Zero Trust Rollout for a Global Bank
Mean-time-to-detect reduced 62%
Flat network architecture, fragmented identity and reactive detection left the bank exposed to lateral movement and unable to satisfy converging regulatory expectations across NYDFS 500, DORA and internal audit.
How we delivered.
- Step 01
Designed an identity-first Zero Trust target architecture aligned to CISA ZTMM and NIST 800-207.
- Step 02
Modernized IAM and PAM with phishing-resistant MFA, just-in-time access and session monitoring.
- Step 03
Implemented micro-segmentation across hybrid environments anchored by workload identity.
- Step 04
Deployed XDR + SOAR with high-fidelity detection content and automated containment playbooks.
- Step 05
Established continuous control validation tied to regulatory mappings for evidence on demand.
Measurable, defensible, durable.
mean-time-to-detect reduction
MFA across the global workforce
control validation tied to regulator mappings
evidence pipelines for NYDFS, DORA and internal audit
- Microsoft Entra + PAM
- Illumio segmentation
- CrowdStrike XDR
- Tines SOAR
- Continuous control validation tooling
