Cyber resilience for the environment around your Swift connectivity

Talanos provides cyber security services related to the Swift Customer Security Programme. We help Swift-connected organisations assess control maturity, close gaps, prepare evidence and maintain stronger operational confidence — year-round, not just at attestation time.

The Customer Security Controls Framework at a glance

Launched by Swift in 2016, the Customer Security Programme defines the controls that all Swift users must apply to the infrastructure supporting their Swift activity. Compliance is mandatory for every Swift user, and each user must publish an attestation against the current CSCF version between July and December every year — with a hard deadline of 31 December. The framework is structured across three security objectives, supported by seven principles that map directly onto the Identify, Protect and Detect & Respond capabilities Talanos delivers.

Objective 1

Secure your environment

  • 1Restrict internet access & protect critical systems
  • 2Reduce attack surface and vulnerabilities
  • 3Physically secure the environment
Objective 2

Know and limit access

  • 4Prevent compromise of credentials
  • 5Manage identities and segregate privileges
Objective 3

Detect & respond

  • 6Detect anomalous activity to systems or transaction records
  • 7Plan for incident response and information sharing

A continuous discipline, not an annual event

Swift defines four milestones in a complete CSP cycle. Most organisations have these steps covered on paper. What separates a defensible posture from a tactical one is how well each milestone connects to the next — and what happens in the months in between.

01

Assess, budget & plan

Confirm architecture type and in-scope components. Establish a structured gap assessment against current CSCF mandatory and advisory controls. Size the remediation effort and secure budget before the attestation window opens.

02

Implement & assess

Remediate identified gaps and perform the independent assessment. As a listed cyber security service provider, Talanos performs community-standard independent assessments aligned to Swift's Independent Assessment Process Guidelines — with lead assessors holding recognised cyber security certifications.

03

Attest & share

Submit the attestation in KYC-SA between July and December, before the 31 December deadline. The Talanos independent assurance letter accompanies the attestation as evidence of community-standard assessment. Compliance status is then visible to counterparties.

04

Resolve & resubmit

Where gaps remain, mark controls as "I will comply by" in KYC-SA, remediate, and have the affected controls re-assessed by an independent assessor. Resubmit a new attestation once compliance is achieved.

The Deliverable

An independent assurance letter on Talanos letterhead

The tangible output of a Talanos CSP engagement is the independent assurance letter — issued by Talanos, on our letterhead, confirming the outcome of the community-standard assessment against the applicable CSCF controls. Clients upload the letter to KYC-SA alongside their attestation, providing Swift and counterparties with the independent evidence required for a Compliant status.

Issued by Talanos Cybersecurity Limited
Submitted via Client upload to KYC-SA
Outcome Compliant attestation

Events that trigger a new attestation

Beyond the annual cycle, Swift requires a new attestation within three months of any of the following events. Mid-year change is a common gap: organisations often miss trigger events buried inside operational or vendor changes, leaving attestations technically out of date.

Change of architecture type

Any move between Swift architecture types — for example, from a self-hosted model to a service bureau, or between A and B variants.

Change of service provider

Changing service bureau, L2BA provider, Group Hub or any other intermediary in your Swift connectivity path.

Attestation no longer accurate

Where any part of the previously submitted attestation is no longer accurate, complete or up to date — including contact information or control compliance status.

Emergency CSCF release

Where Swift publishes an emergency release of the Control Framework that modifies an element against which you previously attested.

Change to traffic hierarchy

Any change to the traffic hierarchy of the entity. Swift Customer Support must be contacted before re-attesting.

Use of a new BIC

Use of any new BIC that falls within the scope of the attestation obligation. New BIC activation requires an attestation before go-live.

Material change to a mandatory control

Any material change to the design or implementation of a mandatory security control — for example, migration to a new operating system supporting an in-scope component, new supporting network devices, or a new patch management tool.

What's in scope, and what isn't

CSP scope is narrower than many institutions assume. The framework focuses on the infrastructure directly supporting Swift connectivity, not the wider enterprise IT environment. Defining scope accurately is the single biggest determinant of assessment cost and effort.

In scope
  • User's Swift infrastructure — the Swift-related systems within the user's environment.
  • Data exchange layer — the components handling messaging between Swift and the user.
  • General & operator PCs and devices — workstations used to interact with Swift services.
  • Operators and tokens — the personnel and authentication factors used to access Swift.
Out of scope
  • Back office — the systems and applications behind the Swift-facing layer.
  • General enterprise IT environment — the wider corporate technology estate.
  • Connections to the Swift network — the network path managed by Swift itself.

Out-of-scope for CSCF doesn't mean low-risk. The wider environment often presents the most attractive attack surface — and is where Talanos broader Identify, Protect and Detect & Respond services apply.

CSP support drawn from the wider Talanos service portfolio

Our CSP work isn't a standalone offering — it draws on services from across our Identify, Protect and Detect & Respond capabilities. The same control environment that satisfies the CSCF is the one that has to withstand real-world attack, every day of the year.

01

Identify

Establish the baseline. Surface the gaps.

  • CSCF gap assessment against your current architecture, mandatory and advisory controls.
  • Vulnerability Management aligned to CSCF control 2.7 and ongoing exposure visibility.
  • Cloud Security Assessments for hosted Swift architectures and adjacent infrastructure.
  • Third Party Risk Management for the supplier ecosystem touching your Swift environment.
02

Protect

Close the gaps. Harden the environment.

