Identity Security & Zero Trust in Mumbai · BFSI Tier-0
IAM topology review, PAM tightening and Zero Trust roadmap for Mumbai BFSI, fintech and listed-corporate identity estates — delivered from BKC.
How a Macksofy identity & zt engagement runs in Mumbai.
Macksofy delivers identity-security and Zero Trust engagements for Mumbai-headquartered banks, NBFCs, AMCs and listed corporates from our Bandra Kurla Complex base. The Mumbai BFSI identity estate has a distinctive shape: an on-prem Active Directory still authoritative for core-banking and treasury, Entra ID syncing a partial cloud footprint, two parallel PAM tools owned by separate teams (the bank IT team's CyberArk vs the treasury team's Delinea), and a long tail of shared service-accounts created during the last decade of CBS migrations. Every engagement begins by mapping that real-world identity surface — not the org chart's version of it.
Mumbai-headquartered private banks and PSUs face explicit identity-control evidence asks from RBI's CSITE Cell during the annual inspection cycle. RBI Master Direction on IT Governance, Risk, Controls and Assurance (November 2023) demands authentication evidence at the application-tier, JIT/JEA evidence for privileged sessions, and break-glass-with-dual-control evidence for tier-0 access. SEBI CSCRF Annexure-K duplicates the ask for broker-and-AMC subsidiaries, with the addition of OMS-to-exchange-gateway service-account hygiene. Macksofy's engagement output maps line-by-line to both circulars so the inspector's clarification-call ends in one round.
BloodHound + Azure AD attack-path enumeration is the technical heart of phase 1. On a typical Mumbai private bank the first enumeration surfaces five to nine kerberoastable service accounts inside the core-banking realm, a tier-0 ESC1/ESC4 certificate-template path from a junior-RM-class workstation, at least one over-privileged backup-service account with cross-realm DCSync rights, and a stale ADFS-server admin group with departed-employee accounts still membership-active. ROADrecon then enumerates the Azure AD side — the unintended Global Administrator promotion via dynamic-group rule, the AAD Connect server's SYSTEM-to-cloud-admin path, and the OAuth grants made by ex-employees that nobody has ever reviewed.
PAM rationalisation is rarely a clean tool-swap in Mumbai BFSI. The bank's CyberArk vault, deployed in 2014 for IT operations, sits in tension with the treasury team's Delinea instance, deployed in 2019 for SWIFT-edge access, and the recent HashiCorp Vault deployment by the cloud team for AWS secrets. Macksofy maps every privileged identity to the right vault, identifies the standing-privilege accounts that should never have been in a vault to begin with, and produces a phased consolidation plan that survives the bank's CAB calendar without breaking the SWIFT operator shift schedule.
Phishing-resistant MFA rollout — FIDO2 keys, smart-card or certificate-based — is the single highest-ROI tier-0 control. Macksofy's Mumbai engagements include a phased rollout playbook calibrated to the bank's three-shift treasury operation, the after-hours break-glass workflow at the Mahape DR site, and the contractor-access path through the BCP-secondary VPN. The plan accounts for the on-prem ADFS that some Mumbai banks still front-end to SaaS apps — phishing-resistant MFA must work consistently across the on-prem and Entra paths, not just at the cloud edge.
Service-account hygiene is the Mumbai BFSI control that most consistently fails inspector scrutiny. The typical estate has 300-900 service accounts, of which 30-50% are shared, 40-60% have passwords older than the inspector wants to see, and 5-15% have password-never-expires and domain-admin equivalence. Macksofy delivers a service-account inventory in week one, a tiered remediation plan in week two, and the actual rotation execution in weeks three through six — using LAPS for local-admin accounts, gMSAs for service accounts that support them, and managed-secrets in the appropriate vault for the rest.
The deliverable includes the board-level identity-risk dashboard that the bank's audit committee asks for at every quarterly cyber review: standing-privilege count over time, MFA coverage percentage by tier, JIT activation count by quarter, stale-account count, and the trend-line vs the previous quarter. This dashboard is the single most-asked-for artefact from RBI-inspected banks; the same data underpins the inspector's evidence-pack acceptance.
