CFOtech US - Technology news for CFOs & financial decision-makers
United States
Greenwich Pacific launches cyber-recovery service for banks

Greenwich Pacific launches cyber-recovery service for banks

Wed, 16th Sep 2026 (Today)
Karen Joy Bacudo
KAREN JOY BACUDO Finance Editor

Greenwich Pacific Technology Partners has launched a combined cybersecurity, penetration-testing and cyber-recovery service for US financial institutions, bringing three service lines into a single programme.

The New York-based consultancy is targeting banks, broker-dealers, asset managers, payment firms and fintechs facing rising scrutiny over operational resilience, third-party technology risk and recovery readiness. Examiners and counterparties are placing greater weight on evidence that systems can be tested, monitored and restored within stated tolerances.

The service combines offensive testing, defensive engineering and cyber-recovery engineering. Offensive testing includes application, network and cloud penetration testing aligned to OWASP and MITRE ATT&CK, alongside red-team-style exercises based on banking attack paths.

Defensive engineering covers SIEM and SOC integration, identity and privileged-access hardening across Entra ID, Okta and CyberArk estates, and web application firewall and network segmentation work across Palo Alto, Cisco, NetScaler and Zscaler environments. Cyber-recovery engineering includes clean-room recovery design, immutable backup architectures, isolated recovery environments and ransomware recovery runbooks tested against contracted recovery time objective and recovery point objective targets.

Timothy Kumar, Consulting Technical Director at Greenwich Pacific Technology Partners, said customers are facing a shift in how resilience is judged.

"Examiners increasingly want evidence that a bank can actually recover - not a binder that says it can," Kumar said.

"We test the controls, break the systems safely, and then prove the recovery. That is the difference between compliance on paper and resilience in practice."

The launch comes as US financial institutions face several linked pressures. The firm said regulators have raised expectations for tested operational resilience, while ransomware incidents have pushed recovery engineering to board level and supplier-related incidents have increased demands from counterparties and auditors for penetration-testing evidence.

Rules and supervisory expectations cited by the firm include FFIEC-style examinations and New York's DFS Part 500 regime. In that environment, institutions are being asked to demonstrate tested controls rather than rely on documented policies alone.

Three phases

Engagements typically run in three stages. The first is a resilience baseline covering attack-surface mapping, control review against NIST CSF and ISO 27001, and an assessment of recovery readiness against stated recovery time and recovery point targets.

The second stage is a live test phase involving scoped penetration testing and recovery exercises, including controlled clean-room restores of priority systems. The third focuses on remediation and hardening, with engineers implementing fixes such as identity controls, segmentation, logging and backup architecture changes rather than producing only a findings report.

Kumar said many mid-sized financial firms struggle to dedicate enough senior engineering time to separate testing, resilience and recovery work.

"Most mid-tier institutions know they need to test more and recover better - the blocker is senior engineering time," Kumar said.

"A community bank or a growth-stage payments firm cannot hire a red team, a resilience architect and a recovery engineer as three separate headcount. Our model puts one senior team across all three disciplines, so the findings from the offensive work feed directly into the defensive fixes and the recovery design. Nothing gets lost between a report and the backlog."

The service is also intended to support institutions responding to examination findings, audit issues or customer due diligence requests where remediation must be demonstrated within fixed timelines. Consultants work alongside client teams across Eastern and Central US time zones, with on-site support available for key testing and recovery milestones.

Greenwich Pacific Technology Partners focuses on regulated technology infrastructure for US banks, broker-dealers, asset managers, payment firms and fintechs. Its work spans cybersecurity and resilience, payments and ISO 20022, cloud and platform engineering, infrastructure, data engineering, and technology risk and controls, aligned with expectations from bodies including the OCC, FDIC, Federal Reserve, SEC, FINRA and FFIEC.

Kumar said the central issue is whether institutions can show working recovery rather than present documentation.

"The industry has trained itself to measure security programmes by artefacts - policies, assessments, dashboards. Regulators are now asking a harder question: show us the restore. Our engagements end with a demonstrated recovery and a tested control set, not a recommendations list. That is what boards should be asking their providers for, and it is what we commit to contractually."