Home Credit Bank is one of Kazakhstan's leading retail banks, focused on digital channels and customer services. The bank consistently pursues a digital-first approach, improving the convenience and accessibility of financial products while raising security requirements at the same time.
The bank has used Idira (formerly CyberArk) solutions for privileged access management since 2018. The solutions arrived as part of a corporate approach brought in from Europe. The process of securing privileged accounts was implemented in stages. As a result, over 8 years, the Idira (formerly CyberArk) platform became part of a systematic approach to reducing cyber risk and protecting critical infrastructure, as well as a foundation for developing mature information security processes.
Main areas of the bank's activity: ● Development of retail banking products and services ● Expansion and optimization of digital service channels ● Improvement of cyber resilience and protection of critical infrastructure ● Adoption and development of modern IT and DevOps practices
The growth of digital services and the increasing complexity of the IT landscape raised the requirements for access control and transparency of privileged users' actions. The bank needed to build a systematic approach to protecting critical systems without slowing down product development or internal processes.
Key challenges: ● A growing number of privileged accounts and access points to critical infrastructure ● Lack of centralized control and auditing of administrator actions ● Risks of unauthorized access and the difficulty of detecting such incidents in time ● The need to comply with internal and international information security requirements ● Increasing workload on IT and security teams from manual access management ● The need for a scalable solution capable of supporting the growth of digital services
When selecting a platform, the bank looked for solutions that could be embedded into its existing infrastructure without adding unnecessary complexity. Idira (formerly CyberArk) stood out for its agentless architecture on target systems, ready-made connectors for key technologies, and a broad set of integrations with SIEM, ITSM, and DevOps tools. This allowed the bank's team to shorten deployment time and run PAM immediately alongside the systems already in use.
Since its implementation at Home Credit Bank, Idira (formerly CyberArk) has evolved steadily from a basic PAM tool into a comprehensive privileged access management system embedded in key IT and information security processes.
As the platform developed, a connected security ecosystem was built around PAM: ● Integration with SIEM for incident monitoring and investigation ● Integration with IDM to automate access provisioning and account management ● Secure access to a wide range of systems, including web applications and databases
Focus on the access management model: ● A move from individual safes to a team-based model ● Automated access provisioning through roles and policies (RBAC) ● Segmentation of environments (production / non-production) ● Adoption of Microsoft's tiering model to isolate critical systems
As a result, the bank was able to move from isolated PAM use to a systematic access control model in which most processes are standardized and automated.
The use of Idira Identity (formerly CyberArk Identity) strengthened authentication controls. Instead of basic OTP/SMS, a range of MFA scenarios became available, and internal applications were brought together under a single access portal.
Implementing Idira (formerly CyberArk) allowed Home Credit Bank to build a managed, resilient model for working with privileged access, in which technology and the processes surrounding it are equally important.
If you are interested in the Idira solution and would like to test it personally,please click the button below: