Navigation

Get in touch
Logo
News

Industries / Financial

Protect trust. Connect finance.

Secure payment processing and connect core banking systems to digital services.

Consulting. Integration. Operations.

person in black suit jacket holding white tablet computer — illustrative image

Built around your industry.

  • Banks and savings banks
  • Payment service providers and acquirers
  • Insurers and asset managers
  • Fintechs and card issuers

Your priorities

Understand the challenge. Shape the solution.

We integrate payment HSMs and key management under PCI DSS, connect core banking systems through controlled interfaces to digital channels and the third-party access required by PSD2, and build data platforms for real-time fraud detection.

01

Payment HSMs and key management

Target architecture with device selection and migration plan

More on this
02

Fraud detection with data and AI

Real-time data platform connected to payment and customer systems

More on this
03

Identity and customer authentication

Identity architecture with authentication flows

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01Payment HSMs and key managementThales payShield 10K · Utimaco Atalla AT1000 · Futurex Excrypt

Our approach

Payment HSMs are certified devices that hold cryptographic keys tamper-resistant and execute PIN verification, card data encryption and tokenization. We advise vendor-neutrally on payment HSMs from Thales, Utimaco, Entrust, IBM and Futurex and plan key ceremonies with roles, quorums and records. We integrate the devices into card processing, acquiring and tokenization. The requirements of PCI DSS and the PCI PIN Security Standard shape architecture, operating procedures and audit files from the first day.

Full scope
  • Target architecture with device selection, redundancy across sites and a migration path from legacy HSMs such as payShield 9000
  • Key ceremonies with roles, quorums, record templates and evidence for PCI PIN assessments
  • Key management with TR-31 key blocks, TR-34 remote key exchange and documented rotation and destruction
  • Integration into card processing, acquiring, issuance and tokenization over the vendor host interfaces
  • Operations manual and monitoring for key rotation, firmware levels, load and disaster recovery

A payment processor replaces end-of-support payment HSMs with a redundant pair across two sites; the key migration runs under a documented ceremony with a planned cutover window for the terminal hosts.

What you get

  • Target architecture with device selection and migration plan
  • Key ceremony records and PCI PIN evidence
  • Operations manual with monitoring and recovery procedures
Discuss this topic
02Core banking integration and PSD2 interfacesAPI gateway · Berlin Group NextGenPSD2 · ISO 20022

Our approach

Core banking systems manage accounts, bookings and products and must not stand still during any change. We place an integration layer with controlled interfaces between the core and the channels. These are online banking, mobile apps, payment platforms and the third-party access that PSD2 requires. New products are built outside the core, while the core stays stable and auditable. Every interface is versioned, tested automatically and equipped with permissions and logging.

Full scope
  • Integration architecture with interface catalog, data contracts, owners and separation of core and channels
  • PSD2 interfaces according to the Berlin Group NextGenPSD2 framework with consent management and fallback
  • Payment integration with ISO 20022 messages for SEPA and instant payments
  • Automated tests, versioning and a release process for every interface, including regression tests against the core
  • Operating model with monitoring, capacity planning and documented change procedures

A regional bank launches a mobile product outside its core banking system; the app reaches accounts and bookings only through a versioned integration layer with full request logging.

What you get

  • Integration architecture with interface catalog and data contracts
  • Tested and versioned interfaces with release process
  • Operating model with monitoring and change procedures
Discuss this topic
03Fraud detection with data and AIApache Kafka · Apache Flink · Feature store

Our approach

Fraud patterns change faster than static rule sets. We build data platforms that merge transaction, customer and device data in real time. On this data we train models that score each transaction before the payment is executed. Rules and models work together so that known patterns are caught reliably and new ones surface early. Every decision is explainable and logged so that customer service, compliance and the supervisor can follow it.

Full scope
  • Streaming platform for transaction events from card, SEPA and instant payment systems
  • Feature store with device, merchant category and behavioral features, versioned and documented
  • Scoring model combined with a rule engine, validated against historical fraud cases and chargebacks
  • Explainability per decision for customer service, compliance and the supervisor
  • Model operations with monitoring of drift, false positives and response times, documented under the EU AI Act

A card issuer scores a payment from a new country in milliseconds by device, merchant category and prior behavior instead of blocking it outright; every decision carries a reason for customer service.

What you get

  • Real-time data platform connected to payment and customer systems
  • Scoring model with rule set, versioned and validated
  • Decision log with explanations for compliance and audit
Discuss this topic
04DORA resilience and third-party managementMicrosoft Sentinel · Splunk · TIBER-EU

Our approach

DORA obliges financial entities to run ICT risk management with incident reporting, resilience testing and contractual control of every ICT provider. We record your ICT risks and document systems and providers in the register of information. Reporting processes, threat-led penetration tests, security monitoring and recovery are set up to match the regulation. For our own services we deliver contracts with audit rights, service levels and exit plans, as DORA requires for third parties.

Full scope
  • ICT risk framework mapped to the DORA chapters and to your ISMS under ISO 27001 or BSI IT-Grundschutz
  • Register of information for all ICT third-party providers with criticality, subcontractors and exit plans
  • Incident classification and reporting workflow with the deadlines of the DORA technical standards
  • Resilience testing program from vulnerability scans to threat-led penetration tests under TIBER-EU
  • Security monitoring with SIEM, backup and recovery tests with documented recovery objectives

An insurer consolidates its provider contracts into a register of information and adds audit rights and exit plans before the supervisor's first DORA review.

What you get

  • ICT risk framework and register of information
  • Incident reporting workflow with templates
  • Resilience test reports and recovery evidence
Discuss this topic
05Identity and customer authenticationFIDO2 and passkeys · OpenID Connect · Keycloak

Our approach

PSD2 requires strong customer authentication for account access and payments, and the card schemes require EMV 3-D Secure for online purchases. We integrate identity providers, passkeys and 3-D Secure into online banking, apps and checkout. Customers authenticate with two independent factors without abandoning the process. Employee access to core systems and HSM consoles gets the same treatment with multi-factor authentication, role models and session logging.

Full scope
  • Identity architecture with identity provider, OpenID Connect flows and consent handling for PSD2 third parties
  • Strong customer authentication with passkeys, app-based approval and dynamic linking of amount and payee
  • EMV 3-D Secure integration for issuing and acquiring with risk-based exemptions
  • Privileged access for administrators of core systems and HSMs with hardware tokens and session recording
  • Migration of legacy TAN procedures and password logins with staged rollout and monitoring

A direct bank replaces its SMS TAN with app-based approval and passkeys; the login for PSD2 third parties runs through the same identity provider with consent records.

What you get

  • Identity architecture with authentication flows
  • Integrated strong customer authentication with evidence for PSD2
  • Privileged access concept with session logs
Discuss this topic
06Post-quantum readiness for payment and PKIML-KEM (FIPS 203) · ML-DSA (FIPS 204) · Hybrid TLS

Our approach

Quantum computers will break RSA and elliptic-curve cryptography, which today protects card keys, TLS connections and every certificate in a bank's PKI. We inventory the cryptography in payment systems, PKI and interfaces and rate each use by lifetime and exposure. The migration to ML-KEM and ML-DSA then follows the order the risk demands. HSMs are selected or upgraded so that the new algorithms run in certified hardware. Hybrid modes keep today's card and terminal fleets compatible during the transition.

Full scope
  • Crypto inventory of payment HSMs, PKI, TLS endpoints, signing services and key formats
  • Risk rating per use by data lifetime, key exposure and regulatory deadline
  • Migration plan with hybrid certificates and hybrid TLS for the transition period
  • HSM selection or firmware upgrade for ML-KEM, ML-DSA and stateful hash-based signatures
  • Pilot in the PKI or on one interface with test plan, rollback and evidence for the supervisor

A payment provider inventories the cryptography of its terminals, HSMs and PKI and starts the migration with a hybrid root CA in certified hardware, while the terminal fleet keeps its current keys until replacement.

What you get

  • Crypto inventory with risk rating
  • Migration roadmap with hybrid transition
  • Pilot report with test results and evidence
Discuss this topic
A finance tracker planner with budget sheets, a gold pen, and paper clips — illustrative image
Financial

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Financial

HSM migration at a payment processor

Payment HSMs reach end of support, key ceremony records are incomplete and the PCI assessor has flagged the gap.

Solution

Target architecture with redundant payment HSMs, documented key ceremonies, TR-31 key blocks and a staged migration per host application.

