Flagship course

Fintech Resilience Audit Lab

A six-week live cohort where you design and defend a cyber resilience audit for a fintech product surface — payments, lending, or wallet — with weekly critique.

Security analyst reviewing systems during a resilience exercise

Learning outcomes

  • Write an audit charter that names in-scope journeys and explicit exclusions.
  • Produce a dependency map covering hosted services, partners, and human escalations.
  • Script tabletop and limited live drills with measurable pass/fail criteria.
  • Draft findings with severity, customer impact, and remediation owners.
  • Deliver a board-legible summary without stripping technical accuracy.

Who it suits

Security engineers, product risk leads, SRE managers, and compliance partners who already know basic controls vocabulary and need audit craft for fintech-specific continuity claims.

Informational price: ₩3,400,000 per seat for the live cohort. Invoicing happens offline — no checkout on this site.

Modules

  1. Scoping without theater Define product journeys, data classes, and regulatory hooks. Practice saying no to out-of-scope wishlist items.
  2. Dependency cartography Map issuers, processors, cloud regions, and on-call humans. Identify single points that diagrams usually hide.
  3. Evidence standards Decide what “proof” means for each control: logs, tickets, signed attestations, or timed drill records.
  4. Drill design Write tabletop scripts and limited live exercises. Capture observations that survive a skeptical re-read.
  5. Findings & remediation Grade severity for fintech customer harm and capital impact. Build a tracker engineers will not ignore.
  6. Board dry-run Present a short memo under timed questions. Faculty and peers play adversarial reviewers.

Instructor

Portrait of lead instructor Hae-won Cho

Hae-won Cho

Former lead auditor for a regional payments processor and later head of continuity for a digital bank. Hae-won designed the Lab’s drill rubrics and still reviews final findings memos for each cohort.

Learner notes

Module four’s drill script template replaced our “happy path” tabletop. We still argue about scoring, which is healthier than pretending every scenario was a pass.

Jun · Platform SRE · 2025 Lab

Strong on payment rails. If you are pure crypto custody, expect to adapt examples — faculty help, but the core scenarios lean traditional fintech.

Client in digital asset ops

FAQ

Do I need a production system to participate?

No. You may use a sandbox product we provide. Many learners prefer their real system with redactions; either works if you can discuss architecture honestly.

What is a real limitation of this course?

The Lab does not replace a licensed external audit firm. We teach method and artifact quality. If your regulator requires an accredited assessor signature, you still need that engagement — we prepare you to work with them efficiently.

How large are cohorts?

Usually 14–18 seats. We close enrollment when critique quality would suffer, not on a marketing countdown.

Language and timezone?

Sessions run in English, scheduled for Korea evening hours with recordings for absences (critique credit still requires two live appearances).

Next step

Tell us your product type and review window. We will confirm fit before invoicing.

Contact admissions