#1 Global Leader in Digital Trust & Quantum-Safe Security.    Discover how Keyfactor makes it possible.

M&T Bank Achieves Full Certificate Visibility with Cloud-Based PKI

M&T Bank, a Fortune 500 American bank, adopted Keyfactor Command to gain centralized visibility and automation across a rapidly growing certificate environment. The platform enables the bank to scale securely, eliminate certificate blind spots, and support modern development practices without disrupting operations.

50%
reduction in self-signed certificates identified and eliminated
350,000+
active certificates managed enterprise-wide
10+
years of partnership with Keyfactor

M&T Bank relies on PKI and digital certificates to secure devices, applications, and workloads across its expanding digital footprint. As certificate volumes increased, manual processes and limited visibility made it difficult to track ownership, ensure compliance, and prevent outages.

With Keyfactor PKI as a Service, M&T Bank centralized certificate discovery, inventory, and lifecycle automation across internal and public certificate authorities. Today, the bank operates with full visibility, automated renewal workflows, and scalable processes that support security agility while maintaining compliance.

The Challenge

M&T Bank’s previous manual PKI environment struggled to stay on top of rapid growth in devices and certificates. Manual request, renewal, and revocation processes created operational bottlenecks and visibility gaps. Developers and system administrators often relied on self-signed or wildcard certificates, causing security and scalability issues.


As we developed certificate lifecycle management systems internally, we found out that it was much more efficient to do it in the cloud. When it was time to switch to cloud based PKI, we went with Keyfactor because of the ease of transition over to cloud hosted products.

Kevin Ha Lead Encryption Engineer
  • Scalability constraints

    Manual certificate processes could not keep pace with rapid growth in certificate usage.

  • Limited visibility and unexpected outages

    Unknown and untracked certificates caused service disruptions and increased operational risk.

  • Policy noncompliance

    Use of self-signed and wildcard certificates conflicted with internal security standards.

The Solution

Centralized Certificate Visibility and Automation

M&T Bank selected Keyfactor Command to provide enterprise-wide certificate discovery, inventory, and lifecycle automation. The platform integrates with Microsoft CAs, public certificate authorities, and network environments to deliver continuous visibility. APIs and self-service workflows enable developers and administrators to provision certificates quickly and securely.

We cannot manage what we cannot see, and Keyfactor gave us that visibility. Keyfactor has allowed us to scale massively and keep everything in view. Keyfactor is a critical component in our security infrastructure.

Joshua Nash Technology Manager and SVP, Security Engineering, M&T Bank

Keyfactor Command scaled alongside M&T Bank as certificate volume increased more than one hundredfold.

Business Impact

With Keyfactor Command, M&T Bank eliminated certificate blind spots and gained real-time insight into hundreds of thousands of certificates. Network discovery and inventory capabilities identified unknown certificates and reduced reliance on insecure self-signed credentials. Automated workflows streamlined certificate issuance and renewal, improving security outcomes while increasing developer efficiency.

The amount of expertise required to maintain an effective PKI system is a pretty big lift for most organizations, even large organizations.But with a third party vendor like Keyfactor, all of that expertise comes with the product.

Kevin Ha Lead Encryption Engineer
  • Enterprise-wide visibility

    Security teams can locate and manage any certificate within seconds.

  • Improved compliance and risk reduction

    Self-signed and noncompliant certificates were replaced with policy-approved alternatives.

  • Scalable security foundation

    M&T Bank scaled from 2,000 to 350,000 certificates without sacrificing performance or control.

Customer Details

Industry
Banking and Financial Services
Location
Buffalo, New York
# Employees
21,000+
Website
Products & Services Used
PKI as a Service
tracking pixel