Resources

USE CASE: Managing PhySec Devices in Financial Services

Written by securithings | Sep 2, 2026, 6:41:28 PM

Cameras that go dark, ATMs with unpatched firmware, and access panels running on expired credentials are the failures that leave a bank unable to demonstrate the safeguards the Bank Protection Act, GLBA, and PCI DSS require.

This use case unpacks where the risk actually lives day to day, and what continuous device control looks like across a multi-branch footprint.

 

Key takeaways:

  • How the five frameworks governing financial services physical security — Bank Protection Act, GLBA Safeguards Rule, PCI DSS Requirement 9, NDAA Section 889, and the FCC Covered List — all converge on the same demand: proving your devices are secure, not just claiming it
  • Why financial services carries the highest share of non-traditional IT devices connected directly to corporate networks (54%, per Forescout Device Cloud data), and what that concentration means for examiner findings
  • Where the operational reality diverges from the regulatory headline: stale inventories that look complete but aren't, detection without a way to act on it, and modernization that runs ahead of what's tracked
  • What continuous device control looks like in practice: fleet-wide visibility across cameras, ATMs, NVRs, and access panels, policy-driven remediation in batches of up to 10,000 devices, and on-demand compliance reporting for risk officers and examiners
This resource is for you if:

You're responsible for physical security, IT, or compliance at a bank, credit union, or other financial institution and need to close the gap between what regulators expect at the device level and what your current tools can actually prove.