BondStats
Learn / Security in Finance / Financial Security Glossary
SECURITY IN FINANCE · A–Z

Financial Security Glossary

A structured reference to the technologies, risks and resilience concepts behind modern finance — from authentication and cryptographic keys to settlement risk, third-party dependencies and systemic cyber resilience.

73SECURITY TERMS
10TOPIC AREAS
73CRAWLABLE TERM PAGES
OriginalBONDSTATS EXPLANATIONS
Built for financial context

This glossary explains security concepts through the lens of banks, markets, payments, settlement and financial infrastructure rather than treating cybersecurity as an isolated IT discipline.

Copyright-safe editorial approach

Definitions and explanations are original BondStats wording. The library does not reproduce third-party articles, proprietary diagrams, tables or long quoted passages.

IDENTITY & ACCESS

Access Control

Rules and mechanisms that determine who or what can access systems, data and functions.

Open definition →
IDENTITY & ACCESS

Account Takeover

Unauthorized control of a legitimate user or employee account.

Open definition →
IDENTITY & ACCESS

Authentication

The process of verifying that a user, device or service is who or what it claims to be.

Open definition →
IDENTITY & ACCESS

Authorization

The process of deciding which resources and actions an authenticated identity is permitted to use.

Open definition →
IDENTITY & ACCESS

Multi-Factor Authentication

Authentication that requires evidence from two or more independent factor categories.

Open definition →
IDENTITY & ACCESS

Privileged Access Management

Controls for issuing, monitoring and limiting high-privilege administrative access.

Open definition →
IDENTITY & ACCESS

Zero Trust

A security model that continuously verifies access rather than assuming trust from network location alone.

Open definition →
IDENTITY & ACCESS

Least Privilege

The principle of granting only the minimum access required for a task.

Open definition →
CRYPTOGRAPHY

Encryption

The transformation of readable information into protected ciphertext using cryptographic algorithms and keys.

Open definition →
CRYPTOGRAPHY

Encryption at Rest

Protection applied to stored data such as databases, disks, backups and archives.

Open definition →
CRYPTOGRAPHY

Encryption in Transit

Protection applied while data moves between systems or networks.

Open definition →
CRYPTOGRAPHY

Cryptographic Key

A value used by a cryptographic algorithm to encrypt, decrypt, sign or verify information.

Open definition →
CRYPTOGRAPHY

Key Management

The lifecycle controls used to generate, store, distribute, rotate, revoke and destroy cryptographic keys.

Open definition →
CRYPTOGRAPHY

Hardware Security Module

A hardened device designed to generate, protect and use cryptographic keys in a controlled environment.

Open definition →
CRYPTOGRAPHY

Digital Signature

A cryptographic mechanism used to verify the origin and integrity of digital information.

Open definition →
CRYPTOGRAPHY

Certificate Authority

An entity that issues and manages digital certificates binding identities to cryptographic keys.

Open definition →
OPERATIONAL RESILIENCE

Cyber Resilience

The ability to anticipate, withstand, recover from and adapt to cyber disruption.

Open definition →
OPERATIONAL RESILIENCE

Operational Resilience

The ability to continue delivering important services through operational disruption.

Open definition →
OPERATIONAL RESILIENCE

Business Continuity

Planning and capabilities designed to keep essential business activities operating during disruption.

Open definition →
OPERATIONAL RESILIENCE

Disaster Recovery

The processes and technology used to restore systems, applications and data after a major disruption.

Open definition →
OPERATIONAL RESILIENCE

Recovery Time Objective

The target maximum period for restoring a service after disruption.

Open definition →
OPERATIONAL RESILIENCE

Recovery Point Objective

The maximum acceptable amount of data loss measured backward in time from a disruption.

Open definition →
OPERATIONAL RESILIENCE

Incident Response

The coordinated process for detecting, containing, investigating and recovering from a security incident.

Open definition →
OPERATIONAL RESILIENCE

Incident Containment

Actions taken to limit the spread and impact of an active security incident.

Open definition →
OPERATIONAL RESILIENCE

Backup

A separate copy of data or system state maintained for recovery after loss, corruption or compromise.

Open definition →
OPERATIONAL RESILIENCE

Immutable Backup

A backup designed so that stored recovery data cannot be altered or deleted during a defined retention period.

Open definition →
CYBER THREATS

Ransomware

Malware or intrusion activity that disrupts access to systems or data and is commonly paired with extortion.

Open definition →
CYBER THREATS

Phishing

Deceptive communication intended to persuade a target to reveal information, approve an action or execute malicious content.

Open definition →
CYBER THREATS

Spear Phishing

Highly targeted phishing tailored to a specific person, role or organization.

Open definition →
CYBER THREATS

Business Email Compromise

Fraud in which trusted business communications or accounts are impersonated or compromised to manipulate payments or sensitive actions.

Open definition →
CYBER THREATS

Malware

Software intentionally designed to disrupt, damage, spy on or gain unauthorized access to systems.

Open definition →
CYBER THREATS

Distributed Denial of Service

An attack that overwhelms an online service with traffic or requests from many sources.

Open definition →
CYBER THREATS

Credential Stuffing

Automated attempts to reuse stolen username and password combinations across services.

Open definition →
CYBER THREATS

Insider Threat

Security risk arising from people with legitimate access who act maliciously, negligently or under coercion.

Open definition →
THIRD-PARTY RISK

Supply Chain Attack

A compromise that reaches a target through software, services, vendors or other dependencies.

Open definition →
THIRD-PARTY RISK

Third-Party Risk

Operational, cyber and compliance risk introduced by external providers and service relationships.

Open definition →
THIRD-PARTY RISK

Concentration Risk

Risk created when many critical services depend on the same provider, technology or location.

Open definition →
THIRD-PARTY RISK

Cloud Concentration Risk

Systemic dependency created when important workloads across institutions rely on a small number of cloud providers or regions.

Open definition →
THIRD-PARTY RISK

Software Supply Chain

The developers, libraries, build systems, repositories and distribution channels involved in producing software.

Open definition →
THIRD-PARTY RISK

Vendor Risk Management

The process of identifying, assessing, monitoring and controlling risks from external providers.

Open definition →
FINANCIAL INFRASTRUCTURE

Payment System

Infrastructure and rules used to transfer monetary value between participants.

Open definition →
FINANCIAL INFRASTRUCTURE

Real-Time Gross Settlement

A settlement model in which individual payments are settled continuously and finally rather than netted for later settlement.

Open definition →
FINANCIAL INFRASTRUCTURE

Clearing

The process of determining obligations between parties before final settlement.

Open definition →
FINANCIAL INFRASTRUCTURE

Settlement

The final transfer of cash or securities that completes a financial transaction.

Open definition →
FINANCIAL INFRASTRUCTURE

Settlement Risk

The risk that one side of a transaction delivers value while the other side does not complete its obligation as expected.

Open definition →
FINANCIAL INFRASTRUCTURE

Delivery versus Payment

A settlement mechanism linking securities delivery to the corresponding payment so one occurs only if the other does.

Open definition →
FINANCIAL INFRASTRUCTURE

Payment versus Payment

A settlement mechanism linking the two currency legs of an FX transaction so one is settled only if the other is.

Open definition →
FINANCIAL INFRASTRUCTURE

Central Counterparty

An entity that interposes itself between counterparties to cleared trades and manages resulting exposures.

Open definition →
FINANCIAL INFRASTRUCTURE

Central Securities Depository

Infrastructure that records securities ownership and supports securities settlement and related services.

Open definition →
FINANCIAL INFRASTRUCTURE

Correspondent Banking

A relationship in which one bank provides payment or other banking services to another bank, often across borders.

Open definition →
FINANCIAL INFRASTRUCTURE

SWIFT

A global cooperative network and standards environment used by financial institutions to exchange structured financial messages.

Open definition →
FINANCIAL INFRASTRUCTURE

CLS

A financial market infrastructure that settles eligible foreign-exchange transactions using payment-versus-payment mechanisms.

Open definition →
DATA SECURITY

Market Data Integrity

The accuracy, completeness and trustworthiness of data used for pricing, trading and risk decisions.

Open definition →
DATA SECURITY

Data Integrity

The property that data remains accurate, complete and protected from unauthorized modification.

Open definition →
DATA SECURITY

Data Loss Prevention

Controls intended to detect and prevent unauthorized disclosure or transfer of sensitive information.

Open definition →
DATA SECURITY

Data Classification

The process of categorizing information according to sensitivity, criticality and required protection.

Open definition →
DETECTION & MONITORING

Security Information and Event Management

Technology and processes that aggregate and analyze security logs and events across systems.

Open definition →
DETECTION & MONITORING

Security Operations Center

A function responsible for monitoring, detecting, investigating and coordinating responses to security events.

Open definition →
DETECTION & MONITORING

Threat Intelligence

Information about threat actors, techniques, vulnerabilities and indicators used to support security decisions.

Open definition →
DETECTION & MONITORING

Vulnerability Management

The continuous process of identifying, assessing, prioritizing and remediating security weaknesses.

Open definition →
DETECTION & MONITORING

Penetration Testing

Authorized testing that simulates attacker techniques to identify exploitable weaknesses in systems and controls.

Open definition →
DETECTION & MONITORING

Red Team

An authorized team that emulates adversary behavior to test detection, response and defensive controls.

Open definition →
DETECTION & MONITORING

Threat-Led Penetration Testing

A controlled security test designed around realistic threat intelligence and adversary behavior.

Open definition →
REGULATION & GOVERNANCE

DORA

The EU Digital Operational Resilience Act, a framework establishing ICT risk, incident, testing and third-party resilience requirements for financial entities.

Open definition →
REGULATION & GOVERNANCE

NIS2

An EU cybersecurity directive establishing risk-management and incident-reporting requirements for covered essential and important entities.

Open definition →
REGULATION & GOVERNANCE

Cyber Risk Governance

The structures through which boards and management oversee cyber risk, responsibilities, controls and accountability.

Open definition →
REGULATION & GOVERNANCE

Cyber Incident Reporting

The formal notification of qualifying cyber or operational incidents to relevant authorities or stakeholders.

Open definition →
REGULATION & GOVERNANCE

Operational Risk

The risk of loss or disruption arising from inadequate or failed processes, people, systems or external events.

Open definition →
SYSTEMIC RISK

Systemic Cyber Risk

Cyber risk capable of causing disruption across multiple institutions, markets or critical financial functions.

Open definition →
SYSTEMIC RISK

Cyber Contagion

The propagation of cyber-related disruption through technical, operational or financial interconnections.

Open definition →
SYSTEMIC RISK

Single Point of Failure

A component whose failure can stop a wider system because no adequate alternative path exists.

Open definition →
SYSTEMIC RISK

Critical Financial Infrastructure

Systems and services whose disruption could materially impair payments, markets, settlement or financial stability.

Open definition →
SYSTEMIC RISK

Resilience Testing

Structured exercises used to evaluate whether critical services can withstand and recover from severe disruption.

Open definition →
No matching terms.