ShieldBank replaced VPNs with a Zero Trust Architecture (ZTA):
- Device Trust: CrowdStrike verifies endpoint health before access.
- User Auth: Okta MFA + step-up auth for sensitive apps.
- Micro-Segmentation: Palo Alto firewalls enforce least-privilege access between departments.
- Web Security: Zscaler inspects all internet traffic (even SSL).
SIEM (Splunk) correlates logs → alerts SOC on anomalies. Phishing simulations train staff monthly. All sessions recorded for forensics. Architecture passed FDIC cybersecurity exam.