For a network that helps the financial community securely exchange payment instructions representing the equivalent of the world's GDP every 3 days, security isn't just a concern, it's the number one priority. At Red Hat Summit 2026, Praveen Siddu, Senior Platform Architect at Swift, and Otmane Benali, Container Platform Product Owner at Swift, alongside Ryan Riley, Senior Solutions Architect at Red Hat, shared how they modernized container platform security. Their journey details how Swift, a financial cooperative connecting over 11,500 institutions in more than 200 countries, established zero-touch automation to manage security policies and vulnerabilities across hundreds of clusters.

Photograph of session presenters Otmane Benali (Container Platform Product Owner at Swift), Praveen Siddu (Senior Platform Architect at Swift), and Ryan Riley (Senior Solutions Architect at Red Hat) speaking on stage at Red Hat Summit 2026.

Figure 1. Otmane Benali, Container Platform Product Owner, and Praveen Siddu, Senior Platform Architect with Swift, alongside Ryan Riley, Senior Solutions Architect with Red Hat

Managing millions of container images across multiple data centers presents a massive tracking challenge. If even 1 image contains a critical vulnerability, finding where that risk lives across a sprawling hybrid cloud environment is a complex task. Doing so manually is impossible.

Balancing massive transaction volume with rigorous security

For Swift, downtime or a security breach carries global macroeconomic consequences. During the session, the team illuminated the sheer scale of their operational environment.

Every 3 days, the equivalent of the world’s GDP passes through the Swift network. That indicates the scale of the economies and supply chains that count on this transaction service, making availability and security our highest priorities.

Otmane Benali

Container Platform Product Owner, Swift

To protect this critical flow, the platform team deployed Red Hat Advanced Cluster Security for Kubernetes. This technology secures workloads across the entire software lifecycle, spanning the build, deployment, and runtime phases.

Reversing the architectural flow to eliminate network congestion

A common pitfall in enterprise security is building architectures where a central configuration management database (CMDB) must reach out and poll every individual cluster for vulnerability data. As Swift’s network grew, this pull-based method consumed excessive network bandwidth and introduced significant operational complexity.

To solve this, the engineering team designed a stateless central architecture that reversed the flow of information. The architecture consists of an agent running locally in each Red Hat OpenShift environment. This agent gathers container image data and sends it to a central object store.

A central scanning job then queries a single Red Hat Advanced Cluster Security central instance to match the images against known Common Vulnerabilities and Exposures entries. This centralized engine enriches the data with ownership mapping from Git and sends the clean, prioritized risk profile back to the CMDB.

By preparing the security data centrally and feeding it directly into the database, the team simplified the architecture so that it could remain resilient. If any cluster is deleted, the system heals automatically because the central state is easily rebuilt from code.

Automating regression testing for security policies

Upgrading security tools or modifying policies can sometimes introduce unexpected disruptions or false positives, which increases alert fatigue for application developers. To prevent this, the team instituted an automated regression testing pipeline.

Before promoting a new policy or a new version of Red Hat Advanced Cluster Security from development to testing and production, the platform team runs it in a sandbox environment. This sandbox contains test workloads that are designed to trigger specific policy violations.

The team verifies that the new version of Red Hat Advanced Cluster Security accurately flags the simulated violations. This regression check prevents security updates from disrupting standard developer workflows or creating unnecessary noise.

By combining daily automated scans of running images, including short-lived pods, with zero-touch certificate management via Argo CD and HashiCorp Vault, the cooperative has successfully minimized manual security tasks. Security teams only interject when a high-priority vulnerability is verified, allowing application developers to maintain velocity while preserving global trust.

Next steps

Ready to strengthen your container security and reduce operational noise? Choose the path that fits your organization's goals:

  • Read the technical details: Learn how to implement lifecycle security and policy guardrails by downloading the official Red Hat Advanced Cluster Security for Kubernetes datasheet.
  • Try the technology: Evaluate the platform in your own environment by registering for a 60-day self-service Red Hat Advanced Cluster Security for Kubernetes trial.

Product trial

Red Hat OpenShift Container Platform | Product Trial

A consistent hybrid cloud foundation for building and scaling containerized applications.

About the author

Debbie Margulies is a principal product marketing manager for Red Hat OpenShift and has been at Red Hat since 2019 through the acquisition of StackRox.

UI_Icon-Red_Hat-Close-A-Black-RGB

Browse by channel

automation icon

Automation

The latest on IT automation for tech, teams, and environments

AI icon

Artificial intelligence

Updates on the platforms that free customers to run AI workloads anywhere

open hybrid cloud icon

Open hybrid cloud

Explore how we build a more flexible future with hybrid cloud

security icon

Security

The latest on how we reduce risks across environments and technologies

edge icon

Edge computing

Updates on the platforms that simplify operations at the edge

Infrastructure icon

Infrastructure

The latest on the world’s leading enterprise Linux platform

application development icon

Applications

Inside our solutions to the toughest application challenges

Virtualization icon

Virtualization

The future of enterprise virtualization for your workloads on-premise or across clouds