News

From Risk to Resilience: A SaaS Provider's Blueprint for Financial Services Security - Friday, August 1, 2025 - 06:38

On April 25, 2025, Patrick Opet, CISO of JPMorgan Chase, issued an open letter to technology providers, urging the industry to address growing concerns about software supply chain security. His message emphasized the increasing operational and systemic risks associated with SaaS providers, particularly in highly regulated sectors like financial services.

To many across the SaaS and cyber security industries, this comes as no great surprise. For years, large businesses have been heavily investing in their own cyber security. However, in response, cyber criminals are moving down the supply chain to third party vendors as the new attack surface to bypass in-house security measures.

Instead of defensive posturing, we see this as an opportunity to demonstrate how purpose-built solutions can directly address these critical concerns. In particular, Opet’s call aligns with a wider industry shift—spurred by frameworks such as the EU’s DORA and the UK’s CTP regime—toward greater transparency, accountability, and operational resilience throughout the supply chain.

Supporting Resilience Through Deployment Choice

A key concern raised in the open letter is the industry’s growing reliance on single deployment models that can introduce concentration risk. Many SaaS providers operate solely in multi-tenant environments with shared IT infrastructure and common update cycles—an approach that can create efficiencies, but may not suit all customers’ control or compliance requirements.

One solution, and our own approach, is to offer deployment flexibility—whether that’s via public cloud, or on-premise. These technical capabilities support both single-tenant and hybrid models, giving clients greater control over how and where their data and workloads are managed.

For example, our asset management clients processing legacy data sets may choose an on-premise deployment for maximum control, while payment processors handling high transaction volumes might opt for our scalable cloud managed service solution.

This flexibility doesn’t need to come at the expense of innovation. Release cycles can be structured to give customers clarity and choice around when to adopt updates, with rigorous testing built into the process. In sectors where operational continuity is mission-critical, this control can be just as important as feature velocity.

Reducing Supply Chain Complexity

Opet’s letter also touches on the systemic risks posed by opaque third-party dependencies. In this regard, a conservative approach to supply chain design can help to minimize reliance on external services in the delivery of core applications.

When cloud infrastructure is relied on, robust business continuity and disaster recovery planning is required, including real-time replication across zones. We actively monitor our providers and maintain the transparency needed to support regulatory expectations around fourth-party oversight.

Resilience is about more than just technical architecture—it’s about building a culture of preparedness, and ensuring clients are confident in how their data is managed, stored, and protected.

Continuous Assurance, Not Annual Compliance

Another theme highlighted is the insufficiency of annual certifications as a stand-alone assurance model. Frameworks like ISO27001 and SOC 2 should be foundational—but not the end of the story.

Organizations must provide ongoing support for client audits and due diligence, and encourage proactive engagement between teams and clients’ governance, risk, and compliance (GRC) functions. Security and resilience aren’t one-off milestones—they are continuous, evolving responsibilities.

Enabling Secure, Governed Use of AI

The growing use of AI across the software landscape brings new opportunities—and new responsibilities. Vendors are integrating AI features in areas such as anomaly detection and process automation, always with clear governance and internal risk oversight.

For regulated firms, assurance around how AI is deployed, tested, and controlled is critical. Having said that, ensuring that any AI capabilities within platforms are developed with transparency, control, and compliance at the forefront, is essential.

Building Tomorrow's Security Standards Today

The message from JPMorgan Chase serves as an important reminder: as technology providers, we are an extension of our customers’ risk environments. Our role is not just to deliver functionality—it’s to help our clients operate safely, confidently, and compliantly in an increasingly complex world.

SaaS providers must commit to providing the flexibility, transparency, and resilience that financial services firms need to navigate today’s evolving regulatory expectations.

In return, the firms that will thrive are those that view security not as a compliance checkbox, but as a competitive advantage built through genuine partnership with their technology providers.

