Securing millions of daily digital interactions: How ICA centralized access across retail, banking and beyond
Logo Securing millions of daily digital interactions: How ICA centralized access across retail, banking and beyond

Securing millions of daily digital interactions: How ICA centralized access across retail, banking and beyond

ICA Gruppen is one of Sweden’s leading retail groups, operating across several interconnected business areas. Its nationwide grocery chain is the core of the business, complemented by Apotek Hjärtat (pharmacies), ICA Banken (financial services), ICA Försäkring (insurance) and ICA Fastigheter (real estate). Together, these businesses employ around 24,000 people and support millions of customers every day through both physical and digital services.

At this scale sits a complex digital landscape, where identity and access must work consistently across stores, warehouses, internal systems, customer-facing applications and APIs.

The Need for a Unified Access Platform

Store and warehouse depended on different applications with their own authentication and user management solutions. For employees working with multiple tools, this meant managing different credentials and access methods, while administrators faced a growing operational burden.

With a large number of users spread across many locations, access administration became cumbersome. Different applications relied on different approaches - some local, some centralized and not all of them worked consistently. This made it harder to maintain a uniform security posture and slowed down the rollout of new applications and integrations.

At the same time, ICA saw growing demand for stronger authentication, modern login experiences and a more consistent way to reuse identities across services. Rather than continuing to patch together individual solutions, ICA set out to centralize identity using open standards and shared infrastructure.

From a Few Applications to a Group-Wide Foundation

ICA’s journey with Curity began with a small number of internal applications. The initial goal was to centralize authentication, using open standards such as OAuth and OpenID Connect, and reduce operational overhead for both IT teams and end users.

As ICA later introduced an API management platform, Curity naturally became the security layer for APIs. This marked an important shift: once APIs were protected centrally, separating end-user authentication from API access control no longer made sense as the Curity Identity Server enabled both.

betalning-med-qr-kod-2

From there, adoption expanded organically. Now Curity sits at the center of ICA’s digital services. It protects both internal applications and customer-facing systems, as well as the APIs that connect them. This includes services used directly by customers in everyday interactions, such as self-checkout systems, handheld scanners, website and mobile app, alongside internal store and warehouse applications.

Smart Choices That Enabled Scale and Growth

Several early decisions beyond adherence to standards have proven to be long-term enablers for ICA.

Choosing a solution with a suitable commercial model allows ICA to support a broad and diverse user base, including employees, partners and customers, with traffic patterns that vary significantly around weekends and major holidays.

Having a clear and transparent pricing allows ICA to integrate new services without introducing cost uncertainty. It means ICA can support self-service API usage and onboard new consumers without procurement delays or budget discussions.

Another key decision lay in deployment flexibility. ICA evaluated running Curity in the cloud but chose to keep the production environment on-premises. With traffic coming from internal networks, public networks and many different API clients, stability and predictability were essential. At the same time, Curity’s ability to run in different environments allows ICA to experiment without lock-in.

Close collaboration with trusted partners has also been central. Ductus plays a key role in operating ICA’s identity platform, working closely with both ICA and Curity. This setup has helped ICA build deep internal knowledge while maintaining direct access to product expertise when exploring new use cases or improvements.

Looking Ahead

ICA continues to follow developments in identity and security with a pragmatic mindset. New authentication methods and evolving regulatory requirements are part of that picture and so is the increasing role of AI in digital services.

As ICA explores AI-driven capabilities across the organization, identity remains a key concern. Securing access to services, APIs and data becomes even more important when systems act with greater autonomy or operate across multiple domains.

While specific use cases are still evolving, the ICA team is certain that identity will play a central role in how AI-enabled services are secured over time, with Curity continuing to be part of that foundation.

Secure Access at National Scale

ICA’s journey shows how a standards-based identity and access platform can grow alongside a large, diverse organization. By starting small, making deliberate architectural choices and expanding gradually, ICA has built a unified identity and API security foundation that supports both current operations and future initiatives.

Curity is no longer a point solution within ICA but part of the group’s shared infrastructure, shaped over time through close collaboration.

Alexander Salwey

There’s not a single ICA service that doesn’t use Curity in one way or another.

Alexander Salwey - Manager, Security Operations

Read More Customer Stories

Ziklo (Volvofinans) Bank has evolved identity and access management across all digital services
Ziklo (Volvofinans) Bank has evolved identity and access management across all digital services

Ziklo (Volvofinans) Bank has evolved identity and access management across all digital services

Read Story
The Curity Identity Server allowed Dun & Bradstreet to unify their many different services and meet their unique requirements
The Curity Identity Server allowed Dun & Bradstreet to unify their many different services and meet their unique requirements

The Curity Identity Server allowed Dun & Bradstreet to unify their many different services and meet their unique requirements

Read Story
SproutLoud leveraged API integrations using the Curity Identity Server, allowing them to create a common identity platform
SproutLoud leveraged API integrations using the Curity Identity Server, allowing them to create a common identity platform

