CYBERSECURITY / BANKINGClient: A digital-first bank

SOC 2 Type II in Five Months for a Digital-First Bank: IAM Consolidation, Zero-Trust, and Continuous Evidence

Security engineering and evidence pipeline. SOC 2 Type II clean opinion. MTTR on vulnerabilities cut from 22 days to 4. Standing production privileges eliminated.

AUERON Technologies
5 mo

to SOC 2 Type II clean opinion

4 days

vulnerability MTTR (from 22)

0

standing production admin sessions

A digital-first bank serving roughly 180,000 retail customers had signed enterprise partnerships that required SOC 2 Type II attestation within six months.

The bank's engineering team was strong on product delivery but had accumulated the identity and audit debt that comes with fast growth. Sixteen IAM systems. Roughly 240 human users across cloud and internal apps. Audit logs scattered across four cloud accounts and three SIEM tenants. Two prior external readiness assessments had flagged 47 findings, of which 23 were rated critical.

AUERON's security engineering team consolidated identity onto a single SSO and SCIM backbone, replaced all standing production admin sessions with just-in-time privileged access, hardened CI/CD to sign every artifact, and built a continuous evidence pipeline that produced audit-ready trail for every one of the SOC 2 Common Criteria.

The bank passed SOC 2 Type II with a clean opinion on the first attempt. Vulnerability mean-time-to-remediate dropped from 22 days to 4.

The Problem & Operational Risk

The bank ran on three cloud accounts (production, staging, corporate) plus GCP for two data science workloads, and a mix of Okta, three legacy LDAP directories, and per-app local logins for eleven SaaS tools. Roughly 240 employees had accounts.

AUERON's discovery phase found that 68 of them had at least one form of standing production access. Either an IAM user with a long-lived key, a saved kubectl context on a laptop, or a database read/write role granted "temporarily" more than three months prior. Six former employees still had at least one active production credential.

Audit logs existed but weren't correlatable. CloudTrail was on but only in the production account. Kubernetes audit logs weren't retained. The SIEM ingested about 20% of relevant sources. When AUERON asked "who touched the payments database in the last seven days," the answer took the team eleven hours to assemble from three consoles.

The bank's CI/CD had grown organically around GitHub Actions with self-hosted runners for the sensitive paths. Runners hadn't been patched in eleven months. Container images were signed only for one of six services. Third-party dependency scanning ran but findings routed to an email alias no one owned. The bank's own product security team was two people, and neither had ever driven a SOC 2.

Two enterprise partnerships were paused pending the attestation. The revenue exposure was material.

The single largest audit finding pre-engagement was standing production access. Eliminating it, not adding controls on top of it, was the difference between passing and failing.
SOC 2 Type II in Five Months for a Digital-First Bank: IAM Consolidation, Zero-Trust, and Continuous Evidence — architecture diagram
Reference architecture

Engineering Architecture & Solution

AUERON structured the engagement in four phases.

Phase one: identity consolidation. Every employee identity was moved to a single Okta tenant, provisioned via SCIM into every downstream system that supported it. The three legacy LDAP directories were decommissioned. Every one of the eleven SaaS tools was moved to SSO-only, per-app local logins disabled. Multi-factor was enforced platform-wide with WebAuthn required for high-sensitivity apps and TOTP allowed elsewhere. Six former-employee accounts were revoked early in the engagement.

Phase two: privileged access. Every standing production admin session was eliminated. Human access to production went through a just-in-time system: a request for a specific resource, a specific action, and a specific time window. Peer approval required for any action touching customer data. All PAM sessions recorded. Emergency break-glass credentials existed but sat in a physical safe and rotated on retrieval. AUERON's team modeled 68 realistic day-to-day operational tasks with the bank's engineering team, confirmed each could be completed through JIT within acceptable latency, and then flipped the standing access off.

Phase three: supply chain and pipeline. GitHub Actions self-hosted runners were replaced with ephemeral, per-job, isolated GitHub-hosted runners for standard workloads, and Actions-Runner-Controller in a dedicated Kubernetes namespace for the small remainder that needed persistent workspace. Every container image built by the pipeline was signed with cosign. Sigstore transparency log entries were required at deploy time via Kyverno policy. Unsigned images were rejected at the admission controller. Dependency scanning was moved to Snyk with findings routed to a triage queue owned by product engineering leads, with SLA tied to CVSS score.

Phase four: continuous evidence. This is the part most SOC 2 engagements underweight. AUERON built a small internal service, the "evidence collector," that pulled data on a schedule from AWS Config, Okta, GitHub, the SIEM, and the vulnerability scanner, and mapped each collected artifact to specific SOC 2 controls. The evidence was stored in an S3 bucket with Object Lock, hash-chained per day.

During the auditor's fieldwork, the requested evidence packs were produced in minutes instead of the days-per-request the bank's peers had described.

Key Architectural Takeaways

  • The single largest audit finding pre-engagement was standing production access. Eliminating it, not adding controls on top of it, was the difference between passing and failing.
  • Continuous evidence is worth the engineering. Auditors moved through fieldwork in nine days instead of the six weeks the bank had budgeted.
  • Just-in-time privileged access is not slower than standing access if the automation is right. Median JIT request-to-grant landed at 38 seconds after week two.
  • Kyverno at the Kubernetes admission controller eliminated an entire class of deploy-time risk. Unsigned or unscanned images literally cannot land in prod.
  • SOC 2 is a control-effectiveness test, not a documentation test. The evidence pipeline forced controls to actually function, not merely exist.

Let's talk

Book your free consultation with an AUERON engineer

One senior engineer will respond within one business day.

Senior engineer on the first call — never a sales rep
30-minute scoping, no obligation
Written follow-up with a rough plan and price band

Prefer email? hello@aueron.in

We reply within one business day. No sales sequences, no newsletters.