sector-financial

Map mid-2026 financial cyber threats to regulatory controls across 35+ jurisdictions.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill sector-financial
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sector-financial
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/sector-financial
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill sector-financial

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Financial services cybersecurity frameworks are outdated for mid-2026 threat realities, including agentic AI fraud, supply chain attacks, and prompt injection, leaving compliance teams unable to map current threats to regulatory requirements across 35+ global jurisdictions.

Core Features & Use Cases

  • Cross-Jurisdictional Regulatory Mapping: Aligns mid-2026 financial cyber threats to 20+ global regimes including EU DORA, PSD2, SWIFT CSCF v2026, NYDFS 23 NYCRR 500, and APRA CPS 234.
  • Control Gap Identification: Flags specific insufficiencies in existing frameworks, such as PSD2 RTS-SCA being silent on agent-initiated payment fraud via prompt injection.
  • Use Case: A financial compliance officer can use this skill to audit their DORA TLPT scope for AI-related threats, or map a recent deepfake-mediated KYC bypass incident to relevant control gaps across EU, US, and APAC regulations.

Quick Start

Use the sector-financial skill to audit your EU DORA TLPT scope for agentic AI payment threats and map identified gaps to PSD2 RTS-SCA and SWIFT CSCF v2026 controls.

Frequently Asked Questions about sector-financial

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map ATT&CK and ATLAS TTPs to financial regulatory controls like DORA and PSD2?

Financial regulatory mapping flags specific insufficiencies in existing frameworks, such as PSD2 RTS-SCA being silent on agent-initiated payment fraud via prompt injection. It applies to compliance audits and threat-led penetration testing scoping for banks, payment processors, and financial market infrastructure operators.

How do I audit a DORA TLPT scope for AI-augmented threats?

You audit DORA TLPT scope for AI-related threats by aligning mid-2026 financial sector cyber threats with global regulatory compliance requirements. This identifies framework gaps for AI-augmented threats, ensuring your threat-led penetration testing covers emerging vectors like agentic AI fraud and prompt injection.

Can I use this to map a deepfake-mediated KYC bypass incident to control gaps across multiple regions?

You can map a deepfake-mediated KYC bypass incident to relevant control gaps across EU, US, and APAC regulations. This identifies framework insufficiencies by aligning mid-2026 threat realities with 20+ global regimes including DORA, NYDFS 23 NYCRR 500, and APRA CPS 234.

Does cross-jurisdictional regulatory mapping cover SWIFT CSCF and NYDFS 23 NYCRR 500?

Cross-jurisdictional regulatory mapping covers SWIFT CSCF v2026 and NYDFS 23 NYCRR 500 alongside EU DORA, PSD2, and APRA CPS 234. It aligns mid-2026 financial cyber threats across 20+ global regimes for compliance audits and regulatory gap analysis.

What are the limitations of using PSD2 RTS-SCA for mitigating agentic AI payment fraud?

A key limitation of PSD2 RTS-SCA is that it is silent on agent-initiated payment fraud via prompt injection. Financial services cybersecurity frameworks are outdated for mid-2026 threat realities, necessitating control gap identification to address agentic AI fraud and supply chain attacks.