Case Study

Accelerating Onboarding and Enhancing Security for a Leading Card Issuer

Discover how Raidiam Connect transformed API security, reduced costs, and streamlined client onboarding for a leading card issuer.

Summary

Case Study Summary

One of Raidiam's clients, a level 1 PCI DSS-certified organisation, faced a series of challenges related to API Security, Client Onboarding and Regulatory Compliance. By implementing Raidiam Connect, they were able to:

  1. 1Meet regulatory obligations around client credential cycling (cf. PCI DSS clause 8.3.2)
  2. 2Enable clients to self-serve, both at point of onboarding and on an ongoing basis, eliminating all manual costs
  3. 3Update their security posture whilst making their API resources public.

The combination of these factors meant that the organisation had enhanced its security posture, improved the onboarding experience for its clients, and reduced operational overheads and time to value, addressing key commercial indicators.

The Challenge

Overcoming Security and Onboarding Roadblocks in a Highly Regulated Industry

The organisation in question operates in the card payment space, where PCI DSS applies, and certification by a QSA is a requirement. Version 4 of this standard, fully in force from March 2025, added a requirement necessitating the cycling of client credentials (i.e. those used for authentication by a service/server, as opposed to a user) at least annually, or at a frequency determined by the organisation's risk assessment.

The organisation has a wide range of API resources accessed by clients, but had not previously routinely cycled authentication credentials, and had no automatic facility for so doing. It was faced with the prospect of manually rotating several hundred credential pairs.

In addition to the above, access to the organisation's resources had been dependent on the client organisation having at least 2 site-to-site tunnels in place. This caused both operational overhead, and introduced brittleness to the system architecture.

Finally, whilst the organisation had a large number of clients, as all onboarding activity was manual, the timeframe to being (technically) ready to consume resources was often elongated, lasting weeks, and necessitating troubleshooting to diagnose problems emanating from the complex integration approach.

Raidiam enabled the client organisation to go live faster, achieving a 100% reduction in associated operational costs while significantly enhancing the organisation's security posture.

The Solution

Raidiam Connect & Modern Authorisation

The organisation implemented Raidiam Connect, alongside an updated Authorisation Server. This had the following impacts:

  1. 01Clients, both new and existing, were given access to a self-service, web UI from where they could manage their applications and client credentials. Some integrated this directly with their KMS, facilitating automatic credential cycling.
  2. 02API resources were made public, and protected with mutual transport level security. This removed the error-prone tunnel approach, hardened perimeter security, and sped up time-to-live for new clients.
  3. 03By moving to certificate-based, asymmetric security, the organisation was able to move away from shared credentials, asymmetrically encrypt cardholder data, and enforce non-repudiation for notification messages.

The combination of these factors meant that client organisations were able to get live quicker, eliminating manual operational costs, but with a manifest improvement to the organisation's security posture. This was confirmed in a series of Cyber Security Audits, and the company's PCI DSS assessment. The QSA service in question have used the innovative approach as a showcase of how to achieve compliance combined with other value adds.

0%Reduction in operational onboarding cost
0PCI DSS 4.0 fully in force, March 2025

Ready to Transform?

Are you facing similar challenges in API security, client onboarding, or regulatory compliance? Don't let outdated systems hold you back. Take the first step towards transforming your organisation's security and operational efficiency:

  1. 1
    Assess Your Current StateEvaluate your existing API security and client onboarding processes. Are they meeting PCI DSS 4.0 requirements?
  2. 2
    Explore Raidiam ConnectDiscover how our solution can address your specific challenges. Visit our website to learn more about Raidiam Connect's features and benefits.
  3. 3
    Request a DemoSee Raidiam Connect in action. Our team can demonstrate how it can be tailored to your organisation's needs.
  4. 4
    Consult with Our ExpertsSchedule a consultation to discuss your unique requirements and how Raidiam Connect can help you achieve compliance while improving operational efficiency.
  5. 5
    Start Your TransformationBegin your journey to enhanced security, streamlined onboarding, and regulatory compliance. Contact us today to get started.

Maintaining PCI DSS compliance shouldn't slow your business down. Raidiam Connect automates the management of digital certificates and trust, helping you reduce operational effort, strengthen security and stay compliant as your organisation evolves.

Request a Demo

Request a demo with our team of experts to discover how our solution can streamline onboarding, enhance security, and reduce operational costs.

Request a Demo
Build Once. Expand Everywhere.

Where will your ecosystem take you?

Whether you're a regulator building a national digital economy, an enterprise platformising across brands and clouds, or a bank that wants to stop rebuilding trust for every new use case, there's a next step.

See It in Action

See how one investment in Raidiam Connect covers your first use case, and the next hundred.

See the Proof

Explore how governments, regulators and enterprises are using Raidiam to deliver trusted digital ecosystems.

Have questions first?

Tell us about your ecosystem and we'll show you where Raidiam fits.