Mumbai engagement scheduling respects the bank's release-train and the regulator's inspection-window. Identity-control changes are sequenced for the calmest operational window — typically post-quarterly-close and pre-RBI-inspection — with a documented rollback per change. The senior consultant on the engagement is physically reachable at the bank's BKC, Lower Parel, Mahape or Andheri MIDC sites inside four hours including a monsoon-traffic buffer; remote sessions for the deep-technical phases happen from the Macksofy BKC office to keep latency to AAD APIs negligible.
Five phases. Mumbai timeline.
Every Macksofy identity & zt engagement in Mumbai runs through the same phased protocol — adapted to Mumbai-specific procurement, regulator and delivery realities.
- Authoritative-directory mapping across on-prem AD, Entra ID, ADFS and any third-party IdP federation
- Tier-0 / tier-1 / tier-2 classification of every human + service identity
- Shadow-IAM discovery via SaaS SSO logs + finance procurement data
- Privileged-account census — domain, cloud, app, DB, OT-bridge admins
- BloodHound enterprise edges + reachability graph
- ROADrecon Azure AD enumeration + dynamic-group rule analysis
- ADCS ESC1-ESC8 certificate-template path validation
- Service-account kerberoasting + DCSync rights enumeration
- Vault-by-vault privileged-account census across CyberArk, Delinea, HashiCorp
- Standing-privilege identification + JIT/JEA workflow design
- Break-glass dual-control + alerting workflow
- Service-account migration to LAPS / gMSA / managed-secrets
- NIST SP 800-207 + CISA ZTMM-aligned trust-boundary diagram
- Conditional Access policy design across Entra ID / Okta / Ping
- Phishing-resistant MFA rollout plan for the three-shift treasury
- Microsegmentation design for east-west traffic in the core-banking realm
- RBI MD-ITGRC + SEBI CSCRF clause-mapped evidence pack
- Board-level identity-risk dashboard with quarterly trend
- 12-month maturity plan + CAB-aware change windows
- Quarterly red-team identity validation (optional retainer)
Which Mumbai verticals we deliver Identity & ZT for.
Mumbai private banks
BKC / Fort / Lower Parel HQ banks — tier-0 isolation, treasury PAM, three-shift MFA rollout, RBI-inspection evidence.
Stock brokers & AMCs
BKC / Worli broker terminals + OMS service-account hygiene + SEBI CSCRF Annexure-K identity evidence.
Payment aggregators
BKC / Lower Parel PA-PG licensees — settlement-reconciliation service-account isolation + RBI PA-PG controls.
Life & general insurers
IRDAI 2023 identity controls + PAS authorisation matrix + claims-team JIT/JEA.
Listed corporates
Mumbai-listed manufacturing, IT-services and retail — Zero Trust roadmap for SOX-equivalent + audit-committee asks.
MMR mid-market
Thane / Navi Mumbai / Andheri MIDC mid-market — phased Zero Trust over 12 months without a NOC swap.
The Mumbai deliverable pack.
Every Mumbai identity & zt engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.
- Identity inventory + tiering memo with shadow-IAM appendix
- BloodHound + ROADrecon attack-path report with prioritised closure backlog
- PAM rationalisation plan across CyberArk / Delinea / HashiCorp
- Phishing-resistant MFA rollout playbook (three-shift-treasury-aware)
- RBI MD-ITGRC + SEBI CSCRF clause-mapped evidence pack
- Board-level identity-risk dashboard + quarterly trend template
- 12-month Zero Trust maturity roadmap with CAB-aware change windows
A Mumbai identity & zt case study.
Tier-0 isolation, PAM consolidation across IT + treasury vaults, phishing-resistant MFA rollout for 4,800 admins
Standing privilege count cut 78% in 60 days; six kerberoastable tier-0 service accounts eliminated; clean first-pass RBI CSITE Cell inspection; dual-vault rationalisation deferred 18 months without operational risk.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions Mumbai buyers ask before signing.
Other Macksofy engagements in Mumbai.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
