How a leading European bank
secured its workforce
A leading European bank with more than 12,000 employees requires secure access to corporate systems and networks. The bank needed a strong authentication solution that could be deployed across a geographically spread workforce yet managed centrally.

The deployment in numbers
MyID issuing and managing strong authentication across a leading bank's workforce
Across financial services, a single compromised password can open the door to a data breach that costs a bank its money, its customers and its reputation. One leading European bank, with more than 12,000 employees spread across branches in multiple countries, faced exactly this risk. Its people needed secure access to corporate systems and networks every day, yet the bank ran a de-centralised structure that made a standard, one-size-fits-all authentication tool a poor fit. The IT team set out to move every employee and contractor onto strong two-factor authentication, mandated centrally but flexible enough to work with the bank's existing Microsoft certificate authorities, hardware security modules and in-house card printing.
This case study shows how MyID credential management software from Intercede met that challenge, issuing and managing the full lifecycle of PKI-based credentials at scale while giving the bank the control, and the room to grow, that it was looking for.
Two-factor authentication for every employee, without replacing what already worked
To reduce the risk of a data breach, the bank chose cryptographic authentication using public key infrastructure, which gave it the two-factor security it needed. Making that work was the harder part. The bank runs a de-centralised organisation, so any solution had to collate identity data from HR systems, LDAP and other sources rather than assume a single central model, and it had to fit the multiple Microsoft certificate authorities, hardware security modules and in-house card printing the bank already ran.
2FA mandated across all employees
The IT team needed a solution that would integrate with the bank's multiple Microsoft certificate authorities and hardware security modules.
In-house card production
The bank needed to print its own employee smart cards at its own facility.
Day-to-day usability for IT operators
A simple, intuitive solution that IT operators could use on a day-to-day basis.
Room to grow beyond smart cards
A vendor offering future scope to deploy across other end-user devices, including USB tokens, mobile devices and virtual smart card technology.
Central management, distributed workforce
Deployment across a geographically spread workforce, managed centrally.
One platform, configured around the bank's own structure
MyID offered the functionality and the technology integrations the IT team was looking for, and it was configured to fit the bank rather than the other way round. The MyID Lifecycle API collates the relevant identity data from HR systems, LDAP and other sources, and the bank's systems call it to trigger user and lifecycle events, whether that is a certificate renewal or a card revocation. MyID works with the certificate authorities, hardware security modules and card printing already in place, so none of that infrastructure had to be replaced.
The MyID Lifecycle API
the bank's systems call this API to trigger user and lifecycle events such as certificate renewals or card revocations.
In-house card production
with their own card production facility, the bank uses MyID to create and print employee smart cards, which are then mailed to the user at their branch location.
Identity data from every source
MyID collates the data it needs from HR systems, LDAP and other sources, so the bank's de-centralised structure did not have to change to accommodate the platform.
Auditable, centrally controlled system
for the bank to issue, replace, and revoke smart cards as and when required.
A measurable step-change in authentication assurance
The deployment delivered a centralised, audited identity solution aligned to the organisation's compliance, operational and user experience goals.
Enhanced security with best practice 2FA deployed across more than 12,000 employees and all branch locations.
Simplified deployment through configuring MyID’s Lifecycle API to fit into the bank’s de-centralised structure.
Improved control and reduced cost
MyID's integration flexibility allows for reduced costs by working with existing CA, HSM, and card printing infrastructure, while also providing improved control over credential issuance and management through a centralized software platform.
Future-proofed authentication security is assured as MyID continues to improve, ensuring the bank has multiple options on how its identity management solution evolves.
The platform behind the deployment
Intercede is a cybersecurity software company and the digital identity experts. For over 25 years, Intercede has helped government agencies, defence programmes, financial institutions and enterprises deploy phishing-resistant digital identities at scale.
The MyID product family, MyID CMS, MyID MFA and MyID PSM, manages millions of credentials across more than 20 countries. Vendor-neutral architecture means MyID integrates with virtually any certificate authority, hardware security module or smart card manufacturer, without organisations replacing existing infrastructure.