-party reviews, so treat the review scores as promotional. | New Source: https://www.aryaka.com/videos/financial-services-company-calypso-on-aryakas-customer-support/
aryaka.com · Checked 29 Jul 2026
06Cato Networks
9 of 28 proven12 of 16 sourcesOpenClose
Cato Networks on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Cato Networks has clear, named evidence of financial services deployments for branch connectivity, cloud on-ramp and remote workforce security, strongest in the US credit union segment through Guardian Credit Union and in insurance through the Philippines-based Standard Insurance. Data residency, sub-processor transparency and log retention are documented in Cato's own compliance material, though FIPS 140-2/140-3 validation is explicitly absent. No evidence connects the named service to FCA/PRA, DORA, US banking regulation (FFIEC, GLBA, NYDFS) or OSFI, and trading/low-latency, cardholder-data segmentation and SWIFT-specific evidence are also absent. The strongest named customer overall is Guardian Credit Union for North American delivery and branch/remote-workforce evidence. IT decision makers in regulated UK, EU or Canadian financial firms would need Cato to supply regime-specific compliance statements before relying on public material alone.
Gaps and unknowns: No FCA/PRA, DORA, FFIEC/GLBA/NYDFS or OSFI alignment statement was found for the named service; a compliance statement or contractual annex addressing these regimes would close this. Trading/low-latency, payment/cardholder data segmentation, SWIFT CSP alignment, managed SOC for FS customers, change control governance and exit/portability terms are also unevidenced and would need dedicated documentation or named case studies to confirm.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Proven
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Proven
- Data residency and sovereignty
- Proven
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Proven
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Proven
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Not found
- Incident notification support
- Partial
- Concentration risk and subcontractor transparency
- Proven
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Partial
- North America delivery
- Partial
- Global delivery
- Partial
Sources (14)
- FIN-157AcceptedProvider-authoredNamed customer case study
Guardian Credit Union Improves Network Control & Security with Cato
- Named financial institution:
- Guardian Credit Union
- Named service:
- Cato SASE Platform (with SD-WAN)
- Sites, branches, users:
- 20 sites across a dozen Alabama counties
- Countries, regions:
- United States (Alabama)
- Regulatory regime:
- US
- Outcome:
- Improved network visibility and control, reduced operational complexity, cloud traffic no longer backhauled to the datacentre
Guardian Credit Union, an Alabama-based credit union, had a private network connecting 20 sites across a dozen Alabama counties.
Guardian Credit Union, a US credit union with 20 sites across Alabama, replaced its private network with Cato's SASE platform for network visibility, control and remote worker support.
Does not prove: Does not address trading/low latency, DC or cloud on-ramp naming, cardholder data segmentation, PCI, or any regulatory regime; page last modified 2024-09-26 but no original publish date shown.
catonetworks.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Branch and office connectivity, Remote and hybrid workforce
- FIN-158AcceptedProvider-authoredNamed customer case study
Cato SASE Cloud secures networking of Bank Avera locations and its mobile employees
- Named financial institution:
- Bank Avera
- Named service:
- Cato SASE Cloud (NGFW, SWG, anti-malware, IPS, Cato Sockets SD-WAN)
- Sites, branches, users:
- Twelve locations, around 45,000 customers
- Countries, regions:
- Switzerland (greater Zurich area)
- Regulatory regime:
- EU
- Outcome:
- Complexity was reduced, uptime increased and processes simplified; new users, bandwidth and locations can be easily integrated
Bank Avera, which has been rooted in the greater Zurich area since 1828, serves around 45,000 satisfied customers via a network of twelve locations.
Bank Avera, a Swiss regional bank with twelve locations, uses Cato SASE Cloud to secure branch connectivity and mobile/home-working employees on one platform.
Does not prove: Switzerland is not UK, EU (post-Brexit EU membership), US or Canada for the regulatory columns in this brief; no PCI, DORA, resilience metrics or cardholder data segmentation stated.
catonetworks.com · Published 25 Nov 2021 · Checked 12 Sept 2026 · Supports: Network segmentation and zoning, Branch and office connectivity, Remote and hybrid workforce
- FIN-159AcceptedProvider-authoredNamed customer case study
How MoonPay Stopped Blocking AI and Started Governing It
- Named financial institution:
- MoonPay
- Named service:
- Cato AI Security
- Standard or regulation:
- PCI Level 1; SOC 2 Type 2; ISO 27001/27018/27701
- Regulatory regime:
- Not stated
- Outcome:
- Network-layer monitoring of prompts and responses, blocking of sensitive data such as crypto wallet addresses from being sent to AI tools, and anonymising outbound data
I could secure the data coming into the computers. I could secure the data going out.
MoonPay, a crypto payments fintech, uses Cato AI Security to monitor and control AI tool usage and prevent sensitive data such as wallet addresses leaving the organisation.
Does not prove: Case is about AI governance/DLP only, not branch connectivity, SD-WAN, segmentation, resilience or any named regulatory regime; PCI/SOC2/ISO are cited as MoonPay's own certifications, not a Cato attestation for the named service.
catonetworks.com · Checked 12 Sept 2026 · Supports: Cloud and SaaS data controls, Remote and hybrid workforce
- FIN-160AcceptedProvider-authoredCompliance attestation or statement
Security, Compliance and Privacy | Cato Networks
- Named service:
- Cato SASE Cloud Platform
- Standard or regulation:
- PCI-DSS Level 1; SOC 2; SOC 3; ISO/IEC 27001:2013; ISO/IEC 27017:2015; ISO/IEC 27018:2019; ISO/IEC 27701:2019; GDPR
- Regulatory regime:
- Not stated
Cato is PCI-DSS Level 1 certified
Cato Networks states it holds SOC 2, SOC 3, PCI-DSS Level 1, several ISO 27000-series certifications and is GDPR compliant, without naming individual financial customers.
Does not prove: General corporate certification list, does not name a financial customer or give FIPS, data residency, log retention or key management specifics; a certification list is not by itself Proven for regulatory-regime columns 20-23 per the grading rules.
catonetworks.com · Checked 12 Sept 2026 · Supports: Encryption and key management, PCI DSS alignment
- FIN-161AcceptedProvider-authoredCompliance attestation or statement
SASE Sovereignty at Cato Networks
- Named service:
- Cato Management Application (CMA) / Cato SASE Cloud
- Countries, regions:
- US, EU, India, Japan (control plane); UK, Germany, Netherlands, Italy, France, Singapore, Australia, Philippines, Israel (regional legal entities)
- Regulatory regime:
- Multiple
Customer policy, configuration, and event data is anchored to the selected region and does not leave it
Cato documents regional Cato Management Application instances in the US, EU, India and Japan, with customer configuration and event data anchored to the chosen region, and lists regional legal entities including the UK, but does not list Canada.
Does not prove: No Canada region listed for the management/data plane; document does not name a financial customer using a specific region, and gives no encryption algorithm or key-management specifics beyond who holds keys in Private CMA deployments.
knowledge.catonetworks.com · Published 22 Jun 2026 · Checked 12 Sept 2026 · Supports: Data residency and sovereignty
- FIN-162AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Cato SASE Cloud Platform
- Regulatory regime:
- Not stated
Cloud computing provider and data hosting
Cato publishes a named list of sub-processors covering general services, remote browser isolation, sandboxing and AI security services, including AWS, Datadog, Snowflake, Twilio, OpenAI and others, last updated 19 May 2026.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page lists AWS as 'Cloud computing provider and data hosting' rather than exact quoted phrasing 'Cloud computing and data hosting'). Re-quote verbatim. List names sub-processors but contains no multi-region independence statement or audit-rights language, and is not specific to financial services customers. [2026-09-15] Re-quoted verbatim using the checker's own already-confirmed page wording - no fresh fetch needed, the exact sentence was already recorded in the check note.
support.catonetworks.com · Published 19 May 2026 · Checked 15 Sept 2026 · Supports: Concentration risk and subcontractor transparency
- FIN-163AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Cato Cloud service
- Regulatory regime:
- Not stated
any instance that is Unavailable for more than six minutes of a clockhour
Cato's published SLA commits to at least 99.5 percent instance-level uptime with tiered service credits, but defines unavailability narrowly as loss of external connectivity and states no RTO, RPO or failover procedure.
Does not prove: No RTO/RPO or tested-failover commitment is stated; this is a generic commercial SLA, not a financial-services-specific resilience commitment, and does not name any FS customer.
cato.digital · Checked 12 Sept 2026 · Supports: Resilience and tested recovery
- FIN-164AcceptedProvider-authoredFinancial services solution page
SASE for Credit Unions | Cato Networks
- Named financial institution:
- Guardian Credit Union
- Named service:
- Cato SASE Cloud
- Countries, regions:
- United States
- Standard or regulation:
- PCI-DSS; NCUA policies
- Regulatory regime:
- US
- Outcome:
- Cato SASE enables compliance policies to be configured in a few days via zero-touch deployment and self-service portals
Federally insured credit unions are required to report cyber security incidents within 72 hours.
Cato's credit union solution page states that credit unions must comply with PCI-DSS and NCUA rules, including a 72-hour cyber incident reporting requirement, and features Guardian Credit Union as its case study, but does not itself state that Cato's service carries a PCI DSS attestation.
Does not prove: States the regulatory requirement credit unions face, not that Cato's own service has a PCI DSS Attestation of Compliance or a specific incident-notification SLA to customers; no FFIEC or GLBA mention.
catonetworks.com · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation, Incident notification support
- FIN-166AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Cato Data Lake
- Regulatory regime:
- Not stated
For contracts and renewals starting from January 1st, 2024, the default retention period for events is 3 months.
Cato documents a default 3-month event log retention period, with 6- and 12-month extended retention available for purchase, and free integrations to export logs to AWS S3, Azure Blob Storage or SIEM tools.
Does not prove: Retention and export are documented for the general Cato Cloud service, not specifically for a financial services customer; no audit-trail-specific retention statement is given.
knowledge.catonetworks.com · Published 24 Aug 2026 · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention
- FIN-167AcceptedProvider-authoredCompliance attestation or statement
Universal ZTNA | Cato Networks
- Named service:
- Cato Universal ZTNA
- Regulatory regime:
- Not stated
Use your SSO/MFA or Cato's user database
Cato's ZTNA platform page documents identity- and context-based access control with SSO/MFA integration, applied uniformly across users, devices and locations.
Does not prove: Generic product documentation with no financial services customer or industry context named on this page.
catonetworks.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access
- FIN-168AcceptedProvider-authoredNamed customer case study
Standard Insurance Uses Cato for Cloud Migration and Digital Transformation
- Named financial institution:
- Standard Insurance
- Named service:
- Cato SASE Platform (Cato Socket SD-WAN devices)
- Sites, branches, users:
- 60 branches, 700+ dealer/agent networks, 1,500 associates
- Countries, regions:
- Philippines
- Regulatory regime:
- Not stated
- Outcome:
- Internet bandwidth increased 10x; branch deployment reduced to minutes; security costs reduced by half
allows our branches to easily connect to the AWS cloud via the Cato network
Standard Insurance, a Philippines-based insurer with 60 branches, uses Cato's SASE platform with Cato Sockets to connect branches and route traffic to AWS through Cato Points of Presence co-located with AWS IXPs.
Does not prove: Philippines is outside the UK/EU/US/Canada regulatory scope of this brief; no PCI, resilience testing or cardholder data segmentation stated.
catonetworks.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Network segmentation and zoning, Branch and office connectivity
- FIN-165RejectedProvider-authoredContradiction
FIPS Compliance and TLS Configuration at Cato Networks
- Named service:
- Cato Networks platform
- Standard or regulation:
- FIPS 140-2; FIPS 140-3
- Regulatory regime:
- Not stated
Cato Networks is not FIPS 140-2 or 140-3 certified
Cato's own support documentation confirms Cato Networks is not FIPS 140-2 or 140-3 certified, and instead documents how to configure TLS cipher suites that align with FIPS-approved algorithms as a workaround.
Does not prove: This page disproves FIPS validation rather than supporting any capability column; kept as a contradiction record only, not used to support column 10.
support.catonetworks.com · Published 24 Jun 2025 · Checked 12 Sept 2026
- FS-014SupersededProvider-authoredExisting source lead
Customers filtered by Financial Services
Guardian Credit Union is a regional business that faced big network challenges.
Cato runs both a Financial Services and a separate Credit Union industry filter. Named customers found: Guardian Credit Union, Bank Avera and MoonPay, a crypto payments business. Conflict recorded and not resolved: the law firm Fidal is also filed under the Financial Services label on Cato's site, which inflates that filter, so the credit union and the bank are the cleaner evidence.
Does not prove: Supplier's own filtered case study listing. | New Source: https://www.catonetworks.com/customers/guardian-credit-union-improves-network-control-security-with-cato/
catonetworks.com · Checked 29 Jul 2026
- FS-015SupersededProvider-authoredExisting source lead
Customers filtered by Credit Union
Guardian Credit Union is a regional business that faced big network challenges.
Cato runs both a Financial Services and a separate Credit Union industry filter. Named customers found: Guardian Credit Union, Bank Avera and MoonPay, a crypto payments business. Conflict recorded and not resolved: the law firm Fidal is also filed under the Financial Services label on Cato's site, which inflates that filter, so the credit union and the bank are the cleaner evidence.
Does not prove: Supplier's own filtered case study listing. | New Source: https://www.catonetworks.com/customers/guardian-credit-union-improves-network-control-security-with-cato/
catonetworks.com · Checked 29 Jul 2026
07Versa Networks
8 of 28 proven15 of 19 sourcesOpenClose
Versa Networks on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Versa Networks has clear evidence for core SD-WAN branch, data-centre and segmentation capabilities in financial services, anchored by a named bank customer (RCBC in the Philippines) and an anonymised US Fortune 500 financial services company, plus product-level PCI DSS, FIPS 140-2, Common Criteria, ISO 27001 and SOC 2 documentation. EU regulatory alignment is evidenced through a specific DORA compliance mapping naming the SD-WAN, SSE and VersaONE products, and an EU sovereign SASE offering supports data residency claims for the DACH region. The main limitation is the near-total absence of UK (FCA/PRA), US banking (FFIEC/GLBA/NYDFS) and Canadian (OSFI) regulatory statements, no named UK financial services delivery evidence, and no published sub-processor list, specific log retention period or exit/data-return terms. Most named financial customer case studies (three of four) are anonymised, which weakens the strength of company-specific claims outside RCBC. IT decision makers in UK and North American regulated financial firms should treat the compliance and delivery picture as strong on paper-level certifications but thin on regime-specific and geography-specific proof for their own jurisdiction.
Gaps and unknowns: No evidence closes UK regulatory alignment (FCA/PRA), US regulatory alignment (FFIEC, GLBA, NYDFS, SEC), Canadian regulatory alignment (OSFI), SWIFT CSP alignment, managed 24x7 SOC for FS customers, third-party/outsourced access controls, sub-processor transparency, exit/portability terms, or trading/low-latency use, and UK delivery has no supporting page. These would be closed by a published UK or North American named financial services case study, a jurisdiction-specific compliance statement (equivalent to the existing DORA blog) for FCA/PRA, FFIEC/NYDFS or OSFI, a public sub-processor list and DPA, and a stated log retention period and incident notification SLA to customers.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Proven
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Proven
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Partial
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Partial
- Incident notification support
- Partial
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Proven
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Partial
- Global delivery
- Partial
Sources (19)
- FIN-436AcceptedProvider-authoredNamed customer case study
Automating and Simplifying the WAN for Financial Services IT
- Named service:
- Versa FlexVNF SD-WAN, Versa Director, Versa Analytics
- Sites, branches, users:
- 1,000 branches, 50,000 employees worldwide
- Countries, regions:
- United States, expanding into new markets
- Regulatory regime:
- Not stated
- Outcome:
- 25x bandwidth increase per branch, 4x improved reliability, 50% reduced maintenance costs, 9x faster time-to-service
single or dual low-speed (T1 – 6 Mbps) MPLS circuits with low-bandwidth LTE backup and no direct Internet access
An anonymised Fortune 500 financial services company with 1,000 branches and 50,000 employees and over $300 billion in assets deployed Versa FlexVNF SD-WAN and SD-Security to replace legacy MPLS links, citing micro-segmentation with separate control and data paths per segment.
Does not prove: Institution is anonymised, so this cannot be treated as a named financial institution; no regulatory regime named; no PCI or trading-specific detail.
versa-networks.com · Checked 12 Sept 2026 · Supports: Change control and configuration governance, Network visibility and reporting, Network segmentation and zoning, Branch and office connectivity
- FIN-437AcceptedProvider-authoredNamed customer case study
Global Financial Services Firm case study
- Named service:
- Versa Secure Cloud IP (SD-WAN Platform-as-a-Service)
- Sites, branches, users:
- Multiple branch offices across dozens of sites globally
- Countries, regions:
- Global
- Regulatory regime:
- Not stated
- Outcome:
- Shortened time-to-deploy and upgrade; improved WAN availability and efficiency
intelligent traffic steering to route around network problems, before users were affected.
An anonymised global financial services firm used Versa Secure Cloud IP with Dell uCPE hardware to segment retail and investment banking network traffic and improve resilience across a global branch footprint.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Exact phrase not found; PDF contains similar wording: 'intelligent traffic steering to route around network problems, before users were affected.'). Re-quote verbatim. Institution anonymised; no named country, no RTO/RPO figures, no trading floor or exchange connectivity explicitly named, only 'investment banking' segmentation mentioned. [2026-09-15] Re-quoted verbatim using the checker's own already-confirmed page wording - no fresh fetch needed, the exact sentence was already recorded in the check note.
versa-networks.com · Checked 15 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Network segmentation and zoning, Resilience and tested recovery
- FIN-438AcceptedProvider-authoredNamed customer case study
Global Credit Card Payments Company Modernizes WAN
- Named service:
- Versa Networks SD-WAN
- Regulatory regime:
- Not stated
- Outcome:
- Eliminated hardware device sprawl; reduced Capex, power consumption and maintenance costs; shortened provisioning timeframes
Their business could no longer be constrained by physical infrastructure
An anonymised global payments and financial/commerce technology company used Versa SD-WAN and VNFs on commodity CPE to connect branch offices, processing centres, cloud resources and mobile/IoT endpoints.
Does not prove: Institution anonymised; no PCI DSS or cardholder data segmentation explicitly named in this document despite being a payments company; no site or user counts given.
versa-networks.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Branch and office connectivity, Remote and hybrid workforce
- FIN-439AcceptedProvider-authoredCompliance attestation or statement
PCI-DSS Compliance with Versa Secure SD-WAN
- Named service:
- Versa Secure SD-WAN
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
No cardholder data is stored on the system. The data is processed and forwarded to the destination instantaneously.
Versa's whitepaper maps Versa Secure SD-WAN capabilities (VLAN/VRF segmentation, per-tenant IPsec tunnels with AES-256, AAA/SAML integration, audit logging) to specific PCI DSS requirements including firewalling, encryption, access control and monitoring.
Does not prove: This is a generic capability-to-requirement mapping, not an Attestation of Compliance (AoC) or certification, and it does not name a customer; no PCI DSS version stated.
versa-networks.com · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation, Logging, audit and evidence retention, Identity and zero trust access, Encryption and key management, PCI DSS alignment
- FIN-441AcceptedProvider-authoredCompliance attestation or statement
Privacy Policy | Versa Networks
- Named service:
- Versa Networks (corporate)
- Countries, regions:
- Global
- Regulatory regime:
- Not stated
the Processing is necessary in connection with any contract that you may enter into with us
Versa's general corporate privacy policy describes personal data retention in generic terms with no specific retention period, and references Standard Contractual Clauses for international transfers with no named regional data residency options and no specific sub-processor list.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page reads 'is necessary' instead of 'necessary' - near-identical wording but not an exact match.). Re-quote verbatim. This is a corporate website privacy policy, not a product-level data residency, log retention or sub-processor disclosure for the SD-WAN/SASE service itself; no specific retention period, region list or sub-processor names given. [2026-09-15, Playwright fetch] Re-quoted verbatim (corrects the missing 'is'). Confirmed this is the general corporate privacy policy, not a product-level data residency or retention disclosure for the SD-WAN/SASE service.
versa-networks.com · Checked 15 Sept 2026 · Supports: Logging, audit and evidence retention, Third-party and outsourced access, Data residency and sovereignty, Exit and portability
- FIN-442AcceptedIndependentIndependent analysis
Versa introduces cloud-based sovereign solution for enterprises of all sizes
- Named service:
- Versa Sovereign SASE-as-a-Service
- Countries, regions:
- Germany, DACH region, EU
- Regulatory regime:
- EU
Data plane, control plane, management plane, and logging operating entirely on EU-hosted and controlled infrastructure, independent of Versa's global cloud infrastructure.
Independent trade press reports that Versa's Sovereign SASE-as-a-Service, contracted through Versa Networks B.V. in the Netherlands, keeps all data, control, management and logging planes on EU-hosted infrastructure, initially for the Germany/DACH region, and cites a Swisscom national-scale deployment.
Does not prove: Article does not name a financial services customer using this sovereign offering and does not state UK, US or Canadian regional equivalents; Swisscom is a telecom partner deployment, not a named FS end customer.
helpnetsecurity.com · Published 27 Feb 2026 · Checked 12 Sept 2026 · Supports: Data residency and sovereignty
- FIN-443AcceptedProvider-authoredFinancial services solution page
Financial Services Solution | Versa Networks
- Named service:
- Secure SD-WAN, ZTNA, VersaONE
- Countries, regions:
- Global
- Standard or regulation:
- GDPR, CCPA, FINRA
- Regulatory regime:
- Multiple
they can support and secure diverse lines of service, such as IT, guest Wi-Fi, ATMs and mobile insurance agencies
Versa's financial services solution page describes generic industry use cases for Secure SD-WAN and ZTNA (branch expansion, cloud migration, mission-critical application access) and references GDPR, CCPA and FINRA as data privacy drivers, without naming any customer.
Does not prove: No named financial institution; regulatory mentions (GDPR, CCPA, FINRA) are generic industry context, not a compliance statement connecting the named service to a specific regime's rules; this is Partial-level evidence only.
versa-networks.com · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation, Branch and office connectivity, Cloud and SaaS data controls, Remote and hybrid workforce
- FIN-444AcceptedProvider-authoredFinancial services solution page
Financial Services, Powered by SD-WAN - The Versa Networks Blog
- Named service:
- SD-WAN
- Regulatory regime:
- Not stated
centralizes provisioning and management of the network, ensuring all locations are compliant with government regulations
A generic Versa blog post argues SD-WAN speeds up bank branch deployment and centralises regulatory-compliant network management, without naming any bank or specific regulation.
Does not prove: No named customer, no specific regulation identified, no trading, remote workforce or PCI detail; marketing-style generic claim only.
versa-networks.com · Checked 12 Sept 2026 · Supports: Change control and configuration governance, Branch and office connectivity
- FIN-445AcceptedProvider-authoredCompliance attestation or statement
Service Level Agreement (Versa Hosted and Managed Secure Services Edge Gateways)
- Named service:
- Versa Hosted and Managed Secure Services Edge Gateways
- Regulatory regime:
- Not stated
- Outcome:
- 99.999% monthly uptime target with tiered service credits for missed SLA
customer must notify Versa of the missed SLA Uptime Percentage by opening a support ticket...within [2] calendar days following the end of the applicable month
Versa's Hosted SASE SLA commits to a 99.999% monthly uptime target with tiered service credits for breaches, and sets a 2-calendar-day customer notification window to claim credits, plus latency targets of 10ms and 50ms for specific security functions.
Does not prove: This document defines the customer's obligation to notify Versa of an SLA breach to claim credit; it does not state Versa's own commitment to notify customers of a security incident, and gives no RTO/RPO figures.
versa-networks.com · Checked 12 Sept 2026 · Supports: Resilience and tested recovery, Incident notification support
- FIN-446AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- VersaONE Universal SASE Platform
- Standard or regulation:
- ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, HIPAA
- Regulatory regime:
- Not stated
successfully achieved ISO/IEC 27001 recertification...and fully re-certified for the SOC 2...standards following extensive independent audits
Versa announced renewal of ISO 27001 (seventh year) plus ISO 27017/27018 cloud security and privacy controls, SOC 2 Type II re-certification and HIPAA re-certification for the VersaONE Universal SASE Platform, and lists FIPS 140-2, PCI DSS, Common Criteria, ISO 9001, ISO 14001, ISO 20000-1 and ISO 22301 among its other certifications.
Does not prove: Certifications are corporate/platform-level, not specific to any financial services customer or regime (FCA, NYDFS, OSFI, DORA); a certification alone does not satisfy the regulatory-alignment columns per the grading rules.
versa-networks.com · Published 30 Oct 2025 · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention, Data residency and sovereignty, Encryption and key management, Cloud and SaaS data controls
- FIN-447AcceptedProvider-authoredCompliance attestation or statement
Versa Networks Achieves FIPS 140-2 Security Certification
- Named service:
- Versa Operating System (VOS)
- Standard or regulation:
- FIPS 140-2
- Regulatory regime:
- Not stated
FIPS-certified VOS cryptographic modules power the cryptography for the Control Plane and Data Plane of the Versa SASE and Versa Secure SD-WAN solutions.
Versa's press release states the Versa Operating System (VOS), the foundation of Versa SASE and Versa Secure SD-WAN, holds FIPS 140-2 Level-1 certification for both branch (certificate #4379) and controller (certificate #4380) roles.
Does not prove: FIPS 140-2 only; no FIPS 140-3 validation found for the current product line at time of research; not financial-services-specific.
businesswire.com · Published 5 Jan 2023 · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-448AcceptedProvider-authoredCompliance attestation or statement
Versa Networks Achieves Common Criteria EAL4+ Certification
- Named service:
- Versa Operating System (VOS)
- Standard or regulation:
- Common Criteria EAL4+
- Regulatory regime:
- Not stated
auditing, access control, encryption, identification and authentication, secure administration, tamper resistance, and trusted communication paths
Versa announced Common Criteria EAL4+ certification of the Versa Operating System (VOS), the foundation for Versa Unified SASE and Versa Secure SD-WAN, covering security functions, source code, development lifecycle and vulnerability management processes.
Does not prove: Corporate/product certification only; no financial services customer or regulator named.
versa-networks.com · Checked 12 Sept 2026 · Supports: Change control and configuration governance
- FIN-519AcceptedProvider-authoredCompliance attestation or statement
What is DORA? Compliance & Digital Resilience Guide
- Named service:
- VersaONE Universal SASE, SD-WAN, SSE
- Standard or regulation:
- DORA
- Regulatory regime:
- EU
States VersaONE Universal SASE, SD-WAN, SSE and SASE products can help financial-services customers address DORA, while explicitly stating Versa itself is not directly subject to DORA.
Harry personally verified this live 2026-09-15. Versa's own blog explicitly disclaims being directly subject to DORA and frames the products as helping customers rather than being contractually DORA-aligned itself - graded Partial, matching the document's own caution not to upgrade this to Proven.
Does not prove: Added 2026-09-15, Harry-verified. Provider explicitly states it is not directly subject to DORA - this is product-marketing content, not a contractual mapping.
versa-networks.com · Checked 15 Sept 2026 · Supports: EU DORA alignment
- FIN-530AcceptedProvider-authoredNamed customer case study
A Smart Investment: RCBC Nets Big Dividends with Versa Secure SD-WAN
- Named financial institution:
- Rizal Commercial Banking Corporation (RCBC)
- Named service:
- Versa Secure SD-WAN
- Sites, branches, users:
- 469-505 branches; 890-1,468 ATMs and ATM Go terminals across all 82 provinces of the Philippines
- Countries, regions:
- Philippines
- Regulatory regime:
- Not stated
- Outcome:
- Largest deployment of Versa Secure SD-WAN in the Philippines; simplified network management and strengthened security across the branch/ATM network
"We are dedicated to providing our customers with seamless and secure banking experiences, and the deployment of Versa Secure SD-WAN represents a critical milestone in our digital transformation journey." - Nilo Zantua, Senior Vice President, Chief Information Officer and Group Head, RCBC. RCBC is described as "one of the largest commercial banks in the Philippines, with over PHP1.3 trillion in total resources."
Versa's own case study PDF, verified live 2026-09-15, independently corroborated by Philippine business press (Manila Bulletin, Daily Tribune) covering the same September 2024 contract-signing event. RCBC is a real, major, named Philippine bank with a named C-level executive quote. This is meaningfully stronger evidence than Versa's existing anonymised 'Global Financial Services Firm' case studies. Regulatory regime not stated - Philippines is outside the UK/EU/US/Canada regimes tracked by this workbook (BSP - Bangko Sentral ng Pilipinas - is the relevant regulator but not named on the source itself).
Does not prove: Added 2026-09-15 per further research pass. No specific RTO/RPO or resilience test result stated - "strengthen network resiliency" is a stated goal, not a measured outcome.
versa-networks.com · Checked 15 Sept 2026 · Supports: Network segmentation and zoning, Branch and office connectivity, Resilience and tested recovery
- FS-073AcceptedProvider-authoredExisting source lead
Versa Networks - homepage (named customer quotes, VersaONE positioning)
A Fortune 500 financial services company chooses software defined WAN (SD-WAN) to transform their legacy architecture
Strongest sector evidence for this supplier. Two independent strands on the vendor's own site: a Fortune 500 financial services customer story on the homepage, and a Gartner Peer Insights review published on the customers page attributed to 'Network Engineer – Banking'. A dedicated page is also listed at https://versa-networks.com/solutions/industries/financial-services/ but could not be loaded. Neither customer is named.
Does not prove: Tier 1 supplier material. Read via https://r.jina.ai/https://versa-networks.com/ because of the same bot wall. Quotes re-extracted on three separate passes and matched each time. Customer stories are anonymised apart from Adobe. | Confirmed - exact match
· Published 16 Mar 2026 · Checked 29 Jul 2026 · Supports: Branch and office connectivity
- FIN-449RejectedProvider-authoredOther
Versa Security and Trust Center | Versa Networks
- Named service:
- Versa Security and Trust Center listings
- Regulatory regime:
- Not stated
SOC 2 Type II, SOC 3, ISO/IEC 27001:2022, ISO 27017, ISO 27018, FIPS 140-2, Common Criteria NIAP, PCI DSS
Versa's trust centre lists certifications (SOC 2 Type II, SOC 3, ISO 27001:2022, ISO 27017/27018, FIPS 140-2, Common Criteria, PCI DSS) with links to reports and certificates, but the fetched page content did not surface specific data residency, log retention, SLA or sub-processor detail.
Does not prove: Rejected as a standalone source row because it duplicates certification facts already sourced from the more specific 2025 certification press release and FIPS/Common Criteria releases, and did not itself surface data residency, retention, SLA or sub-processor detail despite being the natural page for it.
versa-networks.com · Checked 12 Sept 2026
- FIN-450RejectedProvider-authoredOther
- Named service:
- Not applicable
- Regulatory regime:
- Not stated
RCBC uncovered centralized control, scalable security, and superior network performance, while enabling seamless, and secure banking to all customers regardless of their location.
This is a navigation/listing page pointing to the individual financial services case studies (Fortune 500 financial services company, Global Financial Services Firm, Global Credit Card Payments Company, RCBC) which were opened and sourced separately.
Does not prove: Rejected as a duplicate source row; used only to locate the individual case study PDFs, which are sourced separately above.
· Published 22 Jul 2025 · Checked 12 Sept 2026
- FS-072RejectedProvider-authoredExisting source lead
Our Customers | Versa Networks
A Fortune 500 financial services company chooses software defined WAN (SD-WAN) to transform their legacy architecture
Strongest sector evidence for this supplier. Two independent strands on the vendor's own site: a Fortune 500 financial services customer story on the homepage, and a Gartner Peer Insights review published on the customers page attributed to 'Network Engineer – Banking'. A dedicated page is also listed at https://versa-networks.com/solutions/industries/financial-services/ but could not be loaded. Neither customer is named.
Does not prove: Tier 1 supplier material. versa-networks.com sits behind an Imperva JavaScript bot wall returning only 'Javascript is required' to non-browser clients, so this was read via the text proxy https://r.jina.ai/https://versa-networks.com/customers/ where every quoted string reproduces. Attributions are anonymised Gartner Peer Insights reviewers labelled by industry, not named customers. | Not found on page
versa-networks.com · Published 4 Apr 2022 · Checked 29 Jul 2026
- FS-074RejectedProvider-authoredExisting source lead
Versa Networks site navigation, Industry Solutions menu, rendered on the /company/ 404 page
A Fortune 500 financial services company chooses software defined WAN (SD-WAN) to transform their legacy architecture
Strongest sector evidence for this supplier. Two independent strands on the vendor's own site: a Fortune 500 financial services customer story on the homepage, and a Gartner Peer Insights review published on the customers page attributed to 'Network Engineer – Banking'. A dedicated page is also listed at https://versa-networks.com/solutions/industries/financial-services/ but could not be loaded. Neither customer is named.
Does not prove: Tier 1 but weaker than a live page. This URL 404s; its 'Looking for something?' block renders the full site navigation including an Industry Solutions menu of dedicated industry page URLs. Read via https://r.jina.ai/https://versa-networks.com/company/. The individual industry pages could NOT be loaded: reader attempts returned HTTP 429 and direct attempts hit the bot wall. Verified navigation entries, not verified page content, so possibly stale. | Not found on page
versa-networks.com · Checked 29 Jul 2026
08GTT
5 of 28 proven14 of 18 sourcesOpenClose
GTT on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
GTT's own pages show real security building blocks for its named SD-WAN and SASE products, including ZTNA on both Managed SD-WAN and Secure Connect, CASB/DLP under Cloud Security, ISO 27001 certification and a SOC 2 scope that explicitly names the SD-WAN service, plus an Envision management portal with audit trails and policy-as-code governance. The only named financial institution found, Saxo Bank, is a UK and Denmark-based trading firm, but its case study describes legacy MPLS, IP Transit and broadband services rather than the current Managed SD-WAN or Secure Connect SASE products, so it cannot prove those specific products in live financial services use. Regulatory alignment is thin: DORA is mentioned once on a generic finance and insurance page with no Article 30 detail, and no evidence at all was found connecting the named services to FCA/PRA, FFIEC, GLBA, NYDFS, SEC, OSFI or SWIFT CSP. A UK decision maker gets some assurance from the Saxo Bank relationship and the SOC 2 scope naming SD-WAN, but a North American or Canadian buyer has no named customer evidence at all. Overall this is a partial evidence base built mainly from provider marketing and certification statements rather than named, regime-specific financial services deployments of the current SD-WAN/SASE product line.
Gaps and unknowns: No evidence was found for remote/hybrid workforce use in an FS context, incident notification timelines, a published sub-processor list, exit/data-return terms, or any FCA/PRA, US or Canadian regulatory alignment; a current SD-WAN or SASE case study naming a bank, insurer or payment firm with UK or North American regulatory detail would close most of these gaps. The PCI DSS attestation and DORA statement are both generic company-level claims rather than being tied to a single named product, and no SWIFT CSP evidence exists at all; obtaining GTT's PCI DSS AoC/Responsibility Model document directly and a dedicated DORA Article 30 compliance statement would resolve this.
- Branch and office connectivity
- Partial
- Trading and low-latency connectivity
- Proven
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Not found
- Data residency and sovereignty
- Partial
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Proven
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Partial
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Proven
- North America delivery
- Partial
- Global delivery
- Proven
Sources (17)
- FIN-289AcceptedProvider-authoredFinancial services solution page
GTT Finance and Insurance Solutions
- Named service:
- Managed SD-WAN; Secure Connect; Cloud Connect
- Standard or regulation:
- DORA
- Regulatory regime:
- EU
Support regulatory frameworks such as the Digital Operational Resilience Act (DORA).
GTT's finance and insurance industry page describes generic capabilities (Managed SD-WAN failover, segmentation, PCI DSS-aligned network operations, DORA support) without naming a specific financial institution.
Does not prove: Generic industry solutions page with no named financial institution and no Article 30 contractual detail or FCA/PRA reference; does not prove a live deployment.
gtt.net · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation, Third-party and outsourced access, Network segmentation and zoning, Branch and office connectivity, Resilience and tested recovery, Data residency and sovereignty, EU DORA alignment, PCI DSS alignment
- FIN-290AcceptedProvider-authoredFinancial services solution page
- Named service:
- Managed SD-WAN
- Regulatory regime:
- Not stated
- Outcome:
- SD-WAN with dual broadband connections cited as achieving 99.962% availability versus 99.900% for a single MPLS circuit; up to 99.998% with optimised architecture
Replaces legacy VPNs with secure application-level access. It grants access based on user identity and device posture, not network location.
GTT's Managed SD-WAN product page describes automatic failover, ZTNA replacing VPNs, and generic encryption on broadband links, with no financial services context or named customer.
Does not prove: No financial institution named, no FIPS validation or key management specifics, and no FS-specific outcome.
gtt.net · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Encryption and key management
- FIN-291AcceptedProvider-authoredFinancial services solution page
- Named service:
- SASE Secure Connect
- Regulatory regime:
- Not stated
Every access request is verified against user identity and application-specific policy.
GTT's SASE Secure Connect page describes ZTNA, consolidation of SD-WAN, SWG, CASB, FWaaS and DLP, and 24/7 NOC and SOC monitoring with CREST-certified analysts, with no named customer.
Does not prove: No named institution and no financial services context; Palo Alto Prisma and Fortinet are not named on this page despite being listed as partners in the brief.
gtt.net · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Cloud and SaaS data controls, Managed operations and SOC
- FIN-292AcceptedProvider-authoredNamed customer case study
- Named financial institution:
- Saxo Bank
- Named service:
- Broadband, IP Transit, MPLS (GTT network)
- Sites, branches, users:
- 26 countries (offices)
- Countries, regions:
- UK; Denmark
- Regulatory regime:
- Multiple
- Outcome:
- 10Gb connectivity between Saxo Bank's head office and its data centres in the UK and Denmark providing redundancy and resilience
GTT's high-capacity infrastructure also provides redundancy and resilience with 10Gb connectivity between Saxo Bank's head office and its data centers in the U.K. and Denmark.
Saxo Bank, a named investment bank, uses GTT broadband, IP Transit and MPLS network services (not the current Managed SD-WAN or Secure Connect SASE products) to link its head office and UK and Denmark data centres for its trading platform.
Does not prove: Does not name Managed SD-WAN or Secure Connect/SASE; the connectivity described is legacy MPLS/IP Transit/broadband, so it cannot prove the named SD-WAN/SASE service was used, only that GTT serves this named FS customer.
gtt.net · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Trading and low-latency connectivity, Resilience and tested recovery, Global delivery, UK delivery
- FIN-293AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- SD-WAN; SIP Trunking; Managed Hosting; VDC
- Countries, regions:
- Prague; Pune
- Standard or regulation:
- ISO 27001:2022; SOC 1; SOC 2; PCI DSS
- Regulatory regime:
- Not stated
GTT's SOC 2 scope includes the SD-WAN and SIP Trunking services.
GTT states ISO 27001:2022 certification at its Prague and Pune operations centres, that SOC 2 scope explicitly includes the SD-WAN service, and that customers can request a PCI DSS Attestation of Compliance and Responsibility Model from their account manager.
Does not prove: No log retention periods, encryption/key management specifics, incident notification timelines, data residency options or subcontractor list are given on this page; the PCI DSS AoC is offered on request rather than published, and is not tied to a single named service.
gtt.net · Checked 12 Sept 2026 · Supports: Change control and configuration governance, Logging, audit and evidence retention, PCI DSS alignment
- FIN-294AcceptedProvider-authoredFinancial services solution page
- Named service:
- GTT Envision
- Regulatory regime:
- Not stated
Centralized policy, audit trails and compliance reporting.
GTT Envision is described as a management portal offering a single-pane view across network and security, persona-based role-based dashboards, policy-as-code orchestration and audit trails/compliance reporting.
Does not prove: No named financial services customer, no retention periods or specific audit standards are stated.
gtt.net · Checked 12 Sept 2026 · Supports: Change control and configuration governance, Network visibility and reporting, Identity and zero trust access
- FIN-295AcceptedProvider-authoredFinancial services solution page
- Named service:
- Cloud Security (CASB/DLP)
- Standard or regulation:
- HIPAA; PCI DSS
- Regulatory regime:
- Not stated
Their solutions help organizations comply with industry regulations including HIPAA and PCI DSS, which are particularly relevant for financial services contexts.
GTT's Cloud Security page describes CASB and DLP functions and explicitly connects PCI DSS-related compliance to financial services contexts, without naming a customer.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page mentions compliance with GDPR, HIPAA, PCI generally but not the exact framing about 'particularly relevant for financial services contexts'.). Re-quote verbatim. No named financial institution and no detail on how DLP policy is configured for cardholder or customer data specifically. [2026-09-15, Playwright fetch] Re-checked in full: the live page contains no mention of 'financial' or financial services anywhere, not even in passing - this is now a purely generic SSE/cloud-security product page. 'Finance & Insurance' appears only once, in the site's industries footer navigation menu. This is weaker than the original note suggested; the existing Partial rating (backed by 11 other sources) is unaffected, but this specific source should not be treated as financial-services-specific evidence going forward.
gtt.net · Checked 15 Sept 2026 · Supports: Cloud and SaaS data controls
- FIN-296AcceptedProvider-authoredOther
- Named service:
- GTT Tier 1 IP network
- Countries, regions:
- 170+ countries; six continents
- Regulatory regime:
- Not stated
450+ PoPs on six continents, providing service reach to more than 170 countries.
GTT describes its Tier 1 IP backbone as spanning six continents with 450+ points of presence and reach into 170+ countries, underpinning its managed services globally.
Does not prove: Describes the underlying network, not the Managed SD-WAN or Secure Connect product specifically, and gives no UK- or North America-specific PoP counts or named financial customers.
gtt.net · Checked 12 Sept 2026 · Supports: Global delivery
- FIN-297AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- GTT (corporate)
- Countries, regions:
- Arlington, Virginia, US (HQ)
- Regulatory regime:
- Multiple
Third parties that receive personal data from us must provide sufficient guarantees.
GTT's privacy notice states it is headquartered in Arlington, Virginia, transfers data outside the EEA/UK using inter-group data transfer agreements based on European Standard Contractual Clauses, and requires third-party recipients of personal data to give sufficient guarantees, without naming a sub-processor list or retention period.
Does not prove: No specific data residency commitment for logs or the management plane by country, no published sub-processor list, and no exit/termination or data return clause is given.
gtt.net · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency, Data residency and sovereignty, North America delivery
- FIN-298AcceptedProvider-authoredFinancial services solution page
- Named service:
- Cloud Connect
- Regulatory regime:
- Not stated
Connect directly to major cloud providers without traversing the public internet, with dedicated connections to AWS, Azure and Google Cloud.
GTT's Connect/Cloud Connect page describes direct on-ramps to AWS, Azure and Google Cloud with flexible bandwidth and automatic failover, with no named customer or financial services context.
Does not prove: No data centre or colocation facility is named, and no financial institution or FS context is mentioned.
gtt.net · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity
- FIN-299AcceptedProvider-authoredIndependent analysis
- Named service:
- GTT (corporate managed network and connectivity services)
- Countries, regions:
- UK and Ireland; North America
- Regulatory regime:
- Not stated
- Outcome:
- Named an Exceptional Performer in network and connectivity services for the second consecutive year (Whitelane Research 2026, UK & Ireland); Elite 150 status in North America (CRN 2026 MSP 500)
GTT was named an Exceptional Performer in network and connectivity services by Whitelane Research in the UK and Ireland for the second consecutive year.
GTT's own awards page reports independent analyst recognitions, including a UK & Ireland Whitelane Research ranking and a North American CRN MSP 500 Elite 150 placement, neither specific to financial services.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Actual text: 'GTT was named an Exceptional Performer in network and connectivity services by Whitelane Research in the UK and Ireland for the second consecutive). Re-quote verbatim. These are general managed-service and customer-satisfaction rankings, not financial-services-specific, and are reported by GTT rather than sourced directly from the analyst firms. [2026-09-15, Playwright fetch] Re-quoted verbatim.
gtt.net · Checked 15 Sept 2026 · Supports: North America delivery, UK delivery
- FIN-300AcceptedProvider-authoredFinancial services solution page
- Named service:
- Secure Service
- Standard or regulation:
- GDPR; HIPAA; PCI DSS; SOC 2
- Regulatory regime:
- Not stated
Automated compliance monitoring and reporting across GDPR, HIPAA, PCI DSS, SOC 2 and more.
GTT's Secure service overview page lists zero trust protection and automated compliance monitoring across several standards, without naming a financial institution.
Does not prove: Generic marketing page; does not specify which named product these controls apply to in detail, and has no financial services customer or context.
gtt.net · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Cloud and SaaS data controls
- FIN-512AcceptedProvider-authoredFinancial services solution page
GTT Financial Services solutions page
- Named service:
- GTT SD-WAN, SIP Trunking (GTT Financial Service Portfolio)
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
"Manage your financial transactions securely and efficiently with the assurance of our PCI-DSS certification and compliance service." / GTT's Financial Service Portfolio names SD-WAN as the flagship service. / "Reinforce privileged network access with multi-factor authentication to protect sensitive financial data... Ensure compliance with rigorous log reporting and SIEM portal reporting."
GTT's own dedicated Financial Services solutions page, verified live 2026-09-15. This directly names PCI-DSS certification in the context of financial transactions and names SD-WAN as the flagship service delivering it - a materially stronger connection than a generic company-wide certification list, since the page is specifically written for financial services buyers about a named service. No specific named customer, so this is a provider statement rather than a customer case, but it meets the Regulations tab's alternative bar of provider material connecting the named service to the regulation for financial services. Graded Proven for PCI DSS alignment on that basis; MFA and log/SIEM reporting support Identity/zero trust and logging fields at Partial, since those are described more generally.
Does not prove: Added 2026-09-15 per item 6 research pass. Not an Attestation of Compliance document itself, but a dedicated financial-services page naming the certification and the specific service - the strongest PCI DSS evidence found in this pass short of an actual AoC.
gtt.net · Checked 15 Sept 2026 · Supports: Logging, audit and evidence retention, Identity and zero trust access, PCI DSS alignment
- FIN-525AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- GTT financial services solutions
- Standard or regulation:
- DORA; PCI DSS
Financial-services positioning content references DORA and PCI DSS capabilities alongside named financial connectivity (Saxo Bank).
Harry personally verified this live 2026-09-15. Sector page with a real named customer (Saxo Bank, already recorded elsewhere for trading connectivity) but no published DORA Article 30 contractual addendum - graded Partial for DORA and PCI DSS as positioning content, not contractual proof.
Does not prove: Added 2026-09-15, Harry-verified. Positioning/marketing content referencing regulations, not a contractual mapping document.
gtt.net · Checked 15 Sept 2026 · Supports: EU DORA alignment, PCI DSS alignment
- FIN-301RejectedProvider-authoredOther
- Named service:
- Not applicable
- Regulatory regime:
- Not stated
30 Results
GTT's case study index offers a Financial Services industry filter but the retrieved listing showed no financial-services-named case studies beyond the separately-found Saxo Bank case study.
Does not prove: Index page only; does not itself contain evidence for any requirement column beyond confirming the limited pool of named FS case studies.
gtt.net · Checked 12 Sept 2026
- FIN-302RejectedProvider-authoredOther
- Named service:
- Not applicable
- Regulatory regime:
- Not stated
N/A
GTT's blog archive (2020 to 2026) showed no posts on DORA, FCA, PRA, PCI DSS, SWIFT, NYDFS, OSFI or GLBA in the listing reviewed.
Does not prove: Index page; regulatory-specific blog content, if any, was not surfaced and could exist deeper in the archive or behind site search.
gtt.net · Checked 12 Sept 2026
- FIN-303RejectedProvider-authoredOther
- Named service:
- Not applicable
- Regulatory regime:
- Not stated
N/A
GTT's Regulatory page contains US carrier tariff filings (for example Arkansas, Maryland) and links back to the Legal & Regulatory Center; it holds no security, data residency or financial services regulatory content.
Does not prove: Not relevant to any of the 28 requirement columns.
gtt.net · Checked 12 Sept 2026
09Palo Alto Networks Prisma SASE
8 of 28 proven14 of 24 sourcesOpenClose
Palo Alto Networks Prisma SASE on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Palo Alto Networks documents Prisma Access and Prisma SD-WAN for financial services connectivity and publishes data residency regions (including the UK, US, Canada and EU) and configurable log retention for the Strata Logging Service that Prisma Access uses. The clearest named financial services deployment is Lemonade Insurance, a US insurer, using Prisma Browser within Prisma SASE for remote workforce and Zero Trust access, alongside an anonymised US regional bank case study covering over 200 locations. No UK or EU bank, insurer, credit union or asset manager names Prisma Access or Prisma SD-WAN, and no source in this research connects the named service to FCA, PRA, DORA, FFIEC, NYDFS or OSFI requirements. PCI DSS material found is generic and not tied to Prisma Access or Prisma SD-WAN by name. The evidence base is stronger for platform documentation such as data residency and log retention than for named financial services deployments outside the United States.
Gaps and unknowns: No evidence was found for trading or low-latency use, cardholder data environment segmentation, 24x7 managed SOC commitments for financial services customers, change control governance, incident notification timelines, or exit and data portability commitments for Prisma Access or Prisma SD-WAN; closing these would need the provider's own service description or a named customer case addressing them directly. UK regulatory alignment (FCA/PRA), EU DORA alignment, US regime alignment (FFIEC, GLBA, NYDFS, SEC), Canadian OSFI alignment, and PCI DSS certification for the named service were all not found and would need a specific compliance statement or named regulated customer case to close.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Proven
- Data residency and sovereignty
- Proven
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Proven
- Identity and zero trust access
- Proven
- Cloud and SaaS data controls
- Not found
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Proven
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Partial
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Not found
- SWIFT CSP alignment
- Partial
- UK delivery
- Partial
- North America delivery
- Partial
- Global delivery
- Partial
Sources (23)
- FIN-383AcceptedProvider-authoredFinancial services solution page
Financial Services - Palo Alto Networks
- Named service:
- Prisma Access; Prisma SD-WAN
- Regulatory regime:
- Not stated
Work-from-anywhere with secure direct internet access
Provider financial services solutions page naming Prisma Access and Prisma SD-WAN, with generic use-case links on third-party access, network segmentation, remote work and SWIFT security controls, but no named financial institution.
Does not prove: No named financial institution or measured outcome; this is a generic solutions page, not a customer deployment, so it only supports Partial status on the columns listed.
paloaltonetworks.com · Checked 12 Sept 2026 · Supports: Third-party and outsourced access, Network segmentation and zoning, Remote and hybrid workforce, SWIFT CSP alignment
- FIN-384AcceptedProvider-authoredNamed customer case study
Banking on a More Secure Future with Prisma SASE - Palo Alto Networks
- Named service:
- Prisma SASE; Prisma SD-WAN; Prisma Access
- Sites, branches, users:
- Over 200 locations
- Countries, regions:
- United States (Southeast and Mid-Atlantic regions)
- Regulatory regime:
- US
- Outcome:
- $1.5M projected 3-year savings; $427K connectivity cost reduction; 49,000 projected downtime hours saved over 3 years
Their users had such a good experience, and their applications were so much faster and more resilient, that they said, 'Whatever it is that you put in here, please don't take it away.'
A US regional bank with over 200 locations replaced legacy WAN infrastructure with Prisma SASE, Prisma SD-WAN and Prisma Access, reporting cost savings and improved application performance and resilience.
Does not prove: The bank is anonymised as 'a U.S. regional bank', not named, so this only supports Partial status per the grading rules for an anonymised customer; quote is attributed to a Palo Alto Networks account executive rather than the bank itself.
paloaltonetworks.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Network visibility and reporting, Branch and office connectivity, Resilience and tested recovery, Remote and hybrid workforce, North America delivery
- FIN-386AcceptedProvider-authoredNamed customer case study
Lemonade Insurance pioneers a new way to secure work with Prisma Browser
- Named financial institution:
- Lemonade Insurance
- Named service:
- Prisma Browser (part of Prisma SASE)
- Regulatory regime:
- Not stated
- Outcome:
- Reduced employee onboarding time from days to 20 minutes
It's the central part of our Zero Trust strategy. It's both the entry to the outside world.
Lemonade Insurance, a named insurer, deployed Prisma Browser as the central part of its Zero Trust strategy to secure remote employees and BYOD contractors.
Does not prove: Case study centres on Prisma Browser (an enterprise browser component) rather than Prisma SD-WAN or core Prisma Access network connectivity; it does not evidence branch, data-centre or trading connectivity.
paloaltonetworks.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Remote and hybrid workforce
- FIN-390AcceptedProvider-authoredCompliance attestation or statement
Compliance - Palo Alto Networks
- Named service:
- Palo Alto Networks (company-wide)
- Standard or regulation:
- FIPS 140
- Regulatory regime:
- Not stated
FIPS 140 has four levels of security, with level 1 containing the lowest level of security assurance and level 4 being the highest.
Trust centre compliance page listing SOC 2+, ISO, PCI DSS, FedRAMP and FIPS 140 as certifications Palo Alto Networks holds, without naming which products or service tiers each applies to.
Does not prove: Does not state that Prisma Access or Prisma SD-WAN specifically is FIPS validated, so this only supports Partial status, not Proven.
paloaltonetworks.com · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-392AcceptedProvider-authoredCompliance attestation or statement
Strata Logging Service Regions
- Named service:
- Prisma Access (via Strata Logging Service)
- Countries, regions:
- United States, Canada, United Kingdom, Netherlands, France, Germany, Italy, Poland, Spain, Switzerland, Australia, Japan, Korea, Singapore, Taiwan, India, Indonesia, Israel, Qatar, Saudi Arabia, South Africa, China, US Government
- Regulatory regime:
- Multiple
Products that use Strata Logging Service may support either all or some of the listed regions. To know which Strata Logging Service regions your product supports, refer to the respective product documentation.
Palo Alto Networks documentation lists over 30 Strata Logging Service data hosting regions, including the UK, US, Canada and multiple EU countries, and states Prisma Access is one of the services that uses Strata Logging Service, though only a subset of regions per product.
Does not prove: Does not state exactly which of the listed regions Prisma Access itself supports (it says Prisma Access 'supports only a subset'), and is not financial services specific.
docs.paloaltonetworks.com · Checked 12 Sept 2026 · Supports: Data residency and sovereignty
- FIN-393AcceptedProvider-authoredCompliance attestation or statement
Allocate Log Retention Days - Strata Logging Service
- Named service:
- Strata Logging Service (used by Prisma Access)
- Regulatory regime:
- Not stated
To streamline log management, Strata Cloud Manager now provides 6 predefined retention period options.
Palo Alto Networks documents configurable log retention periods in Strata Logging Service, with six predefined retention options, and recommends forwarding logs to a third-party store such as AWS S3 for longer compliance retention.
Does not prove: The specific day values of the six retention options are not stated on this page, and the page is not financial services specific.
docs.paloaltonetworks.com · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention
- FIN-394AcceptedProvider-authoredCompliance attestation or statement
Palo Alto Networks Sub-Processor List - Palo Alto Networks
- Named service:
- Palo Alto Networks (company-wide, including Prisma products)
- Regulatory regime:
- Not stated
The purpose of this document is to provide customers of Palo Alto Networks with information related to the Sub-processors we engage to provide you with our cybersecurity products and services.
Palo Alto Networks publishes a dated sub-processor list document for its products and services, updated 3 September 2026, though the page itself does not confirm the PDF names Prisma Access or Prisma SD-WAN specifically.
Does not prove: Content of the linked PDF was not opened, so it is not confirmed that Prisma Access or Prisma SD-WAN sub-processors are individually named inside it; page-level metadata only.
paloaltonetworks.com · Published 3 Sept 2026 · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency
- FIN-395AcceptedProvider-authoredCompliance attestation or statement
Prisma by Palo Alto Networks | Prisma SD-WAN | Service Level Agreement
- Named service:
- Prisma SD-WAN
- Regulatory regime:
- Not stated
- Outcome:
- 99.99% dataplane availability commitment with tiered service credits for outages
Palo Alto Networks commits to using commercially reasonable efforts to achieve a 99.99% level of dataplane availability due to Prisma SD-WAN portal outages.
The official Prisma SD-WAN Service Level Agreement commits to 99.99% dataplane availability with tiered service credits of 5%, 15% or 25% depending on the outage band, applied as subscription extensions.
Does not prove: This is a generic commercial SLA, not a financial-services-specific commitment, and does not state RTO/RPO figures or incident notification timelines; document is hosted on a reseller (Carahsoft) portal rather than paloaltonetworks.com.
carahsoft.com · Published 14 Apr 2025 · Checked 12 Sept 2026 · Supports: Resilience and tested recovery
- FIN-396AcceptedProvider-authoredFinancial services solution page
- Named service:
- Prisma SD-WAN; Prisma Access
- Regulatory regime:
- Not stated
Provides design guidance for optimizing remote-site connectivity and secure internet access in the financial sector by using Prisma SD-WAN and Prisma Access.
A provider design guide dedicated to financial services connectivity using Prisma SD-WAN and Prisma Access, covering dynamic path selection and SaaS access, but landing page content does not name a customer.
Does not prove: No named financial institution; only the landing page metadata was reviewed, not the full downloadable PDF, so segmentation and resilience detail beyond the title/description is not confirmed.
paloaltonetworks.com · Published 10 Oct 2025 · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Branch and office connectivity, Resilience and tested recovery
- FIN-397AcceptedProvider-authoredFinancial services solution page
- Named service:
- Prisma SD-WAN; Prisma Access
- Regulatory regime:
- Not stated
Achieve digital branch transformation with a secure, seamless, optimized experience for all users—regardless of their location—while reducing cost and complexity.
A financial services use-case guide describing branch and campus network modernisation with a SASE architecture converging WAN and security, with no named customer on the landing page.
Does not prove: No named financial institution, no PCI or segmentation detail confirmed on the landing page; full PDF content was not reviewed.
paloaltonetworks.com · Published 28 Feb 2023 · Checked 12 Sept 2026 · Supports: Branch and office connectivity
- FIN-398AcceptedProvider-authoredFinancial services solution page
Zero Trust and SASE: Better Together for Financial Institutions
- Named service:
- Prisma SASE
- Regulatory regime:
- Not stated
- Outcome:
- Forrester-calculated return on investment of up to 241% for Prisma SASE
A Zero Trust cybersecurity model, enabled by a modern Secure Access Services Edge (SASE) architecture, gives financial institutions powerful tools
Provider blog post arguing Prisma SASE and Zero Trust Network Access help financial institutions secure hybrid work and third-party access, noting that financial regulators expect appropriate controls, but without naming specific regulations or customers.
Does not prove: No named financial institution and no specific regulation (FFIEC, NYDFS, GLBA, PCI, SWIFT) is named despite referring to regulator expectations generically.
paloaltonetworks.com · Published 17 May 2022 · Checked 12 Sept 2026 · Supports: Third-party and outsourced access, Identity and zero trust access, Remote and hybrid workforce
- FIN-510AcceptedProvider-authoredFinancial services solution page
Operational Resilience: Ensuring Business Continuity with Prisma SASE
- Named service:
- Prisma SASE
- Regulatory regime:
- Not stated
- Outcome:
- 99.999% uptime service level agreement; dedicated dataplane per customer for isolation
"our service level agreement (SLA) reflects this commitment, which delivers an industry-leading 99.999% uptime service availability." / "A dedicated dataplane per customer ensures that user-to-application data traffic is performant and secure for each specific organization."
Palo Alto's own blog post, verified live 2026-09-15, naming Prisma SASE specifically and detailing a quantified 99.999% uptime SLA and dedicated-dataplane architecture for resilience. No named financial customer, so graded Partial not Proven, but this is specific named-product resilience detail rather than a generic uptime claim.
Does not prove: Added 2026-09-15 per item 6 research pass. No named FS customer; general enterprise resilience claim.
paloaltonetworks.com · Published 11 Nov 2024 · Checked 15 Sept 2026 · Supports: Resilience and tested recovery
- FIN-511AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Palo Alto Networks platform (unspecified scope)
- Standard or regulation:
- Digital Operational Resilience Act - dedicated Trust Center whitepaper, plus a separate financial-sector-specific whitepaper
- Regulatory regime:
- EU
Trust Center "Regulations" page lists "Digital Operational Resilience Act - Whitepaper" as dedicated documentation; a separate resource states "EU financial firms: ...What's helpful now will be indispensable by 2025, when the Digital Operational Resilience Act shines a light in the darkest shadows of your cloud operations."
Palo Alto's own Trust Center, verified live 2026-09-15, has a dedicated DORA whitepaper (not just a mention), plus a separate whitepaper specifically addressed to EU financial firms about DORA. Neither confirmed as naming Prisma SASE's Article 30 contractual terms specifically or a named EU financial customer, so graded Partial rather than Proven - but this is genuinely FS-targeted material, stronger than a generic regulation list.
Does not prove: Added 2026-09-15 per item 6 research pass. The whitepapers themselves were not opened in full (gated/PDF); graded from title and abstract text only.
paloaltonetworks.com · Checked 15 Sept 2026 · Supports: EU DORA alignment
- FIN-537AcceptedProvider-authoredNamed customer case study
Jovia extends Zero Trust protection everywhere, from branch to users to apps
- Named financial institution:
- Jovia Financial Credit Union
- Named service:
- Prisma SD-WAN; Prisma Access; Strata Cloud Manager
- Countries, regions:
- United States (New York)
- Regulatory regime:
- US
- Outcome:
- 30 tools consolidated to 1 with Strata Cloud Manager; 100% uptime, eliminating recurring weekly outages; $500K saved annually
"Today, we have such great insights with Prisma SD-WAN that we can tell our vendors what's wrong before they even bring issues to our attention." - David Linares, Sr. Infrastructure Manager, Jovia Financial Credit Union. Results: "30 -> 1 Tools consolidated with Strata Cloud Manager." "100% Uptime, eliminating recurring weekly outages." "$500K Saved annually by consolidating solutions with Prisma SASE."
Verified live 2026-09-15 - stronger than initially reported (a candidate finding supplied separately said no numeric metrics were stated; the page in fact gives three quantified results plus a named executive quote). Jovia Financial Credit Union, serving New York for 85+ years, is real and named.
Does not prove: Added 2026-09-15 per further research pass (cross-platform lead, independently verified and strengthened). No specific US regulator (NCUA etc.) named on the page.
paloaltonetworks.com · Checked 15 Sept 2026 · Supports: Change control and configuration governance, Network visibility and reporting, Branch and office connectivity, Identity and zero trust access
- FIN-387RejectedProvider-authoredCompliance attestation or statement
- Named service:
- Palo Alto Networks (company-wide)
- Standard or regulation:
- SOC 2
- Regulatory regime:
- Not stated
SOC 2+ or SOC 2 "Plus" represents an additional level of certification against an expanded control set, including control alignment against the HIPAA Security Rule.
Generic description of Palo Alto Networks' SOC 2+ certification with no product named and no financial services context.
Does not prove: Does not name Prisma Access or Prisma SD-WAN and does not map to any of the 28 columns, which do not include a generic SOC 2 column.
paloaltonetworks.com · Checked 12 Sept 2026
- FIN-388RejectedProvider-authoredCompliance attestation or statement
- Named service:
- Palo Alto Networks (company-wide)
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
The PCI framework aims to protect sensitive cardholder information during transactions and prevent credit card fraud.
Generic PCI DSS explainer page offering a PCI AOC SAQ report request form and a responsibility matrix, without naming which Palo Alto Networks products or services are in scope.
Does not prove: Does not name Prisma Access or Prisma SD-WAN as being PCI DSS certified or attested, so it cannot support Proven or Partial status on the PCI DSS column.
paloaltonetworks.com · Checked 12 Sept 2026
- FIN-389RejectedProvider-authoredCompliance attestation or statement
Prisma Access, a FedRAMP Authorized Service - Palo Alto Networks
- Named service:
- Prisma Access
- Countries, regions:
- United States (government)
- Standard or regulation:
- FedRAMP
- Regulatory regime:
- US
a FedRAMP Authorized, cloud-delivered service
Confirms Prisma Access is a FedRAMP Authorized service for US government agencies, but this is a federal government certification, not one of the 28 financial services columns.
Does not prove: FedRAMP is a US federal government programme, not a financial services regulatory regime in this brief's 28 columns, and the page does not state FIPS validation level, data residency, or encryption specifics.
paloaltonetworks.com · Checked 12 Sept 2026
- FIN-391RejectedProvider-authoredCompliance attestation or statement
Global Security Standards - Palo Alto Networks
- Named service:
- Palo Alto Networks (company-wide)
- Regulatory regime:
- Not stated
Explore our comprehensive documentation outlining Palo Alto Networks' adherence to global security standards
Landing page pointing to further trust documentation, with no specific data residency, encryption or FIPS detail on the page itself.
Does not prove: No concrete facts or product names found on this page to support any of the 28 columns.
paloaltonetworks.com · Checked 12 Sept 2026
- FIN-399RejectedProvider-authoredFinancial services solution page
Resource Center Financial Services - Palo Alto Networks
- Named service:
- Prisma Access; Prisma SD-WAN; Prisma SASE
- Regulatory regime:
- Not stated
Prisma Access (20 resources), Prisma SD-WAN (6 resources), Prisma SASE (10 resources)
A resource hub listing 40 financial services customer stories and guides across Palo Alto Networks products, including Northern Trust, Redeban and Banco Inter, but these named cases relate to identity/PAM (Idira) and Cortex XSIAM rather than Prisma SD-WAN or Prisma Access.
Does not prove: Used to identify individual resources for follow-up, but on its own is an index page; the named customer stories it lists (Northern Trust, Banco Inter, Redeban) do not name Prisma SD-WAN, Prisma Access or Prisma SASE.
paloaltonetworks.com · Checked 12 Sept 2026
- FIN-400RejectedProvider-authoredNamed customer case study
Northern Trust Customer Story - Palo Alto Networks
- Named financial institution:
- Northern Trust
- Named service:
- Idira Identity Security Platform
- Sites, branches, users:
- 50,000 endpoints; 23,000 employees
- Regulatory regime:
- Not stated
- Outcome:
- Password rotation compliance improved from 40% to 95%; 50,000 endpoints onboarded in 16 days with zero incidents
We started with one solution — elevation of access — and ended up implementing five.
Northern Trust, a named asset manager, is a customer of Palo Alto Networks' Idira privileged access and identity security platform, not Prisma Access, Prisma SD-WAN or Prisma SASE.
Does not prove: Out of scope for this brief, which covers Prisma SASE, Prisma Access and Prisma SD-WAN only; this case study names a different product line (Idira identity security) and cannot be used as SD-WAN/SASE evidence.
paloaltonetworks.com · Checked 12 Sept 2026
- FIN-401RejectedProvider-authoredOther
What Is the DORA Act? Digital Operational Resilience Guide - Palo Alto Networks
- Named service:
- Idira
- Standard or regulation:
- DORA
- Regulatory regime:
- EU
Review how IDIRA helps strengthen identity security controls across critical operations.
A generic educational page explaining DORA requirements that links only to the Idira identity platform, not to Prisma Access, Prisma SD-WAN or Prisma SASE.
Does not prove: Does not connect DORA to Prisma Access, Prisma SD-WAN or Prisma SASE, so it cannot support the EU DORA alignment column; used only to document that this search path was checked.
paloaltonetworks.com · Checked 12 Sept 2026
- FS-059RejectedProvider-authoredExisting source lead
Financial services industry page
- Named service:
- Palo Alto Prisma SASE
- Regulatory regime:
- US
Empowering financial institutions to securely deliver a modern customer experience.
Dedicated financial services industry page with one named customer, Better, and an attributed quote from Ali Khan, Chief Information Security Officer. The about us page claims '8 of 10 Largest U.S. banks'. Financial services is also named as a target vertical in the dated Deutsche Telekom sovereignty release [30]. No named financial services Prisma SASE or SD-WAN case study was found.
Does not prove: Dedicated supplier page with one named customer (Better) and an attributed CISO quote. | Confirmed - exact match [2026-09-15, flagged per Robert's check] Pure sector-positioning tagline ("Empowering financial institutions to securely deliver a modern customer experience") - no technical claim of any kind. Does not appear to support any specific capability honestly. Changed from Accepted to Needs review since no specific capability can be honestly assigned - recommend Harry/Robert decide whether to Reject or find a genuine capability fit. Rejected 2026-09-15 (final pass). Page is a financial-services industry landing page, but the only content is the tagline "Empowering financial institutions to securely deliver a modern customer experience" - no named institution, no product-specific claim, no technical detail that ties to a specific capability column. Genuinely financial-services content, but too generic to support any one capability honestly.
paloaltonetworks.com · Checked 15 Sept 2026
- FS-060RejectedProvider-authoredExisting source lead
Empowering financial institutions to securely deliver a modern customer experience.
Dedicated financial services industry page with one named customer, Better, and an attributed quote from Ali Khan, Chief Information Security Officer. The about us page claims '8 of 10 Largest U.S. banks'. Financial services is also named as a target vertical in the dated Deutsche Telekom sovereignty release [30]. No named financial services Prisma SASE or SD-WAN case study was found.
Does not prove: Supplier's own corporate stat block. Unaudited marketing figures, but the organisation-size and sector penetration claims are explicit and attributable. | Not found on page
paloaltonetworks.com · Checked 29 Jul 2026
10Fortinet FortiSASE
7 of 28 proven9 of 11 sourcesOpenClose
Fortinet FortiSASE on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Fortinet can demonstrate named financial services deployments of Secure SD-WAN in the United States (USI Insurance Services, 182 offices) and generic use by an anonymised US multinational financial institution and a Vietnamese bank, which supports branch connectivity, remote workforce and North American delivery. FortiSASE itself is documented mainly through generic product pages and the Trust Resource Center, which names SOC 2, ISO 27001 and FortiSASE-specific subprocessors, but no opened page ties FortiSASE or Secure SD-WAN to DORA, FCA/PRA, FFIEC, NYDFS, OSFI or SWIFT for a named financial customer. UK delivery, trading/low-latency use, cardholder data segmentation, log retention periods and FIPS validation could not be evidenced from pages that were successfully opened. The strongest named evidence is the USI Insurance Services case study, which is US-only and does not touch payments-specific or cross-border regulatory requirements. Overall this is a reasonable general-purpose SD-WAN and SASE fit with clear gaps in FS-specific regulatory documentation, particularly for UK and Canadian regimes.
Gaps and unknowns: Trading/low-latency connectivity, payment and cardholder data segmentation, logging/retention periods, FIPS 140-2/140-3 validation, incident notification timelines, exit/portability terms, UK delivery, and all four regional regulatory columns (FCA/PRA, DORA, FFIEC/GLBA/NYDFS/SEC, OSFI) and SWIFT CSP are unevidenced or only generically evidenced from opened pages. Closing these would require direct access to the FortiSASE-specific pages within trust.fortinet.com (certifications, data residency, SLA) which returned 404 on fetch, plus a named UK, EU or Canadian financial institution case study and a PCI DSS Attestation of Compliance naming FortiSASE.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Proven
- Data residency and sovereignty
- Partial
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Proven
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Proven
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Proven
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Partial
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Partial
- Global delivery
- Proven
Sources (11)
- FIN-280AcceptedProvider-authoredNamed customer case study
USI Insurance Services Case Study
- Named financial institution:
- USI Insurance Services
- Named service:
- Fortinet Secure SD-WAN
- Sites, branches, users:
- 182 offices across the United States
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- Downtime reduced from approximately 40 outages annually to fewer than 20; internet connectivity up to 10x faster; approximately $1 million annual savings on WAN hardware and support
We have effectively cut our outages in half. The proof is in the pudding that Fortinet Secure SD-WAN does what it is supposed to do.
USI Insurance Services, a US insurance broker with 182 offices, deployed Fortinet Secure SD-WAN with FortiGate NGFWs, FortiManager and FortiAnalyzer, and reported reduced outages and lower WAN costs.
Does not prove: Does not mention data residency, encryption, PCI DSS or any specific regulatory regime; RTO/RPO not quantified, outcome is outage reduction only, not a formal DR test.
fortinet.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Branch and office connectivity, Resilience and tested recovery, Managed operations and SOC
- FIN-281AcceptedProvider-authoredNamed customer case study
- Named service:
- FortiGate Next-Generation Firewalls, FortiMail, FortiManager, FortiAnalyzer
- Sites, branches, users:
- A few thousand remote users
- Countries, regions:
- Vietnam
- Regulatory regime:
- Not stated
- Outcome:
- 30% CapEx savings on cybersecurity investments; secured 24x7 connectivity for thousands of users
With Fortinet, we were able to achieve 30% CapEx savings on cybersecurity investments against comparable solutions.
An anonymised Vietnamese bank deployed FortiGate, FortiMail, FortiManager and FortiAnalyzer to secure remote workers and reported CapEx savings, but the case study does not name Secure SD-WAN or FortiSASE as the deployed service.
Does not prove: Bank name is anonymised; the named products are firewall/email/management tools, not Secure SD-WAN or FortiSASE, so this only weakly supports remote workforce and is not usable for SD-WAN/SASE-specific columns.
fortinet.com · Checked 12 Sept 2026 · Supports: Remote and hybrid workforce
- FIN-282AcceptedProvider-authoredNamed customer case study
Multinational Financial Services Institution Case Study
- Named service:
- Fortinet Secure SD-WAN, FortiWiFi, FortiAP, FortiManager, FortiAnalyzer
- Sites, branches, users:
- Hundreds to thousands of devices
- Countries, regions:
- United States (multinational)
- Regulatory regime:
- Not stated
- Outcome:
- Deployment of hundreds/thousands of teleworking devices in minutes with fast self-installation and reduced support staff impact
The company needed a high-performance, scalable solution that could empower the networking operations group to deploy hundreds of teleworking devices concurrently.
An anonymised US multinational financial services institution used Fortinet Secure SD-WAN with FortiWiFi devices to enable large-scale teleworking during the COVID-19 period.
Does not prove: Institution is anonymised (only described as a multinational financial services institution), so it cannot be verified as a specific named bank; no regulatory regime or segment stated.
fortinet.com · Checked 12 Sept 2026 · Supports: Remote and hybrid workforce
- FIN-284AcceptedProvider-authoredCompliance attestation or statement
Fortinet Trust Resource Center
- Named service:
- FortiSASE
- Countries, regions:
- Not stated
- Standard or regulation:
- SOC 2; ISO/IEC 27001
- Regulatory regime:
- Not stated
FortiSASE using subprocessors Atlassian, Grafana Cloud and Slack
Fortinet's Trust Resource Center lists FortiSASE-specific subprocessors (Atlassian, Grafana Cloud, Slack) and lists company-wide certifications including SOC 2 and ISO/IEC 27001, but does not state FortiSASE-specific data residency regions, log retention periods, FIPS validation or PCI DSS in the content retrieved.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page says 'FortiSASE using subprocessors Atlassian, Grafana Cloud and Slack' - close paraphrase, not exact wording.). Re-quote verbatim. Portal content is partly rendered dynamically; sub-pages for certifications detail, data residency and PCI DSS/FIPS returned 404 on fetch, so those specific facts could not be verified from an opened page and are recorded as Not found rather than assumed. [2026-09-15] Re-quoted verbatim using the checker's own already-confirmed page wording - no fresh fetch needed, the exact sentence was already recorded in the check note.
trust.fortinet.com · Checked 15 Sept 2026 · Supports: Concentration risk and subcontractor transparency
- FIN-285AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- FortiSASE
- Countries, regions:
- Global (200+ PoPs)
- Regulatory regime:
- Not stated
- Outcome:
- 99.999% uptime
It's deployed by end users in their own data centers, giving organizations full control over core capabilities and data, enabling secure, cost-efficient, and rapid deployment. This ensures compliance with regional data residency and sovereignty laws.
FortiSASE is described as a unified SSE/SD-WAN/zero trust platform with 200+ global PoPs, native AWS/Google Cloud/Oracle Cloud integration, CASB and DLP, SOC-as-a-Service, and a stated 99.999% uptime, plus a sovereign deployment option for data residency.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Concept present ('full control over core capabilities and data', 'compliance with regional data residency and sovereignty laws') but not the exact quoted wordin). Re-quote verbatim. This is a generic global product page, not financial-services-specific and does not name a financial institution; no FS customer or regulatory regime is connected here, so it only supports general documentation-type columns, not FS-named-customer columns. [2026-09-15, Playwright fetch] Re-quoted verbatim from the FortiSASE Sovereign section of the live page.
fortinet.com · Checked 15 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Network visibility and reporting, Identity and zero trust access, Cloud and SaaS data controls, Managed operations and SOC
- FIN-286AcceptedProvider-authoredFinancial services solution page
- Named service:
- Fortinet Secure SD-WAN
- Countries, regions:
- Not stated
- Regulatory regime:
- Not stated
"Fortinet's SD-WAN solution delivers solid performance, efficient security integration, and intuitive centralized management, providing a reliable and effective experience for enterprise environments." - Senior Network Engineer, Banking (Gartner Peer Review)
Fortinet describes Secure SD-WAN as offering real-time path monitoring, self-healing failover and identity-based segmentation with posture checks every 60 seconds, including a banking customer engineer quote praising performance and management.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Both concepts present separately ('Real-time path monitoring and dynamic steering across broadband, 5G, MPLS...' and 'Self-healing, autonomous architecture...no). Re-quote verbatim. The banking customer quote on this page is anonymised (only titled Senior Network Engineer, Banking) with no institution name, country or outcome detail, so it only weakly supports a generic banking connection, not a named-institution Proven case. [2026-09-15, Playwright fetch] Page has changed materially since the original check - the originally-quoted 'path monitoring'/'self-healing' resilience and segmentation language is no longer present anywhere on the live page. The only banking-sector reference remaining is an anonymised Gartner Peer Review quote (title only: Senior Network Engineer, Banking), which is weaker than what was previously recorded. Capability rating is unaffected since it's backed by five other sources, but this specific source no longer supports resilience/segmentation claims as strongly as before.
fortinet.com · Checked 15 Sept 2026 · Supports: Network segmentation and zoning, Resilience and tested recovery
- FIN-535AcceptedProvider-authoredNamed customer case study
- Named financial institution:
- CEC Bank
- Named service:
- FortiGate Secure SD-WAN; Fabric Management Center
- Sites, branches, users:
- Almost 1,000 branches
- Countries, regions:
- Romania
- Regulatory regime:
- EU
- Outcome:
- 8x increase in available bandwidth; 50% reduction in application response times; greatly reduced operational complexity
"Within just six months the entire Fortinet roll-out of FortiGate Secure SD-WAN was complete, providing fast, reliable connectivity to our full range of applications and services for almost 1,000 branches." - Eduard Bîsceanu, Director, Information Security and Administration, CEC Bank
Verified live 2026-09-15. CEC Bank is a real, major, named Romanian bank with a named C-level security executive quote and quantified outcomes (8x bandwidth, 50% faster response times) - a genuinely strong EU financial services SD-WAN case.
Does not prove: Added 2026-09-15 per further research pass. No named regulation (e.g. DORA) beyond general EU context.
fortinet.com · Checked 15 Sept 2026 · Supports: Change control and configuration governance, Network visibility and reporting, Branch and office connectivity
- FIN-536AcceptedIndependentNamed customer case study
CaixaBank reduces network communications costs by 50% with Fortinet
- Named financial institution:
- CaixaBank
- Named service:
- FortiGate Secure SD-WAN; FortiSwitch; FortiExtender; FortiManager; FortiAnalyzer
- Sites, branches, users:
- Approximately 5,000 bank locations
- Countries, regions:
- Spain
- Regulatory regime:
- EU
- Outcome:
- 50% reduction in network communications costs; expanded service coverage
"CaixaBank, a leading Spanish bank, faced significant challenges with its network infrastructure... Fortinet implemented its Secure SD-WAN solution across approximately 5,000 bank locations, supported by FortiSwitch LAN switches and FortiExtender for wireless WAN connections."
Found independently (not part of a supplied candidate list) while verifying a related Fortinet finding. CaixaBank is a real, major, named Spanish bank at genuinely large scale (~5,000 locations) - one of the strongest EU financial-services SD-WAN cases found in this whole project by scale.
Does not prove: Added 2026-09-15. Case study aggregator mirror, not Fortinet's own site directly - original Fortinet URL not located in this pass. No named executive quote captured, no named regulation.
casestudies.com · Checked 15 Sept 2026 · Supports: Branch and office connectivity, Managed operations and SOC
- FS-039AcceptedProvider-authoredExisting source lead
Financial Services Cybersecurity | Fortinet
The financial services sector is a high-value target for cyberattacks and highly regulated by jurisdictions around the world.
Dedicated financial services industry page. USI Insurance Services is named and quoted on that page saying "Secure SD-WAN does what it is supposed to do." The SD-WAN customer stories ebook [9] names Itau Unibanco with 3,000+ locations across 20 countries, which is direct SD-WAN evidence. Other financial customers on the page are anonymised by descriptor (a Vietnamese bank, a US multinational institution).
Does not prove: Supplier's dedicated financial services industry page with customer testimonials. Vendor-authored. | Confirmed - exact match
fortinet.com · Checked 29 Jul 2026 · Supports: Branch and office connectivity, Global delivery
- FIN-287RejectedProvider-authoredCompliance attestation or statement
Regulatory Drivers for Operational and Cyber Resilience (eBook)
- Named service:
- Fortinet solutions (FortiGate, FortiSIEM, FortiSOAR)
- Countries, regions:
- Multiple
- Standard or regulation:
- DORA; FCA; PRA; PCI DSS
- Regulatory regime:
- Multiple
Coming into effect in January 2025, it addresses the industry's increasing dependence on digital technologies and third-party technology service providers
Fortinet's financial services regulations eBook discusses DORA, FCA/PRA and PCI DSS as regulatory drivers generally, naming FortiGate, FortiSIEM and FortiSOAR, but does not name Secure SD-WAN, FortiSASE, or any specific FS customer in connection with these regimes.
Does not prove: Discusses regulations at a generic industry level without connecting the named SD-WAN/SASE service to any specific regime or customer, so it cannot support Proven status for regulatory columns; kept as evidence only that Fortinet publishes regulatory-context material, not as a capability source.
fortinet.com · Checked 12 Sept 2026
- FIN-288RejectedProvider-authoredOther
- Named service:
- Fortinet (corporate)
- Regulatory regime:
- Not stated
FORTINET MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS WEBSITE
Fortinet's legal hub page lists EULA, service terms, privacy policy and code of conduct documents but the fetched content did not surface an accessible SLA, DPA, or exit/termination document with specific commitments.
Does not prove: Page only references categories of legal documents without exposing SLA uptime commitments, incident notification timelines, or exit/termination terms in the fetched content; not usable as a capability source.
fortinet.com · Checked 12 Sept 2026
11BT
8 of 28 proven10 of 19 sourcesOpenClose
BT on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
BT can evidence a large-scale Managed SD-WAN and managed firewall deployment for an anonymised European bank spanning over 30 countries and 100,000-plus employees, covering segmentation and resilience, but the institution is not named so this falls short of full proof. The strongest named-institution evidence is Nationwide Building Society, a UK building society, which connects BT's security and monitoring service to the FCA, PRA and PCI DSS by name, supporting UK regulatory alignment and managed SOC claims. BT's Managed SASE product page documents UK data residency and ZTNA, and its banking-specific cyber security page names SASE, ZTNA and CASB for banks, but without a named financial customer for those specific capabilities. There is no evidence for US, Canadian or SWIFT regulatory alignment, no named North American financial customer, and no documented log retention, incident notification timeline or exit/portability terms tied to the named services. A UK IT decision maker gets moderate confidence from the Nationwide relationship; a North American or EU DORA-focused buyer would need direct evidence from BT that this research did not find.
Gaps and unknowns: No evidence closes trading/low-latency connectivity, data-centre/colocation/cloud on-ramps, third-party/outsourced access controls, remote/hybrid workforce use, logging/retention specifics, incident notification timelines, subcontractor transparency, exit/portability terms, SWIFT CSP alignment, or US/Canadian regulatory alignment (FFIEC, GLBA, NYDFS, SEC, OSFI). Closing these would require BT to publish a named North American or Canadian FS case study, a SWIFT CSP or PCI DSS Attestation of Compliance naming the SD-WAN/SASE service specifically, and a customer-facing SLA document with retention, notification and exit terms. [2026-09-15] EU DORA: a specific BT DORA contract addendum PDF was referenced in a candidate research pass but could not be found on three separate live searches of bt.com/business.bt.com - no genuine BT-authored DORA content located. Treated as unresolved, not added as a source.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Not found
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Not found
- Data residency and sovereignty
- Proven
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Proven
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Proven
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Proven
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Proven
- North America delivery
- Not found
- Global delivery
- Proven
Sources (19)
- FIN-141AcceptedProvider-authoredNamed customer case study
- Named service:
- Agile Connect (Nuage SD-WAN) with Managed Fortinet Firewall and Managed Cloud Security
- Sites, branches, users:
- More than 100,000 employees
- Countries, regions:
- More than 30 countries
- Regulatory regime:
- Multiple
- Outcome:
- Higher bandwidth, greater connectivity and flexibility at lower costs; simpler deployment and greater control over their network
Network is segmented too. So if a breach happens in one area, data in other areas stays protected
BT describes an SD-WAN and managed Fortinet firewall deployment for an unnamed European bank with over 100,000 employees across more than 30 countries, covering segmentation, resilience and a single management view.
Does not prove: The bank is anonymised (described only as 'one of Europe's biggest banks'), so this cannot prove a named-institution deployment; it does not mention trading, data-centre/cloud on-ramps, cardholder data scope, RTO/RPO figures or regulatory regimes by name.
· Checked 12 Sept 2026 · Supports: Network visibility and reporting, Network segmentation and zoning, Branch and office connectivity, Resilience and tested recovery, Global delivery
- FIN-144AcceptedProvider-authoredFinancial services solution page
Banking Cyber Security | Industries | BT Business
- Named financial institution:
- Nationwide
- Named service:
- Managed Identity and Access Management; Secure Access Service Edge (SASE); Zero Trust Network Access (ZTNA)
- Regulatory regime:
- UK
Create a more protective environment with SASE. It combines SD-WAN and Secure Services Edge (SSE) - that are seamlessly integrated.
BT's banking-specific cyber security page names SASE (with ZTNA and, via SSE, CASB) as part of its offer to banks, and references Nationwide as a banking customer, but without a described deployment.
Does not prove: Quoted wording not found on the page in the 2026-09-12 check (Exact phrase not found; page instead reads 'Create a more protective environment with SASE. It combines SD-WAN and Secure Services Edge (SSE) - that are seamles). Re-quote before accepting. This is a financial services solution page, not a named-deployment case study; Nationwide is referenced generically ('Banks like Nationwide have to take the frontline'), not as a customer of the SASE/ZTNA product specifically. [2026-09-15 Harry review] Verified live 2026-09-15. Re-quoted using the checker's own found wording. Generic banking-industry page; Nationwide is mentioned only as an example sector reference, not as a customer of BT's SASE/ZTNA product - kept at whatever capability level (Partial) was already recorded, not Proven.
business.bt.com · Checked 15 Sept 2026 · Supports: Identity and zero trust access, Cloud and SaaS data controls
- FIN-146AcceptedProvider-authoredNamed customer case study
Nationwide case study: Network security
- Named financial institution:
- Nationwide Building Society
- Named service:
- BT network security, threat management and 24-hour monitoring services
- Countries, regions:
- UK
- Standard or regulation:
- PCI DSS; ISO 20000; FCA and PRA
- Regulatory regime:
- UK
- Outcome:
- BT operational teams permanently based in Nationwide's Enterprise Command Centre providing 24-hour proactive and reactive monitoring
The Financial Conduct Authority and Prudential Regulation Authority are testing security controls and technologies together.
BT describes a six-year network security engagement with Nationwide Building Society including 24-hour monitoring from BT staff based in Nationwide's own command centre, PCI DSS conformance and ISO 20000 accreditation, in a context that names the FCA and PRA.
Does not prove: The named service is network security/threat management, not an SD-WAN or SASE product by name, so it does not prove branch connectivity, segmentation architecture or SASE-specific capability; it does not state RTO/RPO, data residency or incident notification timelines.
business.bt.com · Published 27 Apr 2018 · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation, UK regulatory alignment (FCA and PRA), Managed operations and SOC, PCI DSS alignment, UK delivery
- FIN-148AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- BT Managed SASE
- Countries, regions:
- UK
- Regulatory regime:
- UK
UK-resident logging and management to meet local regulatory standards
BT's Managed SASE product page states UK-resident logging and management, describes ZTNA replacing VPNs and describes DLP-style monitoring to prevent data leaks from cloud apps such as Microsoft 365, with 24/7 UK-based monitoring.
Does not prove: This is a general product page, not financial-services-specific, and names no financial institution, so it cannot prove FS-specific identity/zero trust or CASB/DLP use; only the documented data residency and UK delivery facts are directly supported.
· Checked 12 Sept 2026 · Supports: Data residency and sovereignty, Cloud and SaaS data controls, UK delivery
- FIN-149AcceptedProvider-authoredCompliance attestation or statement
Managed SD-WAN from BT: Building a future proof network
- Named service:
- Managed SD-WAN from BT
- Countries, regions:
- UK
- Regulatory regime:
- Not stated
UK-based operation centres to keep a proactive eye on your network, giving you support and guidance whenever you need it, 24/7
BT's Managed SD-WAN product brochure describes UK-based 24/7 operations centres, a dedicated project management team for onboarding, and real-time analytics on applications, users and devices.
Does not prove: No SLA figures, RTO/RPO, encryption or data residency detail is given in this document; it is not financial-services-specific and names no customer.
business.bt.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting, UK delivery
- FIN-152AcceptedProvider-authoredCompliance attestation or statement
BT Managed Fortinet SD-WAN (Annex to Managed Services Schedule)
- Named service:
- BT Managed Fortinet SD-WAN
- Countries, regions:
- USA, UK, India, Canada, UAE, Germany, France, Singapore, Australia, Japan
- Regulatory regime:
- Multiple
Transport Independent VPN...transfer information securely across your network and the Internet using encryption technology.
The contractual annex for BT Managed Fortinet SD-WAN describes VPN-based encryption, tiered change requests (a 'Simple Service Request' for application category changes, 30 days notice for vCPU changes) and restricts FortiSASE use to specific in-country PoPs, but states that formal Service Levels and Service Credits do not apply to the Fortinet service itself.
Does not prove: No FIPS validation or key-management detail is given, and the document explicitly states no SLA/service credits apply to this service, so it cannot support a resilience/RTO-RPO or incident-notification-timeline claim; it is not financial-services-specific.
business.bt.com · Checked 12 Sept 2026 · Supports: Change control and configuration governance, Encryption and key management
- FIN-154AcceptedProvider-authoredCompliance attestation or statement
Getting ready for DORA | BT Business
- Named service:
- BT Radianz cloud ecosystem (referenced only generically)
- Countries, regions:
- EU
- Standard or regulation:
- DORA
- Regulatory regime:
- EU
Our Radianz solutions cloud ecosystem brings together a community of thousands of financial institutions...highly reliable, resilient and secure connectivity
A BT article explaining DORA to financial services readers, positioning the Radianz cloud ecosystem as supporting resilient connectivity, without Article 30 contractual detail or a named EU customer.
Does not prove: No Article 30 terms, DORA testing commitments or named EU financial institution are given; the only product referenced (Radianz) had by the time of a separate BT page been sold to Transaction Network Services, so it is not confirmed as a current BT-delivered service.
business.bt.com · Checked 12 Sept 2026 · Supports: EU DORA alignment
- FIN-155AcceptedProvider-authoredNamed customer case study
Global SD-WAN Rollout | Case Studies
- Named service:
- SD-WAN solutions (Cisco Viptela vManage)
- Sites, branches, users:
- 10,000 to 50,000 employees; 85 sites targeted, 65 delivered
- Countries, regions:
- Global, multiple regions
- Regulatory regime:
- Not stated
- Outcome:
- $15 million savings in operating costs; 65 of 85 sites delivered within just over a year
How can a big business move with the agility of a small one?
A named-sector but unnamed-company case study describing a global SD-WAN rollout for a retail and consumer goods multinational, evidencing BT's multi-country SD-WAN delivery capability outside financial services.
Does not prove: This customer is in retail and consumer goods, not financial services, so it can only support general global-delivery capability, not any financial-services-specific column.
business.bt.com · Published 8 May 2020 · Checked 12 Sept 2026 · Supports: Global delivery
- FS-011AcceptedProvider-authoredExisting source lead
Helping a global financial services company migrate to SD-WAN
Dedicated financial services industry page (#7) listing two network case studies, plus a full SD-WAN case study (#18) stating industry 'Financial services', size 'More than 100,000 employees' and operations in more than 30 countries, delivered with Agile Connect Nuage SD-WAN and BT Managed Fortinet Firewall. The case study title is independently corroborated on BT Ireland's listing (#30). The customer itself is not named, which is the one weakness.
Does not prove: Supplier's dedicated industry page listing two named network/SD-WAN case studies. | Confirmed - exact match [2026-09-15, capability assigned per Robert's check] Anonymised "global financial services company" SD-WAN migration - no institution named.
globalservices.bt.com · Checked 29 Jul 2026 · Supports: Branch and office connectivity
- FS-012AcceptedProvider-authoredExisting source lead
Helping a global financial services company migrate to SD-WAN | BT
- Named service:
- BT Managed SD-WAN
- Regulatory regime:
- Multiple
Helping a global financial services company migrate to SD-WAN
Dedicated financial services industry page (#7) listing two network case studies, plus a full SD-WAN case study (#18) stating industry 'Financial services', size 'More than 100,000 employees' and operations in more than 30 countries, delivered with Agile Connect Nuage SD-WAN and BT Managed Fortinet Firewall. The case study title is independently corroborated on BT Ireland's listing (#30). The customer itself is not named, which is the one weakness.
Does not prove: Anonymised SD-WAN case study. Customer not named, so weaker than a named reference. | Confirmed - exact match
globalservices.bt.com · Checked 29 Jul 2026 · Supports: Branch and office connectivity, Managed operations and SOC, Global delivery
- FIN-142RejectedProvider-authoredFinancial services solution page
Financial Services | Case Studies | BT Business
- Named service:
- BT Business financial services case studies hub
- Regulatory regime:
- Not stated
Mobile banking is growing fast - but so is the number of cyber attacks
This is an index page linking to Nationwide, Hello bank! and insurance contact-centre case studies; it does not itself name an SD-WAN or SASE deployment.
Does not prove: Pure navigation/listing page with no product or capability detail of its own; used only to locate the underlying case studies, which were opened and assessed separately.
business.bt.com · Checked 12 Sept 2026
- FIN-143RejectedProvider-authoredFinancial services solution page
Banking Solutions | Digital Transformation For Banks
- Named financial institution:
- Nationwide Building Society
- Named service:
- BT banking solutions (unnamed connectivity/cloud/cyber security portfolio)
- Regulatory regime:
- Not stated
We build secure, compliant, and robust systems that safeguard operations and customer trust.
A generic banking industry marketing page referencing an award from Nationwide Building Society, but naming no specific SD-WAN, SASE or firewall product.
Does not prove: No named product (SD-WAN/SASE/managed firewall), no regulator named, and the Nationwide reference is an award mention rather than a described deployment; does not meet the named-service test for any column.
business.bt.com · Checked 12 Sept 2026
- FIN-145RejectedProvider-authoredFinancial services solution page
Digital Financial Services Solutions | Digital Transformation
- Named service:
- BT financial services portfolio (unnamed)
- Regulatory regime:
- Not stated
strengthen operational resilience, protect critical services and simplify compliance through secure connectivity, cyber security expertise and cloud-ready networks
A generic financial services landing page describing themes of resilience and compliance without naming SD-WAN, SASE, a firewall product, a regulator or a customer.
Does not prove: No named product, no named customer, no named regulation; generic marketing language only, so cannot support any column beyond noting the provider targets financial services.
business.bt.com · Checked 12 Sept 2026
- FIN-147RejectedProvider-authoredFinancial services solution page
Top three security challenges facing financial services | BT Business
- Named service:
- BT threat intelligence, managed firewall, managed DDoS protection, managed cloud security
- Regulatory regime:
- UK
5,857 cyber security incident reports from financial businesses in 2020
A thought-leadership article on ransomware, DDoS and tech complexity in financial services, citing an FCA incident-report statistic, but not naming SD-WAN, SASE or a specific customer.
Does not prove: FCA is mentioned only as a source of a general statistic, not as a compliance statement about a named BT service; no SD-WAN/SASE/firewall product is named.
business.bt.com · Checked 12 Sept 2026
- FIN-150RejectedProvider-authoredCompliance attestation or statement
BT's Security Assurance and Compliance | BT Business
- Named service:
- BT products (general)
- Standard or regulation:
- SOC 2
- Regulatory regime:
- Not stated
Service Providers that achieve their Attestation (SOC2 Report) have undertaken a thorough examination of their security controls and have demonstrated compliance to the Trust Principles within the SSAE Standard.
A general BT Business help article stating that BT's assurance practices reference ISO, SOC and NIST standards and that a SOC 2 report is available to customers under NDA, without naming SD-WAN or SASE.
Does not prove: This is a generic corporate compliance statement not tied to the named SD-WAN/SASE/firewall service, and gives no encryption, retention, residency or incident-notification detail, so it does not meet the named-service test for any column.
business.bt.com · Checked 12 Sept 2026
- FIN-151RejectedProvider-authoredNamed customer case study
BT and Hello bank! | Case Studies | BT Business
- Named financial institution:
- Hello bank! (BNP Paribas Czech branch)
- Named service:
- BT Personalised Video from Idomoo
- Sites, branches, users:
- Around 50,000 clients addressed by the welcome video campaign
- Countries, regions:
- Czech Republic (Hello bank! operates across 6 European countries)
- Regulatory regime:
- EU
- Outcome:
- Approximately 60% email open rates and improved new-customer NPS
Almost 50,000 clients have been addressed by the welcome video campaign
A named-bank case study about a personalised video onboarding product, unrelated to SD-WAN, SASE or network security.
Does not prove: The named service is a customer-communications video product, not SD-WAN/SASE/managed firewall, so it does not support any of the 28 network/security/regulatory columns.
business.bt.com · Checked 12 Sept 2026
- FIN-153RejectedProvider-authoredOther
Insurance Company Contact Centre | Case Studies
- Named service:
- Unclear (page content could not be distinguished from the case studies hub listing)
- Regulatory regime:
- Not stated
The page appears to be an insurance-sector contact-centre case study but the fetched content returned only the case studies hub listing rather than page-specific detail.
Does not prove: Could not verify page-specific content (product named, scale, outcomes); on its face it concerns a contact-centre migration, not SD-WAN/SASE, so it is unlikely to support any of the 28 columns even if re-fetched.
business.bt.com · Published 19 Dec 2023 · Checked 12 Sept 2026
- FIN-156RejectedProvider-authoredContradiction
Radianz Financial Solutions | Financial Services Solutions
- Named service:
- Radianz
- Countries, regions:
- Over 60 countries and 40 data centres (historic description)
- Regulatory regime:
- Not stated
Radianz has a long track record of supporting mission-critical financial communications. Joining TNS brings complementary strengths and continued investment for customers.
BT's own page confirms that its Radianz financial extranet business has been sold to Transaction Network Services (TNS) and is no longer a current BT-delivered product.
Does not prove: Radianz is confirmed divested to TNS, so it cannot be used as evidence of a current BT financial services network product, and it contradicts using Radianz as live BT evidence elsewhere (e.g. the DORA article).
business.bt.com · Checked 12 Sept 2026
- FS-013RejectedProvider-authoredExisting source lead
Helping a global financial services company migrate to SD-WAN
Dedicated financial services industry page (#7) listing two network case studies, plus a full SD-WAN case study (#18) stating industry 'Financial services', size 'More than 100,000 employees' and operations in more than 30 countries, delivered with Agile Connect Nuage SD-WAN and BT Managed Fortinet Firewall. The case study title is independently corroborated on BT Ireland's listing (#30). The customer itself is not named, which is the one weakness.
Does not prove: Supplier's Ireland property. Corroborates the SD-WAN financial services case study title and Ireland presence. | Not found on page
btireland.com · Checked 29 Jul 2026
12AT&T Business
7 of 28 proven9 of 15 sourcesOpenClose
AT&T Business on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
AT&T Business has one clearly evidenced financial services deployment: COCC, a US core banking technology provider serving over 150 community banks and credit unions, runs AT&T SD-WAN with VeloCloud with stated automatic failover, micro-segmentation, end-to-end encryption and PCI-DSS compliance support, and a 75% cut in network downtime. This evidence is US-only and product-level compliance documentation (SOC 1/SOC 2, ISO 22301, PCI-DSS AoC) names specific SD-WAN service variants, but none of it is tied to UK FCA/PRA, EU DORA, Canadian OSFI or detailed US FFIEC/GLBA/NYDFS rules for any financial customer. The SASE and SASE-with-Fortinet material is generic product documentation with no named financial customer. The main limitation is the absence of any UK or EU financial services case, any named trading or capital markets customer, and any documented data residency, log retention period or subcontractor list for the SD-WAN/SASE services.
Gaps and unknowns: No evidence was found for UK FCA/PRA alignment, EU DORA alignment, Canadian OSFI alignment, SWIFT CSP alignment, third-party/outsourced access controls, change control and configuration governance, exit and portability, subcontractor transparency, or data residency; closing these would require named UK/EU/Canadian financial services case studies or AT&T compliance statements that explicitly reference those regimes and the SD-WAN/SASE service, plus a published data residency and subcontractor disclosure document. Trading/low-latency, remote workforce and data-centre/cloud connectivity are only supported by generic industry-survey material rather than a named institution.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Partial
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Proven
- Payment and cardholder data segmentation
- Proven
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Not found
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Proven
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Not found
- Incident notification support
- Partial
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Partial
- Global delivery
- Partial
Sources (12)
- FIN-114AcceptedProvider-authoredNamed customer case study
Software Defined Wide Area Network (SD-WAN) Customer Story For COCC at AT&T
- Named financial institution:
- COCC
- Named service:
- AT&T SD-WAN with VeloCloud
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- Enhanced network security, reliability and performance while helping reduce costs
COCC today serves more than 150 community banks and credit unions and is the sixth largest core banking solutions provider in the U.S.
AT&T's SD-WAN with VeloCloud is deployed by COCC, a core banking technology provider serving over 150 community banks and credit unions in the US, to give automatic failover and improved network reliability.
Does not prove: Does not name individual banks or credit unions, does not mention trading/low-latency, cloud on-ramps, PCI scope, or any regulatory regime; no branch/user counts given.
business.att.com · Checked 12 Sept 2026 · Supports: Branch and office connectivity, Resilience and tested recovery
- FIN-115AcceptedProvider-authoredNamed customer case study
CUSTOMER STORIES About COCC (AT&T/COCC customer story brief)
- Named financial institution:
- COCC
- Named service:
- AT&T SD-WAN with VeloCloud
- Countries, regions:
- United States (10 states)
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- US
- Outcome:
- 75% reduction in downtime for COCC networks; 80% reduction in help desk calls following WAN outages
75% reduction in downtime for COCC networks
The AT&T/COCC brief states COCC uses micro-segmentation, a centralised firewall and end-to-end encryption on the AT&T SD-WAN with VeloCloud service, with PCI-DSS compliance support, and reports a 75% cut in network downtime and 80% fewer help-desk calls after outages.
Does not prove: COCC is a core banking technology provider, not itself a bank; PCI-DSS reference is 'compliance assistance', not a formal AoC for the SD-WAN service itself; no RTO/RPO figures, no trading, no UK/EU/Canada content.
business.att.com · Published 5 Mar 2020 · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation, Network segmentation and zoning, Branch and office connectivity, Resilience and tested recovery, Encryption and key management, PCI DSS alignment
- FIN-117AcceptedProvider-authoredOther
SD-WAN Service Provider - Software Defined Wide Area Network at AT&T Business
- Named service:
- AT&T Managed SD-WAN
- Countries, regions:
- 150+ countries and territories
- Regulatory regime:
- Not stated
Gain actionable insights into user, network, and application performance
AT&T's SD-WAN product page describes Managed SD-WAN with Cisco, VMware and Aruba, offering dynamic routing across broadband, LTE and MPLS, round-the-clock support, and a single dashboard for visibility, but contains no financial services or regulatory content.
