Skip to content
Client access

Industry

Banking & Fintech

SBS and PCI DSS requirements, digital fraud and exposed APIs. We assess your risk through an attacker’s eyes.

The context

Digital channels, demanding regulation and financially motivated attackers

Mobile banking, instant payments, digital wallets and APIs open to third parties have transformed how people use financial services. Every new channel is also a new attack surface.

Entities supervised by Peru’s SBS must demonstrate cybersecurity management in line with SBS Resolution No. 504-2021, and those who process cards must comply with PCI DSS. Fintechs, meanwhile, grow fast with small teams and must earn the trust of customers, partners and regulators.

We assess your channels through an attacker’s eyes and provide technical evidence that helps both reduce risk and respond to auditors and regulators.

Key threats

The risks that matter most in the financial sector

We focus on the scenarios that translate into financial losses, penalties and loss of trust.

Fraud in digital channels

Account takeover, abuse of transaction logic and automated attacks against apps and online banking.

Exposed APIs

Third-party integrations, open banking and mobile services with authorization flaws that expose other customers’ data.

Brand impersonation and phishing

Fake sites, messages and calls targeting customers and employees to steal credentials or authorize transactions.

Ransomware and extortion

System encryption combined with the threat of leaking customer data to pressure payment.

Vendor risk

Core banking, cloud, payment processor and fintech partners with access to your systems or data.

Insider threats

Misuse of privileged access by internal or third-party staff, whether intentional or accidental.

Regulation and frameworks

Requirements that guide security in the financial sector

SBS Resolution No. 504-2021

Regulation for information security and cybersecurity management for companies supervised by Peru’s SBS.

PCI DSS

Mandatory standard for anyone who stores, processes or transmits payment card data.

ISO/IEC 27001

An internationally recognized information security management system.

NIST CSF 2.0

A framework to govern cybersecurity risk and communicate it to the board.

SWIFT CSCF

Security controls of the SWIFT program for entities connected to its network.

Law No. 29733

Protection of your customers’ and employees’ personal data under Peruvian law.

How we help

Services built for banks, lenders and fintechs

We test your channels like an attacker would and help you prove your controls work.

Penetration Testing

Manual testing of web applications, APIs, mobile apps, infrastructure and cloud that goes where a scanner can’t.

Red Team & Ethical Hacking

Human-led adversary exercises that test whether your organization detects and contains a real attack, with tactics mapped to MITRE ATT&CK.

Compliance & Risk Management

We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.

Source Code Review

We find vulnerabilities in your code before they reach production, in any language.

Social Engineering & Awareness

Controlled phishing, vishing and malicious QR campaigns that measure the human factor and turn it into a line of defense.

Frequently asked questions

What financial institutions usually ask us

Do your reports serve as evidence for the SBS?

Yes. We structure our reports to serve as evidence of cybersecurity control assessments for internal and external auditors and regulators.

Can you test our apps without affecting customers?

Yes. We work in staging environments equivalent to production or in agreed windows, using controlled techniques and no real customer transactions.

Do you work with growth-stage fintechs?

Yes. We tailor the scope to your stage: from a first test of your app and APIs to an ongoing security program.

Can you help with PCI DSS?

Yes. We perform the penetration tests the standard requires, help define the cardholder data environment scope and support your assessment readiness.

Do you assess open banking APIs and third-party integrations?

Yes. We test object- and function-level authorization, data exposure and logic abuse, following the OWASP API Security Top 10.

Other industries

We also protect

Government

Digital citizen services, personal data and legacy systems. We help public entities protect them.

Mining

Remote operations, critical OT assets and extended supply chains. We protect production continuity.

Kamaya Secure logo on an office wall

Let’s define the right scope for your organization

Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.

Chat on WhatsApp (opens in a new tab)