Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Encryption Consulting Success Story: How a Fortune 500 Retailer Built a Secure PKI Program

success-story
How We Helped a Leading Fortune 500 Retail Company Forge a Long-Term Partnership in Building a Secure Environment

A Fortune 500 retailer operating across multiple countries needed more than a vendor. They needed a team that could own PKI operations, absorb production incidents before they became global outages, upgrade an aging infrastructure to current compliance standards, and deploy a certificate management platform that gave every application owner visibility and control. Encryption Consulting delivered all four across two contract years. This is how the engagement unfolded and what the outcomes looked like in practice.

Quick Answer: What Does an Encryption Consulting PKI Engagement Deliver?

Encryption Consulting provides dedicated PKI monitoring, incident response, disaster recovery, version migration, and certificate lifecycle management through PKI-as-a-Service and CertSecure Manager. For a multinational Fortune 500 retailer, the outcome was complete elimination of unresolved global outages within the first contract year and a full PKI infrastructure upgrade in the second. The recommended first step for any enterprise evaluating this engagement model is a PKI health assessment to identify monitoring gaps, expiration risks, and architecture debt before they become operational incidents.

The Company’s Requirements

The company approached us to provide support for its Public Key Infrastructure (PKI) system. PKI is the framework of digital certificates, certificate authorities, registration authorities, and cryptographic policies that underpins authentication, encryption, and digital signing across an organization’s entire technology environment. They wanted Encryption Consulting’s team of experts to manage their PKI across multiple countries to ensure seamless operations. They required active monitoring, alerting, and disaster recovery capabilities to prevent global outages.

Why Multinational PKI Management Is Operationally Complex

PKI environments at Fortune 500 scale involve hundreds to thousands of certificates issued across different business units, geographies, and application teams. Root CA certificates and Certificate Revocation Lists (CRLs) each have their own expiration schedules that, if missed, cascade into authentication failures, TLS handshake errors, and in some cases full production outages affecting all systems that trust the issuing hierarchy. At the same time, certificate enrollment is frequently handled manually by individual application owners with no centralized enforcement of issuance policies, which creates inconsistency and risk across the estate.

The IBM Cost of a Data Breach Report 2024 found that the average cost of a data breach reached $4.88 million globally. Certificate-related outages, while not always security incidents, carry comparable operational cost in lost transactions, emergency response, and reputational damage when they affect customer-facing systems at scale. For a large multinational retailer, the business case for professional PKI management is not difficult to make.

Solutions Provided by Encryption Consulting

PKI-as-a-Service

We offered our PKI-as-a-Service solution and assigned a dedicated team to proactively monitor their infrastructure, ensuring smooth operations. In case of any incidents, a separate team was promptly deployed to handle the situation and restore operations as quickly as possible. During the first year of service, there were incidents resulting in global outages, all of which were resolved within an hour.

However, due to unforeseen circumstances, one incident took around 12 hours to resolve, and our experts provided the company with the utmost attention to ensure a swift resolution. By effectively addressing frequent operational outages, we significantly improved their global operations, leading them to renew their contract for the second year.

What PKI-as-a-Service Covered in This Engagement

FunctionWhat we deliveredOutcome
Proactive monitoring24/7 monitoring of CA certificates, CRL schedules, and certificate expiration timelines across all geographiesNo missed expiration events during the contract year
Incident responseDedicated incident team separate from the monitoring team, deployed on alertAll global outages resolved within one hour (one exception: 12 hours due to unforeseen circumstances)
Disaster recoveryDR plan designed and validated for the multinational PKI hierarchyRecovery capability documented and tested before any production event required it
AlertingCustomized alerts distributed to relevant stakeholders before certificate events occurredApplication owners and security teams notified with lead time sufficient to act

PKI Upgradation

After a successful partnership, the company requested additional services to establish a more secure and advanced PKI infrastructure.

The reasons for upgrading to the latest version of PKI were as follows:

  • Their existing version was reaching end-of-life.
  • They needed enhanced architecture.
  • They aimed to comply with all relevant regulations and compliance standards.

