Enterprise Security Architecture for a Mid-Tier Bank
A mid-tier Australian bank engaged Zysla to define a target-state security architecture and multi-year roadmap ahead of a major core banking transformation programme.
The challenge
The bank was preparing to replace its core banking platform — a programme spanning five years and involving more than thirty technology vendors. Security had not been formally considered in the programme architecture, and the organisation lacked a documented target-state security architecture against which solution designs could be assessed. The board had also received regulatory feedback from APRA regarding the maturity of the bank's CPS 234 compliance posture.
Zysla's approach
Zysla was engaged to lead the security architecture workstream across the transformation programme. We began with a current-state assessment of the bank's security controls, architecture and governance arrangements, benchmarked against APRA CPS 234 and the bank's own risk appetite. From this foundation we developed a target-state security architecture covering identity and access, data security, network segmentation, third-party integration security and security operations. The architecture was translated into a prioritised three-year roadmap with clear investment cases for each initiative, designed for presentation to the board and APRA.
Outcomes
- Target-state security architecture adopted as the governing framework for the core banking programme
- Security architecture review process embedded across all thirty-plus vendor engagements
- Three-year security roadmap approved by the board with full investment commitment
- APRA CPS 234 gap closure plan accepted by the regulator at subsequent review
- Security Architecture as a Service engagement extended for ongoing programme support