PartnersTrust CenterInvestorsCareers

CAELION Insights

Customer Brief: Multinational Financial Services Group — Identity Execution Under DORA

A financial services group operating across four continents ran its privileged identity operations the way most large institutions do: governance decided in one system, execution scattered across scripts, tickets, and manual operators in several others. Under DORA scrutiny, that gap became untenable. Cube23 closed it — and cut recertification effort by more than half in the process.

The organization

The client is a multinational financial services group with operating entities on four continents, spanning banking, asset management, and insurance lines. Its identity estate is the accumulation of decades and acquisitions: on-premises Active Directory forests, Entra ID tenants, Exchange environments in transition, and a privileged access management platform vaulting credentials for critical systems. Regulatory obligations arrive from multiple supervisors, with the EU's Digital Operational Resilience Act setting the most demanding bar for demonstrable control over privileged access to critical ICT systems.

The challenge

Governance was not the problem. The group had a mature IGA program that decided who should have what access, and a PAM platform that vaulted the credentials. The problem sat between decision and done: the execution layer. Privileged operations — granting elevated roles, provisioning service accounts, modifying group memberships across AD and Entra, adjusting Exchange permissions, onboarding systems into PAM — were carried out through a patchwork of PowerShell scripts, service-desk tickets, and manual operator sessions.

The consequences compounded under regulatory attention. Execution was inconsistent across regions, so the same approved change could be implemented three different ways on three continents. Evidence was reconstructed after the fact: when auditors asked how a change was made, teams assembled screenshots, ticket histories, and script logs into a narrative. Standing privileged access accumulated because revocation was manual and nobody's ticket. And access recertification campaigns — the periodic proof that privileged rights remain justified — consumed weeks of coordinated effort per cycle, largely spent gathering data that should have existed already.

DORA's expectations around ICT access control and auditability turned these from hygiene issues into findings-in-waiting. The group needed privileged execution to be as governed as privileged decision-making already was.

The deployment

CAELION deployed Cube23 as the execution control plane for privileged identity operations across the group's AD, Entra ID, Exchange, and PAM estate. The operating model changed in three ways.

First, operations became protocol-bound. Each class of privileged operation was encoded as a defined protocol — a contract specifying the permitted scope, the required approvals, the exact sequence of actions across the connected systems, and the evidence to be captured. Operators and automated requests alike invoke the protocol; nobody free-hands a change in a console or runs an unversioned script against a domain controller.

Second, execution moved to just-in-time. Rather than operators holding standing administrative rights in case they are needed, Cube23 brokers scoped, time-boxed elevation at the moment a protocol executes, under zero-trust assumptions, and withdraws it when the operation completes. Standing privileged access stopped being the default posture and became the exception requiring justification.

Third, evidence became a by-product of execution rather than a reconstruction after it. Every protocol run produces its own audit record as it happens: who requested, who approved, what executed, on which objects, in which systems, with before-and-after state. The evidence exists because the work happened — not because someone assembled it later.

The results

The measurable movement came in the areas regulators and internal audit care about most.

DimensionBeforeAfter
Privileged execution methodScripts, tickets, manual operator sessionsProtocol-bound, just-in-time execution
Recertification effortWeeks of manual campaign work per cycleCut by more than half
Audit evidenceReconstructed after the factProduced as work happens
Standing privileged accessAccumulating, revocation manualSharply reduced
Audit preparationWeeksDays

Recertification effort fell by more than half, because reviewers now certify against live, evidence-backed records of what access exists and how it got there, rather than spreadsheets assembled by hand. Standing privileged access was sharply reduced as just-in-time elevation replaced permanently held rights. And audit preparation — previously a weeks-long exercise in evidence archaeology — now takes days, because the evidence for every privileged operation was captured at the moment of execution and is queryable on demand.

The less measurable result may matter as much: for the first time, the group's control owners can answer "how do privileged changes actually happen here?" with a single, consistent answer that holds on every continent.

Why it worked

The engagement succeeded because it targeted the layer everyone else skips. Governance tooling and PAM were left in place and made more valuable — Cube23 did not replace the decision layer or the vault, it gave them an execution layer worthy of them. Protocol-binding removed the variance that scripts and tickets inevitably produce across regions and shifts. Just-in-time execution attacked standing privilege at its source, the operational convenience that created it. And building evidence into execution, rather than around it, converted DORA compliance from a periodic project into a property of daily operations.

If your privileged operations still run on scripts and tickets while your regulators expect contracts and evidence, CAELION can walk your team through Cube23 against your own identity estate in a private briefing.

Client identity withheld by agreement. Figures anonymized and rounded from engagement reporting.

Related

Continue reading

Identity

The Identity Execution Gap: Governance Decided, Nobody Executed

April 28, 2026

Identity

Zero Standing Privilege: From Vault-and-Rotate to Just-in-Time Execution

April 14, 2026

Identity

Joiner-Mover-Leaver at Enterprise Scale: Why It Still Breaks, and What Fixes It

March 31, 2026