# A use case for each way of working.

> Employees with a phone, with a computer, shared workstations, third-party vendors, banking, healthcare, public sector, B2B travel, and NIS2 suppliers.

URL: https://www.ironchip.com/en/use-cases

Use cases


Who accesses, from where, and what changes in each organization. These are the scenarios we see most often, with the concrete problem, how Ironchip solves it, and who it applies to.

## Four profiles, one platform.

01

### Employees with a mobile phone

Passwordless authentication from the smartphone

**1 tap** to approve each access, without typing codes

Mobile app · push + biometry + location

#### The problem

Employees access Office 365, VPN, or CRM from their phone daily. Phishing and SIM swapping intercept OTPs and SMS, and without location control, any remote access can be fraudulent.

#### How Ironchip solves it

- Push notification on access attempt, approved with device biometry.
- Safe zone verification before granting access.
- Provisioning, deprovisioning, and device management from a single console.

Sales Remote and hybrid Field technicians Executives Customer support

02

### Employees with a computer

Second factor on desktop, corporate or personal

**65%** of users reuse passwords

Desktop app · Windows, Linux, macOS

#### The problem

The workstation is the primary attack vector: reused passwords, Man-in-the-Middle attacks that steal session tokens, and remote work from IT-uncontrolled devices.

#### How Ironchip solves it

- The desktop app acts as a second factor, without a smartphone.
- Factors tied to device and location, impossible to spoof.
- Compatible with USB token and NFC card for privileged access.

IT and support Development and engineering Finance HR Remote work without corporate mobile

03

### Shared workstations

Individual identity in multi-user environments

**100%** adoption using existing cards

NFC / RFID card · USB token · OTP token

#### The problem

Multiple employees operate on the same terminal with the same account. The password is known by the entire shift, rotation increases IT costs, and no one can audit who performed each operation.

#### How Ironchip solves it

- The access badge they already carry serves as MFA: holding it near the reader is all it takes.
- Each session is linked to the person, even if the device is shared.
- Reusable tokens across users, no phones to buy.

Healthcare Industry and manufacturing Retail and point of sale Logistics Public sector

04

### Third-party vendor access

Third parties without apps or passwords

**60%** of breaches at large organizations start with third parties

Magic Link · temporary access · brokered privileged access

#### The problem

Consultancies, maintenance providers and partners access with temporary accounts that are never removed, from devices outside policy and with no record of what they do inside.

#### How Ironchip solves it

- Single-use link, no installation or passwords required.
- Least privilege: access only to assigned resources and only during the project.
- Instant revocation and immutable audit log of every session.

Maintenance Auditors Consultancies Partners and distributors Independent contractors

## Where access is a regulated risk.

05

### Banking and fintech

Digital channel fraud: money mule, SIM swapping and authorized push payment fraud

**0 steps** more for the end customer who operates from where they always do

Datasource SDK · Fraud Detection API

#### The problem

Fraud no longer needs to steal the password: it convinces the customer to authorize the transfer, duplicates their SIM to receive the SMS, or uses their account as a money mule. With valid credentials, the bank sees nothing unusual.

#### How Ironchip solves it

- Every login, account registration, transfer or account change is scored by location, device and behavior.
- In-session malware protection: overlays, RATs like AnyDesk, keyloggers and IBAN changes at the last second.
- Detection of VPN, virtual SIM, impossible travel and transfers during a call. [Real case: how Abanca stops money mules and SIM swaps from their app](https://www.ironchip.com/en/customers/abanca)

06

### Healthcare

National Health System Cybersecurity Strategy

**80%** of incidents are due to unauthorized access or lack of audit trail

Professional NFC card · safe zone per center

#### The problem

Clinical terminals shared between shifts, sessions that stay open and passwords on sticky notes. The new regulation not only requires protecting data: it requires proving who accessed what, when and from where.

#### How Ironchip solves it

- Access with professional NFC card, no phone on the plant floor.
- Individual audit trail for every access to medical records.
- Workstation location as a factor: outside the center, doesn't open.

07

### Public sector

ENS and ITDR compliance

**SIEM** each access, correlated with the rest of events

Passwordless on USB, NFC card, desktop and mobile

#### The problem

Citizen data and case files with limited resources and diverse device fleets. And in citizen services, industrialized fraud: money mules, vishing and synthetic identities.

#### How Ironchip solves it

- Passwordless on USB, NFC card, desktop and mobile, with HIGH level CCN.
- Detection of spoofed GPS, impossible travel and hotspots.
- Detection of money mules, authorized push payment fraud and synthetic identity registration. [Customer story: how Alcobendas City Council deployed a second factor compliant with ENS across its entire workforce](https://www.ironchip.com/en/customers/alcobendas)

08

### B2B travel

Fraud through impersonation on booking platforms

**API** integration on top of the booking platform

Fraud Detection API · contextual identity per booking

#### The problem

Attackers impersonate legitimate agencies to launch fake bookings on tour operators and B2B platforms, causing direct financial loss and reputational damage.

#### How Ironchip solves it

- Contextual identity in every booking: location, device and behavior.
- Blocking proxies, VPN and spoofed GPS before closing the transaction.
- API layer on top of the existing platform, without slowing operations.

09

### NIS2 suppliers

Supply chain in critical sectors

**NIS2**: Directive (EU) 2022/2555

Phishing-resistant MFA · access reports and audit trail

#### The problem

If your customer is energy, banking, transport, healthcare or water, NIS2 requires them to demand security from their vendors. Even if you're not regulated, the requirement reaches you by contract.

#### How Ironchip solves it

- Phishing-resistant MFA for all staff who touch the customer's systems.
- Access reports and audit trail ready for customer audit.
- Fast deployment on the existing IdP and directory.

## Tell us your scenario and we'll test it with your users.

A pilot with a group of users and one critical application, on your IdP and directory.

[Request a pilot](https://www.ironchip.com/en/talk-sales) [See customer stories](https://www.ironchip.com/en/#casos)
