Financial services
Legacy core systems, third-party access and SOX 404 — where the CEO and CFO sign personally. Identity security for financial services
Every sector we work in has a regulator, a set of systems that were not built for modern identity controls, and a specific way access goes wrong. Seven pages, each written for the person doing the job in that sector.
The systems differ, the acronyms differ, and the answer is the same identity program.
Legacy core systems, third-party access and SOX 404 — where the CEO and CFO sign personally. Identity security for financial services
Shared clinical logins, break-glass, medical devices that cannot be patched, and the HIPAA Security Rule. Identity security for healthcare
Agents, brokers, MGAs and TPAs governed to NAIC model law and 23 NYCRR 500. Identity security for insurance
Whole cohorts joining and leaving every semester, decentralized IT, FERPA and GLBA. Identity security for education
Seasonal turnover, shared store logins, vendor access and PCI-DSS Requirements 7 and 8. Identity security for retail
The IT/OT boundary, vendor remote access, and NERC CIP with its 24-hour rule. Identity security for energy and utilities
70% turnover, a PMS that touches everything, and a help desk that can be talked into a reset. Identity security for hospitality
Underneath the vocabulary, every regulator asks the same four questions: who can access what, is it controlled, is it logged, and can you prove it. The systems differ, the acronyms differ, and the answer is the same identity program applied with the sector's constraints in mind. That is all our IAM services, and it starts with a free audit.
Evidence assembled after the fact, once the audit is booked.
Evidence produced as a byproduct of how the program runs.
Framework coverage varies by engagement and sector. We scope the controls and evidence that apply to your environment.
A free audit is a 30-minute review of your privileged accounts by a certified engineer, with the findings in writing. No cost, no obligation.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.