العربية
Under attack? Get help nowActive incidents only
Talk to us

Ready for the audit. Ready for the attack.

For banks and digital banks, payment companies and wallets, and insurers. We prepare you for the CBI Cyber Resilience Controls and the audit cycles, and we build the apps and platforms your customers use.

Request a confidential consultationA named practice lead replies.

What is driving this

Banks and digital banks

  • CBI Cyber Resilience Controls
  • annual internal IS audit
  • PCI DSS / EMV / SWIFT CSP
  • audited BCP/DRP
  1. Reform standards
  2. Audit cycle 1
  3. Technical audit cycle
  4. Final validation

Reform standards, two audit cycles and a final validation follow, in that order. We prepare you for the technical audit cycle.

Which institutions the timeline applies to depends on your pathway and licence — ask us, or see Payment companies and wallets.

Dates to be confirmed against the CBI circular Last reviewed 28 September 2026

See what the audit will ask for

We are your readiness partner ahead of the CBI-approved auditor. The firm that prepares your evidence does not sign assurance on it — that separation is yours to keep and ours to respect.

We prepare you for:
  • CBI Cyber Resilience Controls
  • ISO/IEC 27001
  • PCI DSS
  • SWIFT CSP
  • NIST CSF
  • COBIT 2019

Payment companies and wallets

  • Your licence conditions

A fixed-scope readiness assessment.

  • Licence-checklist mapping
  • Penetration-test scope
  • Policy-set gap
  • Incident-response-plan gap
  • Remediation plan

Fixed scope; the quote follows the scoping call.

Book a CBI readiness assessment

Insurers

For insurers, the pressure comes from digital sales and claims, and from the expansion of health insurance.

What we build

  • E-banking, wallet and onboarding apps
  • integrations with payment rails and card schemes
  • branch customer-experience feedback
  • dashboards and internal data platforms

Software & AI

What we guard

  • CBI Controls readiness
  • banking-reform technical audit readiness
  • penetration testing
  • incident response and retainers
  • brand-impersonation monitoring

Red Crow

A rule or AI?

  • Where AI helps: spotting impersonation and fraud signals across channels, and reading thousands of complaints and survey answers.
  • Where a rule is better: AML thresholds, transaction limits and control mapping, because your auditor will ask how each decision was made.

How we decide

Platforms we built

Also from DigiFort

  • Bridgeway: IT governance and transformation roadmaps a board can read.
  • Training: staff awareness and committee training you can evidence.

FAQ

Where is our data handled?

Agreed with you in writing before the engagement starts: where each deliverable is stored, in which region, who can open it, and how it is handed back or deleted when we finish.

Who owns the code?

You keep the keys: code, repositories, hosting and accounts, in writing.

Will you also sign assurance on our audit?

We are your readiness partner ahead of the CBI-approved auditor. The firm that prepares your evidence does not sign assurance on it — that separation is yours to keep and ours to respect.