Home Solutions Services About Us Discovery Contact Us

Strawinskylaan 411 1077XX,
Amsterdam, Netherlands

Wilhelmina van Pruisenweg 35,
2595 AN Den Haag

+31 6 11 10 62 26

[email protected]

picus

Success Story: tbi bank & Picus

tbi bank Transforms Its Cybersecurity Posture with Continuous Validation Through Picus and Netsmart

Estimated reading time: 4 minutes
 - 11 December 2025, Thursday

As one of the leading digital-first banks in the region, tbi bank set out to ensure that every layer of its security controls performs effectively against real-world threats. By implementing the Picus Security Platform together with Netsmart’s expertise, the bank shifted from periodic, assumption-based security testing to a continuous, data-driven validation model.

In this success story, Dobrin Dobrev (CISO, tbi bank), Evrim Özsoy (Director of Sales, Netsmart), and Dr. Süleyman Özarslan (Co-Founder, Picus Security) share their perspectives on the project.

tbi bank’s Approach to Technology and Security

Dobrin Dobrev, CISO, tbi bank

“As a digital-first bank, security isn’t a secondary layer, it’s a foundational part of our customer trust and brand promise. We see cybersecurity as a business enabler, not a barrier.”

tbi bank combines a strong in-house security team with strategic partnerships to extend its capabilities. Dobrev explains:

“Our hybrid model allows us to stay agile. Netsmart’s deep expertise complements our internal strengths and serves as an extension of our own team.”

 

Project Rationale: Moving from Assumptions to Evidence-Based Security

Even with significant investments in next-generation firewalls and EDR platforms, tbi bank needed definitive answers to a critical question:

“How effective are our controls against real-world threats today, not six months ago?”

Traditional penetration tests offered value but lacked continuity. The bank needed the ability to:

  • Continuously validate controls against emerging threats
  • Quantify the ROI of security investments with reliable data
  • Identify weaknesses proactively
  • Prioritize vulnerabilities based on actual exploitability, not just severity

This led to the decision to explore an automated, continuous validation solution.

Project Scope and Key Objectives

The initiative focused on deploying the Picus Security Platform to validate tbi bank’s core security capabilities. The main objectives included:

  1. Real-Time Visibility: Understanding the performance of security controls against thousands of threat samples
  2. Optimization of Controls: Testing NGFW and EDR rules using real-world infiltration and post-exploitation techniques
  3. Attack Surface Clarity: Mapping potential attacker paths through the environment using the Attack Path Validation module
  4. Measurement & Reporting: Establishing a clear baseline for security effectiveness and continuously tracking improvements for internal and regulatory reporting

Why Picus? Why Netsmart?

Technology Decision: What Set Picus Apart

  • Threat-Centric Approach: Testing against a vast library of real-world attack techniques
  • Actionable Mitigation: Immediate, vendor-specific mitigation content
  • Safe Automation: Running thousands of attack simulations safely in production
  • Continuous Improvement: Persistent validation cycles without operational disruption

Partner Decision: Why Netsmart Was the Right Fit

tbi bank chose Netsmart not just as a vendor, but as a long-term strategic partner. Dobrev highlights:

  • “They understood both the Picus platform and the complexities of our security stack.”
  • “Their team worked seamlessly with ours throughout the POC and deployment phases, and their continued support and guidance have been instrumental in our path to security excellence.”
  • “Their expertise in the banking sector’s regulatory landscape was invaluable.”

Business and Security Benefits

The project delivered measurable improvements across cost efficiency, performance, and overall security posture.

1. Price & ROI

  • Maximized effectiveness of existing security investments
  • Identified misconfigurations quickly and accurately
  • Reduced manual workload through automated validation

2. Operational Performance

  • Attack Path Validation enabled precise prioritization of critical weaknesses
  • EDR rules were fine-tuned to reduce false positives
  • SOC teams gained higher-fidelity alerts and clearer visibility

3. Technology & Cyber Resilience

  • Security became quantitative and data-driven
  • Continuous validation enabled proactive risk detection
  • The bank’s overall “Security Effectiveness Score” improved steadily

Enhancing Security to Its Full Potential

Evrim Özsoy, Director Of Sales, Netsmart

Our partnership with tbi bank brought a shared vision of proactive, validated security to life. By tuning the Picus platform to their environment and enhancing the performance of their existing controls, we helped deliver resilience that is measurable and continuously improving. At Netsmart, our goal is not just to make security work, but to make it work at its best and this project proved the impact of the right technology paired with the right partnership.

Security as a Validated Reality

Dr. Süleyman Özarslan, Co-Founder, Picus Security

In banking, security cannot simply be a statement; it must be a validated reality. tbi bank stands out by treating security as a strategic capability rather than a checkbox. With the Picus platform and Netsmart, tbi bank continuously tests its defenses against real-world attacks, identifies and remediates gaps, and turns cyber resilience into a measurable, continuously improving capability.

Post-Quantum Cryptography: A Strategic Roadmap for Cybersecurity

Thales

The rise of quantum computing introduces significant challenges to existing cryptographic systems.

More
In today’s post we’ll explain how to simulate Active Directory attacks using Splunk and various tools to improve an organization's security posture.

Simulation of Active Directory Attacks with Splunk

Splunk

In today’s post we’ll explain how to simulate Active Directory attacks using Splunk and various tools to improve an organization’s security posture.

More
In this blog post, we will cut through the confusion and explain the core differences between SIEM and SOAR, two essential security tools used to protect your organization.

SIEM vs. SOAR

Versus

In this blog post, we will cut through the confusion and explain the core differences between SIEM and SOAR, two essential security tools used to protect your organization.

More
In this blog post, we will explore how to strengthen the security of CyberArk by leveraging Hardware Security Modules (HSMs).

Integration of CyberArk with HSM

CyberArk

The privileged accounts of organizations play an important role in today’s cybersecurity ecosystem. Protecting these accounts and the critical resources they access has become crucial for organizations to manage, control, and audit all privileged account activities.

More