Financial Services / Banking

Cyber Security

Zero Trust Identity Modernisation for a Tier-1 Retail Bank

The Client & The Challenge

Context

A Tier-1 retail bank operating across five states with over 9,000 employees, a hybrid on-premises/cloud environment, and a legacy identity model built around perimeter-based VPN access and static role assignments accumulated over a 15-year IT history.

The Problem Statement

The bank's identity and access architecture had become a systemic risk. Privileged accounts were over-provisioned, contractor access lacked consistent offboarding controls, and the security team had no unified, real-time view of "who can access what" across core banking, digital channels, and back-office systems. This exposed the bank to regulatory scrutiny under APRA CPS 234 and elevated the risk profile ahead of an upcoming external audit, while the existing VPN-based perimeter model was increasingly incompatible with a distributed, hybrid workforce.

The Strategic Solution & Engineering Architecture

Approach

AIIDA led with a risk-first discovery phase — mapping identity sprawl, privileged access pathways, and regulatory obligations before a single control was redesigned. A Zero Trust target-state architecture was co-developed with the bank's risk and compliance function to ensure the technical roadmap was defensible in front of the board and the regulator, not just the security team.

Technical Execution

Deployment of a Zero Trust Network Access (ZTNA) model replacing legacy VPN, underpinned by continuous identity verification, device posture checks, and micro-segmented access to core banking and payment systems. Privileged Access Management (PAM) was implemented for all administrative and service accounts, paired with Identity Governance and Administration (IGA) tooling to automate access certification and enforce least-privilege by default. A centralised SIEM/SOAR layer was tuned to detect anomalous identity behaviour in real time.

Methodology

Delivery ran through cross-functional squads (security engineering, identity architecture, and compliance) using an agile-at-scale model with fortnightly control sign-off gates, followed by a structured hypercare transition period post go-live to stabilise detection tuning and reduce false-positive noise before handover to the bank's SOC.

The Strategic Solution & Engineering Architecture

Metric Category Pre-Transformation Post-Transformation Business Impact (%)
Efficiency / Speed 14-day average access provisioning/de-provisioning cycle Same-day automated provisioning via IGA workflows 85% Reduction in Access Cycle Time
Cost / Resource Optimization Manual quarterly access reviews consuming ~1,200 analyst hours/year Automated, continuous access certification ~$410K Saved Annually in Manual Review Effort
Quality / Reliability 22% of privileged accounts flagged as over-provisioned in baseline audit Reduced to under 3% post-remediation 86% Reduction in Privileged Access Risk
Strategic Adoption Fragmented, VPN-based access viewed as a workforce pain point ZTNA rolled out to 100% of in-scope workforce with minimal helpdesk friction 94% Employee Satisfaction on Access Experience

Key Takeaway / Lesson Learned

The success of this engagement hinged on treating Zero Trust as a governance and risk transformation first, and a technology deployment second — aligning every control decision to a regulatory obligation the board already understood. This gave the bank a security architecture that was not only more resilient, but immediately defensible under formal audit.