Company Profile
The company featured in this case study asked to have its name publicly blinded because publicly endorsing vendors is against their policies.
- Company
- Financial Institution
- Size
- Large Enterprise
- Industry
- Financial Services
- Location
- Global
How a Leading Financial Institution Leveraged PK Encrypt for Compliance and Efficiency
A regional bank running more than 1,100 branches and 2,400 ATMs across 11 states extended a long-standing PKWARE deployment from compression into encryption. The work was done with custom REXX scripts in batch and TSO rather than with a new platform, because PK Encrypt integrates with IBM System Authorization Facility and runs inside the batch jobs that already performed unzip operations.
Background
This financial institution operates more than 1,100 branches and 2,400 ATMs spanning 11 states. With a workforce of approximately 20,000 employees, the company provides a comprehensive array of financial services, including personal and business banking, wealth management, and investment services. The bank’s extensive network and diverse service offerings position it as a key player in the regional financial sector. IBM Z provides the security, resiliency, performance, scalability, and sustainability that enable this financial institution, along with many other customers, to trust the agility of the platform.
IBM Z is the reason that approach was available at all. A mainframe estate concentrates transaction processing in one place, so a control added there covers a large share of the data movement at once. Scale of that kind also means any new step in the batch window has to justify the time it consumes.
The Use Case
Our client, a long-time PKWARE user, initially employed the software primarily for compression purposes. Recently, they’ve expanded their usage to include encryption, leveraging PK Encrypt in both batch processing and interactive environments through custom REXX scripts. Their workflow now encompasses decrypting PGP files within TSO, as well as encrypting and decrypting data on-demand using PK Encrypt. This approach allows for secure data handling, transmitting encrypted data rather than sensitive information in clear text.
Encrypting on demand rather than as a separate stage is the operational distinction. Data leaves the system already protected, so nothing is transmitted in clear text and no secondary process has to be scheduled, monitored or reconciled against the first.
Why PKWARE
The decision to adopt PK Encrypt was driven by several factors:
- Existing familiarity with PKWARE products
- Seamless integration with current processes and IBM’s System Authorization Facility (SAF)
- No need for additional tool setup or complex implementations
- Ability to leverage existing batch jobs that performed unzip operations
The ease of incorporating PK Encrypt into their established workflows allowed for a smooth transition and immediate productivity gains.
PKWARE’s Solution
Key advantages of PK Encrypt include:
- Versatility in both batch and interactive modes
- On-the-fly encryption capabilities
- Secure encrypted data exchange instead of transmitting clear data
- Time-saving features that streamline processes
The flexibility of PK Encrypt has significantly enhanced the client’s data security posture while maintaining operational efficiency.
System Authorization Facility integration is what removes the usual administrative cost. Access to encryption functions is governed by the security manager the bank already operates, so no second set of permissions has to be created, kept current or audited separately.
Results
The implementation of PK Encrypt has yielded substantial benefits:
- Compliance with regulatory requirements
- Adherence to PCI standards
- Enhanced overall data security posture
- Improved efficiency in secure data handling processes
By leveraging PK Encrypt, the client has successfully bolstered their security infrastructure while meeting crucial industry standards and regulations.
PCI adherence is the standard named here, and the general point holds beyond it. Regulators increasingly ask what protects the data rather than what protects the perimeter around it, and encryption applied at the point of processing answers that question without depending on network boundaries.
