Finance and insurance
Banks, PSFs, funds, insurers, asset managers
Connected sources
- Microsoft 365 or Google Workspace tenants and employee accounts
- Business applications: online banking, portfolio management, KYC platforms, reporting tools
- Bastion hosts and administrator accounts, ICT third-party provider access
- Firewalls, VPN, endpoints and EDR, databases
- Code of in-house applications, via LuxGap DevOps
What the SOC detects
- Abnormal sign-ins and MFA bypasses on sensitive accounts
- Business email compromise and payment diversion fraud attempts
- Provider access outside agreed windows
- Client data exfiltration, bulk queries
- Internet-exposed vulnerabilities and configuration deviations
Regulatory framework
DORA (initial notification of major incidents to the CSSF within 4 hours of classification), CSSF circulars, GDPR, anti-money laundering obligations for KYC platforms.