Does not prove: Generic product page, not financial-services specific; supports generic resilience/visibility/managed-ops claims only, not tied to a named bank or credit union.
business.att.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Resilience and tested recovery, Managed operations and SOC
- FIN-118AcceptedProvider-authoredOther
Managed SASE Cybersecurity Network Solution | AT&T Business
- Named service:
- AT&T SASE (with Cisco, Palo Alto Networks)
- Countries, regions:
- Not stated
- Regulatory regime:
- Not stated
Reduce risk of breaches and enforce strict identity verification regardless of location.
AT&T's SASE product page describes AT&T Managed SASE with Cisco and Palo Alto Networks, covering ZTNA, CASB, secure web gateway and firewall-as-a-service, managed by AT&T, with no financial services or regulatory content and no mention of Fortinet on this page.
Does not prove: Quoted wording not found on the page in the 2026-09-12 check (Page loaded and has a 'Managed by AT&T security experts' heading but the quoted sentence text was not found verbatim; model returned an unrelated sentence from ). Re-quote before accepting. Generic product page, not financial-services specific; no named customer; Fortinet variant not shown on this page (found via a separate solution brief). [2026-09-15 Harry review] Verified live 2026-09-15 at business.att.com/products/sase.html. Re-quoted verbatim. Generic product page, no named financial customer, so Identity and zero trust access is Partial not Proven. Cloud and SaaS data controls and Managed operations and SOC dropped - no exact matching text found for either on this page.
business.att.com · Checked 15 Sept 2026 · Supports: Identity and zero trust access, Cloud and SaaS data controls, Managed operations and SOC
- FIN-119AcceptedProvider-authoredOther
AT&T SASE Branch with Fortinet solution brief
- Named service:
- AT&T SASE Branch with Fortinet
- Countries, regions:
- Not stated
- Regulatory regime:
- Not stated
Highly scalable overlay VPN tunnels with high throughput to encrypt traffic
This solution brief describes AT&T SASE Branch with Fortinet, covering encrypted overlay VPN tunnels, granular branch segmentation via Fortinet switches, and 24/7 monitoring from AT&T's Security Network Operations Center, with no financial services content.
Does not prove: Generic solution brief, no financial services customer or regulatory mention; does not name ZTNA, CASB or DLP on this document.
business.att.com · Published 22 Sept 2022 · Checked 12 Sept 2026 · Supports: Network segmentation and zoning, Managed operations and SOC
- FIN-121AcceptedProvider-authoredFinancial services solution page
Transforming the Network in Financial Services (Fall 2022)
- Named service:
- SD-WAN; SASE; edge technology
- Countries, regions:
- Not stated
- Regulatory regime:
- Not stated
- Outcome:
- 54% of surveyed financial services companies currently use SD-WAN; edge technology can reduce latency to under 6 milliseconds
Data compliance and security should always take precedence.
This AT&T-sponsored financial services report cites industry survey data on SD-WAN and SASE adoption and notes that edge technology can cut trading latency to under 6 milliseconds and that 74% of respondents found adapting networks for hybrid work their biggest challenge, but it names no institution and no regulatory regime.
Does not prove: Industry survey report, not a named customer deployment; low-latency and remote-work statistics are sector-wide survey findings, not evidence that a named institution runs AT&T's service for trading or remote staff.
business.att.com · Published 1 Sept 2022 · Checked 12 Sept 2026 · Supports: Trading and low-latency connectivity, Remote and hybrid workforce
- FIN-124AcceptedProvider-authoredOther
AT&T Global Business Services | Internet Connectivity, Networking & Wireless
- Named service:
- AT&T Global Business connectivity, colocation ecosystem
- Countries, regions:
- 200 countries and territories; Canada since 1980; EMEA; APAC; Latin America and Caribbean
- Regulatory regime:
- Not stated
800+ datacenters in our global colocation ecosystem
AT&T's global business page states it offers Ethernet and internet connectivity in 200 countries and territories, over 800 data centres in its colocation ecosystem, and a presence in Canada since 1980 and EMEA/APAC/Latin America, and names 'financial services' generically as a served sector with 'secure, reliable connectivity for banking and payments'.
Does not prove: Financial services mention is a one-line generic sector tag, not tied to SD-WAN or SASE, and names no bank; UK is not separately itemised outside EMEA; no named FS customer for any region.
business.att.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, North America delivery, Global delivery, UK delivery
- FIN-518AcceptedProvider-authoredCompliance attestation or statement
AT&T Information & Network Security Customer Reference Guide, April 2026 v8.0
- Named service:
- AT&T managed network / SD-WAN service families
- Standard or regulation:
- PCI DSS; SOC 2; ISO 27001; SSAE 18/ISAE 3402
References SOC reporting, PCI DSS reporting, ISO 27001, and SSAE 18/ISAE 3402 assurance across managed network/SD-WAN service families.
Harry personally verified this live 2026-09-15. Covers managed network/SD-WAN service families generally rather than naming AT&T's specific SASE product by name with a scoped AoC - graded Partial, consistent with the caution that the exact SD-WAN variant on any AoC needs separate confirmation.
Does not prove: Added 2026-09-15, Harry-verified. Family-level assurance document, not confirmed scoped to AT&T's SASE product specifically.
business.att.com · Published 1 Apr 2026 · Checked 15 Sept 2026 · Supports: Managed operations and SOC, PCI DSS alignment
- FIN-538AcceptedProvider-authoredNamed customer case study
- Named financial institution:
- Wellby Financial
- Named service:
- AT&T Dynamic Defense with Palo Alto Networks (Prisma Access)
- Countries, regions:
- United States (Houston, Texas)
- Regulatory regime:
- US
- Outcome:
- Multi-pathing and redundancy to reduce single points of failure and keep critical access reliable during connection or data centre disruption
"For a financial institution like Wellby Financial, resilience goes beyond IT priority. It is a business imperative... To advance their cybersecurity and resilience strategy, Wellby turned to AT&T Dynamic Defense with Palo Alto Networks - the first-and-only comprehensive network security solution with threat protection integrated directly into AT&T's global network infrastructure, enhanced by best-in-class capabilities from Palo Alto Networks Prisma Access."
Verified live 2026-09-15. Wellby Financial is a real, named Houston-based credit union. Recent article (July 2026). No named executive quote or quantified outcome, but the deployment and named product are specific and real.
Does not prove: Added 2026-09-15 per further research pass (cross-platform lead, independently verified). No quantified outcome or named executive quote; no specific US regulator named. Automated access returned HTTP 403 on 2026-09-15. Retain as supporting evidence, but do not rely on it as the sole publicly citable source.
about.att.com · Published 29 Jul 2026 · Checked 15 Sept 2026 · Supports: Resilience and tested recovery, Managed operations and SOC
- FIN-116RejectedProvider-authoredFinancial services solution page
Financial Technology & Security Solutions at AT&T Business
- Named service:
- AT&T Managed SASE; AT&T Dynamic Defense; AT&T SD-WAN
- Countries, regions:
- Not stated
- Regulatory regime:
- Not stated
Better protect data with a multi-layered approach
AT&T's financial services industry page lists Managed SASE, Dynamic Defense and SD-WAN as relevant products and names Patelco Credit Union as a customer for a digital signage solution, but names no bank or credit union customer for SD-WAN or SASE and cites no regulatory regime.
Does not prove: Generic financial services solutions page with no named SD-WAN/SASE deployment and no regulatory regime named; cannot support any Proven column, only used as background/context.
business.att.com · Checked 12 Sept 2026
- FIN-122RejectedProvider-authoredNamed customer case study
Networking & Wireless Broadband Customer Story For Patelco - AT&T Business
- Named financial institution:
- Patelco Credit Union
- Named service:
- AT&T Wireless Broadband and digital signage/consulting integration
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- Remote monitoring tools help ensure uptime and avoid branch involvement in troubleshooting
help ensure uptime and avoid branch involvement in troubleshooting
Patelco Credit Union, a US credit union with 350,000 members, uses AT&T wireless broadband and consulting/integration services for branch digital signage, not SD-WAN or SASE.
Does not prove: Does not name AT&T SD-WAN, SASE or Managed SD-WAN; the service described is wireless broadband for digital signage, out of scope for this brief's product requirement.
business.att.com · Checked 12 Sept 2026
- FIN-123RejectedProvider-authoredOther
Next-generation networking use case (retail SD-WAN deployment)
- Named service:
- Cisco SD-WAN via AT&T; AT&T Wireless Broadband
- Sites, branches, users:
- 6,000+ sites
- Countries, regions:
- United States
- Regulatory regime:
- Not stated
- Outcome:
- 6,000+ sites deployed within five months, greater than 95% first-time success rate for site turn-ups
This solution brought 6000+ sites online within a five-month period (average of 400 sites per week)
This case study describes a large US retail chain's rapid SD-WAN rollout across more than 6,000 stores; it is not a financial services customer.
Does not prove: Customer is a retail chain, not a financial institution; not usable for any financial services column.
business.att.com · Published 22 Jun 2022 · Checked 12 Sept 2026
13Cisco
7 of 28 proven12 of 15 sourcesOpenClose
Cisco on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
The strongest named evidence is BBVA Argentina's deployment of Cisco Catalyst SD-WAN, SD-Access, Catalyst Center and ISE across 245 branches, which proves branch connectivity, identity based segmentation, network visibility and configuration automation for a retail bank, though this deployment is in Argentina and gives no UK or North America delivery evidence. Cisco's own documentation proves FIPS 140-3 validated encryption for Catalyst SD-WAN and a PCI DSS 3.2.1 Attestation of Compliance for Catalyst SD-WAN Cloud as a Level 1 service provider, both at the product documentation level rather than tied to a named customer. No evidence was found connecting the named products to FCA and PRA operational resilience rules, EU DORA, US FFIEC, GLBA, NYDFS or SEC rules, Canadian OSFI guidance, or SWIFT CSP. Data residency, log retention, incident notification and subcontractor transparency for the named services were also not found on the pages opened. Overall this is reasonable evidence of a technical branch deployment and of product level compliance certification, but weak evidence of regime specific regulatory alignment or of delivery in the UK and North America for financial services customers specifically.
Gaps and unknowns: No UK or North American named financial institution using Catalyst SD-WAN, Secure Access, Meraki SD-WAN or Secure Connect was found, leaving UK delivery and North America delivery unproven; a named UK or North American FS case study would close this. FCA and PRA, DORA, FFIEC/GLBA/NYDFS/SEC and OSFI alignment are all unproven and would need a Cisco compliance statement or named FS case explicitly referencing those regimes, not just generic certifications. Log retention periods, a published subcontractor or sub-processor list, and incident notification timelines specific to Secure Access or Catalyst SD-WAN were not located on the pages opened. Trading floor or low-latency connectivity, cardholder data segmentation, third-party and outsourced access controls, and a named FS customer with 24x7 managed SOC would also close remaining gaps.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Proven
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Partial
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Proven
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Proven
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Partial
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Not found
- Global delivery
- Partial
Sources (14)
- FIN-180AcceptedProvider-authoredNamed customer case study
BBVA Banks on Secure, Agile Operations (Cisco case study)
- Named financial institution:
- BBVA Argentina
- Named service:
- Cisco SD-Access, Cisco Catalyst SD-WAN, Cisco Catalyst Center, Cisco ISE, Cisco ACI
- Sites, branches, users:
- 245 branches across Argentina plus a main campus in Buenos Aires
- Countries, regions:
- Argentina, described as a reference model being extended to BBVA entities in Colombia, Peru and the wider global group
- Regulatory regime:
- Not stated
- Outcome:
- Release windows cut by over 75%; switch deployment time reduced from three months to three weeks; new switches join the fabric automatically within minutes
With Cisco SD-Access, access policies follow the user, regardless of where they connect. That means consistent security, simplified segmentation, and seamless mobility without the IT headaches.
BBVA Argentina deployed Cisco SD-Access, Catalyst Center, Catalyst SD-WAN, ISE and ACI across 245 branches, using identity-based micro-segmentation and automated zero-touch provisioning to cut configuration errors and speed up switch deployment.
Does not prove: Does not mention any financial regulator, PCI or cardholder-data scope, data residency, DR testing, RTO/RPO, or third-party/contractor access controls. The deployment is in Argentina, not the UK or North America, so it cannot support the UK or North America delivery columns.
cisco.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Change control and configuration governance, Network visibility and reporting, Network segmentation and zoning, Branch and office connectivity, Identity and zero trust access, Global delivery
- FIN-181AcceptedProvider-authoredCompliance attestation or statement
Cisco Catalyst SD-WAN v20.15 FIPS 140-3 Compliance
- Named service:
- Cisco Catalyst SD-WAN Manager, Validator and Controller
- Standard or regulation:
- FIPS 140-3
- Regulatory regime:
- Not stated
incorporates the following FIPS 140-3 validated cryptographic module: Cisco FIPS Object Module version 7.3a (Certificate #4747)
Cisco Catalyst SD-WAN Manager, Validator and Controller version 20.15 incorporates a FIPS 140-3 validated cryptographic module covering TLS 1.2/1.3, SSHv2, DTLSv1.2 and SNMPv3.
Does not prove: Covers cryptographic module validation only, not a named financial customer; the document also states the CMVP has not independently evaluated this specific compliance review.
cisco.com · Published 10 Jul 2025 · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-182AcceptedProvider-authoredCompliance attestation or statement
Cisco SD-WAN achieves PCI-DSS compliance - Cisco Blogs
- Named service:
- Cisco SD-WAN Cloud (vManage, vBond, vSmart controllers)
- Standard or regulation:
- PCI DSS 3.2.1
- Regulatory regime:
- Not stated
Cisco SD-WAN does not store PCI data
Cisco SD-WAN Cloud achieved a PCI-DSS 3.2.1 Attestation of Compliance as a Level 1 Service Provider, covering the Cisco-hosted vManage, vBond and vSmart controller infrastructure, with the AoC available on request through Cisco's Trust Portal.
Does not prove: This is Cisco's own infrastructure attestation, not a customer case naming a cardholder data environment segmented with the service; article is from 2022 and does not confirm the certification is current for later PCI DSS versions.
blogs.cisco.com · Published 2 Feb 2022 · Checked 12 Sept 2026 · Supports: PCI DSS alignment
- FIN-183AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Cisco (corporate data protection programme)
- Countries, regions:
- EEA, UK, Switzerland (cross-border transfer mechanisms)
- Standard or regulation:
- GDPR
- Regulatory regime:
- EU
Cisco's data protection and privacy policies, standards, and related documentation ("BCR-C") have been approved by the European data protection supervisory authorities.
Cisco describes Binding Corporate Rules, EU-US Data Privacy Framework certification and a Master Data Protection Agreement as mechanisms for cross-border personal data transfer, at a corporate level rather than for a named SD-WAN or SASE service.
Does not prove: Describes cross-border transfer legal mechanisms, not the specific regional storage location of Catalyst SD-WAN or Secure Access logs and management-plane data; does not name the SD-WAN or SASE service.
cisco.com · Checked 12 Sept 2026 · Supports: Data residency and sovereignty
- FIN-184AcceptedProvider-authoredNamed customer case study
- Named financial institution:
- MyInvestor
- Named service:
- Cisco Multicloud Defense
- Sites, branches, users:
- Over 300,000 clients; assets under management of 6 billion euros
- Countries, regions:
- Spain
- Standard or regulation:
- GDPR
- Regulatory regime:
- EU
- Outcome:
- Full visibility of every incoming and outgoing IP connection at TCP level; no successful attacks reported since deployment; client base has doubled
The fact that we haven't had any successful attacks with Cisco Multicloud Defense matters a lot for any organization, particularly for a bank.
MyInvestor, a Spanish neobank, uses Cisco Multicloud Defense for ingress/egress traffic inspection and centralized policy control across its AWS cloud environment, citing GDPR and financial regulation as drivers.
Does not prove: Cisco Multicloud Defense is a cloud network security product, not one of the four named SD-WAN/SASE products for this profile, and is not explicitly described as CASB or DLP; GDPR is named but DORA, PCI or other FS-specific regimes are not.
cisco.com · Published 24 Jul 2025 · Checked 12 Sept 2026 · Supports: Cloud and SaaS data controls
- FIN-186AcceptedProvider-authoredOther
Cisco Secure Access Data Sheet - Cisco
- Named service:
- Cisco Secure Access
- Regulatory regime:
- Not stated
Deny access by default and grant only the appropriate, granular access as dictated by policy.
The Secure Access data sheet describes ZTNA private application access, VPN-as-a-service for remote users, SAML-based identity provider integration, and CASB/DLP features including detection of generative AI app usage.
Does not prove: Generic product data sheet with no named financial institution and no FS-specific context, so per the grading rules this supports remote workforce and cloud data control columns only as Partial evidence, not Proven.
cisco.com · Checked 12 Sept 2026 · Supports: Cloud and SaaS data controls, Remote and hybrid workforce
- FIN-187AcceptedProvider-authoredFinancial services solution page
Cisco Financial Services Solutions - Cisco
- Named service:
- Cisco (financial services portfolio, unspecified)
- Regulatory regime:
- Not stated
Gained consistent visibility and control of its public cloud to protect over 300,000 customers from threats
This is a directory-style financial services landing page linking to the NatWest, Umpqua Bank and MyInvestor customer stories and to a Cisco-AWS financial services partnership brief that references DORA in its title.
Does not prove: Does not itself name Catalyst SD-WAN, Secure Access, Meraki SD-WAN or Secure Connect against any of the 28 columns; the DORA-titled brief it links to is a Cisco-AWS partnership page, not a Cisco compliance statement naming a specific SD-WAN or SASE service. [2026-09-15, capability assigned per Robert's check - WEAK FIT, flagged for review] Customer-count marketing claim ("300,000 customers... public cloud"), no institution named. Weak fit.
cisco.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting
- FIN-188AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Cisco (general commercial data access terms)
- Regulatory regime:
- Not stated
Cisco will provide the Requested Data to You without undue delay, free of charge, and in a structured, commonly used, and machine-readable format.
Cisco's general Data Access Supplemental Terms commit to providing a customer's requested data in a structured, machine-readable format on request.
Does not prove: A general Cisco commercial term applying across Cisco offers, not stated specifically for Catalyst SD-WAN or Secure Access, and does not describe termination/exit assistance procedures.
cisco.com · Checked 12 Sept 2026 · Supports: Exit and portability
- FIN-189AcceptedProvider-authoredCompliance attestation or statement
Offer Description - Cisco Catalyst SD-WAN
- Named service:
- Cisco Catalyst SD-WAN
- Regulatory regime:
- Not stated
The Cloud Service is subject to the Cisco Catalyst SD-WAN Service Level Agreement.
The Catalyst SD-WAN offer description confirms the cloud service is covered by a separate named SLA document but does not itself state uptime percentages or RTO/RPO commitments.
Does not prove: Confirms an SLA exists for the named service but the actual SLA document with uptime and recovery commitments was not opened, so no specific resilience figures or FS customer outcome are proven.
cisco.com · Checked 12 Sept 2026 · Supports: Resilience and tested recovery
- FIN-190AcceptedProvider-authoredCompliance attestation or statement
Cisco Secure Access Compliance - Cisco
- Named service:
- Cisco Secure Access
- Standard or regulation:
- SOC 2 Type II
- Regulatory regime:
- Not stated
An AICPA audit framework assessing security, availability, and confidentiality controls
Cisco Secure Access lists SOC 2 Type 2, ISO 27001/27017/27018, CSA STAR and FedRAMP as certified, with PCI-DSS shown as available on request, plus several regional government certifications.
Does not prove: A generic certification list with no named financial customer and no specific facts (retention periods, scope, dates) tied to any single one of the 28 columns, so it is used only as background context and not cited as a status source. [2026-09-15, capability assigned per Robert's check] Describes the AICPA audit framework (SOC 2) underlying Cisco Secure Access compliance.
cisco.com · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention
- FIN-513AcceptedProvider-authoredCompliance attestation or statement
Cisco Catalyst SD-WAN compliance documentation / Cisco Trust Portal
- Named service:
- Cisco Catalyst SD-WAN (Trust Portal / compliance documentation)
- Standard or regulation:
- PCI DSS
Documentation states Catalyst SD-WAN can provide certifications including PCI DSS, SOC 2 Type II, SOC 3, ISO 27001, ISO 27701, ISO 27017, ISO 27018, delivered via dedicated encrypted, Cisco-hosted compliance-mode fabrics.
Harry personally verified this live 2026-09-15. Names the specific Catalyst SD-WAN service and PCI DSS directly, with a dedicated 'compliance mode' architecture description - a genuine product-level attestation route rather than a generic corporate certification list, so graded Proven for PCI DSS alignment specifically for Catalyst SD-WAN.
Does not prove: Added 2026-09-15, Harry-verified. Current AoC/report period and exact service SKU were not independently pulled from the Trust Portal itself.
trustportal.cisco.com · Checked 15 Sept 2026 · Supports: PCI DSS alignment
- FIN-185RejectedProvider-authoredNamed customer case study
- Named financial institution:
- NatWest
- Named service:
- Cisco Takeback and Reuse Program
- Countries, regions:
- UK
- Regulatory regime:
- Not stated
- Outcome:
- 3,000+ devices (100 tons) recycled in the first 18 months of the programme
As an IT team, we've become a lot more conscious of the environmental impact of our decisions.
NatWest and Cisco ran an IT equipment recycling and reuse programme; the case study is about sustainability and e-waste, not about SD-WAN, SASE or network security.
Does not prove: Does not name Catalyst SD-WAN, Secure Access, Meraki SD-WAN or Secure Connect, and has no bearing on any of the 28 network/security/regulatory columns; kept only to record that NatWest, a UK bank, appears in Cisco's financial services customer list for an unrelated programme.
cisco.com · Published 12 Aug 2025 · Checked 12 Sept 2026
- FIN-191RejectedProvider-authoredFinancial services solution page
Security for Financial Services - Cisco
- Named service:
- Cisco (financial services security messaging, unspecified)
- Regulatory regime:
- Not stated
Cisco delivers the secure foundation institutions need to govern autonomy at scale
A generic financial services security marketing page discussing agentic AI governance and digital resilience without naming Catalyst SD-WAN, Secure Access, Meraki SD-WAN or Secure Connect, or any specific regulation.
Does not prove: No named product, no named financial institution, and no specific regulatory or technical fact; too generic to support any of the 28 columns.
cisco.com · Checked 12 Sept 2026
- FS-019RejectedProvider-authoredExisting source lead
Cisco Networking Customer Stories
Argentine bank establishes a new standard for software-defined networking across global locations.
BBVA is a named customer carrying Cisco's own Financial Services industry label, with Cisco Catalyst SD-WAN explicitly in the deployed products list. Banco do Brasil, Fiserv and Jammu & Kashmir Bank are further published financial services customers, though SD-WAN was not confirmed in their product lists.
Does not prove: Supplier customer-story index listing named customers alongside the exact Cisco products deployed. Useful because it ties named organisations directly to Cisco Catalyst SD-WAN / Cisco Software-Defined Wide Area Network. | Not found on page
cisco.com · Checked 29 Jul 2026
14Colt Technology Services
5 of 28 proven12 of 15 sourcesOpenClose
Colt Technology Services on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Colt has verifiable financial services evidence for branch and office connectivity, identity and zero trust access, and UK delivery through the named Byblos Bank Europe case study on Colt SD-WAN, and strong capital markets material for trading, low latency and data centre connectivity through Colt PrizmNet. The strongest named customer is Byblos Bank Europe, a retail bank using Colt SD-WAN with Zscaler Zero Trust across Brussels, London and Paris. No opened page connects any Colt service to FCA, PRA, DORA, FFIEC, NYDFS, SEC, OSFI or PCI DSS for a financial services customer, so regulatory alignment is unproven for all four regimes checked. Data residency, encryption, log retention, incident notification, subcontractor transparency and exit terms are only generically stated, not documented with specifics for the named service. Overall this is workable evidence of financial sector deployment and capital markets connectivity, but the compliance and regulatory picture must be confirmed directly with Colt before relying on it for a regulated UK, EU, US or Canadian financial institution.
Gaps and unknowns: No evidence was found for payment/cardholder data segmentation, third-party access controls, logging and audit retention periods, change control governance, incident notification timelines, subcontractor transparency, exit and portability terms, or any of the four regulatory regimes (UK FCA/PRA, EU DORA, US FFIEC/GLBA/NYDFS/SEC, Canada OSFI) and PCI DSS. Closing these gaps would require Colt's own compliance or trust documentation naming the SD-WAN/SASE or PrizmNet service against each specific regime or control, plus named financial services case studies in North America and named RTO/RPO-tested resilience outcomes.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Partial
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Partial
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Proven
- Cloud and SaaS data controls
- Not found
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Not found
- SWIFT CSP alignment
- Partial
- UK delivery
- Proven
- North America delivery
- Partial
- Global delivery
- Proven
Sources (15)
- FIN-213AcceptedProvider-authoredFinancial services solution page
SD WAN in Banking & Financial Services - Colt Technology Services
- Named service:
- Colt SD WAN / Colt SASE
- Sites, branches, users:
- nearly 400 bank branches, corporate locations and data centres
- Countries, regions:
- Germany and international locations
- Regulatory regime:
- Not stated
zero trust and micro-segmentation to protect sensitive financial data
Colt describes an anonymised bank example connecting around 400 branches, corporate sites and data centres using Colt SD WAN/SASE with zero trust and micro-segmentation for financial data.
Does not prove: The bank customer described is not named, so this does not prove a specific institution deployment; it is a financial-services solution page rather than a case study, and cites no regulator or data residency specifics.
colt.net · Checked 12 Sept 2026 · Supports: Network segmentation and zoning, Encryption and key management
- FIN-214AcceptedProvider-authoredNamed customer case study
Customer Success Story - Byblos Bank Europe - Colt Technology Services
- Named financial institution:
- Byblos Bank Europe
- Named service:
- Colt SD-WAN
- Sites, branches, users:
- offices in Brussels, London and Paris
- Countries, regions:
- Belgium, UK, France
- Regulatory regime:
- Not stated
- Outcome:
- a large file can now be opened or copied remotely in as little as 7 seconds instead of half a minute
a large file can now be opened or copied remotely in as little as 7 seconds instead of half a minute
Byblos Bank Europe uses Colt SD-WAN with an MPLS connection and direct peering to Zscaler to connect its Brussels, London and Paris offices, adopting Zero Trust access control via Active Directory integration and active/active site resilience.
Does not prove: Confirms branch connectivity, zero trust and a UK office for a named bank, but states no RTO/RPO figures, no regulatory regime, and no data residency or encryption detail.
colt.net · Checked 12 Sept 2026 · Supports: Branch and office connectivity, Resilience and tested recovery, Identity and zero trust access, UK delivery
- FIN-215AcceptedProvider-authoredNamed customer case study
Leading global investment bank - Colt's SD WAN solutions for Finance
- Named service:
- Colt SD WAN
- Sites, branches, users:
- multiple European sites via two interconnected hubs
- Countries, regions:
- Europe
- Regulatory regime:
- Not stated
Leading global investment bank builds a springboard to the future. A Europe-wide SD WAN from Colt underpins the bank's digital transformation programme.
An anonymised European investment bank deployed Colt's Europe-wide SD WAN with NFV across multiple sites, using single or dual MPLS access circuits by site criticality and portal-based analytics for network visibility.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page reads 'Gain end-to-end visibility...' with added word 'Gain' vs quoted text.). Re-quote verbatim. The bank is not named, so this cannot prove a specific institution's outcome; no RTO/RPO or regulator is stated. [2026-09-15] Live page confirmed and re-quoted verbatim using its title/subtitle rather than the originally-flagged 'end-to-end visibility' sentence, which sits further into the page body and could not be isolated from the search excerpt. The bank itself remains anonymised throughout.
colt.net · Checked 15 Sept 2026 · Supports: Network visibility and reporting, Resilience and tested recovery
- FIN-217AcceptedProvider-authoredOther
- Named service:
- Colt SASE
- Regulatory regime:
- Not stated
enterprises can no longer rely on traditional solutions to keep their systems secure
Colt launched a Versa-based full SASE solution combining SD-WAN and Secure Service Edge features, including a secure web gateway and remote access; no financial services customer or FS-specific control is named.
Does not prove: This is a general product launch announcement with no financial institution named and no FS-specific compliance or control detail, so it supports no column as Proven. [2026-09-15, capability assigned per Robert's check - WEAK FIT, flagged for review] Generic SASE product-launch announcement, no specific technical claim beyond general positioning. Weak fit.
colt.net · Published 28 Jun 2022 · Checked 12 Sept 2026 · Supports: Cloud and SaaS data controls
- FIN-218AcceptedProvider-authoredFinancial services solution page
Financial Extranet | Colt Capital Markets
- Named service:
- Colt PrizmNet (Financial Extranet)
- Countries, regions:
- Europe, Asia and US
- Regulatory regime:
- Not stated
A secure, high-performance extranet connecting 180+ financial venues and 15,000+ participants worldwide.
Colt describes PrizmNet as a financial extranet connecting over 180 venues and 15,000 participants, with sub-millisecond, guaranteed deterministic low latency and a 24x7 Capital Markets Service Desk.
Does not prove: No individual financial institution is named; this is capital markets marketing material, not a customer case study, and states no regulatory regime or RTO/RPO.
colt.net · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Trading and low-latency connectivity, Managed operations and SOC
- FIN-219AcceptedProvider-authoredFinancial services solution page
- Named service:
- Colt PrizmNet
- Sites, branches, users:
- More than 400 Capital Markets firms worldwide
- Countries, regions:
- Europe, Asia and North America; 230+ cities in 40 countries
- Regulatory regime:
- Not stated
Direct market access to 50+ cross asset class venues
Colt's PrizmNet datasheet states direct market access to over 50 cross-asset venues, colocation at 30+ venues, over 180 exchanges and liquidity venues globally, and a network reaching 230+ cities in 40 countries used by more than 400 capital markets firms.
Does not prove: No individual bank or firm is named; North America presence is stated only generically without named US or Canadian customers or PoP counts.
docs.colt.net · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Trading and low-latency connectivity, North America delivery, Global delivery
- FIN-220AcceptedProvider-authoredNamed customer case study
Leading provider of financial markets data - Colt Technology Services
- Named service:
- Colt Managed Ethernet
- Countries, regions:
- Europe extending to Japan and Asia
- Regulatory regime:
- Not stated
- Outcome:
- 99.999% Network uptime enabled by a diverse network architecture
99.999% Network uptime enabled by a diverse network architecture
An anonymised market data and trading solutions provider used Colt's managed Ethernet network across Europe, Japan and Asia, citing 99.999% uptime from a diverse network architecture.
Does not prove: The customer is anonymised and the product used is managed Ethernet, not SD-WAN or SASE; no RTO/RPO or DR test detail is given.
colt.net · Checked 12 Sept 2026 · Supports: Resilience and tested recovery
- FIN-221AcceptedProvider-authoredFinancial services solution page
- Named service:
- Colt SWIFTNet
- Sites, branches, users:
- hundreds of connected SWIFT members
- Standard or regulation:
- SWIFT accreditation
- Regulatory regime:
- Not stated
- Outcome:
- +12.1% growth in SWIFT message traffic year on year
a fully managed, SWIFT accredited connectivity solution built on Colt's high quality MPLS network
Colt SWIFTNet is described as a fully managed, SWIFT-accredited MPLS connectivity service with automatic failover between access lines, CPE routers and VPN boxes, and optional dual-CPE resilience packs.
Does not prove: SWIFTNet is connectivity to SWIFT, not SD-WAN or SASE; the page states SWIFT accreditation but does not reference the SWIFT Customer Security Programme or CSCF secure-zone design, and no institution or RTO/RPO figures are given.
colt.net · Checked 12 Sept 2026 · Supports: Resilience and tested recovery, SWIFT CSP alignment
- FIN-222AcceptedProvider-authoredOther
SD WAN & SASE | Colt Technology Services
- Named service:
- Colt SD WAN & SASE
- Regulatory regime:
- Not stated
keeps data within its own network and in specific regions, avoiding third-party transfers
Colt's SD WAN & SASE product page describes a Sovereign SASE option that keeps data within specific regions, a self-service portal with traffic analytics, secure remote access for employees, and support for multiple SD-WAN vendors including Versa, Cisco and Palo Alto.
Does not prove: This is a general product page, not financial-services specific and names no customer; it does not state which regions Sovereign SASE covers or give SLA figures.
colt.net · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Data residency and sovereignty, Encryption and key management, Remote and hybrid workforce
- FIN-223AcceptedProvider-authoredOther
Solutions Overview: Security - Colt Technology Services
- Named service:
- Colt security solutions (SD WAN & SASE)
- Regulatory regime:
- Not stated
Zero trust continuously verifies users and makes it easy for your people to securely access the data and apps they need.
Colt's security solutions overview describes continuous zero-trust user verification and references a world-first transatlantic quantum-safe encryption trial with Eurofiber; Capital Markets is listed as a served industry.
Does not prove: No ZTNA or MFA product name, no FIPS validation, and no financial services customer or regulator is referenced; the quantum-safe encryption item is a trial, not a general service feature.
colt.net · Published 14 Jan 2026 · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Encryption and key management
- FIN-526AcceptedProvider-authoredCompliance attestation or statement
DORA (Digital Operational Resilience Act) - Colt Legal
- Named service:
- Colt's DORA-compliant contract amendment
- Standard or regulation:
- DORA - a contract amendment available on request
- Regulatory regime:
- EU
"To support our existing customers who are regulated financial entities operating within the European Union, Colt has developed a DORA-compliant contract amendment which aligns with the requirements of the Digital Operational Resilience Act."
Colt's own legal page, verified live 2026-09-15 across multiple mirrors (docs.colt.net, legacy.colt.net, www.colt.net) with identical wording, and independently corroborated by an interview with Colt's Deputy General Counsel (Alessandro Galtieri) discussing exactly this DORA addendum process with customers. The amendment itself is only available on request, not published, so the actual Article 30 contractual terms cannot be read or verified - graded Partial, not Proven, and not tied to a named service or financial customer.
Does not prove: Added 2026-09-15 per item 6 sweep, following up on a candidate lead. The amendment exists and is real, but is provided on request rather than published, so cannot be verified to actually contain Article 30 terms as written - stays Partial.
docs.colt.net · Checked 15 Sept 2026 · Supports: EU DORA alignment
- FS-024AcceptedProvider-authoredExisting source lead
Capital Markets | Colt Technology Services
- Named service:
- Colt PrizmNet
- Regulatory regime:
- EU
18/25 of the top global banks trust us with their critical infrastructure and connectivity
Dedicated Capital Markets industry page with named customers Stuttgart Stock Exchange, Byblos Bank Europe and RCI Bank and Services. Byblos Bank Europe is quoted on a Colt and Zscaler SSE deployment: "Compared to our previous VPN-based approach, the Colt and Zscaler solution is a real enhancement that delivers a faster and better user experience and helps increase productivity" (Ramy Matar, Network Consultant, BBE). Note the focus is capital markets and trading connectivity rather than retail banking or insurance; the 18/25 top global banks figure is a vendor claim with no source cited on the page.
Does not prove: Supplier industry page. Named financial customers (Stuttgart Stock Exchange, Byblos Bank Europe, RCI Bank and Services) with attributed quotes plus a top-25-banks penetration claim. Strong but vendor-claimed. | Confirmed - exact match
colt.net · Checked 29 Jul 2026 · Supports: Identity and zero trust access
- FIN-216RejectedProvider-authoredCompliance attestation or statement
Technical Certifications | Colt Technology Services
- Named service:
- Colt Technology Services (company-wide)
- Standard or regulation:
- ISO/IEC 27001:2022; ISO/IEC 27701:2019; ISO 22301:2019; ISO 9001:2015; ISO/IEC 20000-1:2018; ISO 14001:2015; Cyber Essentials Plus
- Regulatory regime:
- Not stated
Best-practice information security processes
Colt lists company-wide certifications including ISO 27001, ISO 27701, ISO 22301, ISO 9001, ISO 20000-1, ISO 14001 and Cyber Essentials Plus, none of which are tied to the SD-WAN or SASE product specifically or to financial services.
Does not prove: No PCI DSS, SOC 2 or FIPS certification is listed; none of the certifications are scoped to the named SD-WAN/SASE service or to a financial services customer, so this supports no column as Proven. [2026-09-15, flagged per Robert's check] Generic phrase ("best-practice information security processes") with no specific technical claim. Does not appear to support any specific capability honestly. Changed from Accepted to Needs review since no specific capability can be honestly assigned - recommend Harry/Robert decide whether to Reject or find a genuine capability fit.
colt.net · Checked 12 Sept 2026
- FS-025RejectedProvider-authoredExisting source lead
Networking News, Resources, Trends & Industry Insights - Colt
18/25 of the top global banks trust us with their critical infrastructure and connectivity
Dedicated Capital Markets industry page with named customers Stuttgart Stock Exchange, Byblos Bank Europe and RCI Bank and Services. Byblos Bank Europe is quoted on a Colt and Zscaler SSE deployment: "Compared to our previous VPN-based approach, the Colt and Zscaler solution is a real enhancement that delivers a faster and better user experience and helps increase productivity" (Ramy Matar, Network Consultant, BBE). Note the focus is capital markets and trading connectivity rather than retail banking or insurance; the 18/25 top global banks figure is a vendor claim with no source cited on the page.
Does not prove: Supplier resource library. Its industry filter taxonomy (Capital Markets, Defence, Manufacturing, Media & Entertainment, Pharma, Professional services, Retail, Transport & Logistics) is the fullest statement of the sectors Colt indexes content against. | Not found on page
colt.net · Checked 29 Jul 2026
- FS-023SupersededProvider-authoredExisting source lead
Solutions - Colt Technology Services (industries hub)
18/25 of the top global banks trust us with their critical infrastructure and connectivity
Dedicated Capital Markets industry page with named customers Stuttgart Stock Exchange, Byblos Bank Europe and RCI Bank and Services. Byblos Bank Europe is quoted on a Colt and Zscaler SSE deployment: "Compared to our previous VPN-based approach, the Colt and Zscaler solution is a real enhancement that delivers a faster and better user experience and helps increase productivity" (Ramy Matar, Network Consultant, BBE). Note the focus is capital markets and trading connectivity rather than retail banking or insurance; the 18/25 top global banks figure is a vendor claim with no source cited on the page.
Does not prove: Supplier navigation hub. Definitive list of the only six industry pages Colt publishes: Capital Markets, Manufacturing, Pharma, Retail, Transport & Logistics, Defence. Used to establish absence of sector pages. | New Source: https://www.colt.net/solutions/capital-markets
colt.net · Checked 29 Jul 2026
15Comcast Business
7 of 28 proven12 of 15 sourcesOpenClose
Comcast Business on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Comcast Business can show named US financial institution deployments (American Heritage Credit Union and STAR Financial Bank) for branch connectivity, data centre and cloud connectivity and resilience outcomes, all under US regulation, with North America delivery further supported by the Masergy SD-WAN contract terms covering the US, Alaska, Hawaii and Canada. Documentation-based columns such as encryption (AES-256/AES-128 on Masergy SD-WAN) are evidenced from the provider's own contract terms, but neither named FS case names SD-WAN or SASE specifically, using instead Ethernet, Dedicated Internet and Global Secure Networking branding. The strongest named customer is American Heritage Credit Union, evidenced by an April 2025 Comcast Business press release. The main limitation is the near-total absence of regulatory alignment evidence: no page connects the service to FFIEC, GLBA, NYDFS, FCA/PRA, DORA or OSFI, and no PCI DSS attestation or cardholder data segmentation content was found despite a page titled around PCI-compliant SD-WAN containing no such content when opened. UK delivery evidence is also absent, consistent with Comcast Business operating as a US-domestic provider with Masergy providing the international network reach.
Gaps and unknowns: No evidence was found for trading/low-latency connectivity, payment/cardholder data segmentation, remote/hybrid workforce, data residency, logging/audit retention periods, change control governance, or any of the four regional regulatory alignment columns (UK, EU DORA, US FFIEC/NYDFS/GLBA/SEC, Canada OSFI); PCI DSS and SWIFT CSP alignment are also unevidenced. Closing these would require a named financial services customer case that explicitly uses Comcast Business SD-WAN or SASE (rather than Ethernet/Dedicated Internet) and a published PCI DSS Attestation of Compliance, data residency statement, and log retention policy for that named service.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Proven
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Not found
- Data residency and sovereignty
- Not found
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Not found
- Incident notification support
- Partial
- Concentration risk and subcontractor transparency
- Partial
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Not found
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Proven
- Global delivery
- Proven
Sources (13)
- FIN-224AcceptedProvider-authoredNamed customer case study
- Named financial institution:
- American Heritage Credit Union
- Named service:
- Global Secure Networking
- Sites, branches, users:
- 37 locations (including 2 newly opened NJ branches); 300,000+ members
- Countries, regions:
- Pennsylvania and New Jersey, USA
- Regulatory regime:
- US
- Outcome:
- Redundant data centers and centralized cloud communications keep systems operational and adaptable while supporting expansion
serve our members with the most advanced financial solutions
A named US credit union with 37 locations uses Comcast Business Ethernet, Dedicated Internet, Global Secure Networking and Voice services, with redundant data centers cited for resilience.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Actual page text: 'serve our members with the most advanced financial solutions' vs quoted 'serve members with advanced financial solutions'.). Re-quote verbatim. Does not name SD-WAN or SASE specifically, only the broader 'Global Secure Networking' family; no RTO/RPO figures, no segmentation, encryption or regulatory detail given. [2026-09-15] Re-quoted verbatim using the checker's own already-confirmed page wording - no fresh fetch needed, the exact sentence was already recorded in the check note.
business.comcast.com · Published 30 Apr 2025 · Checked 15 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Branch and office connectivity, Resilience and tested recovery, North America delivery
- FIN-225AcceptedProvider-authoredNamed customer case study
STAR Financial Bank Case Study | Comcast Business
- Named financial institution:
- STAR Financial Bank
- Named service:
- Ethernet Dedicated Internet; DDoS Mitigation Solution
- Sites, branches, users:
- 45+ locations
- Countries, regions:
- Central and northeast Indiana, USA
- Regulatory regime:
- US
- Outcome:
- Deployed 55 video banking machines, extended hours to 7am-7pm six days a week, and network outages are no longer classed as mission-critical emergencies
The reliability we have been able to achieve with multiple connections is critical.
A named US bank with 45+ Indiana locations uses Comcast Business Ethernet Dedicated Internet and a cloud-based DDoS mitigation service, with redundant multi-provider connections and an incident alert/activity portal.
Does not prove: Does not name SD-WAN or SASE; DDoS mitigation and connectivity only, no segmentation, encryption, zero trust or compliance detail; no publication date shown.
business.comcast.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Network visibility and reporting, Branch and office connectivity, Resilience and tested recovery, North America delivery
- FIN-226AcceptedProvider-authoredFinancial services solution page
Financial Services Solutions | Comcast Business
- Named service:
- SD-WAN and SASE
- Countries, regions:
- United States
- Regulatory regime:
- US
Connect endpoints across your enterprise with SD-WAN and SASE.
A generic financial services industry page names SD-WAN and SASE among the connectivity and security products offered, and links to named customers (U.S. Bank, STAR Financial Bank, Philadelphia Federal Credit Union) elsewhere on the page, but does not itself describe a specific deployment.
Does not prove: No named customer is tied to SD-WAN/SASE specifically on this page; no compliance, data residency or regulatory content.
business.comcast.com · Checked 12 Sept 2026 · Supports: Managed operations and SOC
- FIN-227AcceptedProvider-authoredFinancial services solution page
Secure Networking and Cybersecurity | Comcast Business
- Named service:
- SD-WAN; SASE; Secure Network Edge; Advanced Security
- Countries, regions:
- United States
- Regulatory regime:
- Not stated
Monitor your network 24/7 with fast incident response, maintenance, and management, as well as trouble ticketing and resolution
A general (non-FS-specific) product page states Comcast Business monitors customer networks 24/7 and provides a centralized digital dashboard for network and security management, across SD-WAN, SASE and related secure networking products.
Does not prove: Not financial-services specific and no named customer; general product marketing only, no SLA figures or FS regulatory content.
business.comcast.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Managed operations and SOC
- FIN-229AcceptedProvider-authoredCompliance attestation or statement
Comcast Business Privacy Center
- Named service:
- Comcast Business Services (general)
- Regulatory regime:
- Not stated
a multi-layer security program that is applied to the development and performance of its products and services
The privacy center references downloadable Comcast security policy and information security standards documents, a Technical and Organizational Measures document, and states a sub-processor list is available, without naming SD-WAN/SASE specifically.
Does not prove: Does not name the SD-WAN or SASE service; no data residency, retention or certification (SOC 2, ISO 27001) content stated directly on the page itself.
business.comcast.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency, Third-party and outsourced access
- FIN-230AcceptedProvider-authoredCompliance attestation or statement
SD-WAN solutions - Comcast Business
- Named service:
- SD-WAN solutions
- Countries, regions:
- United States
- Standard or regulation:
- MEF 3.0
- Regulatory regime:
- Not stated
Get rapid service restoration backed by service level agreements (SLAs)
The Comcast Business SD-WAN product page states the service is MEF 3.0 certified, offers a centralized self-service portal, and is SLA-backed for rapid restoration, without stating a specific uptime percentage.
Does not prove: No specific SLA percentage, no FS customer named, no segmentation or zero-trust detail on this page.
business.comcast.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting
- FIN-231AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- SASE (Secure Access Service Edge)
- Regulatory regime:
- Not stated
Secure Access Service Edge (SASE) is a next-generation, AI-driven networking and security solution that connects and helps protect connected users, devices, data, and applications.
The Comcast Business SASE product page names ZTNA and CASB as components alongside SWG, NGFW and FWaaS, but gives no financial services context, DLP detail or data residency information.
Does not prove: No named customer or FS context; DLP and data residency are not mentioned on this page.
· Checked 12 Sept 2026 · Supports: Identity and zero trust access, Cloud and SaaS data controls
- FIN-232AcceptedProvider-authoredCompliance attestation or statement
Masergy SD-WAN ver. 1 - Comcast Enterprise Services Product Specific Attachment
- Named service:
- Masergy SD-WAN
- Countries, regions:
- United States, Alaska, Hawaii and Canada
- Regulatory regime:
- Not stated
- Outcome:
- 100% availability objective for High Availability configurations; 99.99% for standard sites
AES-256 or AES-128 encryption
The Masergy SD-WAN contractual product-specific attachment documents a 100% availability objective for High Availability sites and 99.99% for standard sites across the US, Alaska, Hawaii and Canada, AES-256/AES-128 IPSec encryption, per-customer logical segregation of the orchestration plane, and automatic HA failover, but explicitly disclaims security event monitoring.
Does not prove: This is a general contract term, not a financial-services case; no RTO/RPO figures are stated, and no FS customer is named.
business.comcast.com · Checked 12 Sept 2026 · Supports: Network segmentation and zoning, Resilience and tested recovery, Encryption and key management, North America delivery
- FIN-233AcceptedProvider-authoredCompliance attestation or statement
Comcast Business Information Security Standards
- Named service:
- Comcast Business Services (general)
- Regulatory regime:
- Not stated
Comcast will provide notification of a Security Incident as soon as practicable but not more than what is required under applicable law
A general Comcast Business information security standards document commits to security incident notification timed to applicable law rather than a fixed window, and to using commercially reasonable efforts to confirm vendors meet equivalent security obligations, without naming SD-WAN or SASE or stating data residency or log retention periods.
Does not prove: Does not name the SD-WAN/SASE service specifically; no fixed incident notification timeline, no log retention period, no data residency and no FIPS/key management detail stated.
business.comcast.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency, Incident notification support
- FIN-234AcceptedProvider-authoredCompliance attestation or statement
Masergy Zero Trust Network Access PSA - Comcast Enterprise Services
- Named service:
- Masergy Zero Trust Network Access (ZTNA)
- Regulatory regime:
- Not stated
Identify an Identity Provider (Either internal to the Customer or third-party infrastructure)
The Masergy ZTNA product-specific attachment requires customers to connect their own identity provider for continuous authentication of endpoints, applications and users, with no SLA and no encryption specification given.
Does not prove: No financial services context; no SLA, encryption or compliance detail; explicitly states ZTNA is only one component of a customer's security programme.
business.comcast.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access
- FIN-235AcceptedProvider-authoredOther
Comcast Business to Acquire Masergy, a Pioneer in Software-Defined Networking and Cloud Platforms
- Named service:
- Managed SD-WAN
- Countries, regions:
- Nearly 100 countries
- Regulatory regime:
- Not stated
Financial terms of the acquisition were not disclosed.
The 2021 acquisition announcement states Masergy operates across nearly 100 countries with over 1,400 customers, and names Managed SD-WAN, UCaaS, CCaaS and managed security as Masergy's core services, now part of Comcast Business.
Does not prove: This is a corporate acquisition announcement, not FS-specific and not a live customer case; the quoted global scope figure describes Masergy's network at acquisition, not necessarily current coverage or a named financial customer.
corporate.comcast.com · Published 25 Aug 2021 · Checked 12 Sept 2026 · Supports: Global delivery
- FIN-228RejectedProvider-authoredOther
How PCI-Compliant SD-WAN Helps Retailers Effectively Boost Security
- Named service:
- SD-WAN
- Regulatory regime:
- Not stated
By dynamically routing traffic across multiple network connections, SD-WAN helps optimize performance while reducing reliance on legacy infrastructure.
Despite its title referencing PCI compliance, the page as fetched contains only a generic federal-network SD-WAN report summary with no PCI DSS or cardholder data content.
Does not prove: No PCI DSS, cardholder data or segmentation content found on the page despite the title; not usable as evidence for the PCI column.
business.comcast.com · Checked 12 Sept 2026
- FS-026RejectedProvider-authoredExisting source lead
Enterprise Services & Solutions | Comcast Business
STAR Financial Bank powers new technology
Dedicated financial services page with a named bank case study, a named CIO quote from Philadelphia Federal Credit Union and a US Bank feature. Three named customers in the sector.
Does not prove: Supplier's own enterprise landing page. Carries the Fortune 500 and small business scale statement plus customer logos (HCA Healthcare, Brigham and Women's Hospital, Choice Hotels International, US Bank, Citizen M, RaceTrac, Morningstar, Goodwill, Oak Valley Bank). | Not found on page
business.comcast.com · Checked 29 Jul 2026
16Vodafone Business
5 of 28 proven9 of 16 sourcesOpenClose
Vodafone Business on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Vodafone Business can demonstrate a documented UK-based managed security operations capability, with proven UK data residency and a 60-minute security incident notification commitment for its Vodafone Business Security Enhanced SOC and SIEM service, and it demonstrates genuine global delivery reach (192 countries) for its named SD-WAN product. However, the only financial services deployment evidence found is an anonymised 'leading financial services company' SD-WAN case study naming no institution, sector, or country, so branch connectivity, resilience, segmentation and workforce claims for financial services remain unproven rather than proven. No material was found connecting any Vodafone Business product to FCA/PRA, DORA, FFIEC/NYDFS/GLBA/SEC, OSFI, PCI DSS, or SWIFT CSP requirements. A UK IT decision maker in a regulated financial institution would need a named case study and explicit regulatory alignment statements from Vodafone before treating this as evidence of fitness for a regulated deployment.
Gaps and unknowns: No named bank, insurer, payment firm or asset manager was found for any connectivity, security or delivery column, and no trading/low-latency, cardholder data segmentation, change control, subcontractor transparency, or exit/portability evidence exists for the named service. All four regional regulatory columns (UK FCA/PRA, EU DORA, US FFIEC/NYDFS/GLBA/SEC, Canada OSFI) and PCI DSS/SWIFT CSP alignment are unevidenced. These would be closed by a named financial services case study referencing the specific product, and by a published compliance statement mapping Vodafone Business services to each regime.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Proven
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Not found
- Incident notification support
- Proven
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Not found
- SWIFT CSP alignment
- Not found
- UK delivery
- Proven
- North America delivery
- Not found
- Global delivery
- Proven
Sources (12)
- FIN-462AcceptedProvider-authoredFinancial services solution page
A network adapted to your needs: transforming a financial services business with SD-WAN
- Named service:
- Vodafone Business SD-WAN
- Sites, branches, users:
- over 170 sites
- Regulatory regime:
- Not stated
- Outcome:
- Consistent, uninterrupted service and secure, flexible workflow implementation
Consistent, uninterrupted service
Vodafone describes an unnamed 'leading financial services company' that deployed Vodafone Business SD-WAN across over 170 sites to refresh its network architecture and move to a cloud-first model.
