Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Security at scale at Citi: what security teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Balancing innovation, risk management, and resilience in environments shaped by legacy systems, regulatory pressure, and interconnected operations is a central challenge for global institutions, according to Sprocket Security. The main lesson is that security at scale depends as much on communication, governance, and business alignment as it does on technical controls.

NHIMG editorial — based on content published by Sprocket Security: Ahead of the Breach conversation on security at scale with Citi’s Ryan Hays

By the numbers:

Questions worth separating out

Q: How should security teams govern database access at enterprise scale?

A: Security teams should treat database access as a lifecycle process, not a one-time permission grant.

Q: Why does security communication matter in large organisations?

A: Security communication matters because large organisations depend on many teams to interpret the same risk differently.

Q: What do teams get wrong about resilience in complex environments?

A: Teams often treat resilience as a backup and recovery problem, but identity failures can break recovery before infrastructure fails.

Practitioner guidance

  • Map identity policy drift across critical systems Inventory where access approvals, exception handling, and revocation rules differ across core platforms, cloud services, and third-party connections.
  • Assign lifecycle ownership for every identity class Make a named owner responsible for service accounts, API keys, certificates, tokens, and human privileged access.
  • Test recovery under identity stress Run scenarios that force rapid credential rotation, privilege removal, and exception rollback across multiple teams.

What's in the full article

Sprocket Security's full discussion covers the operational detail this post intentionally leaves for the source:

  • How Citi-style enterprise decision-making translates into security leadership practice at scale
  • The practical trade-offs between innovation, risk management, and regulatory responsibility in large financial environments
  • Why communication patterns and cross-team coordination shape outcomes as much as technical controls
  • What security leaders can apply from a global institution to smaller programmes without importing unnecessary complexity

👉 Read Sprocket Security's discussion of security leadership at global enterprise scale →

Security at scale at Citi: what security teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Security at scale is an identity governance problem before it is a tooling problem. In large enterprises, the difficulty is not knowing that least privilege matters. The difficulty is enforcing it across legacy systems, cloud services, and delegated teams that each interpret access differently. That creates policy fragmentation, which is where risk accumulates. Practitioners should treat access consistency as a board-level governance issue, not a local admin task.

A few things that frame the scale:

  • The 2024 ESG Report: Managing Non-Human Identities found that 72% of organisations have experienced or suspect a non-human identity breach.
  • Compromised NHI incidents averaged 2.7 separate attacks in the past 12 months for affected enterprises, according to the same report.

A question worth separating out:

Q: Who should own non-human identity lifecycle decisions?

A: The accountable owner should be the business and technical team that can explain the workload, the dependency, and the change impact. Security should define the guardrails and evidence requirements, but it should not be the only team making operational decisions about creation, rotation, or decommissioning.

👉 Read our full editorial: Security at scale: what large enterprises change about risk



   
ReplyQuote
Share: