Streamlining User Access Reviews At South Atlantic Bank With the Finosec Platform

Case Study
South AtlanticBank

South Atlantic Bank, a community bank in Myrtle Beach, SC with an asset size of 1.5 Billion and 170 employees, was grappling with a critical challenge: keeping up with regular security, permission, and authority reviews across their extensive network of banking systems. One of these systems was Jack Henry Silverlake, a core processor with over 3,500 permission options, adding additional complexity to the already cumbersome task. Kimberly West, the Information Security Officer at the bank, identified that the team often had to settle for minimum-effort reviews due to time constraints. She cited the limited hours in a workday as a significant hurdle to performing in-depth reviews, emphasizing that this compromise made them susceptible to human error and raised concerns about their adherence to FFIEC’s August 2021 guidance on authentication and other regulatory requirements.

“I was only doing the bare minimum reviews because they are time-consuming and there’s not enough hours in the day, and I was doing more frequent reviews but concerned about missing a change.”

The Problem

  1. Time-Consuming Reviews: With 20+ high-risk systems, requiring regular scrutiny, along with the added complexity of the applications like the Jack Henry Silverlake 3,500+ permission options, the task was overwhelming.
  2. Risk of Human Error: The manual nature of these reviews and the complexity introduced by systems led to a high potential for mistakes.
  3. Compliance Concerns: Struggling to meet FFIEC’s authentication guidelines posed significant risks, including regulatory and legal repercussions.
  4. Cyber Insurance Risks: Inaccurate or incomplete reviews could jeopardize their cyber insurance coverage, and the ability to validate management of access to the principle of least privilege.

The Solution

South Atlantic Bank adopted Finosec’s user access reporting solution, a system designed to automate the intricate process of tracking user permissions across a multitude of systems, including the complex core processing system.

“Finosec is the answer. There is a way to reduce the time AND have 100% accuracy. With Finosec, it is possible, efficient, and effective!”

Kimberly West

ISO, South Atlantic Bank

Our Features

Simplified Reporting

Finosec’s focus on changes and privileged access streamlined the review process.

FFIEC Compliance

The solution was aligned with the FFIEC authentication guidelines, simplifying compliance maintenance.

Audit Preparedness

With Finosec, the bank could more effectively prepare for future exams or audits.

Finosec platform

The Results

Time Savings

Kimberly and her team experienced substantial time-saving benefits, allowing for more strategic work.

Enhanced Security

The risk of human error was drastically reduced thanks to automation.

Audit Confidence

Armed with detailed and precise reports, the bank felt more confident going into regulatory exams or internal audits.

Regulatory Compliance

The bank is now better poised to meet FFIEC guidelines, reducing its exposure to legal and regulatory action.

Insurance Benefit

The accurate and comprehensive user access reports facilitated accurate completion of cyber insurance questionnaires, reducing the risk of claim denial.

Conclusion

For South Atlantic Bank, investing in Finosec’s automated user access reporting solution has been a game-changer. It effectively addressed the challenges arising from time constraints and the complexity of systems like Silverlake while enhancing regulatory compliance and cyber insurance risk profiles. Through automation and strategic alignment with industry standards, the bank has substantially mitigated its risks and operational costs related to compliance and cybersecurity.
Talk To An Expert Now
Talk To An Expert Now 770.268.2765