DOWNLOAD Zero-Trust Case Study
Mercury Financial Case Study: Implementing Zero Trust for FinTech Operations
Mercury Financial partnered with VerSprite to implement a Zero Trust security architecture, using risk-centric governance, risk, and compliance (GRC) practices and PASTA threat modeling to protect a hybrid workforce and connected partner network without slowing down the business.

About Mercury Financial
Mercury Financial is a fintech company focused on expanding financial inclusion by providing access to credit lines for hardworking Americans, offering more than $4.7 billion in available credit. When the company shifted to a hybrid workforce in Q1 2020, it needed to secure operations against a new set of risks introduced by remote employees and connected partners — without disrupting the consumer growth the business depended on.
The Challenge
Zero Trust security has become widely adopted across financial services because it removes the assumption of inherent trust between systems, networks, users, and applications. That shift mattered for Mercury Financial: as the fintech industry has grown, traditional perimeter-based defenses have become less effective against modern cyber threats, especially with a distributed workforce and third-party integrations expanding the attack surface.
Mercury Financial needed to move beyond a location-based idea of “perimeter” and toward an identity-based one — verifying every user, device, and connection continuously, rather than trusting anything already inside the network.
What Is Zero Trust?
Zero Trust — also known as Zero Trust Architecture (ZTA), Zero Trust Network Architecture, or Zero Trust Network Access (ZTNA) — is a security model built on the principle of “never trust, always verify.” Instead of assuming anything inside the network perimeter is safe, Zero Trust continuously authenticates and verifies every user, device, and connection before granting access.
VerSprite’s Approach: Risk-Centric GRC and PASTA Threat Modeling
VerSprite provided risk-centric governance, risk, and compliance (GRC) services to help Mercury Financial build a Zero Trust program grounded in actual business risk, not just technical controls. Using the PASTA threat modeling methodology, VerSprite’s team identified potential threats and vulnerabilities across Mercury Financial’s environment, then ran a risk assessment to prioritize mitigation efforts — so the company could focus resources on its most critical risks first, instead of treating every finding as equally urgent.
How Mercury Financial Achieved Zero Trust
To meet PCI DSS compliance requirements and close the gaps introduced by a hybrid workforce, Mercury Financial and VerSprite:
- Shifted more security controls to the user level rather than relying solely on network perimeter defenses
- Implemented micro-tunnels and fingerprinted critical application traffic
- Integrated Zscaler and CrowdStrike to monitor and secure the network in real time
- Deployed a granular policy engine to detect potential rogue connections or services
- Used advanced alerting and detection to automatically stop intruders
The Results
By adopting a Zero Trust approach with VerSprite, Mercury Financial achieved:
- Increased employee productivity across critical operational functions
- Reduced potential attack surfaces
- Materially reduced likelihood of lateral movement by adversaries
- Standardized authentication and authorization models across applications and cloud services
- Decreased mean time to detect (MTTD) across cybersecurity events
- Better-aligned connected supplier risk with company risk thresholds
Why This Approach Matters for FinTech
This case study demonstrates the value of pairing a comprehensive cybersecurity governance program with a risk-centric approach and effective threat modeling methodologies like PASTA. By partnering with an experienced provider, fintech companies can identify and mitigate security risks while protecting sensitive data and maintaining customer trust — critical in an industry where compliance requirements and consumer trust are directly tied to business growth.
Frequently Asked Questions
What is Zero Trust security in fintech?
Zero Trust is a security model that eliminates inherent trust between systems, networks, users, and applications, instead requiring continuous verification. In fintech, this is especially important given regulatory compliance requirements and the sensitivity of financial data.
How does PASTA threat modeling support a Zero Trust implementation?
PASTA helps identify potential threats and vulnerabilities in a system and prioritize them by business risk. That allows organizations to focus Zero Trust implementation efforts, like access controls and micro-segmentation, on the areas with the highest actual risk rather than applying controls evenly across the board.
What are the general steps to implement Zero Trust security?
Zero Trust implementation typically follows five steps: identifying and classifying assets, creating micro-segmentation across the network, implementing access controls based on role and sensitivity, continuously monitoring for suspicious activity, and responding to and remediating incidents as they’re detected.
What are the main benefits of Zero Trust for financial services companies?
Zero Trust provides a stronger security posture against modern cyber threats, helps meet regulatory compliance requirements like PCI DSS, improves visibility into network activity, and increases resilience against emerging risks.
Ready to strengthen your organization’s security posture? Contact VerSprite to learn how a risk-centric Zero Trust approach and PASTA threat modeling can protect your business.
Subscribe for Our Updates
Please enter your email address and receive the latest updates.