Securing a Financial IT Environment with Secure FTP and Key Management
One of the biggest financial institutions in the world found itself overwhelmed by SSH keys in its IT environment and the need for a robust SFTP solution.
Customer
-
A large Asian financial institution
-
Billions of financial transactions every day
-
Once a year, they conduct a thorough evaluation of their technology stack to ensure that they have the best solutions available
Challenge: Lack of a secure file transfer solution that also supports centralized key management
The customer had the following main drivers:
The institution relies heavily on SSH keys to manage secure access to important IT resources and, like many enterprises, found itself overwhelmed by the volume, variety, and complexity of SSH keys in its IT environment.
These keys were being created by both in-house IT staff and external third-party contractors who had been hired, sometimes temporarily, to support specific projects. Key mismanagement created several operational and administrative challenges.
Employees and partners rely heavily on file transfers to securely share data, and they need an SFTP solution (instead of the previously used FTP solution) that enables agile ways of working – a reliable, secure solution without slowing down productivity.
Solution: Robust security and compliance of Tectia combined with PrivX Key Manager
At first, the customer considered OpenSSH – besides the fact that it’s a free tool, they thought that using OpenSSH would promote higher code quality within its development team. However, they realized that using OpenSSH could potentially open the code of their core banking systems to the public, making it vulnerable to hackers.
The organization’s security team had other concerns around OpenSSH. They have SFTP automation scripts within their infrastructure, and a migration to OpenSSH would be too costly, time-consuming, and demanding for the team. They also wanted a clear path to compliance and felt the need for local support.
Ultimately, Tectia Server and PrivX Desktop (client) were chosen over OpenSSH for their robust security, compliance, 24/7 support, and committed product development. Additionally, Tectia is trusted by many other large banks, insurance companies, retailers, and governmental bodies across the world.
Besides its robust security, the solution is also fast – the customer reported transferring large files up to twice as fast as OpenSSH.
To solve the organization’s extensive SSH key management problem, the SSH client/server solution was integrated with another solution by SSH Communications Security – PrivX Key Manager.
It automatically scans the organization’s IT infrastructure to identify and create an accurate inventory of SSH keys. It analyzes and presents the trust relationships enabled by the found keys – it’s easy to remediate any unmanaged or policy-violating keys. That significantly cuts down on oversight time, and additional manpower no longer needs to be used on manually identifying keys and their relationships.
Benefits
SSH access discovery
PrivX Key Manager discovers and maps all SSH trust relationships and identifies unused, unmanaged, or unauthorized access. It also creates an inventory of such trusts as well as cryptographic assets.
Fast file transfers & integrations
Tectia Server and PrivX Desktop support massive file transfers (terabyte-sized files) with configurable compression. The solution interoperates across Linux, Windows, UNIX, and IBM z/OS mainframes, and supports smartcards including U.S. federal PIV cards, like CAC and YubiKey.
Compliance
With PrivX Key Manager, you can define and implement SSH key policies. It tracks when and how keys are used - you receive alerts when keys are added, removed, or modified.
Tectia Server and PrivX Desktop solution supports FIPS, PCI-DSS, HIPAA, and GDPR out of the box.
Remediation
With PrivX Key Manager, it's easy to identify and remove unused, duplicate, and non-compliant SSH keys through a secure automated workflow. Or update authorizations and renew old and non-compliant keys.
SSH key lifecycle management & automation
A complete view of every SSH key in the environment, including who accessed what, when, and how. PrivX Key Manager offers extensive automation features for SSH key creation, rotation, approval, and retirement within a secure, policy-driven workflow. All from a single central management platform.
Future-proof security
PrivX Key Manager offers a structured path to just-in-time, certificate-based SSH access - from managing static credentials to centrally controlled, keyless access. It also establishes a complete inventory of cryptographic assets to support your post-quantum cryptography strategy.
Tectia's hybrid approach to post-quantum readiness covers Crystal/Kyber, FrodoKEM, NTRU (for compatibility reasons, and FireSaber (backup), alongside Kyber/ML-KEM.