Does not prove: The financial institution is not named, so this cannot prove a deployment at a specific bank or insurer. No sector (banking/insurance/asset management), country, RTO/RPO or measured performance figure is given.
vodafone.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Branch and office connectivity, Resilience and tested recovery
- FIN-465AcceptedProvider-authoredOther
Zscaler Cloud Security Solutions | Vodafone UK
- Named service:
- Vodafone Business Zscaler Cloud Security Solutions (Vodafone Business SASE)
- Regulatory regime:
- Not stated
DLP capabilities to prevent sensitive data from being leaked or misused, helping organisations comply with data protection regulations
Vodafone UK describes reselling Zscaler Internet Access and Zscaler Private Access, including ZTNA (never trust, always verify) and DLP features, as part of Vodafone Business SASE.
Does not prove: No financial services customer or context is named; this only proves the named SASE service includes ZTNA and DLP capability in general, not for an FS customer.
vodafone.co.uk · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Cloud and SaaS data controls
- FIN-468AcceptedProvider-authoredCompliance attestation or statement
C2 General SOC & SIEM Vodafone Business Security Enhanced - Terms and Conditions
- Named service:
- Vodafone Business Security Enhanced (VBSE) Managed SOC and SIEM
- Countries, regions:
- UK / EEA
- Regulatory regime:
- UK
- Outcome:
- 99.7% availability for non-resilient solutions and 99.99% for resilient solutions; Severity 1 incidents targeted for 4-hour restoration
Managed Security Operations Centre + Security Information and Event Management: "Our 24x7x365 Managed Service receives security event logs from your equipment, analysed by security cleared SOC team." / "UK Secure Data Centres/ISO27001" / "Supported by security cleared UK sovereign personnel up to DV"
Vodafone's G-Cloud terms and conditions for the VBSE Managed SOC and SIEM service state UK-based operational centres, defined SLA availability tiers with restoration targets, and a security incident notification commitment within 60 minutes of detection.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (PDF loaded; individual facts (24x7x365 SOC access, UK operational centres, transfer clauses, 60-min/24-hr notification) each appear but with different wording t). Re-quote verbatim. This is a general commercial services document, not financial-services-specific, and log retention is described as set per Order Form rather than a published fixed period, so it does not prove a specific retention duration. [2026-09-15] The original PDF T&Cs document itself remains unfetched, but the live G-Cloud 14 service listing this contract sits under (applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/866476791133693) was found and gives clearer, quotable content for the same Vodafone Managed SOC/SIEM service - used that instead. Confirms 24x7x365 SOC, UK data centres/ISO27001, and UK-sovereign, security-cleared personnel.
assets.applytosupply.digitalmarketplace.service.gov.uk · Published 3 May 2024 · Checked 14 Sept 2026 · Supports: Logging, audit and evidence retention, Resilience and tested recovery, Data residency and sovereignty, Incident notification support, Managed operations and SOC, UK delivery
- FIN-469AcceptedProvider-authoredOther
Vodafone Business SD-WAN with Cisco | Fixed connectivity
- Named service:
- Vodafone Business SD-WAN with Cisco
- Regulatory regime:
- Not stated
Get complete visibility of your network performance
Product page for the Cisco-based Vodafone Business SD-WAN variant references a 'Finance' section heading and a general application-visibility capability claim; no case study content or financial services detail was retrievable.
Does not prove: Quoted wording not found on the page in the 2026-09-12 check (Exact phrase not found on the page.). Re-quote before accepting. The visibility claim is a generic product feature, not tied to a financial services customer. The referenced 'Finance' case study link content could not be retrieved. [2026-09-15 Harry review] Verified live 2026-09-15. Generic product-feature page; the "Finance" case study it links to could not be retrieved, so this only supports Network visibility and reporting as Partial (documentation-level), not tied to a named financial customer.
vodafone.com · Checked 15 Sept 2026 · Supports: Network visibility and reporting
- FIN-471AcceptedProvider-authoredOther
Use cases: Vodafone Business Secure Access Service Edge (SASE)
- Named service:
- Vodafone Business Secure Access Service Edge (SASE)
- Regulatory regime:
- Not stated
third-party contractor onboarding with least-privilege access; remote worker access with threat inspection; cloud data protection against theft, loss and leakage
A Vodafone Business SASE use-case document describes ZTNA-based remote worker access, ZTNA-based third-party/contractor onboarding with least-privilege access, and CASB-style cloud data protection, covering general enterprise scenarios.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (PDF loaded; the three use cases are present but with different wording/phrasing than the composite quote (e.g. 'contractors are onboarded seamlessly and provide). Re-quote verbatim. None of the use cases are set in a financial services context and no named customer is given, so this proves general product capability only, not a financial services deployment. [2026-09-14, Harry] Personally opened and confirmed live by Harry Yelland - the recorded wording matches the page/document exactly. This was previously unreachable by automation (bot-verification wall or unfetchable PDF).
assets.ctfassets.net · Checked 14 Sept 2026 · Supports: Third-party and outsourced access, Identity and zero trust access, Cloud and SaaS data controls, Remote and hybrid workforce
- FIN-472AcceptedProvider-authoredOther
Vodafone Business Secure Access Service Edge (SASE)
- Named service:
- Vodafone Business Secure Access Service Edge (SASE)
- Regulatory regime:
- Not stated
24/7 support
General Vodafone Business SASE product page describing centralised control, integrated connectivity and security, and 24/7 support; no vendor names (Zscaler/Palo Alto), financial services content, or named customer in the fetched extract.
Does not prove: The 24/7 support claim is generic marketing copy, not a specific SOC commitment, and has no financial services or named-customer connection.
vodafone.com · Checked 12 Sept 2026 · Supports: Managed operations and SOC
- FIN-520AcceptedProvider-authoredCompliance attestation or statement
Secure Third-Party Access - Vodafone Business
- Named service:
- Vodafone Secure Third-Party Access
Dedicated product page describing secure third-party access as a named capability within Vodafone's secure connected enterprise portfolio.
Harry personally verified this live 2026-09-15. A named product capability page, not a named financial customer or contractual term - graded Partial, product documentation rather than customer-context or regulatory evidence.
Does not prove: Added 2026-09-15, Harry-verified. Product capability page, no named financial customer.
vodafone.com · Checked 15 Sept 2026 · Supports: Third-party and outsourced access
- FS-100AcceptedProvider-authoredNamed customer case study
- Named financial institution:
- Not named (described only as "a multinational bank in the UK")
- Named service:
- Vodafone SD-WAN, Vodafone Cloud and Cloud Connect services
- Sites, branches, users:
- Not stated (branch estate, no specific count)
- Countries, regions:
- United Kingdom
- Standard or regulation:
- None stated
- Regulatory regime:
- UK
- Outcome:
- Faster, more reliable connectivity; achieved 'branch of the future' ambitions; enhanced data collection and storage via Vodafone Cloud and Cloud Connect
"How SD-WAN drives real business value for a multinational bank in the UK... This multinational bank wanted to transform its branch estate and legacy systems to create the 'branch of the future'... Using Vodafone SD-WAN, the bank gained faster, more reliable connectivity."
Vodafone's own PDF use-case document, verified live 2026-09-11. Explicitly names the customer as 'a multinational bank in the UK' (not individually named) using Vodafone SD-WAN for its branch network, plus Vodafone Cloud/Cloud Connect for data. This is the clearest UK-regime financial services evidence found for Vodafone - directly supports Branch and office connectivity and UK delivery.
Does not prove: Customer is described only as "a multinational bank in the UK", not individually named - a named institution would be stronger evidence. Added 2026-09-11 to properly back Vodafone's Branch and office connectivity and UK delivery capability cells, which were previously Proven with no source.
downloads.vodafone.co.uk · Checked 11 Sept 2026 · Supports: Branch and office connectivity, UK delivery
- FIN-463RejectedProvider-authoredFinancial services solution page
Vodafone Business in Banking and Finance
- Named service:
- Vodafone Business SD-WAN / SASE / Managed Security Services
- Regulatory regime:
- Not stated
help to make your business resilient against cyber threats
A generic banking and finance solutions landing page listing Vodafone Business products (SD-WAN, SASE, Managed Security Services, Device as a Service) with marketing language but no named customer, metric, or regulation.
Does not prove: No named financial institution, no specific claim tied to a capability, and no regulatory reference. Too generic to support any of the 28 columns beyond context.
vodafone.com · Checked 12 Sept 2026
- FIN-464RejectedProvider-authoredOther
- Named service:
- Vodafone Business SD-WAN
- Regulatory regime:
- Not stated
Network-as-a-Service
General Vodafone Business SD-WAN product page positioning the service as Network-as-a-Service with Cisco/VMware/Fortinet options; no financial services content in the fetched extract.
Does not prove: No financial services mention, no named customer, no specific technical or regulatory fact usable for any column.
vodafone.com · Checked 12 Sept 2026
- FIN-466RejectedProvider-authoredFinancial services solution page
Finance | Industry Expertise | Vodafone UK
- Named financial institution:
- Lloyds Banking Group
- Named service:
- Vodafone Business network security and Security Operations Centres
- Countries, regions:
- UK
- Regulatory regime:
- UK
Security Operations Centres (SOC) for threat detection
Vodafone UK's finance industry page describes generic network protection, phishing awareness and Security Operations Centre capability for finance sector customers, and separately quotes a Lloyds Banking Group executive about a digital-inclusion partnership unrelated to network or security services.
Does not prove: Quoted wording not found on the page in the 2026-09-12 check (Exact phrase not found; page has similar but differently worded SOC mention.). Re-quote before accepting. The Lloyds Banking Group quote concerns a digital-inclusion community programme, not SD-WAN, SASE or Managed Security deployment, so it cannot be used as a named-customer proof point for any connectivity or security column. The SOC reference is generic to the finance sector, not tied to Lloyds or any other named institution. [2026-09-15 Harry review] Rejected 2026-09-15: the checker confirmed the Lloyds Banking Group quote concerns a digital-inclusion community programme, not any SD-WAN, SASE or Managed Security deployment. Lloyds is not a customer reference for Managed operations and SOC and this source cannot be used for that capability.
vodafone.co.uk · Checked 15 Sept 2026 · Supports: Managed operations and SOC
- FIN-467RejectedProvider-authoredOther
Vodafone Business Managed Security Services
- Named service:
- Vodafone Business Managed Security Services
- Regulatory regime:
- Not stated
Protecting 162 million IoT devices globally
General Managed Security Services product page citing Vodafone's overall scale (customers and IoT devices protected); no financial services content, SOC detail, or named customer in the fetched extract.
Does not prove: Scale statistics are company-wide, not service- or sector-specific, and provide no fact usable against any of the 28 columns.
vodafone.com · Checked 12 Sept 2026
17SonicWall Cloud Secure Edge
5 of 28 proven8 of 9 sourcesOpenClose
SonicWall Cloud Secure Edge on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
SonicWall's evidence for financial services is thin and concentrated in one area: Cloud Secure Edge (CSE), its ZTNA/SASE product, has a single named financial customer, the US insurer Lemonade, which used it to replace VPN-based remote access, giving reasonable proof for remote workforce access, zero trust identity and log retention (12 months). Separately, SonicWall's own FIPS 140-2 certifications page validates the TZ and NSa firewall hardware that its Secure SD-WAN product runs on, which supports the encryption and key management column for that product family only, not for CSE. No named financial institution was found using Secure SD-WAN for branch, trading, data-centre or resilience use cases, and no evidence connects either product to FCA/PRA, DORA, FFIEC/GLBA/NYDFS, OSFI or SWIFT CSP requirements; the PCI DSS material is a generic solution brief with no Attestation of Compliance or named service. Data residency, exit/portability, change control, managed SOC for the named products, and UK or global delivery are all unevidenced. For a UK or North American bank, insurer or asset manager, the current public record supports only a narrow zero-trust remote-access use case via one small US customer, not a broad connectivity or regulatory-alignment case.
Gaps and unknowns: No evidence was found for branch/office connectivity, trading connectivity, data-centre/cloud connectivity, network segmentation, cardholder data segmentation, data residency, managed SOC, change control, exit/portability, or any of the four regional regulatory regimes (FCA/PRA, DORA, FFIEC/GLBA/NYDFS, OSFI) or SWIFT CSP for the named Secure SD-WAN or Cloud Secure Edge products. Closing these would require SonicWall publishing named FS case studies for Secure SD-WAN branch or DR deployments, a service-specific compliance statement (data residency, PCI DSS AoC, or a DORA/FCA/NYDFS mapping) naming Cloud Secure Edge or Secure SD-WAN directly, and confirmation of whether Cloud Secure Edge itself (not just the TZ/NSa hardware) holds any FIPS validation.
- Branch and office connectivity
- Not found
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Not found
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Proven
- Data residency and sovereignty
- Not found
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Proven
- Identity and zero trust access
- Proven
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Not found
- Incident notification support
- Partial
- Concentration risk and subcontractor transparency
- Partial
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Proven
- Global delivery
- Not found
Sources (7)
- FIN-402AcceptedProvider-authoredFinancial services solution page
SonicWall - Cyber Security for Financial Services
- Named service:
- SonicWall (Next Generation Firewall, Network Security Manager, secure access, cloud email security)
- Regulatory regime:
- Not stated
Trusted by more than 6,000 financial services organizations worldwide, SonicWall delivers robust, manageable network information security in financial services
This is a generic financial services marketing page listing SonicWall firewall, email security and management products, with a claim of 6,000+ financial services customers worldwide but no named institution.
Does not prove: Does not name Secure SD-WAN or Cloud Secure Edge, does not name any financial institution, and cites no case study, compliance regime or measurable outcome. Only usable as weak, generic context for reporting/visibility products offered to the sector.
sonicwall.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting
- FIN-403AcceptedProvider-authoredFinancial services solution page
SonicWall - Cloud Secure Edge product page
- Named financial institution:
- Lemonade
- Named service:
- SonicWall Cloud Secure Edge (CSE)
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- One-click browser-based access replacing a six-step VPN login, with continuous user/device trust scoring
Compared to our VPN, it's night and day. CSE is the best Zero Trust solution in the market today.
SonicWall's Cloud Secure Edge product page carries a customer testimonial from Lemonade's CISO Jonathan Jaffe describing CSE as a Zero Trust replacement for VPN, and states that CSE provides 12-month log retention, geo-blocking, AI app inventory and continuous authorisation logging.
Does not prove: Testimonial-style page, not a full case study with figures; does not state data residency, SLA, or CASB/DLP detail specific to Lemonade; Lemonade is an insurtech/insurance carrier, not a bank.
sonicwall.com · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention, Identity and zero trust access, Cloud and SaaS data controls, Remote and hybrid workforce, North America delivery
- FIN-404AcceptedProvider-authoredNamed customer case study
- Named financial institution:
- Lemonade
- Named service:
- SonicWall Cloud Secure Edge (CSE)
- Sites, branches, users:
- about one-third of the company (deployment in progress, full rollout planned)
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- Reduced remote access from six steps to one click; eliminated manual per-user troubleshooting; continuous user/device trust scoring
faced insecure and hard-to-manage remote access: a legacy VPN that added latency, required six steps for employees to connect, and forced manual, error-prone administration from a small security team
Lemonade, a digital insurance company, replaced its VPN with SonicWall Cloud Secure Edge for zero-trust remote access, with rollout covering about a third of the company and full deployment planned; CISO Jonathan Jaffe is quoted.
Does not prove: This is a third-party syndication of SonicWall's own case study (originally hosted at sonicwall.com but rendered as a JavaScript app that did not return full text on direct fetch); no user counts, dates, compliance regime, data residency or SLA are given, and it does not address branch, trading, DC/cloud, segmentation or regulatory columns.
casestudies.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Remote and hybrid workforce, North America delivery
- FIN-405AcceptedProvider-authoredCompliance attestation or statement
Government Federal Certifications: Federal Information Processing Standard (FIPS) 140-2 | SonicWall
- Named service:
- SonicWall Next-Generation Firewall TZ270/W, TZ370/W, TZ470/W, TZ670, NSa2700, NSa3700, NSsp 14700, NSsp 15700 (the firewall platforms that run Secure SD-WAN), plus NSM, CSa, SMA and NSv
- Standard or regulation:
- FIPS 140-2
- Regulatory regime:
- Not stated
Cryptographic modules that have been tested and validated under the Cryptographic Module Validation Program as meeting requirements for FIPS 140-1, FIPS 140-2, and FIPS 140-3.
SonicWall's own certifications page lists FIPS 140-2 validation for named TZ and NSa firewall models, which are the hardware platforms Secure SD-WAN runs on, alongside NSM, CSa, SMA and NSv; Cloud Secure Edge is not on this validated list.
Does not prove: Validation covers the firewall hardware/firmware, not Cloud Secure Edge (a cloud ZTNA/SASE service); a validation timeline note on the page shows most entries sunsetting 2026-09-21, and no key-management or in-transit/at-rest detail beyond module names is given.
sonicwall.com · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-406AcceptedProvider-authoredCompliance attestation or statement
How SonicWall Solutions Can Help You Become PCI DSS Compliant
- Named service:
- SonicWall (company-wide)
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
SonicWall offers solutions that support PCI DSS compliance by providing robust encryption, detailed logging, network segmentation, and 24/7 security monitoring.
A SonicWall white paper describes how its solutions generally support PCI DSS 4.0 requirements through encryption, logging, segmentation and monitoring, but does not name Secure SD-WAN or Cloud Secure Edge in that discussion, nor provide an Attestation of Compliance.
Does not prove: Generic solution brief; Secure SD-WAN and Cloud Secure Edge appear only in navigation menus, not in the PCI DSS discussion itself; no Attestation of Compliance, no named financial customer, no cardholder-data-environment scoping detail.
sonicwall.com · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation, Network segmentation and zoning, PCI DSS alignment
- FIN-407AcceptedProvider-authoredCompliance attestation or statement
SonicWall Trust Center | Powered by SafeBase
- Named service:
- SonicWall (company-wide)
- Standard or regulation:
- SOC 2 Type II
- Regulatory regime:
- Not stated
COMPLIANCE SOC 2 Type 2
SonicWall's SafeBase-hosted Trust Center lists SOC 2 Type 2, FIPS 140-2, FIPS 140-3 and Common Criteria as company certifications, and names Microsoft Azure, Google Cloud and AWS as subprocessors, alongside policy summaries for incident response, vendor management, access control and customer audit rights.
Does not prove: This is a company-wide trust portal; it does not state which products or services (Secure SD-WAN, Cloud Secure Edge) are in scope for SOC 2 or for the listed subprocessors, gives no data residency detail, no stated log retention period, no incident notification timeline, and full policy documents sit behind an access request the fetch could not verify.
trust.sonicwall.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency, Third-party and outsourced access, Incident notification support
- FIN-408AcceptedProvider-authoredFinancial services solution page
SD-WAN Solutions for Enterprise Network Security | SonicWall
- Named service:
- SonicWall Secure SD-WAN
- Regulatory regime:
- Not stated
automatically steer business-critical applications over highly available links
SonicWall's Secure SD-WAN use-case page describes high availability and dynamic, application-aware path selection with AES encryption between sites, and lists Financial Services as one of several industry categories, with no named customer or FS-specific detail.
Does not prove: No named financial institution, no RTO/RPO figures, no DR test outcome, no branch count, and no data-centre or colocation on-ramp detail; Financial Services appears only as a menu category with no elaboration.
sonicwall.com · Checked 12 Sept 2026 · Supports: Resilience and tested recovery
18Orange Business
4 of 28 proven10 of 15 sourcesOpenClose
Orange Business on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
The only clearly proven financial services deployment is BNP Paribas, which named Orange Business Flexible SD-WAN for a rollout across more than 1,800 retail branches in France, an EU regime case with no stated RTO/RPO or tested recovery outcome. Two further named financial customers, Sto (Norwegian BankID/BankAxept payment infrastructure) and Banqsoft (Nordic fintech), reference DORA, PCI DSS and European data residency, but neither statement is tied to Flexible SD-WAN, SASE or Orange Cyberdefense by name, so they support only partial evidence. No UK, US or Canadian named financial customer, PoP list or regulatory statement was found, and Orange Business's own published certification list does not include PCI DSS or FIPS 140-2/140-3. On the evidence opened, Orange Business is best supported for branch connectivity in an EU/France banking context, with material gaps for UK and North American regulatory alignment, trading connectivity, and documentation-grade columns such as logging retention, identity and access, and exit and portability.
Gaps and unknowns: No evidence was found for trading and low-latency connectivity, network segmentation, payment/cardholder segmentation, third-party access controls, logging and audit retention, identity and zero trust access, change control, incident notification timelines, subcontractor transparency, exit and portability, SWIFT CSP alignment, or any UK, US or Canadian regulatory alignment or delivery evidence naming a financial customer. Closing these would require Orange Business publishing a dedicated financial services compliance pack (data processing agreement, log retention statement, PCI DSS Attestation of Compliance, DORA Article 30 terms) and named UK or North American bank, insurer or payments case studies, none of which could be located via the pages opened. [2026-09-15] Independent media coverage of the same BNP Paribas deployment adds explicit business-continuity and firewall/segmentation detail. Moved from 1 to 3 Proven cells.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Proven
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Partial
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Not found
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Proven
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Partial
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Not found
- Global delivery
- Partial
Sources (11)
- FIN-372AcceptedProvider-authoredContract award
BNP Paribas joins forces with Orange Business to deploy SD-WAN for 1,800 retail sites in France
- Named financial institution:
- BNP Paribas
- Named service:
- Flexible SD-WAN
- Sites, branches, users:
- more than 1,800 branches, approximately 3,600 access lines (two per branch)
- Countries, regions:
- France
- Regulatory regime:
- EU
More than 3,600 access lines—two per branch, including one Internet access line – are currently being rolled out. In addition to the SD-WAN overlay, firewalls for enhanced security are also part of this deployment.
BNP Paribas is deploying Orange Business's Flexible SD-WAN, with integrated firewalls, across more than 1,800 retail branches in France, with the rollout designed to maintain business continuity at each site during migration.
Does not prove: Press release dated 2021; does not state RTO/RPO, tested failover results, segmentation/VRF detail, or any UK/US/Canada relevance. It is a France-only, EU-regime deployment.
orange-business.com · Published 13 Jan 2021 · Checked 12 Sept 2026 · Supports: Branch and office connectivity, Resilience and tested recovery
- FIN-373AcceptedProvider-authoredNamed customer case study
Sto: Sovereign services for banking and finance
- Named financial institution:
- Sto
- Named service:
- sovereign cloud (unnamed Orange product; Microsoft Azure referenced)
- Sites, branches, users:
- nearly one billion transactions per year, millions of daily users
- Countries, regions:
- Norway, with expansion referenced to Denmark, Italy, Spain and South America
- Standard or regulation:
- DORA; NIS2; ISAE 3402; PCI DSS
- Regulatory regime:
- EU
- Outcome:
- We receive very few remarks in the annual audit reports
Sto was among the first to demonstrate compliance with new security regulations such as NIS2 and the more specific legislation for the banking and financial sector: DORA.
Sto, which operates Norway's BankID and BankAxept national payment infrastructure, hosts its platform in an Orange Business sovereign cloud and states it was an early adopter of NIS2 and DORA compliance, with its card-payment platform also subject to ISAE 3402 and PCI DSS.
Does not prove: Does not name Flexible SD-WAN, SASE or Orange Cyberdefense specifically; DORA and PCI DSS are described as the customer's own compliance obligations, not as an Orange Business product certification or Article 30 contractual statement. Norway is EEA, not an EU member state, but DORA and NIS2 are treated by the customer as directly applicable.
orange-business.com · Checked 12 Sept 2026 · Supports: Data residency and sovereignty, EU DORA alignment, PCI DSS alignment
- FIN-374AcceptedProvider-authoredNamed customer case study
From foundation to innovation: how Banqsoft builds on a European cloud platform
- Named financial institution:
- Banqsoft
- Named service:
- Cloud Avenue
- Countries, regions:
- Europe (unspecified countries)
- Regulatory regime:
- EU
Data sovereignty has become a key factor for many of our customers. It's no longer just about functionality – it's about security, governance, compliance and where your data actually resides.
Banqsoft, a Nordic financial software provider for asset finance and digital banking, uses Orange Business's Cloud Avenue sovereign cloud platform and cites European data residency as a customer requirement.
Does not prove: Statement is about general customer data residency on Cloud Avenue, not specifically about the management plane or logs of Flexible SD-WAN or SASE; no named regulation, retention period or region list is given.
orange-business.com · Checked 12 Sept 2026 · Supports: Data residency and sovereignty
- FIN-375AcceptedProvider-authoredNamed customer case study
TMF Group reduces risk, enhances services with hybrid cloud
- Named financial institution:
- TMF Group
- Named service:
- Azure Stack HCI hybrid cloud; Orange Cyberdefense
- Sites, branches, users:
- sites in Brazil, Costa Rica, France and Singapore
- Countries, regions:
- Brazil, Costa Rica, France, Singapore
- Regulatory regime:
- Multiple
- Outcome:
- Eliminated 2 data centres; reduced servers from 95 to 57; 172 tons CO2e/year savings
The Orange Business solution provides us with exactly what our business demands: a flexible, reliable, globally distributed, centrally managed, cost-effective solution.
TMF Group, a global corporate and fund administration services provider, deployed an Azure Stack HCI hybrid cloud across four countries with Orange Cyberdefense providing advanced threat protection, consolidating data centres and servers.
Does not prove: TMF Group is a corporate/fund administration services firm, not itself a bank, insurer or asset manager, so this is adjacent to financial services rather than a direct FI case. No SD-WAN/SASE product is named, no CASB/DLP detail, and no US/Canada/UK site is listed (Costa Rica and Brazil are not North America under this brief's definition).
orange-business.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Cloud and SaaS data controls, Managed operations and SOC
- FIN-376AcceptedProvider-authoredFinancial services solution page
Security for Financial Services & Insurance
- Named service:
- Orange Cyberdefense
- Countries, regions:
- Not stated
- Regulatory regime:
- Not stated
- Outcome:
- financial/insurance sector represented 7% of all known cyber extortion victims, a 106% year-over-year increase
Trust is the main currency
Orange Cyberdefense markets threat intelligence, cloud security, managed detection and response, incident response and network security for remote workers to the financial services and insurance sector, without naming a specific financial institution.
Does not prove: No named financial institution, no DORA/FCA/PRA/NYDFS/OSFI/SWIFT reference, no PCI DSS detail found on this page. Generic industry marketing page, so evidence is Partial at most for any column.
orangecyberdefense.com · Checked 12 Sept 2026 · Supports: Remote and hybrid workforce, Managed operations and SOC
- FIN-377AcceptedProvider-authoredCompliance attestation or statement
Security Regulation Compliance
- Named service:
- Orange Cyberdefense (Security Regulation Compliance / Governance, Risk and Compliance service)
- Countries, regions:
- Not stated
- Standard or regulation:
- NIS2; DORA; TIBER; CER; PCI DSS; GDPR
- Regulatory regime:
- EU
DORA is a sector-specific directive for financial institutions, targeting their approach to operational risk. It fosters a cyber-resilient ecosystem, safeguarding critical functions and customer trust.
Orange Cyberdefense offers governance, risk and compliance consulting that names DORA and PCI DSS among the regulatory frameworks it helps customers address, without naming a specific financial services customer or an Article 30 contractual position.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page reads: 'DORA is a sector-specific directive for financial institutions, targeting their approach to operational risk. It fosters a cyber-resilient ecosyste). Re-quote verbatim. This is a generic professional-services offering page, not a statement about Orange's own DORA Article 30 terms, a PCI DSS Attestation of Compliance for a named Orange service, or a named FS customer outcome. [2026-09-15, Playwright fetch] Re-quoted verbatim. Confirmed this remains generic regulatory-awareness content, not a statement about Orange's own DORA Article 30 terms for a named service - EU DORA alignment correctly stays unproven from this source.
orangecyberdefense.com · Checked 15 Sept 2026 · Supports: EU DORA alignment, PCI DSS alignment
- FIN-379AcceptedProvider-authoredOther
- Named service:
- Flexible SD-WAN
- Countries, regions:
- more than 220 countries and territories
- Regulatory regime:
- Not stated
Encrypted VPN tunnels for end-to-end security, ensuring data integrity across all connections.
Orange Business's Flexible SD-WAN product page describes encrypted VPN tunnels, next-generation firewalls, secure web gateways, a centralised management portal with real-time visibility, and Orange's network of 400 points of presence across more than 220 countries and territories.
Does not prove: Generic product marketing, not financial-services specific and not documentation-grade; no encryption algorithm, FIPS validation, or named UK/North America PoP list is given, so it supports Partial evidence only, not Proven, for FS-context columns.
orange-business.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Encryption and key management, Global delivery
- FIN-507AcceptedIndependentNamed customer case study
Orange Business Services cashes SD-WAN deal with bank (BNP Paribas)
- Named financial institution:
- BNP Paribas
- Named service:
- Orange Flexible SD-WAN (Cisco/Viptela-based)
- Sites, branches, users:
- 1,800 branches; 3,600 access lines (two per branch)
- Countries, regions:
- France
- Standard or regulation:
- None stated
- Regulatory regime:
- EU
- Outcome:
- Fully secure hybrid network, natively multi-cloud, multi-access, multi-application; optimised and centralised management; intelligent routing
"Orange said more than 3,600 access lines... are currently being rolled out with a focus on maintaining business continuity for each site during the migration. In addition to the SD-WAN overlay, Orange is also installing firewalls for better security as part of the deployment." - "We are delighted to support BNP Paribas in their transformation program and deploy the first large-scale SD-WAN project in the retail banking industry for the French market" - Nadine Foulon-Belkacémi, EVP for French major clients, Orange Business Services
Independent trade press (Fierce Network/Fierce Telecom), verified live 2026-09-15, on the same BNP Paribas deployment already backing Branch and office connectivity (FS-058 etc.). This additional independent-media detail explicitly names business-continuity focus during migration and firewall installation for segmentation/security, supporting two further capability fields from the same well-evidenced named deployment.
Does not prove: Added 2026-09-15 per thin-provider research pass. Same underlying BNP Paribas deployment as existing sources, providing additional independently-reported detail (business continuity focus, firewall installation) not previously captured.
fierce-network.com · Checked 15 Sept 2026 · Supports: Network segmentation and zoning, Resilience and tested recovery
- FIN-515AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- SD-WAN Cisco Offer; Flexible SD Branch Offer
- Standard or regulation:
- SOC 2 Type II
SOC 2 Type II audited scope explicitly lists the 'SD-WAN Cisco Offer' and 'Flexible SD Branch Offer' by name, alongside the Orange backbone network.
Harry personally verified this live 2026-09-15. This is unusually specific - most providers' SOC 2 pages don't name individual SD-WAN products, but Orange's does. This is genuine product-level assurance evidence for managed operations, not proof of any specific regulatory regime alignment (DORA/FCA/PCI) on its own.
Does not prove: Added 2026-09-15, Harry-verified. SOC 2 report itself was not read - only the scope statement naming the products.
orange-business.com · Checked 15 Sept 2026 · Supports: Change control and configuration governance, Managed operations and SOC
- FIN-378RejectedProvider-authoredOther
Orange Business homepage and certifications summary
- Named service:
- Orange Business (corporate)
- Countries, regions:
- Not stated
- Regulatory regime:
- Not stated
ISO 27001, SOC2 Type II, CISPE (GDPR/RGPD Compliance), SecNumCloud, TISAX, HDS (healthcare division)
Orange Business's published certification list covers ISO 27001, SOC 2 Type II, CISPE/GDPR, SecNumCloud, TISAX and HDS; no PCI DSS, FIPS 140-2/140-3 or FedRAMP certification appears on the corporate site pages reached.
Does not prove: Confirms the absence of PCI DSS/FIPS certification on the corporate site but does not name Flexible SD-WAN, SASE or a financial customer, so it cannot itself prove or disprove any of the 28 columns; used only as negative evidence in searched_where.
orange-business.com · Checked 12 Sept 2026
- FIN-381RejectedProvider-authoredFinancial services solution page
Customer stories filtered by Bank & insurance industry
- Named service:
- Not stated on listing page
- Countries, regions:
- Not stated
- Regulatory regime:
- Not stated
Bank & insurance (4)
The customer-stories filter shows a "Bank & insurance" category of 4 stories; only Sto and Banqsoft could be confirmed as bank/insurance-tagged case studies after checking two result pages.
Does not prove: Navigational/listing page only; the other 2 of the 4 tagged stories could not be located across the pages checked, so this cannot itself support any column and is used only to record where the search for named FS customers was conducted.
orange-business.com · Checked 12 Sept 2026
19Verizon Business
2 of 28 proven10 of 19 sourcesOpenClose
Verizon Business on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Verizon Business can show Managed SD WAN deployed at scale in retail banking (over 1,000 and over 1,850 branch case studies) and can show named-product documentation for SASE Management (ZTNA, CASB) and Secure Cloud Gateway (SSL inspection, DLP), plus a 24x7 SOC service, but every banking case study is anonymised so no institution can be named for any column. The evidence is strongest for US retail branch connectivity and for basic managed operations and change control documentation. There is no evidence at all connecting these named services to FCA/PRA, DORA, FFIEC/GLBA/NYDFS, or OSFI regimes, to trading or low-latency workloads, to cardholder data segmentation, to data residency commitments, or to any UK financial services customer. The main limitation for an IT decision maker in a regulated financial institution is the complete absence of a named customer and the complete absence of regime-specific compliance statements tying Managed SD-WAN, SASE Management or Secure Cloud Gateway to a named regulatory framework.
Gaps and unknowns: No named financial institution appears anywhere in the material found, so branch connectivity, resilience, workforce and delivery columns rest on anonymised case studies only. All four regulatory regime columns (UK FCA/PRA, EU DORA, US FFIEC/GLBA/NYDFS/SEC, Canada OSFI) are Not found, as are data residency, logging/audit retention, incident notification, subcontractor transparency and exit/portability; closing these would need a dedicated Verizon trust centre or compliance statement naming Managed SD-WAN, SASE Management or Secure Cloud Gateway alongside a specific regime or documented control, which was not located during this search.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Not found
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Not found
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Partial
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Partial
- UK delivery
- Not found
- North America delivery
- Partial
- Global delivery
- Partial
Sources (18)
- FIN-419AcceptedProvider-authoredNamed customer case study
Financial Services Network Case Study (leading bank) | Verizon Business
- Named service:
- Managed SD WAN
- Sites, branches, users:
- 1850+ branches
- Regulatory regime:
- Not stated
- Outcome:
- Improved critical branch application uptime with multiple network paths
Improved critical branch application uptime with multiple network paths
A Verizon case study describes an unnamed bank deploying Managed SD WAN across more than 1,850 branches, plus Private IP circuits with 4G LTE backup, to improve bandwidth, uptime and restoration capability.
Does not prove: Customer is anonymised (referred to only as 'the bank'), so this does not prove a named financial institution deployment. No RTO/RPO figures, no regulatory mentions, no country stated.
verizon.com · Checked 12 Sept 2026 · Supports: Branch and office connectivity, Resilience and tested recovery
- FIN-420AcceptedProvider-authoredNamed customer case study
Retail Banking Network Technology Case Study | Verizon Business
- Named service:
- Managed SD WAN
- Sites, branches, users:
- 1,000+ branches
- Countries, regions:
- United States (10-state regional banking presence)
- Regulatory regime:
- US
- Outcome:
- Thousands of employees gaining improved mobility; easily scale thousands of locations with centralized administration
Managed SD WAN Spin up virtual WAN services and make network adjustments on the fly.
A Verizon case study describes an unnamed 10-state US retail bank upgrading over 1,000 branches to Ethernet and deploying Managed SD WAN and secure Wi-Fi to support a new mobile banking app and modernised branch workspaces.
Does not prove: Customer is anonymised ('retail bank'). No cardholder data, segmentation, resilience metric, or regulatory detail is given. US only, so not evidence for UK, EU or Canada columns.
verizon.com · Checked 12 Sept 2026 · Supports: Branch and office connectivity, Remote and hybrid workforce
- FIN-422AcceptedProvider-authoredFinancial services solution page
Secure Access Service Edge (SASE) Solutions | Verizon
- Named service:
- SASE Management
- Regulatory regime:
- Not stated
SASE Management merges network and cloud security management across the enterprise to help you securely connect people, data, and devices
Verizon's SASE Management product page describes a unified SD-WAN and cloud security platform with ZTNA, CASB, FWaaS and centralised policy control, supporting Versa, Cisco, Zscaler and Palo Alto Prisma Access, but names no financial services customer or regulatory standard.
Does not prove: Product-named documentation confirms ZTNA and CASB capability exist in the service, but with no financial services context, no named customer, and no certification detail (FIPS, SOC, ISO not mentioned).
verizon.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Cloud and SaaS data controls
- FIN-423AcceptedProvider-authoredNamed customer case study
Managed SD WAN Solutions and Services | Verizon
- Named service:
- Managed SD WAN
- Sites, branches, users:
- thousands of locations
- Regulatory regime:
- Not stated
- Outcome:
- Easily scale thousands of locations with centralized administration and improved traffic prioritization using Managed SD WAN
easily scaled thousands of locations with centralized administration and improved traffic prioritization using Managed SD WAN
The Managed SD WAN product page states the service is 24x7 managed with automated near real-time monitoring and customer-accessible reporting via the Verizon Enterprise Center, backed by SLAs, and references an unnamed retail bank customer.
Does not prove: 24x7 management and reporting is generic, not financial-services specific; retail bank reference is anonymised and gives no metric for visibility/reporting outcomes.
verizon.com · Checked 12 Sept 2026 · Supports: Change control and configuration governance, Network visibility and reporting, Managed operations and SOC
- FIN-424AcceptedProvider-authoredCompliance attestation or statement
Governance, Risk & Compliance (GRC) Services | Verizon Global
- Named service:
- Governance, Risk & Compliance (GRC) Services
- Standard or regulation:
- PCI DSS; SWIFT Customer Security Controls Framework (CSCF)
- Regulatory regime:
- Not stated
Payment Card Industry Data Security Standard (PCI DSS) experts can help you assess, manage and implement a plan to maintain PCI compliance
Verizon offers separate professional-services assessments for PCI DSS compliance and SWIFT CSCF independent assessment, but these are advisory services distinct from Managed SD-WAN, SASE Management or Secure Cloud Gateway, and the page does not connect them to those named network/security products.
Does not prove: Does not name Managed SD-WAN, SASE Management or Secure Cloud Gateway as the assessed or certified service; this is an advisory offering, not a product certification or a customer case, so it is Partial evidence only for PCI DSS and SWIFT columns.
verizon.com · Checked 12 Sept 2026 · Supports: SWIFT CSP alignment, PCI DSS alignment
- FIN-432AcceptedProvider-authoredProvider-authored
Managed SD WAN: Wiser WAN Solution | Verizon Solutions
- Named service:
- Managed SD WAN
- Regulatory regime:
- Not stated
We provide geo-diversified network operations centers, trained personnel and scaled, carrier-integrated management platforms
This solution brief for Managed SD WAN with Application Aware Routing describes a standardised security policy overlay across sites, unified fault, configuration and change management, geo-diversified NOCs, and a Global WAN SLA covering multiple third-party service providers.
Does not prove: Documents change management and network operations for the named product but gives no financial services context, no named customer, no VRF/micro-segmentation detail, and no explicit RTO/RPO commitment.
verizon.com · Checked 12 Sept 2026 · Supports: Change control and configuration governance, Network segmentation and zoning, Resilience and tested recovery
- FIN-433AcceptedProvider-authoredCompliance attestation or statement
Verizon Secure Cloud Gateway fact sheet
- Named service:
- Secure Cloud Gateway
- Regulatory regime:
- Not stated
Deep file-based data loss prevention service helps detect and block the transfer of sensitive data from your enterprise.
The Secure Cloud Gateway fact sheet documents SSL/TLS decryption and re-encryption for inspection purposes and a deep file-based DLP capability that can detect credit card numbers and PII, naming the service directly, but with no financial services example and no FIPS or key management standard cited.
Does not prove: Confirms encryption handling and DLP as named-product documentation, but does not cite FIPS 140-2/140-3 validation, does not name a key management standard, and the fact sheet is dated 2018 with no confirmation it reflects the current service.
verizon.com · Checked 12 Sept 2026 · Supports: Encryption and key management, Cloud and SaaS data controls
- FIN-434AcceptedProvider-authoredCompliance attestation or statement
Soc As A Service | Verizon Business
- Named service:
- Advanced Security Operations Center (SOC) Services
- Regulatory regime:
- Not stated
Gain 24/7 access to monitoring, extensive global threat visibility and expert analysis.
Verizon's SOC as a Service page confirms 24x7 monitoring, detection and analyst escalation as a named managed security service, but does not mention financial services customers or connect explicitly to Managed SD-WAN, SASE Management or Secure Cloud Gateway.
Does not prove: Proves a 24x7 SOC service exists at Verizon generally, but not specifically wrapped around the three named network/SASE products, and with no financial services customer.
verizon.com · Checked 12 Sept 2026 · Supports: Managed operations and SOC
- FIN-521AcceptedProvider-authoredCompliance attestation or statement
Strengthening Your Critical Infrastructure Security - Verizon Business
- Named service:
- Verizon managed security / critical infrastructure services
- Standard or regulation:
- DORA; PCI DSS; Cyber Essentials; TIBER-EU
Lists DORA, PCI DSS, Cyber Essentials and TIBER-EU in the context of Verizon's managed security and critical-infrastructure services.
Harry personally verified this live 2026-09-15. A portfolio-level list of frameworks Verizon's security services touch, not a named-service contractual mapping - graded Partial, consistent with the document's own caution against treating this as Proven.
Does not prove: Added 2026-09-15, Harry-verified. Portfolio-level framework list, not scoped to a named SD-WAN/SASE product.
verizon.com · Checked 15 Sept 2026 · Supports: EU DORA alignment, PCI DSS alignment
- FS-070AcceptedProvider-authoredExisting source lead
Retail Banking Network Technology Case Study | Verizon Business
A slow and dated network kept this retail bank from moving its business into the future.
Two distinct SD-WAN banking case studies exist. The retail bank story is quoted here. A second story on a leading bank states it Deployed SD WAN architecture and private IP circuits with 4G LTE backup. Both customers are anonymised, which is why this is vendor-claimed rather than independently verifiable, but the sector and the SD-WAN solution are explicit in both. Financial services also has a dedicated industry page.
Does not prove: Supplier's own case study. Customer anonymised, sector and SD-WAN outcome stated explicitly. | Confirmed - exact match
verizon.com · Checked 29 Jul 2026 · Supports: Branch and office connectivity, Resilience and tested recovery
- FIN-421RejectedProvider-authoredFinancial services solution page
Financial Services Solutions & Financial Services Technology | Verizon
- Named service:
- Secure Access Service Edge (SASE)
- Regulatory regime:
- Not stated
Get informed about cybercriminals and protect your customers' sensitive personal and financial data with the help of our security experts.
Verizon's financial services solutions hub lists SASE and managed network services in a generic products menu but gives no named financial customer, deployment detail or regulatory reference on the page itself.
Does not prove: Purely a navigation/marketing hub with no named customer, no product-to-outcome connection, and no regulatory content; rejected as not evidentiary beyond generic industry framing.
verizon.com · Checked 12 Sept 2026
- FIN-425RejectedProvider-authoredFinancial services solution page
Financial Services Technology Trends & Insights | Verizon
- Named service:
- Not applicable
- Regulatory regime:
- Not stated
The report highlights key regulatory standards, including PCI DSS and ISO frameworks
A generic financial services resources hub links to SD-WAN and SASE product pages and to third-party report abstracts mentioning PCI DSS and ISO frameworks for banks, without naming any financial institution or connecting a named Verizon product to a specific regulation.
Does not prove: No named customer, no direct product-to-regulation link, only a summary of an external report abstract; not usable as evidence for any specific column.
verizon.com · Checked 12 Sept 2026
- FIN-426RejectedProvider-authoredFinancial services solution page
Build Better Financial Services Infrastructure | Verizon
- Named service:
- Managed SD-WAN; Network as a Service (NaaS)
- Regulatory regime:
- Not stated
Strengthen your operational core and be ready to adapt to changing needs and technologies with networking solutions that are secure and agile.
This financial services infrastructure page positions Managed SD-WAN and Network as a Service generically for the sector, with no named institution, no data-centre or cloud on-ramp detail, and no resilience metric.
Does not prove: Generic solutions page with no named customer, no measurable outcome, and no regulatory reference; does not meet the bar for any column beyond what the dedicated case studies already establish.
verizon.com · Checked 12 Sept 2026
- FIN-427RejectedProvider-authoredOther
Secure Gateway Service | Verizon
- Named service:
- Secure Gateway
- Regulatory regime:
- Not stated
Strong service level agreements (SLAs) and a team of Verizon networking experts
Secure Gateway is a Private IP WAN extension/backup product for remote users and locations; it is a different, older product from Secure Cloud Gateway and does not mention financial services, CASB or DLP.
Does not prove: Not the same product as Verizon Secure Cloud Gateway; no financial services, no security control detail relevant to the 28 columns.
verizon.com · Checked 12 Sept 2026
- FIN-428RejectedProvider-authoredOther
Verizon Business zero trust dynamic access
- Named service:
- Zero Trust Dynamic Access; SASE
- Regulatory regime:
- Not stated
make a strategic shift to an identity-centric, unified network and security management service
This cybersecurity solutions page lists SASE alongside DDoS Shield, mobile security and an Advanced SOC, and references identity-centric management, but does not explicitly describe ZTNA, MFA or IdP integration mechanics or any financial services use.
Does not prove: Too generic on identity/zero trust mechanics and has no financial services or named-customer content; does not meet the bar to support column 12 beyond the SASE Management page already accepted.
verizon.com · Checked 12 Sept 2026
- FIN-429RejectedProvider-authoredOther
Business Case Studies | Verizon Global
- Named service:
- Not applicable
- Regulatory regime:
- Not stated
Scottsdale Unified School District empowers staff and boosts safety
The UK case study index lists no financial services, banking, insurance or credit union case studies; the only visible case study is a US school district, and a 'global financial services firm' link elsewhere on the site returns a 404.
Does not prove: Confirms the case study index does not surface further named financial institution studies beyond the ones already found; used only to record where the search was conducted.
verizon.com · Published 7 Nov 2024 · Checked 12 Sept 2026
- FIN-430RejectedProvider-authoredNamed customer case study
Wealth Management Technology Case Study | Verizon Business
- Named service:
- Secure Cloud Interconnect
- Sites, branches, users:
- 2,500 agents
- Regulatory regime:
- Not stated
- Outcome:
- Delivered greater insight, personalization and instant responses for 20M customers
Provided seamless, flexible access to SaaS and AI web services
This wealth management case study describes an unnamed firm using Secure Cloud Interconnect and Next Gen Network (4G LTE) to support 2,500 agents and 20 million customers, but does not name Managed SD-WAN, SASE Management or Secure Cloud Gateway.
Does not prove: Does not reference any of the three named services in scope for this research (Managed SD-WAN, SASE Management, Secure Cloud Gateway), so it cannot support any of the 28 columns for this provider.
verizon.com · Checked 12 Sept 2026
- FIN-431RejectedProvider-authoredFinancial services solution page
Protect Customer Financial Data with a Cybersecurity Strategy | Verizon
- Named service:
- SASE
- Regulatory regime:
- Not stated
Our security experts can help you identify vulnerabilities and design a cybersecurity strategy
This financial data protection page references SASE under Network and Cloud Security and links to a 'large global bank' case study, but names no institution, no CASB/DLP/ZTNA mechanics, and no regulation.
Does not prove: No named customer, no regulatory reference, no specific security control detail beyond what is already captured from the SASE Management and Secure Cloud Gateway pages.
verizon.com · Checked 12 Sept 2026
20VeloCloud
5 of 28 proven7 of 14 sourcesOpenClose
VeloCloud on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
VeloCloud SD-WAN has one named financial services customer opened in this research, STAR Financial Bank, a US retail bank that used it to connect rural branches, ATMs and interactive teller machines, which supports branch connectivity and North America delivery. The provider's own financial services solution brief and retail solution brief give documentation-type evidence for PCI DSS alignment, cardholder data segmentation and FIPS-based encryption, but the financial and insurance customers quoted in the financial services brief are anonymised rather than named. No evidence was found connecting the named service to trading floors, UK delivery, DORA, FCA/PRA, FFIEC/GLBA/NYDFS/SEC, OSFI or SWIFT CSP, and Arista's corporate trust centre does not confirm whether VeloCloud specifically sits within its SOC 2 scope from the page content available. Overall this is reasonable evidence for US retail-banking branch connectivity and PCI-related segmentation, but weak or absent evidence for UK and EU regulatory alignment, data residency, logging retention, incident notification and subcontractor transparency. An IT decision maker in a UK or EU FS firm would need to request the gated subprocessor list, a named UK or EU customer reference and an explicit DORA or FCA/PRA statement directly from Arista before relying on this service for a regulated deployment.
Gaps and unknowns: No evidence was found for trading/low-latency connectivity, UK delivery, UK regulatory alignment (FCA/PRA), EU DORA alignment, US FFIEC/GLBA/NYDFS/SEC alignment, Canadian OSFI alignment, SWIFT CSP, data residency, logging/audit retention, change control governance, incident notification timelines, exit/portability terms, managed 24x7 SOC, and third-party/subcontractor access controls. Closing these would require the gated Arista trust centre subprocessor and per-product certification documents, a published data processing agreement or GDPR/DORA statement naming VeloCloud, and additional named UK, EU or Canadian financial services case studies, none of which were accessible or found during this research.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Proven
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Not found
- Data residency and sovereignty
- Not found
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Proven
- Global delivery
- Partial
Sources (12)
- FIN-410AcceptedProvider-authoredFinancial services solution page
Arista Networks - SD-WAN & Edge Routing (VeloCloud SD-WAN solution page)
- Named service:
- VeloCloud SD-WAN, VeloCloud SASE
- Regulatory regime:
- Not stated
zero trust networking with end-to-end encryption and an integrated L7 firewall
General VeloCloud SD-WAN and SASE product page describing encryption, zero trust, multi-cloud on-ramps (AWS Cloud WAN, Azure Virtual WAN, Google Cloud) and a global network of over 3,000 cloud gateways across 150+ SASE points of presence, and links out to a financial services brief and a PCI compliance brief.
Does not prove: Generic product page with no named customer; does not by itself prove any financial-services deployment, only product capability and global footprint.
arista.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Identity and zero trust access, Encryption and key management, Global delivery
- FIN-411AcceptedProvider-authoredFinancial services solution page
VeloCloud SD-WAN for Financial Services - Solution Brief (PDF)
- Named service:
- VeloCloud SD-WAN
- Sites, branches, users:
- large insurance company with thousands of sites
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
- Outcome:
- 20% reduction in maintenance costs for branches and ATMs within two years; 83% of network incidents automatically identified, 100% triaged, 34% automatically restored
VeloCloud gave us peace of mind during the testing phase as the VeloCloud SD-WAN solution proved to be the reliable solution we were seeking, thanks to VeloCloud's superior architecture and technology.
Arista's financial services solution brief for VeloCloud SD-WAN cites an unnamed global financial institution, international bank and large insurance company, describing branch/ATM connectivity, DR combining MPLS, broadband and 4G-LTE, native support for 9 of 12 PCI DSS requirements, and automated incident detection.
Does not prove: All customers quoted are anonymised (Global Financial Institution, international banking institution, Fortune 500 technical-services provider, large insurance company); no institution is named, so this is treated as Partial-strength evidence per the grading rules for anonymised customers.
arista.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Payment and cardholder data segmentation, Network visibility and reporting, Network segmentation and zoning, Branch and office connectivity, Resilience and tested recovery
- FIN-412AcceptedProvider-authoredNamed customer case study
Bringing Secure Interactive Financial Services to Rural Regions with SD-WAN - VeloCloud
- Named financial institution:
- STAR Financial Bank
- Named service:
- VeloCloud (VMware SD-WAN by VeloCloud)
- Sites, branches, users:
- branches, insurance offices, ATMs and ITMs
- Countries, regions:
- United States (Indiana)
- Regulatory regime:
- US
Banking services were provided using a combination of locations such as branches, insurance offices, automated teller machines (ATM) and interactive teller machines (ITM).
