Critical Cloud and Tarian Labs Launch Continuous Runtime Security Validation to Transform Cloud Security for UK Fintech

Listen to this Post

Featured ImageIntroduction: Why Traditional Security Is No Longer Enough

The cybersecurity landscape has changed dramatically over the past few years. Financial technology companies are rapidly adopting cloud-native infrastructure, containerized applications, APIs, artificial intelligence, and automation to remain competitive. While these innovations accelerate business growth, they also introduce new attack surfaces that evolve almost daily. A penetration test performed once every few months is no longer enough to guarantee that production environments remain secure.

Recognizing this challenge, Critical Cloud and Tarian Labs have formed a strategic partnership to introduce Continuous Runtime Security Validation, a new security assurance service designed specifically for organizations across the UK and Ireland. Instead of treating security assessments as isolated events, the service creates an ongoing validation cycle that continuously verifies whether security controls remain effective as infrastructure, applications, and AI systems change.

This collaboration represents a shift from periodic compliance exercises toward continuous operational security assurance—an approach that aligns with the realities of modern cloud computing.

Critical Cloud and Tarian Labs Join Forces

The newly announced partnership combines two complementary areas of expertise.

Critical Cloud contributes its Managed Runtime Assurance operational model, which focuses on maintaining the health, security, compliance, and resilience of production environments. Rather than simply deploying monitoring tools, the company continuously manages cloud operations while ensuring systems remain secure throughout their lifecycle.

Meanwhile, Tarian Labs brings extensive offensive security experience developed through projects involving government agencies, defense organizations, and critical national infrastructure. Their expertise includes penetration testing, cloud assessments, API security evaluations, web application testing, and infrastructure security reviews.

Together, the companies offer fintech organizations a comprehensive security validation service that extends well beyond traditional penetration testing.

Moving Beyond One-Time Security Reports

One of the biggest limitations of conventional penetration testing is that it captures security posture at only a single moment in time.

Organizations typically receive a lengthy report listing discovered vulnerabilities. After remediation, many companies wait months before conducting another assessment. During that period, cloud environments evolve, developers release new code, APIs change, infrastructure scales automatically, and AI systems receive updates—all of which can introduce fresh security risks.

Continuous Runtime Security Validation replaces this outdated workflow with a continuous improvement cycle.

Instead of generating static reports, security findings immediately enter an operational workflow where vulnerabilities are remediated, independently retested, validated, and documented with evidence confirming successful resolution.

This transforms penetration testing into an ongoing operational process rather than an annual compliance exercise.

How the Observe, Detect, Validate Methodology Works

The foundation of the new service is a structured framework called Observe, Detect, Validate.

Each stage performs a distinct role in strengthening production security.

Observe

Critical Cloud continuously monitors production environments using its Datadog-powered managed platform.

This monitoring provides visibility into:

Cloud infrastructure

Runtime applications

AI workloads

Operational performance

Security events

Compliance status

Instead of waiting for scheduled audits, organizations receive continuous insight into production systems.

Detect

Tarian Labs independently evaluates security controls through offensive security testing.

Its assessments include:

Penetration testing

Cloud security reviews

Infrastructure assessments

Web application testing

API security testing

Configuration validation

This offensive approach simulates the techniques real attackers would use to identify weaknesses before cybercriminals exploit them.

Validate

Once vulnerabilities are identified, remediation begins immediately.

Critical Cloud works with customers to resolve identified issues before Tarian Labs independently performs follow-up testing.

Only after vulnerabilities have been successfully verified as fixed are they considered closed.

This produces evidence-based assurance rather than assumptions that remediation was successful.

A Clear Separation of Responsibilities

An important feature of the partnership is its governance model.

Maintaining independence between testing and remediation helps preserve objectivity throughout the validation process.

Under the agreement:

Tarian Labs owns testing methodologies.

Tarian Labs determines vulnerability severity.

Tarian Labs performs independent retesting.

Critical Cloud manages operational improvements.

Critical Cloud oversees remediation.

Critical Cloud handles runtime operations and monitoring.

This separation ensures customers receive unbiased validation while still benefiting from integrated operational support.

Designed for Highly Regulated Industries

The service is particularly valuable for fintech companies operating under increasingly demanding regulatory frameworks.

Financial institutions face ongoing compliance obligations covering:

Operational resilience

Cloud governance

Third-party risk management

Data protection

Incident response

Continuous monitoring

Rather than producing compliance documentation based on outdated assessments, Continuous Runtime Security Validation enables organizations to demonstrate that production controls continue functioning correctly over time.

This evidence-based approach provides stronger assurance for auditors, regulators, and executive leadership.

Leadership Emphasizes Continuous Assurance

James Smith, CEO of Critical Cloud, highlighted a key weakness affecting many security programs today.

According to Smith, detecting threats without validating whether security controls actually work provides hope instead of genuine assurance. As organizations adopt increasingly complex technologies—including AI—continuous validation becomes essential rather than optional.

Kevin Hanford, Co-Founder and CEO of Tarian Labs, echoed a similar perspective.

He explained that penetration testing should serve as the starting point for continuous improvement rather than marking the end of a security engagement. By integrating testing, remediation, and independent verification, organizations gain confidence that identified risks have truly been eliminated.

Availability Across the UK and Ireland

Continuous Runtime Security Validation is immediately available to fintech organizations throughout the UK and Ireland.

The partnership also plans several future initiatives, including:

A packaged joint security offering

Fintech-focused cybersecurity events across Wales

Live demonstration environments

Full Observe, Detect, Validate workflow showcases

Practical remediation demonstrations

Evidence-based validation presentations

These initiatives aim to educate organizations on adopting continuous security assurance practices.

Industry Certifications Strengthen Trust

Both organizations possess credentials that reinforce confidence in the partnership.

Critical Cloud maintains:

ISO 27001 certification

Cyber Essentials Plus certification

Powered by Datadog Accreditation

Datadog Advanced Partner status

Meanwhile, Tarian Labs delivers security engagements through CREST-registered practitioners, with final approval provided at the National Cyber Security Centre (NCSC) recognized CHECK Team Leader (CSTL-INF) level.

These certifications demonstrate adherence to internationally recognized security and operational standards.

Why Continuous Validation Matters in the AI Era

Artificial intelligence is rapidly becoming embedded within enterprise infrastructure.

AI assistants, machine learning models, automated decision engines, and generative AI applications frequently receive updates, new integrations, and expanded permissions.

Unlike traditional software, AI systems can evolve quickly through retraining, configuration changes, API updates, and new data sources.

This creates a dynamic environment where yesterday’s security assessment may no longer accurately reflect today’s production risks.

Continuous Runtime Security Validation addresses this challenge by ensuring security controls remain effective even as AI workloads evolve alongside cloud infrastructure.

Deep Analysis

The partnership reflects a broader cybersecurity trend: organizations are moving away from reactive security toward continuous verification. Traditional penetration testing has long been considered a best practice, but its value diminishes quickly in environments where code is deployed multiple times a day and infrastructure changes automatically. Continuous validation bridges this gap by combining offensive testing with operational monitoring and rapid remediation.

The integration of Datadog into the service is particularly significant because runtime telemetry provides the contextual data needed to validate whether security controls are functioning under real-world conditions. Instead of relying solely on vulnerability scanners, organizations gain operational intelligence that helps prioritize risks based on actual production behavior.

Financial institutions are increasingly embracing DevSecOps principles, and this offering aligns well with those methodologies. Security is no longer confined to annual audits; it becomes an integral part of the software development and deployment lifecycle.