Certified devices in operation, complete key records for the PCI PIN assessment, cutover in planned windows outside peak hours.

Discuss this topic

02 / Financial

Instant payments at a regional bank

Instant payments go live, the static rule set blocks legitimate transfers and lets new fraud patterns through.

Solution

Streaming platform with transaction events, scoring model combined with rules, explanation per decision for customer service.

Scoring before execution, fewer false alarms in manual review, decision logs for compliance and the supervisor.

Discuss this topic

03 / Financial

DORA readiness at an insurer

The supervisor announces a DORA review, provider contracts predate the regulation and no register of information exists.

Solution

ICT risk framework mapped to the ISMS, register of information with criticality and exit plans, incident reporting workflow, resilience test program.

Complete register, contracts with audit rights, first threat-led penetration test documented before the review.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Prioritized list of gaps and measures

    Inventory of payment processes, core systems, interfaces and regulatory gaps, prioritized measures
  2. 02

    Concept

    Target architecture, security measures, operating model

    Target architecture, HSM and interface design, operating model, alignment with supervisory expectations
  3. 03

    Implementation

    HSMs, interfaces and data platform in stages

    Integrated HSMs, tested interfaces, fraud platform, documentation and acceptance per stage
  4. 04

    Operations

    Monitoring, audits, knowledge transfer

    Monitoring, key rotation, audit support, stepwise handover to your teams

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What are IT solutions for banks and financial services?

Six modules from payment HSMs to post-quantum readiness, delivered and operated by OTOKO®. The entire solution runs in German data centers, documented for DORA, PCI DSS and PSD2 audits.

IT solutions for banks and financial services secure payments cryptographically, keep core banking systems running through every change and prove each change to the supervisor. OTOKO® covers six modules: payment HSMs and key management, core banking integration and PSD2 interfaces, fraud detection with data and AI, DORA resilience and third-party management, identity and customer authentication, and post-quantum readiness for payment and PKI.

The difference lies in the evidence. Every HSM, interface and model comes with the documentation that DORA, PCI DSS and PSD2 auditors ask for, from key ceremony records to change logs. Cryptography and hardware security modules are our core competence. Payment keys, PINs and certificates are protected accordingly.

Why OTOKO® for banks and financial services

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. Payment keys, PINs and certificates are handled with the care that PCI PIN and the card schemes demand.

  • German data centers

    The entire solution runs in German data centers, from the payment HSM to the fraud platform, with the location evidence your DORA register needs.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what information security officers, compliance and auditors expect from a provider.

  • One team through to operations

    One team accompanies you from consulting to operations. Cryptography specialists, integration developers and data engineers stay on without handover to third parties.

Delivery and details

Most institutions do not fail on technology but on the evidence and the dependencies around it.

Keys without records

Payment keys were loaded years ago, ceremony records are incomplete and nobody knows which key block format the terminals use.

Core system as bottleneck

Every new channel connects directly to the core banking system, so each release puts the nightly batch and the booking run at risk.

Rules that lag behind fraud

Static rule sets catch known patterns, while new fraud schemes only show up weeks later in chargebacks and customer complaints.

Third parties without contracts

DORA requires audit rights, exit plans and a register of information, but the provider contracts predate the regulation.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour data center, your HSMsData centers in Germany, operated under ISO 27001Azure, AWS or Google Cloud, region selectable
OperationYour team or OTOKO® as managed serviceOTOKO®, with audit rights for your institutionShared, platform services by the provider
ToolsPayment HSMs and key managers on siteHosted HSMs and key management in GermanyCloud HSM services, payShield Cloud HSM
Suited forCard processing, PIN handling, PCI PIN scopeRegulated institutions with a need for sovereigntyDigital channels, analytics, fast pilots
ComplianceFull control, evidence from your ISMSProcessing agreement under GDPR, DORA register entry, location GermanyProcessing agreement, standard contractual clauses per service, DORA subcontractor chain

Collaboration

Project

Clearly scoped module with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for HSM migrations, PSD2 interfaces and DORA gap closure

Team reinforcement

Cryptography specialists, integration developers or data engineers work in your teams, with your tools and in your sprints.