STAR Financial Bank, a US bank based in Indiana, used VeloCloud SD-WAN to connect rural branches, ATMs and interactive teller machines that needed more bandwidth for video than legacy MPLS could provide.
Does not prove: This is a legacy VMware/VeloCloud blog post; the linked full case study (velocloud.com) could not be fetched (robots-disallowed), so specific outcome metrics are not available from an opened page. Does not evidence trading, DR testing, resilience metrics, or any regulatory regime beyond general US location.
blogs.vmware.com · Published 20 Mar 2018 · Checked 12 Sept 2026 · Supports: Branch and office connectivity, North America delivery
- FIN-413AcceptedProvider-authoredFinancial services solution page
- Named service:
- VeloCloud SD-WAN, VeloCloud SASE
- Regulatory regime:
- Not stated
segment-aware, layer 7 stateful firewall
Product page listing VeloCloud SD-WAN and SASE security features including a layer 7 firewall, IDS/IPS, and URL/DNS/Geo-IP filtering powered by Webroot Brightcloud, and linking to a financial services brief and a PCI compliance brief.
Does not prove: Generic security feature list, not a CASB/DLP statement and not financial-services specific; does not name any customer.
arista.com · Checked 12 Sept 2026 · Supports: Cloud and SaaS data controls
- FIN-417AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- VeloCloud SD-WAN Orchestrator, Edge
- Standard or regulation:
- FIPS 140-2
- Regulatory regime:
- Not stated
FIPS 140-2 certification for cryptographic modules enables organizations to meet compliance requirements
VeloCloud's own Orchestrator Guide documents a FIPS mode for the SD-WAN Edge and Orchestrator using FIPS-validated cryptographic modules (the system kernel crypto library, OpenSSL, and OpenSSH), with FIPS-approved algorithms such as AES, HMAC-SHA2 and ECDH.
Does not prove: Documents FIPS-validated component modules and a FIPS operational mode, but does not itself state a specific CMVP certificate number or that the whole VeloCloud SD-WAN product line holds current FIPS 140-2/140-3 validation; treat as partial validation evidence, not a full product certification.
arista.com · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-418AcceptedProvider-authoredCompliance attestation or statement
VeloCloud SD-WAN for Retail - Solution Brief
- Named service:
- VeloCloud Orchestrator, SD-WAN Controller, SD-WAN Edge, Partner Gateway
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
Failure to comply with PCI requirements in these areas can create liabilities that put sensitive purchase data at risk, damaging brand reputation.
Arista's retail solution brief states that the VeloCloud Orchestrator, SD-WAN Controller, SD-WAN Edge and Partner Gateway are offered as PCI-certified infrastructure elements to protect customers' personal data including credit card numbers.
Does not prove: Retail context, not financial services, and no named customer; supports the PCI DSS/cardholder-segmentation columns as documentation-type evidence but is not FS-sector proof of a deployment.
arista.com · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation, PCI DSS alignment
- FIN-534AcceptedProvider-authoredNamed customer case study
Scaling Your Network to Accommodate 2000+ Remote Sites - VMware SD-WAN
- Named financial institution:
- Grupo Bancolombia
- Named service:
- VMware SD-WAN (VeloCloud)
- Sites, branches, users:
- 640+ branches; 1,200+ ATMs; 20,000 employees; 20 million+ customers
- Countries, regions:
- Colombia; Central America; Caribbean
- Standard or regulation:
- Colombian Financial Superintendency
- Regulatory regime:
- Not stated
- Outcome:
- Integrated nearly 700 branches with SD-WAN in just over four months; estimated 20% cost savings for branch/ATM maintenance within two years
"VMware gave us peace of mind during testing phase as the VMware SD-WAN solution proved to be the reliable solution we were seeking, thanks to VMware's superior architecture and technology." - Angel David Niebles, Leader of Branches and ATMs Connectivity Area of Telecommunications Management, Bancolombia. "Bancolombia also trusts SD-WAN's built-in AES 256 encryption for data links to protect its most sensitive data."
Verified live 2026-09-15. Grupo Bancolombia is the largest bank in Colombia, real and named, with a named executive quote. Named regulator (Colombian Financial Superintendency) - outside UK/EU/US/Canada regimes tracked, so Regulatory regime stays Not stated per schema. AES-256 encryption is explicitly named.
Does not prove: Added 2026-09-15 per further research pass (cross-platform lead, independently verified).
blogs.vmware.com · Checked 15 Sept 2026 · Supports: Network segmentation and zoning, Branch and office connectivity, Encryption and key management
- FIN-409RejectedProvider-authoredContradiction
Arista Networks - Electronic Trading solutions
- Named service:
- Arista 7130 Series, MetaMux, MetaProtect, MetaWatch
- Regulatory regime:
- Not stated
round trip time of only 44 ns
Arista's electronic trading page covers only its 7130 FPGA switches and precision timing/tap products for high-frequency trading; VeloCloud SD-WAN or SASE is not mentioned anywhere in the trading context, only appearing in the general site navigation.
Does not prove: Confirms VeloCloud is not positioned for trading/exchange connectivity on Arista's own site; does not prove or disprove the requirement, just shows no evidence exists here.
arista.com · Checked 12 Sept 2026
- FIN-414RejectedProvider-authoredOther
- Named service:
- VeloCloud SD-WAN
- Regulatory regime:
- Not stated
Administration Guide, Operator Guide, Partner Guide
A navigation/support hub page linking to VeloCloud documentation, software downloads and advisories; contains no financial services, compliance, PCI, SLA or data residency content itself.
Does not prove: No substantive compliance or FS evidence; used only to confirm no relevant documents are indexed here.
arista.com · Checked 12 Sept 2026
- FIN-415RejectedProvider-authoredOther
Arista Customer Success Story (Converged Cloud Fabric, Financial Services)
- Named service:
- Converged Cloud Fabric (CCF), VMware NSX, CloudVision
- Regulatory regime:
- Not stated
- Outcome:
- Lower capital expenditure and reduced troubleshooting time versus alternative architectures
Changing over to Arista was a significant savings in capital expenditures, but more important, in man hours spent troubleshooting configuration issues, compared to other architectures we were evaluating.
An anonymised financial services company's case study about Arista's data-centre Converged Cloud Fabric switching and NSX; VeloCloud SD-WAN/SASE is not mentioned anywhere in this document.
Does not prove: Wrong product family (data-centre switching fabric, not SD-WAN/SASE); does not name VeloCloud so cannot support any of the 28 columns per the brief's product-naming rule.
arista.com · Published 1 Jun 2020 · Checked 12 Sept 2026
- FIN-416RejectedProvider-authoredCompliance attestation or statement
- Named service:
- Arista Networks (corporate)
- Standard or regulation:
- SOC 2 Type 2
- Regulatory regime:
- Not stated
For individual products or Cloud Services certifications like SOC2, select the product from the drop-down above.
Arista's corporate SafeBase-powered trust centre lists company-wide certifications (SOC 2, SOC 2 Type 2, Cyber Essentials, Cyber Essentials Plus, ENS) and a gated subprocessors document, but the visible page does not confirm VeloCloud SD-WAN or SASE specifically as being in scope.
Does not prove: Does not name VeloCloud SD-WAN/SASE as being within the certified scope on the page content retrieved; the subprocessors list and per-product certificates require an authenticated 'Get access' request that could not be completed, so data residency, retention and subcontractor detail remain unverified from this page.
trust.arista.com · Checked 12 Sept 2026
- FS-003RejectedProvider-authoredExisting source lead
Arista Networks - Customer Testimonials / Customer Success Stories
From the exchange edge to the back office, Arista offers a range of products optimized for demanding finance and trading environments.
Strongest sector evidence found. There is a dedicated Electronic Trading industry page with named customer stories (Deutsche Boerse Group, ING Romania), named banking customers Odeabank and FIBI Bank under a 'Finance' label in the customer story library, and a VeloCloud SD-WAN for Financial Services solution brief. Caveat worth carrying: the named customers are Arista switching, CloudVision and data centre deployments, while the VeloCloud-specific financial brief keeps its deployments anonymous ('an international banking institution', 'a large insurance company').
Does not prove: Supplier's named-customer library with an explicit industry filter taxonomy. Strongest source for which sectors Arista can actually name customers in. Caveat: the visible stories are campus, Wi-Fi, CloudVision and data centre deployments, not VeloCloud SD-WAN. | Not found on page
arista.com · Checked 29 Jul 2026
21Ericsson Cradlepoint
2 of 28 proven12 of 20 sourcesOpenClose
Ericsson Cradlepoint on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Ericsson Cradlepoint publishes device-level FIPS 140-3 validation, a SOC 2 Type II attestation covering NetCloud Manager and NetCloud SASE, ISO 27001 and NIST SSDF coverage, a 30-day NetCloud Manager activity log retention period, and PCI DSS configuration guidance, which together give reasonable documentation-based evidence for encryption, logging and PCI groundwork. There is no named bank, credit union, insurer or payment firm case study evidencing branch backup, ATM connectivity, trading, resilience testing or remote workforce use on NetCloud; the strongest financial-sector reference found, Jackson Hewitt, is a US tax-preparation franchise named only for kiosk cellular routers, not a bank. No source connects the named service to FCA/PRA, DORA, FFIEC/GLBA/NYDFS/SEC, OSFI or SWIFT CSP regimes, and UK delivery evidence is limited to a UK sales phone number. Overall this is background compliance documentation with essentially no financial-services proof points, so an IT decision maker at a bank or credit union cannot rely on it as an evidenced fit for FS regulatory or operational requirements without direct vendor engagement.
Gaps and unknowns: No named financial institution case studies exist for branch/office connectivity, trading, data-centre/cloud connectivity, resilience testing, segmentation, third-party access, or remote workforce use; a named bank, credit union or insurer deployment with sites, outcomes and dates would close these. All four UK, EU, US and Canada regulatory alignment columns and SWIFT CSP are unevidenced; a published compliance statement or FS customer case naming FCA/PRA, DORA, FFIEC/GLBA/NYDFS/SEC or OSFI would be needed. Sub-processor transparency, data export/exit assistance, and a genuine security-incident notification SLA (rather than maintenance notice or a 30-day code-remediation clause) are also unevidenced and would need dedicated trust-centre or contractual documentation.
- Branch and office connectivity
- Partial
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Not found
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Not found
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Partial
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Proven
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Not found
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Partial
- Incident notification support
- Partial
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Partial
- Global delivery
- Partial
Sources (18)
- FIN-236AcceptedProvider-authoredFinancial services solution page
Wireless Edge Solutions for Financial Services | Ericsson
- Named service:
- Ericsson Cradlepoint NetCloud
- Regulatory regime:
- Not stated
Deliver secure, flexible LTE/5G connectivity to branches, mobile offices, ATMs, and connected security cameras and signs, with zero trust security built in.
This is a generic financial services solutions page describing branch, ATM and kiosk connectivity plus zero trust access features of NetCloud, with no named financial institution.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page has the two clauses as separate sentences ('...zero trust security built in' and the enforce-policy sentence), not combined verbatim as quoted.). Re-quote verbatim. Does not name any bank, credit union, insurer or payment firm; does not evidence trading, data-centre, PCI segmentation, regulatory alignment or delivery geography. [2026-09-15, Playwright fetch] Re-quoted verbatim, full combined tagline confirmed on the live page.
cradlepoint.ericsson.com · Checked 15 Sept 2026 · Supports: Branch and office connectivity, Identity and zero trust access
- FIN-237AcceptedProvider-authoredNamed customer case study
Connectivity for finance, insurance and fintech - Ericsson
- Named financial institution:
- Jackson Hewitt (franchise)
- Named service:
- Ericsson Cradlepoint cellular routers
- Countries, regions:
- United States
- Regulatory regime:
- US
Discover how a Jackson Hewitt franchise accelerates kiosk deployment while lowering costs by using Ericsson Cradlepoint cellular routers.
A one-sentence teaser names Jackson Hewitt, a tax-preparation franchise offering consumer refund-advance lending products, using Cradlepoint cellular routers for kiosk deployment; no dedicated case study page with detail was found.
Does not prove: Jackson Hewitt is a tax-preparation franchise, not a bank, credit union or insurer; the reference names only cellular routers, not NetCloud SD-WAN/SASE by name, and no fuller case study page could be located to verify scope, sites or outcome.
ericsson.com · Checked 12 Sept 2026 · Supports: Branch and office connectivity
- FIN-238AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Ericsson NetCloud (NetCloud Manager, NetCloud SASE)
- Standard or regulation:
- ISO 27001; FIPS 140-3; SOC 2 Type II; NIST SSDF (SP 800-218)
- Regulatory regime:
- Not stated
The result is the security posture for Ericsson NetCloud and select Ericsson Cradlepoint routers that has been independently validated across two major regulatory certifications, including ISO 27001, and FIPS 140.
Ericsson states that NetCloud Manager and NetCloud SASE hold a SOC 2 Type II attestation and ISO 27001 and NIST SSDF coverage, and that select Cradlepoint routers hold FIPS 140-3 validation for cryptography covering data in transit and at rest.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Facts present (11 test areas; 62 controls/10 IT services/Unmodified Opinion) but in separate paragraphs, not the combined quote.). Re-quote verbatim. Blog post summarises the certifications but does not reproduce the SOC 2 report, ISO certificate scope statement or FIPS certificate itself; not financial-services specific and does not state UK/EU/US regulatory alignment. [2026-09-15, Playwright fetch] Re-quoted verbatim from the live blog post.
· Published 2 Apr 2026 · Checked 15 Sept 2026 · Supports: Encryption and key management
- FIN-240AcceptedProvider-authoredCompliance attestation or statement
End User Agreement | NetCloud Manager Services | Cradlepoint
- Named service:
- NetCloud Manager Services
- Regulatory regime:
- Not stated
Cradlepoint will use commercially reasonable efforts to make the...Services available 24 hours a day, 7 days a week, except for: (i) scheduled maintenance downtime, (ii) emergency maintenance, and (iii) any unavailability caused by circumstances beyond Cradlepoint's reasonable control.
The NetCloud Manager Services end user agreement commits to best-effort 24x7 availability and a 30-day period to correct or provide a plan for non-compliant harmful code issues, but does not set a measurable uptime percentage or general incident notification timeline.
Does not prove: No RTO/RPO, no data residency, no log retention, no sub-processor list, and no general security-incident notification commitment; only a narrow 30-day non-compliance cure period is stated.
cradlepoint.com · Checked 12 Sept 2026 · Supports: Incident notification support
- FIN-241AcceptedProvider-authoredCompliance attestation or statement
FIPS 140-3 Certified Products - Cradlepoint
- Named service:
- Ericsson Enterprise Wireless routers (E-Series, R-Series, S-Series)
- Standard or regulation:
- FIPS 140-3
- Regulatory regime:
- US
Ericsson Enterprise Wireless has FIPS 140-3 level 1 certified part numbers
Cradlepoint documentation lists specific E-Series, R-Series and S-Series router part numbers that hold FIPS 140-3 Level 1 validation.
Does not prove: Confirms device-level FIPS validation only; does not itself confirm NetCloud Manager or NetCloud SASE cloud service encryption or key management, and is not financial-services specific.
docs.cradlepoint.com · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-242AcceptedProvider-authoredCompliance attestation or statement
Foundational security | Ericsson
- Named service:
- NetCloud Manager
- Regulatory regime:
- Not stated
confidentiality of customer network configuration data is maintained via encryption-at-rest and encryption-in-transit
Ericsson describes NetCloud Manager architecture using AWS-hosted infrastructure with encryption at rest and in transit, TLS for the management connection, and account security features including MFA, federated identity and role-based permissions.
Does not prove: General product security description, not financial-services specific; does not state data residency, log retention periods or FIPS validation for the cloud service itself.
cradlepoint.ericsson.com · Checked 12 Sept 2026 · Supports: Change control and configuration governance, Identity and zero trust access, Encryption and key management
- FIN-243AcceptedProvider-authoredCompliance attestation or statement
Privacy Policy - January 31, 2024 | Archive - Cradlepoint
- Named service:
- Cradlepoint Services
- Countries, regions:
- United States; European Economic Area; Australia
- Regulatory regime:
- Multiple
We primarily store your information in the United States, the European Economic Area and Australia.
Cradlepoint's privacy notice states personal data is primarily stored in the US, EEA and Australia, with international transfers governed by Standard Contractual Clauses and the EU-US Data Privacy Framework.
Does not prove: Company-wide privacy notice, not NetCloud-service-specific; does not state UK-specific storage (EEA excludes the UK) or Canada-specific storage, and gives no log retention period.
cradlepoint.com · Published 31 Jan 2024 · Checked 12 Sept 2026 · Supports: Data residency and sovereignty
- FIN-244AcceptedProvider-authoredCompliance attestation or statement
NetCloud Exchange Terms and Conditions | Cradlepoint
- Named service:
- NetCloud SASE
- Regulatory regime:
- Not stated
99.9% per each calendar month subject to Excluded Disruptions
NetCloud SASE terms set a 99.9% monthly availability target with tiered service credits down to 96% availability, and state Cradlepoint will use reasonable efforts to give advance notice of maintenance outside routine windows.
Does not prove: This is a generic uptime SLA, not an RTO/RPO or disaster-recovery commitment, and the maintenance notice language is not a general security-incident notification commitment; not financial-services specific and no sub-processor list is included.
cradlepoint.com · Checked 12 Sept 2026 · Supports: Incident notification support
- FIN-246AcceptedProvider-authoredCompliance attestation or statement
Ericsson Enterprise Wireless Configuration Guidance for PCI DSS Compliance
- Named service:
- Cradlepoint routers
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
Ericsson Enterprise Wireless does not transmit, process, or store Cardholder Information (CHI). This document provides configuration guidelines to enhance solution security and support customers in meeting PCI compliance requirements.
Cradlepoint publishes device configuration guidance mapped to the twelve PCI DSS requirements, including cardholder data environment access and monitoring, to help customers configure Cradlepoint routers for PCI DSS compliance.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Requirement 9 and 10 appear as separate list items, not combined into one sentence as quoted.). Re-quote verbatim. This is configuration guidance to help customers achieve their own PCI DSS compliance, not an Attestation of Compliance or PCI DSS certification of the NetCloud service itself, and the detailed requirement-by-requirement sub-pages returned 404 errors so could not be quoted further. [2026-09-15, Playwright fetch] Re-quoted verbatim. Confirms this is customer-facing configuration guidance, not an Attestation of Compliance for the NetCloud service itself - the existing caution about PCI DSS alignment not being Proven from this source stands.
docs.cradlepoint.com · Checked 15 Sept 2026 · Supports: Payment and cardholder data segmentation, PCI DSS alignment
- FIN-247AcceptedProvider-authoredCompliance attestation or statement
Accessing and Viewing the Activity Log - Cradlepoint
- Named service:
- NetCloud Manager
- Regulatory regime:
- Not stated
Activity Log entries are stored for 30 days.
NetCloud Manager documentation states that Activity Log entries, the audit trail of account and configuration actions, are retained for 30 days.
Does not prove: Confirms only a 30-day retention window for the Activity Log; does not state SIEM export capability or retention periods for other log types (traffic, security event logs), and is not financial-services specific.
docs.cradlepoint.com · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention
- FIN-249AcceptedProvider-authoredOther
ZTNA | Network Security for 5G and LTE - Ericsson Cradlepoint
- Named service:
- Ericsson NetCloud SASE ZTNA
- Regulatory regime:
- Not stated
Zero Trust Network Access (ZTNA) technology that prevents lateral movements, limits user access to just enough, verifies before trusting, and never stops monitoring. ... easily integrates with your organization's identity provider so you can build access policies that directly connect authenticated users with authorized resources
The product page describes NetCloud SASE ZTNA, which integrates with an organisation's identity provider, assigns users to specific applications rather than broad network segments, and continuously re-verifies access.
Does not prove: Generic product description with no financial services customer or context; does not explicitly name MFA, and does not describe CASB or DLP capability.
cradlepoint.ericsson.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access
- FIN-250AcceptedProvider-authoredOther
Ericsson NetCloud SASE and NetCloud Exchange | Ericsson
- Named service:
- Ericsson NetCloud SASE
- Regulatory regime:
- Not stated
Offers integration to any SAML 2.0 compliant Identity Management Platform, preventing identity sprawl. ... NetCloud's Traffic Monitor dashboard is a powerful tool that lets administrators drill into every flow for detailed traffic analysis and forensic.
The NetCloud SASE datasheet describes SAML 2.0 identity provider integration and a Traffic Monitor dashboard for flow-level traffic analysis and forensics.
Does not prove: Generic datasheet with no financial services customer named; does not mention CASB, DLP, or a 24x7 SOC/managed monitoring service.
cradlepoint.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Identity and zero trust access
- FIN-239RejectedProvider-authoredOther
Ericsson Cradlepoint product certifications
- Named service:
- Ericsson Cradlepoint routers
- Standard or regulation:
- PTCRB; GCF-CC
- Regulatory regime:
- Not stated
PTCRB for North America and GCF-CC for the rest of the world
This page lists only cellular network/radio certifications (PTCRB, GCF-CC) required to connect to mobile networks; it contains no security or compliance certifications.
Does not prove: Not relevant to any of the 28 requirement columns; carrier RF certification only, no security, compliance or financial services content.
cradlepoint.ericsson.com · Checked 12 Sept 2026
- FIN-245RejectedProvider-authoredOther
- Named service:
- Ericsson Cradlepoint solutions
- Regulatory regime:
- Not stated
public safety, transportation, manufacturing, mining, utilities, retail, healthcare and ports success stories
The provider's full success-stories index of roughly 81 documents contains no banking, credit union, insurance or payments case study.
Does not prove: Confirms the absence of any named financial services case study on the provider's own success-stories index; not used to support any capability.
cradlepoint.ericsson.com · Checked 12 Sept 2026
- FS-029RejectedTo reviewExisting source lead
Branch - Ericsson Enterprise Wireless Solutions
- Named service:
- Ericsson Cradlepoint NetCloud
For pop-up locations such as seasonal stores, tax prep offices, and election polling places, wired connectivity often either isn't available or is too expensive.
Checked the UK industries page, the branch and branch continuity product pages, the retail collateral, the resource library, the full page sitemap and all 198 press release titles in the press release sitemap. No bank, credit union, insurer, payments firm or financial services customer is named anywhere, and there is no financial services landing page. The nearest mention is tax prep offices in a list of pop-up location types, which is not sector evidence. Graded unknown.
Does not prove: Supplier product page naming Valvoline Instant Oil Change franchisee Henley Enterprises as a customer. | Confirmed - exact match [2026-09-15, flagged per Robert's check] Content describes pop-up retail/election locations, not financial services - this source does not appear to belong under any FS capability column and should probably be Rejected rather than assigned one. Changed from Accepted to Needs review since no specific capability can be honestly assigned - recommend Harry/Robert decide whether to Reject or find a genuine capability fit.
cradlepoint.com · Checked 29 Jul 2026
- FS-030RejectedProvider-authoredExisting source lead
Resources library - Ericsson Enterprise Wireless Solutions
For pop-up locations such as seasonal stores, tax prep offices, and election polling places, wired connectivity often either isn't available or is too expensive.
Checked the UK industries page, the branch and branch continuity product pages, the retail collateral, the resource library, the full page sitemap and all 198 press release titles in the press release sitemap. No bank, credit union, insurer, payments firm or financial services customer is named anywhere, and there is no financial services landing page. The nearest mention is tax prep offices in a list of pop-up location types, which is not sector evidence. Graded unknown.
Does not prove: Supplier resource library. Only four success stories are currently surfaced: City of Cheyenne, Valvoline, a Seattle transit agency and a dozer operations story. Filters are by technology (Private 5G, Wireless WAN, 5G, Security), not by industry. | Not found on page
cradlepoint.ericsson.com · Checked 29 Jul 2026
- FS-031RejectedProvider-authoredExisting source lead
For pop-up locations such as seasonal stores, tax prep offices, and election polling places, wired connectivity often either isn't available or is too expensive.
Checked the UK industries page, the branch and branch continuity product pages, the retail collateral, the resource library, the full page sitemap and all 198 press release titles in the press release sitemap. No bank, credit union, insurer, payments firm or financial services customer is named anywhere, and there is no financial services landing page. The nearest mention is tax prep offices in a list of pop-up location types, which is not sector evidence. Graded unknown.
Does not prove: Supplier XML sitemap listing 198 press release URLs. Used as an index to locate sector and region evidence and to confirm which sectors are absent. | Not found on page
cradlepoint.com · Checked 29 Jul 2026
- FS-032RejectedProvider-authoredExisting source lead
For pop-up locations such as seasonal stores, tax prep offices, and election polling places, wired connectivity often either isn't available or is too expensive.
Checked the UK industries page, the branch and branch continuity product pages, the retail collateral, the resource library, the full page sitemap and all 198 press release titles in the press release sitemap. No bank, credit union, insurer, payments firm or financial services customer is named anywhere, and there is no financial services landing page. The nearest mention is tax prep offices in a list of pop-up location types, which is not sector evidence. Graded unknown.
Does not prove: Supplier XML sitemap listing all site pages. Used to confirm there is no financial services, healthcare, education or hospitality landing page. | Not found on page
cradlepoint.com · Checked 29 Jul 2026
22Check Point
3 of 28 proven8 of 14 sourcesOpenClose
Check Point on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Check Point's Harmony SASE product documents zero trust network access with least-privilege identity controls and publishes a named sub-processor list for the SASE product with the countries each sub-processor operates in, which are the two areas that reach Proven status. Beyond that, the evidence is limited to generic, non-financial marketing and compliance pages: an insurance industry solution page with no named customer, horizontal SOC 2 Type 2 and ISO 27001/27002 certifications with no financial regulatory linkage, and a Quantum SD-WAN launch announcement with no customers named at all. No named bank, insurer, payment firm or asset manager was found using Harmony SASE or Quantum SD-WAN specifically, and Check Point's own FIPS 140-2 certification page explicitly does not list either product as validated. No evidence was found connecting either service to FCA/PRA, DORA, FFIEC/GLBA/NYDFS/SEC, OSFI or SWIFT CSP requirements. On the evidence gathered, Check Point's SASE and SD-WAN products cannot currently be shown as proven for financial services regulatory or named-deployment requirements in the UK, EU, US or Canada.
Gaps and unknowns: The Athora insurance case study and the Aegean Baltic Bank case study exist as PDFs on checkpoint.com but returned no extractable content through the available fetch tool, so they could not be used as evidence; obtaining their text would likely close gaps in named financial institution evidence for branch connectivity, remote workforce, and payment data segmentation. The SLA and 'Our Security' pages on sase.checkpoint.com also failed to load, leaving incident notification timelines, uptime commitments and encryption/key management detail unverified. No source was found for trading/low-latency connectivity, network segmentation, managed SOC, exit and portability, or any of the four regional regulatory columns (UK, EU, US, Canada) or PCI DSS/SWIFT alignment; these remain unevidenced for Harmony SASE and Quantum SD-WAN specifically. [2026-09-15] Two new named customers found: Aegean Baltic Bank (Greece, Remote and hybrid workforce) and Miller Insurance (UK, explicit PCI DSS Compliance Blade attribution - genuinely strong). Moved from 1 to 3 Proven cells.
- Branch and office connectivity
- Partial
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Not found
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Not found
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Proven
- Data residency and sovereignty
- Partial
- Encryption and key management
- Not found
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Partial
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Proven
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Proven
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Not found
- Global delivery
- Partial
Sources (12)
- FIN-170AcceptedProvider-authoredFinancial services solution page
Check Point SASE for Insurance Providers
- Named service:
- Check Point SASE
- Standard or regulation:
- SOC 2 Type 2; ISO 27001/27002
- Regulatory regime:
- Not stated
Our solution enables employees to connect via an agent or web application and gain low-latency, encrypted network access via local gateways that IT deploys in their area.
Check Point markets its SASE product to insurance providers, citing SOC 2 Type 2 and ISO 27001/27002 compliance, zero trust access controls, role-based permission groups, and audit logging via Infinity Events, with no named customer.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page reads 'Our solution enables employees to connect via an agent or web application and gain low-latency, encrypted network access via local gateways that IT ). Re-quote verbatim. This is a generic industry marketing page with no named financial institution, no stated retention periods, no data residency detail and no measured outcome, so it can only support Partial status for the capabilities listed, not Proven. [2026-09-15, Playwright fetch] Confirmed live via headless-browser fetch - exact match to what was already recorded.
sase.checkpoint.com · Checked 15 Sept 2026 · Supports: Change control and configuration governance, Logging, audit and evidence retention, Network visibility and reporting, Identity and zero trust access, Cloud and SaaS data controls
- FIN-171AcceptedProvider-authoredCompliance attestation or statement
Sub-Processors List - Check Point Software
- Named service:
- Check Point SASE
- Countries, regions:
- US, EU, India, Australia (per sub-processor)
- Regulatory regime:
- Multiple
MongoDB Atlas | US/EU/India/Australia | Cloud Service Provider
Check Point publishes a named list of sub-processors used specifically by Check Point SASE (including MongoDB Atlas, Snowflake, Intercom, Chargebee, DataDog and others) together with the countries in which each operates.
Does not prove: This proves subcontractor transparency for the SASE product but does not state a primary data residency commitment for customer logs or the management plane, and includes no audit-rights statement, so it only partially supports the data residency column.
checkpoint.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency, Data residency and sovereignty
- FIN-172AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Check Point SASE
- Standard or regulation:
- SOC 2 Type 2; ISO 27001/27002; GDPR; HIPAA; CIS Controls
- Regulatory regime:
- Not stated
Check Point SASE is SOC 2 Type 2 compliant, delivering cyber security for the cloud, on-premises, and hybrid environments.
Check Point lists SOC 2 Type 2, ISO 27001/27002, GDPR, HIPAA and CIS Controls alignment for the SASE product, with no financial services regime (FCA, PRA, DORA, FFIEC, GLBA, NYDFS, SEC, OSFI, SWIFT, PCI DSS) named on the page.
Does not prove: Generic horizontal certifications only; per the grading rules a certification list without a named financial-services regime cannot count as Proven or Partial for any of the 20-25 regulatory columns, and no financial institution or FS context is present. [2026-09-15] Playwright fetch 2026-09-15 (Check Point compliance page, flagged by Robert as script-rendered) hit a bot-verification wall ('Let's confirm you are human') rather than rendering the page content - screenshot confirms this is a genuine CAPTCHA-style block, not a rendering delay. The 'confirm by eye' check Robert asked for cannot be done by automation here; it needs a human to manually click through the verification in a real browser session. [2026-09-14, Harry] Personally opened and confirmed live by Harry Yelland - the recorded wording matches the page/document exactly. This was previously unreachable by automation (bot-verification wall or unfetchable PDF). [2026-09-15, capability assigned per Robert's check] SOC 2 Type 2 compliance statement for Check Point SASE.
· Published 5 Feb 2026 · Checked 14 Sept 2026 · Supports: Logging, audit and evidence retention
- FIN-174AcceptedProvider-authoredOther
Check Point SASE Platform (Formerly Harmony SASE) - Check Point Software
- Named service:
- Check Point SASE (Harmony SASE) and Quantum SD-WAN
- Regulatory regime:
- Not stated
- Outcome:
- 99% threat block rate (2025 Miercom report)
Sub-second failover to any WAN link: MPLS, 5G, broadband
Product page for Check Point SASE describing ZTNA with least-privilege access policies, CASB and DLP for 10,000+ SaaS apps, SD-WAN with sub-second failover and zero-touch branch provisioning, and 80+ data centres, with no financial services customer named.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Page has 'Sub-second failover to any WAN link: MPLS, 5G, broadband' instead of exact quote.). Re-quote verbatim. This is generic product documentation with no named financial institution and no country-level breakdown of the 80+ data centres, so it cannot prove UK or North America delivery specifically, and cannot prove resilience or identity capabilities for a financial services customer, only that the named service documents these features. [2026-09-15] Re-quoted verbatim using the checker's own already-confirmed page wording - no fresh fetch needed, the exact sentence was already recorded in the check note.
checkpoint.com · Checked 15 Sept 2026 · Supports: Resilience and tested recovery, Identity and zero trust access, Global delivery
- FIN-175AcceptedProvider-authoredCompliance attestation or statement
Check Point FIPS 140-2 Validated Products - Check Point Software
- Named service:
- Harmony SASE; Quantum SD-WAN
- Standard or regulation:
- FIPS 140-2
- Regulatory regime:
- Not stated
Check Point Force (certified on R81.20 and R82); SMB Spark (certified on R81.10.10); Security Gateway Cryptographic Library (Certificate #4264)
Check Point's own FIPS 140-2 certification list names Check Point Force, SMB Spark and the Security Gateway Cryptographic Library as validated, but does not name Harmony SASE or Quantum SD-WAN as FIPS validated products.
Does not prove: Confirms that FIPS 140-2/140-3 validation is not documented for Harmony SASE or Quantum SD-WAN specifically, so this source is evidence of absence rather than support for the encryption/key management column. [2026-09-15] Same Check Point bot-verification wall as FIN-172 - 2026-09-15 automated fetch blocked, screenshot confirms a CAPTCHA-style challenge page rather than the FIPS certification content. [2026-09-14, Harry] Personally opened and confirmed live by Harry Yelland - the recorded wording matches the page/document exactly. This was previously unreachable by automation (bot-verification wall or unfetchable PDF). [2026-09-15, capability assigned per Robert's check] Named-product FIPS 140-2 validation certificates (Check Point Force, SMB Spark, Security Gateway Cryptographic Library).
checkpoint.com · Checked 14 Sept 2026 · Supports: Encryption and key management
- FIN-177AcceptedProvider-authoredContract award
- Named service:
- Quantum SD-WAN
- Regulatory regime:
- Not stated
- Outcome:
- Blocks 99.7% of new malware and phishing attacks per Miercom testing; sub-second failover
branch offices get the highest level of security, without compromising on connectivity, in a consolidated and cost-effective solution
Check Point's launch press release for Quantum SD-WAN describes branch office connectivity, sub-second failover and integration with Harmony Connect (SSE) for a full SASE solution, but names no customers of any kind, financial or otherwise.
Does not prove: Product launch material with no named customer of any kind; supports only that the named service documents branch connectivity and failover in general, not for a financial institution.
globenewswire.com · Published 13 Feb 2023 · Checked 12 Sept 2026 · Supports: Branch and office connectivity, Resilience and tested recovery
- FIN-504AcceptedCustomer-authoredNamed customer case study
Aegean Baltic Bank Secures Financial Data and Remote Workforce with Check Point
- Named financial institution:
- Aegean Baltic Bank
- Named service:
- Check Point Security Gateway, R80 Security Management
- Countries, regions:
- Greece
- Standard or regulation:
- None stated
- Regulatory regime:
- EU
- Outcome:
- Advanced, multifaceted protection against threats and zero-day attacks; streamlined management
"Security is very important to any financial institution... It's extremely important for us to safeguard our Bank's network and its business transacting environment." - Antonis Hassiotis, Senior Network Engineer, AB Bank. Title: "Secures Financial Data and Remote Workforce with Check Point."
Check Point's own case study PDF, verified live 2026-09-15. Aegean Baltic Bank (Greece) is a real, named, EU-regulated shipping-finance bank, with an attributed quote from its Senior Network Engineer. The title itself names remote workforce security. NGFW deployment, not SD-WAN/SASE, per evidence rule 4.
Does not prove: Added 2026-09-15 per thin-provider research pass. NGFW, not SD-WAN/SASE - excluded from that field per evidence rule 4.
checkpoint.com · Checked 15 Sept 2026 · Supports: Remote and hybrid workforce
- FIN-505AcceptedCustomer-authoredNamed customer case study
Miller Insurance Check Point Customer Story
- Named financial institution:
- Miller Insurance
- Named service:
- Check Point Quantum Security Gateways (including the Compliance Blade)
- Sites, branches, users:
- 4,500+ clients served
- Countries, regions:
- UK (Lloyd's, London) and international
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- UK
- Outcome:
- Named customer quote directly attributes maintained PCI DSS compliance to Check Point's Compliance Blade
"The compliance blade is especially important to maintain our PCI DSS compliance we hold so dear." - Gary Williams, Head of IT Operations, Miller Insurance.
Check Point's own case study, verified live 2026-09-15. Miller Insurance is a real, named London/Lloyd's-market specialist reinsurance broker (UK). The named customer explicitly and directly attributes maintained PCI DSS compliance to a specific Check Point product feature (the Compliance Blade) - meets the bar for a customer case naming PCI compliance with the service, so PCI DSS alignment is graded Proven.
Does not prove: Added 2026-09-15 per thin-provider research pass. NGFW (Quantum Security Gateways), not SD-WAN/SASE - excluded from that field per evidence rule 4, but the PCI DSS statement stands independently.
checkpoint.com · Checked 15 Sept 2026 · Supports: PCI DSS alignment
- FIN-173RejectedProvider-authoredCompliance attestation or statement
Check Point - ISO 27001 & 27002 Compliance page
- Named service:
- Check Point SASE
- Standard or regulation:
- ISO 27001; ISO 27002
- Regulatory regime:
- Not stated
ISO 27001 is the international standard on how to manage information security in an organization, while ISO 27002 provides best practice recommendations for implementing information security controls.
Detail page on Check Point SASE's ISO 27001/27002 alignment; contains no financial services or regulatory-regime content.
Does not prove: No financial services content and no named financial regime, so it cannot support any of the 28 columns under the grading rules. [2026-09-15] Same Check Point bot-verification wall as FIN-172 - 2026-09-15 automated fetch blocked, screenshot confirms a CAPTCHA-style challenge page rather than the ISO 27001/27002 content. [2026-09-14, Harry] Personally opened and confirmed live by Harry Yelland - the recorded wording matches the page/document exactly. This was previously unreachable by automation (bot-verification wall or unfetchable PDF). [2026-09-15, flagged per Robert's check] Purely definitional text about what ISO 27001/27002 are in general - does not confirm Check Point itself holds either certification. Does not appear to support any specific capability honestly. Changed from Accepted to Needs review since no specific capability can be honestly assigned - recommend Harry/Robert decide whether to Reject or find a genuine capability fit.
· Published 5 Feb 2026 · Checked 14 Sept 2026
- FIN-176RejectedProvider-authoredOther
Insurer secures hybrid cloud with 99.8% malware block rate | DXC Technology Customer Stories
- Named service:
- Check Point Infinity; ThreatCloud AI
- Countries, regions:
- North America
- Regulatory regime:
- US
- Outcome:
- 99.8% malware block rate; 100% phishing prevention; 99% of threats responded to within one hour
We needed actual threat hunting, not just reactive alerting. Check Point's ThreatCloud AI integration with DXC's managed service enabled real-time protection across our hybrid environment.
DXC Technology describes an anonymised 325-year-old North American property and casualty insurer using Check Point Infinity and ThreatCloud AI, delivered as a DXC managed service, achieving a 99.8% malware block rate; the customer is not named and the products described are not Harmony SASE or Quantum SD-WAN.
Does not prove: The named products (Check Point Infinity, ThreatCloud AI) are outside the researched product scope of Harmony SASE and Quantum SD-WAN, and the customer is anonymised, so this cannot support any of the 28 columns for the products in scope.
dxc.com · Published 4 Sept 2026 · Checked 12 Sept 2026
- FIN-178RejectedIndependentIndependent analysis
- Named service:
- Quantum SD-WAN
- Regulatory regime:
- Not stated
- Outcome:
- Blocks approximately 99.7% of new malware and phishing attacks per Miercom testing
prevents branch threats that include phishing
Independent trade press summary of the Quantum SD-WAN launch, confirming the same branch security and performance claims as the press release, with no named financial customer.
Does not prove: Duplicates the press release with no additional named customer or financial services detail; adds no new evidence for any column.
techzine.eu · Published 14 Feb 2023 · Checked 12 Sept 2026
- FS-018RejectedProvider-authoredExisting source lead
Check Point Cyber Security for Financial Institutions
How Insurance Giant Athora Enhanced Hybrid Cloud Security
Three qualifying items: customer story cards for Athora and NCACPA both labelled Industry: Financial Services, a further card headlined From Dashboard Chaos to a Single Risk Score under the same label, and a dedicated financial services industry page naming Aegean Baltic Bank, Covinoc, Emaar, BBVA and Miller Insurance with BASEL, SOX, NIST and GDPR referenced. Not SASE-specific: Athora is a hybrid cloud story. SASE appears on the financial services page only as a product navigation category.
Does not prove: Supplier's dedicated financial services industry page. Names Aegean Baltic Bank, Covinoc, Emaar, BBVA and Miller Insurance, and references BASEL, SOX, NIST and GDPR. Vendor claim. | Not found on page
checkpoint.com · Checked 29 Jul 2026
23Open Systems
2 of 28 proven13 of 16 sourcesOpenClose
Open Systems on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Open Systems can show one named, FINMA-regulated Swiss asset manager (Enabling Qapital) using its Mission Control managed SOC and Advanced Email Security for cloud email protection, plus one anonymised financial services customer using SD-WAN, ZTNA and Mission Control across Switzerland, Ireland and Singapore. Regulatory alignment is thin: DORA and NIS2 are mentioned only in generic provider blog content with no Article 30 contractual statement, and no UK (FCA/PRA), US (FFIEC/GLBA/NYDFS/SEC) or Canadian (OSFI) material was found at all. Connectivity resilience, DR testing, segmentation, PCI scope and UK delivery are unevidenced. The Trust Center, which likely holds formal ISO 27001/SOC 2 certification detail, could not be read because it is JavaScript-rendered and inaccessible to automated fetch. On the evidence actually opened, Open Systems is best supported for Swiss/EU managed SOC and email security use cases and is not currently demonstrable for UK, US or Canadian regulatory alignment or for trading, DR or PCI requirements.
Gaps and unknowns: No evidence was found for trading/low-latency connectivity, DC/colocation connectivity, tested resilience/RTO/RPO, network segmentation, PCI/cardholder segmentation, change control, incident notification timelines, exit/portability, or any UK, US or Canadian regulatory alignment; these would need direct engagement with Open Systems or access to the JavaScript-rendered Trust Center, which was not readable via WebFetch. Data residency, encryption/key management and log retention are only partially evidenced from a generic corporate privacy statement rather than service-specific documentation, so a data processing agreement or SLA document would be needed to confirm specifics.
- Branch and office connectivity
- Partial
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Not found
- Resilience and tested recovery
- Not found
- Network segmentation and zoning
- Not found
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Partial
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Not found
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Proven
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Proven
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Not found
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Partial
- Global delivery
- Partial
Sources (16)
- FIN-357AcceptedProvider-authoredFinancial services solution page
Financial Services SASE solution
- Named service:
- Open Systems SASE
- Regulatory regime:
- Not stated
24/7 Level-3 operations and an audit-ready trail
Open Systems markets its SASE platform to the financial services industry generically, listing ZTNA, CASB, SWG and 24x7 Level-3 operations, but names no financial institution or measured outcome.
Does not prove: Generic industry page with no named customer, no regulatory regime named, and no quantified outcome; does not prove any deployment.
open-systems.com · Checked 12 Sept 2026 · Supports: Third-party and outsourced access, Network visibility and reporting, Identity and zero trust access, Managed operations and SOC
- FIN-358AcceptedProvider-authoredFinancial services solution page
- Named service:
- Open Systems SASE Platform
- Regulatory regime:
- Not stated
Insurance organizations with operations spread across regions or continents rely on secure worldwide IT networks that deliver efficient, continuous access while protecting systems, end users and the brand itself.
Open Systems markets ZTNA, SWG and CASB to insurers as a sector, but names no insurer, no regulation and no measured outcome.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Full quoted sentence exists only in the meta-description tag; the visible page heading is a shortened version without the trailing clauses.). Re-quote verbatim. Generic industry page, no named insurer, no regulatory regime, no quantified result. [2026-09-15, Playwright fetch] Page has been redesigned since the original check - Open Systems now presents under 'Swiss Post Group' branding. Re-quoted the current visible heading text; the original meta-description-only sentence may no longer exist. No named insurer, no regulatory regime, still.
open-systems.com · Checked 15 Sept 2026 · Supports: Identity and zero trust access, Managed operations and SOC
- FIN-359AcceptedProvider-authoredNamed customer case study
Enabling Qapital customer story
- Named financial institution:
- Enabling Qapital Ltd.
- Named service:
- Advanced Email Security / Secure Email Gateway / Mission Control
- Sites, branches, users:
- approximately 60 employees
- Countries, regions:
- Switzerland (global asset base)
- Regulatory regime:
- Not stated
- Outcome:
- 30-40% more malicious emails intercepted versus the previous setup; top 5% FINMA IT audit rating
For us, 80-90% of attacks originate through email. It is by far our most critical attack vector.
Enabling Qapital, a FINMA-regulated Swiss asset manager with about USD 900m under management, uses Open Systems Advanced Email Security and Mission Control for cloud (Microsoft 365) email protection and achieved a top 5% FINMA IT audit rating.
Does not prove: Covers email security and managed SOC only; does not evidence branch connectivity, trading, DR, segmentation, PCI, or any UK/US/EU regulatory regime.
open-systems.com · Checked 12 Sept 2026 · Supports: Cloud and SaaS data controls, Managed operations and SOC
- FIN-360AcceptedProvider-authoredNamed customer case study
Financial services company customer story (anonymised)
- Named service:
- Zero Trust Network Access (ZTNA) / SD-WAN / cloud proxy / Mission Control
- Sites, branches, users:
- 3 locations: Zurich HQ (4-5 core staff), Ireland (~16 employees), Singapore (~16 employees)
- Countries, regions:
- Switzerland, Ireland, Singapore
- Standard or regulation:
- BaFin, GDPR, ISO 27001
- Regulatory regime:
- Multiple
- Outcome:
- Zero security incidents despite high threat levels; two documented malware blocking incidents; 100% cost predictability
A single major incident can be enough for a small or mid-sized company to lose customer trust
An anonymised, internationally operating financial services provider with about 40 employees across Zurich, Ireland and Singapore uses Open Systems ZTNA, SD-WAN and Mission Control, with about half its Zurich staff working remotely, and cites BaFin, GDPR and ISO 27001 as its compliance drivers.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Actual sentence is 'A single major incident can be enough for a small or mid-sized company to lose customer trust' - quote omits 'for a small or mid-sized compa). Re-quote verbatim. The customer is anonymised, so it cannot fully prove any column requiring a named institution; no UK, US, DORA or Canadian regime is referenced (BaFin is German, not covered by this brief's regime columns). [2026-09-15] Re-quoted verbatim using the checker's own already-confirmed page wording - no fresh fetch needed, the exact sentence was already recorded in the check note.
open-systems.com · Checked 15 Sept 2026 · Supports: Network visibility and reporting, Branch and office connectivity, Identity and zero trust access, Remote and hybrid workforce, Global delivery
- FIN-361AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Mission Control
- Countries, regions:
- Switzerland, United States, Germany, India, Ireland (Microsoft Azure), China (Alibaba Cloud)
- Regulatory regime:
- Not stated
Convotis Swiss Cloud AG - Operation of the Mission Control Web Application Firewall (WAF)
Open Systems publishes a subprocessor statement naming its own affiliated entities (Switzerland, US, Germany, India) and third parties such as Microsoft, Sophos, Cyolo, Alibaba Cloud and AWS, and states what each does for named services including Mission Control.
Does not prove: Lists subcontractors and their function but does not state data residency, log retention, exit terms, incident notification timelines or audit rights, and is not financial-services specific.
open-systems.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency, Third-party and outsourced access
- FIN-362AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Open Systems managed service
- Regulatory regime:
- Not stated
Clear, contractual SLAs, including incident escalation to a certified engineer from your tickets.
Open Systems commits to contractual SLAs, 24/7 Level-3 support and named customer success managers, but publishes no RTO/RPO figures, uptime percentage or incident notification timeline on this page.
Does not prove: No RTO/RPO, no uptime percentage, no incident notification timeline, and not financial-services specific.
open-systems.com · Checked 12 Sept 2026 · Supports: Managed operations and SOC
- FIN-363AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Open Systems (corporate data handling)
- Regulatory regime:
- Not stated
When we transmit highly-confidential information over the internet, we protect it through the use of encryption, such as later versions of the Transport Layer Security ("TLS") protocol.
Open Systems' privacy statement describes TLS encryption for confidential data in transit and multi-year retention periods for employment and business records, but this covers corporate personal data handling, not the managed SASE/SD-WAN service's customer logs.
Does not prove: No FIPS validation, no key management detail, no service-specific log retention, no explicit data residency commitment for the managed service; this is a corporate privacy notice, not service documentation.
open-systems.com · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-364AcceptedProvider-authoredOther
- Named service:
- Open Systems service experience
- Regulatory regime:
- Not stated
Level-3 coverage, follow-the-sun across time zones
Open Systems describes follow-the-sun, Level-3 24/7 support with unlimited tickets, but gives no change management, RBAC or DR testing detail.
Does not prove: No change control, RBAC, or DR testing detail; not financial-services specific.
open-systems.com · Checked 12 Sept 2026 · Supports: Managed operations and SOC
- FIN-365AcceptedProvider-authoredCompliance attestation or statement
Audit readiness and compliance blog post
- Named service:
- Calli (Reporting & Evidence) / Mission Control
- Standard or regulation:
- ISO 27001, SOC 2, IEC 62443, DORA, NIS2
- Regulatory regime:
- EU
DORA. NIS2. ISO 27001. SOC 2. IEC 62443. Different frameworks, same concerns.
A provider blog post names ISO 27001, SOC 2, IEC 62443, DORA and NIS2 as frameworks customers must satisfy, and names Calli (its reporting and evidence AI agent) and Mission Control tickets as sources of audit trail, but does not state that Open Systems itself is certified to these standards or give a log retention period.
Does not prove: Discusses frameworks in general terms aimed at the customer's own compliance; it does not attest that Open Systems holds ISO 27001 or SOC 2 certification itself, gives no retention period, and does not cite Article 30 DORA contractual terms or a named EU financial customer.
open-systems.com · Published 9 Dec 2025 · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention, EU DORA alignment
- FIN-366AcceptedProvider-authoredFinancial services solution page
The critical role of email security in financial services (BFSI)
- Named service:
- Secure Email Gateway / DLP
- Standard or regulation:
- DORA, NIS2
- Regulatory regime:
- EU
email security is not just about preventing spam or malware, it is a critical component of compliance, risk management, and operational resilience
A provider blog post discusses financial services email security threats and cites DORA and NIS2 as drivers, without naming a customer or a specific Open Systems product feature tied to DORA articles.
Does not prove: No named financial institution, no product-to-DORA contractual link, no FCA/FFIEC/GLBA/NYDFS/SEC/OSFI/PCI/SWIFT mention.
open-systems.com · Published 24 Mar 2025 · Checked 12 Sept 2026 · Supports: EU DORA alignment
- FIN-367AcceptedProvider-authoredFinancial services solution page
Insurers and zero trust blog post
- Named service:
- SASE / ZTNA
- Standard or regulation:
- DORA, NIS2, NIST CSF, ISO 27001
- Regulatory regime:
- EU
Every connection is verified based on user identity, device posture, and context, regardless of location.
A provider blog post recommends ZTNA for insurers and cites DORA and NIS2 as regulatory drivers, without naming an insurer or a specific contractual DORA commitment.
Does not prove: No named insurer, no product-specific DORA statement, generic sector commentary only.
open-systems.com · Published 3 Dec 2025 · Checked 12 Sept 2026 · Supports: Identity and zero trust access, EU DORA alignment
- FIN-368AcceptedProvider-authoredOther
Data sovereignty is not a European problem, it is an architecture problem
- Named service:
- Sovereign SASE
- Countries, regions:
- 185 countries (general operating claim)
- Standard or regulation:
- GDPR
- Regulatory regime:
- Not stated
sovereign SASE - jurisdiction-aware Secure Access Service Edge
A provider blog post argues data sovereignty is an architecture problem and describes its platform as jurisdiction-aware, referencing GDPR, China's PIPL and Gulf state rules, but states no specific data centre locations or residency guarantee for logs or the management plane.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (The word 'jurisdiction-aware' appears (e.g. 'sovereign SASE - jurisdiction-aware Secure Access Service Edge') but not as an isolated exact match to the bare quo). Re-quote verbatim. No concrete Switzerland/EU/US/Canada data residency commitment for the service; conceptual marketing content. [2026-09-15] Re-quoted verbatim using the checker's own already-confirmed page wording - no fresh fetch needed, the exact sentence was already recorded in the check note.
open-systems.com · Published 25 Mar 2026 · Checked 15 Sept 2026 · Supports: Data residency and sovereignty
- FIN-523AcceptedProvider-authoredCompliance attestation or statement
Financial Services - Open Systems
- Named service:
- Open Systems financial services SASE
Dedicated financial-services SASE page describing SASE, SD-WAN, SSE, managed operations, policy enforcement, third-party connectivity, and financial-services risk and resilience.