We've listed the best software asset management (SAM) tools.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

Best Smart Glasses in 2025 - Friday, August 1, 2025 - 08:00
Devices like the Meta Ray Bans can be surprisingly good, but they're evolving fast, so you'll probably want to wait right now.
Best Internet Speed Tests for August 2025 - Friday, August 1, 2025 - 08:00
Taking an internet speed test is quick and easy. Here's how to know if you're getting the speeds you're paying for.
HP OmniBook X Flip 16 Review: A Poorly Stitched Frankenstein of a 2-in-1 - Friday, August 1, 2025 - 08:00
While it has a handful of appealing features, this midrange 16-inch convertible ends up being a clumsy assemblage of disparate parts.
Hidden iOS 26 Features Apple Didn't Mention at WWDC - Friday, August 1, 2025 - 08:00
Here are 26 gems in iOS 26 that most people might miss.
I Use a Simple Pomodoro Timer App to Boost My Productivity. Here's How - Friday, August 1, 2025 - 09:00
You can use the Pomodoro Technique to enhance your productivity by getting into deep focus, concentrating on one task at a time and building in brain breaks.
Best MacBooks We've Tested (August 2025) - Friday, August 1, 2025 - 10:00
MacBook Air or MacBook Pro? Which size MacBook should I get? Is the older M1 Air still worth it? You've got MacBook questions, and CNET's laptop experts have the answers.
Best Noise-Canceling Headphones We've Tested (August 2025) - Friday, August 1, 2025 - 10:34
I've tested dozens of noise-canceling headphones. These are my current top picks at a variety of prices -- from high-end to budget models.
Nintendo Raises Original Switch Prices, Blaming 'Market Conditions' - Friday, August 1, 2025 - 12:48
If you're looking to buy an original Switch or Switch 2, you'll need to pick one up right away.
Helix Midnight Mattress Review 2025: Sleep Experts Cover What’s New With the Core, Luxe & Elite Beds - Friday, August 1, 2025 - 13:00
Helix Sleep just upgraded its three mattress lines. All 21 of its beds now have different looks and, in some cases, slightly different feels. Here’s what our team likes about this Helix update.
Reddit Shifting Towards Search as Company Wants to Become a Search Engine - Friday, August 1, 2025 - 13:31
Reddit CEO Steve Huffman wants to expand Reddit Answers to capitalize on increasing demand for Reddit results.
Best Over-Ear Headphones We've Tested (August 2025) - Friday, August 1, 2025 - 13:36
Prefer full-size headphones to earbuds? These are the best over-ear cans, according to CNET's headphones expert.
Watch NASA's SpaceX Crew-11 Launch to the International Space Station video - Friday, August 1, 2025 - 14:01
See every launch stage of NASA's SpaceX Crew-11 mission to the International Space Station, marking NASA's 11th Commercial Crew Program flight aboard a Falcon 9 rocket and Crew Dragon Endeavour spacecraft.
Yes, You Can Bundle Other Cybersecurity Services With Some VPNs. But Is It a Good Idea? - Friday, August 1, 2025 - 15:00
You need more than just a VPN to boost your digital privacy and security. Bundling additional tools with your VPN can be convenient, but be aware of the pitfalls.
To Bundle or Not to Bundle: Your Guide to VPNs and Other Cybersecurity Service Packages - Friday, August 1, 2025 - 15:00
A handful of VPN providers offer bundled packages that feature additional privacy and security tools. Here's what to know about what's available.
If Your Roku Keeps Crashing, You Probably Haven't Tried This - Friday, August 1, 2025 - 15:20
This simple button combo can reboot your Roku faster than rewiring your internet.
'Final Destination Bloodlines' Is Now Streaming. Here's How to Watch - Friday, August 1, 2025 - 15:42
Get the weekend off to a gory start.
Today's NYT Strands Hints, Answers and Help for Aug. 2 #517 - Friday, August 1, 2025 - 16:00
Here are hints and answers for the NYT Strands puzzle for Aug. 2 No. 517.
Today's Wordle Hints, Answer and Help for Aug. 2, #1505 - Friday, August 1, 2025 - 16:00
Here are hints and the answer for today's Wordle for Aug. 2, No. 1,505.
Today's NYT Connections: Sports Edition Hints and Answers for Aug. 2, #313 - Friday, August 1, 2025 - 16:00
Here are hints and the answers for the NYT Connections: Sports Edition puzzle No. 313 for Saturday, Aug. 2.

Pages