Why Older Adults Are at Greater...
Impersonation scams are making it easier for fraudsters to exploit trust, particularly where older relatives or vulnerable customers are involved....
Read MoreThe financial sector remains a prime target for cybercriminals, leading to continuous updates in compliance standards. Each year, SWIFT revises its CSCF, which can impact payment operations and associated technologies. These updates apply to all organisations using SWIFT. To meet the 2025 requirements, businesses must undergo an independent review to verify that all mandatory controls are in place before completing their attestation.
The framework consists of 32 security controls – 25 mandatory and 7 advisory – structured around key objectives to strengthen the security of SWIFT users’ infrastructure. These controls serve as the basis for independent security assessments and the required Know Your Customer-Security Attestation (KYC-SA), which all SWIFT users must complete.
The latest update to SWIFT’s Customer Security Controls Framework (CSCF) for 2025 introduces no major changes, with a focus instead on minor adjustments and clarifications to improve understanding and consistency. Unlike previous years, no advisory controls have been elevated to mandatory status, and SWIFT has indicated that the overall requirement level will remain stable after successive increases in recent updates. Uncharacteristically, they have already announced Control 2.4 becomes mandatory in 2026.
While there are no new mandatory controls for the 2025 assessment cycle, there are changes organisations need to make to achieve a compliant audit, particularly:
While the 2025 update does not introduce immediate mandatory changes, organisations should take a proactive approach, particularly in preparing for the expected elevation of Control 2.4A.
Are you Ready for Compliance v2025?
It is essential for SWIFT users to align their security controls with CSCF requirements and undergo annual compliance verification. SWIFT requires an independent review of at least all mandatory controls within the attestation process to ensure reliability, consistency, and accuracy in security assessments.
Ensure timely resolution of any non-compliance issues prior to the end of 2025 with our SWIFT Compliance Assessment. AJC offers comprehensive cybersecurity services encompassing assistance in evaluating the SWIFT customer security programmes. Our comprehensive SWIFT assessment reviews your current security posture and offers clear, actionable recommendations to help you meet the 2025 requirements.
Please contact us on 020 7101 4861 email us info@ajollyconsulting.co.uk if you think we can help.
Image accreditation: Philipp Katzenberger (January 2019) from Unsplash.com. Last accessed on 12th March 2024. Available at: https://unsplash.com/photos/closeup-photo-of-turned-on-blue-and-white-laptop-computer-iIJrUoeRoCQ
Impersonation scams are making it easier for fraudsters to exploit trust, particularly where older relatives or vulnerable customers are involved....
Read MoreAI chatbots are becoming part of everyday business operations, but they can also create new security risks. This article looks...
Read MoreIn this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...
Read More