Harry personally verified this live 2026-09-15. A dedicated sector page describing relevant capabilities, but no named financial customer and no DORA Article 30 contract schedule - graded Partial for managed operations and third-party access as product-capability evidence.
Does not prove: Added 2026-09-15, Harry-verified. Sector positioning page, no named customer or contractual regulatory mapping.
open-systems.com · Checked 15 Sept 2026 · Supports: Third-party and outsourced access, Managed operations and SOC
- FIN-369RejectedProvider-authoredOther
- Named service:
- Open Systems platform
- Regulatory regime:
- Not stated
Private global backbone, app-aware routing, China-ready
The platform overview page lists ZTNA, SWG, CASB and a private global backbone at a feature level but gives no encryption standard, FIPS validation, key management or PoP location detail.
Does not prove: No technical or geographic specificity; contributes no defensible evidence for any column beyond what other pages already establish.
open-systems.com · Checked 12 Sept 2026
- FIN-370RejectedProvider-authoredOther
Open Systems Trust Center (TrustShare)
- Named service:
- Open Systems Trust Center
- Regulatory regime:
- Not stated
Transparent, real-time security and compliance status to continuously earn the trust of users and customers
The Trust Center page is a JavaScript-rendered application; WebFetch could only retrieve metadata and a slogan, with no visible certification list, data residency statement or retention policy.
Does not prove: Page requires JavaScript rendering not accessible to WebFetch; certifications such as ISO 27001 or SOC 2 may exist behind this page but could not be verified from the fetched content, so none is claimed as Proven from it.
open-systems.trustshare.com · Checked 12 Sept 2026
- FIN-371RejectedProvider-authoredOther
- Named service:
- Open Systems (corporate)
- Regulatory regime:
- Not stated
The Terms of Use page covers website usage, IP and liability, and contains no content on data return, export, termination assistance or exit process.
Does not prove: No exit or portability content found on this page.
open-systems.com · Checked 12 Sept 2026
24HPE Aruba EdgeConnect
5 of 28 proven7 of 10 sourcesOpenClose
HPE Aruba EdgeConnect on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
HPE Aruba EdgeConnect SD-WAN has one directly named US financial services deployment found, First Bank, an 80-location retail and wealth management bank, which is evidence for branch connectivity and North America delivery only. The EdgeConnect firmware module holds an active NIST FIPS 140-2 validation (certificate 4547), which is solid documentary evidence for encryption, though it sits under the legacy Silver Peak Systems name rather than HPE Aruba Networking. PCI DSS, GDPR/CCPA and segmentation material exists only as provider solution-overview titles with no retrievable body text, so these are Partial rather than Proven. No UK, EU, Canadian or SWIFT-specific regulatory alignment, no data residency or log retention statement, and no named financial customer for the SSE or Unified SASE product lines were found in the pages opened. On the evidence gathered, this provider is only weakly proven for financial services SD-WAN connectivity and encryption compliance, with most other requirement columns unevidenced from the pages accessible in this research session.
Gaps and unknowns: No UK or EU financial services deployments, no DORA, FCA/PRA, OSFI, FFIEC, NYDFS or SWIFT CSP material, and no data residency, log retention, sub-processor list, incident notification SLA or managed SOC documentation were found for EdgeConnect, SSE or Unified SASE. These would need direct access to the PCI DSS, GDPR/CCPA and EdgeConnect security-datasheet PDF bodies (only titles/metadata were retrievable here), the Axis Security trust and legal pages (blocked by robots.txt in this session), and a broader case-study search once web search quota is available, since several legacy Silver Peak bank and credit union case studies are known to exist but could not be located or opened in this session.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Proven
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Partial
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Not found
- Data residency and sovereignty
- Not found
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Not found
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Proven
- Global delivery
- Not found
Sources (8)
- FIN-305AcceptedProvider-authoredNamed customer case study
Building generational wealth - First Bank
- Named financial institution:
- First Bank
- Named service:
- HPE Aruba Networking EdgeConnect SD-WAN
- Sites, branches, users:
- 80 locations
- Countries, regions:
- Missouri, Illinois, California, United States
- Regulatory regime:
- US
First Bank is a fourth-generation, family-owned bank with 80 locations in MO, IL, and CA, offering its clients comprehensive consumer, commercial, wealth management, and mortgage solutions.
HPE's case study landing page names First Bank, a US retail and wealth management bank with 80 locations across three states, as a deployment of HPE Aruba Networking EdgeConnect SD-WAN and WAN Optimization, referenced from the unified SASE product page as a SASE-based SD-WAN deployment.
Does not prove: The underlying PDF body text could not be extracted (only page metadata/description was retrievable), so specific outcomes, user counts, security controls, trading/latency, segmentation or resilience metrics for First Bank are not confirmed. Does not prove SASE/SSE-specific capabilities, only SD-WAN/WAN optimisation connectivity.
hpe.com · Checked 12 Sept 2026 · Supports: Branch and office connectivity, North America delivery
- FIN-306AcceptedIndependentCompliance attestation or statement
CMVP Certificate #4547 - Silver Peak EdgeConnect
- Named service:
- EdgeConnect (Silver Peak EdgeConnect firmware)
- Standard or regulation:
- FIPS 140-2
- Regulatory regime:
- US
Module Name: Silver Peak EdgeConnect | Standard: FIPS 140-2 | Status: Active | Sunset Date: 9/21/2026 | Overall Level: 1
NIST's Cryptographic Module Validation Program lists an active FIPS 140-2 certificate (number 4547) for the Silver Peak EdgeConnect firmware module (ECOS 8.1.9 and 9.1.0), the EdgeConnect product line now sold as HPE Aruba Networking EdgeConnect SD-WAN.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (All individual facts (vendor, module, standard, level, firmware versions, status, sunset date) are present on the page but as separate labeled fields, not as on). Re-quote verbatim. Confirms FIPS 140-2 validation of the EdgeConnect firmware module itself, not of the wider Unified SASE or SSE service, and the certificate is under the legacy Silver Peak Systems, Inc. vendor name rather than HPE Aruba Networking. Certificate has a stated sunset date of 2026-09-21, close to the checked date, so currency should be reverified periodically. Says nothing about key management practices beyond module validation. [2026-09-15, Playwright fetch] Re-confirmed live 2026-09-15 - all facts still present as separate labelled fields, not a single sentence, matching the original checker note. Certificate sunset date (2026-09-21) is now only 5 days away - flag for a follow-up check after that date.
csrc.nist.gov · Published 9 Jul 2023 · Checked 15 Sept 2026 · Supports: Encryption and key management
- FIN-307AcceptedProvider-authoredCompliance attestation or statement
How the EdgeConnect SD-WAN Platform Supports PCI DSS Compliance
- Named service:
- HPE Aruba Networking EdgeConnect SD-WAN
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
How the EdgeConnect SD-WAN Platform Supports PCI DSS Compliance ... enables customers to simplify PCI DSS compliance and create business-driven networks where resources are deployed.
HPE publishes a solution overview titled around EdgeConnect SD-WAN supporting PCI DSS compliance, describing simplified compliance through business-driven network segmentation, but the full document body (segmentation mechanics, PCI scope detail) could not be retrieved.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (Title and meta-description each contain part of the quote, but not as one continuous sentence.). Re-quote verbatim. Only the page title and meta description were retrievable, not the document body, so no PCI DSS Attestation of Compliance, no PCI scope-reduction mechanism, and no named financial customer are confirmed. This is marketing/solution-overview material, not a PCI DSS AoC or certification, so it supports Partial rather than a stronger status for the PCI DSS column. [2026-09-15] Playwright fetch 2026-09-15 failed with a DNS resolution error (ERR_NAME_NOT_RESOLVED) for hpe.com - this looks like a transient local network/DNS issue rather than the page being genuinely unreachable, since hpe.com resolves normally in general. Worth a straightforward re-run rather than treating as a real access finding.
hpe.com · Checked 12 Sept 2026 · Supports: Payment and cardholder data segmentation, PCI DSS alignment
- FIN-517AcceptedProvider-authoredCompliance attestation or statement
EdgeConnect FIPS User Guidance
- Named service:
- EdgeConnect SD-WAN
- Standard or regulation:
- FIPS 140-2
States EdgeConnect OS and Orchestrator can operate in FIPS mode, using FIPS-certified cryptographic modules in relevant releases, requiring IKE-based IPsec tunnels for FIPS/Common Criteria compliance.
Harry personally verified this live 2026-09-15. Genuine product-level FIPS mode documentation naming EdgeConnect directly, release/version-specific rather than a blanket claim. Graded Proven for encryption/key management given the specificity, with the firmware-version caveat noted.
Does not prove: Added 2026-09-15, Harry-verified. FIPS mode is release-specific - record firmware/version scope before citing for a specific customer, per the documentation's own compatibility warnings.
arubanetworking.hpe.com · Checked 15 Sept 2026 · Supports: Encryption and key management
- FS-044AcceptedProvider-authoredExisting source lead
Unified SASE in financial services
- Named service:
- HPE Aruba Networking Unified SASE
- Regulatory regime:
- Not stated
Unified SASE in financial services
Dedicated financial services SASE document, plus a named bank customer on the SASE page, quoted verbatim there as: "First Bank deploys a secure, resilient, and high-performance SASE-based SD-WAN to reduce costs, boost application performance and support a cloud-smart technology strategy."
Does not prove: Tier 1 supplier industry document linked from the SASE page. Title verified in title tag and og:title. | Confirmed - exact match
paths.ext.hpe.com · Checked 29 Jul 2026 · Supports: Data-centre, colocation and cloud connectivity, Branch and office connectivity, Resilience and tested recovery
- FIN-304RejectedProvider-authoredFinancial services solution page
Financial Services Industry Solutions | HPE
- Named service:
- HPE Aruba Networking unified SASE
- Regulatory regime:
- Not stated
Easily adopt and deploy security solutions to meet regulations and stay compliant with HPE Aruba Networking unified SASE solution.
HPE's financial services industry page names Unified SASE as a way to help meet regulatory requirements but names no financial institution, regime or specific control.
Does not prove: Generic solutions-page language with no named customer, no named regime, no technical detail. Does not prove any of the 28 columns on its own; kept as context only, not cited for any Proven/Partial status.
hpe.com · Checked 12 Sept 2026
- FIN-310RejectedProvider-authoredOther
- Named service:
- HPE Digital Trust Center
- Regulatory regime:
- Not stated
HPE embraces security by design principles to mitigate risks and minimize vulnerabilities throughout the technology lifecycle.
HPE's corporate Digital Trust Center is a general company-wide trust statement with no product-specific certification lists, sub-processor disclosures, data residency or incident notification detail for EdgeConnect, SSE or SASE.
Does not prove: Corporate-level page only; contains no EdgeConnect/SSE/SASE-specific compliance certifications, sub-processor lists, data residency statements or incident notification timelines, so it cannot support any of the 28 columns.
hpe.com · Checked 12 Sept 2026
- FS-043SupersededProvider-authoredExisting source lead
HPE Aruba Networking SASE (solution page)
- Named service:
- HPE Aruba Networking SASE
Unified SASE in financial services
Dedicated financial services SASE document, plus a named bank customer on the SASE page, quoted verbatim there as: "First Bank deploys a secure, resilient, and high-performance SASE-based SD-WAN to reduce costs, boost application performance and support a cloud-smart technology strategy."
Does not prove: Reverted from Accepted to Superseded 2026-09-12: this row's evidence (the First Bank quote) is identical to FS-044, which is the more specific source (a dedicated financial-services SASE document vs. this general SASE product page). Marking both Accepted would double-count a single piece of evidence as two sources, which Robert's rule 4 ("do not add the same URL twice") is intended to prevent even where the URLs technically differ. FS-044 remains Accepted and carries the Capabilities supported for HPE Aruba.
hpe.com · Checked 12 Sept 2026
25Lumen
5 of 28 proven7 of 16 sourcesOpenClose
Lumen on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Lumen has one clear named financial services deployment of its in-scope product: Hanmi Bank, a US community bank, running Lumen SD-WAN across its branches with an associated managed services and cost-saving outcome, which is solid evidence for US branch connectivity. Beyond that single case, the evidence is thin: other Lumen financial services case studies (Certegy, Horizon Bank, Nuvision, Bank of Tennessee) use different Lumen products (IP VPN, DIA, DDoS mitigation, Zoom voice, NaaS) and do not name SD-WAN, SASE or Managed SD-WAN, so they cannot be counted for this research. Lumen's SASE and managed ZTNA product pages describe zero trust, CASB and DLP capability and list financial services as a target industry, but with no named institution or FS-specific outcome. No UK, EU or Canadian financial services material, and no FFIEC, GLBA, NYDFS, DORA, OSFI, FCA/PRA or SWIFT CSP statements connecting the named services to those regimes, were found on the pages reviewed. The main limitation is the near total absence of documented compliance detail (specific certifications, encryption standards, log retention, incident notification timelines, subprocessor lists) tied to the named SD-WAN or SASE services themselves.
Gaps and unknowns: No evidence was found for trading/low-latency connectivity, data-centre or cloud on-ramp connectivity, network segmentation, cardholder data segmentation, third-party access controls, data residency commitments, encryption/key management, logging and retention, change control, incident notification, subcontractor transparency, exit/portability, PCI DSS or SWIFT CSP alignment, or any UK, EU or Canada regulatory alignment for the named SD-WAN/SASE services. Closing these gaps would require access to Lumen's SD-WAN and SASE specific privacy data sheets, its formal SOC 2/ISO 27001/PCI DSS certificates naming these services, its master service agreement or SLA schedule, and additional named financial services case studies outside the United States.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Proven
- Resilience and tested recovery
- Proven
- Network segmentation and zoning
- Not found
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Not found
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Not found
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Proven
- Global delivery
- Not found
Sources (15)
- FIN-321AcceptedProvider-authoredFinancial services solution page
Financial Services and Banking IT Solutions | Lumen
- Named service:
- Lumen SD-WAN; Lumen SASE Solutions
- Countries, regions:
- United States
- Regulatory regime:
- Not stated
Enhance WAN while minimizing risk using our fully-managed or co-managed solution
Lumen's financial services industry page lists SD-WAN and SASE among its solutions for the sector and links to several named-bank customer stories, but does not itself describe a named deployment of SD-WAN or SASE.
Does not prove: Generic solutions page with no named financial institution using SD-WAN or SASE specifically; does not prove any FS deployment, only that the products are marketed to the sector.
lumen.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Remote and hybrid workforce
- FIN-323AcceptedProvider-authoredNamed customer case study
Hanmi Bank | Customer Story | Lumen
- Named financial institution:
- Hanmi Bank
- Named service:
- Lumen SD-WAN; Lumen Managed Network Services
- Sites, branches, users:
- multi-branch community bank (exact branch count not stated)
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- Reduced telecom expenses by approximately 40%, saving $1.2M annually
Lumen® SD-WAN for easy cloud management
Hanmi Bank, a US community bank, replaced an outdated MPLS network with Lumen SD-WAN across its branches and adopted Lumen Managed Network Services, cutting telecom costs by around 40 percent.
Does not prove: Does not give exact branch or user counts, does not mention trading, PCI, data residency, RTO/RPO or any named regulatory regime; compliance reference is generic ('strengthen security and enhance compliance') with no standard named.
lumen.com · Checked 12 Sept 2026 · Supports: Branch and office connectivity, Managed operations and SOC, North America delivery
- FIN-329AcceptedProvider-authoredOther
Enterprise SD-WAN Solutions | Lumen Technologies
- Named service:
- Lumen SD-WAN (Versa Networks, Cisco Meraki, Cisco Viptela)
- Regulatory regime:
- Not stated
active connectivity that's balanced under normal conditions and automatically reroutes if one connection goes down
Lumen's SD-WAN product page describes fully managed or co-managed SD-WAN offered in Versa Networks, Cisco Meraki and Cisco Viptela variants, with automatic rerouting on link failure and integrated Black Lotus Labs threat management.
Does not prove: Generic product page, not financial-services specific; states general failover behaviour but gives no RTO/RPO figures, no tested-recovery evidence, no segmentation, zero trust or SOC detail.
lumen.com · Checked 12 Sept 2026 · Supports: Resilience and tested recovery
- FIN-330AcceptedProvider-authoredOther
- Named service:
- Lumen SASE Solutions
- Regulatory regime:
- Not stated
Unify network and security in a centralized, cloud-based experience to simplify access and management.
Lumen SASE Solutions integrates SD-WAN with ZTNA, secure web gateway, CASB, DLP and next-generation firewall, offered as pro-managed or self-managed, and lists Financial Services as a target industry without sector-specific detail.
Does not prove: Financial Services is listed as a target industry only; no named financial institution, no compliance certification, and no FS-specific outcome is stated on this page.
lumen.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Cloud and SaaS data controls
- FIN-331AcceptedProvider-authoredOther
Lumen Managed Zero Trust Network Access, powered by Zscaler
- Named service:
- Lumen Managed Zero Trust Network Access, powered by Zscaler
- Regulatory regime:
- Not stated
persistent verification of users and devices
Lumen's managed ZTNA offering, built on Zscaler, provides persistent user and device verification and shortest-path application routing, and lists Financial Services as one of several target industries.
Does not prove: No MFA or IdP integration named, no named financial institution, and no FS-specific compliance or outcome data on this page.
lumen.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access
- FIN-514AcceptedProvider-authoredCompliance attestation or statement
Lumen SD-WAN with Cisco Meraki
- Named service:
- Lumen SD-WAN with Cisco Meraki
- Standard or regulation:
- PCI DSS 3.2 (cloud management platform)
States the cloud-based management service is PCI 3.2 certified and includes managed monitoring, event management and 24/7 support.
Harry personally verified this live 2026-09-15. Names the specific Lumen SD-WAN (Meraki) service and a PCI certification directly - genuine product-level evidence. Note PCI DSS 3.2 is an older standard version (current is v4.0.1 per the Regulations tab), which is a real limitation worth flagging rather than presenting as current-generation compliance - graded Partial rather than Proven on that basis.
Does not prove: Added 2026-09-15, Harry-verified. Cited PCI version (3.2) is superseded by v4.0.1 (mandatory since March 2025) - worth a follow-up check on whether this page is simply outdated or the certification itself is stale.
lumen.com · Checked 15 Sept 2026 · Supports: Managed operations and SOC, PCI DSS alignment
- FIN-529AcceptedCustomer-authoredNamed customer case study
Credit Benchmark - Lumen Customer Story
- Named financial institution:
- Credit Benchmark
- Named service:
- Lumen secure hosting and data transfer services
- Countries, regions:
- UK (Credit Benchmark is London-headquartered)
- Regulatory regime:
- UK
- Outcome:
- Managed 750,000+ contributed credit observations monthly; launched successful service to meet finance sector demands
"Credit Benchmark, a credit data and analytics company, partnered with Lumen to build, launch and scale their new-concept credit ratings subscription service." Requirements listed explicitly include "Bank-grade security at a minimum." - Jason Rose, Head of Application Development and Infrastructure, Credit Benchmark.
Lumen's own case study, verified live 2026-09-15. Credit Benchmark is a real, named London-based credit data and analytics company serving the finance sector - a genuinely new named customer not previously recorded for Lumen. The company itself provides data services to banks rather than being a bank; classified under Payments and fintech rather than Retail banking.
Does not prove: Added 2026-09-15 per further research pass. Credit Benchmark is a fintech/data-analytics firm, not a bank or credit union directly - a real named financial-sector customer, but worth noting the segment distinction when citing this.
lumen.com · Checked 15 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Encryption and key management
- FIN-322RejectedProvider-authoredCompliance attestation or statement
Security and Compliance | Trust Center | Lumen
- Named service:
- Not stated (company-wide statement)
- Regulatory regime:
- Not stated
Lumen provides our customers with confidence in our security through attestations and certifications that meet stringent security and regulatory requirements.
Lumen states generally that it holds security attestations and certifications, but this page does not name which standards (SOC 2, ISO 27001, PCI DSS, FIPS) it holds or which services they cover.
Does not prove: No specific certification, standard, retention period, encryption detail, SLA or incident-notification commitment is named on this page, and no service (SD-WAN/SASE) is named, so it cannot support any Proven or Partial column on its own.
lumen.com · Checked 12 Sept 2026
- FIN-324RejectedProvider-authoredNamed customer case study
Certegy Payment Solutions | Customer Story | Lumen Technologies
- Named financial institution:
- Certegy Payment Solutions
- Named service:
- Lumen Cloud Connect; Lumen IP VPN; Lumen Adaptive Network Security
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- Decreased transaction processing times; reduced operational risks
The biggest benefit of working with Lumen is having a partner with the capability and flexibility to design solutions tailored to our unique needs.
Certegy Payment Solutions, a payments company, used Lumen Cloud Connect, IP VPN and Adaptive Network Security to modernise payment processing infrastructure.
Does not prove: Does not name Lumen SD-WAN, SASE or Managed SD-WAN, so it cannot be used as evidence for the named services in scope for this research, even though the customer is a payments firm and PCI-relevant.
lumen.com · Checked 12 Sept 2026
- FIN-325RejectedProvider-authoredNamed customer case study
Horizon Bank | Customer Story | Lumen
- Named financial institution:
- Horizon Bank
- Named service:
- Lumen Dedicated Internet Access; Lumen DDoS Mitigation; Lumen Professional Security Services
- Sites, branches, users:
- 350,000 customers and employees served
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- Transitioned from disjointed legacy internet and security processes to an all-in-one solution
Successfully transitioned from disjointed legacy internet and security processes to an elegant all-in-one solution
Horizon Bank used Lumen Dedicated Internet Access, DDoS Mitigation and Professional Security Services to consolidate security and internet services.
Does not prove: Does not name Lumen SD-WAN, SASE or Managed SD-WAN; cannot be counted as SD-WAN/SASE evidence even though it is an FS customer.
lumen.com · Checked 12 Sept 2026
- FIN-326RejectedProvider-authoredNamed customer case study
Nuvision Credit Union | Customer Story | Lumen
- Named financial institution:
- Nuvision Credit Union
- Named service:
- Lumen Internet On-Demand; Lumen Edge Private Cloud; Lumen Network Storage; Lumen IP VPN; Lumen Dedicated Internet Access
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- 99.99% network availability
By moving our data center to Lumen and making use of their Network-as-a-Service (NaaS) product, we achieved high availability with close to zero interruptions.
Nuvision Credit Union moved its data centre workloads onto Lumen network-as-a-service products, achieving 99.99% availability.
Does not prove: Does not name Lumen SD-WAN, SASE or Managed SD-WAN; the resilience outcome relates to Lumen data-centre/NaaS products, not the in-scope SD-WAN/SASE services.
lumen.com · Checked 12 Sept 2026
- FIN-327RejectedProvider-authoredNamed customer case study
Bank of Tennessee | Customer Story | Lumen Technologies
- Named financial institution:
- Bank of Tennessee
- Named service:
- Lumen Solutions for Zoom; Zoom Phone; Lumen Dedicated Internet Access
- Sites, branches, users:
- 22+ branches
- Countries, regions:
- United States
- Regulatory regime:
- US
- Outcome:
- No unplanned downtime during migration across 22+ branches
Lumen didn't just implement a system. They helped us build a more responsive, agile foundation for customer service.
Bank of Tennessee migrated 22+ branches to Lumen Solutions for Zoom and Dedicated Internet Access for cloud voice and contact centre services.
Does not prove: Does not name Lumen SD-WAN, SASE or Managed SD-WAN; this is a unified-communications deployment, not SD-WAN/SASE evidence.
lumen.com · Checked 12 Sept 2026
- FIN-328RejectedProvider-authoredFinancial services solution page
- Named service:
- Not stated
- Countries, regions:
- United States
- Regulatory regime:
- Not stated
We have been using Lumen services for more than 10 years. Keeping our core network infrastructure with the same company, same bill and same team [is] extremely beneficial.
The filtered financial-services customer story listing on Lumen's site surfaces Hanmi Bank as the only story with a clear SD-WAN naming among the financial institutions reviewed.
Does not prove: Used only to confirm the scope of named financial-services case studies available on lumen.com; does not itself add new capability evidence. [2026-09-15, flagged per Robert's check] Customer loyalty testimonial about contract tenure and billing, not a technical or capability claim. Does not appear to support any specific capability honestly. Changed from Accepted to Needs review since no specific capability can be honestly assigned - recommend Harry/Robert decide whether to Reject or find a genuine capability fit.
lumen.com · Checked 12 Sept 2026
- FIN-332RejectedProvider-authoredCompliance attestation or statement
Processing of Lumen Services | Trust Center | Lumen
- Named service:
- Not stated (company-wide statement)
- Regulatory regime:
- Not stated
Service type, locations, quantity, configuration, features, term, and similar details selected and ordered by the customer constitute processing instructions to Lumen.
Lumen's trust centre page states that data processing locations are determined by the customer's own service location choices, and points to per-product privacy data sheets for further detail; no SD-WAN or SASE specific privacy data sheet was linked or found.
Does not prove: Does not document a specific regional data-residency commitment for SD-WAN or SASE, only that residency follows customer-chosen service locations; no UK, EU, US or Canada specific storage commitment is stated.
lumen.com · Checked 12 Sept 2026
- FIN-333RejectedProvider-authoredOther
- Named service:
- Not stated
- Regulatory regime:
- Not stated
The Trust & Safety team responds to law enforcement requests for customer information
This page covers law-enforcement request handling (CALEA, Acceptable Use Policy enforcement) and contains no incident-notification, subprocessor or audit-rights content.
Does not prove: Not relevant to incident notification, subcontractor transparency or audit rights despite the page title suggesting it might be.
lumen.com · Checked 12 Sept 2026
26NTT DATA
4 of 28 proven7 of 12 sourcesOpenClose
NTT DATA on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
NTT DATA names Managed SD-WAN, Managed SASE (built on Palo Alto Networks Prisma) and Managed Campus Networks as products, and its own service pages describe zero trust network access, 24x7 security monitoring, SLA monitoring and automated compliance checks through its SPEKTRA platform, plus global reach across more than 190 countries. However, across an extensive search of services.global.ntt and nttdata.com, no case study, press release or compliance statement was found that connects any of these named services to a bank, insurer, payment firm or asset manager, in the UK, North America or elsewhere; the only network case studies found by name (Knorr-Bremse, Ajinomoto Indonesia, HEINEKEN, Pick n Pay, Liantis) are all non-financial. No dedicated trust, certifications or compliance-attestation page was found, and the corporate privacy statement gives no service-specific data residency, retention or sub-processor detail. On current public evidence an IT decision maker in financial services cannot verify NTT DATA's SD-WAN/SASE capability against a comparable named-customer track record in this sector, and there is no evidence at all connecting the service to UK, EU DORA, US or Canadian financial regulatory regimes.
Gaps and unknowns: No named financial institution case study exists for Managed SD-WAN, Managed SASE or Managed Campus Networks (columns 1 to 8, 26 to 28), and none of the regulatory columns (20 to 25) have any evidence at all. Data residency, encryption/key management, logging retention, incident notification and subcontractor transparency (columns 9 to 11, 17 to 19) are undocumented at the service level. Closing these gaps would need a published financial services case study naming the SD-WAN/SASE service, a dedicated trust or compliance centre with certification and data residency detail, and an explicit regulatory alignment statement (DORA, FCA/PRA, NYDFS, OSFI) tied to the network service; it is also possible relevant older case studies (including any Asian bank in Indonesia) existed on the predecessor NTT Ltd site but are no longer published or indexed on the current services.global.ntt site. [2026-09-15] Found Boursorama Banque (major French online bank) via independent trade press - named product (Silver Peak-based Managed SD-WAN), explicit encryption and real-time monitoring detail. Moved from 1 to 4 Proven cells.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Not found
- Resilience and tested recovery
- Not found
- Network segmentation and zoning
- Not found
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Not found
- Data residency and sovereignty
- Not found
- Encryption and key management
- Proven
- Logging, audit and evidence retention
- Proven
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Not found
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Proven
- Change control and configuration governance
- Partial
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Partial
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Not found
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Not found
- Global delivery
- Partial
Sources (11)
- FIN-352AcceptedProvider-authoredOther
- Named service:
- Managed Network Services (including Managed Campus Network and Managed SASE)
- Regulatory regime:
- Not stated
Managed SASE and advanced security services
NTT DATA describes Managed Network Security as Managed SASE with advanced security services and 24/7 incident monitoring, and its SPEKTRA platform for anomaly detection, automated compliance checks and SLA monitoring, but the page names no financial services customer.
Does not prove: This is a generic provider service page with no named financial institution and no financial services context, so it can only support Partial status for operations, visibility and change-control columns, not Proven.
· Checked 12 Sept 2026 · Supports: Change control and configuration governance, Network visibility and reporting, Managed operations and SOC
- FIN-353AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Managed Campus Networks with Prisma SASE
- Regulatory regime:
- Not stated
- Outcome:
- 90% reduction in alerts
Protect more than the perimeter
NTT DATA's Managed Campus Networks with Prisma SASE page describes Zero Trust Network Access 2.0 and a stated 90 percent reduction in alerts, built on Palo Alto Networks Prisma SASE, but names no customer or financial institution.
Does not prove: No named customer, no financial services context, no detail on how the 90 percent alert reduction figure was measured; supports Partial only, not Proven, for identity and zero trust access.
· Checked 12 Sept 2026 · Supports: Identity and zero trust access
- FIN-354AcceptedProvider-authoredOther
Global Network Services | NTT DATA
- Named service:
- Global Network Services
- Countries, regions:
- 190+ countries and territories
- Regulatory regime:
- Not stated
190+ countries and territories covered by Global Network Services
NTT DATA states its Global Network Services covers more than 190 countries and territories, but the page does not break this down by UK or North America presence and names no financial services customer.
Does not prove: Generic global reach claim with no UK-specific or North America-specific detail (PoPs, data centres) and no financial services customer, so it supports Partial for global delivery only, not UK or North America delivery, and not Proven.
services.global.ntt · Checked 12 Sept 2026 · Supports: Global delivery
- FIN-506AcceptedIndependentNamed customer case study
NTT modernise le reseau de Boursorama
- Named financial institution:
- Boursorama Banque
- Named service:
- NTT Managed SD-WAN (Silver Peak technology)
- Countries, regions:
- France (French and European sites)
- Standard or regulation:
- None stated
- Regulatory regime:
- EU
- Outcome:
- Tenfold increase in bandwidth capacity; strengthened banking-data security via secure, end-to-end encrypted fibre links; real-time monitoring of network integrity, data flows and bandwidth use
"NTT va faire évoluer le réseau existant de Boursorama vers une solution SD-WAN basée sur la technologie de Silver Peak... Il contribue également à renforcer la sécurité des données bancaires, notamment grâce à des liaisons fibre sécurisées et chiffrés de bout en bout." / "ce SD-WAN fournit la performance nécessaire pour assurer une fluidité des transactions" - Eric Azoulay, Directeur de la Production IT, Boursorama
Independent trade press article (Le Monde Informatique), verified live 2026-09-15. Boursorama Banque is a real, named, major French online bank (a Société Générale subsidiary). This is independent media reporting, not an NTT-authored case study, which is stronger corroboration than a vendor's own page. Explicitly names the SD-WAN technology (Silver Peak), end-to-end encryption, and real-time network monitoring, with an attributed customer quote.
Does not prove: Added 2026-09-15 per thin-provider research pass. No specific site count given for the French/European footprint.
lemondeinformatique.fr · Checked 15 Sept 2026 · Supports: Network visibility and reporting, Branch and office connectivity, Encryption and key management
- FIN-527AcceptedProvider-authoredCompliance attestation or statement
NTT DORA Outsourcing Supplement
- Named service:
- NTT DORA Outsourcing Supplement
- Standard or regulation:
- DORA Article 3(21) ICT services definition
- Regulatory regime:
- EU
States NTT provides ICT services to financial entities under DORA and that the relevant services are identified in the agreement or order, per Article 3(21) DORA.
Harry personally verified this document live 2026-09-15. A genuine DORA contractual supplement, though it ties DORA coverage to what is named in the specific customer agreement/order rather than naming the Managed SD-WAN service directly on the document itself - graded Partial rather than Proven, since the supplement is generic across NTT service lines and the specific SD-WAN/SASE order scope was not independently confirmed.
Does not prove: Added 2026-09-15, Harry-verified. Generic DORA supplement applying to whichever NTT ICT service is named in a given order - not confirmed as covering Managed SD-WAN specifically.
services.global.ntt · Checked 15 Sept 2026 · Supports: Concentration risk and subcontractor transparency, EU DORA alignment
- FIN-533AcceptedProvider-authoredNamed customer case study
- Named financial institution:
- Family Bank Kenya
- Named service:
- Cisco SD-WAN, Catalyst Center, F5 security, Infoblox DNS protection (managed by NTT DATA)
- Sites, branches, users:
- 100+ branches
- Countries, regions:
- Kenya
- Standard or regulation:
- PCI DSS; Central Bank of Kenya CAMELS rating system
- Regulatory regime:
- Not stated
- Outcome:
- Improved operational efficiency; meeting audit and regulatory requirements; optimised costs; enhanced security posture
"Family Bank is a leading commercial bank in Kenya... The Central Bank of Kenya regulates Family Bank and uses the global capital adequacy, asset quality, management, earnings, liquidity and sensitivity (CAMELS) system to rate the bank's performance. Family Bank also has to comply with international standards, such as the Payment Card Industry Data Security Standard (PCI DSS)."
Verified live 2026-09-15. Family Bank Kenya is a real, named commercial bank. Explicit named regulator (Central Bank of Kenya) and named standard (PCI DSS), though Kenya is outside the UK/EU/US/Canada regimes this workbook tracks, so Regulatory regime stays Not stated per the schema.
Does not prove: Added 2026-09-15 per further research pass (cross-platform lead, independently verified). No quantified outcome figures given.
services.global.ntt · Checked 15 Sept 2026 · Supports: Logging, audit and evidence retention, Network visibility and reporting, Branch and office connectivity
- FS-055AcceptedProvider-authoredExisting source lead
NTT builds network using SD-WAN for leading Indonesian bank | NTT
- Named service:
- NTT Managed SD-WAN
- Regulatory regime:
- Not stated
a leading Asian bank in Indonesia
Two independent supplier sources. The newsroom item (evidence 15) is SD-WAN specific but the bank is not named. The dedicated Banking and Financial Services industry page (evidence 9) names BBVA and states 320+ clients in this sector globally and 8 of top 15 global banks have been clients, but carries no networking content. Insurance also has its own industry page in the supplier's industry index.
Does not prove: Supplier newsroom item. SD-WAN specific and sector specific, but the bank is not named, which weakens it. | Confirmed - exact match
services.global.ntt · Checked 29 Jul 2026 · Supports: Branch and office connectivity
- FIN-349RejectedProvider-authoredFinancial services solution page
Banking and Financial Services | NTT DATA
- Named service:
- Digital Banking Transformation, IT and Digital Operations
- Regulatory regime:
- Not stated
reduces costs, improves security and ensures compliance
NTT DATA's banking and financial services industry page covers consulting, digital banking transformation and IT operations, but does not mention SD-WAN, SASE or managed campus networks, and names no network case studies.
Does not prove: Does not name Managed SD-WAN, Managed SASE or Managed Campus Networks anywhere; no regulatory regime named; case studies on the page (BBVA, credit unions) relate to application/AI consulting, not the network service, so it cannot support any of the 28 columns.
nttdata.com · Checked 12 Sept 2026
- FIN-350RejectedProvider-authoredNamed customer case study
Knorr-Bremse drives digitization with managed SD-WAN
- Named service:
- Managed SD-WAN
- Sites, branches, users:
- 100 locations
- Countries, regions:
- 30+ countries (Asia, EMEA, Americas)
- Regulatory regime:
- Not stated
SD-WAN guarantees us high-speed and robust connectivity, as well as fast, reliable and secure access to cloud services
This case study names Knorr-Bremse, a rail and commercial vehicle systems manufacturer, using NTT DATA's Managed SD-WAN across 100 locations in 30-plus countries.
Does not prove: Knorr-Bremse is a manufacturing company, not a bank, insurer or other financial institution, so this cannot evidence any financial services column even though it names the Managed SD-WAN product.
services.global.ntt · Checked 12 Sept 2026
- FIN-355RejectedProvider-authoredOther
- Named service:
- NTT DATA (corporate privacy programme, not service-specific)
- Regulatory regime:
- Not stated
We use a combination of physical, administrative and technical safeguards
NTT DATA's corporate privacy statement describes general safeguards and cross-border transfer practices but does not name the Managed SD-WAN, Managed SASE or Managed Campus Networks service, give specific data residency regions, list sub-processors, or cite any certification.
Does not prove: This is a general corporate privacy statement, not service-specific documentation; it does not name the service, give retention periods, name regions for data storage, or list sub-processors, so it cannot support data residency, logging/retention, or subcontractor transparency columns.
services.global.ntt · Checked 12 Sept 2026
- FIN-356RejectedProvider-authoredFinancial services solution page
Banking and Financial Services | NTT DATA
- Named service:
- Not named (industry consulting only)
- Regulatory regime:
- Not stated
scaling innovation within regulatory boundaries
NTT DATA's banking industry page on services.global.ntt covers consulting, AI, digital banking and IT operations, lists case studies for BBVA and several US credit unions, but never mentions SD-WAN, SASE, managed campus networks or any specific regulatory regime.
Does not prove: No connectivity, network or security service is named on this page at all, so it cannot support any of the 28 network/SASE-specific columns; the case studies on it concern applications and consulting work, not managed network services.
services.global.ntt · Checked 12 Sept 2026
27Virgin Media O2 Business
2 of 28 proven5 of 11 sourcesOpenClose
Virgin Media O2 Business on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Virgin Media O2 Business can show two named UK financial services customers, Royal London Group and Endsleigh Insurance, but both use IPVPN or Ethernet leased-line services rather than the company's named SD-WAN or SASE product, so branch connectivity and trading evidence for the SD-WAN/SASE service itself is not proven. The SASE product page documents zero trust, MFA and CASB features on the named service, giving Proven identity/zero-trust status, but with no financial services customer attached. No UK regulatory alignment (FCA/PRA), DORA, PCI DSS or SWIFT evidence was found connecting the named service to those regimes; the only FCA reference found relates to Telefonica UK's own consumer credit permissions, not the network service. The provider is a UK-domestic network operator with no evidenced US or Canadian delivery, so North American regulatory and delivery columns are marked not applicable. Overall this is thin evidence for a financial services buyer: useful as a UK connectivity and security product set, but with almost no documented compliance, resilience or regulatory alignment specific to regulated financial institutions.
Gaps and unknowns: No evidence was found for data residency, logging and retention periods, change control, incident notification timelines, subcontractor transparency, exit and portability, PCI DSS, SWIFT CSP, FCA/PRA operational resilience or DORA alignment for the named SD-WAN/SASE/Managed SASE services. Closing these would require the provider to publish a dedicated trust or compliance centre naming the SD-WAN/SASE service alongside specific certifications (ISO 27001, Cyber Essentials Plus, PCI DSS AoC), retention periods and regulatory statements, and at least one named UK bank, building society or insurer case study describing SD-WAN or SASE deployment rather than legacy IPVPN or Ethernet services.
- Branch and office connectivity
- Not found
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Proven
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Not found
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Partial
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not applicable
- Canada regulatory alignment (OSFI)
- Not applicable
- PCI DSS alignment
- Not found
- SWIFT CSP alignment
- Not found
- UK delivery
- Proven
- North America delivery
- Not applicable
- Global delivery
- Not found
Sources (11)
- FIN-451AcceptedProvider-authoredOther
SD-WAN for Enterprise | Virgin Media O2 Business
- Named service:
- Virgin Media O2 Business SD-WAN
- Regulatory regime:
- Not stated
Protect your organisation with comprehensive security, including firewalls and encryption to guarantee data integrity and confidentiality.
This is the provider's own product page for Virgin Media O2 Business SD-WAN, describing MPLS, broadband and 4G/LTE aggregation, centralised management, dynamic routing, near zero-touch provisioning and embedded firewalls/encryption. It names no financial institution and no compliance standard.
Does not prove: Generic product marketing page. No named customer, no financial services context, no specific encryption standard (no FIPS or algorithm named), no SLA or resilience metrics. Cannot support any column beyond Partial.
virginmediao2business.co.uk · Checked 12 Sept 2026 · Supports: Network visibility and reporting, Encryption and key management
- FIN-455AcceptedCustomer-authoredNamed customer case study
Royal London Group | Virgin Media Business
- Named financial institution:
- Royal London Group
- Named service:
- IPVPN
- Sites, branches, users:
- 2,800 employees
- Countries, regions:
- UK and Isle of Man
- Regulatory regime:
- UK
- Outcome:
- Staff have easy, always-on access to central business systems and costs are reduced as a result of running voice communications over the network.
"If there are any issues, I can always get hold of someone to help me - we always get it sorted. They're ultimately helping us to be more responsive as an organisation." - Paul Templeman, Group Networks, Royal London Group
Royal London Group, a UK mutual insurance, pensions and investment group with 2,800 employees across the UK and Isle of Man, uses a Virgin Media Business IPVPN to connect offices, relocate data for business continuity, and converge voice, data and video traffic.
Does not prove: Checker 2026-09-12: page carries the fact but the wording differs (First clause found but page continues 'Now that's true peace of mind' rather than 'Their staff now have a secure link to their central business systems' - compo). Re-quote verbatim. The named product is IPVPN, not SD-WAN or SASE, so this cannot be used as SD-WAN/SASE branch connectivity evidence. No RTO/RPO figures, no segmentation, no regulatory statement, and the case study is undated. [2026-09-15, Playwright fetch] Re-quoted verbatim, live-confirmed. Royal London Group is genuinely named (3.6 million customers, GBP 35.5bn+). Named product is confirmed as IPVPN, not SD-WAN/SASE - existing caution stands.
virginmediabusiness.co.uk · Checked 15 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Resilience and tested recovery, UK delivery
- FIN-456AcceptedCustomer-authoredNamed customer case study
Endsleigh Insurance | Virgin Media Business
- Named financial institution:
- Endsleigh Insurance Services Limited
- Named service:
- High Capacity Service (point-to-point) and Ethernet VPN
- Countries, regions:
- UK (Cheltenham and Burnley)
- Regulatory regime:
- UK
- Outcome:
- High-speed, increased capacity and low latency connection means Endsleigh can move huge volumes of data between its Cheltenham and Burnley sites, up to 10 times less expensive than a traditional Wide Area Network.
High-speed, increased capacity and low latency connection means Endsleigh can move huge volumes of data between its Cheltenham and Burnley sites.
Endsleigh Insurance Services Limited uses a 1Gbit/s point-to-point High Capacity Service to keep two UK data centres (Cheltenham and Burnley) synchronised for disaster recovery, plus a 500Mbit/s Ethernet VPN for daily voice and data traffic.
Does not prove: Named product is a leased-line/Ethernet service, not SD-WAN or SASE. No RTO/RPO commitment stated, only that data centres are 'constantly synchronised'. Case study is undated and gives no site/user counts.
virginmediabusiness.co.uk · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Resilience and tested recovery, UK delivery
- FIN-460AcceptedProvider-authoredOther
- Named service:
- SD-WAN, SASE, cloud IaaS/PaaS, Managed Detection and Response
- Regulatory regime:
- Not stated
migration to the cloud is the first step in the digital transformation of a business and that cyber security must be integrated from the beginning.
Press release announcing a partnership with Telefonica Tech to add cloud IaaS/PaaS, private cloud hosting and Managed Detection and Response security services alongside the existing SD-WAN and SASE portfolio, delivered by a UK-based cloud professional and managed services team.
Does not prove: No financial services customer named, no 24x7 SOC wording, no FS-specific outcome. Only generic managed security operations claim, so supports Partial status at most.
news.virginmediao2.co.uk · Published 26 Apr 2023 · Checked 12 Sept 2026 · Supports: Managed operations and SOC
- FIN-522AcceptedProvider-authoredCompliance attestation or statement
What is SASE? | Secure Access Service Edge network strategy
- Named service:
- Virgin Media O2 Business SASE
- Countries, regions:
- UK
- Standard or regulation:
- DORA; FCA; PRA
- Regulatory regime:
- UK
Discusses operational resilience, DORA, and PRA/FCA compliance in the context of SASE and secure, resilient connectivity.
Harry personally verified this live 2026-09-15. General advisory/educational content about DORA and FCA/PRA in the context of SASE, not a contractual mapping or named-service statement from Virgin Media O2 itself - graded Partial, updating this provider from 'no DORA/FCA content found' to 'general context found, not service-specific'.
Does not prove: Added 2026-09-15, Harry-verified. Educational/advisory framing rather than a contractual or product-specific statement.
virginmediao2business.co.uk · Checked 15 Sept 2026 · Supports: UK regulatory alignment (FCA and PRA), EU DORA alignment
- FIN-452RejectedProvider-authoredFinancial services solution page
Enterprise Business | Finance & Banking | Virgin Media Business
- Named service:
- IPSEC VPN, managed firewalls, managed authentication services
- Regulatory regime:
- Not stated
Share big data securely with secure dedicated internet access - such as our IPSEC VPN (virtual private network) with end-to-end encryption, separated from general internet traffic.
A generic finance and banking sector solutions page describing IPSEC VPN, dedicated internet access, leased lines, managed firewalls and unified communications, and stating that solutions help meet data protection and financial regulatory compliance. It links to Royal London Group and Endsleigh Insurance customer stories but does not name SD-WAN or SASE.
Does not prove: Does not name SD-WAN, SASE or Managed SASE. References 'financial regulatory compliance' with no named regime (not FCA, PRA, DORA or PCI specifically), so it cannot support the regulatory columns. Rejected in favour of the dedicated named case studies (Royal London Group, Endsleigh Insurance) which give more specific evidence.
virginmediabusiness.co.uk · Checked 12 Sept 2026
- FIN-454RejectedProvider-authoredOther
Business & Tech Case Studies | Virgin Media O2 Business
- Named service:
- Not applicable
- Regulatory regime:
- Not stated
Read our Tech Case Studies on how we've helped some of the businesses in the UK improve team collaboration and unlock efficiencies using the latest tech.
This is an index/landing page for case studies. No individual case study content, company names or product details render in the fetched page.
Does not prove: No usable content: no named customers, no financial services material, nothing to attribute to any column.
virginmediao2business.co.uk · Checked 12 Sept 2026
- FIN-457RejectedProvider-authoredCompliance attestation or statement
Cyber Security Executive Summary
- Named service:
- SASE (general)
- Regulatory regime:
- Not stated
Never trust, always verify.
A short executive-summary PDF discussing the shift from VPN to SASE and a zero-trust philosophy. It contains no certifications, no data residency, encryption, retention, incident response or SLA detail.
Does not prove: No ISO 27001, Cyber Essentials Plus, PCI DSS, SOC 2, data residency, encryption standard or SLA content found. Cannot support any of the 28 columns.
virginmediao2business.co.uk · Checked 12 Sept 2026
- FIN-458RejectedProvider-authoredOther
Business Success Agreement | SLA | Virgin Media O2 Business
- Named service:
- Business Success Agreement
- Regulatory regime:
- Not stated
Standard Service Level Agreements (SLAs) are about defining the minimum service you can expect from a supplier.
This page describes a commercial 'Success Agreement' replacing a technical SLA: reduced charges of 25% for up to 12 months if business goals are not met, a change allowance of 15%, and three months free at the start. It contains no technical resilience, incident response or uptime commitments.
Does not prove: Commercial outcome guarantee, not a technical SLA. No RTO/RPO, no incident notification timelines, no financial services context. Cannot support the resilience or incident notification columns.
virginmediao2business.co.uk · Checked 12 Sept 2026
- FIN-459RejectedProvider-authoredOther
Connect Protect and Empower | Virgin Media O2 Business
- Named service:
- SASE / zero trust (general)
- Regulatory regime:
- Not stated
Telefonica UK Ltd is authorised and regulated by the Financial Conduct Authority.
A marketing page on hybrid work and cloud-based zero trust security. The FCA reference in the footer is Telefonica UK Ltd's own regulatory status as a credit broker/appointed representative for consumer finance products, not a statement about the SD-WAN/SASE service meeting FCA or PRA operational resilience or outsourcing rules for financial services customers.
Does not prove: This page was checked specifically because it is the only place an FCA reference appears in the provider's own site navigation, but the reference concerns Telefonica UK's consumer credit permissions, not the SD-WAN/SASE service's alignment with FCA/PRA operational resilience rules (SYSC 15A, SS1/21, SS2/21) for financial services customers. Cannot be used for UK regulatory alignment.
virginmediao2business.co.uk · Checked 12 Sept 2026
- FIN-461RejectedProvider-authoredOther
Enterprise Connectivity Solutions | Virgin Media O2 Business
- Named service:
- Not applicable
- Regulatory regime:
- Not stated
Tackling tech debt and legacy systems helps release funds to further innovation efforts and keep pace.
A general enterprise modernisation page with an anonymised quote attributed to 'a Chief Information Officer in financial services' about tech debt, and an unrelated local government cost-of-downtime quote. Neither SD-WAN nor SASE is named on the page.
Does not prove: The financial services quote is anonymised (no institution named) and does not reference SD-WAN, SASE, security or resilience, so it cannot support any column.
virginmediao2business.co.uk · Checked 12 Sept 2026
28Juniper Networks
3 of 28 proven9 of 15 sourcesOpenClose
Juniper Networks on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Proven for Identity and zero trust access (AmeriTrust, US insurer), Branch and office connectivity (Seacoast Bank, US community bank), and Data-centre/cloud connectivity (First Bank, 50% reduction stat). All three are US-regime customers; two of three use Juniper's Wi-Fi/wired/Mist platform rather than SD-WAN/SASE specifically, per evidence rule 4.
Gaps and unknowns: The most significant gap is the Trust Center's inaccessible compliance content, which blocks verification of encryption/FIPS, data residency, retention, sub-processor and incident notification claims; obtaining this would require either a rendered browser fetch of that page or Juniper's underlying compliance/legal PDF documents. No named financial institution case study for SD-WAN, Secure Edge or SASE was located; this would need a dedicated search of Juniper's case study archive or press releases (blocked in this session because the WebSearch budget was exhausted before this task began) or direct enquiry to Juniper/HPE sales. All four regulatory alignment columns (UK, EU, US, Canada) and PCI DSS and SWIFT CSP remain entirely unevidenced and would need explicit compliance statements or FS customer references naming those regimes. [2026-09-15] Three new named customers found: AmeriTrust (insurance, Zero Trust), Seacoast Bank (US community bank, branch connectivity via Mist wired/wireless), and First Bank (50% reduction managing data centre network). Moved from 0 to 3 Proven cells. Still no regulatory column evidence, no trading/low-latency, no PCI/SWIFT evidence.
- Branch and office connectivity
- Proven
- Trading and low-latency connectivity
- Partial
- Data-centre, colocation and cloud connectivity
- Proven
- Resilience and tested recovery
- Partial
- Network segmentation and zoning
- Not found
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Not found
- Data residency and sovereignty
- Not found
- Encryption and key management
- Not found
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Proven
- Cloud and SaaS data controls
- Not found
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Not found
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Not found
- Global delivery
- Partial
Sources (10)
- FIN-313AcceptedProvider-authoredOther
Secure Access Service Edge (SASE) Solutions | HPE Juniper Networking US
- Named service:
- Juniper SASE (Secure Services Edge / SSE plus SD-WAN)
- Regulatory regime:
- Not stated
- Outcome:
- 99.7% exploit block rate with zero false positives in independent testing
zero-trust access to any application from anywhere while optimizing every connection
Juniper's own SASE page documents zero-trust access as a built-in capability of its named SASE/SSE service, independent of any financial services context.
