SWIFT Customer Security Programme: The Essentials
SWIFT Customer Security Programme: The Essentials
Security Programme
The essentials
December 2020
Why is it important?
What is the SWIFT Customer In response to a number of cyber In 2020*, SWIFT promoted 2 existing
Security Programme (CSP)? attacks and breaches throughout advisory controls to mandatory and
2016, in 2017 SWIFT identified, 16 introduced 2 new advisory controls
mandatory and 11 optional security resulting in 21 mandatory and 10
SWIFT has introduced its Customer controls for all of its 11,000 advisory controls in the CSCF
Security Controls Framework customers worldwide. All customers V2020. For 2021, SWIFT promoted 1
(CSCF) to drive security are asked to attest to meeting the control to mandatory resulting in 22
improvement and transparency controls on an annual basis, and the mandatory and 9 advisory controls in
across the global financial results of same are shared with the CSCF v2021. As from mid-2021,
community.The SWIFT CSP counterparts and regulators. organizations will need to support
focuses on three mutually How will this impact their attestation against CSCF
reinforcing areas: protecting and SWIFT customers? v2021 with an independent internal
securing your local environment, or external assessment.
preventing and detecting fraud in The SWIFT CSP has evolved, and will
your commercial relationships, and continue to do so, since inception. What are the success factors?
continuously sharing information Customers will need to continue to To be successful, organisations must
and preparing to defend against implement security controls and raise take a thoughtful and systematic
future cyber threats. the bar to ensure compliance with the approach, requiring collaboration
CSCF. Previously, SWIFT customers across the three lines of defence,
While all customers remain were required to self-attest to the
primarily responsible for protecting strong leadership and a diverse
CSCF V2019 by 31 December 2019. organised team. Are you ready for
their own environments, SWIFT’s This updated framework contained 19
CSP aims to support its community this increased level of mandatory
mandatory and 10 advisory requirements?
in the fight against cyber-attacks. security controls.
*Given the global COVID-19 situation SWIFT has published updated guidelines on 18 June 2020 regarding
changes to CSP self-attestation and independent assessment requirements for 2020. SWIFT has announced that
in 2020, customers can self-attest against the 2019 version of the SWIFT CSP and can optionally support the
self-attestation with an independent assessment. In 2021, independent assessment will be a mandatory
requirement and customers will be required to attest against the 2021 version of the CSP framework.
What milestones should you be aware of?
2020 2020 2021 2021
PwC capabilities
How can Pwc help to meet SWIFT’S Independent assessment?
SWIFT CSP assessment Embedded in internal audit
A detailed independent assessment of Work alongside your Internal Audit,
SWIFT CSP controls by leveraging our Information Technology, and/or Risk
CSP accelerator functions to report on SWIFT CSP controls
This content is for general information purposes only, and should not be used as a substitute for consultation with professional advisors.
© 2020 PwC. All rights reserved. PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity. Please see
www.pwc.com/structure for further details.