  • Identity & Access Management supporting CSCF access control families and operator security.
  • Privileged Account Management for the operators and administrators inside your Swift footprint.
  • Cloud Security Operations for ongoing configuration, hardening and posture management.
  • Policy, procedure & evidence review to confirm controls reflect operational reality.
03

Detect & Respond

Sustain resilience between assessments.

  • Managed SOC providing 24/7 monitoring of the environment supporting Swift connectivity.
  • Managed Detection & Response (MDR) covering CSCF detection control objectives.
  • Endpoint & eXtended Detection & Response (EDR / XDR) across operator workstations and infrastructure.
  • Attestation readiness support, evidence packs and pre-assessment walkthroughs.

Listed in Swift's Directory of cyber security service providers

Talanos Cybersecurity Limited is included in Swift's Directory of cyber security service providers for selected regions, supporting Swift-connected organisations with services related to the Customer Security Programme.

Europe — UK, Ireland, Isle of Man Africa Asia & Pacific
SWIFT does not certify, warrant, endorse or recommend any service provider listed in its directory and SWIFT customers are not required to use providers listed in the directory.
View our listing in Swift's directory →

Cyber-first delivery, full lifecycle

As a managed SOC provider with capabilities spanning Identify, Protect and Detect & Respond, the same teams who run our 24/7 SOC also deliver the assessment and engineering work behind a defensible CSP posture. One team, one view of risk.

Cyber-first delivery

Cyber security is what we do. Consulting, engineering and managed services delivered by one specialist team, with a single view of risk across the engagement lifecycle.

Resilience over checkbox

Our work focuses on the security of the environment supporting Swift connectivity — not just the documentary evidence presented at attestation.

Multi-region delivery

Coverage across Europe, Africa and Asia-Pacific, supporting institutions with Swift connectivity across multiple jurisdictions and regulators.

Common questions about Swift CSP

The questions we hear most often from Swift-connected organisations preparing for, working through, or maintaining CSP compliance.

What is the Swift Customer Security Programme?

The Customer Security Programme (CSP) was launched by Swift in 2016 to reinforce the security of the Swift community. It mandates that all Swift users implement and maintain a defined set of cyber security controls — the Customer Security Controls Framework (CSCF) — to protect their Swift-related infrastructure, reduce cyberattack risk, and minimise the impact of fraudulent transactions.

When must we attest, and what's the deadline?

Every Swift user must publish at least one attestation against the current CSCF version between July and December each year. The hard deadline is 31 December of the year the CSCF version applies. A new attestation must also be submitted within three months of a number of trigger events, including changes to architecture type, service provider, traffic hierarchy, or any material change to a mandatory control implementation.

What's the difference between self-assessment and independent assessment?

A self-assessment is conducted by the user's first line of defence, typically the CISO office. It is treated as "Not Compliant" in KYC-SA, and is usually only used as an interim measure — for example, when activating a new BIC where an attestation is a pre-requisite. A community-standard assessment is independently performed by an external or internal independent function, and is mandatory for a "Compliant" attestation. An independent assessment must cover, at a minimum, all applicable mandatory controls.

Who counts as an "independent assessor"?

Independent assessors must have recent and relevant cyber security assessment experience. The lead assessor must hold at least one industry-recognised cyber security professional certification. They can be external (a third-party cyber security firm), internal (a function such as risk, compliance or internal audit — independent from the team that submits the attestation), or a mixed approach combining both. Talanos delivers external and mixed independent assessments aligned to Swift's Independent Assessment Process Guidelines.

Can we rely on an existing assurance report?

In some cases, yes. Swift allows reliance on a third-party assurance or internal report provided three conditions are met: the report's control coverage matches the CSCF control definitions; the assessment period is no older than 18 months from attestation submission; and the issuing organisation is qualified and fully independent from the entity being assessed. Where these conditions are only partially met, complementary assessment work may be required.

What happens if we submit a non-compliant attestation?

A non-compliant attestation is visible to messaging counterparties through KYC-SA and to supervisory authorities through a real-time compliance dashboard. The practical consequences include higher cyber risk exposure, reputational impact, and potential commercial impact as counterparties consider compliance status in their own risk decisions. Swift also reserves the right to inform supervisors of users that fail to submit an attestation on time, or that fail to respond to a Swift-Mandated Assessment request.

What does Talanos actually deliver at the end of an engagement?

The principal deliverable is an independent assurance letter, issued by Talanos Cybersecurity Limited on Talanos letterhead, confirming the outcome of the community-standard independent assessment performed against the applicable CSCF controls. Clients upload the letter to KYC-SA alongside their attestation submission, providing Swift and their counterparties with the independent evidence required for a Compliant attestation status. Engagements also typically produce a detailed assessment report covering each control, remediation guidance for any gaps, and supporting evidence appropriate to your internal governance.

Does Swift endorse Talanos?

No. Talanos Cybersecurity Limited is included in Swift's Directory of cyber security service providers for selected regions, but Swift does not certify, warrant, endorse or recommend any service provider listed in its directory, and Swift customers are not required to use providers listed in the directory. Our inclusion in the directory reflects our completion of Swift's CSP curriculum and our regional capability to support Swift-connected organisations.

Stronger control of the environment around your Swift connectivity

Start a conversation about CSP readiness, control improvement, or ongoing resilience with one of our specialists.

Book a consultation →