Does not prove: Documents zero-trust access at product level only; no mention of MFA, IdP integration, or any financial services customer or context.
juniper.net · Checked 12 Sept 2026 · Supports: Identity and zero trust access
- FIN-314AcceptedProvider-authoredOther
Session Smart Router | HPE Juniper Networking US
- Named service:
- Juniper Session Smart Router
- Regulatory regime:
- Not stated
deny-by-default Zero Trust model
The Session Smart Router product page documents a deny-by-default Zero Trust security model as a built-in architectural feature.
Does not prove: Product-level architecture claim only, no financial services context, no MFA/IdP or ZTNA-application-access detail beyond the routing layer.
juniper.net · Checked 12 Sept 2026 · Supports: Identity and zero trust access
- FIN-315AcceptedProvider-authoredOther
WAN Assurance Cloud Service | HPE
- Named service:
- Juniper Mist WAN Assurance
- Regulatory regime:
- Not stated
Monitor and enforce service level experiences (SLEs) using key metrics on application response times, WAN link status, gateway health, and other network conditions.
WAN Assurance, Juniper's cloud WAN monitoring service (now hosted on HPE's site after the Juniper-HPE merger), provides monitoring and SLE-based reporting on WAN links and gateways.
Does not prove: No financial services customer or context; no numeric SLA/uptime commitment given; page is now HPE-branded post-acquisition, not a Juniper-specific compliance document.
hpe.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting
- FIN-502AcceptedCustomer-authoredNamed customer case study
Financial Services Solutions | Juniper Networks
- Named financial institution:
- Seacoast Bank
- Named service:
- Juniper Mist AI-driven wired and wireless networking
- Countries, regions:
- United States (Florida)
- Standard or regulation:
- None stated
- Regulatory regime:
- US
- Outcome:
- Ensures branch locations and banking services operate seamlessly during an active acquisition/integration process
Founded 90+ years ago, Florida's Seacoast has grown into a large community bank through an aggressive acquisition strategy. Seacoast uses Juniper AI-driven wired and wireless networking to ensure its branch locations and banking services operate seamlessly.
Juniper's own Financial Services page, verified live 2026-09-15. Seacoast Bank is a real, named US community bank (Florida). This is wired/wireless (Wi-Fi/LAN) networking, not SD-WAN/SASE specifically - per evidence rule 4, graded Not relevant on the SD-WAN/SASE field, but still valid, real evidence for general branch connectivity.
Does not prove: Added 2026-09-15 per thin-provider research pass. Wired/wireless LAN evidence, not SD-WAN/SASE - correctly excluded from that field per evidence rule 4.
juniper.net · Checked 15 Sept 2026 · Supports: Branch and office connectivity
- FIN-503AcceptedProvider-authoredNamed customer case study
Mitigate Risk and Reduce TCO and OpEx with the AI-Native Networking Platform (Solution Brief)
- Named financial institution:
- First Bank
- Named service:
- Juniper AI-Native Networking Platform
- Countries, regions:
- Not stated
- Standard or regulation:
- None stated
- Regulatory regime:
- Not stated
- Outcome:
- 50% reduction in managing the data center network
"50% Reduction in managing the data center network (First Bank)"
Juniper's own solution brief, verified live 2026-09-15. 'First Bank' is named only by that generic name (several institutions share it globally, as previously noted for HPE Aruba) - the quantified 50% figure is real and attributed, but the specific entity and country cannot be confirmed with confidence, so Regulatory regime stays Not stated.
Does not prove: Added 2026-09-15. Same "First Bank" ambiguity as the HPE Aruba source (FIN-044/307) - several institutions share this name globally, so no regime is claimed.
juniper.net · Checked 15 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity
- FIN-316RejectedProvider-authoredOther
HPE Customer Case Studies (financial services filter)
- Named financial institution:
- DB Life Insurance
- Named service:
- HPE Private Cloud AI / GreenLake
- Regulatory regime:
- Not stated
DB Life Insurance selects HPE to build a scalable sovereign AI foundation for future innovation
The only financial services entry on HPE's customer case studies page is an insurer buying HPE Private Cloud AI and GreenLake for a generative AI copilot, unrelated to Juniper networking, SD-WAN or Secure Edge.
Does not prove: Does not name any Juniper SD-WAN/SASE/Secure Edge product, so provides no evidence for any of the 28 columns; rejected as out of scope for this provider's networking products.
hpe.com · Published 22 Jan 2026 · Checked 12 Sept 2026
- FIN-317RejectedProvider-authoredOther
Trust Center | HPE Juniper Networking US
- Named service:
- Juniper Trust Center
- Regulatory regime:
- Not stated
Our mission is to foster trust by building secure, reliable, and ethically sound solutions, empowering stakeholders to navigate today's complex digital landscape with confidence.
Juniper's Trust Center landing page exists and states a general mission statement, but its detailed certification, data residency, sub-processor and retention content is loaded client-side and was not retrievable through the fetch tool.
Does not prove: No certifications (SOC 2, ISO 27001, FIPS, PCI DSS), data residency regions, sub-processor list, SLA or retention figures could be extracted; the page's substantive content did not render. Provides no usable evidence for any compliance column. [2026-09-15] Playwright fetch 2026-09-15 (Juniper Trust Center, flagged by Robert as script-rendered) failed with a DNS resolution error (ERR_NAME_NOT_RESOLVED) for juniper.net, so the 'confirm by eye' check for this page is still outstanding - needs a re-run once the DNS issue clears. [2026-09-14, Harry] Personally opened and confirmed live by Harry Yelland - the recorded wording matches the page/document exactly. This was previously unreachable by automation (bot-verification wall or unfetchable PDF). [2026-09-15, flagged per Robert's check] Pure mission statement ("foster trust by building secure, reliable, and ethically sound solutions") with no technical claim of any kind. Does not appear to support any specific capability honestly. Changed from Accepted to Needs review since no specific capability can be honestly assigned - recommend Harry/Robert decide whether to Reject or find a genuine capability fit.
juniper.net · Checked 14 Sept 2026
- FIN-318RejectedProvider-authoredOther
Managed Network Services Solutions | HPE Juniper Networking US
- Named service:
- Juniper managed services (unnamed)
- Regulatory regime:
- Not stated
Discover how Vodafone Business SD-LAN with Juniper Mist revolutionized connectivity at Vodafone's Malaga office by replacing legacy infrastructure with a cloud-native, AI-Native Networking Platform.
Juniper's managed services page cites a Vodafone SD-LAN office case, not a financial institution, and does not mention 24x7 operations or a SOC.
Does not prove: No SOC or 24x7 managed operations claim found; no financial services customer named; provides no usable evidence for the managed operations and SOC column.
juniper.net · Checked 12 Sept 2026
- FIN-319RejectedProvider-authoredOther
- Named service:
- Juniper Secure Edge
- Regulatory regime:
- Not stated
The Juniper Secure Edge product page now redirects into the HPE e-commerce store, which returned only a search/login page with no product or compliance content.
Does not prove: No usable content on Secure Edge features, compliance or financial services applicability; the redirect chain following the Juniper-HPE merger has broken the original marketing page.
buy.hpe.com · Checked 12 Sept 2026
- FIN-320RejectedProvider-authoredOther
HPE Juniper Networking US (homepage)
- Named service:
- Juniper Networks / HPE Juniper Networking (corporate site)
- Regulatory regime:
- Not stated
Juniper Networks is now part of Hewlett Packard Enterprise
Juniper's homepage confirms the company is now part of HPE and was used only to locate navigation links (Trust Center, industries, products) for further research.
Does not prove: Navigation-only page, used solely to find other URLs; provides no direct evidence for any of the 28 columns.
juniper.net · Checked 12 Sept 2026
29Expereo
0 of 28 proven8 of 13 sourcesOpenClose
Expereo on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Expereo publishes general Managed SD-WAN, SASE (partnered with Cato Networks) and expereoOne visibility material, but nothing on its own website names a bank, insurer, payments company or asset manager, and there is no dedicated financial services industry page. Its standard terms describe service levels as non-binding targets with no service credits and no stated RTO or RPO, place fault-reporting duty on the customer, cap liability at 500,000 euros a year, and permit subcontracting without customer consent. No regulatory alignment statement (FCA/PRA, DORA, FFIEC/GLBA/NYDFS/SEC, OSFI or PCI DSS) exists for any named Expereo service, and no SOC 2 or PCI attestation was found, only a company-wide ISO 27001 claim not tied to a specific product. Delivery evidence is limited to a London office, a Reston, Virginia office, and a general claim of reach into up to 190 countries, none of it financial services specific. On the evidence gathered, Expereo cannot be shown fit for a regulated UK, EU, US or Canadian financial services deployment without further direct evidence from the provider.
Gaps and unknowns: No evidence exists for any of the eight regulatory and governance columns (FCA/PRA, DORA, FFIEC/GLBA/NYDFS/SEC, OSFI, PCI DSS, SWIFT CSP, incident notification, subcontractor transparency, exit and portability); a named financial services case study or a compliance statement addressing these regimes would close them. Data residency, encryption/key management, logging and change-control detail are also unevidenced; a technical trust centre or security whitepaper naming the specific service would be needed. Resilience and RTO/RPO commitments are unevidenced and are contradicted by standard terms describing service levels as non-binding targets.
- Branch and office connectivity
- Not found
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Partial
- Resilience and tested recovery
- Not found
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Not found
- Encryption and key management
- Not found
- Logging, audit and evidence retention
- Not found
- Identity and zero trust access
- Partial
- Cloud and SaaS data controls
- Partial
- Managed operations and SOC
- Partial
- Network visibility and reporting
- Partial
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Not found
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Not found
- SWIFT CSP alignment
- Not found
- UK delivery
- Partial
- North America delivery
- Partial
- Global delivery
- Partial
Sources (13)
- FIN-255AcceptedProvider-authoredContradiction
- Named service:
- Expereo Managed SD-WAN / SASE / Global Internet (general service agreement)
- Regulatory regime:
- Not stated
Service Level Targets...are targets only. Expereo will provide reasonable efforts to achieve these targets. Service credits are not applicable and non-achievement of such stated targets by Expereo will not constitute a breach of the Agreement.
Expereo's standard terms describe service levels as non-binding targets with no service credits, place the duty to report faults on the customer within 30 days, limit aggregate liability to 500,000 euros a year, and permit Expereo to subcontract or assign the agreement to any affiliate or third party without customer consent.
Does not prove: Shows there is no published RTO/RPO or guaranteed resilience commitment, no provider-to-customer incident notification commitment, no defined data export/exit process, and no restriction on subcontracting; it does not itself say a regulatory regime applies. This is standard-terms evidence, not proof any of these controls exist for a specific FS customer.
expereo.com · Checked 12 Sept 2026 · Supports: Concentration risk and subcontractor transparency, Resilience and tested recovery, Incident notification support, Exit and portability
- FIN-257AcceptedProvider-authoredFinancial services solution page
expereoOne platform - Total visibility & control through a single view
- Named service:
- expereoOne
- Regulatory regime:
- Not stated
see the status of your Global Internet, Enhanced Internet, SASE and SD-WAN services
expereoOne is described as a portal and API giving a single view of network performance, incidents, tickets, orders and invoices across Expereo's connectivity, SD-WAN and SASE services.
Does not prove: Generic product description with no financial services customer, no RBAC, change-management or audit-trail detail, and no data residency statement for the platform's own data.
expereo.com · Checked 12 Sept 2026 · Supports: Network visibility and reporting
- FIN-258AcceptedProvider-authoredFinancial services solution page
- Named service:
- Expereo SASE
- Regulatory regime:
- Not stated
Verifies the identity of users and devices and checks against business policy before granting access to applications and data
The Expereo SASE page describes ZTNA, secure web gateway and CASB components covering identity verification, URL filtering, malware detection, DLP and cloud app discovery.
Does not prove: Generic architecture description with no financial services customer, no named vendor partner on this specific page, and no MFA/IdP or CASB/DLP outcome tied to a real deployment.
expereo.com · Checked 12 Sept 2026 · Supports: Identity and zero trust access, Cloud and SaaS data controls
- FIN-259AcceptedProvider-authoredFinancial services solution page
Enhancing Network Security With SD-WAN - Expereo
- Named service:
- Expereo Managed SD-WAN (via SASE)
- Regulatory regime:
- Not stated
Network segmentation and Zero Trust Security reduce the attack surface and prevent lateral movement of threats within the network
A provider blog states that network segmentation and zero trust security, delivered as part of SASE/SD-WAN, reduce attack surface and lateral movement.
Does not prove: General marketing blog, not financial services material; no mention of VRF, micro-segmentation mechanics, cardholder data or PCI scope.
expereo.com · Checked 12 Sept 2026 · Supports: Network segmentation and zoning
- FIN-260AcceptedProvider-authoredFinancial services solution page
- Named service:
- Expereo Managed SD-WAN
- Regulatory regime:
- Not stated
optimized user experience for all your employees, no matter where they work
Expereo describes Managed SD-WAN as cloud-centric, optimising traffic to SaaS applications and giving real-time analytics of service performance for employees regardless of location.
Does not prove: No named financial customer, no explicit data centre or colocation on-ramp list, and no detail on how remote/hybrid access is secured for regulated staff such as advisers or traders.
expereo.com · Checked 12 Sept 2026 · Supports: Data-centre, colocation and cloud connectivity, Network visibility and reporting, Remote and hybrid workforce
- FIN-261AcceptedProvider-authoredFinancial services solution page
- Named service:
- Expereo (support operations)
- Countries, regions:
- US, South America, Europe, Middle East, Asia
- Regulatory regime:
- Not stated
Our global Customer Support Team and Network Operation Centers (NOC), operate on a 'follow-the-sun' basis to ensure 24/7 support is available when you need it.
Expereo operates 24/7 follow-the-sun Network Operation Centres and regional phone support covering the US, South America, Europe, the Middle East and Asia.
Does not prove: Describes a Network Operations Centre, not a Security Operations Centre, gives no financial services customer, and does not list a UK-specific phone line separately from 'Europe'.
expereo.com · Checked 12 Sept 2026 · Supports: Managed operations and SOC, North America delivery, UK delivery
- FIN-262AcceptedProvider-authoredFinancial services solution page
- Named service:
- Expereo Global Internet
- Countries, regions:
- Up to 190 countries
- Regulatory regime:
- Not stated
We can connect in up to 190 countries with local experts and partners
Expereo states its Connect services (Global Internet, Fixed Wireless Access, Low Earth Orbit) can reach up to 190 countries using local partners.
Does not prove: General global coverage claim with no PoP count, no financial services customer and no breakdown by region.
expereo.com · Checked 12 Sept 2026 · Supports: Global delivery
- FIN-263AcceptedProvider-authoredOther
- Named service:
- Expereo (corporate offices)
- Countries, regions:
- Netherlands, UK, USA, UAE, Singapore, Argentina, Brazil, Poland, Philippines, Spain, France
- Regulatory regime:
- Not stated
Corporate offices are listed in the UK and the US; no Canadian office is listed on this page.
Expereo lists a London, UK office and a Reston, Virginia, USA office among its eleven listed corporate office locations; no Canadian office is listed.
Does not prove: Quoted wording not found on the page in the 2026-09-12 check (Address text present but split across separate lines, not as one continuous string as quoted.). Re-quote before accepting. Confirms corporate office presence in the UK and US only, not network PoPs, data centres or named UK/US financial services customers, and shows no Canadian office. [2026-09-15 Harry review] Verified live 2026-09-15 (paraphrased per the checker's note - office addresses render as separate lines, not one continuous sentence, so no single verbatim sentence exists to quote). Confirms UK/US corporate presence only - not network PoPs or data centres, and explicitly no Canadian office, so this cannot support Canada delivery and only weakly supports UK/North America delivery as Partial.
expereo.com · Checked 15 Sept 2026 · Supports: North America delivery, UK delivery
- FIN-251RejectedProvider-authoredOther
- Named service:
- Expereo (general)
- Regulatory regime:
- Not stated
How Heras delivered reliable connectivity across 5 countries
Expereo's case studies index lists 12 customer stories (Heras, Kramp, LP Building Solutions, Socomec, Bilfinger, Schoeller Allibert and others), none of which are banks, insurers, payment firms or asset managers.
Does not prove: Does not prove any financial services capability; no named financial institution appears anywhere in the case study index.
expereo.com · Checked 12 Sept 2026
- FIN-252RejectedProvider-authoredOther
Faster to the future - Expereo
- Named service:
- Expereo (general)
- Regulatory regime:
- Not stated
Connect, Enhance, Secure, expereoOne
The main site navigation has no Industries or Financial Services section and no dedicated trust/security/compliance hub; only generic Privacy, Cookies, Terms and Modern Slavery links appear.
Does not prove: Confirms absence of a financial services vertical page and of a dedicated trust/compliance centre on the main site; proves nothing about any capability directly.
expereo.com · Checked 12 Sept 2026
- FIN-253RejectedProvider-authoredOther
Expereo and Cato Networks Announce Collaboration
- Named service:
- Expereo SASE (with Cato Networks)
- Regulatory regime:
- Not stated
Direct on-ramps from Expereo's underlay to Cato's global private backbone, to deliver lower latency, higher reliability
Expereo announced a partnership with Cato Networks to deliver managed SASE combining Expereo's global internet underlay with Cato's SASE overlay, targeted at medium to large multinational enterprises.
Does not prove: Confirms the named Cato SASE partnership but names no financial institution, no regulatory regime and no specific capability fact (e.g. segmentation, ZTNA detail, SLA); marketing-level partnership announcement only.
expereo.com · Published 4 Feb 2026 · Checked 12 Sept 2026
- FIN-254RejectedProvider-authoredOther
- Named service:
- Expereo (corporate privacy policy)
- Standard or regulation:
- GDPR
- Regulatory regime:
- EU
Expereo processes your personal data solely for internal purposes and does not give or sale any of your personal data to third parties.
Expereo's website privacy policy references GDPR and Dutch law and states it does not sell personal data to third parties, but does not state data storage locations, retention periods, sub-processor names or encryption methods.
Does not prove: Covers website/marketing personal data, not the SD-WAN/SASE service's management-plane or log data; no data residency, retention or sub-processor detail is given, so it cannot prove columns 9, 11 or 18.
expereo.com · Checked 12 Sept 2026
- FIN-256RejectedProvider-authoredCompliance attestation or statement
Our ESG Practices To Make The World Better | Expereo
- Named service:
- Expereo (corporate)
- Standard or regulation:
- ISO 27001
- Regulatory regime:
- Not stated
we are proud to be ISO 27001 certified
Expereo states on its ESG page that it is ISO 27001 certified and that staff are trained on cybersecurity and data protection; no SOC 2 or PCI DSS certification is mentioned anywhere on this page.
Does not prove: The ISO 27001 claim is a corporate-wide statement not tied to a named product (Managed SD-WAN, SASE or expereoOne) and gives no scope statement, certificate reference or audit date, so per the grading rules it cannot prove any of the named-service documentation columns or the regulatory columns.
expereo.com · Checked 12 Sept 2026
30Forcepoint
1 of 28 proven9 of 20 sourcesOpenClose
Forcepoint on the marketplace · Reviewed 14 Sept 2026 by Harry Yelland
Forcepoint's public evidence for financial services is concentrated in data-loss-prevention and data-security-posture case studies (Vakifbank in Turkey, Fedbank in India, HDI Seguros in Brazil, an anonymised Middle East bank, FBD Insurance in Ireland and UCI in Spain), none of which names Forcepoint SD-WAN or Forcepoint ONE SASE as the deployed service. The strongest named customer is VAKIFBANK, a large Turkish bank using Forcepoint DLP at scale across 17,000 endpoints for GDPR and KVKK compliance. Cloud and SaaS data controls (DLP/CASB) is the only column reaching Proven status, based on named FS institutions. No UK, US or Canadian named financial institution was found, and none of the specific regulatory regimes tracked here (FCA/PRA, DORA, FFIEC/GLBA/NYDFS/SEC, OSFI) is connected to a named Forcepoint service anywhere in the pages opened. Connectivity, resilience, segmentation, identity, logging-retention, incident-notification and exit-portability columns are all unevidenced for the named SD-WAN/SASE product line, so this evidence base does not currently support Forcepoint ONE or Secure SD-WAN as a proven fit for UK or North American FS operational-resilience requirements.
Gaps and unknowns: No UK or North American named financial institution case study was found for any Forcepoint product, so UK delivery, North America delivery, FCA/PRA and NYDFS/GLBA/FFIEC/SEC columns are all unevidenced; a named SD-WAN or Forcepoint ONE deployment at a UK or US bank would close this. Forcepoint ONE's data residency, log retention period, SLA/uptime commitment and incident-notification timeline could not be located on any reachable page (the datasheet, SLA page and data-residency help page all returned 404), so these would need a directly-fetchable trust or product document. DORA, OSFI and SWIFT CSP alignment are entirely unevidenced and would require a dedicated compliance statement or an EU/Canadian named FS customer referencing those regimes.
- Branch and office connectivity
- Not found
- Trading and low-latency connectivity
- Not found
- Data-centre, colocation and cloud connectivity
- Not found
- Resilience and tested recovery
- Not found
- Network segmentation and zoning
- Partial
- Payment and cardholder data segmentation
- Not found
- Third-party and outsourced access
- Not found
- Remote and hybrid workforce
- Partial
- Data residency and sovereignty
- Not found
- Encryption and key management
- Partial
- Logging, audit and evidence retention
- Partial
- Identity and zero trust access
- Not found
- Cloud and SaaS data controls
- Proven
- Managed operations and SOC
- Not found
- Network visibility and reporting
- Not found
- Change control and configuration governance
- Not found
- Incident notification support
- Not found
- Concentration risk and subcontractor transparency
- Not found
- Exit and portability
- Not found
- UK regulatory alignment (FCA and PRA)
- Not found
- EU DORA alignment
- Partial
- US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)
- Not found
- Canada regulatory alignment (OSFI)
- Not found
- PCI DSS alignment
- Partial
- SWIFT CSP alignment
- Not found
- UK delivery
- Not found
- North America delivery
- Not found
- Global delivery
- Partial
Sources (17)
- FIN-265AcceptedCustomer-authoredNamed customer case study
VAKIFBANK Customer Story | Forcepoint
- Named financial institution:
- VAKIFBANK
- Named service:
- Forcepoint DLP
- Sites, branches, users:
- 900+ branches; 17,000 endpoint agents
- Countries, regions:
- Turkey, with international offices in the US, Qatar, Bahrain and Austria
- Standard or regulation:
- GDPR; KVKK
- Regulatory regime:
- Not stated
- Outcome:
- Blocked 4,000 incidents within the first three months; classified or fingerprinted nearly 20 million files
VAKIFBANK blocked 4,000 incidents within the first three months and now manages nearly 50 policies.
VAKIFBANK, Turkey's second-largest bank, deployed Forcepoint DLP across 17,000 endpoints to protect customer PII and financial information and to meet GDPR and KVKK requirements.
Does not prove: This is a DLP/data-security deployment, not a named SD-WAN or SASE service, so it does not prove branch connectivity, segmentation or any of the North American/UK/EU regulator-specific columns; Turkey is not one of the schema's tracked regimes.
forcepoint.com · Published 7 Jun 2022 · Checked 12 Sept 2026 · Supports: Cloud and SaaS data controls
- FIN-267AcceptedProvider-authoredCompliance attestation or statement
- Named service:
- Forcepoint ONE (FONE); Cloud DLP; Cloud DSPM; Cloud Web
- Standard or regulation:
- ISO/IEC 27001:2022; SOC 2 Type 2; FIPS 140-3
- Regulatory regime:
- Not stated
SOC 2, Type 2 Report - Forcepoint ONE (FONE)
Forcepoint's trust centre lists a SOC 2 Type 2 report specifically naming Forcepoint ONE, alongside organisation-wide ISO/IEC 27001:2022, 27017, 27018 certificates and a FIPS 140-3 listing, with detailed documents gated behind an access request.
Does not prove: FIPS 140-3 and the ISO certificates are listed at organisation level rather than tied to a named product on this page, and no data residency, retention period or SLA figures are disclosed; the underlying reports were not accessible without a gated request.
trust.forcepoint.com · Checked 12 Sept 2026 · Supports: Encryption and key management
- FIN-269AcceptedProvider-authoredFinancial services solution page
Forcepoint cybersecurity solutions for banks (Financial Services industry page)
- Named service:
- Forcepoint AI Data Security (DLP, DSPM, DDR, CASB, NGFW)
- Regulatory regime:
- Not stated
Speed reporting and audits for national and industry-specific regulations
Forcepoint's financial services industry page names Fedbank, UCI and Vakifbank as case studies and lists AI Data Security, DLP, DSPM, DDR, CASB and NGFW products, but does not name a specific regulation (no DORA, FCA, GLBA, NYDFS, OSFI or SWIFT reference) and includes no SD-WAN/SASE connectivity content.
Does not prove: Generic financial services solutions page; per the grading rules this is Partial at most and is used here only as the index linking to the three named case studies, not as standalone proof of any column. [2026-09-15, capability assigned per Robert's check] Directly describes "speed reporting and audits for national and industry-specific regulations."
forcepoint.com · Checked 12 Sept 2026 · Supports: Logging, audit and evidence retention
- FIN-271AcceptedCustomer-authoredNamed customer case study
FBD Insurance Customer Story | Forcepoint
- Named financial institution:
- FBD Insurance
- Named service:
- Forcepoint DSPM; Forcepoint DDR
- Countries, regions:
- Ireland
- Standard or regulation:
- GDPR
- Regulatory regime:
- EU
- Outcome:
- Reduced alert fatigue and improved mean time to detect and respond
It's allowed us really to pinpoint what is the critical data we must manage, what we must lock down.
FBD Insurance, an Irish general insurer, deployed Forcepoint DSPM and DDR to classify sensitive policyholder and claims data and support GDPR compliance reporting.
Does not prove: Quoted wording not found on the page in the 2026-09-12 check (Actual page text: 'It's allowed us really to pinpoint what is the critical data we must manage, what we must lock down.' - differs from quoted text.). Re-quote before accepting. No verbatim wording obtained on the page ties this deployment to a specific log retention period, audit-trail export or DORA; the case is EU/Ireland but concerns data classification, not SD-WAN/SASE connectivity or a named regulator regime beyond GDPR. [2026-09-15 Harry review] Re-quoted using the exact sentence the checker found on the live page. This is about data classification, not SD-WAN/SASE connectivity, and does not name a log-retention period, audit-trail export, or DORA - capability claims beyond general sector-fit are not supported by this source. [2026-09-15, capability assigned per Robert's check - WEAK FIT, flagged for review] FBD Insurance quote about data classification ("what is the critical data we must manage, what we must lock down") - closest capability fit but does not name a specific mechanism, retention period or regulation.
forcepoint.com · Published 13 Oct 2025 · Checked 15 Sept 2026 · Supports: Cloud and SaaS data controls
- FIN-273AcceptedCustomer-authoredNamed customer case study
Middle East Bank Customer Story | Forcepoint
- Named service:
- Forcepoint Data Loss Prevention Suite (IP Protection); Forcepoint DSPM
- Sites, branches, users:
- 1,000 users
- Countries, regions:
- Egypt (Middle East)
- Standard or regulation:
- PCI DSS
- Regulatory regime:
- Not stated
- Outcome:
- Enhanced data visibility and faster incident response; shift from reactive compliance to proactive governance
The bank's leadership recognized that the evolving regulatory landscape spanning central bank mandates, PCI DSS, and PII protection requires a proactive and intelligent approach to data governance.
An anonymised Egypt-headquartered bank deployed Forcepoint DLP Suite and DSPM for 1,000 users to address central bank, PCI DSS and PII data-governance requirements.
Does not prove: The institution is not named (described only as a leading Middle East bank headquartered in Egypt), so this is anonymised evidence; no PCI DSS Attestation of Compliance for the Forcepoint service itself is shown, and Egypt is outside the schema's tracked regimes.
forcepoint.com · Published 12 Jan 2026 · Checked 12 Sept 2026 · Supports: PCI DSS alignment
- FIN-276AcceptedCustomer-authoredNamed customer case study
Fedbank Financial Services Ltd (Fedfina) Customer Story | Forcepoint
- Named financial institution:
- Fedbank Financial Services Ltd (Fedfina)
- Named service:
- Forcepoint Web Security; Forcepoint DLP
- Sites, branches, users:
- 250+ gold loan branches; 300+ offices; 1,800+ employees; approx. 30,000 customers
- Countries, regions:
- India
- Standard or regulation:
- RBI (Reserve Bank of India) NBFC DLP mandate
- Regulatory regime:
- Not stated
- Outcome:
- Blocked unwanted internet access; reduced policy application reflection time to 10-15 minutes
Besides, the regulatory mandate by Reserve Bank of India (RBI) also required NBFCs to install a Data Loss Prevention (DLP) system for data security.
Fedbank Financial Services Ltd, an Indian NBFC with 250+ branches, deployed Forcepoint Web Security and DLP to meet an RBI mandate and to prevent data leakage.
Does not prove: The regulator named is India's RBI, which is outside the schema's tracked UK/EU/US/Canada regimes, so this does not support columns 20 to 23; the product is Web Security and DLP, not SD-WAN or SASE.
forcepoint.com · Published 16 Mar 2020 · Checked 12 Sept 2026 · Supports: Cloud and SaaS data controls
- FIN-516AcceptedProvider-authoredCompliance attestation or statement
Forcepoint EBA Guidance / Compliance Hub
- Named service:
- Forcepoint ONE (SASE)
- Standard or regulation:
- DORA (EBA guidance referenced)
- Regulatory regime:
- EU
Discusses DORA's applicability and directs customers to the Forcepoint Trust Hub; the Compliance Hub separately lists an EU DORA compliance document alongside SOC 2 Type II and ISO Statement of Applicability access.
Harry personally verified this live 2026-09-15. General DORA-awareness document referencing EBA guidance, not a named Forcepoint ONE contractual mapping or Article 30 terms - graded Partial, consistent with the document's own caveat that this needs contract-level confirmation.
Does not prove: Added 2026-09-15, Harry-verified. Awareness/guidance document rather than a contractual DORA mapping for the named SASE product.
forcepoint.com · Checked 15 Sept 2026 · Supports: EU DORA alignment
- FIN-531AcceptedIndependentNamed customer case study
Chilean Bank Gets Proactive on Data Security After Cyberattacks Rock Latin America (Banco BICE)
- Named financial institution:
- Banco BICE
- Named service:
- Forcepoint CASB and Forcepoint DLP
- Countries, regions:
- Chile
- Regulatory regime:
- Not stated
- Outcome:
- Reduced leakage risk; controls aligned with daily business processes; stronger protection
"In July 2018 the bank adopted Forcepoint CASB and DLP and rolled out continuous internal training to create a human-centered, dynamic security model that anticipates incidents."
Verified live 2026-09-15 (found independently via search; matches a candidate finding supplied separately). Banco BICE is a real, named Chilean corporate banking group. Product is CASB/DLP, not SD-WAN/SASE/SSE - correctly excluded from that field per evidence rule 4, supporting-only for data-control capabilities.
Does not prove: Added 2026-09-15. NGFW/DLP/CASB deployment, not SD-WAN/SASE. No specific regulation named on the page despite mentioning "accelerated regulation" generally.
casestudies.com · Checked 15 Sept 2026 · Supports: Logging, audit and evidence retention, Cloud and SaaS data controls
- FIN-532AcceptedProvider-authoredNamed customer case study
Compartamos Banco Safeguards Data in Order to Better Serve its Customers
- Named financial institution:
- Compartamos Banco
- Named service:
- Forcepoint Hybrid Web Security with integrated DLP
- Sites, branches, users:
- 16,000 employees; 500+ offices; 2.5 million customers
- Countries, regions:
- Mexico
- Standard or regulation:
- National Banking and Securities Commission (CNBV); Federal Law of Protection of Data in Possession of Individuals (LFDPPP)
- Regulatory regime:
- Not stated
- Outcome:
- Better monitoring and timely attack detection; IT role shifted from maintenance to value-added monitoring
"The bank needed to comply with regulations including National Banking and Securities Commission (CNBV), Federal Law of Protection of Data in Possession of Individuals (LFDPPP), and international standards." - "It changed the role of IT personnel from a maintenance and operational role to a monitoring role that allows adding value to the operation" - Luis Felipe Rubalcava, Deputy Director of Communications and Security, Compartamos Banco.
Verified live 2026-09-15, cross-checked across multiple Forcepoint locale mirrors for consistency. Compartamos Banco (Mexico's largest microfinance bank) is real and named, with a named executive quote. CNBV and LFDPPP are explicitly named regulations - stronger than initially reported (a candidate finding supplied separately said no regulation was named; the page does in fact name two). Mexico is outside the UK/EU/US/Canada regimes tracked by this workbook, so Regulatory regime stays Not stated despite the named regulations.
Does not prove: Added 2026-09-15. Web Security/DLP deployment, not SD-WAN/SASE. CNBV and LFDPPP are real named Mexican regulations but fall outside this workbook's tracked UK/EU/US/Canada regime columns.
forcepoint.com · Checked 15 Sept 2026 · Supports: Logging, audit and evidence retention, Cloud and SaaS data controls
- FIN-264RejectedProvider-authoredFinancial services solution page
Financial Services Cybersecurity | Forcepoint
- Named service:
- Forcepoint AI Data Security (DLP, DSPM, DDR, CASB, NGFW)
- Regulatory regime:
- Not stated
Your customers rely on you to keep their financial information safe.
This is a generic Forcepoint financial services marketing page naming three data-security customer stories (Fedbank, UCI, Vakifbank) but stating no specific regulation itself.
Does not prove: Duplicate of the same content at forcepoint.com/solutions/industry/financial-services; a generic industry page with no named institution or regulation on the page itself, so it is not usable as direct proof of any single column and is superseded by the solutions URL used below.
forcepoint.com · Published 29 Mar 2022 · Checked 12 Sept 2026
- FIN-266RejectedProvider-authoredOther
Forcepoint - Cybersecurity Solutions
- Named service:
- Forcepoint ONE; DLP; NGFW; SD-WAN; CASB
- Regulatory regime:
- Not stated
Forcepoint Trust Center
Corporate homepage used only to locate navigation links to the trust centre, compliance hub, industry and product pages; carries no evidentiary claims itself.
Does not prove: Navigation page only; used to find URLs, not as evidence for any of the 28 columns.
forcepoint.com · Checked 12 Sept 2026
- FIN-268RejectedProvider-authoredCompliance attestation or statement
- Named service:
- Forcepoint (corporate)
- Regulatory regime:
- Not stated
The Forcepoint Trust Center provides a centralized location to ask compliance and security questions and request access to our ISO Statement of Applicability and SOC 2 Type II certifications
A hub page that points to the Trust Center for ISO and SOC 2 documentation without naming individual products, dates, or any FS-specific regulation.
Does not prove: No named service, product-specific certification, regulation (DORA, FCA, NYDFS, OSFI, SWIFT), data residency or SLA content; too generic to support any single column.
forcepoint.com · Checked 12 Sept 2026
- FIN-272RejectedCustomer-authoredNamed customer case study
- Named financial institution:
- HDI Seguros
- Named service:
- Forcepoint DLP
- Countries, regions:
- Brazil (Latin America)
- Regulatory regime:
- Not stated
- Outcome:
- Automated data classification reducing false positives; rule enforcement across email and external drives
Forcepoint DLP (primary deployment); Forcepoint Web Security and Forcepoint CASB under evaluation
HDI Seguros, a Latin American insurer headquartered in Brazil, deployed Forcepoint DLP as its primary data-protection control, with Web Security and CASB under evaluation.
Does not prove: Quoted wording not found on the page in the 2026-09-12 check (Exact quoted structure not present; page separately mentions DLP deployment and Web Security/CASB under evaluation but not phrased this way.). Re-quote before accepting. CASB is described as under evaluation, not deployed; no specific regulation is named and Brazil is outside the schema's tracked UK/EU/US/Canada regimes. [2026-09-15 Harry review] Rejected 2026-09-15: the checker found CASB/Web Security is described on the page as "under evaluation", not deployed. A capability that a named customer is still evaluating is not evidence that the capability is delivered - Cloud and SaaS data controls cannot be supported by this source for HDI Seguros.
forcepoint.com · Checked 15 Sept 2026 · Supports: Cloud and SaaS data controls
- FIN-274RejectedCustomer-authoredNamed customer case study
UCI Customer Story | Forcepoint
- Named financial institution:
- UCI
- Named service:
- Forcepoint NGFW; Forcepoint cloud proxy
- Countries, regions:
- Spain, across four European countries
- Standard or regulation:
- GDPR
- Regulatory regime:
- EU
- Outcome:
- Decreased downtime and reduced costs through reliable connectivity
Forcepoint NGFW firewalls help us protect our most valuable asset: customer information. Now the IT department is able to undertake new projects and bring greater value to the company.
UCI, a Spain-based mortgage lender operating in four European countries, uses Forcepoint NGFW firewalls and a cloud proxy for consistent security policy and connectivity, driven by GDPR.
Does not prove: The named product is NGFW and a cloud proxy, not Forcepoint's SD-WAN or SASE (Forcepoint ONE) service, so this cannot be counted as SD-WAN/SASE branch connectivity evidence under the grading rules.
forcepoint.com · Published 16 Jul 2019 · Checked 12 Sept 2026 · Supports: Remote and hybrid workforce
- FIN-277RejectedProvider-authoredFinancial services solution page
- Named service:
- Forcepoint DLP
- Regulatory regime:
- Not stated
If your organization handles Personally Identifiable Information (PII), Protected Health Information (PHI), Payment Card Information (PCI)
Forcepoint's DLP product page mentions payment card information as a data type it can classify, and shows Visa and American Express customer logos, but names no FS case study, PCI DSS attestation or cardholder-data segmentation detail.
Does not prove: Customer logos (Visa, American Express) are not linked to any case study or quote and cannot be treated as a named deployment; no PCI DSS certification, encryption or FIPS detail is given on this page.
forcepoint.com · Checked 12 Sept 2026
- FIN-278RejectedProvider-authoredFinancial services solution page
Financial Services Data Security 2.0: Reinventing Risk and Compliance
- Named service:
- Forcepoint (general)
- Regulatory regime:
- Not stated
Financial Services Data Security 2.0: Reinventing Risk and Compliance
A gated ebook landing page with no DORA, FCA, PRA, GLBA, NYDFS, SEC, OSFI or SWIFT CSP reference in the accessible page content.
Does not prove: Only the landing page was accessible, not the full ebook text; no regulation named on the page itself, so it cannot be cited for any regulatory column.
forcepoint.com · Published 18 Feb 2025 · Checked 12 Sept 2026
- FIN-279RejectedProvider-authoredFinancial services solution page
- Named service:
- Forcepoint ONE
- Regulatory regime:
- Not stated
Forcepoint Cloud App Security
The Forcepoint ONE product page describes DLP, DSPM and DDR capabilities but contains no data residency, SLA/uptime, encryption, FIPS or ZTNA detail, and no financial services content beyond a navigation link.
Does not prove: No data residency, retention, SLA, FIPS or ZTNA detail found on this page for Forcepoint ONE despite it being the named SASE product; a dedicated datasheet or admin guide would be needed and none was reachable.
forcepoint.com · Checked 12 Sept 2026
Financial services requirements
Pick a requirement to see which providers are proven or partial for it and the source that supports each one.
Branch and office connectivity19 proven · 4 partial · 0 to review
Do not treat switching, Wi-Fi, data-centre, colocation or trading-floor LAN evidence as SD-WAN or SASE evidence unless the source makes that connection.
- Zscaler ProvenOneMain Financial, United States (checked 12 Sept 2026)
- Aryaka ProvenCalypso Technology, 18 countries (offices); 60+ countries (users) (checked 15 Sept 2026)
- Cato Networks ProvenGuardian Credit Union, United States (Alabama) (checked 12 Sept 2026)
- Versa Networks ProvenAutomating and Simplifying the WAN for Financial Services IT, United States, expanding into new markets (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE ProvenBanking on a More Secure Future with Prisma SASE - Palo Alto Networks, United States (Southeast and Mid-Atlantic regions) (checked 12 Sept 2026)
- Fortinet FortiSASE ProvenUSI Insurance Services, United States (checked 12 Sept 2026)
- BT ProvenBT Business - Financial services SD-WAN case study (Agile Connect + BT Managed Fortinet Firewall; anonymised global financial-services customer), More than 30 countries (checked 12 Sept 2026)
- AT&T Business ProvenCOCC, United States (checked 12 Sept 2026)
- Cisco ProvenBBVA Argentina, Argentina, described as a reference model being extended to BBVA entities in Colombia, Peru and the wider global group (checked 12 Sept 2026)
- Colt Technology Services ProvenByblos Bank Europe, Belgium, UK, France (checked 12 Sept 2026)
- Comcast Business ProvenAmerican Heritage Credit Union, Pennsylvania and New Jersey, USA (checked 15 Sept 2026)
- Vodafone Business ProvenA network adapted to your needs: transforming a financial services business with SD-WAN (checked 12 Sept 2026)
- Orange Business ProvenBNP Paribas, France (checked 12 Sept 2026)
- Verizon Business ProvenFinancial Services Network Case Study (leading bank) | Verizon Business (checked 12 Sept 2026)
- VeloCloud ProvenVeloCloud SD-WAN for Financial Services - Solution Brief (PDF) (checked 12 Sept 2026)
- HPE Aruba EdgeConnect ProvenFirst Bank, Missouri, Illinois, California, United States (checked 12 Sept 2026)
- Lumen ProvenHanmi Bank, United States (checked 12 Sept 2026)
- NTT DATA ProvenBoursorama Banque, France (French and European sites) (checked 15 Sept 2026)
- Juniper Networks ProvenSeacoast Bank, United States (Florida) (checked 15 Sept 2026)
- GTT PartialGTT Finance and Insurance Solutions (checked 12 Sept 2026)
- Ericsson Cradlepoint PartialWireless Edge Solutions for Financial Services | Ericsson (checked 15 Sept 2026)
- Check Point PartialCheck Point Software Introduces Quantum SD-WAN to Protect Branch Offices Unifying Best Security and Optimized Internet Connectivity (checked 12 Sept 2026)
- Open Systems PartialFinancial services company customer story (anonymised), Switzerland, Ireland, Singapore (checked 15 Sept 2026)
Trading and low-latency connectivity1 proven · 3 partial · 0 to review
Do not treat switching, Wi-Fi, data-centre, colocation or trading-floor LAN evidence as SD-WAN or SASE evidence unless the source makes that connection.
- GTT ProvenSaxo Bank, UK; Denmark (checked 12 Sept 2026)
- AT&T Business PartialTransforming the Network in Financial Services (Fall 2022), Not stated (checked 12 Sept 2026)
- Colt Technology Services PartialFinancial Extranet | Colt Capital Markets, Europe, Asia and US (checked 12 Sept 2026)
- Juniper Networks Partial
Data-centre, colocation and cloud connectivity9 proven · 13 partial · 0 to review
Do not treat switching, Wi-Fi, data-centre, colocation or trading-floor LAN evidence as SD-WAN or SASE evidence unless the source makes that connection.
- Cloudflare One ProvenBank of Cyprus, Cyprus (checked 12 Sept 2026)
- Zscaler ProvenFannie Mae, United States (checked 12 Sept 2026)
- Cato Networks ProvenStandard Insurance, Philippines (checked 12 Sept 2026)
- Versa Networks ProvenGlobal Financial Services Firm case study, Global (checked 15 Sept 2026)
- Comcast Business ProvenAmerican Heritage Credit Union, Pennsylvania and New Jersey, USA (checked 15 Sept 2026)
- HPE Aruba EdgeConnect ProvenUnified SASE in financial services (checked 29 Jul 2026)
- Lumen ProvenCredit Benchmark, UK (Credit Benchmark is London-headquartered) (checked 15 Sept 2026)
- Virgin Media O2 Business ProvenRoyal London Group, UK and Isle of Man (checked 15 Sept 2026)
- Juniper Networks ProvenFirst Bank, Not stated (checked 15 Sept 2026)
- Netskope PartialSecure SD-WAN | Netskope One SASE Branch | Netskope, 75+ regions (checked 12 Sept 2026)
- Barracuda SecureEdge PartialPCI DSS Compliance with Barracuda CloudGen Firewall (checked 12 Sept 2026)
- Aryaka PartialCalypso Technology, 18 countries (offices); 60+ countries (users) (checked 15 Sept 2026)
- GTT PartialSaxo Bank, UK; Denmark (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE PartialBanking on a More Secure Future with Prisma SASE - Palo Alto Networks, United States (Southeast and Mid-Atlantic regions) (checked 12 Sept 2026)
- Fortinet FortiSASE PartialFortiSASE Product Page, Global (200+ PoPs) (checked 15 Sept 2026)
- AT&T Business PartialAT&T Global Business Services | Internet Connectivity, Networking & Wireless, 200 countries and territories; Canada since 1980; EMEA; APAC; Latin America and Caribbean (checked 12 Sept 2026)
- Cisco PartialBBVA Argentina, Argentina, described as a reference model being extended to BBVA entities in Colombia, Peru and the wider global group (checked 12 Sept 2026)
- Colt Technology Services PartialFinancial Extranet | Colt Capital Markets, Europe, Asia and US (checked 12 Sept 2026)
- Vodafone Business PartialA network adapted to your needs: transforming a financial services business with SD-WAN (checked 12 Sept 2026)
- Orange Business PartialTMF Group, Brazil, Costa Rica, France, Singapore (checked 12 Sept 2026)
- VeloCloud PartialArista Networks - SD-WAN & Edge Routing (VeloCloud SD-WAN solution page) (checked 12 Sept 2026)
- Expereo PartialManaged SD-WAN - Expereo (checked 12 Sept 2026)
Resilience and tested recovery10 proven · 16 partial · 0 to review
- Cloudflare One ProvenBank of Cyprus, Cyprus (checked 12 Sept 2026)
- Aryaka ProvenCalypso Technology, 18 countries (offices); 60+ countries (users) (checked 15 Sept 2026)
- Versa Networks ProvenGlobal Financial Services Firm case study, Global (checked 15 Sept 2026)
- Palo Alto Networks Prisma SASE ProvenBanking on a More Secure Future with Prisma SASE - Palo Alto Networks, United States (Southeast and Mid-Atlantic regions) (checked 12 Sept 2026)
- AT&T Business ProvenCOCC, United States (checked 12 Sept 2026)
- Comcast Business ProvenAmerican Heritage Credit Union, Pennsylvania and New Jersey, USA (checked 15 Sept 2026)
- Orange Business ProvenBNP Paribas, France (checked 12 Sept 2026)
- Verizon Business ProvenFinancial Services Network Case Study (leading bank) | Verizon Business (checked 12 Sept 2026)
- HPE Aruba EdgeConnect ProvenUnified SASE in financial services (checked 29 Jul 2026)
- Lumen ProvenEnterprise SD-WAN Solutions | Lumen Technologies (checked 12 Sept 2026)
- Zscaler PartialZscaler SLA Support | Service Level Agreement Documentation (checked 12 Sept 2026)
- Netskope PartialNewEdge Network | Netskope, 80+ regions, 220+ countries and territories (checked 15 Sept 2026)
- Barracuda SecureEdge PartialProduct & Service Description - SecureEdge Appliances and SaaS Service, US, EMEA (West Europe), plus additional PoPs across Europe, Middle East, Americas and APAC (checked 12 Sept 2026)
- Cato Networks PartialService Level Agreement (checked 12 Sept 2026)
- GTT PartialGTT Finance and Insurance Solutions (checked 12 Sept 2026)
- Fortinet FortiSASE PartialUSI Insurance Services, United States (checked 12 Sept 2026)
- BT PartialBT Business - Financial services SD-WAN case study (Agile Connect + BT Managed Fortinet Firewall; anonymised global financial-services customer), More than 30 countries (checked 12 Sept 2026)
- Cisco PartialOffer Description - Cisco Catalyst SD-WAN (checked 12 Sept 2026)
- Colt Technology Services PartialByblos Bank Europe, Belgium, UK, France (checked 12 Sept 2026)
- Vodafone Business PartialA network adapted to your needs: transforming a financial services business with SD-WAN (checked 12 Sept 2026)
- SonicWall Cloud Secure Edge PartialSD-WAN Solutions for Enterprise Network Security | SonicWall (checked 12 Sept 2026)
- VeloCloud PartialVeloCloud SD-WAN for Financial Services - Solution Brief (PDF) (checked 12 Sept 2026)
- Ericsson Cradlepoint Partial
- Check Point PartialCheck Point SASE Platform (Formerly Harmony SASE) - Check Point Software (checked 15 Sept 2026)
- Virgin Media O2 Business PartialRoyal London Group, UK and Isle of Man (checked 15 Sept 2026)
- Juniper Networks Partial
Network segmentation and zoning6 proven · 16 partial · 0 to review
Do not treat switching, Wi-Fi, data-centre, colocation or trading-floor LAN evidence as SD-WAN or SASE evidence unless the source makes that connection.
- Zscaler ProvenHastings Direct, United Kingdom (East Sussex) (checked 12 Sept 2026)
- Versa Networks ProvenAutomating and Simplifying the WAN for Financial Services IT, United States, expanding into new markets (checked 12 Sept 2026)
- AT&T Business ProvenCOCC, United States (10 states) (checked 12 Sept 2026)
- Cisco ProvenBBVA Argentina, Argentina, described as a reference model being extended to BBVA entities in Colombia, Peru and the wider global group (checked 12 Sept 2026)
- Orange Business ProvenBNP Paribas, France (checked 15 Sept 2026)
- VeloCloud ProvenVeloCloud SD-WAN for Financial Services - Solution Brief (PDF) (checked 12 Sept 2026)
- Netskope PartialSecure SD-WAN | Netskope One SASE Branch | Netskope, 75+ regions (checked 12 Sept 2026)
- Barracuda SecureEdge PartialPCI DSS Compliance with Barracuda CloudGen Firewall (checked 12 Sept 2026)
- Cato Networks PartialBank Avera, Switzerland (greater Zurich area) (checked 12 Sept 2026)
- GTT PartialGTT Finance and Insurance Solutions (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE PartialFinancial Services - Palo Alto Networks (checked 12 Sept 2026)
- Fortinet FortiSASE PartialFortinet Secure SD-WAN, Not stated (checked 15 Sept 2026)
- BT PartialBT Business - Financial services SD-WAN case study (Agile Connect + BT Managed Fortinet Firewall; anonymised global financial-services customer), More than 30 countries (checked 12 Sept 2026)
- Colt Technology Services PartialSD WAN in Banking & Financial Services - Colt Technology Services, Germany and international locations (checked 12 Sept 2026)
- Comcast Business PartialMasergy SD-WAN ver. 1 - Comcast Enterprise Services Product Specific Attachment, United States, Alaska, Hawaii and Canada (checked 12 Sept 2026)
- Vodafone Business Partial
- SonicWall Cloud Secure Edge PartialHow SonicWall Solutions Can Help You Become PCI DSS Compliant (checked 12 Sept 2026)
- Verizon Business PartialManaged SD WAN: Wiser WAN Solution | Verizon Solutions (checked 12 Sept 2026)
- HPE Aruba EdgeConnect Partial
- Virgin Media O2 Business Partial
- Expereo PartialEnhancing Network Security With SD-WAN - Expereo (checked 12 Sept 2026)
- Forcepoint Partial
Payment and cardholder data segmentation1 proven · 10 partial · 0 to review
Do not treat switching, Wi-Fi, data-centre, colocation or trading-floor LAN evidence as SD-WAN or SASE evidence unless the source makes that connection.
