Independent technical practice

Forensics and cyber risk for financial institutions

Investigations and independent assessments for institutions that answer to examiners, boards and customers at the same time.

Boardroom table prepared for a technical briefing.

Exposure

Where the exposure starts

Fraud inside a financial institution is rarely a single event. It is a pattern spread across core banking records, email, messaging, mobile devices and personal accounts, and reconstructing it requires evidence handling that will hold if the matter proceeds to termination, arbitration, regulatory referral or prosecution.

Account takeover, business email compromise and payment redirection remain the highest-frequency external exposures, and all three exploit process and authority rather than software defects. The investigative question is usually who authorized what, on which device, on the basis of which instruction.

Concentration risk in vendors and service providers is the structural issue. Core processors, payment platforms, cloud providers and outsourced technology functions mean that an institution’s effective attack surface is largely other companies’ environments, which is why third-party assessment is now examined as a governance matter rather than a procurement one.

Scoping

Questions the engagement must answer

  1. Which accounts, devices and transaction systems hold the record of the disputed activity?
  2. Can insider activity be distinguished from credential misuse on the available logs?
  3. What retention windows are about to close on the evidence that matters?
  4. What does the examiner’s finding mean for regulatory notification and customer remediation?
  5. How will the analysis be explained to a regulator, an auditor and, if needed, a court?

Services

How we help

Context

Regulatory context

Gramm-Leach-Bliley Act
The safeguards obligation requires a documented information security program with risk assessment, oversight and service-provider management, all of which have to be evidenced rather than asserted.
SEC cybersecurity disclosure rules
Public registrants must disclose material cybersecurity incidents and describe risk management, strategy and governance, which puts a premium on defensible, fast materiality analysis.
FFIEC guidance
Examiners assess cyber program maturity, resilience and third-party oversight using published interagency expectations.
Suspicious activity reporting
Investigations into internal fraud frequently intersect with reporting obligations, so evidence is preserved in a form that supports both the internal decision and any subsequent filing.

We are not your compliance counsel; we produce the technical findings and evidence your counsel and examiners rely on.

Related case study

Banking Industry: Executive-Level Financial Fraud

Examination of executive conduct and transaction records inside a banking institution.

Financial Fraud

See all case studies

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.