HOME NEWS ARTICLES PODCASTS VIDEOS EVENTS JOBS COMMUNITY TECH DIRECTORY ABOUT US
at Financial Technnology Year
Comprehensive managed detection and response, security assessments, threat intelligence, cloud and endpoint protection, and compliance services optimized for financial sector.
More about EY (Ernst & Young) Cybersecurity
Specialized security tools protecting sensitive deal information, portfolio company data, and limited partner communications.
More Cybersecurity Solutions
More Operations and Finance ...
Multi-factor Authentication (MFA) Requires users to verify identity using multiple credentials for critical systems. |
EY Cybersecurity Managed Services provides identity management, access control, and critical system protection, typically deploying MFA as a baseline security control. Supported by offering to financial sector. | |
Single Sign-On (SSO) Support Allows seamless, secure access to multiple systems using one set of credentials. |
Single Sign-On is standard in managed security solutions integrating with client IT; SSO mentioned as part of enabling seamless identity integration. | |
Role-Based Access Control (RBAC) Assigns system permissions based on job role to enforce least-privilege access. |
Role-Based Access Control is referenced in managed security documentation for least-privilege implementations as a best practice for clients. | |
User Provisioning and De-provisioning Speed Time required to add or revoke user access upon onboarding or departure. |
No information available | |
Privileged User Monitoring Tracks activities of high-access users for early detection of misuse. |
Privileged user monitoring is included as part of managed detection and response, as per marketing documentation and industry practice. | |
Audit Trail Retention Period Length of time that records of user access and changes are kept. |
No information available | |
Integration With Directory Services Can synchronize with corporate directories (e.g., Active Directory, LDAP). |
Integration with Active Directory and similar directory services is typical for a managed cybersecurity provider; EY states readiness for client directory integration. | |
Self-Service Password Reset Allows users to securely reset passwords without admin involvement. |
No information available | |
Account Lockout Threshold Number of failed login attempts allowed before an account is locked. |
No information available | |
Mandatory Password Expiry Enforces periodic password changes to reduce the risk of compromise. |
Password policies and regular forced password changes are a staple within financial service security compliance and expected from a managed solution. |
In-Transit Encryption Utilizes strong cryptographic protocols (e.g., TLS 1.2+) for data moving across networks. |
EY advertises extensive in-transit encryption/TLS 1.2+ for data protection as part of managed services. | |
At-Rest Encryption Ensures stored data in databases and file systems is encrypted. |
EY documentation and reference architectures cite encryption at rest in all managed environments. | |
End-to-End Encryption for Communications All communication channels (email, messaging, file transfer) support end-to-end encryption. |
End-to-end encryption is noted for critical communications and cloud-native managed services. | |
Encryption Key Management Automated and audited management of cryptographic keys. |
Key management is a fundamental component of enterprise cyber managed services, with mentions in compliance documentation. | |
Granularity of Data Encryption Defines whether encryption is file-level, database-level, or field-level. |
No information available | |
Hardware Security Module (HSM) Integration Supports securing keys within HSMs for added protection. |
Enterprise-grade encryption and integration with HSMs are included in managed environments for financial services. | |
Secure File Sharing Enables secure, encrypted document sharing with third parties or LPs. |
Secure file sharing solutions incorporating encryption and secure access for third parties are part of regulated managed service packages. | |
Data Loss Prevention (DLP) Monitors and blocks unauthorized data transfers inside and outside the organization. |
Data Loss Prevention is a promoted offering in their managed cybersecurity service for regulated industries. | |
Real-time Data Encryption Speed The speed at which the system can encrypt or decrypt data in real-time. |
No information available | |
Compliance with Industry Encryption Standards Effectively meets standards such as FIPS 140-2/3 or ISO/IEC 27001. |
EY references compliance with standards such as FIPS, ISO/IEC 27001 in their managed security documentation. |
Real-time Threat Detection Ability to identify threats as they occur using AI/ML and signature-based detection. |
AI- and ML-based real-time threat detection is highlighted as part of the MDR capabilities. | |
Automated Incident Response Workflows System can automatically respond to certain threat types to contain damage. |
Automated workflows for incident containment and response are standard features cited in the product overview. | |
Security Event Log Retention How long security events/logs are retained for forensic analysis. |
