From Shadow to Secure: Regaining Control of 52,000 Identities

The Situation

 

Unmanaged Non-Human Identities Create Growing Risk

 

A large financial institution was undertaking a privileged access management (PAM) modernization initiative with a focus on non-human identities (NHIs) across server and application environments.

 

The client was struggling to manage approximately 52,000 NHIs across 341 in-scope applications. Ownership was unclear as there were almost no assigned application owners, and more than 1,000 IDs were in scope without accountable stakeholders.

 

As a result, the PAM effort was at risk of becoming a purely technical exercise: teams were busy onboarding accounts, but leadership lacked the visibility needed to define success, understand whether risk was being reduced and sustain control at scale.

 

 

The Solution

 

A Structured, Measurable NHI Program Designed to Scale

 

By establishing governance, ownership and executive visibility alongside technical delivery, Optiv helped the client transform a stalled PAM effort into a scalable NHI management program. The client gained clearer visibility across the 341 in-scope applications, improved accountability for the 52,000 NHIs and a repeatable process to onboard, manage and retire privileged service identities.

 

With consistent KPIs and steering-committee-ready reporting, executives could track progress in business terms: what was onboarded, what remained and where ownership or exceptions were required, strengthening confidence in the program’s trajectory and enabling more informed risk decisions.

 

Image
identity-regaining-control-of-52000-identities -asset-download@2x
 

Download a printable version of this case study

 

 

 

Industry Served:

Financial Services


Challenges

 

  • Unclear ownership across thousands of NHIs
     
  • Limited visibility into application and identity risk
     
  • Difficulty measuring progress and demonstrating risk reduction
     
  • PAM effort at risk of becoming purely technical

Optiv’s Actions

 

  • Agile NHI assessment and risk-based prioritization
     
  • Application ownership and accountability framework
     
  • Governance model with standardized NHI lifecycle processes
     
  • Executive-ready metrics, reporting and exception management

Client’s Success

 

  • Improved visibility across 341 applications and 52,000 identities
     
  • Clear ownership established for high-risk NHIs
     
  • Scalable, repeatable NHI onboarding and governance program
     
  • Executive confidence increased through measurable progress reporting

How can we help you secure greatness?

 

Optiv can advise on, deploy and operate end-to-end cybersecurity programs aligned to your business goals. As the cyber advisory and solutions leader, we serve nearly 6,000 companies across every major industry. Our certified experts can help you gain the agility, security, scale and control you need to stay ahead of the competition.