VinCSS: Decoding Tenacious Roadmap To Passwordless With Locker Password Manager

Learn more about how Locker - a product of CyStack - has helped VinCSS enjoy password management capabilities that are both secure and convenient, aiming to eliminate dependence on passwords in the future.

CyStack products used

0
CyStack

Công ty Cổ phần Dịch vụ An ninh mạng VinCSS

CyStack products used

0

Since January 2023, CyStack has implemented the Locker Password Manager for VinCSS Cybersecurity Service Joint Stock Company under Vingroup. This is a strategic step of VinCSS in the roadmap to reduce the dependence on passwords for its personnel. VinCSS R&D team soon collaborated with CyStack's team to integrate more passwordless authentication capabilities into Locker, thereby using Locker as an optimal solution to protect existing passwords and solve problems. solve some other problems on security and privacy of VinCSS. By April 2023, CyStack has successfully handed over the PoC to VinCSS.

VinCSS: Decoding Tenacious Roadmap To Passwordless With Locker Password Manager

Learn more about how Locker - a product of CyStack - has helped VinCSS enjoy password management capabilities that are both secure and convenient, aiming to eliminate dependence on passwords in the future.

Our client

VinCSS Joint Stock Company under VinGroup was established and operates mainly in the field of research - development, manufacturing products, and providing cyber security services. With a team of leading Vietnamese and international engineers and experts, VinCSS provides comprehensive, intelligent, and automated solutions to customers.

Like all other businesses in the world, ensuring network security is paramount to VinCSS. Possessing a professional internal security team and being a pioneering passwordless authentication solution provider in ASEAN, VinCSS's roadmap to reducing dependence on passwords also faces many difficulties.

  • Many applications do not yet have “passwordless login”: Many third-party applications currently do not support the “Passwordless login” solution. Hence, VinCSS continued to utilize passwords and alternative login methods until these providers incorporated the capability to log in without a password.
  • Difficulties in managing and sharing information: With a large number of employees, the need to manage online accounts, grant & delete permissions, and share information with employees continuously increased every day.

Solution

Until dependence on passwords can be eliminated, VinCSS needed a secure password management solution that provided speed and convenience while still ensuring absolute security.

To solve this problem for businesses and their customers, VinCSS's R&D team soon coordinated with CyStack to integrate passwordless authentication capabilities into Locker, thereby using Locker as an optimal solution to protect existing passwords and solve some other security issues of VinCSS.

Project implementation time: January 2023 - April 2023

Type: Complete On-premise deployment for VinCSS

Number of deployed personnel: 100+ users.

About Locker

Locker is a password and secret data manager developed by CyStack. Locker allows users to store, create, and manage passwords, secret notes on devices and services in the network environment. In addition, the application also helps users store confidential information, warn of data breaches, etc

Locker is built and designed based on two core values of privacy and transparency, ensuring maximum safety for users while still maintaining convenience in use. All essential features to protect users in the network environment are present in the Locker Password Manager application.

Learn more about Locker Password Manager: https://locker.io/

Result

  • Until April 2023, VinCSS has deployed Locker across the entire system of more than 100 employees in Vietnam.
  • Within 2 months, all employees acclimated to password management through Locker. This resulted in a notable decrease in tasks associated with passwords, including the need for password resets, modifications upon employee departure, and the seamless delegation of access to new personnel. Locker significantly expedited internal information sharing, fostering a more efficient workflow and contributing to the optimization of work processes at VinCSS.
  • Embarking on the "go passwordless" journey, starting January 2024, VinCSS collaborates with CyStack to implement the Locker password manager across the entire VinGroup corporation, encompassing over 30,000 employees. This initiative aims to cultivate a robust security culture across all levels of the organization, mitigate security risks, and enhance the convenience of remote work, thereby fortifying VinGroup's position for stronger development in the global market.

Target

By applying Locker to the organizational system, VinCSS aims to achieve long-term goals, including:

  • Enhance system security: Locker saves all passwords and secret notes in the Vault. VinCSS employees only need to log in to Locker (through FIDO2 security authentication technology researched by VinCSS and integrated into Locker) to access them. This helps set long and different passwords for each account, increasing security and minimizing risks if the password is stolen.
  • Manage passwords and documents: Locker helps VinCSS's management team manage all accounts from the secure Administration Panel, helping to change passwords and share accounts, important documents become easy and secure. Instead of writing it down on paper or spreading it by word of mouth like before, all information is shared directly in Locker, avoiding misplacement, loss, hacking, etc.
  • Build a new security culture: Security culture is quite popular in the US and some European countries, but it is not properly recognized in the Vietnamese market. The Locker application is a necessary tool for VinCSS to maintain its internal security culture in particular, and change the security mindset of customers in general.

Customer Services

Throughout the meticulous deployment phase, CyStack adeptly navigated a myriad of challenges arising from the stringent security policies that characterized the landscape. The complexity of these security measures necessitated careful consideration and innovative solutions. Before obtaining consent to proceed with on-premise deployment, CyStack engaged in comprehensive discussions, presenting a series of strategic proposals designed to address the intricacies of the security framework.

In addition to reducing the attack surface and risks from third-party technology obsolescence, Locker also promoted information exchange and sharing between internal personnel. Simultaneously, Locker effectively addressed the issue of decentralization of digital assets in the vast realm of cyberspace, striking a delicate balance between convenience and the assurance of safety and security for every system. The strategic deployment of Locker not only streamlined security protocols but also laid the foundation for a robust and interconnected digital environment within VinCSS.

The proposed solution involved the seamless installation and operation of Locker directly on VinCSS' servers. This tactical approach not only aligned with the company's security policies but also empowered businesses to take a proactive stance in overseeing and controlling their security measures. By anchoring Locker within VinCSS' infrastructure, a robust and tailored security environment was established, allowing for heightened vigilance against potential threats.

About CyStack

CyStack is a cybersecurity company based in Vietnam since 2017. We offer comprehensive solutions, including testing, security consulting, and managed services. With over 200 businesses and 20,000 users around the world, we are recognized as a trusted partner for organizations and a strong leading firm in cybersecurity research and development.

For more information, please visit: https://cystack.net/

Quotes

“Like all other businesses worldwide, we fully understand the importance of network security. However, reducing reliance on passwords poses a major hurdle for us.” – Mr. Do Ngoc Duy Trac, CEO of VinCSS.

“The Locker team has provided us with a highly comprehensive and meticulously planned deployment progress. We are greatly impressed by CyStack’s enthusiasm and professionalism throughout our partnership.” – Mr. Do Ngoc Duy Trac, CEO of VinCSS.

Other Case Studies

VietnamCredit: Shaping Business Success From Security Policy Development
Case study|
VietnamCredit: Shaping Business Success From Security Policy Development
VietnamCredit faced many challenges related to security policies, making it difficult to work with end customers. CyStack, along with the Security Policy Building solution, has helped VietnamCredit overcome obstacles and gain customer trust.
Vayana Weaves Success by Connecting a Network of 300.000+ Enterprises with Smart Contract Audit
Case study|
Vayana Weaves Success by Connecting a Network of 300.000+ Enterprises with Smart Contract Audit
With proactive security morale, Vayana has successfully built customers' trust, and maintained its position as one of the leading technology companies in the tech-stack metropolis India, thanks to Smart Contract Audit.
Petit Gateau: Proactive Shielding, Customer Trust Yielding
Case study|
Petit Gateau: Proactive Shielding, Customer Trust Yielding
Petit Gateau successfully protected the products of its partner Dai-ichi Life, a leading worldwide company in the insurance industry, thanks to the application of Penetration Testing performed by the CyStack experts team.