Skip to main content
Home/Cases/BFSI
BFSI · India

Indian financial institution unifies network and privileged access.

NAC + PAM across 6 sites secure 2,200 users, 8,000 servers and 800 devices.

// Client overview

A large financial institution that aims to reach every individual in the country with one or more payment services, alongside a robust payment infrastructure. It runs a diverse infrastructure spread across multiple geographies offering cutting-edge payment services; as it expanded, its digital footprint grew, demanding robust cybersecurity to safeguard sensitive financial and customer data.

India's digital-payment space has transformed and the country has embraced digital payments. With the spike in usage and the sensitivity of the financial realm, the need to maintain the highest level of security is high. With the explosion of cyber threats and rising daily transaction volumes, the client recognized the need for effective network access control (NAC) and privileged access management (PAM).

Sector
BFSI
Region
India
Engagement
Cyber transformation
Services
Network Access Control (NAC) · Privileged Access Management (PAM) · Compliance & policy enforcement · Multi-factor authentication
Technologies
Dynamic role-based ACLs · AAA / 802.1X · Password vault · Commvault · RSA token MFA
// Key challenges
Distributed network across 6 different geographical locations made it difficult to control and monitor the network.
More than 3,000 devices and 2 data centers made controlling and monitoring the network increasingly complex.
Implementing uniform security policies and access-control measures across sites was extremely difficult.
With 2,200 users across 6 locations, 8,000+ servers and 800 network devices, securing and monitoring privileged accounts and access to critical systems was a daunting task.
Device health checks were needed across all 6 locations to validate compliance policy, along with user-based network access restriction and certificate validation during 802.1X authentication.
Complete visibility into privileged accounts and least-privilege access for employees was required.
// The solution · highlights
Inspira - the global cybersecurity, data analytics and AI services partner - proposed a comprehensive solution implementing Network Access Control and Privileged Access Management across all locations.
Network Access Control: highly scalable, reliable policies with dynamic role-based ACLs were designed and pushed to switches and controllers, with security-posture policies based on RBI guidelines.
An AAA (Authentication, Authorization and Accounting) framework was established for every device connecting to the corporate network; non-compliant devices were blocked from the corporate VLAN.
Privileged Access Management: a Just-in-Time access-control model granted approvals on a limited, as-required basis with configured approval workflows, backed by a password vault automating end-to-end password management.
Databases, Windows and Linux servers, network devices and application web UIs were integrated; quarterly DR drills were run; video-log management and backup on Commvault were established; and RSA token management provided multi-factor authentication.
// Outcome & benefits
Only compliant devices connected to the corporate VLAN, and regulatory compliance was achieved through robust security policies.
Authorized network access was delivered via the AAA solution, and users enjoyed faster, more seamless transactions.
The network became highly scalable, reliable and future-ready, with comprehensive visibility into privileged accounts.
Access was automatically provisioned and de-provisioned as roles changed or users left, reducing account-takeover risk.
Damage from malicious insiders was limited as PAM restricted users to only the systems they work with, cutting data-breach and unauthorized-access risk.
Operational efficiency improved by streamlining network management and privileged-access control, and business continuity was strengthened through highly available data centers.
// Recent posts

More from our team.

Thought Leadership

Tech Achieve Media (Q & A) Pritam Shah, Inspira Enterprise | Tech Achieve Media

Read article →
Thought Leadership

Zero Trust for Modern Enterprises as the Foundation of Cyber Resilience

Read article →
Thought Leadership

Cyber Resilience in Times of Crisis: How Enterprises Can Stay Secure and Operational

Read article →

Explore our top services.

All services →
svc.01
Managed Security and AI Driven SOC
svc.02
Cyber Advisory
svc.03
AI Identity & Access Management
svc.04
Operational Technology (OT) Security
svc.05
Threat & Vulnerability Management (TVM)

Facing a similar challenge in BFSI?

Talk to the team that delivered this outcome. We will walk your environment, name the moves that matter, and leave you with a clear point of view.

Talk to an expert →← All case studies