en

Security Policy Audit for a Fintech Company

Client:
International company providing BaaS solutions and digital banking
Industry:
FinTech (financial technologies)
Focus:
Assessment of compliance with international security policy standards
Main challenge:
Review of core security policies and increasing their maturity in accordance with ISO 27001, DORA, GDPR, and NBG
Market:
International
Services provided:
Security policy and compliance audit
Key Takeaways
  • Seven key cybersecurity policies were reviewed and assessed
  • Regulations aligned with ISO 27001, DORA, GDPR, and NBG
  • Process maturity levels elevated to Managed / Optimized
  • Metrics and post-incident analysis processes implemented
  • Information Security Management System (ISMS) has improved
  • 7
    policies reviewed
    4
    standards assessed
    3
    weeks – audit duration
    Security Policy Audit for a Fintech Company
    For fintech companies, having a strong security system is critically important, as weak policies can lead to fines and failures during official inspections. To assess the real maturity level and improve process governance, the client approached Datami for a security policy audit.

    The company operates in the international financial technology market and provides digital banking and BaaS solutions for payment institutions, electronic money services, and fintech platforms.

    A business that handles personal and financial data must maintain robust security policies, as any deficiencies can lead to fines and compliance risks.

    Tasks and challenges
    The client approached Datami to assess key documents: Backup Policy, ISMS Policy, BCP/DRP, Cryptographic Policy, ICT Risk Management Framework, Security Monitoring and Logging Policy, and Governance and Control Overview.
     
    The fintech company also requested a compliance review of these security policies with international standards and regulatory requirements – ISO 27001, DORA, GDPR, and NBG.
    • Conduct an audit of security policies and assess their compliance with international standards
    • Provide reports with assessments and recommendations for improving maturity levels
    • Adjust the policies in accordance with international standards and best practices
    icon
    Security policy audit
    Examine and assess the maturity of seven key cybersecurity documents.
    icon
    Compliance review
    Analyze the coverage of ISO 27001, DORA, GDPR, and NBG requirements within the policies.
    icon
    Report and adjustments
    Prepare conclusions and update the policies to increase maturity.
    Main project stages

    The project work included three stages. After reviewing the documentation, the Datami team checked seven security policies for compliance with international standards.

    Based on the results of the audit, reports were prepared for each policy with recommendations for increasing the maturity level. The final stage was implementing the proposed changes.

    • Security policy review
      Analyzed the content of the documents, identified gaps, and checked compliance with four standards.
    • Reports with recommendations
      Prepared detailed conclusions and suggestions to increase process maturity and update each policy.
    • Policy updates
      Implemented the changes that strengthened the effectiveness, consistency, and manageability of the security system.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations
    Results and recommendations

    At the start of the project, several elements of the company’s security policies were assessed at the Defined and Repeatable maturity levels. After implementing Datami’s recommendations, the maturity level increased to Managed / Optimized.

    The fintech company received the following improvements:

    • implementation of MTTD, MTTA, MTTR, SLA, and FPR metrics;
    • mandatory post-incident analyses in accordance with DORA and ISO;
    • alignment of policy elements with regulatory standards;
    • strengthened vendor requirements and cryptographic clauses in contracts;
    • regular crypto-audits of third-party providers.

    As a result, the client significantly improved its cybersecurity posture:

    • security policies were updated according to ISO/IEC 27001, GDPR, DORA, and NBG requirements;
    • critical gaps in the Information Security Management System (ISMS) were identified and remediated;
    • access control, privilege management, logging, and monitoring were enhanced.

    Datami also recommended tracking updates to DORA, NBG, and GDPR and documenting them in the policy change log.

    Our certificates
    Project summary

    This case study demonstrates the importance of security policy audits for fintech companies operating in a regulated environment. Through collaboration with Datami, the client achieved compliance with international security standards and received a fully aligned set of documents.

    The project was completed within the agreed timeframe, enabling the company to prepare for upcoming audits, avoid regulatory risks, and strengthen partner trust.

    Policy maturity level
    Defined / Repeatable
    Managed / Optimized
    Audit readiness
    Low
    High, aligned with international standards
    Document consistency
    Partial, with gaps
    Full compliance with ISO, GDPR, DORA, NBG
    More success stories with Datami
    Browse other project case studies
    Mobile App Security Outstaff Audit

    Mobile App Security Outstaff Audit

    • Identified dangerous configurations and data leaks
    • Strengthened security before product launch
    Services:
     
    Nov 20, 2025
    Security Testing of the DonorUA Medical Platform

    Security Testing of the DonorUA Medical Platform

    • A report with recommendations for strengthening security was provided.
    • No critical security threats were confirmed.
    Services:
    Web application pentest (Black-box)
    Nov 18, 2025
    Security Protocol for INOI

    Security Protocol for INOI

    • A personalized Security Protocol has been developed
    • The company's readiness for crises has been improved
    Services:
    Development of a Security Protocol – cybersecurity consulting
    Nov 7, 2025
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    KillSec Ransomware Attacks Healthcare Datami Newsroom
    Datami Newsroom

    KillSec Ransomware Attacks Healthcare

    The hacker group KillSec has recently been actively attacking the IT systems of the healthcare sector in Latin America and other countries — the attackers have already stolen dozens of gigabytes and nearly 95,000 files.

    Nov 18, 2025
    Datami at MERGE Madrid and EBC 25 Datami Newsroom
    Datami Newsroom

    Datami at MERGE Madrid and EBC 25

    The Datami team attended MERGE Madrid and the European Blockchain Convention 2025 to share their expertise and witness how Web3 is evolving. This year, the focus shifted toward real-world solutions – security, auditing, and transparent standards.

    Nov 13, 2025 3 min
    Cyberattack Types Oleksandr Filipov: Security engineer at Datami, author of articles
    Oleksandr Filipov: Security engineer at Datami, author of articles

    Cyberattack Types

    To effectively protect data and systems, it is important to understand what types of cyberattacks exist and how they work. In this article, we will look at the main types of attacks and figure out how to protect your business from them.

    Nov 6, 2025 15 min
    Order a free consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy