Skip to content

Top 15 Global Bank Restores Compliance and Reduces Risk with PrivX Key Manager

A security audit raised attention to the risk and compliance issues stemming from the lack of governance over SSH user keys that grant access to critical banking systems.

bank

Customer

  • One of the largest banks in the world

  • Over $2.5 trillion in assets 

Powerful quantum-safe security solutions

Challenge: Failed audit and violation of compliance mandates

The customer had the following main drivers:

A security audit revealed risk and compliance issues stemming from a lack of governance over SSH user keys. 

Auditors advised the bank's management that the existence of this unmanaged authentication system violated compliance mandates (MAS & SOX) and, even more seriously, represented an existential threat to the organization itself. 

A single compromised key granting root access to server infrastructure would expose the bank to information theft, tampering, and data loss.

Solution: SSH key lifecycle management paired with advisory services

The customer felt that they needed a vendor-partner that could provide a complete SSH key management product as well as advice and expertise to design and implement the solution.

The bank realized that they simply did not have sufficient in-house SSH knowledge and expertise to deal with this problem that had been growing for years.

They decided that SSH Communications Security and PrivX Key Manager are the best solution on the market for them.

Unneeded keys were removed and actively used keys were brought under administrative control. PrivX Key Manager now provides central administration to ensure policy control over key usage, key lifetimes, and authority over key creation. It also actively monitors the environment and alerts administrators to policy violations.
"One of the first things SSH Communications Security did was to demonstrate the scope of the problem. Their SSH key discovery showed us that the problem was even more widespread and serious than our auditors were saying. SSH’s technical deployment team found we had over 1.5 million SSH user keys distributed across our entire infrastructure, including over 150,000 user keys granting root access, with no records as to who was in possession of the corresponding private keys."
Project Manager at the bank
“We found that some of our critical security safeguards, such as those ensuring separation of test and production environments, were easily circumvented via SSH keys. SSH Communications Security showed us how PrivX Key Manager combined with their professional services would enable us to take back control. No other vendor had the products or expertise to do this. SSH has been a true partner in this endeavor. Their expertise and attention to detail have been invaluable in helping us address this major risk and compliance issue.”
Project Manager at the bank

Benefits

key-skeleton

Discover

PrivX Key Manager discovers and maps all SSH trust relationships and identifies unused, unmanaged, or unauthorized access. It also creates an inventory of such trusts as well as cryptographic assets.

Certification

Audit & comply

Define and implement SSH key policies, including length, expiration, and approved usage types. PrivX Key Manager tracks when and how keys are used - you receive alerts when keys are added, removed, modified, or unauthorized changes are made to SSH configurations.

Priviledged-access-management

Remediate

Identify and remove unused, duplicate, and non-compliant SSH keys through a secure automated workflow. Or update authorizations and renew old and non-compliant keys.

gear-cycle

Manage & automate

A complete view of every SSH key in the environment, including who accessed what, when, and how. Automate SSH key creation, rotation, approval, and retirement within a secure, policy-driven workflow. All from a single central management platform.

Shield

Migrate to keyless SSH access

PrivX Key Manager offers a structured path to just-in-time, certificate-based SSH access - from managing static credentials to centrally controlled, certificate-based, keyless access. No need to vault the private keys first, no need to edit scripts, no need to edit applications.

 

Learn more about securing access of human and non-human identities with keyless SSH access.