  • Onboarding into your processes and change management
  • Scalable as the project progresses
  • Suited for in-house IT with capacity gaps

Managed service

OTOKO® operates HSMs, interfaces or data platforms with agreed service levels, reports and the contract terms DORA requires.

  • Monitoring, key rotation, support and security updates
  • Audit rights, service levels and exit plans in the contract
  • Suited for institutions without their own operations team

What each regulation requires and what OTOKO® delivers for it.

Standards and evidence
RequirementDemandsOTOKO® delivers
DORAICT risk management, incident reporting, resilience testing, register of information and contractual control of ICT third-party providersRisk framework, register of information, reporting workflow, test program and contracts with audit rights and exit plans for our own services
PCI DSSProtection of cardholder data with network segmentation, encryption, access control, logging and annual assessmentScope definition, HSM-based encryption and tokenization, key management procedures, evidence for the assessor
PCI PIN SecurityPIN processing in PCI-approved HSMs, dual control and split knowledge for keys, documented key ceremonies and key blocksApproved payment HSMs, key ceremony records, TR-31 key block migration, operating procedures for the PIN assessment
PSD2Strong customer authentication with dynamic linking and access interfaces for licensed third-party providersAuthentication integration with passkeys and 3-D Secure, PSD2 interfaces with consent management and fallback evidence
GDPRLegal basis, data minimization, data subject rights, processing agreements and data protection impact assessmentData protection concept for fraud models, pseudonymization, deletion concept, processing agreement with location Germany

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which IT solutions for banks and financial services does OTOKO® offer?

The portfolio covers payment HSMs and key management under PCI DSS and PCI PIN. It includes core banking integration with PSD2 interfaces and fraud detection with data platforms and models. It also covers DORA resilience, customer authentication and post-quantum readiness. Each module can be commissioned on its own or as a package. Operation runs in your data center, in German data centers or on a hyperscaler.

How does OTOKO® support DORA compliance?

We record your ICT risks, document systems and providers in the register of information and set up incident reporting and resilience testing. For our own services we deliver contracts with audit rights, service levels and exit plans, as DORA requires for ICT third-party providers. Your institution stays able to answer the supervisor at any time.

Can existing payment HSMs stay in operation?

Usually yes. We check firmware levels, certifications and vendor support. A replacement is planned only where devices reach end of support or miss requirements such as PCI PTS HSM v3 or post-quantum cryptography. Migrations run with documented key ceremonies and planned cutover windows, as we are used to with operators of critical infrastructure and regulated industries.

How does fraud detection stay explainable for the supervisor?

Every score is stored with the features that drove it, the rule that fired and the model version that produced it. Customer service sees the reason in plain terms and compliance gets the full log. The model card documents training data, quality and limits under the EU AI Act.

Does the solution run in German data centers?

Yes. Payment HSMs, key management, interfaces and the fraud platform can run in your data center or in German data centers operated under ISO 27001. Hyperscaler regions in Germany are an option for channels and analytics where the data classification allows it.

When should a bank start with post-quantum cryptography?

Now, with the inventory. Card keys, root certificates and archived data have lifetimes that exceed the expected arrival of capable quantum computers, and HSM refresh cycles take years. The inventory decides which systems migrate first and which can wait for the next hardware cycle.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

Cryptography architect: HSM architecture, key management, PCI evidence. Integration architect: Interface catalog, data contracts, core banking integration. Data engineer: Streaming platform, feature store, model operations. Security architect: DORA framework, identity, monitoring. Compliance lead: Register of information, audit files, supervisor communication. Project lead: Milestones, acceptance, reporting.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Prioritized list of gaps and measures Inventory of payment processes, core systems, interfaces and regulatory gaps, prioritized measures

Operations & development4 questions

How can we work together?

Project: Clearly scoped module with a defined result, milestones and acceptance. Team reinforcement: Cryptography specialists, integration developers or data engineers work in your teams, with your tools and in your sprints. Managed service: OTOKO® operates HSMs, interfaces or data platforms with agreed service levels, reports and the contract terms DORA requires.

What happens at handover to operations?

Monitoring, audits, knowledge transfer Monitoring, key rotation, audit support, stepwise handover to your teams

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Financial

Let's discuss your next step.

Let us explore together how payment security, core system integration and fraud detection can work together in your institution.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.