We facilitated a seamless migration to the latest version of PKI, enabling the company to build a new and robust PKI infrastructure.

PKI upgrades of this scale require careful sequencing: the existing trust hierarchy must remain operational for relying applications throughout the migration, the new Root CA and Intermediate CAs must be introduced with appropriate cross-certification or trust anchor distribution, and legacy components must be decommissioned only after all relying parties have transitioned. For a multinational environment, this sequencing must account for country-specific application dependencies that cannot be updated on a uniform schedule. For organizations evaluating whether their own PKI infrastructure requires upgrade, see our guide on six factors for PKI health and PKI Services.

Certificate Management Solution

Given the company’s substantial size, several challenges had to be addressed to establish a secure PKI environment, including:

  • Proactive monitoring of Root CA certificate and Certificate Revocation List (CRL) expirations.
  • Centralized management and monitoring of the PKI infrastructure.
  • Efficient enrollment of certificates for various application owners.
  • Automated certificate enrollment on devices.
  • Enforcement of issuance policies.
  • Customized alerts for certificate expirations to users and application owners.
  • Active monitoring of issuing CA certificate expirations.

To overcome these challenges, we collaborated closely with the company to implement our comprehensive certificate management solution as we continue to provide our second year of service of PKI-as-a-Service.

What CertSecure Manager Delivered in This Engagement

CertSecure Manager is Encryption Consulting’s certificate lifecycle management platform. In this engagement it addressed all seven of the operational gaps the company identified:

  • Root CA and CRL expiration monitoring: proactive tracking of every CA certificate and CRL in the hierarchy with advance alerting before expiration events.
  • Centralized PKI visibility: a single pane of glass across all issued certificates, replacing the fragmented spreadsheet and manual tracking approach.
  • Application owner enrollment: streamlined certificate request and issuance workflows for application owners across multiple countries without requiring manual security team involvement for each request.
  • Automated device enrollment: certificate deployment to devices via enrollment protocols, removing the manual installation steps that create certificate gaps.
  • Issuance policy enforcement: policy-driven controls ensuring certificates are only issued under approved conditions with the correct parameters.
  • Customized expiration alerts: expiration notifications sent directly to the application owner responsible for renewal, not just to a central security mailbox where alerts go unacted on.
  • Issuing CA expiration monitoring: active tracking of issuing CA certificate expirations separately from the end-entity certificates they sign, closing a common gap in enterprises that monitor only leaf certificates.

Enterprise Implications: What This Engagement Model Means for Your Organization

The pattern this engagement illustrates applies broadly to large enterprises managing PKI at scale. The challenges the company faced before engagement, undetected expirations, manual enrollment, end-of-life infrastructure, and distributed application ownership without centralized monitoring, are not specific to retail. They appear in financial services, healthcare, manufacturing, and any other sector operating a large certificate estate across multiple business units.

Three enterprise implications stand out from this case:

  • Monitoring and incident response require dedicated resourcing: the company’s ability to resolve global outages within one hour during the first contract year was a direct result of having a monitoring team and a separate incident response team. Internal security teams managing PKI alongside other responsibilities cannot sustain that response time during peak incident load.
  • Certificate management automation is not optional at scale: manual tracking of certificate expirations across hundreds of certificates and multiple application owners produces gaps. CertSecure Manager automated the workflows that consistently fail when handled manually.
  • PKI upgrades require planning before end-of-life pressure arrives: the company initiated its PKI upgrade after a successful year of managed operations, which meant the migration could be planned and sequenced properly. Organizations that wait until end-of-life is imminent often compress a multi-month migration into an inadequate window under compliance pressure.
  1. Conduct a PKI health assessment: inventory all CA certificates, CRL schedules, and issued certificates before any managed services engagement. The assessment defines the scope and identifies the highest-risk gaps.
  2. Map certificate ownership to application owners: determine who is responsible for renewing each certificate and whether they receive expiration alerts with sufficient lead time. This is the most common operational gap in large enterprises.
  3. Assess your PKI version against current vendor support timelines: if your PKI infrastructure is approaching end-of-life, begin architecture planning now rather than waiting for the deadline.
  4. Evaluate whether your monitoring function and incident response function are separated: combining them in a single team creates a resource conflict during production incidents that extends resolution time.
  5. Define your DR capability: document the recovery procedure for your PKI hierarchy and test it before a production event requires you to execute it under pressure.

