Resource Library
Case StudiesVisibilityIncident ResponseSegmentationSeptember 11, 2025

Why Leading Financial Institutions Trust ORDR

Texas-Based Financial Services Leader Chooses ORDR To Secure All Connected Assets

Leading financial services organization classifies all devices, baselines device behavior and significantly reduces time to respond to compromised devices using ORDR

Industry: Financial Services

Financial services Leader With 788 Branches Across 17 States Selects the ORDR AI Protect platform to secure all connected devices

A privately held financial services organization headquartered in The Woodlands, Texas, with more than 788 branches in 17 different states, had deployed a variety of connected devices ranging from video surveillance cameras, printers, PCs and ATM machines. The CISO for this organization was concerned that he did not have a real-time asset inventory, or visibility into what devices were actually connected to the network and what risks they brought. The CISO began the search for a cybersecurity platform that could champion his vision of visibility and security of all connected devices, but one that integrated with his existing security stack.

“My objective when entering the banking world 8.5 years ago was to make security more intelligent and efficient. A device as simple as a badge reader can be used to compromise an enterprise network. So the main thing we were trying to address was the security around a lot of these agentless devices. We started to search for an asset visibility and security platform that could help improve our security posture.”

— CISO

Not Just IoT, Securing All Connected Assets Everywhere

ORDR is the leading platform for exposure assessment and AI-powered segmentation. Within a few hours of deployment, using deep packet inspection, ORDR discovered every connected device including IT, IoT, IoMT, and OT, with granular context such as device type, manufacturer, serial number, operating system, location and more.

Within the ORDR Data Lake, the device context is enriched with network topology details and threat intelligence data such as known vulnerabilities, ICS-CERT advisories and more.

“Asset discovery is extremely important but understanding what risks are around those assets is critical. Not all assets should be treated the same. If you don’t have an individual profile for each asset, your system treats them the same. Our core payment system is not going to be treated the same as another system that doesn’t contain the same type of data, or the value data from a regulatory perspective. Understanding assets and their risks is how CSOs should approach security,” said the CISO.

ORDR also detects known and unknown threats. An integrated threat detection engine detects active threats, exploits and lateral movement such as attacker tools. In addition, ORDR’s Flow Genome uses advanced machine learning (ML) to map each device’s unique, customer-specific communications patterns, and baselines exactly how it should behave.

Unlike users, devices are deterministic, and have specific and predictable communications patterns. Baseline communications, for example, mapping how a video surveillance camera is behaving and what it is communicating to on the network, allows ORDR to surface anomalous behaviors such as devices communicating to command and control (C2) domains or moving laterally in the network. The baseline communications is also the foundation to implement Zero Trust policies for every device, allowing only “normal” communications and blocking everything else.

Challenges

• Distributed architecture with 788 branches in 17 states

• Lack of visibility into inventory of IT, IoT and OT assets on network

• Configuration Management Data Base (CMDB) not up to date

• Incomplete attack surface understanding for risk and security

“But the interesting thing as we dug into it a little bit more, and specifically looked at ORDR is that it is not just for IoT (Internet of Things) devices. It’s anything that is connected to your network, and that’s what I think makes ORDR special among peers. You do not realize how expansive your network is until you inventory every connected device.”

— CISO

ORDR Is Delivering Business Outcomes and Value

“We talked about a visibility and security platform that would integrate with our entire security stack. This intelligent system is what I kept going back to — we need efficiency and security,” said the CISO.

ORDR is designed to complement existing systems and existing infrastructure. In particular, this financial services leader wanted to accelerate Cisco ISE deployments using ORDR. ORDR maximizes Cisco ISE’s powerful authentication and authorization features, addresses challenges with profiling, and accelerates policy creation. In fact, ORDR has been able to reduce device profile-oriented tasks by more than half, reducing this financial services leader’s operational costs dramatically.

ORDR’s comprehensive platform is delivering many benefits for this financial services organization. In addition to discovery and classification of all connected devices, with these insights shared with Cisco ISE, the financial services leader also uses ORDR’s Flow Genome to monitor and inspect the communications flows of its connected devices, including ATM machines, to detect suspicious and malicious behaviors.

“I will say from the get-go that ORDR has done a fantastic job—from the onboarding process and getting the information we needed, to the regulatory side, where ORDR provides us with reporting for our regulators.”

— CISO

ORDR Results

• Comprehensive asset visibility — from laptops, workstations, and ATMs to video surveillance cameras

• Delivered IT and security operational efficiencies with critical device insights

• Measurable risk reduction through identification of devices with vulnerabilities and outdated operating systems

• Proactive monitoring of communications flows for anomalies

• Accelerated Cisco ISE segmentation to isolate at-risk systems

• Maintained compliance via regulatory reporting on assets and risks

Aligning to Financial Services Leader’s Focus on Customer Success

One of the key values for this financial services organization is its commitment to customers. This organization is a community bank built upon the needs of its customers, and these same principles are reflected in ORDR’s “customer first” philosophy.

“ORDR believes in customer success and has an executive devoted to customer success, which is very important. Three of my top vendors have great customer success teams, and I would go to bat for each of those vendors anytime I’m asked to. ORDR fits in that same mode of believing in customer success, which is essential when you get the product and decide how you are going to utilize it.

Is it going to become shelfware, or are you going to be one of those companies that uses the system to its full potential?” said the CISO.

“In terms of surprises along the way — there haven’t been any hiccups. You typically run into a lot of hiccups when you’re implementing certain solutions, but it’s been a successful journey so far, and we look forward to continued success,” continued the CISO. “ORDR is a tool that can help your institution evaluate your risk and set up your strategy. The world of IT is constantly changing. We are in an era of advanced threats in a dynamic environment, and you need ORDR as a critical part of your security stack.”

Frequently asked questions
How can financial institutions achieve real-time visibility across distributed branch networks?
ORDR enables automatic device discovery and inventory across hundreds of branch locations simultaneously, providing real-time visibility without manual intervention. This approach eliminates blind spots in distributed environments where traditional tools struggle to maintain current asset databases.
What is behavioral baselining and why does it matter for incident response?
Behavioral baselining establishes normal device activity patterns, allowing ORDR to automatically detect anomalies that indicate compromise or misconfiguration. When deviations occur, the system enables instant isolation and response, significantly reducing dwell time and breach impact.
Can network segmentation help meet financial regulatory compliance requirements?
Yes, ORDR's automated segmentation strategies are specifically designed to satisfy financial industry compliance frameworks by isolating critical assets and controlling lateral movement. The case study demonstrates how segmentation reduces regulatory audit scope and strengthens security posture simultaneously.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →