Global Bank Strengthens Insider Risk Visibility Without Compromising Endpoint Performance

Industry

Financial Services

Company Size

60,000+ employees

Location

Global, U.S.-Based

Solution

The DTEX Platform

Key Results
  • Enterprise-scale deployment
  • AWS automation
  • Low endpoint overhead
  • Faster time to insight

A global financial institution with more than 60,000 employees serves millions of customers through its banking and lending businesses. As one of the largest banks in the United States by total assets, the organization manages highly sensitive financial and customer information across an extensive digital environment.

The bank holds every security technology to strict governance and performance standards. Any new solution must protect sensitive information without disrupting employees or limiting the organization’s broader technology strategy.


The bank reassessed its insider risk strategy after discovering that a privileged employee had accessed and stolen confidential information without detection for more than two years. Although the bank had a DLP solution in place, it lacked the behavioral context needed to recognize the activity.

Endpoint performance made the problem harder to solve. The existing DLP tool was a resource intensive enough that the bank could run scans only on weekends, yet those scans still failed to provide the intelligence needed to identify the breach.

The bank evaluated several UEBA products, but none met the full set of operational requirements. Some offered limited behavioral visibility. Others struggled to scale or created deployment challenges. The bank needed an approach that could support its AWS environment and aggressive patching strategy without affecting employee productivity.


Endpoint performance was non-negotiable. As part of a broader redesign of its endpoint strategy, the bank established a performance standard across its security stack: combined CPU use from all endpoint security tools could not exceed 4%.

The DTEX endpoint collector averaged 0.2% CPU use for a normal user during testing, placing it well within that threshold. The bank also confirmed that DTEX could operate alongside its existing software without relying on kernel extensions.

DTEX was then deployed across 70,000 Windows, macOS, Linux, and server endpoints. Its cloud-ready architecture supported automatic scaling within AWS and aligned with the bank’s patching and server rehydration requirements.

After evaluating several options, the bank selected DTEX for the behavioral visibility it could provide without compromising endpoint performance or the bank’s cloud operating model.


DTEX began collecting user activity metadata as soon as the endpoint collector was installed, without depending on outside data sources. Predefined behavioral indicators provided immediate alerting, while analytics established a baseline of normal user behavior within 10 days. The bank operationalized its initial use cases within weeks of deployment.

The security team now uses DTEX to monitor activity involving highly sensitive documents and investigate related behavior in one place. The bank also applies this visibility to potential IT sabotage and credential misuse, with particular attention to privileged users interacting with sensitive information.

DTEX gave the bank the behavioral visibility it had been missing while meeting its requirements for endpoint performance and cloud deployment. The team can now adapt its use cases as risks change without reworking its broader technology strategy.


  • Enterprise-scale deployment: DTEX extended behavioral visibility across 70,000 endpoints.
  • Low endpoint overhead: The collector averaged 0.2% CPU use for a normal user during testing.
  • AWS automation: Automatic scaling supported the bank’s cloud environment and operating model.
  • Faster time to insight: DTEX began collecting metadata after installation and established behavioral baselines within 10 days.
  • Privileged-user visibility: The security team gained context around activity involving sensitive documents, potential credential misuse, and IT sabotage.

Ready to Learn More?