How a Leading Bank Automated Renewals for 5,000+ TLS Certificates

 

Speak to an Expert

The Situation

 

Audit Failures Spark Urgent Security Overhaul

 

Financial institutions are often subject to stricter standards than other businesses, which means more audits and more risk of financial and client loss when facing poor audit results. This was the case for a leading commercial bank, which had repeated audit failures due to weak signing algorithms and insufficient cipher strength. Tired of paying penalties and unsure of how to go forward, the bank reached out to Optiv’s managed machine identity security team.

 

Right away, the team discovered issues within the reporting structure. The third-party certificate manager was no longer functioning properly, preventing the delivery of the appropriate data for remediation. To ensure full visibility and remediation, Optiv’s team performed a complete overhaul of the monitoring and reporting structure, implementing custom created reports and discovery jobs to find all certificates causing the audit failure.

 

 

The Solution

 

Custom Certificate Management Overhaul Puts Bank Back on Track

 

Optiv’s managed machine identity security team collaborated with certificate owners and the client’s security team to update configurations for proper certificate installation and prevent future issues. The team standardized formatting and naming conventions, then used the client's existing certificate manager to upgrade weak ciphers and algorithms that caused audit failures.

 

Rules for certificate processing were established, templates were restricted according to audit requirements and automations were implemented to monitor lifecycles and renew and install certificates nearing expiration. As a result, the client has not faced any audit failures or penalties since adopting Optiv’s solution, saving millions in potential outage costs and thousands of hours spent manually renewing certificates.

Image
ManagedMachineIdentitySecurity_PKI_case-study_Assest

Download a printable version of this case study

 

Industry Served:

Financial


What Client Purchased

 

  • Managed Machine Identity Security 
    Service

Optiv’s Actions

 

  • Comprehensive certificate discovery and reporting overhaul
  • Upgraded weak ciphers and signing algorithms
  • Standardized certificate naming and formatting
  • Automated certificate lifecycle 
    management

Client Success

 

  • Fully automated certificate renewal and installation process
  • 5,000 certifications under management
  • Eliminated audit failures and penalties
  • Improved certificate management visibility
  • Enhanced security and compliance posture

Automate Your CLM Process with Confidence

 

Speak to our PKI experts for more information on end-to-end managed machine identity security, including discovery, policy enforcement, renewal automation, monitoring and incident response.