Skip to content

Leading Asian Bank Eliminates SSH Key Sprawl and Starts Its Migration to PQC

A security audit revealed an SSH key management problem, complicating the bank's security, compliance, and migration roadmap to Post-Quantum Cryptography (PQC).

Central mainframe augmented with light data

Customer

  • A leading bank in Singapore

  • Tens of thousands of hosts

  • Millions of SSH keys across their environment
Powerful quantum-safe security solutions

Challenge: An audit revealed an SSH key management problem

The customer had the following main drivers:

A security audit revealed an extensive SSH key sprawl across the bank's environment - with limited visibility into ownership and usage of existing SSH keys. The audit uncovered SSH keys as a serious risk to the bank's security posture.

The audit revealed:

  • Over 1 million SSH keys
  • Across 10,000+ hosts
  • 42% of SSH keys were 5+ years old
  • Outdated DSA keys

The SSH key sprawl exposed the customer to compliance and security risks, while complicating their post-quantum readiness roadmap (migration to post-quantum cryptography).

Solution: Automated SSH key lifecycle management & creating PQC crypto-inventory

Full SSH key visibility

The bank deployed PrivX Key Manager to gain full visibility into their SSH key estate, mapping keys across servers, users, and systems. They moved from near-zero visibility to a comprehensive, auditable inventory and management system of their SSH key estate.

SSH key lifecycle management

PrivX Key Manager enabled automated lifecycle management, including key rotation, expiration setup, and de-provisioning. Its policy enforcement flags and remediates legacy and non-compliant keys, including outdated DSA keys. Improving the customer's compliance posture, cutting down the manual burden of key management, and reducing their attack surface.

A complete crypto-inventory

PrivX Key Manager also created a complete crypto-inventory of the bank's cryptographic assets, laying the foundation for their migration to post-quantum cryptography. It allowed the customer to assess their level of PQC readiness, track PQC algorithm usage, and determine the risks of their tech stack in the PQC era.

Benefits

key-skeleton

Discover

PrivX Key Manager discovers and maps all SSH trust relationships and identifies unused, unmanaged, or unauthorized access. It also creates an inventory of such trusts as well as cryptographic assets.

Certification

Audit & comply

Define and implement SSH key policies, including length, expiration, and approved usage types. PrivX Key Manager tracks when and how keys are used - you receive alerts when keys are added, removed, modified, or unauthorized changes are made to SSH configurations.

Priviledged-access-management

Remediate

Identify and remove unused, duplicate, and non-compliant SSH keys through a secure automated workflow. Or update authorizations and renew old and non-compliant keys.

gear-cycle

Manage & automate

A complete view of every SSH key in the environment, including who accessed what, when, and how. Automate SSH key creation, rotation, approval, and retirement within a secure, policy-driven workflow. All from a single central management platform.

Shield

Migrate to keyless SSH access

PrivX Key Manager offers a structured path to just-in-time, certificate-based SSH access - from managing static credentials to centrally controlled, certificate-based, keyless access. No need to vault the private keys first, no need to edit scripts, no need to edit applications.

 

Learn more about securing access of human and non-human identities with keyless SSH access.