SWIFT Customer Security Programme

SWIFT's payments community continues to suffer from a number of cyber-attacks and breaches, (some stemming from third parties). While all SWIFT customers remain primarily responsible for protecting their own environments, SWIFT aims to support its community in the fight against cyber-attacks and have identified 19 mandatory and 10 optional security controls for all its 11,000 customers worldwide.

For 2020, SWIFT promoted 2 existing advisory controls to mandatory and introduced 2 additional advisory controls resulting in 21 mandatory and 10 advisory controls in the CSCF v2020. All SWIFT users are required to undergo an “independent assessment” in support of their annual self-attestation in 2020 of their compliance with the SWIFT CSCF.

SWIFT CSP Development - What milestones should you be aware of?

Swift Plan

How is PwC positioned to help with this?

SWIFT CSP Independent Assessment

Perform an independent assessment to determine if your current controls satisfy SWIFT CSP requirements.

Remediation

Develop workstreams to address identified controls gaps via both technology and process changes.

Embedded in Internal Audit

Work alongside your internal audit function to report on SWIFT CSP controls.

Why PwC?

Cohesive team who understand SWIFT

PwC understands SWIFT like no other as we have been performing an annual review of SWIFT under the internationally recognised ISAE3000 standard for over 10 years.

Proven performance on similar projects

PwC have performed numerous SWIFT CSP security assessments worldwide and we have a proven approach and understanding of how to ensure the security of SWIFT infrastructure, while maintaining functionality.

Technical expertise and knowledge base

PwC is the only ‘Big-4’ firm with a professional Certified Cyber Security Consultancy certificate from the NCSC. PwC are unique in our ability to leverage threat intelligence to build and simulate realistic cyber attack scenarios.

Adapting to your requirements

PwC will leverage inhouse accelerators and our extensive SWIFT CSP expertise to ensure that your needs are met ahead of SWIFTs required independent assessment due on 31 December 2020.

SWIFT customer security programme: FAQs

  1. What is the SWIFT CSP?

    SWIFT's customer security programme (CSP) aims to prevent and detect fraudulent activity through a set of mandatory security controls, community-wide information sharing initiatives and enhanced security features on their products.
  2. When is the deadline for SWIFT CSP compliance?

    You are required to submit a self-attestation on an annual basis by 31 December. An independent assessment is required alongside a customers’ attestations from 31 December 2020 onwards.
  3. What form does the SWIFT required independent assessment need to take?

    There are two forms in which a SWIFT customer can gain an independent assessment:

    An internal assessment. This is similar to an internal audit, carried out by the internal audit function of the customer and independent from the function submitting the attestation

    An external assessment. This is similar to an external audit, carried out by organisations such as PwC who will provide an independent assessment against the CSP controls
  4. What are the 21 SWIFT CSP mandatory controls?

    There are 21 mandatory controls focused on securing your environment, knowing and limiting access and detecting and responding.
  5. What happens if you attest to non-compliance?

    SWIFT reports all cases of non-compliance and where members have not attested at all to local regulators. In addition, SWIFT will select a sample of attestations for validation each year.
  6. What happens if I suspect my organisation has been targeted or breached?

    It is vital that you share all relevant information and let SWIFT know there is a problem as soon as possible, in order to protect other organisations in the network.

Contact us

Kyra Mattar

Third Party Trust Leader, PwC Singapore

Tel: +65 9735 2506

Ali Rasheed Butt

Director, Digital Solutions, PwC Singapore

Tel: +65 9616 7159

We unite expertise and tech so you can outthink, outpace and outperform
See how
Follow us
Hide

Required fields are marked with an asterisk(*)

By submitting your email address, you acknowledge that you have read the Privacy Statement and that you consent to our processing data in accordance with the Privacy Statement (including international transfers). If you change your mind at any time about wishing to receive the information from us, you can send us an email message using the Contact Us page.