SproutLoud leveraged API integrations using the Curity Identity Server, allowing them to create a common identity platform

Read Story
Securing the Backbone of the Internet: How Arelion Built an Independent Identity Foundation
Securing the Backbone of the Internet: How Arelion Built an Independent Identity Foundation

Securing the Backbone of the Internet: How Arelion Built an Independent Identity Foundation

Read Story
Seamless and modern authentication for Scandic Hotels guests powered by the Curity Identity Server
Seamless and modern authentication for Scandic Hotels guests powered by the Curity Identity Server

Seamless and modern authentication for Scandic Hotels guests powered by the Curity Identity Server

Read Story
Santander strengthens API security across Nordic markets with the Curity Identity Server
Santander strengthens API security across Nordic markets with the Curity Identity Server

Santander strengthens API security across Nordic markets with the Curity Identity Server

Read Story
Poppulo achieves their API-first strategy with the Curity Identity Server
Poppulo achieves their API-first strategy with the Curity Identity Server

Poppulo achieves their API-first strategy with the Curity Identity Server

Read Story
PayEx established a secure and flexible IAM system allowing for easier customer integrations
PayEx established a secure and flexible IAM system allowing for easier customer integrations

PayEx established a secure and flexible IAM system allowing for easier customer integrations

Read Story
Nowcom improved login security with the Curity Identity Server
Nowcom improved login security with the Curity Identity Server

Nowcom improved login security with the Curity Identity Server

Read Story
Maersk Customs Services created ‘one truth’ for identity and data sharing with the Curity Identity Server
Maersk Customs Services created ‘one truth’ for identity and data sharing with the Curity Identity Server

Maersk Customs Services created ‘one truth’ for identity and data sharing with the Curity Identity Server

Read Story
Ikano Bank streamlined identity management in multiple countries with the Curity Identity Server
Ikano Bank streamlined identity management in multiple countries with the Curity Identity Server

Ikano Bank streamlined identity management in multiple countries with the Curity Identity Server

Read Story
If Insurance built a secure, scalable identity platform powering partners, customers and AI
If Insurance built a secure, scalable identity platform powering partners, customers and AI

If Insurance built a secure, scalable identity platform powering partners, customers and AI

Read Story
How Skandia Scaled Digital Banking with Curity
How Skandia Scaled Digital Banking with Curity

How Skandia Scaled Digital Banking with Curity

Read Story
How ATG moved to a microservice architecture with the Curity Identity Server
How ATG moved to a microservice architecture with the Curity Identity Server

How ATG moved to a microservice architecture with the Curity Identity Server

Read Story
HealthHero future-proofs its virtual healthcare services with the Curity Identity Server
HealthHero future-proofs its virtual healthcare services with the Curity Identity Server

HealthHero future-proofs its virtual healthcare services with the Curity Identity Server

Read Story
Entercard complies with banking regulations and secures its microservices with the Curity Identity Server
Entercard complies with banking regulations and secures its microservices with the Curity Identity Server

Entercard complies with banking regulations and secures its microservices with the Curity Identity Server

Read Story
E.ON’s seamless transition to modern identity management with the Curity Identity Server
E.ON’s seamless transition to modern identity management with the Curity Identity Server

E.ON’s seamless transition to modern identity management with the Curity Identity Server

Read Story
Curity helped dmTECH secure online sales and provide smooth login UX for dm-drogerie markt digital services
Curity helped dmTECH secure online sales and provide smooth login UX for dm-drogerie markt digital services

Curity helped dmTECH secure online sales and provide smooth login UX for dm-drogerie markt digital services

Read Story
Curity enabled easier ways of logging in, leading to an increased usage of Tele2 services
Curity enabled easier ways of logging in, leading to an increased usage of Tele2 services

Curity enabled easier ways of logging in, leading to an increased usage of Tele2 services

Read Story
Curity enabled PagerDuty to deploy in different regions and enhance service availability
Curity enabled PagerDuty to deploy in different regions and enhance service availability

Curity enabled PagerDuty to deploy in different regions and enhance service availability

Read Story
Bjorn Lunden unifies authentication and accelerates growth with Curity and Elastx
Bjorn Lunden unifies authentication and accelerates growth with Curity and Elastx

Bjorn Lunden unifies authentication and accelerates growth with Curity and Elastx

Read Story
Bankdata modernizes identity infrastructure with the Curity Identity Server
Bankdata modernizes identity infrastructure with the Curity Identity Server

Bankdata modernizes identity infrastructure with the Curity Identity Server

Read Story
Arion Banki now has a standards-based identity platform and robust Open Banking protection
Arion Banki now has a standards-based identity platform and robust Open Banking protection

Arion Banki now has a standards-based identity platform and robust Open Banking protection

Read Story

Next steps

Ready for the Next Generation of IAM?

Build secure, flexible identity solutions that keep pace with innovation. Start today.