Company Profile
- Company
- UK Retail Banking Company
- Size
- UK Big Four Clearing Bank
- Industry
- Financial Services
- Location
- United Kingdom
A UK Big Four clearing bank serving more than 16 million customers found unprotected personal and financial data in the sandbox environment it provides to third-party developers. That environment holds 250 separate connections, each of which had to be examined. PKWARE was brought in through IBM and Kyndryl to scan all of them with one tool, quickly enough to act on what the penetration test had already exposed.
Background
As one of the UK’s “Big Four” clearing banks, this large retail bank boasts an extensive network of branches and serves more than 16 million personal customers and small business accounts.
A developer sandbox is an easy place for production data to accumulate. It exists to be permissive, it is used by people outside the bank, and it rarely sits inside the controls applied to production systems. Sixteen million customer records set the scale of what a gap there would mean.
Challenges
While running a pen test on the sandbox environment that is available for third-party developers, the bank found a plethora of unprotected personal and financial information. This required a tool that could scan for all sensitive data within the sandbox. An added challenge, however, was the need to individually scan 250 connections in order to discover what type of sensitive data was in that sandbox environment.
Two hundred and fifty connections is what made manual work impossible. Examining each one individually is not merely slow; it produces 250 separate judgements taken at different moments, so the picture is never current for the whole environment at once. A single scan across all of them is what turns that into one answer.
Use Cases
Since any exposed data creates great risk, the bank needed a solution in place quickly that would work from day one. Already a customer of IBM, the bank raised their issue and was directed by IBM global services consulting partner Kyndryl to consider PKWARE.
PKWARE’s PK Discovery tool, part of the PK Protect suite of data security solutions, is able to work with all 250 connections in the sandbox to find sensitive data. As a result, the bank only needs to invest in and manage one solution to meet their needs. The speed and accuracy of PK Discovery also meant the bank would be able to start scanning the sandbox almost immediately for sensitive data and be confident in the results it uncovered.
Speed mattered here in a specific sense. A penetration test establishes that exposure exists without establishing its extent, and the interval between those two facts is time the bank spends carrying an unmeasured risk. Scanning that starts immediately and covers every connection closes that interval rather than documenting it.
Our Approach
PK Discovery delivered on the bank’s urgent requirements with clarity on both current and future support. The current use case includes scanning operating systems.
Results
A tried and proven solution already well-known by Kyndryl to support IBM, PK Discovery delivered on the bank’s urgent requirements with clarity on both current and future support. The current use case includes scanning operating systems. Once the bank has access to scan databases, PK Discovery can be easily scaled to discover on those as well without the need for the bank to invest in and install another solution. Future plans may also include the option to remediate any discovered data with masking, redaction, and/or encryption, all available within the PK Protect product suite.
The path beyond the sandbox is why a single platform mattered. Databases are the next scope, and remediation by masking, redaction or encryption sits in the same suite, so extending coverage becomes a configuration decision rather than a fresh procurement and a second tool to operate.
