Financial Security Glossary
A structured reference to the technologies, risks and resilience concepts behind modern finance — from authentication and cryptographic keys to settlement risk, third-party dependencies and systemic cyber resilience.
This glossary explains security concepts through the lens of banks, markets, payments, settlement and financial infrastructure rather than treating cybersecurity as an isolated IT discipline.
Definitions and explanations are original BondStats wording. The library does not reproduce third-party articles, proprietary diagrams, tables or long quoted passages.
Access Control
Rules and mechanisms that determine who or what can access systems, data and functions.
Open definition →IDENTITY & ACCESSAccount Takeover
Unauthorized control of a legitimate user or employee account.
Open definition →IDENTITY & ACCESSAuthentication
The process of verifying that a user, device or service is who or what it claims to be.
Open definition →IDENTITY & ACCESSAuthorization
The process of deciding which resources and actions an authenticated identity is permitted to use.
Open definition →IDENTITY & ACCESSMulti-Factor Authentication
Authentication that requires evidence from two or more independent factor categories.
Open definition →IDENTITY & ACCESSPrivileged Access Management
Controls for issuing, monitoring and limiting high-privilege administrative access.
Open definition →IDENTITY & ACCESSZero Trust
A security model that continuously verifies access rather than assuming trust from network location alone.
Open definition →IDENTITY & ACCESSLeast Privilege
The principle of granting only the minimum access required for a task.
Open definition →CRYPTOGRAPHYEncryption
The transformation of readable information into protected ciphertext using cryptographic algorithms and keys.
Open definition →CRYPTOGRAPHYEncryption at Rest
Protection applied to stored data such as databases, disks, backups and archives.
Open definition →CRYPTOGRAPHYEncryption in Transit
Protection applied while data moves between systems or networks.
Open definition →CRYPTOGRAPHYCryptographic Key
A value used by a cryptographic algorithm to encrypt, decrypt, sign or verify information.
Open definition →CRYPTOGRAPHYKey Management
The lifecycle controls used to generate, store, distribute, rotate, revoke and destroy cryptographic keys.
Open definition →CRYPTOGRAPHYHardware Security Module
A hardened device designed to generate, protect and use cryptographic keys in a controlled environment.
Open definition →CRYPTOGRAPHYDigital Signature
A cryptographic mechanism used to verify the origin and integrity of digital information.
Open definition →CRYPTOGRAPHYCertificate Authority
An entity that issues and manages digital certificates binding identities to cryptographic keys.
Open definition →OPERATIONAL RESILIENCECyber Resilience
The ability to anticipate, withstand, recover from and adapt to cyber disruption.
Open definition →OPERATIONAL RESILIENCEOperational Resilience
The ability to continue delivering important services through operational disruption.
Open definition →OPERATIONAL RESILIENCEBusiness Continuity
Planning and capabilities designed to keep essential business activities operating during disruption.
Open definition →OPERATIONAL RESILIENCEDisaster Recovery
The processes and technology used to restore systems, applications and data after a major disruption.
Open definition →OPERATIONAL RESILIENCERecovery Time Objective
The target maximum period for restoring a service after disruption.
Open definition →OPERATIONAL RESILIENCERecovery Point Objective
The maximum acceptable amount of data loss measured backward in time from a disruption.
Open definition →OPERATIONAL RESILIENCEIncident Response
The coordinated process for detecting, containing, investigating and recovering from a security incident.
Open definition →OPERATIONAL RESILIENCEIncident Containment
Actions taken to limit the spread and impact of an active security incident.
Open definition →OPERATIONAL RESILIENCEBackup
A separate copy of data or system state maintained for recovery after loss, corruption or compromise.
Open definition →OPERATIONAL RESILIENCEImmutable Backup
A backup designed so that stored recovery data cannot be altered or deleted during a defined retention period.
Open definition →CYBER THREATSRansomware
Malware or intrusion activity that disrupts access to systems or data and is commonly paired with extortion.
Open definition →CYBER THREATSPhishing
Deceptive communication intended to persuade a target to reveal information, approve an action or execute malicious content.
Open definition →CYBER THREATSSpear Phishing
Highly targeted phishing tailored to a specific person, role or organization.
Open definition →CYBER THREATSBusiness Email Compromise
Fraud in which trusted business communications or accounts are impersonated or compromised to manipulate payments or sensitive actions.
Open definition →CYBER THREATSMalware
Software intentionally designed to disrupt, damage, spy on or gain unauthorized access to systems.
Open definition →CYBER THREATSDistributed Denial of Service
An attack that overwhelms an online service with traffic or requests from many sources.
Open definition →CYBER THREATSCredential Stuffing
Automated attempts to reuse stolen username and password combinations across services.
Open definition →CYBER THREATSInsider Threat
Security risk arising from people with legitimate access who act maliciously, negligently or under coercion.
Open definition →THIRD-PARTY RISKSupply Chain Attack
A compromise that reaches a target through software, services, vendors or other dependencies.
Open definition →THIRD-PARTY RISKThird-Party Risk
Operational, cyber and compliance risk introduced by external providers and service relationships.
Open definition →THIRD-PARTY RISKConcentration Risk
Risk created when many critical services depend on the same provider, technology or location.
