Modernizing PKI for the Post Quantum Era for a National Bank

Table of Contents

Consolidated PKI Management and PQC Readiness. Preparing a National Bank for the Post-Quantum Transition.

A large national bank operating across multiple European markets is a leading universal financial institution with a long history supporting international trade and secure financial services. As cryptographic threats evolved and post-quantum timelines accelerated, the bank identified that its legacy PKI, spread across disparate systems and manual processes, could no longer meet future security, compliance, and scalability needs. To remain resilient, the organization required a modern, unified certificate lifecycle approach to consolidate PKI operations, modernize legacy infrastructure, and improve cryptographic agility, while establishing a clear roadmap for Post-Quantum Cryptography (PQC) readiness by 2027 and full transition planning through 2030.

ISS Solution: PQC Ready ILM & Unified PKI

ISS deployed its Identity Lifecycle Management (ILM) platform in a cloud-native OpenShift environment, establishing a modern foundation for PKI consolidation and post-quantum transition.

ILM replaced spreadsheet-based certificate tracking with automated discovery, centralized inventory, and lifecycle management, while integrating seamlessly with the bank’s existing PKI environment. This approach allowed the institution to maintain operational continuity while preparing for migration toward hybrid and PQC-enabled certificate hierarchies.

By abstracting PKI complexity behind a vendor-agnostic lifecycle layer, ILM enabled the bank to standardize processes, reduce operational risk, and confidently plan its transition to post-quantum-ready cryptographic infrastructure.

Key Capabilities Delivered

  • Cryptographically agile PKI deployment, integrated with enterprise identity systems, HSMs, and SIEM platforms
  • Migration of legacy certificate data into a centralized, modern PKI management environment
  • Post-quantum readiness validation, demonstrating the ability to issue and manage PQ-resistant certificates
  • Performance and scalability testing to ensure long-term operational viability
  • Improved governance and control over cryptographic assets and compliance requirements

Results

  • Consolidated PKI operations under a single lifecycle management platform
  • Elimination of manual certificate tracking, reducing operational overhead and risk
  • Clear, actionable roadmap for PQC transition aligned with industry timelines
  • Increased cryptographic agility, enabling faster response to evolving security standards
  • Stronger compliance posture through centralized visibility and control

Popular Case Studies

Smart Cities & Infrastructure

A global electric vehicle manufacturer needed to support ISO 15118-compliant Plug & Charge across its growing network of vehicles, charge points, and service providers. As EV adoption accelerated, the company required a unified trust infrastructure that could authenticate vehicles, chargers, and mobility service providers automatically — eliminating user friction while maintaining cryptographic control and compliance with international standards.

Smart Cities & Infrastructure

Smart infrastructure operators face escalating risks as PLCs, SCADA systems, elevators, building management systems (BMS), and connected city services converge on digital networks. These assets are long-lived, safetycritical, and regulated under IEC 62443, SIL 3/4, and NIST SP 800-82. Challenges include legacy assets with expired credentials, PLC-driven elevators integrated into fire and BMS systems, and emergency phone lines converted to IP/VoIP, creating new attack surfaces. SCADA/DCS controllers managing power, water, and city services are also exposed to cyber and compliance risks, compounded by fragmented visibility across suppliers and infrastructure. To meet safety and regulatory demands, operators require a resilient, audit-ready trust foundation ensuring compliance and uptime.

Power, Energy & Utilities

A leading U.S. power utility needed to secure and modernize its digital trust infrastructure across IT and OT networks. With thousands of certificates, keys, and secrets spread across enterprise applications, SCADA devices, and mobile endpoints, the risk of outage, cyberattack, and compliance gaps was rising sharply. At the same time, the organization faced increasing regulatory pressure and had committed to a full digital transformation by 2030, requiring a more resilient, unified trust foundation.

Resource Library

Post-Quantum Cryptography Implementation Guide

Deep dive into post-quantum crypto deployment strategies for embedded systems

Post-Quantum Cryptography Implementation Guide

Deep dive into post-quantum crypto deployment strategies for embedded systems
Ready to Secure Your Trust Lifecycle?

Let's secure your entire trust lifecycle from the physical edge to the cloud, the sea, and beyond.