The five controls that actually matter
A short, unglamorous list. Most breaches in finance come from missing one of these, not from anything exotic.
One: hardware keys, everywhere
SMS codes and authenticator apps are phishable. Hardware keys are not, in practice. Every person with access to client data or payment rails uses one. No exceptions for seniority.
Two: separation of instruction and execution
The person who receives an instruction never executes it alone. Two roles, two credentials, two devices. It slows nothing down when it is designed in from day one.
Three: policy-controlled wallets
Crypto settlement is only as safe as key custody. Our wallets are policy-controlled with whitelisted destinations and value thresholds. A new destination address is a governance event, not a click.
Four: logging you can read
Logs nobody reads are decoration. Ours are summarised daily into a form a non-engineer can review: who accessed what, which limits were touched, what changed.
Five: rehearsed recovery
We test recovery on a schedule, with the desk involved. The measure is not whether backups exist. It is how long until a client can move money again.