No information available | |
Integration with SIEM (Security Information and Event Management) Ability to feed data to SIEM platforms for correlated analysis. |
Integration with SIEMs is explicitly mentioned under service interoperability and client integration. | |
Alert Notification Time Maximum time between threat detection and alerting security staff. |
No information available | |
24/7 Monitoring Security monitoring is available at all times, not just business hours. |
24/7 SOC monitoring and alerting is a core value proposition of managed detection and response. | |
Customizable Threat Signatures Can create and tune custom detection signatures for sector-specific threats. |
Product claims customization and tuning of detection signatures, as expected of enterprise MDR/XDR. | |
Phishing Detection and Prevention Alerts users and blocks suspicious communications targeting credentials. |
Phishing prevention and domain warning capabilities are listed as part of cyber defense features. | |
Incident Response Playbooks Pre-defined, customizable workflows for different incident types. |
Incident response playbooks and tailored runbooks are an advertised deliverable for clients. | |
Mean Time to Detect (MTTD) Average time between threat occurring and being discovered. |
. | No information available |
Encrypted Messaging Internal and external chat/messages are encrypted at rest and in transit. |
. | No information available |
Secure Video Conferencing Video meetings use encryption and access controls to protect confidentiality. |
. | No information available |
Encrypted Email Integration Email solutions support encrypted delivery and attachments. |
. | No information available |
Customizable Access Policies for Communications Ability to restrict communication tools usage by user or group. |
. | No information available |
Automated Message Retention Policy Controls how long communication records are kept and when they are deleted. |
. | No information available |
Message Recall or Revocation Capability to retract messages sent in error. |
. | No information available |
Digital Signatures on Communications Ensures authenticity and non-repudiation for critical messages. |
. | No information available |
Watermarking Confidential Messages Messages can be automatically watermarked for traceability. |
. | No information available |
External Participant Verification Verifies the identity of external recipients in communications. |
. | No information available |
Communication Channel Redundancy System supports alternative communication methods in case of outages. |
. | No information available |
Comprehensive Audit Logs Records all relevant system and user activities for auditing purposes. |
. | No information available |
Customizable Reporting Dashboards Flexible dashboard tools for real-time monitoring and historical analysis. |
. | No information available |
Automated Compliance Reports Generates reports for regulatory and LP compliance needs. |
. | No information available |
Log Integrity Monitoring Detects if audit logs have been tampered with. |
. | No information available |
API Access to Logs Logs and reports accessible via standard APIs. |
. | No information available |
Alert Customization Users can define thresholds and triggers for alerting. |
. | No information available |
Log Retention Period Set length of time all logs are retained for compliance. |
. | No information available |
Anomaly Detection in User Activity Automatically highlights unusual user behavior for investigation. |
. | No information available |
Scheduled vs Real-time Reporting System can provide both scheduled and real-time reports. |
. | No information available |
Audit Log Search/Filtering Speed Rate at which logs can be queried for specific events. |
. | No information available |
Compliance Certifications Dashboard Displays current compliance certifications (e.g., SOC 2, ISO 27001). |
. | No information available |
GDPR Support Product supports General Data Protection Regulation for EU LPs and companies. |
. | No information available |
California Consumer Privacy Act (CCPA) Support Compliant with CCPA for handling California data subjects. |
. | No information available |
Automated Data Subject Requests Can handle right-to-access, right-to-be-forgotten, and correction requests. |
. | No information available |
Audit-trail for Compliance Actions Proof of compliance actions is logged and accessible. |
. | No information available |
Data Residency Controls Can restrict data storage and processing to certain jurisdictions. |
. | No information available |
Policy Change Alerting Alerts administrators when compliance policies change or are updated. |
. | No information available |
Compliance Report Generation Speed Time required to produce a full compliance report for auditors. |
. | No information available |
Customizable Data Retention Policies Allows organizations to define bespoke regulatory retention periods. |
. | No information available |
Vendor Risk Assessment Integration Integrates third-party assessments into compliance reporting. |
. | No information available |
Open API Availability Product offers open APIs for extensibility and automation. |
