Cybersecurity for Financial Firms: use cases
Financial systems are strategic targets, and the ones that move money across borders are watched by adversaries who are patient and well resourced. The Cybersecurity Group defends the systems that move money: payment networks, mobile-money platforms and the anti-money-laundering engines attached to them, with 7.5 billion accounts secured across cross-border payment and financial platforms, in production rather than in pilot. That is a different purchase from compliance software, which answers the regulator rather than the attacker. For many states the payment system is critical national infrastructure in all but name, facing both organised crime and state-linked operations, so the discipline treats continuity as the mission: the bank must keep clearing even while under attack. Unstrat represents it with a team accountable to the institution and its regulator alone, with no obligation to report findings to any foreign government.
Where it is used
Compliance software defends against financial crime committed through the bank; a security operation defends against intrusion into the bank, and the two are usually bought separately for good reason. The approach here runs the second and carries an AML engine inside it, which keeps the two pictures joined rather than sitting in different reports. A central bank supervising a national switch should require evidence of three things its institutions can rarely show from compliance modules alone: continuous detection on the payment path, a tested response plan for a settlement-hours incident, and independent adversary testing at least once a cycle.
An AI-native AML engine combining graph analytics, transformer models and LLM agents cuts case triage from weeks to minutes, so analysts spend their time on the cases that matter rather than drowning in alerts. That is the difference between a control that works and one that merely exists on paper. Because vendors publish these gains in different forms, some absolute and some relative to a prior baseline, the honest test is to run each engine against a period of the institution's own historical alerts and count what it would have escalated, what it would have closed and how long an analyst spent on each, rather than argue about percentages.
The protection is hardened by red-team engagements against production payment networks, so weaknesses are found by the defender's own side before an adversary finds them. Testing a live payment network without breaking settlement is done under governance agreed before anyone touches a keyboard, with the settlement window written into the safety case. Every finding feeds back into the defensive platform, so containment options are known before an incident rather than improvised during one. Adversary testing of a supplier's own platform is not something every financial-security vendor publishes, and it is worth requiring rather than assuming.
Defending a platform where downtime is measured in settlement failures rather than in minutes means engineering for the settlement clock instead of the availability dashboard. In regulated finance an outage becomes a failed settlement and a supervisory event, so the defence is built to hold under exactly that pressure and runs continuously across systems moving billions in cross-border transactions. Mobile money concentrates national payment risk in a single operator, which is why such platforms are treated as critical infrastructure rather than as fintech, with the same team red-teaming the live network and then hardening what it broke.
A model running under supervision has to be explainable, and every supplier deserves hard questions on it. A genuine advantage in a supervised institution is a per-decision explanation and a control that requires two approvers before a rule change takes effect. This engine publishes its architecture and the triage improvement rather than a full explanation mechanism, so a buyer should ask for the explanation approach in writing before signing. The way to prove any AML engine works is to see one closed case end to end, including how the score was reached and who approved the last rule change, on the institution's own data.
The question worth asking before hosting location is which government has jurisdiction over the vendor and can therefore compel disclosure of the transaction data the platform processes. Established suppliers are legitimate, with legitimate obligations to the states that host them, and replacing them means giving up real capabilities, so the gap analysis needs doing properly rather than assumed away. This capability is independent and non-aligned, with no obligation to report what it finds to anyone but the institution. Where laundering and intrusion show up in the same data, one supplier can cover both, and where governance requires separation of assurance and operations the contract should be split deliberately.