Open definition →THIRD-PARTY RISKCloud Concentration Risk
Systemic dependency created when important workloads across institutions rely on a small number of cloud providers or regions.
Open definition →THIRD-PARTY RISKSoftware Supply Chain
The developers, libraries, build systems, repositories and distribution channels involved in producing software.
Open definition →THIRD-PARTY RISKVendor Risk Management
The process of identifying, assessing, monitoring and controlling risks from external providers.
Open definition →FINANCIAL INFRASTRUCTUREPayment System
Infrastructure and rules used to transfer monetary value between participants.
Open definition →FINANCIAL INFRASTRUCTUREReal-Time Gross Settlement
A settlement model in which individual payments are settled continuously and finally rather than netted for later settlement.
Open definition →FINANCIAL INFRASTRUCTUREClearing
The process of determining obligations between parties before final settlement.
Open definition →FINANCIAL INFRASTRUCTURESettlement
The final transfer of cash or securities that completes a financial transaction.
Open definition →FINANCIAL INFRASTRUCTURESettlement Risk
The risk that one side of a transaction delivers value while the other side does not complete its obligation as expected.
Open definition →FINANCIAL INFRASTRUCTUREDelivery versus Payment
A settlement mechanism linking securities delivery to the corresponding payment so one occurs only if the other does.
Open definition →FINANCIAL INFRASTRUCTUREPayment versus Payment
A settlement mechanism linking the two currency legs of an FX transaction so one is settled only if the other is.
Open definition →FINANCIAL INFRASTRUCTURECentral Counterparty
An entity that interposes itself between counterparties to cleared trades and manages resulting exposures.
Open definition →FINANCIAL INFRASTRUCTURECentral Securities Depository
Infrastructure that records securities ownership and supports securities settlement and related services.
Open definition →FINANCIAL INFRASTRUCTURECorrespondent Banking
A relationship in which one bank provides payment or other banking services to another bank, often across borders.
Open definition →FINANCIAL INFRASTRUCTURESWIFT
A global cooperative network and standards environment used by financial institutions to exchange structured financial messages.
Open definition →FINANCIAL INFRASTRUCTURECLS
A financial market infrastructure that settles eligible foreign-exchange transactions using payment-versus-payment mechanisms.
Open definition →DATA SECURITYMarket Data Integrity
The accuracy, completeness and trustworthiness of data used for pricing, trading and risk decisions.
Open definition →DATA SECURITYData Integrity
The property that data remains accurate, complete and protected from unauthorized modification.
Open definition →DATA SECURITYData Loss Prevention
Controls intended to detect and prevent unauthorized disclosure or transfer of sensitive information.
Open definition →DATA SECURITYData Classification
The process of categorizing information according to sensitivity, criticality and required protection.
Open definition →DETECTION & MONITORINGSecurity Information and Event Management
Technology and processes that aggregate and analyze security logs and events across systems.
Open definition →DETECTION & MONITORINGSecurity Operations Center
A function responsible for monitoring, detecting, investigating and coordinating responses to security events.
Open definition →DETECTION & MONITORINGThreat Intelligence
Information about threat actors, techniques, vulnerabilities and indicators used to support security decisions.
Open definition →DETECTION & MONITORINGVulnerability Management
The continuous process of identifying, assessing, prioritizing and remediating security weaknesses.
Open definition →DETECTION & MONITORINGPenetration Testing
Authorized testing that simulates attacker techniques to identify exploitable weaknesses in systems and controls.
Open definition →DETECTION & MONITORINGRed Team
An authorized team that emulates adversary behavior to test detection, response and defensive controls.
Open definition →DETECTION & MONITORINGThreat-Led Penetration Testing
A controlled security test designed around realistic threat intelligence and adversary behavior.
Open definition →REGULATION & GOVERNANCEDORA
The EU Digital Operational Resilience Act, a framework establishing ICT risk, incident, testing and third-party resilience requirements for financial entities.
Open definition →REGULATION & GOVERNANCENIS2
An EU cybersecurity directive establishing risk-management and incident-reporting requirements for covered essential and important entities.
Open definition →REGULATION & GOVERNANCECyber Risk Governance
The structures through which boards and management oversee cyber risk, responsibilities, controls and accountability.
Open definition →REGULATION & GOVERNANCECyber Incident Reporting
The formal notification of qualifying cyber or operational incidents to relevant authorities or stakeholders.
Open definition →REGULATION & GOVERNANCEOperational Risk
The risk of loss or disruption arising from inadequate or failed processes, people, systems or external events.
Open definition →SYSTEMIC RISKSystemic Cyber Risk
Cyber risk capable of causing disruption across multiple institutions, markets or critical financial functions.
Open definition →SYSTEMIC RISKCyber Contagion
The propagation of cyber-related disruption through technical, operational or financial interconnections.
Open definition →SYSTEMIC RISKSingle Point of Failure
A component whose failure can stop a wider system because no adequate alternative path exists.
Open definition →SYSTEMIC RISKCritical Financial Infrastructure
Systems and services whose disruption could materially impair payments, markets, settlement or financial stability.
Open definition →SYSTEMIC RISKResilience Testing
Structured exercises used to evaluate whether critical services can withstand and recover from severe disruption.
Open definition →