Zero-Trust Security Architecture for a German Financial Services Provider
Design and rollout of a zero-trust security architecture on EU-sovereign infrastructure - BSI C5-compliant, fully auditable, and without a single workload leaving European jurisdiction.
Challenge
The client operated a hybrid estate grown over a decade: flat networks, VPN-based access, and security tooling spread across three US vendors. Regulatory pressure (DORA, BaFin) demanded demonstrable data residency and a verifiable security model - but a "big bang" migration was ruled out by the board.
Approach
We introduced identity-centric access in stages: first a European IdP with phishing-resistant MFA for all administrative paths, then micro-segmentation of the core banking-adjacent workloads, and finally policy-as-code guardrails (OPA) in every deployment pipeline. All logging and SIEM workloads were moved to a BSI C5-certified EU cloud, with retention and encryption keys held exclusively by the client. Every step shipped with evidence: architecture decision records, audit-ready access reports, and automated compliance checks in CI.
Outcome
External audit passed without findings in the first attempt. Lateral-movement risk reduced to near zero through segmentation, privileged access now fully attributable to individuals, and 100% of security-relevant logs stored under EU jurisdiction. The internal team operates the platform independently after a structured handover.