Customer Stories / Financial Services
Zeta Helps Banks Securely Deliver Digital Services at Scale with Zero-Trust Architecture on AWS
Learn how Zeta achieves banking compliance and reduces engineering efforts by implementing a zero-trust architecture on AWS and open-source security tools, along with Zeta’s proprietary tools.
92-94%
of customer compliance needs addressed
280
out of approximately 300 compliance controls fulfilled
45%
faster compliance
Shift-left security
Strengthens security with reduced effort
Overview
Zeta offers cloud-native, next-generation card issuing and transaction processing solutions for financial services providers. As the impact of cyber threats increases, Zeta wanted to develop a zero-trust architecture (ZTA) that aligned with banking compliance needs worldwide and could be easily adapted for the needs of individual banks.
By working with AWS, Zeta developed a ZTA that meets regulatory frameworks globally. This flexible solution has helped the company achieve compliance 45 percent faster, with its customers realizing value more quickly. Additionally, the ZTA’s elasticity helps banks securely deliver digital services at scale.
Opportunity | Tailoring Zero-Trust Architecture for Global Compliance and Ease of Integration
Zeta offers cloud-native, next-generation card issuing and processing solutions for financial institutions globally. Its platform helps banks build digital-first hyper-personalized card programs quickly and at scale, all while ensuring full regulatory compliance.
As banks face the growing impact of cyber threats, Zeta prioritizes the security of its platform by implementing a zero-trust architecture (ZTA) across identity, devices, networks, apps, and data. In a ZTA, no one—whether inside or outside the network—is granted trusted access by default. "Our zero-trust architecture ensures that security remains uncompromised, even as our platform scales," says Ramki Gaddipati, cofounder, APAC CEO, and global CTO at Zeta.
Zeta tailors its ZTA for each bank, depending on the customer’s specific security needs, regulatory environment, and IT infrastructure. To onboard customers as quickly as possible, the company wanted its ZTA to align with compliance frameworks worldwide straight out of the box, plus integrate easily with third-party technologies to make fine-tuning efficient. “Our objective was to deliver the security our customers needed while also helping them achieve value more quickly,” says Shashidhar Soppin, enterprise architect at Zeta.
Our zero-trust architecture on AWS approaches security ground-up from its fundamentals and provides deep defense without any bolted infrastructure or applications. By implementing rigorous identity verification and continuous monitoring, it not only fortifies defenses but also ensures compliance with the most stringent regulatory requirements, enhancing overall data security and resilience.”
Ramki Gaddipati
Cofounder, APAC CEO, and Global CTO at Zeta
Solution | Developing Zero-Trust Architectures on AWS for Enhanced Security and Compliance
To ensure global banking compliance, Zeta uses Amazon Web Services (AWS) to build and customize ZTAs for its customers. Each ZTA pillar is constructed using AWS services and then fine-tuned to meet specific customer requirements with Zeta’s proprietary security technology stack, variety of open-source tools, and customized plugins. "With the support of AWS, we've developed a solution that meets the security regulations for digital banking services worldwide," says Shashidhar Soppin.
A core component of the ZTA is AWS Security Hub, which automates security checks and centralizes security alerts, notifying Zeta of any vulnerabilities and threats to the platform’s security posture. The service continuously aggregates and prioritizes alerts for emerging threats or potential issues.
Meanwhile, Amazon GuardDuty is used within the ZTA to protect AWS accounts, workloads, and data with intelligent threat detection. The service combines machine learning and integrated threat intelligence from AWS and leading third parties for protection. Says Atma Ram, architect at Zeta, “This fully managed solution tells us which elements of the platform are at low, medium, or high risk and how to mitigate the threats.”
An essential component of Zeta's ZTA is AWS Identity and Access Management (IAM) and AWS IAM Identity Center, which the Zeta team uses to control access to AWS services and resources. Complementing this, Zeta’s homegrown Cipher tool adds an extra layer of security by enhancing data encryption and access controls, ensuring a robust and comprehensive zero-trust approach.
Throughout the development of its ZTA, Zeta worked closely with AWS security experts. The company also leveraged the AWS Well-Architected framework to ensure its cloud architecture aligned with AWS best practices and recommendations. Using the framework, the Zeta technology team can guarantee its designs are highly scalable, secure, and compliant.
With AWS supporting the security architecture, Zeta meets bank compliance requirements almost entirely out of the box. Using AWS Security Hub, 92–94 percent of customer compliance needs are addressed. Zeta has found that standard AWS security services fulfill 280 of approximately 300 compliance controls for its ZTA, and the technology team only needs to make minor adjustments to satisfy all the controls.
Says Gaddipati, “We achieve compliance 45 percent faster for our zero-trust architecture thanks to the comprehensiveness and flexibility of AWS services. Our innovative approach, incorporating shift-left security, allows us to enhance security with less effort.”
Outcome | Delivering Secure, Seamless Digital Banking Services
By using AWS, Zeta ensures banks can deliver their digital services strategies cost-effectively at scale, while meeting their specific security, regulatory, and infrastructure needs. The flexibility of the AWS-based ZTA also means that Zeta can make changes to platform security as threats and compliance regulations evolve.
Gaddipati comments, “Our zero-trust architecture on AWS approaches security ground-up from its fundamentals and provides deep defense without any bolted infrastructure or applications. By implementing rigorous identity verification and continuous monitoring, it not only fortifies defenses but also ensures compliance with the most stringent regulatory requirements, enhancing overall data security and resilience.”
Shashidhar Soppin adds, “Zero trust is more than just a model; it's a mindset. With AWS’s extensive security services and Zeta’s innovative strategies, our zero-trust architecture provides a strategic advantage, helping us continuously validate and protect resources against potential threats.”
Furthermore, customers gain protection without any impact on the scalable performance of the omni-channel platform. They can deliver industry-leading digital banking services that provide highly secure, seamless user experiences. “This approach is helping maintain the crucial trust between banks and consumers that supports development,” states Ram.
To further strengthen its platform’s security posture, Zeta has set out to adopt generative artificial intelligence (generative AI). Through advanced pattern recognition and anomaly detection, generative AI can help Zeta detect and respond to sophisticated cyber threats in real time. As part of its generative AI journey, Zeta is exploring Amazon Bedrock. “Amazon Bedrock and large language models are changing the face of cloud security,” says Shashidhar Soppin. “We’re about to start exploring how this can enhance our proactiveness in addressing threats.”
About Zeta
Zeta is a banking technology company that helps financial institutions launch extensible and compliant banking asset and liability products rapidly. Its cloud-native and fully API-enabled stack supports processing, issuing, lending, core banking, fraud, loyalty, digital banking apps, and many other capabilities. Zeta has 1700+ employees with over 70 percent in technology roles across the US, Middle East, and Asia. Globally, customers have issued 25M+ cards on Zeta’s platform.
AWS Services Used
AWS Security Hub
Use AWS Security Hub to automate security best practice checks, aggregate security alerts into a single place and format, and understand your overall security posture across all of your AWS accounts.
Amazon GuardDuty
Amazon GuardDuty combines ML and integrated threat intelligence from AWS and leading third parties to help protect your AWS accounts, workloads, and data from threats.
AWS Identity and Access Management
Use AWS Identity and Access Management (IAM) to manage and scale workload and workforce access securely supporting your agility and innovation in AWS.
AWS Well-Architected
AWS Well-Architected helps cloud architects build secure, high-performing, resilient, and efficient infrastructure for a variety of applications and workloads.
More Financial Services Customer Stories
Get Started
Organizations of all sizes across all industries are transforming their businesses and delivering on their missions every day using AWS. Contact our experts and start your own AWS journey today.