case study icon

Cyber security without third-party cloud infrastructure. How PREBYTES helped a bank retain control of its data

A bank serving more than 7 million users needed protection for its digital services with clear data processing arrangements and effective supplier oversight. Dedicated PREBYTES servers provided a segregated environment and clear responsibility for maintenance, without requiring the bank to build its own infrastructure.

PREBYTES case study cover showing server racks protected by a shield symbol, illustrating cybersecurity without reliance on external cloud services.

Deployment context

Client: commercial bank serving more than 7 million users
Scope: digital service protection, data governance and third-party risk management
Deployment model: dedicated servers used exclusively by the bank and maintained by PREBYTES
Outcome: documented data processing arrangements and clear responsibilities, without maintaining in-house servers

‍

What challenges did the client face, and why did they matter?

The bank was strengthening protection for its digital services and assessing providers on both effectiveness and service delivery. It examined data residency, administrative access and subcontractor involvement. These are also important considerations for outsourcing due diligence in UK banking under PRA SS2/21. Security, IT and compliance teams needed clear answers: where would data be processed, who could access it, and who was responsible for restoring the service? In the UK, oversight of these dependencies supports operational resilience: banks must be able to deliver important business services within their impact tolerances. Unclear responsibilities made it harder to approve the solution. Unresolved dependencies raised questions about data confidentiality, continuity of protection and coordination during an incident. The bank also wanted a managed service. Building server infrastructure and expanding its systems administration capabilities were outside the project scope. It needed oversight of the service while the provider maintained the infrastructure.

Key challenges

  • control over data residency, access and processing arrangements;
  • server resources dedicated exclusively to the bank;
  • no reliance on a third-party cloud provider for the service;
  • clear responsibilities for infrastructure maintenance and incident handling;
  • deploying protection without building infrastructure or expanding the bank’s teams.

What did we implement, and how did it work in practice?

At PREBYTES, we deployed the service in a dedicated infrastructure environment reserved exclusively for the bank. We segregated these resources from other clients’ environments and took responsibility for their day-to-day maintenance. This deployment combined our proprietary technology with dedicated infrastructure, without reliance on a third-party cloud provider. We documented the data flows from the bank’s systems to its dedicated environment, the processing location and the scope of data submitted for analysis. The bank could use this information in its risk assessment. For a UK bank, processing data within the EEA also provided a clear framework for international data transfers under UK data protection rules. We apply the principle of least privilege and role-based access control. We also provide a data processing agreement and define arrangements for control over data storage locations.

The bank retained oversight of the service arrangements while we handled day-to-day infrastructure operations. This reflects the UK principle that using a third-party provider does not transfer the bank’s regulatory accountability to that provider.

What were the outcomes, and what changed day to day?

The bank’s teams gained a clear view of the environment: they knew where data was processed, who administered the servers and how to raise issues. Service oversight was grounded in identified infrastructure and documented arrangements. The security team could review the scope of protection and incident handling. IT had a clear allocation of maintenance responsibilities, while compliance had a basis for assessing whether service delivery met the agreed data processing requirements. Data sovereignty had a practical meaning in this deployment: oversight of data location, access permissions and responsibility for the environment. The bank retained that control without taking on day-to-day server administration.

Outcomes following deployment

  • server resources dedicated exclusively to the bank;
  • a defined data processing location and agreed access controls;
  • service delivery without reliance on a third-party cloud provider;
  • documented infrastructure arrangements supporting risk assessment and supplier oversight;
  • a direct route for raising issues with the team responsible for the service;
  • server maintenance handled by PREBYTES, without expanding the bank’s infrastructure.

Have questions about this case study? Contact us.

See more deployments in this industry: Banking
Deployment in other industries
No items found
Close window
Get STARTED

Get all of the things today!

Free, no obligation consultation. You can either give us a call, or complete the form if you prefer email.

Via phone
Give us a call and ask, we won’t hassle.

+44 7915-525-434

Let us know how we can reach you

More about a privacy policy can be found here.
Thank you!

Your submission has been received! We will contact you shortly.
Close window
Oops! Something went wrong while submitting the form.
Not now, close window