SWIFT Customer Security Programme

In 2016 attackers compromised systems at the Bangladesh Central Bank and sent payment instructions totalling USD $951m, of which $101m were processed by the Federal Reserve Bank of New York. This remains the biggest bank heist in history.

Since this time, SWIFT's payments community continues to suffer from a number of cyber-attacks and breaches. While all SWIFT customers remain primarily responsible for protecting their own environments, SWIFT aims to support its community in the fight against cyber-attacks with the development of their Customer Security Programme and have identified mandatory and optional security controls that their 11,000 customers worldwide must comply with.

SWIFT’s customers have to attest compliance to all mandatory controls on an annual basis*. Furthermore, SWIFT has introduced a requirement that mandates an independent assessment for all customers' attestations. This comes into force in 2021.
 

SWIFT CSP Development

[*] COVID-19 Update: Given the global COVID-19 situation SWIFT has published updated guidelines on 18 June 2020 regarding changes to the CSP self-attestation and independent assessment requirements for 2020. SWIFT has announced that in 2020, customers can self-attest against the 2019 version of the SWIFT CSP and can optionally support the self-attestation with an independent assessment. In 2021, independent assessment will be a mandatory requirement and customers will be required to attest against the 2021 version of the CSP framework.

Why PwC?

PwC will leverage inhouse accelerators and our extensive SWIFT CSP expertise to ensure that your needs are met ahead of SWIFT's required independent assessment due on 31 December 2021.


Proven CSP Assurance Experience

We have performed numerous SWIFT CSP assurance engagements across multiple territories and industries.

Cohesive team who understand SWIFT

We understand SWIFT like no other as we performed an annual review of SWIFT under the internationally recognised ISAE3000 standard for over 10 years.

Technical expertise and knowledge

We are the only ‘Big-4’ firm with a professional Certified Cyber Security Consultancy certificate from the NCSC. We are unique in our ability to leverage threat intelligence to build and simulate realistic cyber-attack scenarios.

Adapting to your requirements

PwC will leverage inhouse accelerators and our extensive SWIFT CSP expertise to ensure that your needs are met ahead of SWIFT's required independent assessment due on 31 December 2021.

PwC will provide industry insight that is relevant to your market segment and geographical segment, as well as a balanced view on how to prioritise any associated actions.

SWIFT customer security programme: FAQs

1) What is the SWIFT CSP?

SWIFT's customer security programme (CSP) aims to prevent and detect fraudulent activity through a set of mandatory security controls, community-wide information sharing initiatives and enhanced security features on their products.

Contact us

Rishabh Rastogi

Rishabh Rastogi

SWIFT CSP SME, PwC United Kingdom

Tel: +44 (0)7725 068141

Hattie Johnstone-Browne

Hattie Johnstone-Browne

SWIFT CSP SME, PwC United Kingdom

Tel: +44 (0)7802 659300

We unite expertise and tech so you can outthink, outpace and outperform
See how
Follow us