Conclusion

This engagement demonstrates what a structured, long-term PKI partnership produces: outages resolved within one hour, a compliant infrastructure upgrade completed without disruption, and a certificate management platform that gave the organization operational visibility it did not have before. The contract renewal into a second year reflects the outcome of addressing all four requirements: monitoring, incident response, architecture upgrade, and lifecycle automation.

For organizations evaluating a similar engagement, the starting point is a PKI health assessment. For organizations already managing a large certificate estate and looking for lifecycle automation, see CertSecure Manager. For fully managed PKI operations across multiple geographies, see PKI-as-a-Service. For the broader PKI services portfolio including CP/CPS development and PKI design, see PKI Services.

Frequently Asked Questions

What PKI challenges do large multinational enterprises most commonly face?

Multinational enterprises most commonly face three PKI challenges: inconsistent certificate lifecycle management across different countries and business units, lack of centralized monitoring that allows CA certificate and CRL expirations to go undetected until they cause outages, and end-of-life PKI infrastructure that no longer receives vendor support or security patches. These challenges compound at enterprise scale because different application owners operate semi-independently, automated enrollment is absent, and no single team has full visibility across the entire certificate inventory.

What does PKI-as-a-Service include and how does it differ from self-managed PKI?

PKI-as-a-Service from Encryption Consulting includes dedicated proactive monitoring of the entire PKI hierarchy, incident response with a separate on-call team, disaster recovery planning and execution, and ongoing management of CA certificates, CRL schedules, and certificate issuance policies. It differs from self-managed PKI in that the monitoring, alerting, and response functions are staffed by specialists who are on call around the clock, rather than relying on internal security teams to detect and respond to issues alongside other responsibilities.

What is CertSecure Manager and what problems does it solve?

CertSecure Manager is Encryption Consulting’s certificate lifecycle management platform. It provides centralized visibility into all certificates across the PKI infrastructure, proactive expiration monitoring with customized alerts sent to application owners before certificates expire, automated certificate enrollment for devices and application workloads, enforcement of issuance policies, and active monitoring of issuing CA certificate expirations separately from the end-entity certificates they sign.

Why do enterprises upgrade their PKI infrastructure and what does the process involve?

Enterprises upgrade PKI infrastructure for three primary reasons: the existing version is reaching end-of-life and will no longer receive security patches or vendor support; the current architecture does not meet current compliance requirements; and the infrastructure cannot support new use cases such as automated certificate enrollment or short-lived certificate issuance. The upgrade process involves assessing the current PKI hierarchy design, planning the new architecture, migrating trust anchors without disrupting relying applications, and decommissioning legacy components.

How does Encryption Consulting support enterprises managing PKI across multiple countries?

Encryption Consulting manages multinational PKI environments through PKI-as-a-Service, which assigns a dedicated team responsible for proactive monitoring, alerting, incident response, and disaster recovery across all geographies. A separate incident response team is deployed when a production outage occurs, allowing faster resolution without pulling the monitoring function offline. Country-specific compliance requirements are mapped to the PKI configuration and certificate policies in each jurisdiction.

What are the most important certificate management controls for a Fortune 500 organization?

The most important certificate management controls for a large enterprise are: proactive Root CA and CRL expiration monitoring, centralized inventory of all issued certificates across all business units, automated enrollment to remove manual steps that cause certificate gaps, customized expiration alerts that go directly to the application owner responsible for renewal, enforced issuance policies, and active monitoring of issuing CA certificate expirations separately from the end-entity certificates they sign.