Recent Breaches
Breaches
View All →
Banking

Path Governance for Transaction Networks and Trading Floors

Financial institutions operate networks where milliseconds matter and a single breach can move billions. Payment systems, trading infrastructure, and SWIFT connections demand physical path governance that software alone cannot provide.

Back to Control
Control

Banking

When payment systems and trading infrastructure are reachable through the same network paths as email and web browsing, every phishing email becomes a potential path to fraudulent transactions worth millions.

100%

SWIFT infrastructure isolation

Zero

Persistent third-party access to payment systems

7

Transaction zones with independent governance

Full

DORA and PCI DSS compliance evidence

The Challenge

Financial networks are high-value targets.

SWIFT and Payment Risks

SWIFT infrastructure and payment processing systems are prime targets for sophisticated attackers seeking direct financial gain through fraudulent transactions.

Trading Floor Exposure

Trading systems require ultra-low latency connectivity that conflicts with traditional security controls, creating gaps that attackers exploit.

Third-Party Connectivity

Correspondent banking, market data providers, and fintech integrations create persistent network paths into core financial infrastructure.

The Scenario

Scenario: SWIFT Infrastructure Compromise

Attackers compromise an employee workstation through a targeted phishing campaign and move laterally over four weeks until they reach the SWIFT Alliance Lite2 server. They install custom malware that intercepts and modifies SWIFT messages, submitting fraudulent payment instructions during a bank holiday weekend. The fraud totals over forty million pounds before detection. With Firevault Control, the SWIFT infrastructure exists on a physically separated network. Employee workstations cannot reach SWIFT systems because the network path does not exist. Payment message submission requires multi-party authorisation with physical path activation.

"The attackers were in our network for 28 days. They moved from a marketing workstation to the SWIFT server in seven lateral hops. Each hop crossed a firewall boundary that should have stopped them. None did."

Module deployment · bank network

Where each Control module is deployed across customers, core banking, payments and vendors.

Banks layer the estate around the cardholder data environment: an internet edge, a perimeter, an identity tier, applications, and the core ledger and payments environments. Control puts a real boundary at every change of trust.

Grounded in PCI DSS v4 network segmentation guidance, ISO 27001 Annex A, FFIEC and PRA SS1/21.

B0

Internet edge

External

WAF
DDoS
Mobile banking
FirebreakValidate

External traffic stops at the perimeter.

B1

Perimeter / DMZ

DMZ · trust boundary

Reverse proxy
Public APIs

All inbound terminates here.

All inbound terminates here.

IsolateValidate

Identity sits behind its own boundary.

B2

Identity

IT

Customer IAM
Staff SSO
PAM
LockExecute

App access ties to named identities and approved actions.

B3

Applications

IT

Channels
Open banking
Servicing
IsolateValidate

Core ledger is reachable only through approved paths.

B4

Core banking

Data

Ledger
Customer records

The general ledger and account master.

The general ledger and account master.

IsolateLockExecute

Payments is segmented to PCI scope.

B5

Payments (CDE)

Data

Card switch
Faster Payments
SWIFT / RTGS

Cardholder data environment, PCI in scope.

Cardholder data environment, PCI in scope.

RelayFirebreakUnlink

Vendor and fintech access opens on a schedule.

VND

Vendor zone

DMZ · trust boundary

Fintech APIs
MSPs
OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Regulatory records, ledger snapshots, recovery sets and any files you have to be able to produce later.

Offline by design · secure by default

Modules & symbols

FirebreakPhysical sever
ValidateIntegrity check
IsolateZone boundary
LockNamed access
ExecuteApproved action
RelayTime-bound path
UnlinkRemove trust
DMZ boundaryTrust transition
OSS calloutOff-network detail

Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

  1. Firebreak

    On the B0 to B1 link and the vendor link

    Real hardware off switches on the public and vendor boundaries, with vendor connectivity opened only for named work.

  2. Validate

    On the B0 to B1 link, the B1 to B2 link and the B3 to B4 link

    Requests crossing into trusted estates are checked for origin, integrity and authority before they reach an account or a ledger.

  3. Isolate

    On the B1 to B2, B3 to B4 and B4 to B5 links

    Identity, core and payments sit on their own physical fabrics, in line with PCI segmentation expectations.

  4. Lock

    On the B2 to B3 link and the B4 to B5 link

    Privileged access ties to named identities with the right entitlement. Standing access is the exception.

  5. Execute

    On the B2 to B3 link and the B4 to B5 link

    Cross-system actions require approval in line. Execute holds the action until that approval is in place.

  6. Relay

    On the vendor link

    Vendor and fintech access opens for the window of work and not a minute more.

  7. Unlink

    On the vendor link

    When a vendor relationship ends, Unlink removes the persistent connection and the inherited trust.

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Key Capabilities

Sovereign Financial Data

All payment system configurations and transaction data remain within the agreed jurisdiction in NATO-approved Firevault Bunkers.

Dual-Control Access

All access to payment and trading infrastructure requires authorisation from both operations and information security teams.

DORA Compliance

Automated compliance logging maps directly to DORA operational resilience requirements and PCI DSS network segmentation controls.

Independent Communications

Out-of-band management ensures control plane access to financial systems independent of the corporate network.

Regulatory Audit Trail

Every access, transaction, and authorisation decision is recorded in tamper-proof logs meeting FCA and PRA evidence requirements.

Verified Configuration Baselines

Verified baselines of financial system configuration enable restoration of control-plane state during total compromise scenarios.

Demo to Live

Adoption Guide

Step 1

Financial Network Assessment

Map all network paths between corporate IT, payment systems, trading infrastructure, SWIFT, and third-party connections.

Step 2

Transaction Zone Design

Design physically separated zones for each financial system category with Control modules governing every inter-zone boundary.

Step 3

Non-Production Pilot

Deploy in a test environment mirroring your transaction infrastructure with full zone separation, dual-control authorisation, and compliance logging.

Step 4

Production Deployment

Phased deployment across financial infrastructure with verified configuration baselines, continuous compliance evidence, and independent management communications.

Step 1

Financial Network Assessment

Map all network paths between corporate IT, payment systems, trading infrastructure, SWIFT, and third-party connections.

Step 2

Transaction Zone Design

Design physically separated zones for each financial system category with Control modules governing every inter-zone boundary.

Step 3

Non-Production Pilot

Deploy in a test environment mirroring your transaction infrastructure with full zone separation, dual-control authorisation, and compliance logging.

Step 4

Production Deployment

Phased deployment across financial infrastructure with verified configuration baselines, continuous compliance evidence, and independent management communications.

Questions

Frequently Asked

Banking blueprint - PoC

Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy

    Banking

    Physically segment payment networks, SWIFT terminals, and core banking systems. Multi-party authorisation and air-gapped recovery for regulated banking infrastructure.

    © 2026 Firevault Limited. Disconnect to Protect®