. | No information available |
Integration with Document Management Systems Works seamlessly with DMS like Box, Dropbox, SharePoint. |
. | No information available |
CRM Integration Works with Salesforce and other CRM systems for LP and portfolio tracking. |
. | No information available |
Automated Data Sync Frequency How frequently data is automatically synchronized across platforms. |
. | No information available |
Support for SAML/OAuth Connectors Allows secure identity federation across multiple SaaS tools. |
. | No information available |
Marketplace of Pre-Built Integrations Catalog of out-of-the-box plugins and connectors. |
. | No information available |
Custom Integration Toolkit Offers SDKs/libraries for custom workflow integration. |
. | No information available |
Real-time Integration Monitoring Notifies when integrations fail or are at risk. |
. | No information available |
Versioning and Backward Compatibility Ensures integration APIs remain available across product upgrades. |
. | No information available |
Granular Integration Permissions Permissions for integrations can be defined by user or group. |
. | No information available |
Automated Backups Scheduled, automatic backups of all critical data. |
. | No information available |
Backup Frequency How often backups are taken. |
. | No information available |
Recovery Point Objective (RPO) Maximum acceptable age of files in backup, indicating potential data loss time window. |
. | No information available |
Recovery Time Objective (RTO) Maximum acceptable time to restore systems after a failure. |
. | No information available |
Encrypted Backups All backup data is encrypted during storage and transit. |
. | No information available |
Geo-Redundant Backup Storage Backups are replicated in multiple data centers or regions. |
. | No information available |
Disaster Recovery Playbooks Pre-defined procedures for different disaster scenarios. |
. | No information available |
Backup Restore Testing Frequency How often backup restores are tested for integrity. |
. | No information available |
Granular Restore Capability Can restore individual files, folders, or full systems. |
. | No information available |
Automated Failover Support Enables seamless transition to backup systems automatically. |
. | No information available |
Context-aware Access Controls Adapts access policies based on user location, device, or time. |
. | No information available |
User Activity Feedback System provides immediate visual/audible feedback for security events (e.g., successful login, warning for suspicious activity). |
. | No information available |
Security Warnings/Explainability Clear and actionable security warnings for users. |
. | No information available |
Adaptive User Training Prompts In-app security learning for users when risky behaviors are detected. |
. | No information available |
Minimal Security Task Completion Time Low latency for users performing security actions (e.g., reviewing access requests). |
. | No information available |
Accessibility Support in Secure Workflows Features and workflows accessible to all users, including those with impairments. |
. | No information available |
Integrated Secure Approval Processes Enables approvals for sensitive actions within secured workflows. |
. | No information available |
Session Timeout Configuration Customizable length before automatic user logout due to inactivity. |
. | No information available |
Mobile Security Features Appropriate controls and protections for mobile users. |
. | No information available |
Frictionless Delegated Access Temporarily delegate access securely and efficiently. |
. | No information available |
Third-party Risk Assessment Automation Automates evaluation and scoring of third-party risk. |
. | No information available |
Vendor Access Control Restricts and monitors vendor/outsourced IT access to systems and data. |
. | No information available |
Continuous Vendor Security Monitoring Monitors ongoing risk from vendors (e.g., dark web exposure, breaches). |
. | No information available |
Vendor Security Questionnaire Management Centralizes collection and review of security documentation from vendors. |
. | No information available |
Vendor Breach Notification Speed Time between vendor-reported security incidents and notifications to your firm. |
. | No information available |
Vendor Data Segmentation Ensures vendor access is limited to specific, well-defined areas and data sets. |
. | No information available |
Automated Vendor Offboarding Instant removal of vendor access once a contract ends. |
. | No information available |
Vendor Cost Monitoring Tracks and manages the cost of vendor cybersecurity services. |
. | No information available |
Vendor Contract Compliance Flags Alerts for upcoming expirations, lacking attestations, or non-compliance. |
. | No information available |
Portfolio Company Security Guidance Tools Provides tools or frameworks for portfolio companies to follow security best practices. |
. | No information available |
This data was generated by an AI system. Please check
with the supplier. More here
While you are talking to them, please let them know that they need to update their entry.