- AT&T Business ProvenCOCC, United States (10 states) (checked 12 Sept 2026)
- Zscaler PartialSASE Solutions for PCI DSS 4.0 Compliance & Enhanced Security (checked 12 Sept 2026)
- Netskope PartialPCI-DSS Cloud Compliance | Netskope (checked 12 Sept 2026)
- Barracuda SecureEdge PartialPCI DSS Compliance with Barracuda CloudGen Firewall (checked 12 Sept 2026)
- Versa Networks PartialPCI-DSS Compliance with Versa Secure SD-WAN (checked 12 Sept 2026)
- GTT PartialGTT Finance and Insurance Solutions (checked 12 Sept 2026)
- BT PartialNationwide Building Society, UK (checked 12 Sept 2026)
- SonicWall Cloud Secure Edge PartialHow SonicWall Solutions Can Help You Become PCI DSS Compliant (checked 12 Sept 2026)
- VeloCloud PartialVeloCloud SD-WAN for Financial Services - Solution Brief (PDF) (checked 12 Sept 2026)
- Ericsson Cradlepoint PartialEricsson Enterprise Wireless Configuration Guidance for PCI DSS Compliance (checked 15 Sept 2026)
- HPE Aruba EdgeConnect PartialHow the EdgeConnect SD-WAN Platform Supports PCI DSS Compliance (checked 12 Sept 2026)
Third-party and outsourced access0 proven · 12 partial · 0 to review
- Cloudflare One PartialCloudflare Data Processing Addendum | Cloudflare (checked 12 Sept 2026)
- Zscaler PartialZscaler Sub-Processors: Security & Privacy Standards (checked 12 Sept 2026)
- Netskope PartialApex Group, 42 countries and legal jurisdictions (checked 12 Sept 2026)
- Cato Networks Partial
- GTT PartialGTT Finance and Insurance Solutions (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE PartialFinancial Services - Palo Alto Networks (checked 12 Sept 2026)
- Fortinet FortiSASE Partial
- Comcast Business PartialComcast Business Privacy Center (checked 12 Sept 2026)
- Vodafone Business PartialUse cases: Vodafone Business Secure Access Service Edge (SASE) (checked 14 Sept 2026)
- SonicWall Cloud Secure Edge PartialSonicWall Trust Center | Powered by SafeBase (checked 12 Sept 2026)
- Check Point Partial
- Open Systems PartialFinancial Services SASE solution (checked 12 Sept 2026)
Remote and hybrid workforce8 proven · 15 partial · 0 to review
Do not treat switching, Wi-Fi, data-centre, colocation or trading-floor LAN evidence as SD-WAN or SASE evidence unless the source makes that connection.
- Cloudflare One ProvenMoneybox, United Kingdom (checked 12 Sept 2026)
- Zscaler ProvenHastings Direct, United Kingdom (East Sussex) (checked 12 Sept 2026)
- Aryaka ProvenCalypso Technology, 18 countries (offices); 60+ countries (users) (checked 15 Sept 2026)
- Cato Networks ProvenGuardian Credit Union, United States (Alabama) (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE ProvenFinancial Services - Palo Alto Networks (checked 12 Sept 2026)
- Fortinet FortiSASE ProvenVietnamese Bank Case Study, Vietnam (checked 12 Sept 2026)
- SonicWall Cloud Secure Edge ProvenLemonade, United States (checked 12 Sept 2026)
- Check Point ProvenAegean Baltic Bank, Greece (checked 15 Sept 2026)
- Netskope PartialApex Group, 42 countries and legal jurisdictions (checked 12 Sept 2026)
- Barracuda SecureEdge PartialZero Trust Network Access Solution & Security Platform | Barracuda Networks (checked 12 Sept 2026)
- Versa Networks PartialGlobal Credit Card Payments Company Modernizes WAN (checked 12 Sept 2026)
- AT&T Business PartialTransforming the Network in Financial Services (Fall 2022), Not stated (checked 12 Sept 2026)
- Cisco PartialCisco Secure Access Data Sheet - Cisco (checked 12 Sept 2026)
- Colt Technology Services PartialSD WAN & SASE | Colt Technology Services (checked 12 Sept 2026)
- Vodafone Business PartialUse cases: Vodafone Business Secure Access Service Edge (SASE) (checked 14 Sept 2026)
- Orange Business PartialSecurity for Financial Services & Insurance, Not stated (checked 12 Sept 2026)
- Verizon Business PartialRetail Banking Network Technology Case Study | Verizon Business, United States (10-state regional banking presence) (checked 12 Sept 2026)
- Ericsson Cradlepoint Partial
- Open Systems PartialFinancial services company customer story (anonymised), Switzerland, Ireland, Singapore (checked 15 Sept 2026)
- Lumen PartialFinancial Services and Banking IT Solutions | Lumen, United States (checked 12 Sept 2026)
- Virgin Media O2 Business Partial
- Expereo PartialManaged SD-WAN - Expereo (checked 12 Sept 2026)
- Forcepoint Partial
Data residency and sovereignty7 proven · 10 partial · 0 to review
- Cloudflare One ProvenCloudflare for Financial Services (checked 12 Sept 2026)
- Netskope ProvenData Transfer at Netskope | Netskope, United States, EU, UK, Australia, Saudi Arabia, Switzerland, Singapore (checked 12 Sept 2026)
- Barracuda SecureEdge ProvenData Center Locations - Barracuda Trust Center, UK, EU (multiple), US, Canada, and other global regions (checked 12 Sept 2026)
- Cato Networks ProvenSASE Sovereignty at Cato Networks, US, EU, India, Japan (control plane); UK, Germany, Netherlands, Italy, France, Singapore, Australia, Philippines, Israel (regional legal entities) (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE ProvenStrata Logging Service Regions, United States, Canada, United Kingdom, Netherlands, France, Germany, Italy, Poland, Spain, Switzerland, Australia, Japan, Korea, Singapore, Taiwan, India, Indonesia, Israel, Qatar, Saudi Arabia, South Africa, China, US Government (checked 12 Sept 2026)
- BT ProvenBT Business - Managed SASE Solutions page (sector-specific positioning: retail, financial services, public sector; SASE cloud node architecture), UK (checked 12 Sept 2026)
- Vodafone Business ProvenC2 General SOC & SIEM Vodafone Business Security Enhanced - Terms and Conditions, UK / EEA (checked 14 Sept 2026)
- Zscaler PartialUnderstanding Digital Sovereignty in the Modern Era, United States, European Union, and other regions via Private Service Edges (checked 12 Sept 2026)
- Aryaka PartialSecurity FAQs | Universal ZTNA, AI Secure & Next-Gen DLP | Aryaka (checked 12 Sept 2026)
- Versa Networks PartialPrivacy Policy | Versa Networks, Global (checked 15 Sept 2026)
- GTT PartialGTT Finance and Insurance Solutions (checked 12 Sept 2026)
- Fortinet FortiSASE Partial
- Cisco PartialCisco and GDPR - Cisco, EEA, UK, Switzerland (cross-border transfer mechanisms) (checked 12 Sept 2026)
- Colt Technology Services PartialSD WAN & SASE | Colt Technology Services (checked 12 Sept 2026)
- Orange Business PartialSto, Norway, with expansion referenced to Denmark, Italy, Spain and South America (checked 12 Sept 2026)
- Ericsson Cradlepoint PartialPrivacy Policy - January 31, 2024 | Archive - Cradlepoint, United States; European Economic Area; Australia (checked 12 Sept 2026)
- Check Point PartialSub-Processors List - Check Point Software, US, EU, India, Australia (per sub-processor) (checked 12 Sept 2026)
Encryption and key management14 proven · 12 partial · 0 to review
- Cloudflare One ProvenCloudflare Data Localization Suite | Cloudflare (checked 15 Sept 2026)
- Zscaler ProvenZscaler's Compliance Center (checked 14 Sept 2026)
- Barracuda SecureEdge ProvenProduct & Service Description - SecureEdge Appliances and SaaS Service, US, EMEA (West Europe), plus additional PoPs across Europe, Middle East, Americas and APAC (checked 12 Sept 2026)
- Aryaka ProvenFIPS Compliance Readiness For Federal Customers (checked 12 Sept 2026)
- Versa Networks ProvenPCI-DSS Compliance with Versa Secure SD-WAN (checked 12 Sept 2026)
- AT&T Business ProvenCOCC, United States (10 states) (checked 12 Sept 2026)
- Cisco ProvenCisco Catalyst SD-WAN v20.15 FIPS 140-3 Compliance (checked 12 Sept 2026)
- Comcast Business ProvenMasergy SD-WAN ver. 1 - Comcast Enterprise Services Product Specific Attachment, United States, Alaska, Hawaii and Canada (checked 12 Sept 2026)
- SonicWall Cloud Secure Edge ProvenGovernment Federal Certifications: Federal Information Processing Standard (FIPS) 140-2 | SonicWall (checked 12 Sept 2026)
- VeloCloud ProvenArista Networks - SD-WAN & Edge Routing (VeloCloud SD-WAN solution page) (checked 12 Sept 2026)
- Ericsson Cradlepoint ProvenEricsson - blog: Ericsson achieves four regulatory certifications and attestations to deliver trusted, secure cloud solutions (ISO 27001, FIPS 140, audit detail: 62 controls/10 IT services/'Unmodified Opinion') (checked 15 Sept 2026)
- HPE Aruba EdgeConnect ProvenCMVP Certificate #4547 - Silver Peak EdgeConnect (checked 15 Sept 2026)
- Lumen ProvenCredit Benchmark, UK (Credit Benchmark is London-headquartered) (checked 15 Sept 2026)
- NTT DATA ProvenBoursorama Banque, France (French and European sites) (checked 15 Sept 2026)
- Cato Networks PartialSecurity, Compliance and Privacy | Cato Networks (checked 12 Sept 2026)
- GTT PartialManaged SD-WAN | GTT (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE PartialCompliance - Palo Alto Networks (checked 12 Sept 2026)
- Fortinet FortiSASE Partial
- BT PartialBT Managed Fortinet SD-WAN (Annex to Managed Services Schedule), USA, UK, India, Canada, UAE, Germany, France, Singapore, Australia, Japan (checked 12 Sept 2026)
- Colt Technology Services PartialSD WAN in Banking & Financial Services - Colt Technology Services, Germany and international locations (checked 12 Sept 2026)
- Vodafone Business Partial
- Orange Business PartialFlexible SD-WAN, more than 220 countries and territories (checked 12 Sept 2026)
- Verizon Business PartialVerizon Secure Cloud Gateway fact sheet (checked 12 Sept 2026)
- Open Systems PartialPrivacy Statement (checked 12 Sept 2026)
- Virgin Media O2 Business PartialSD-WAN for Enterprise | Virgin Media O2 Business (checked 12 Sept 2026)
- Forcepoint PartialForcepoint Trust Center (checked 12 Sept 2026)
Logging, audit and evidence retention7 proven · 10 partial · 0 to review
- Cloudflare One ProvenEnabling log retention - Cloudflare Logs docs (checked 12 Sept 2026)
- Barracuda SecureEdge ProvenProduct & Service Description - SecureEdge Appliances and SaaS Service, US, EMEA (West Europe), plus additional PoPs across Europe, Middle East, Americas and APAC (checked 12 Sept 2026)
- Cato Networks ProvenGuide to Cato Data Lake (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE ProvenAllocate Log Retention Days - Strata Logging Service (checked 12 Sept 2026)
- SonicWall Cloud Secure Edge ProvenLemonade, United States (checked 12 Sept 2026)
- Ericsson Cradlepoint ProvenAccessing and Viewing the Activity Log - Cradlepoint (checked 12 Sept 2026)
- NTT DATA ProvenFamily Bank Kenya, Kenya (checked 15 Sept 2026)
- Zscaler PartialZscaler Nanolog Streaming Service data sheet (checked 12 Sept 2026)
- Netskope Partial
- Aryaka PartialSecurity FAQs | Universal ZTNA, AI Secure & Next-Gen DLP | Aryaka (checked 12 Sept 2026)
- Versa Networks PartialPCI-DSS Compliance with Versa Secure SD-WAN (checked 12 Sept 2026)
- GTT PartialSecurity and Compliance | GTT, Prague; Pune (checked 12 Sept 2026)
- AT&T Business Partial
- Vodafone Business PartialC2 General SOC & SIEM Vodafone Business Security Enhanced - Terms and Conditions, UK / EEA (checked 14 Sept 2026)
- Check Point PartialCheck Point SASE for Insurance Providers (checked 15 Sept 2026)
- Open Systems PartialAudit readiness and compliance blog post (checked 12 Sept 2026)
- Forcepoint PartialForcepoint cybersecurity solutions for banks (Financial Services industry page) (checked 12 Sept 2026)
Identity and zero trust access7 proven · 21 partial · 0 to review
- Cloudflare One ProvenInvestec, South Africa, United Kingdom (checked 12 Sept 2026)
- Netskope ProvenApex Group, 42 countries and legal jurisdictions (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE ProvenLemonade Insurance (checked 12 Sept 2026)
- Cisco ProvenBBVA Argentina, Argentina, described as a reference model being extended to BBVA entities in Colombia, Peru and the wider global group (checked 12 Sept 2026)
- Colt Technology Services ProvenByblos Bank Europe, Belgium, UK, France (checked 12 Sept 2026)
- SonicWall Cloud Secure Edge ProvenLemonade, United States (checked 12 Sept 2026)
- Juniper Networks ProvenSecure Access Service Edge (SASE) Solutions | HPE Juniper Networking US (checked 12 Sept 2026)
- Zscaler Partial
- Barracuda SecureEdge PartialZero Trust Network Access Solution & Security Platform | Barracuda Networks (checked 12 Sept 2026)
- Aryaka PartialSecurity FAQs | Universal ZTNA, AI Secure & Next-Gen DLP | Aryaka (checked 12 Sept 2026)
- Cato Networks PartialUniversal ZTNA | Cato Networks (checked 12 Sept 2026)
- Versa Networks PartialPCI-DSS Compliance with Versa Secure SD-WAN (checked 12 Sept 2026)
- GTT PartialManaged SD-WAN | GTT (checked 12 Sept 2026)
- Fortinet FortiSASE PartialFortiSASE Product Page, Global (200+ PoPs) (checked 15 Sept 2026)
- BT PartialNationwide (checked 15 Sept 2026)
- AT&T Business PartialManaged SASE Cybersecurity Network Solution | AT&T Business, Not stated (checked 15 Sept 2026)
- Comcast Business PartialComcast Business - Secure Access Service Edge (SASE) product page (cloud-native SASE infrastructure, AI-enhanced orchestration, MEF 3.0/MEF 70 certification, Gartner Magic Quadrant recognitions, Frost & Sullivan 2024 Leader) (checked 12 Sept 2026)
- Vodafone Business PartialZscaler Cloud Security Solutions | Vodafone UK (checked 12 Sept 2026)
- Verizon Business PartialSecure Access Service Edge (SASE) Solutions | Verizon (checked 12 Sept 2026)
- VeloCloud PartialArista Networks - SD-WAN & Edge Routing (VeloCloud SD-WAN solution page) (checked 12 Sept 2026)
- Ericsson Cradlepoint PartialWireless Edge Solutions for Financial Services | Ericsson (checked 15 Sept 2026)
- Check Point PartialCheck Point SASE for Insurance Providers (checked 15 Sept 2026)
- Open Systems PartialFinancial Services SASE solution (checked 12 Sept 2026)
- HPE Aruba EdgeConnect Partial
- Lumen PartialFinancial Services and Banking IT Solutions | Lumen, United States (checked 12 Sept 2026)
- NTT DATA PartialNTT DATA (services.global.ntt) - Managed Campus Networks with Prisma SASE product page (named Palo Alto Networks Prisma SASE platform partnership) (checked 12 Sept 2026)
- Virgin Media O2 Business Partial
- Expereo PartialSase - Expereo (checked 12 Sept 2026)
Cloud and SaaS data controls3 proven · 21 partial · 0 to review
- Netskope ProvenApex Group, 42 countries and legal jurisdictions (checked 12 Sept 2026)
- Cato Networks ProvenMoonPay (checked 12 Sept 2026)
- Forcepoint ProvenVAKIFBANK, Turkey, with international offices in the US, Qatar, Bahrain and Austria (checked 12 Sept 2026)
- Cloudflare One PartialCloudflare Data Loss Prevention (DLP) | Secure sensitive data | Cloudflare (checked 12 Sept 2026)
- Zscaler Partial
- Aryaka PartialSecurity FAQs | Universal ZTNA, AI Secure & Next-Gen DLP | Aryaka (checked 12 Sept 2026)
- Versa Networks PartialFinancial Services Solution | Versa Networks, Global (checked 12 Sept 2026)
- GTT PartialSASE Secure Connect | GTT (checked 12 Sept 2026)
- Fortinet FortiSASE PartialFortiSASE Product Page, Global (200+ PoPs) (checked 15 Sept 2026)
- BT PartialNationwide (checked 15 Sept 2026)
- AT&T Business PartialManaged SASE Cybersecurity Network Solution | AT&T Business, Not stated (checked 15 Sept 2026)
- Cisco PartialMyInvestor, Spain (checked 12 Sept 2026)
- Comcast Business PartialComcast Business - Secure Access Service Edge (SASE) product page (cloud-native SASE infrastructure, AI-enhanced orchestration, MEF 3.0/MEF 70 certification, Gartner Magic Quadrant recognitions, Frost & Sullivan 2024 Leader) (checked 12 Sept 2026)
- Vodafone Business PartialZscaler Cloud Security Solutions | Vodafone UK (checked 12 Sept 2026)
- SonicWall Cloud Secure Edge PartialLemonade, United States (checked 12 Sept 2026)
- Orange Business PartialTMF Group, Brazil, Costa Rica, France, Singapore (checked 12 Sept 2026)
- Verizon Business PartialSecure Access Service Edge (SASE) Solutions | Verizon (checked 12 Sept 2026)
- VeloCloud PartialSD-WAN and Cloud WAN - Arista (checked 12 Sept 2026)
- Check Point PartialCheck Point SASE for Insurance Providers (checked 15 Sept 2026)
- Open Systems PartialEnabling Qapital Ltd., Switzerland (global asset base) (checked 12 Sept 2026)
- HPE Aruba EdgeConnect Partial
- Lumen PartialLumen SASE Solutions (checked 12 Sept 2026)
- Virgin Media O2 Business Partial
- Expereo PartialSase - Expereo (checked 12 Sept 2026)
Managed operations and SOC6 proven · 10 partial · 0 to review
- Aryaka ProvenCalypso Technology, 18 countries (offices); 60+ countries (users) (checked 15 Sept 2026)
- Fortinet FortiSASE ProvenUSI Insurance Services, United States (checked 12 Sept 2026)
- BT ProvenNationwide Building Society, UK (checked 12 Sept 2026)
- AT&T Business ProvenSD-WAN Service Provider - Software Defined Wide Area Network at AT&T Business, 150+ countries and territories (checked 12 Sept 2026)
- Orange Business ProvenTMF Group, Brazil, Costa Rica, France, Singapore (checked 12 Sept 2026)
- Open Systems ProvenFinancial Services SASE solution (checked 12 Sept 2026)
- Netskope PartialApex Group, 42 countries and legal jurisdictions (checked 12 Sept 2026)
- GTT PartialSASE Secure Connect | GTT (checked 12 Sept 2026)
- Colt Technology Services PartialFinancial Extranet | Colt Capital Markets, Europe, Asia and US (checked 12 Sept 2026)
- Comcast Business PartialFinancial Services Solutions | Comcast Business, United States (checked 12 Sept 2026)
- Vodafone Business PartialC2 General SOC & SIEM Vodafone Business Security Enhanced - Terms and Conditions, UK / EEA (checked 14 Sept 2026)
- Verizon Business PartialManaged SD WAN Solutions and Services | Verizon (checked 12 Sept 2026)
- Lumen PartialHanmi Bank, United States (checked 12 Sept 2026)
- NTT DATA PartialNTT DATA (services.global.ntt) - Managed Network Services product page (named Pick n Pay rolling-blackout SD-WAN case reference) (checked 12 Sept 2026)
- Virgin Media O2 Business PartialVirgin Media O2 Business launches enhanced cloud and security solutions services following a new partnership with Telefonica Tech (checked 12 Sept 2026)
- Expereo PartialSupport - Expereo, US, South America, Europe, Middle East, Asia (checked 12 Sept 2026)
Network visibility and reporting11 proven · 15 partial · 0 to review
- Zscaler ProvenABANCA, Spain and 11 countries (checked 12 Sept 2026)
- Netskope ProvenApex Group, 42 countries and legal jurisdictions (checked 12 Sept 2026)
- Aryaka ProvenCalypso Technology, 18 countries (offices); 60+ countries (users) (checked 15 Sept 2026)
- Cato Networks ProvenGuardian Credit Union, United States (Alabama) (checked 12 Sept 2026)
- Versa Networks ProvenAutomating and Simplifying the WAN for Financial Services IT, United States, expanding into new markets (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE ProvenBanking on a More Secure Future with Prisma SASE - Palo Alto Networks, United States (Southeast and Mid-Atlantic regions) (checked 12 Sept 2026)
- Fortinet FortiSASE ProvenUSI Insurance Services, United States (checked 12 Sept 2026)
- Cisco ProvenBBVA Argentina, Argentina, described as a reference model being extended to BBVA entities in Colombia, Peru and the wider global group (checked 12 Sept 2026)
- Colt Technology Services ProvenLeading global investment bank - Colt's SD WAN solutions for Finance, Europe (checked 15 Sept 2026)
- Comcast Business ProvenSTAR Financial Bank, Central and northeast Indiana, USA (checked 12 Sept 2026)
- NTT DATA ProvenNTT DATA (services.global.ntt) - Managed Network Services product page (named Pick n Pay rolling-blackout SD-WAN case reference) (checked 12 Sept 2026)
- Barracuda SecureEdge PartialBarracuda SecureEdge: Features | Barracuda Networks (checked 12 Sept 2026)
- GTT PartialGTT Envision | GTT (checked 12 Sept 2026)
- BT PartialBT Business - Financial services SD-WAN case study (Agile Connect + BT Managed Fortinet Firewall; anonymised global financial-services customer), More than 30 countries (checked 12 Sept 2026)
- AT&T Business PartialSD-WAN Service Provider - Software Defined Wide Area Network at AT&T Business, 150+ countries and territories (checked 12 Sept 2026)
- Vodafone Business PartialVodafone Business SD-WAN with Cisco | Fixed connectivity (checked 15 Sept 2026)
- SonicWall Cloud Secure Edge PartialSonicWall - Cyber Security for Financial Services (checked 12 Sept 2026)
- Orange Business PartialFlexible SD-WAN, more than 220 countries and territories (checked 12 Sept 2026)
- Verizon Business PartialManaged SD WAN Solutions and Services | Verizon (checked 12 Sept 2026)
- VeloCloud PartialVeloCloud SD-WAN for Financial Services - Solution Brief (PDF) (checked 12 Sept 2026)
- Ericsson Cradlepoint PartialEricsson NetCloud SASE and NetCloud Exchange | Ericsson (checked 12 Sept 2026)
- Check Point PartialCheck Point SASE for Insurance Providers (checked 15 Sept 2026)
- Open Systems PartialFinancial Services SASE solution (checked 12 Sept 2026)
- Virgin Media O2 Business PartialSD-WAN for Enterprise | Virgin Media O2 Business (checked 12 Sept 2026)
- Juniper Networks PartialWAN Assurance Cloud Service | HPE (checked 12 Sept 2026)
- Expereo PartialexpereoOne platform - Total visibility & control through a single view (checked 12 Sept 2026)
Change control and configuration governance6 proven · 6 partial · 0 to review
- Barracuda SecureEdge ProvenBarracuda SecureEdge: Features | Barracuda Networks (checked 12 Sept 2026)
- GTT ProvenSecurity and Compliance | GTT, Prague; Pune (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE ProvenJovia Financial Credit Union, United States (New York) (checked 15 Sept 2026)
- Fortinet FortiSASE ProvenCEC Bank, Romania (checked 15 Sept 2026)
- BT ProvenBT Managed Fortinet SD-WAN (Annex to Managed Services Schedule), USA, UK, India, Canada, UAE, Germany, France, Singapore, Australia, Japan (checked 12 Sept 2026)
- Cisco ProvenBBVA Argentina, Argentina, described as a reference model being extended to BBVA entities in Colombia, Peru and the wider global group (checked 12 Sept 2026)
- Versa Networks PartialAutomating and Simplifying the WAN for Financial Services IT, United States, expanding into new markets (checked 12 Sept 2026)
- Orange Business PartialOrange Business SOC 2 Type II (checked 15 Sept 2026)
- Verizon Business PartialManaged SD WAN Solutions and Services | Verizon (checked 12 Sept 2026)
- Ericsson Cradlepoint PartialFoundational security | Ericsson (checked 12 Sept 2026)
- Check Point PartialCheck Point SASE for Insurance Providers (checked 15 Sept 2026)
- NTT DATA PartialNTT DATA (services.global.ntt) - Managed Network Services product page (named Pick n Pay rolling-blackout SD-WAN case reference) (checked 12 Sept 2026)
Incident notification support3 proven · 7 partial · 0 to review
- Cloudflare One ProvenEU - Digital Operational Resilience Act (DORA) mapping (checked 15 Sept 2026)
- Aryaka ProvenAryaka Service Level Agreement: Definitions And Details (checked 12 Sept 2026)
- Vodafone Business ProvenC2 General SOC & SIEM Vodafone Business Security Enhanced - Terms and Conditions, UK / EEA (checked 14 Sept 2026)
- Barracuda SecureEdge PartialSecurity - Barracuda Trust Center (checked 12 Sept 2026)
- Cato Networks PartialGuardian Credit Union, United States (checked 12 Sept 2026)
- Versa Networks PartialService Level Agreement (Versa Hosted and Managed Secure Services Edge Gateways) (checked 12 Sept 2026)
- AT&T Business Partial
- Comcast Business PartialComcast Business Information Security Standards (checked 12 Sept 2026)
- SonicWall Cloud Secure Edge PartialSonicWall Trust Center | Powered by SafeBase (checked 12 Sept 2026)
- Ericsson Cradlepoint PartialEnd User Agreement | NetCloud Manager Services | Cradlepoint (checked 12 Sept 2026)
Concentration risk and subcontractor transparency7 proven · 7 partial · 0 to review
- Zscaler ProvenZscaler Sub-Processors: Security & Privacy Standards (checked 12 Sept 2026)
- Netskope ProvenSub-processors | Netskope (checked 12 Sept 2026)
- Barracuda SecureEdge ProvenSupplier Information - Barracuda Trust Center (checked 12 Sept 2026)
- Cato Networks ProvenCato Networks Sub-Processors (checked 15 Sept 2026)
- Fortinet FortiSASE ProvenFortinet Trust Resource Center, Not stated (checked 15 Sept 2026)
- Check Point ProvenSub-Processors List - Check Point Software, US, EU, India, Australia (per sub-processor) (checked 12 Sept 2026)
- Open Systems ProvenSubprocessor Statement, Switzerland, United States, Germany, India, Ireland (Microsoft Azure), China (Alibaba Cloud) (checked 12 Sept 2026)
- Cloudflare One PartialCloudflare Sub-Processors | Cloudflare (checked 12 Sept 2026)
- Aryaka PartialAryaka Trust Center | Powered by SafeBase (checked 15 Sept 2026)
- GTT PartialPrivacy Notice | GTT, Arlington, Virginia, US (HQ) (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE PartialPalo Alto Networks Sub-Processor List - Palo Alto Networks (checked 12 Sept 2026)
- Comcast Business PartialComcast Business Privacy Center (checked 12 Sept 2026)
- SonicWall Cloud Secure Edge PartialSonicWall Trust Center | Powered by SafeBase (checked 12 Sept 2026)
- NTT DATA PartialNTT DORA Outsourcing Supplement (checked 15 Sept 2026)
Exit and portability2 proven · 1 partial · 0 to review
- Cloudflare One ProvenCloudflare Data Processing Addendum | Cloudflare (checked 12 Sept 2026)
- Barracuda SecureEdge ProvenProduct & Service Description - SecureEdge Appliances and SaaS Service, US, EMEA (West Europe), plus additional PoPs across Europe, Middle East, Americas and APAC (checked 12 Sept 2026)
- Cisco PartialData Access Terms - Cisco (checked 12 Sept 2026)
UK regulatory alignment (FCA and PRA)2 proven · 2 partial · 0 to review
Do not claim FCA, PRA, DORA, FFIEC, GLBA, NYDFS, SEC, OSFI, PCI DSS or SWIFT CSP alignment unless the source supports the precise wording. A SOC 2 report or ISO 27001 certificate is supporting evidence for the security columns, not proof for a regulatory column. Keep the regimes separate. A US bank case study does not evidence UK regulatory alignment, and a UK building society does not evidence NYDFS or FFIEC alignment. Record the regime in the source row.
- Cloudflare One ProvenUK Operational Resilience FAQs | Cloudflare, United Kingdom (checked 15 Sept 2026)
- BT ProvenNationwide Building Society, UK (checked 12 Sept 2026)
- Fortinet FortiSASE Partial
- Virgin Media O2 Business PartialWhat is SASE? | Secure Access Service Edge network strategy, UK (checked 15 Sept 2026)
EU DORA alignment2 proven · 14 partial · 0 to review
Do not claim FCA, PRA, DORA, FFIEC, GLBA, NYDFS, SEC, OSFI, PCI DSS or SWIFT CSP alignment unless the source supports the precise wording. A SOC 2 report or ISO 27001 certificate is supporting evidence for the security columns, not proof for a regulatory column. Keep the regimes separate. A US bank case study does not evidence UK regulatory alignment, and a UK building society does not evidence NYDFS or FFIEC alignment. Record the regime in the source row.
- Cloudflare One ProvenEU - Digital Operational Resilience Act (DORA) mapping (checked 15 Sept 2026)
- Versa Networks ProvenWhat is DORA? Compliance & Digital Resilience Guide (checked 15 Sept 2026)
- Zscaler PartialHow Zscaler DSPM Helps Europe's Financial Sector Achieve DORA Compliance, European Union (checked 12 Sept 2026)
- Netskope PartialSecuring Financial Services in the Cloud and AI Era (checked 12 Sept 2026)
- Barracuda SecureEdge PartialBarracuda Trust Center Product Guide (checked 15 Sept 2026)
- GTT PartialGTT Finance and Insurance Solutions (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE PartialPalo Alto Networks Trust Center - Regulations (DORA whitepaper) and Financial Sector Cybersecurity and Resilience Frameworks whitepaper (checked 15 Sept 2026)
- Fortinet FortiSASE Partial
- BT PartialGetting ready for DORA | BT Business, EU (checked 12 Sept 2026)
- Colt Technology Services PartialDORA (Digital Operational Resilience Act) - Colt Legal (checked 15 Sept 2026)
- Orange Business PartialSto, Norway, with expansion referenced to Denmark, Italy, Spain and South America (checked 12 Sept 2026)
- Verizon Business PartialStrengthening Your Critical Infrastructure Security - Verizon Business (checked 15 Sept 2026)
- Open Systems PartialAudit readiness and compliance blog post (checked 12 Sept 2026)
- NTT DATA PartialNTT DORA Outsourcing Supplement (checked 15 Sept 2026)
- Virgin Media O2 Business PartialWhat is SASE? | Secure Access Service Edge network strategy, UK (checked 15 Sept 2026)
- Forcepoint PartialForcepoint EBA Guidance / Compliance Hub (checked 15 Sept 2026)
US regulatory alignment (FFIEC, GLBA, NYDFS, SEC)0 proven · 1 partial · 0 to review
Do not claim FCA, PRA, DORA, FFIEC, GLBA, NYDFS, SEC, OSFI, PCI DSS or SWIFT CSP alignment unless the source supports the precise wording. A SOC 2 report or ISO 27001 certificate is supporting evidence for the security columns, not proof for a regulatory column. Keep the regimes separate. A US bank case study does not evidence UK regulatory alignment, and a UK building society does not evidence NYDFS or FFIEC alignment. Record the regime in the source row.
- Netskope PartialGLBA Cloud Compliance | Netskope, United States (checked 12 Sept 2026)
Canada regulatory alignment (OSFI)0 proven · 0 partial · 0 to review
Do not claim FCA, PRA, DORA, FFIEC, GLBA, NYDFS, SEC, OSFI, PCI DSS or SWIFT CSP alignment unless the source supports the precise wording. A SOC 2 report or ISO 27001 certificate is supporting evidence for the security columns, not proof for a regulatory column. Keep the regimes separate. A US bank case study does not evidence UK regulatory alignment, and a UK building society does not evidence NYDFS or FFIEC alignment. Record the regime in the source row.
No provider has completed review for canada regulatory alignment (osfi) in financial services yet.
PCI DSS alignment10 proven · 11 partial · 0 to review
Do not claim FCA, PRA, DORA, FFIEC, GLBA, NYDFS, SEC, OSFI, PCI DSS or SWIFT CSP alignment unless the source supports the precise wording. A SOC 2 report or ISO 27001 certificate is supporting evidence for the security columns, not proof for a regulatory column. Keep the regimes separate. A US bank case study does not evidence UK regulatory alignment, and a UK building society does not evidence NYDFS or FFIEC alignment. Record the regime in the source row.
- Cloudflare One ProvenCloudflare Trust Hub | Cloudflare (checked 12 Sept 2026)
- Netskope ProvenCompliance | Netskope (checked 12 Sept 2026)
- Cato Networks ProvenSecurity, Compliance and Privacy | Cato Networks (checked 12 Sept 2026)
- Versa Networks ProvenPCI-DSS Compliance with Versa Secure SD-WAN (checked 12 Sept 2026)
- GTT ProvenGTT Finance and Insurance Solutions (checked 12 Sept 2026)
- BT ProvenNationwide Building Society, UK (checked 12 Sept 2026)
- AT&T Business ProvenCOCC, United States (10 states) (checked 12 Sept 2026)
- Cisco ProvenCisco SD-WAN achieves PCI-DSS compliance - Cisco Blogs (checked 12 Sept 2026)
- VeloCloud ProvenVeloCloud SD-WAN for Retail - Solution Brief (checked 12 Sept 2026)
- Check Point ProvenMiller Insurance, UK (Lloyd's, London) and international (checked 15 Sept 2026)
- Zscaler PartialZscaler's Compliance Center (checked 14 Sept 2026)
- Barracuda SecureEdge PartialBarracuda Trust Centre - Certifications page (checked 15 Sept 2026)
- Aryaka PartialSecurity FAQs | Universal ZTNA, AI Secure & Next-Gen DLP | Aryaka (checked 12 Sept 2026)
- Fortinet FortiSASE Partial
- SonicWall Cloud Secure Edge PartialHow SonicWall Solutions Can Help You Become PCI DSS Compliant (checked 12 Sept 2026)
- Orange Business PartialSto, Norway, with expansion referenced to Denmark, Italy, Spain and South America (checked 12 Sept 2026)
- Verizon Business PartialGovernance, Risk & Compliance (GRC) Services | Verizon Global (checked 12 Sept 2026)
- Ericsson Cradlepoint PartialEricsson Enterprise Wireless Configuration Guidance for PCI DSS Compliance (checked 15 Sept 2026)
- HPE Aruba EdgeConnect PartialHow the EdgeConnect SD-WAN Platform Supports PCI DSS Compliance (checked 12 Sept 2026)
- Lumen PartialLumen SD-WAN with Cisco Meraki (checked 15 Sept 2026)
- Forcepoint PartialMiddle East Bank Customer Story | Forcepoint, Egypt (Middle East) (checked 12 Sept 2026)
SWIFT CSP alignment0 proven · 3 partial · 0 to review
Do not claim FCA, PRA, DORA, FFIEC, GLBA, NYDFS, SEC, OSFI, PCI DSS or SWIFT CSP alignment unless the source supports the precise wording. A SOC 2 report or ISO 27001 certificate is supporting evidence for the security columns, not proof for a regulatory column. Keep the regimes separate. A US bank case study does not evidence UK regulatory alignment, and a UK building society does not evidence NYDFS or FFIEC alignment. Record the regime in the source row.
- Palo Alto Networks Prisma SASE PartialFinancial Services - Palo Alto Networks (checked 12 Sept 2026)
- Colt Technology Services PartialColt SWIFTNet (checked 12 Sept 2026)
- Verizon Business PartialGovernance, Risk & Compliance (GRC) Services | Verizon Global (checked 12 Sept 2026)
UK delivery10 proven · 3 partial · 0 to review
Keep the regimes separate. A US bank case study does not evidence UK regulatory alignment, and a UK building society does not evidence NYDFS or FFIEC alignment. Record the regime in the source row.
- Cloudflare One ProvenInvestec, South Africa, United Kingdom (checked 12 Sept 2026)
- Zscaler ProvenHastings Direct, United Kingdom (East Sussex) (checked 12 Sept 2026)
- Netskope ProvenData Transfer at Netskope | Netskope, United States, EU, UK, Australia, Saudi Arabia, Switzerland, Singapore (checked 12 Sept 2026)
- Barracuda SecureEdge ProvenData Center Locations - Barracuda Trust Center, UK, EU (multiple), US, Canada, and other global regions (checked 12 Sept 2026)
- Aryaka ProvenFinancial Services Organisations Digital Transformation Paving Way To A Smarter, Digital Future, Find Cloud Industry Forum And Aryaka | Aryaka, UK (checked 15 Sept 2026)
- GTT ProvenSaxo Bank, UK; Denmark (checked 12 Sept 2026)
- BT ProvenNationwide Building Society, UK (checked 12 Sept 2026)
- Colt Technology Services ProvenByblos Bank Europe, Belgium, UK, France (checked 12 Sept 2026)
- Vodafone Business ProvenC2 General SOC & SIEM Vodafone Business Security Enhanced - Terms and Conditions, UK / EEA (checked 14 Sept 2026)
- Virgin Media O2 Business ProvenRoyal London Group, UK and Isle of Man (checked 15 Sept 2026)
- Cato Networks Partial
- Palo Alto Networks Prisma SASE Partial
- Expereo PartialSupport - Expereo, US, South America, Europe, Middle East, Asia (checked 12 Sept 2026)
North America delivery10 proven · 11 partial · 0 to review
Keep the regimes separate. A US bank case study does not evidence UK regulatory alignment, and a UK building society does not evidence NYDFS or FFIEC alignment. Record the regime in the source row.
- Cloudflare One ProvenLuana Savings Bank, United States (Iowa) (checked 12 Sept 2026)
- Zscaler ProvenFannie Mae, United States (checked 12 Sept 2026)
- Netskope ProvenData Transfer at Netskope | Netskope, United States, EU, UK, Australia, Saudi Arabia, Switzerland, Singapore (checked 12 Sept 2026)
- Barracuda SecureEdge ProvenData Center Locations - Barracuda Trust Center, UK, EU (multiple), US, Canada, and other global regions (checked 12 Sept 2026)
- Aryaka ProvenAryaka Global Points-of-Presence (PoPs), US: Ashburn, Atlanta, Chicago, Dallas, Denver, Los Angeles, Miami, Newark, San Jose, Seattle; Canada: Toronto; UK: London; plus EMEA and APAC PoPs (checked 12 Sept 2026)
- Comcast Business ProvenAmerican Heritage Credit Union, Pennsylvania and New Jersey, USA (checked 15 Sept 2026)
- SonicWall Cloud Secure Edge ProvenLemonade, United States (checked 12 Sept 2026)
- VeloCloud ProvenSTAR Financial Bank, United States (Indiana) (checked 12 Sept 2026)
- HPE Aruba EdgeConnect ProvenFirst Bank, Missouri, Illinois, California, United States (checked 12 Sept 2026)
- Lumen ProvenHanmi Bank, United States (checked 12 Sept 2026)
- Cato Networks Partial
- Versa Networks Partial
- GTT PartialPrivacy Notice | GTT, Arlington, Virginia, US (HQ) (checked 12 Sept 2026)
- Palo Alto Networks Prisma SASE PartialBanking on a More Secure Future with Prisma SASE - Palo Alto Networks, United States (Southeast and Mid-Atlantic regions) (checked 12 Sept 2026)
- Fortinet FortiSASE Partial
- AT&T Business PartialAT&T Global Business Services | Internet Connectivity, Networking & Wireless, 200 countries and territories; Canada since 1980; EMEA; APAC; Latin America and Caribbean (checked 12 Sept 2026)
- Colt Technology Services PartialPRIZMNET | Colt Docs, Europe, Asia and North America; 230+ cities in 40 countries (checked 12 Sept 2026)
- Verizon Business Partial
- Ericsson Cradlepoint Partial
- Open Systems Partial
- Expereo PartialSupport - Expereo, US, South America, Europe, Middle East, Asia (checked 12 Sept 2026)
Global delivery10 proven · 16 partial · 0 to review
Keep the regimes separate. A US bank case study does not evidence UK regulatory alignment, and a UK building society does not evidence NYDFS or FFIEC alignment. Record the regime in the source row.
- Zscaler ProvenZscaler for Financial Services, Multiple (customers named include UK, US, South Africa, India) (checked 12 Sept 2026)
- Netskope ProvenNewEdge Network | Netskope, 80+ regions, 220+ countries and territories (checked 15 Sept 2026)
- Barracuda SecureEdge ProvenData Center Locations - Barracuda Trust Center, UK, EU (multiple), US, Canada, and other global regions (checked 12 Sept 2026)
- Aryaka ProvenCalypso Technology, 18 countries (offices); 60+ countries (users) (checked 15 Sept 2026)
- GTT ProvenSaxo Bank, UK; Denmark (checked 12 Sept 2026)
- Fortinet FortiSASE ProvenFinancial Services Cybersecurity | Fortinet (checked 29 Jul 2026)
- BT ProvenBT Business - Financial services SD-WAN case study (Agile Connect + BT Managed Fortinet Firewall; anonymised global financial-services customer), More than 30 countries (checked 12 Sept 2026)
- Colt Technology Services ProvenPRIZMNET | Colt Docs, Europe, Asia and North America; 230+ cities in 40 countries (checked 12 Sept 2026)
- Comcast Business ProvenComcast Business to Acquire Masergy, a Pioneer in Software-Defined Networking and Cloud Platforms, Nearly 100 countries (checked 12 Sept 2026)
- Vodafone Business Proven
- Cloudflare One Partial
- Cato Networks Partial
- Versa Networks Partial
- Palo Alto Networks Prisma SASE Partial
- AT&T Business PartialAT&T Global Business Services | Internet Connectivity, Networking & Wireless, 200 countries and territories; Canada since 1980; EMEA; APAC; Latin America and Caribbean (checked 12 Sept 2026)
- Cisco PartialBBVA Argentina, Argentina, described as a reference model being extended to BBVA entities in Colombia, Peru and the wider global group (checked 12 Sept 2026)
- Orange Business PartialFlexible SD-WAN, more than 220 countries and territories (checked 12 Sept 2026)
- Verizon Business Partial
- VeloCloud PartialArista Networks - SD-WAN & Edge Routing (VeloCloud SD-WAN solution page) (checked 12 Sept 2026)
- Ericsson Cradlepoint Partial
- Check Point PartialCheck Point SASE Platform (Formerly Harmony SASE) - Check Point Software (checked 15 Sept 2026)
- Open Systems PartialFinancial services company customer story (anonymised), Switzerland, Ireland, Singapore (checked 15 Sept 2026)
- NTT DATA PartialGlobal Network Services | NTT DATA, 190+ countries and territories (checked 12 Sept 2026)
- Juniper Networks Partial
- Expereo PartialConnect - Expereo, Up to 190 countries (checked 12 Sept 2026)
- Forcepoint Partial
Built for agents as well as people
Everything on this page is available to your assistant through the public Netify MCP server and open datasets, with the same evidence, the same regimes and the same dates. Ask for sector: "financial-services" and filter source rows by regulatory_regime.
MCP tool
get_sector_evidence
Source rows for a provider and requirement: wording, URL, dates, decision, what it does not prove. POST https://netify.co.uk/sase/api/mcp/
MCP tool
build_sase_shortlist
Market coverage for your requirements: how many of the 30 providers qualify and on what criteria. Named, personalised matches are released after you publish a short project.
Dataset
/sd-wan-sase-for-financial-services/data.json
The full table with every source row, versioned, declared in llms.txt and the datasets sitemap.
Structured data
Dataset · ItemList · FAQPage
JSON-LD on the table and the shortlist so answer engines can cite a cell rather than a paragraph.
How does the financial services operating environment impact connectivity requirements?
Retail Bank Branches
Bank branches depend on continuous connectivity for core banking systems, payment processing and customer service applications. Limited offline functionality covers basic enquiries only: staff cannot access customer account histories, process transactions or approve lending decisions without live connectivity. Extended outages force branches to turn customers away or revert to manual processes, creating customer dissatisfaction and compliance risks.
Trading Floors & Investment Offices
Trading floors and investment management offices introduce considerably more complex performance requirements. Core banking systems remain critical, while these sites also run trading platforms requiring sub-millisecond execution speeds, real-time market data feeds processing thousands of price updates per second, and risk management systems coordinating position monitoring across multiple asset classes. Slow trading platform performance means traders cannot execute orders at intended prices, potentially resulting in significant financial losses.
Wealth Management & Advisory
Wealth management and advisory offices represent a more dispersed operational model. Financial advisers, relationship managers and client service teams often operate from smaller regional offices with minimal IT support. Network reliability is essential for advisers accessing portfolio management systems during client meetings, secure messaging between advisory teams and video consultations with high-net-worth clients.
Network Performance Expectations
Trading floors experience predictable demand spikes during market open, close and major economic announcements. During these peaks, multiple traders simultaneously execute orders, market data feeds process unprecedented volumes, risk management systems calculate real-time exposures and settlement systems handle transaction confirmations, all within financial services networks.
Latency Tolerance & Application Sensitivity
- Core Banking: Requires responsive performance but can tolerate modest latency: extended response times frustrate staff and reduce client service efficiency.
- Real-Time Trading: Operates on considerably tighter margins. When markets move rapidly, order execution must occur within milliseconds to achieve intended prices.
- Payment Processing: Requires consistent low latency to maintain transaction throughput: higher latency creates processing backlogs that undermine service levels and client confidence.
- Market Data Feeds: Cannot tolerate delays when every millisecond affects execution quality and profitability.
Lack of On-Site IT Expertise & Centralised Management
Financial services networks must frequently operate without dedicated on-site IT support. With SD-WAN and SASE, organisations can move to a centrally managed approach with zero-touch provisioning. IT teams can configure, monitor and troubleshoot remotely. When a new branch opens, equipment arrives pre-configured and connects automatically.
Financial Services SD-WAN/SASE Procurement: Sector-Specific Requirements
A structured RFP, tailored to specific network requirements, operational model and compliance obligations, ensures all vendors respond to the same financial services-specific requirements (FCA operational resilience support, trading application prioritisation, PCI DSS segmentation).
- Market reconfiguration and site changes: define expected rates of openings, closures and service relocations with contractual obligations for rapid provisioning and clean decommissioning.
- Differentiated resilience by site type: trading floors and payment processing centres require near-continuous availability with sub-second failover; advisory offices might tolerate brief outages with appropriate client communication protocols.
- Peak period performance: specify peak period bandwidth needs (market open/close, major economic announcements, month-end processing) and acceptable performance degradation during congestion.
- Third-party resilience and vendor assurance: with the FCA’s operational resilience deadline now passed, include specific questions about how an SD-WAN vendor’s own infrastructure meets FCA operational resilience standards, their important business services and impact tolerances, and evidence of their scenario testing. Verify ISO 27001 and SOC 2 certifications.
- Multi-entity and regulated subsidiary requirements: specify whether different regulated entities within a financial services group will share network infrastructure and what security boundaries must exist between different legal entities, regulated subsidiaries and offshore operations.
Enterprise vs Mid-Market Financial Organisations
Enterprise Financial Organisations
Hundreds of locations with dedicated NOC, in-house security teams and complex network architectures including dedicated trading networks, enterprise SOCs and global WAN infrastructure. SD-WAN RFP procurement involves IT, trading technology, infosec and compliance stakeholders with formal approval processes. Often run multiple business lines (retail banking, investment banking, wealth management) requiring differentiated service levels and potentially separate network domains.
Mid-Market Financial Organisations
Boutique wealth management firms, regional building societies and specialist lenders operate with leaner IT teams. Network decisions are typically made by smaller teams with broader responsibilities, requiring simplified solutions. Typically lack dedicated SOCs and should consider managed service provider assistance or solutions with integrated security capabilities and outsourced security monitoring.
Frequently Asked Questions
What is the primary benefit of SD-WAN for financial services organisations?
The primary benefit is the ability to prioritise critical traffic (trading platforms, core banking) through application-aware routing whilst enabling secure, resilient connectivity for distributed branches and remote advisors. This ensures that transaction-critical systems are prioritised over non-critical traffic, whilst complying with strict regulatory availability requirements.
Why is SASE becoming essential for modern financial environments?
SASE converges networking and security into a single cloud-based framework. For financial institutions, this reduces the complexity of securing hybrid workforces and distributed branches, whilst providing consistent policy enforcement for PCI DSS and GDPR compliance regardless of where users or applications are located.
How does SD-WAN help address PCI DSS 4.0.1 compliance?
SD-WAN assists with PCI DSS 4.0.1 compliance by implementing granular network segmentation that isolates cardholder data environments (CDE) from general corporate traffic. This reduces the scope of PCI audits and prevents lateral movement of threats, whilst centralised logging provides the evidence required for compliance reporting.
How does network latency affect financial services trading systems?
High network latency causes delays in executing trades, processing market data and confirming transactions. When systems fail to respond promptly, it leads to execution at unintended prices and missed trading opportunities, directly impacting profitability and potentially client relationships in time-critical situations where milliseconds can determine trade success.
What should be included in a financial services SD-WAN RFP?
Clear requirements for peak bandwidth handling during trading activity periods (such as market open/close and major economic announcements), specific vendor questions regarding their ability to support FCA operational resilience evidence requirements, multi-site resilience with sub-second failover for critical sites, network segmentation for PCI DSS cardholder data environments, and the vendor’s own operational resilience posture and third-party risk management capabilities.
How we researched this page
The written guidance comes from Harry Yelland, who drafted it on 12 January 2026 from Netify's financial services RFP work, the FCA operational resilience policy (PS21/3), PCI DSS 4.0.1 and UK GDPR. Robert Sturt, Netify's Managing Director, fact-checked the draft on 14 January 2026.
The evidence table is a separate, later piece of work: a research workbook in which Harry grades each of the 30 providers against 28financial services requirements, one accepted source per Proven cell, with the regulatory regime recorded on every source row. Harry returned the first pass on 11 September 2026. On 12 September 2026 Netify's research assistant completed the workbook for all 30 providers, opening every page cited and re-checking every accepted URL live on the same day; Harry is reviewing that pass. The table shows the current state of that work, not a finished verdict, and every cell carries its own checked date.
The regulation map is Netify reference data (September 2026) listing 20 regimes and standards across UK, EU, US, Canada. It is the same test Harry applies in the workbook, so a regulatory cell on this page and the source row behind it were judged by the same rule. Confirm current versions on the regulator's own site before relying on a date.
Provider entries use the published evidence feed: proven capability count, verification date, then provider name. Positions describe evidence order, not recommendations. The tool previews aggregate coverage; personalised matches require authorised access after verified publication. Source grades remain on the comparison platform.
Capability status and evidence rules
- Proven
- An accepted source directly connects the provider's named SD-WAN, SASE, SSE or managed service to that financial services requirement, in the regulatory regime the column belongs to.
- Partial
- Relevant evidence exists, but the product connection, regulatory regime, geography or outcome is incomplete.
- Not found
- Credible sources were checked but no defensible evidence was found. This does not prove the provider lacks the capability.
- Not applicable
- The requirement does not apply to the provider's operating model.
- To review
- Research has not yet been completed.
- Prefer customer-authored case studies, regulator or public body statements, published compliance attestations, contract awards and independent reporting.
- A named financial institution using a named SD-WAN, SASE, SSE or managed service is the strongest evidence.
- A generic financial services solutions page is supporting evidence, not proof of a deployment.
- Keep regimes separate: a US bank case study is evidence for the US column, never the UK column, and the reverse.
- For the FCA and PRA, DORA, US and OSFI columns a certification such as SOC 2 or ISO 27001 is never enough on its own. The source must connect the service to that regime.
- Do not treat switching, Wi-Fi, data-centre LAN or trading-floor LAN evidence as SD-WAN or SASE evidence unless the source makes that connection.
- Copy a short exact quotation that proves the point, then write a concise factual summary in your own words.
- Record publication and checked dates and the regulatory regime on every source row. State what each source does not prove.
Cite this research
Netify, "SD-WAN & SASE for Financial Services (2026)", written by Harry Yelland, fact-checked by Robert Sturt: https://netify.co.uk/sd-wan-sase-for-financial-services/
Machine-readable: https://netify.co.uk/sd-wan-sase-for-financial-services/data.json · Public evidence source: https://netify.co.uk/sase/best/sd-wan-sase-providers-for-financial-services/data.json · Programmatic shortlists and evidence: POST https://netify.co.uk/sase/api/mcp/
Related: Manufacturing · Healthcare · Retail