Organizations implementing similar models may incorporate automation such as:

Continuous Infrastructure Monitoring

terraform plan
terraform apply

Kubernetes Security Validation

kubectl get pods -A
kubectl get events
kubectl describe pod <pod-name>

Runtime Container Inspection

docker ps
docker inspect <container_id>

API Security Testing

curl -X GET https://api.example.com/health

Network Exposure Assessment

nmap -sV target-ip

Cloud Configuration Review

aws securityhub get-findings
az security assessment list
gcloud security posture list

These commands illustrate the types of operational activities commonly associated with continuous runtime validation. When integrated with independent penetration testing and evidence-based remediation, they provide organizations with a far stronger security posture than periodic assessments alone.

The partnership also reflects a growing market demand for measurable security outcomes. Boards and regulators increasingly expect organizations to demonstrate that vulnerabilities are not merely discovered but are actually remediated and independently verified. This evidence-driven approach supports compliance initiatives while improving resilience against increasingly sophisticated cyber threats.

What Undercode Say:

The announcement represents one of the strongest examples of how cybersecurity services are evolving from static assessments into continuous operational assurance. Modern fintech companies deploy software at a pace that traditional penetration testing simply cannot keep up with. By the time a report is delivered, parts of the production environment may already have changed.

Critical Cloud’s operational expertise complements Tarian Labs’ offensive security capabilities in a way that addresses this gap effectively. The separation of responsibilities is particularly noteworthy because it maintains the independence required for credible security validation while ensuring remediation is handled efficiently.

Another important aspect is the focus on runtime environments rather than development environments alone. Many organizations invest heavily in secure development practices but overlook the reality that production systems continue changing after deployment through configuration updates, scaling events, third-party integrations, and AI model updates.

The inclusion of AI workloads is especially timely. As enterprises increasingly rely on generative AI and machine learning systems, continuous validation will likely become a regulatory expectation rather than simply a best practice.

From a business perspective, continuous validation may also reduce long-term operational costs by identifying weaknesses earlier, shortening remediation cycles, and minimizing the likelihood of costly security incidents.

This model aligns closely with Zero Trust principles, where trust is never assumed and security controls must be continuously verified. It also complements DevSecOps by embedding security into operational workflows rather than treating it as a separate audit function.

The Observe, Detect, Validate methodology provides a practical framework that organizations can understand and integrate into existing cloud operations. Instead of replacing traditional penetration testing, it enhances its value by extending the lifecycle of every finding until verified closure is achieved.

For regulated industries such as banking and fintech, the ability to provide evidence-based assurance could significantly improve relationships with auditors, insurers, regulators, and customers alike.

Looking ahead, similar continuous validation services are likely to expand beyond fintech into healthcare, manufacturing, telecommunications, and government sectors where operational resilience is becoming equally critical.

Overall, this partnership highlights an important industry transition—from proving security once to proving security continuously.

✅ Fact: Critical Cloud and Tarian Labs have officially announced a strategic partnership to deliver Continuous Runtime Security Validation across the UK and Ireland. This is consistent with the information presented in the announcement and reflects a legitimate collaboration focused on production security assurance.

✅ Fact: The service combines Critical Cloud’s Managed Runtime Assurance model with Tarian Labs’ offensive security testing, following an Observe, Detect, Validate methodology. The described separation of testing and remediation responsibilities aligns with recognized security governance practices that preserve assessment independence.

✅ Fact: The certifications mentioned—including ISO 27001, Cyber Essentials Plus, Datadog partnership status, CREST practitioners, and NCSC CHECK Team Leader oversight—are credible industry-recognized qualifications that strengthen confidence in the service’s operational and technical capabilities.

Prediction

(+1) Continuous Runtime Security Validation is likely to become a standard requirement for regulated industries as cloud-native applications, APIs, and AI systems continue to evolve at high speed. Organizations will increasingly favor continuous evidence-based assurance over annual penetration testing alone.

(-1) Companies that continue relying solely on periodic security assessments may experience larger security gaps as infrastructure changes outpace traditional testing schedules, potentially increasing regulatory scrutiny and cyber risk exposure.

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.itsecurityguru.org
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube