Security & GRC
Essays on security programs in regulated fintech: SOC 2 and PCI evidence as code, GRC, incident response, and consolidating tools down to controls.
Essays on running a security program in regulated fintech: SOC 2 and PCI evidence as code, consolidating tool sprawl down to the controls that matter, breach-disclosure decisions, and treating culture as an auditable control. Written by Michael York, VP of Information Security & DevOps at SavvyMoney, from the work itself — not vendor talking points.
32 posts, newest first
Security Culture Is a Control. Audit It.
Security culture is usually a poster — no objective, no defined behavior, no evidence, no failure mode. Give it those four and it audits like any firewall.
70 Security Tools, 9 Controls: Consolidate
The license fee is the cheapest part of a security tool — integration, console staffing, and alert fatigue are the real bill. Rationalize on control coverage.
Evidence as Code: Make the Next Audit Boring
Audits feel like fire drills because evidence is hunted after the fact. Machine-readable SOC reports and modern PCI rules let proof live in the pipeline.
Start Post-Quantum Migration in 2026
Post-quantum cryptography stopped being research and became a config task. The teams that win aren't waiting for a quantum computer — they wait for nothing.
Your Security Program Is a Sales Asset
Why provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.
Pre-Wire Breach Disclosure Before the Breach
Materiality, the SEC's four-day clock, the OFAC ransom gate: decisions to pre-wire with a standing disclosure committee, not improvise at hour three.
Context Lock-In Is the Next Vendor Risk
Everyone negotiated data egress and capacity in their AI contracts. Almost nobody negotiated the prompts, context, and memory that became the switching cost.
WAF in the Agent Era: Good Bots vs. Abuse
Agents are now real customers hitting your edge with real economics. The old bot question — human or machine? — is the wrong one. Here's the one that matters.
Stop Charging the SSO Tax
SSO and audit logs are the controls a buyer needs to trust you — conversion features, not enterprise upsells. Paywall them and you tax your own funnel.
Consolidate SecOps on OCSF, Not Aggregators
Dashboard sprawl isn't a tooling gap you fix with more tooling — it's a schema problem. Standardize on OCSF and the single pane of glass becomes real.
Autonomous Pentesting in a Regulated Shop
A tool that scans and exploits your estate on its own schedule is a gift and a loaded gun. The scoping, approvals, and evidence I'd want before it runs.
The Eight-Domain Azure Security Review
A tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in audit order, and the evidence each has to produce.
Vendor License Audits: Bring Your Own Numbers
A vendor "license review" is a revenue motion in compliance clothes. Reconcile entitlements against deployment continuously and walk in with your own number.
Fine-Grained Authorization for Fintech APIs
Authorization scattered across your codebase isn't a feature — it's a liability you can't prove. The pattern multi-tenant regulated platforms actually need.
MCP Is a New Attack Surface: An IAM Playbook
Every MCP server is a new identity reaching into your cloud. Whether that's leverage or liability comes down to least-privilege IAM on every tool call.
Fraud and Security Are One Threat Model
Account takeover, synthetic identity, and scams sit between fraud and security — one adversary split across two budgets. Fuse the threat model and the signal.
The Audit Passed in March. Is It Still True?
Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits — and what it takes to run it year-round.
How to Survive an FFIEC Exam
An exam isn't a pop quiz you cram for. It's referenceable proof of control — run it right and the examiner's findings become your best sales collateral.
PCI DSS 4.0 Without the Last-Minute Scramble
PCI DSS 4.0 didn't add a longer checklist — it changed who does the thinking. Bake continuous-control expectations into engineering, not audit-week cramming.
Run a Human-Risk Program, Not Awareness
Training completion is the cleanest number in the board deck and the least tied to risk. Score human risk per team and measure behavior, not attendance.
Data Privacy Is an Operations Problem
Every privacy promise rests on unglamorous plumbing — consumer-rights workflows, retention, DLP. Treat privacy as an operating program, not an annual PDF.
An SBOM Nobody Reads Is Compliance Cosplay
Generating a software bill of materials is the easy part. Wiring it into the moment a change ships is where supply-chain security stops being theater.
Threat Intel Your Sales Team Will Brag About
Most threat intel dies as a PDF nobody reads. Done right, it sharpens your defense and becomes something your account team wants to put in front of customers.
Security and DevOps Under One Roof
The case for running security and DevOps as one mandate: org-chart distance doesn't create security, and owning the pipelines changes how you protect them.
Tabletops That Find Real Gaps
Most incident tabletops are theater confirming the runbook. The useful ones break your assumptions and expose who decides — before a real incident does.
SOC Metrics Are Vanity Until Decisions Change
MTTD and MTTR look great on a slide and tell you almost nothing. The only metric that matters is whether it changed what someone did next.
Third-Party Risk When You ARE the Third Party
Serving 1,500+ financial institutions means vendor-risk teams audit you constantly. Done right, that scrutiny becomes the fastest way to close your next deal.
Underwrite the Security Budget Like a Loss
The security budget is the line defended with emotion — and emotion gets discounted. Price the loss, count the revenue it unlocks, argue in the CFO's math.
Zero Trust for Humans: Just-in-Time Access
Everyone's obsessing over non-human identity. Meanwhile your humans sit on standing admin rights — and the fix only works if people will actually use it.
Incident Response: The First 24 Hours
Most IR plans are binders nobody opens at 2 a.m. What has to happen in the first day of a breach — roles, decision rights, evidence, and a comms cadence.
The New Security Leader's First 90 Days
Hired to build a security function from nothing? The trap isn't moving too slow — it's freezing the business. How to triage, ship quick wins, and earn budget.
Post-Close Cyber Integration: A 100-Day Plan
The post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.