Blockchain security standard for an institutional custodian
- Sector
- Custody and institutional banking
- Scale
- Global custody and asset servicing
Situation
The institution wanted a defensible position on blockchain and digital assets. The business interest was real, but nobody had defined internally what adequate security looked like for this kind of technology.
Constraints
The existing control frameworks were written for systems where a transaction can be reversed and a lost key recovered. Neither of those holds here, so the frameworks could not simply be stretched to cover it.
Approach
I developed and implemented the firm’s blockchain security standard, setting out what responsible adoption required: how new chains and protocols get assessed, what custody controls are expected, and what evidence a system has to produce before anyone approves it.
Outcome
The firm could weigh digital asset propositions against defined criteria, and the internal conversation moved on to architecture.
Frameworks: NIST CSF v2 · Key management · Custody controls