Week 1
Author a Baseline NIST SP 800-30 Risk Assessment for a Fintech Cross-Border Expansion
Client Background
Brightline Pay is a 90-person, venture-backed fintech offering real-time USD remittance through a partner bank. The company was founded in Austin in 2022. The team is preparing to launch Canadian remittance corridors through a Canadian bank partner and will become subject to PIPEDA, FINTRAC MSB registration, and Quebec Law 25. Until now, security has been handled ad hoc by the engineering team.
Business Environment
Single-account AWS in us-east-1, ~30 microservices on ECS/Fargate, RDS Postgres, Stripe + Plaid integrations, GitHub Cloud for source management, Slack for collaboration. No formal GRC function; the head of engineering acts as security lead by default.
Security Incident
The Canadian partner bank's compliance questionnaire revealed Brightline has not performed a formal risk assessment. Brightline's SOC 2 Type I attestation is due in 90 days. No risk register exists. The platform has had two unrecorded incidents this year that the team is recalling after a kickoff workshop.
Scope
Platform AWS account (us-east-1), partner integrations (Stripe, Plaid, Canadian bank), the SaaS application layer (frontend + ~30 microservices), and HR/admin tooling. On-prem assets and the marketing site are out of scope.
Objectives
- Conduct a baseline risk assessment using NIST SP 800-30r1
- Develop a risk register with at least 12 risks, each scored using a 5-level likelihood/impact rubric
- Define a treatment decision (Accept/Mitigate/Transfer/Avoid) and a mitigation owner for every risk
- Map cross-border fintech regulatory references to OSFI Guideline B-13 and the CPPA (successors to legacy PIPEDA framing) and align the risk assessment to NIST CSF 2.0.
Required Deliverables