Skip to main content

A German IT Service Provider Enhances Compliance with Syteca Session Monitoring to Secure Privileged Access

Industry

IT Service provider

Location

Germany

About

Raiffeisen-IT GmbH, based in Germany, provides comprehensive IT services to several shareholder companies. Its service portfolio includes IT support for office applications, infrastructure and network operations, as well as managed services for operating systems, databases, and SAP Basis. Services are delivered centrally from the company’s locations in Kassel and Karlsruhe.

Customer’s requests:

  • Complete documentation of activities performed with elevated privileges
  • Fast detection and containment of potentially harmful actions
  • Support for forensic investigations and audit documentation
  • Early detection of suspicious or unauthorized access

The challenge

Three control-relevant domains were at the center of focus:

  • Access Management (AM) – particularly in AD and Azure AD
  • Change Management (CM) – for example, within SAP system landscapes
  • Network & Infrastructure (NI) – including core components used in service delivery

To ensure secure handling of privileged access – such as to the SAP database – a tool for comprehensive, audit-proof traceability had previously been missing. In a highly regulated environment, this represented a significant gap in terms of ISO-compliant security controls.

“With Syteca, we have full transparency over the activities of our administrators and external service providers. Especially in the SAP environment, this has been a real asset – not least with regard to audit requirements. The solution runs reliably, integrates well into our daily operations, and proved its value quickly. Techway supported us from the very beginning with hands-on expertise and practical guidance.”

Marc Golenko, Teamleiter SAP-Betrieb

Marc Golenko,
Teamleiter SAP-Betrieb

The results

With Syteca’s capabilities, Raiffeisen-IT GmbH was able to:

  • Close a critical gap in the implementation of Raiffeisen-IT GmbH’s internal control system (ICS)
  • Significantly enhanced ISO/IEC 27001:2022 compliance
  • Established a robust foundation for:
    • Transparency
    • Accountability
    • Auditability in managing privileged access
  • Provided flexibility to continuously evolve the control framework in line with regulatory requirements

See how Syteca enabled the customer’s success

Share: