Banking

When the examiner asks what happened, the record answers.

Schedule a meeting

Banks under the 36-hour rule, NYDFS Part 500 and DORA

Security built for how banks are examined

Answer the examiner from your own systems, with a record they can check.

Evidence

RuleWhat the examiner asksARRTECH record
DORA RTS 2024/1774, Art. 12Log listed events; detect logging failures.Collection by agent, syslog, SQL and file; a silent-source alert. →
DORA RTS 2024/1774, Art. 12Logs protected against tampering and deletion.Hash, signature, chain and a standalone verifier. →
DORA Art. 10Promptly detect anomalous activity.Log source alerts, and near-hourly behavioral baselines. →
Model risk guidance, Apr 2026How a model was validated.Detectors proven on your telemetry; promotion recorded. →
23 NYCRR 500.17Notice within 72 hours; 24 after a ransom.A case timeline and report. Filing stays with you. →
23 NYCRR 500.17Certification signed by two executives.SOAR Operator history of who approved what. →

NYDFS 500.6

Show your examiner an unbroken audit trail

Part 500.6 asks for audit trails that can reconstruct material financial transactions, kept for at least five years. ARRTECH SIEM signs every log as it is written, so your examiner can check that nothing was changed.

Incident Notification Rule

Meet the 36-hour notice with facts, not guesses

Under the Computer-Security Incident Notification Rule, a bank must tell its primary federal regulator within 36 hours of deciding a notification incident has occurred. In ARRTECH SIEM, every alert opens a case with its timeline and owner, so you notify from evidence.

DORA Article 10

Monitor core banking and payment systems

DORA Article 10 asks EU financial firms to detect anomalous activity promptly. ARRTECH SIEM reads core banking and payment systems from their databases or audit files, beside identity and network logs, so one timeline shows what happened.

NYDFS 500.17

Prove who approved every action

Part 500.17 requires a yearly certification signed by your highest-ranking executive and your CISO. ARRTECH SOAR waits for a named person to approve each response and records who chose what, so your response decisions have a record behind them.

By rule

DORA RTS 2024/1774, Art. 12

Log listed events; detect logging failures. ARRTECH: Collection by agent, syslog, SQL and file; a silent-source alert.

DORA RTS 2024/1774, Art. 12

Logs protected against tampering and deletion. ARRTECH: Hash, signature, chain and a standalone verifier.

Model risk guidance, Apr 2026

How a model was validated. ARRTECH: Detectors proven on your telemetry; promotion recorded.

Questions

Does it read our core systems?

Yes. ARRTECH SIEM reads core and payment systems straight from their databases or audit files. If a system is not supported yet, we write the connector at no charge under support.

What about our branches?

Each branch server and workstation runs a small agent. If the link drops, the agent holds the logs and sends them, encrypted, when the link returns.

Are sign-ins and network traffic in one place?

Yes. Directory, VPN and Microsoft 365 sign-ins sit in the same store as firewall, proxy, DNS and network traffic, and all of it is checked against threat intelligence.

Who approves an action?

A person. ARRTECH SOAR emails the approver up to five options and waits. Nothing runs until they reply.

What stays with you?

Filing notices, signing the certification and validating your own models. ARRTECH has no stated SWIFT connector. Cyberdroid AI Detection reports about once an hour and never changes anything.

Sources

Guide

What cybersecurity rules apply to banks?

US banks answer to the 36-hour Computer-Security Incident Notification Rule, NYDFS Part 500 in New York, and DORA in the EU. Each asks for monitoring, intact audit trails and fast notice.

What is the best SIEM for banks?

Look for a bank SIEM that reads core banking and payment systems, keeps signed audit trails an examiner can verify, and runs on your own servers.

How do banks meet NYDFS 500.6 audit trail rules?

Part 500.6 asks for audit trails that reconstruct material financial transactions, kept five years. ARRTECH SIEM signs every log so the record can be checked.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.