This case study shows how Home Credit Bank built a mature privileged access management system based on Idira (formerly CyberArk), turning it from a basic PAM tool into a key element of cyber resilience for 8 years. Learn how the bank scaled the platform, integrated it into its information security and IT processes, adapted it through organizational change, and why—despite a re-evaluation of the solutions market—it kept Idira (formerly CyberArk) as the strategic foundation for protecting its critical infrastructure.

BAKOTECH operates through a partner network.

Company profile

Home Credit Bank is one of Kazakhstan’s leading retail banks, focused on digital channels and customer services. The bank consistently pursues a digital-first approach, improving the convenience and accessibility of financial products while raising security requirements at the same time.

The bank has used Idira (formerly CyberArk) solutions for privileged access management since 2018. The solutions arrived as part of a corporate approach brought in from Europe. The process of securing privileged accounts was implemented in stages. As a result, over 8 years, the Idira (formerly CyberArk) platform became part of a systematic approach to reducing cyber risk and protecting critical infrastructure, as well as a foundation for developing mature information security processes.

Main areas of the bank’s activity

  • Development of retail banking products and services
  • Expansion and optimization of digital service channels
  • Improvement of cyber resilience and protection of critical infrastructure
  • Adoption and development of modern IT and DevOps practices 

Challenges

The growth of digital services and the increasing complexity of the IT landscape raised the requirements for access control and transparency of privileged users’ actions. The bank needed to build a systematic approach to protecting critical systems without slowing down product development or internal processes.

Key challenges:

  • A growing number of privileged accounts and access points to critical infrastructure
  • Lack of centralized control and auditing of administrator actions
  • Risks of unauthorized access and the difficulty of detecting such incidents in time
  • The need to comply with internal and international information security requirements
  • Increasing workload on IT and security teams from manual access management
  • The need for a scalable solution capable of supporting the growth of digital services

When selecting a platform, the bank looked for solutions that could be embedded into its existing infrastructure without adding unnecessary complexity. Idira (formerly CyberArk) stood out for its agentless architecture on target systems, ready-made connectors for key technologies, and a broad set of integrations with SIEM, ITSM, and DevOps tools. This allowed the bank’s team to shorten deployment time and run PAM immediately alongside the systems already in use.

Experience operating Idira (formerly CyberArk)

Since its implementation at Home Credit Bank, Idira (formerly CyberArk) has evolved steadily from a basic PAM tool into a comprehensive privileged access management system embedded in key IT and information security processes.

The solution developed along several tracks:

  • Platform scaling. Expanding licensing, deploying High Availability, EPV, and additional modules
  • Expanding authentication. Adding Idira Identity (formerly CyberArk Identity), with support for MFA, SSO, and an application access portal
  • Building in-house expertise. The team independently deploys, updates, and configures the system to fit its own processes

As the platform developed, a connected security ecosystem was built around PAM:

  • Integration with SIEM for incident monitoring and investigation
  • Integration with IDM to automate access provisioning and account management
  • Secure access to a wide range of systems, including web applications and databases

Focus on the access management model:

  • A move from individual safes to a team-based model
  • Automated access provisioning through roles and policies (RBAC)
  • Segmentation of environments (production / non-production)
  • Adoption of Microsoft’s tiering model to isolate critical systems

As a result, the bank was able to move from isolated PAM use to a systematic access control model in which most processes are standardized and automated.

The use of Idira Identity (formerly CyberArk Identity) strengthened authentication controls. Instead of basic OTP/SMS, a range of MFA scenarios became available, and internal applications were brought together under a single access portal.

Results of the implementation

Implementing Idira (formerly CyberArk) allowed Home Credit Bank to build a managed, resilient model for working with privileged access, in which technology and the processes surrounding it are equally important.

Key results

  • Stability and fault tolerance. No failures have been recorded over 8 years of operation. Failover is used only as part of planned testing
  • Full coverage of PAM scenarios. RDP, SSH, web access, database work via RDS, and expanding access to container infrastructure
  • A mature access management model. Transition to team safes, separation of prod/non-prod environments, automated role-based access provisioning
  • Integration into information security processes. Implementation of the tiering model, integration with IDM, centralized management of privileged accounts
  • Monitoring and response. All deviations from normal PAM operation are logged, processed through the SOC, and escalated into incidents where necessary
  • A flexible security approach. Collaboration with IT is built as a partnership, which simplifies the deployment and use of the solution
  • Proven effectiveness. Following comparative pilots, Idira (formerly CyberArk) remains the most functional PAM solution on the market

In summary, the platform has become the foundation for systematic privileged access management and cyber risk reduction, aligned with the real needs of the business and IT.

Plans for the future

Home Credit Bank continues to develop its use of Idira (formerly CyberArk), shifting focus toward modern, dynamic IT environments.

Upcoming plans include:

  • Container infrastructure — extending the PAM approach to dynamic environments
  • SSH access to containers — controlling and auditing interactive sessions without direct access to hosts
  • Kubernetes control (kubectl) — managing and auditing administrative actions at the API level
  • Web access to infrastructure — unifying entry points with session recording and monitoring

The bank’s team maintains the platform’s effectiveness by continuously developing access management processes, regularly expanding coverage of new systems, fine-tuning integrations, and engaging the teams that work with privileged accounts.

Another news

Whenstandardintegrationsarenotenough:DevelopingcustomCyberArkconnectorsinpractice

When standard integrations are not enough: Developing custom CyberArk connectors in practice

Onecontractor,oneincident:HowtoclosethemainholeinyoursecurityperimeterwithCyberArk

One contractor, one incident: How to close the main hole in your security perimeter with CyberArk

Privilegedaccesssecurityasthefoundationofcityservicescybersilience:Kyivteleservicecasestudy

Privileged access security as the foundation of city services cybersilience: Kyivteleservice case study

Securityvs.Speed:HowtoImplementaSecretsManagerWithoutFightingWithYourDevOpsTeam

Security vs. Speed: How to Implement a Secrets Manager Without Fighting With Your DevOps Team