Skip to content
Macksofy Technologies
Mumbai · Identity & ZT
CERT-In EmpanelledMumbai

Identity Security & Zero Trust in Mumbai · BFSI Tier-0

IAM topology review, PAM tightening and Zero Trust roadmap for Mumbai BFSI, fintech and listed-corporate identity estates — delivered from BKC.

01
0+
Mumbai BFSI identity engagements
02
0d
median tier-0 remediation window
03
0%
median standing-privilege reduction
04
0h
MMR onsite SLA (monsoon-aware)
Identity & ZT in Mumbai

How a Macksofy identity & zt engagement runs in Mumbai.

Macksofy delivers identity-security and Zero Trust engagements for Mumbai-headquartered banks, NBFCs, AMCs and listed corporates from our Bandra Kurla Complex base. The Mumbai BFSI identity estate has a distinctive shape: an on-prem Active Directory still authoritative for core-banking and treasury, Entra ID syncing a partial cloud footprint, two parallel PAM tools owned by separate teams (the bank IT team's CyberArk vs the treasury team's Delinea), and a long tail of shared service-accounts created during the last decade of CBS migrations. Every engagement begins by mapping that real-world identity surface — not the org chart's version of it.

Mumbai-headquartered private banks and PSUs face explicit identity-control evidence asks from RBI's CSITE Cell during the annual inspection cycle. RBI Master Direction on IT Governance, Risk, Controls and Assurance (November 2023) demands authentication evidence at the application-tier, JIT/JEA evidence for privileged sessions, and break-glass-with-dual-control evidence for tier-0 access. SEBI CSCRF Annexure-K duplicates the ask for broker-and-AMC subsidiaries, with the addition of OMS-to-exchange-gateway service-account hygiene. Macksofy's engagement output maps line-by-line to both circulars so the inspector's clarification-call ends in one round.

BloodHound + Azure AD attack-path enumeration is the technical heart of phase 1. On a typical Mumbai private bank the first enumeration surfaces five to nine kerberoastable service accounts inside the core-banking realm, a tier-0 ESC1/ESC4 certificate-template path from a junior-RM-class workstation, at least one over-privileged backup-service account with cross-realm DCSync rights, and a stale ADFS-server admin group with departed-employee accounts still membership-active. ROADrecon then enumerates the Azure AD side — the unintended Global Administrator promotion via dynamic-group rule, the AAD Connect server's SYSTEM-to-cloud-admin path, and the OAuth grants made by ex-employees that nobody has ever reviewed.

PAM rationalisation is rarely a clean tool-swap in Mumbai BFSI. The bank's CyberArk vault, deployed in 2014 for IT operations, sits in tension with the treasury team's Delinea instance, deployed in 2019 for SWIFT-edge access, and the recent HashiCorp Vault deployment by the cloud team for AWS secrets. Macksofy maps every privileged identity to the right vault, identifies the standing-privilege accounts that should never have been in a vault to begin with, and produces a phased consolidation plan that survives the bank's CAB calendar without breaking the SWIFT operator shift schedule.

Phishing-resistant MFA rollout — FIDO2 keys, smart-card or certificate-based — is the single highest-ROI tier-0 control. Macksofy's Mumbai engagements include a phased rollout playbook calibrated to the bank's three-shift treasury operation, the after-hours break-glass workflow at the Mahape DR site, and the contractor-access path through the BCP-secondary VPN. The plan accounts for the on-prem ADFS that some Mumbai banks still front-end to SaaS apps — phishing-resistant MFA must work consistently across the on-prem and Entra paths, not just at the cloud edge.

Service-account hygiene is the Mumbai BFSI control that most consistently fails inspector scrutiny. The typical estate has 300-900 service accounts, of which 30-50% are shared, 40-60% have passwords older than the inspector wants to see, and 5-15% have password-never-expires and domain-admin equivalence. Macksofy delivers a service-account inventory in week one, a tiered remediation plan in week two, and the actual rotation execution in weeks three through six — using LAPS for local-admin accounts, gMSAs for service accounts that support them, and managed-secrets in the appropriate vault for the rest.

The deliverable includes the board-level identity-risk dashboard that the bank's audit committee asks for at every quarterly cyber review: standing-privilege count over time, MFA coverage percentage by tier, JIT activation count by quarter, stale-account count, and the trend-line vs the previous quarter. This dashboard is the single most-asked-for artefact from RBI-inspected banks; the same data underpins the inspector's evidence-pack acceptance.

Mumbai engagement scheduling respects the bank's release-train and the regulator's inspection-window. Identity-control changes are sequenced for the calmest operational window — typically post-quarterly-close and pre-RBI-inspection — with a documented rollback per change. The senior consultant on the engagement is physically reachable at the bank's BKC, Lower Parel, Mahape or Andheri MIDC sites inside four hours including a monsoon-traffic buffer; remote sessions for the deep-technical phases happen from the Macksofy BKC office to keep latency to AAD APIs negligible.

