What challenges did the client face, and why were they critical?
The bank needed greater visibility into who developed and maintained its technology, which third parties were involved, where data was processed and who was accountable in the event of an incident.
Each additional supplier or subcontractor increased the scope of Vendor Risk Management, due diligence, compliance reviews and audits. It also increased third-party concentration risk at a time when operational resilience and impact tolerances and were becoming more important.
At the same time, the bank needed to strengthen Authorised Push Payment (APP) fraud prevention, including remote access scam detection, without adding unnecessary friction or replacing its existing fraud stack. This was particularly relevant in the context of reimbursement exposure and consumer outcomes.
Key challenges
- reducing ICT third-party concentration risk,
- strengthening operational resilience,
- supporting APP fraud prevention and remote access scam detection,
- limiting reimbursement exposure while protecting consumer outcomes,
- avoiding additional complexity around the existing fraud stack.
What did we implement, and how did it work in practice?
The bank chose PREBYTES as a specialist European provider developing its own cybersecurity technologies and operating its own research infrastructure.
PREBYTES was directly responsible for the development, maintenance and delivery of its solutions. This replaced a multi-layered supplier model with a direct relationship with one accountable provider and simplified supplier assessment, compliance and audit processes.
The model complemented the bank’s existing fraud stack rather than replacing it. The bank gained access to specialist capabilities without creating new teams or infrastructure, while retaining control over fraud policies, risk decisions and operational processes.
PREBYTES’ ISO/IEC 27001:2022, ISO 9001:2015 and Cyber Essentials certifications provided additional support during supplier assessments and periodic security reviews.
What were the results, and what changed in day-to-day operations?
The bank reduced the number of third-party relationships requiring ongoing assessment and gained a clearer accountability model across technology, infrastructure and incident support.
This lowered the administrative burden on security, compliance, procurement and legal teams while giving internal fraud and risk teams access to specialist expertise without increasing headcount.
The direct delivery model also supported a shorter time to value and allowed the bank to strengthen APP fraud prevention without compromising a frictionless customer journey.
Results after implementation:
- The Vendor Risk Management team received one consistent set of information covering technology, infrastructure and accountability.
- The bank replaced a model involving at least four categories of external dependency with one provider responsible for its own technology and infrastructure.
- Compliance and risk teams gained a clearer model for managing operational resilience, impact tolerances and ICT third-party risk.
- The bank improved supplier diversification while reducing third-party concentration risk.
- PREBYTES complemented the existing fraud stack with specialist capabilities relevant to APP fraud prevention, authorised payment scams and remote access scam detection.
- Existing teams gained specialist expertise without additional headcount or organisational structures.
Learn more about PREBYTES’ security, compliance and operational standards in our Trust Center:
PREBYTES Trust Center | Security, Compliance & Certifications