Organisations using any kind of application-to-application communication in the Swift payment process will typically fall under Type A4. Only organisations still fully manually inputting payments in a GUI can attest as Type B. The system enabling these (semi-) automated payments is called a “customer client connector,” and must be protected by several key security controls.
Last year, protecting these connectors was only recommended, but now it is mandatory. This means every customer connector, regardless of whether it’s a server-based or a client connector, must meet basic cyber security standards. Examples of these client connectors are IBM MQ clients, sFTP clients and API clients.
These changes matter because the connections between Swift infrastructure, customer connectors and back-office systems are often where payment data leaves the most tightly controlled environment. If these flows are not properly identified, encrypted and monitored, attackers may be able to intercept, manipulate or misuse sensitive transaction data before traditional security controls detect the issue.