Engagement workflow

Five phases. Mumbai timeline.

Every Macksofy identity & zt engagement in Mumbai runs through the same phased protocol — adapted to Mumbai-specific procurement, regulator and delivery realities.

01
Phase 01
Identity inventory
  • Authoritative-directory mapping across on-prem AD, Entra ID, ADFS and any third-party IdP federation
  • Tier-0 / tier-1 / tier-2 classification of every human + service identity
  • Shadow-IAM discovery via SaaS SSO logs + finance procurement data
  • Privileged-account census — domain, cloud, app, DB, OT-bridge admins
02
Phase 02
Attack-path enumeration
  • BloodHound enterprise edges + reachability graph
  • ROADrecon Azure AD enumeration + dynamic-group rule analysis
  • ADCS ESC1-ESC8 certificate-template path validation
  • Service-account kerberoasting + DCSync rights enumeration
03
Phase 03
PAM rationalisation
  • Vault-by-vault privileged-account census across CyberArk, Delinea, HashiCorp
  • Standing-privilege identification + JIT/JEA workflow design
  • Break-glass dual-control + alerting workflow
  • Service-account migration to LAPS / gMSA / managed-secrets
04
Phase 04
Zero Trust architecture
  • NIST SP 800-207 + CISA ZTMM-aligned trust-boundary diagram
  • Conditional Access policy design across Entra ID / Okta / Ping
  • Phishing-resistant MFA rollout plan for the three-shift treasury
  • Microsegmentation design for east-west traffic in the core-banking realm
05
Phase 05
Roadmap & evidence
  • RBI MD-ITGRC + SEBI CSCRF clause-mapped evidence pack
  • Board-level identity-risk dashboard with quarterly trend
  • 12-month maturity plan + CAB-aware change windows
  • Quarterly red-team identity validation (optional retainer)
Industries served

Which Mumbai verticals we deliver Identity & ZT for.

Mumbai private banks

BKC / Fort / Lower Parel HQ banks — tier-0 isolation, treasury PAM, three-shift MFA rollout, RBI-inspection evidence.

Stock brokers & AMCs

BKC / Worli broker terminals + OMS service-account hygiene + SEBI CSCRF Annexure-K identity evidence.

Payment aggregators

BKC / Lower Parel PA-PG licensees — settlement-reconciliation service-account isolation + RBI PA-PG controls.

Life & general insurers

IRDAI 2023 identity controls + PAS authorisation matrix + claims-team JIT/JEA.

Listed corporates

Mumbai-listed manufacturing, IT-services and retail — Zero Trust roadmap for SOX-equivalent + audit-committee asks.

MMR mid-market

Thane / Navi Mumbai / Andheri MIDC mid-market — phased Zero Trust over 12 months without a NOC swap.

What ships

The Mumbai deliverable pack.

Every Mumbai identity & zt engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.

  • Identity inventory + tiering memo with shadow-IAM appendix
  • BloodHound + ROADrecon attack-path report with prioritised closure backlog
  • PAM rationalisation plan across CyberArk / Delinea / HashiCorp
  • Phishing-resistant MFA rollout playbook (three-shift-treasury-aware)
  • RBI MD-ITGRC + SEBI CSCRF clause-mapped evidence pack
  • Board-level identity-risk dashboard + quarterly trend template
  • 12-month Zero Trust maturity roadmap with CAB-aware change windows
Recent Mumbai engagement

A Mumbai identity & zt case study.

Mumbai-headquartered private bank (BKC corporate tower)
Scope

Tier-0 isolation, PAM consolidation across IT + treasury vaults, phishing-resistant MFA rollout for 4,800 admins

Outcome

Standing privilege count cut 78% in 60 days; six kerberoastable tier-0 service accounts eliminated; clean first-pass RBI CSITE Cell inspection; dual-vault rationalisation deferred 18 months without operational risk.

What clients say · Trusted India + UAE

Rated 4.9 ★ from 612 client reviews.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
AK
Aisha Khan
Information Security Manager · Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
IK
Inspector K. Joshi
Cyber Cell · Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
VI
Vivek Iyer
DevSecOps Lead · Healthcare SaaS · Hyderabad
FAQ

Questions Mumbai buyers ask before signing.

Yes — bundling identity-security with the annual VAPT is common in Mumbai BFSI. The identity team's BloodHound + ROADrecon work feeds the pentest team's exploitation phase, and the deliverable is one binder that closes both RBI MD-ITGRC sections without a separate audit.
More services in Mumbai

Other Macksofy engagements in Mumbai.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements
Human verification· Cloudflare Turnstile

By submitting this form you agree to be contacted by Macksofy. We typically respond within a few business hours and never share your details. Protected by Cloudflare Turnstile and rate limiting.