Skip to main content
← All case studies

FinTech & Banking

Ending permanent admin access at a community bank, before the next review

Community bank · ~$900M in assets · 210 staff, 3-person IT team · FFIEC follow-up review in one quarter

24 → 2

permanent admin accounts (emergency use only)

15 min

elevation window, down from permanent

0

identity findings at the follow-up review

2 days

evidence prep, down from 3 weeks

This is an illustrative engagement, composed from incident and enforcement patterns published since 2024. It is not an account of a specific client, and the figures are representative of the pattern rather than drawn from one organisation's records. How we build these →

Context

The core banking platform still ran on shared admin credentials — a pattern regulators have flagged since before cloud existed. Two attempts to fix it had failed for the same reason: the three people who run IT could not do their jobs without permanent access, so every proposed control was quietly worked around within weeks.

This is the position most community banks are in. The rules that apply are the rules that apply to institutions a hundred times the size, and the team expected to satisfy them fits around one table.

Regulatory driver

An open FFIEC finding on shared administrator credentials and separation of duties, read against the Authentication booklet and InfoBase VI.A.3 expectations for privileged-user authentication. The evidence had to answer a question about one admin action on one date — not a policy document asserting that the control exists.

What we did

Made the compliant path the easy one. Rather than fighting how the team already worked, we rebuilt around it: CyberArk Privilege Cloud issues credentials on request with a 15-minute window, approvals route to the IT manager on a phone, and every admin session on core systems is recorded. Requesting access is now faster than the workaround was.

Separation of duties moved into the system. The payment initiate/approve conflict became impossible to hold rather than something to catch later — a request that would combine both roles is blocked at the point it is made, instead of being found in a quarterly spreadsheet review.

Evidence collects itself. Every request, approval and recorded session writes the audit trail as it happens. The pre-review fire drill became a two-day export.

Result

Follow-up review: no identity findings. The question — “show me that this particular admin action was approved, limited and recorded” — now takes minutes to answer, for any action, at any point.

Scope note: this was one workstream over eight weeks, covering privileged access on the core platform and Active Directory. It was not a whole-bank security programme, and it was not sold as one.

Stack hardened: CyberArk Privilege CloudMicrosoft Entra IDActive DirectorySplunk

Recognise any of this in your own setup?

Composites are built from patterns, and patterns repeat. In 30 minutes we can tell you how much of this one applies to you, and which part of it would surface first under examination.

Book an Identity Risk Review