DOWNLOAD Zero-Trust Case Study

alt

Thank you for filling out a form!

Now you can download your resource file.

Download

Mercury Financial Case Study: Implementing Zero Trust for FinTech Operations

Mercury Financial partnered with VerSprite to implement a Zero Trust security architecture, using risk-centric governance, risk, and compliance (GRC) practices and PASTA threat modeling to protect a hybrid workforce and connected partner network without slowing down the business.

Mercury Financial Case Study


About Mercury Financial

Mercury Financial is a fintech company focused on expanding financial inclusion by providing access to credit lines for hardworking Americans, offering more than $4.7 billion in available credit. When the company shifted to a hybrid workforce in Q1 2020, it needed to secure operations against a new set of risks introduced by remote employees and connected partners — without disrupting the consumer growth the business depended on.


The Challenge

Zero Trust security has become widely adopted across financial services because it removes the assumption of inherent trust between systems, networks, users, and applications. That shift mattered for Mercury Financial: as the fintech industry has grown, traditional perimeter-based defenses have become less effective against modern cyber threats, especially with a distributed workforce and third-party integrations expanding the attack surface.

Mercury Financial needed to move beyond a location-based idea of “perimeter” and toward an identity-based one — verifying every user, device, and connection continuously, rather than trusting anything already inside the network.


What Is Zero Trust?

Zero Trust — also known as Zero Trust Architecture (ZTA), Zero Trust Network Architecture, or Zero Trust Network Access (ZTNA) — is a security model built on the principle of “never trust, always verify.” Instead of assuming anything inside the network perimeter is safe, Zero Trust continuously authenticates and verifies every user, device, and connection before granting access.


VerSprite’s Approach: Risk-Centric GRC and PASTA Threat Modeling

VerSprite provided risk-centric governance, risk, and compliance (GRC) services to help Mercury Financial build a Zero Trust program grounded in actual business risk, not just technical controls. Using the PASTA threat modeling methodology, VerSprite’s team identified potential threats and vulnerabilities across Mercury Financial’s environment, then ran a risk assessment to prioritize mitigation efforts — so the company could focus resources on its most critical risks first, instead of treating every finding as equally urgent.


How Mercury Financial Achieved Zero Trust

To meet PCI DSS compliance requirements and close the gaps introduced by a hybrid workforce, Mercury Financial and VerSprite:

  • Shifted more security controls to the user level rather than relying solely on network perimeter defenses
  • Implemented micro-tunnels and fingerprinted critical application traffic
  • Integrated Zscaler and CrowdStrike to monitor and secure the network in real time
  • Deployed a granular policy engine to detect potential rogue connections or services
  • Used advanced alerting and detection to automatically stop intruders


The Results

By adopting a Zero Trust approach with VerSprite, Mercury Financial achieved:

  • Increased employee productivity across critical operational functions
  • Reduced potential attack surfaces
  • Materially reduced likelihood of lateral movement by adversaries
  • Standardized authentication and authorization models across applications and cloud services
  • Decreased mean time to detect (MTTD) across cybersecurity events
  • Better-aligned connected supplier risk with company risk thresholds


Why This Approach Matters for FinTech

This case study demonstrates the value of pairing a comprehensive cybersecurity governance program with a risk-centric approach and effective threat modeling methodologies like PASTA. By partnering with an experienced provider, fintech companies can identify and mitigate security risks while protecting sensitive data and maintaining customer trust — critical in an industry where compliance requirements and consumer trust are directly tied to business growth.


Frequently Asked Questions

What is Zero Trust security in fintech?
Zero Trust is a security model that eliminates inherent trust between systems, networks, users, and applications, instead requiring continuous verification. In fintech, this is especially important given regulatory compliance requirements and the sensitivity of financial data.

How does PASTA threat modeling support a Zero Trust implementation?
PASTA helps identify potential threats and vulnerabilities in a system and prioritize them by business risk. That allows organizations to focus Zero Trust implementation efforts, like access controls and micro-segmentation, on the areas with the highest actual risk rather than applying controls evenly across the board.

What are the general steps to implement Zero Trust security?
Zero Trust implementation typically follows five steps: identifying and classifying assets, creating micro-segmentation across the network, implementing access controls based on role and sensitivity, continuously monitoring for suspicious activity, and responding to and remediating incidents as they’re detected.

What are the main benefits of Zero Trust for financial services companies?
Zero Trust provides a stronger security posture against modern cyber threats, helps meet regulatory compliance requirements like PCI DSS, improves visibility into network activity, and increases resilience against emerging risks.


Ready to strengthen your organization’s security posture? Contact VerSprite to learn how a risk-centric Zero Trust approach and PASTA threat modeling can protect your business.

Subscribe for Our Updates

Subscribe for Our Updates

Please enter your email address and receive the latest updates.