Skip to main content
Home/Cases/BFSI
BFSI · APAC

Asian stock exchange lifts identity secure score from 53% to 95.8%.

Four Entra ID tenants unified, Conditional Access cut from 51 policies to 9, and every subsidiary brought under one identity governance model.

// Client overview

Among the world’s leading stock exchanges and Asia’s gateway to global capital markets, the group offers investment and risk management solutions worldwide through a single trusted point of access. Its environment spans 4 Entra ID tenants, more than 4,000 employees, an on-premises Active Directory, 4 subsidiaries and over 150 financial and trading applications - a complex and highly dynamic IT landscape.

Operating in a highly regulated, mission-critical environment, the group is pivotal to market integrity, investor trust and financial stability. But managing identity and access across a hybrid estate had become progressively harder, and the gaps carried real consequences for regulatory compliance, operational resilience and overall security posture.

Sector
BFSI
Region
APAC
Engagement
Cyber transformation
Services
Identity & access management · Privileged Access Management (PAM) · Conditional Access policy design · Modern authentication migration · Cloud-native endpoint management · Identity monitoring & audit readiness
Technologies
Microsoft Entra ID · Microsoft Entra Conditional Access · Privileged Identity Management (PIM) · Active Directory · Cloud-native endpoint management · Multi-factor & passwordless authentication
// Key challenges
Fragmented identity ecosystem: disparate identity systems across business units drove inconsistent governance and raised risk exposure.
Inconsistent access policies: overlapping, non-standardised access controls created compliance gaps.
Legacy authentication dependencies: continued reliance on outdated authentication mechanisms left the group exposed to modern threats.
Limited threat visibility: without centralised monitoring, privileged access misuse and anomalous activity were hard to detect.
Decentralised control: no unified governance for hybrid identities, authentication or endpoint policy.
Low security maturity: an initial secure score of 53%, with multiple audit non-conformities, made remediation urgent.
// The solution · highlights
Unified identity architecture: on-premises and cloud identity ecosystems integrated into one framework, consolidating multiple Microsoft Entra ID tenants and legacy directories.
Standardised access policies: risk-based Conditional Access streamlined and optimised, aligned to central bank regulatory requirements and global best practice.
Modernised authentication: legacy applications migrated to modern authentication protocols, with MFA and passwordless options enabled.
Centralised device management: traditional Group Policy Objects transitioned to cloud-native endpoint management, giving unified visibility and control across hybrid environments.
Privileged Access Management: Privileged Identity Management deployed for just-in-time access, with approval workflows and time-bound privilege elevation.
Real-time monitoring and auditing: centralised logging, monitoring and alerting across the hybrid estate, with comprehensive reporting for audit readiness.
// Outcomes
Enhanced security posture: a significant, measured improvement in secure score.
Regulatory compliance: alignment achieved with central bank and financial regulatory authority guidelines, and with global financial regulatory standards.
Improved visibility and control: centralised identity governance enabled real-time monitoring and faster incident response.
Reduced risk exposure: privileged access risk minimised through just-in-time access and policy standardisation.
Operational efficiency: streamlined identity lifecycle management reduced administrative overhead.
// Key benefits
CIS-aligned hardening established a consistent Zero Trust framework.
Legacy applications migrated to modern identity systems without disruption.
Secure B2B collaboration enabled across all four subsidiaries.
Real-time audit and alerting established across hybrid and on-premises environments.
// By the numbers · ROI
Microsoft Secure Score (Identity): 53% → 95.8%
Conditional Access policies: 51 → 9
Subsidiaries secured: 0 → 4
Entra ID tenants unified: 0 → 4
// Recent posts

More from our team.

White Paper

Turning GRC From a Compliance Burden Into a Business Advantage & Resilience

Read article →
Thought Leadership

Tech Achieve Media (Q & A) Pritam Shah, Inspira Enterprise | Tech Achieve Media

Read article →
Thought Leadership

Zero Trust for Modern Enterprises as the Foundation of Cyber Resilience

Read article →

Explore our top services.

All services →
svc.01
Managed Security and AI Driven SOC
svc.02
Cyber Advisory
svc.03
AI Identity & Access Management
svc.04
Operational Technology (OT) Security
svc.05
Threat & Vulnerability Management (TVM)

Facing a similar challenge in BFSI?

Talk to the team that delivered this outcome. We will walk your environment, name the moves that matter, and leave you with a clear point of view.

Talk to an expert →← All case studies