Critical Cloud and Tarian Labs target fintech runtime security gap

Two UK cybersecurity firms unite to replace point-in-time pen tests with continuous runtime validation for regulated fintech firms.

A modern operations center with bright natural light from windows features a large curved video wall displaying global maps, data, and code across multiple screens, alongside several ergonomic chairs and sleek curved desks.

Critical Cloud and Tarian Labs, two UK-based cybersecurity specialists, have announced a formal alliance to deliver what they are calling Continuous Runtime Security Validation, a managed service aimed squarely at the compliance and operational security gap facing fintech firms operating in production environments that change faster than annual penetration-test cycles can track.

The service is designed around a core tension that has become increasingly acute in regulated financial services: security assurance that was accurate at the moment of testing can be outdated within hours when a new AI feature is deployed, a cloud configuration drifts, or a dependency is patched. For firms operating under FCA scrutiny or aligned to frameworks such as DORA (the EU's Digital Operational Resilience Act), that gap between a signed-off pen-test report and the live production state is not a technicality but a material regulatory exposure.

What the service actually does

The offering stitches together two distinct capability sets under a single commercial engagement. Critical Cloud contributes its Managed Runtime Assurance model, an always-on operating layer for cloud, observability and AI runtime environments, built on Datadog tooling. Tarian Labs brings practitioner-led offensive security, with its team credentialled at CREST and NCSC-recognised CHECK Team Leader level, drawing on 22 years of combined experience in UK defence and critical national infrastructure contexts.

The operating model is deliberately structured to keep the two functions independent. Tarian Labs owns testing methodology, findings, severity ratings and retesting. Critical Cloud owns remediation and runtime improvement. The logic is that a managed service provider who both finds and fixes vulnerabilities introduces a conflict of interest that regulators in financial services are increasingly alert to. Separation of duties is not a marketing point here but a structural design choice.

"Detection without validation is hope, not assurance," said James Smith, CEO of Critical Cloud. "Fintech firms need more than a pen test report that ages the moment production changes. They need independent evidence that runtime controls work, and a managed operating model that turns findings into fixes."

The service is available now across the UK and Ireland, with a packaged joint offer described as forthcoming. Both companies are headquartered in Wales, and early market activation includes Welsh fintech community events.

The wider cybersecurity and fintech convergence angle

The launch sits within a structural shift in how regulated industries are being forced to think about security assurance. Frameworks such as DORA, which came into force across EU financial entities in January 2025, explicitly require financial firms to demonstrate operational resilience on a continuous basis, not merely at audit intervals. UK equivalents are developing in parallel under the PRA and FCA's operational resilience regime. The upshot is regulatory demand for exactly the kind of continuous, evidence-generating assurance model Critical Cloud and Tarian Labs are commercialising.

The AI dimension adds a further layer of urgency. As fintech firms embed generative AI features into production applications, the attack surface shifts in ways that static annual testing cannot capture. Runtime environments that include large-language-model inference endpoints, AI-assisted decisioning layers or third-party model APIs introduce new categories of vulnerability that conventional penetration-test playbooks are still catching up with. A managed service that continuously monitors and validates those environments is addressing a genuinely emerging compliance need, not a legacy one.

From a capital and competitive landscape perspective, the managed security services space for financial services is crowded at the enterprise end, with large incumbents such as IBM Security and Accenture Security competing alongside specialist boutiques. The Cardiff-based pairing is pitching into the mid-market fintech segment, where compliance budgets are real but dedicated in-house security operations are rare. Whether this alliance can hold its structural independence at scale, particularly if acquisition interest from a larger managed-services or cloud-security player materialises, is the question that will determine its longevity as a proposition rather than a feature within a larger platform.