
World-renowned cybersecurity firm now part of Google Cloud, delivering threat intelligence-led penetration testing and red teaming informed by front-line incident response experience.
Threat intelligence for financial services comes in two distinct forms, and the firms below cover both. The first is enterprise threat intelligence: who is targeting your institution, which campaigns and tooling they use, and what indicators to watch for, feeding a security operations centre and threat-led testing such as CBEST and TIBER-EU. The second is product-focused threat intelligence: continuous research into the vulnerabilities, fraud techniques, and attack methods aimed at the payment devices, POS and PTS terminals, ATMs, and payment applications that banks, acquirers, and payment service providers actually operate.
The list leads with our Featured partner PCA Cyber Security for the second of those. PCA delivers product-focused threat intelligence for payment solution providers, device manufacturers, banks, and fintechs, alongside payment device and ATM penetration testing, aligned to PCI DSS, PCI PTS, and PSD2. The broader incident-response and managed-detection firms that follow supply the actor-centric intelligence that financial regulators and SOC teams rely on. Both matter to a financial institution, and few providers do both.
Related: Product threat intelligence providers · PCI PTS compliance testing companies · Threat-led penetration testing (TLPT)
Enterprise threat intelligence answers the question: which threat actors are likely to target our institution, and how? It tracks named groups, their campaigns and infrastructure, and the indicators of compromise that let a security operations centre detect them. In financial services it also underpins regulatory threat-led testing, where CBEST in the UK and TIBER-EU under DORA require a bespoke threat intelligence phase before the red team engagement begins.
Product threat intelligence answers a different question: what are the vulnerabilities and attack techniques threatening the payment products and infrastructure we run, and how do we stay ahead of them? For a bank, acquirer, or payment service provider that means the PIN entry devices, POS and PTS terminals, ATMs, card readers, and mobile payment applications that handle every transaction. The work is hands-on: attacking representative devices in a hardware lab, tracking disclosed vulnerabilities in the chips, firmware, and protocols those devices rely on, and monitoring the fraud techniques used against payment infrastructure in the wild. PCI PTS approval is a point-in-time status and real devices keep changing, so this intelligence is how an institution keeps its payment estate resilient after approval.
When shortlisting, be clear which problem you are solving. An institution building out its SOC or preparing for CBEST or TIBER-EU needs actor-centric intelligence from a firm with a live incident-response caseload. An acquirer, PSP, or bank running a payment device estate needs product intelligence from a firm with a hardware lab and payment-device research record. PCA Cyber Security is the specialist listed here for the latter.
Munich- and Budapest-based embedded cybersecurity experts focused on financial services, automotive and mobility, manufacturing and industrial automation, energy and more. The services and platform go beyond compliance, supporting the requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and other standards and regulations.

World-renowned cybersecurity firm now part of Google Cloud, delivering threat intelligence-led penetration testing and red teaming informed by front-line incident response experience.

Global risk advisory firm with a 400+ person cyber practice. IR-led penetration testing that feeds active breach intelligence straight into test scoping.

Global cybersecurity leader leveraging world-class threat intelligence from the Falcon platform to deliver intelligence-led penetration testing and red teaming.

Dell Technologies-backed cybersecurity firm with elite Counter Threat Unit intelligence informing enterprise penetration testing and adversary simulation.
It is intelligence about the threats facing a bank, payment provider, or fintech, in two forms. Enterprise threat intelligence tracks the actors and campaigns targeting the institution itself and feeds its security operations and regulatory threat-led testing. Product threat intelligence tracks the vulnerabilities and fraud techniques aimed at the payment devices, ATMs, and payment applications the institution operates.
Continuous research into how payment hardware and software is actually attacked: vulnerabilities in PIN entry devices, POS and PTS terminals, ATMs, and mobile payment apps, disclosed weaknesses in the chips and firmware they rely on, and fraud techniques seen in the wild. It is fed back into device security, patching, and incident response, and supports PCI DSS, PCI PTS, and PSD2 obligations.
Banks, acquirers, payment service providers, and fintechs running payment infrastructure, and the device manufacturers and payment solution providers supplying them. Institutions preparing for CBEST or TIBER-EU threat-led testing also need a bespoke threat intelligence phase from a qualified provider.
Threat-led penetration testing such as CBEST and TIBER-EU uses threat intelligence as its first phase, then runs an intelligence-led red team engagement against live systems. Threat intelligence on its own is the ongoing research and monitoring, whether of actors targeting the institution or of attacks on its payment products, without the red team exercise.