Home >> Latest News

How Leagsoft XCAD Took a Nuclear Design Institute from Compliance Anxiety to Security Confidence

Leagsoft
2026-07-07

The Customer: When National Security Is Your Day Job

This isn't your average enterprise. The institute designs third-generation nuclear power systems for China — the kind of work that lands on a national science and technology priority list. They hold the country's highest-level Class A design qualification. Mistakes here don't just cost money; they cost trust.

So when Beijing moved cybersecurity to the top of the strategic agenda, this team felt it first. They weren't looking for a vendor. They were looking for a partner who understood that "good enough" is a phrase that doesn't exist in their vocabulary.

The Squeeze: Three Laws, One Deadline, Zero Room for Error

Three regulatory hammers dropped in rapid succession. The Cybersecurity Law. The Data Security Law. The Personal Information Protection Law. Each one raised the bar. Then SASAC Document No. 79 landed with a hard 2027 deadline: central SOEs must complete full domestic IT substitution. No extensions, no exceptions.

Meanwhile, the Ministry of Public Security launched its "two highs and one weak" crackdown — high-risk vulnerabilities, high-risk ports, and weak passwords. Guess which one attackers exploit first? Weak passwords like "Ceshi@123" were still floating around the environment. In a nuclear design shop, that's not a policy gap. That's a liability that keeps the CISO awake at night.

The institute needed three things simultaneously — and they needed them yesterday:

· A domestic AD replacement that preserved every existing capability: authentication, SSO, resource scheduling.

· A security upgrade that eliminated weak passwords and closed the gaps attackers love.

· Zero business disruption to operations supporting national nuclear programs.

Most vendors offered two out of three. Leagsoft XCAD was built for exactly this trifecta.

Pillar 1: Weak Passwords Were the Unlocked Back Door. XCAD Slammed It Shut.

The institute knew the stats. Weak passwords are the entry point in over 80% of successful breaches. They had policies on paper, but paper doesn't stop "Ceshi@123" from working. XCAD replaced the honor system with enforcement that actually sticks.

Layer 1: Strong Password Policies That Mean Business

XCAD ships with a built-in weak password library — the kind of dictionary that knows "Password123" isn't clever. But it doesn't stop there. Enterprises can layer their own rules on top:

· Minimum 8 characters — but the system nudges users toward 12+

· Complexity requirements: uppercase, lowercase, numbers, special characters

· Custom rule sets for departments with higher security clearance

The result? "Qwer#@!9587" passes. "Ceshi@123" gets rejected at the source — not flagged in an audit three months after a breach. This is prevention, not archaeology.

Layer 2: Passwords That Rotate Before They Rot

Static passwords are ticking time bombs. XCAD's policy engine automates the lifecycle:

· Expiration windows — configurable by role, department, or clearance level

· History checks — can't recycle the last 12 passwords, not just the last one

· Proactive reminders — 14 days, 7 days, 1 day before expiration, not a single surprise lockout

The message to users is clear: your password has a shelf life, and the system watches the clock so you don't have to.

Layer 3: When Something Looks Fishy, the System Screams

Every password change, account toggle, and permission tweak is logged. But logging alone is just a diary. XCAD adds real-time anomaly detection:

· Repeated failed logins in a 5-minute window → instant alert

· Off-hours access attempts from new locations → flagged for review

· Privilege escalations outside normal change windows → blocked pending approval

Security admins don't dig through logs hoping to find a needle. The system hands them the needle — with a timestamp, IP address, and recommended action.

Pillar 2: One Identity. Every System. Zero Chaos.

Before XCAD, the institute ran a patchwork of identity systems. Microsoft AD for Windows. Something else for Linux. A third thing for cloud desktops. Users juggled passwords like a circus act. IT spent more time resetting forgotten credentials than improving security. XCAD consolidated the mess into a single command center.

Sync Once, Propagate Everywhere

XCAD connects bidirectionally to existing Microsoft AD and LDAP systems. Full sync for initial load. Incremental sync for ongoing changes — scheduled or triggered on-demand. When a new engineer joins the nuclear program, HR creates one account. XCAD pushes it to every system that needs to know: email, VPN, file shares, cloud apps, badge readers. No duplicate data entry. No stale accounts lingering in forgotten systems. No "oh, we missed that one" discovered during an audit.

The Authentication Gateway That Speaks Every Protocol

The institute runs a mix of legacy and modern systems. XCAD doesn't force them to choose. A virtual LDAP proxy service creates a unified identity gateway — internal systems, third-party apps, even decades-old tools connect via standard LDAP without redevelopment. A virtual RADIUS proxy extends the same identity to VPN concentrators, wireless access points, and cloud desktops.

Users experience one login. One password. One set of credentials that works everywhere they're authorized to be. The "one app, one password" madness ends here.

From First Day to Last Day — and Every Day In Between

Account lifecycle management happens in one console, not across a dozen tools:

· Onboarding: One creation, automatic propagation, welcome email with temp credentials

· Job changes: Role-based access updates, old permissions auto-revoked, new ones auto-granted

· Suspension: Instant disable across all systems — no orphaned active accounts

· Offboarding: Full deactivation with audit trail for compliance retention

Least-privilege enforcement is automatic. Users get exactly what they need for their role — not a permission more. When roles change, access changes with them. No privilege creep, no surprise audits.

Pillar 3: The Migration Users Didn't Even Notice

The institute's biggest fear wasn't the technology. It was the transition. Nuclear design work doesn't pause for IT projects. A migration that breaks authentication midway through a critical review isn't an inconvenience — it's a national program delay. XCAD was built specifically to eliminate that risk.

Same Login Screen. Same Password. Same Habits.

XCAD syncs the organizational structure from Microsoft AD, then gradually assumes control of endpoints — Windows, UOS, Kylin, Linux. Users never see a different login prompt. They never install a new client. They never rejoin a domain. They never reset a password they didn't choose. The system they trust keeps looking exactly like the system they trusted.

Behind the scenes, XCAD takes over. In front of the screen, users keep working. That's not just smooth — that's invisible.

One Policy. Every Endpoint. No Exceptions.

Group policy management pushes security configurations from a single console to every endpoint in the fleet — regardless of operating system:

· Weak password enforcement — same rules, same rejection, same guidance across Windows and domestic OS

· High-risk port closure — automated scanning and remediation

· Screen lock and idle timeout — uniform enforcement, no manual exceptions

· Vulnerability patching — real-time detection, automated hardening

The system monitors compliance continuously. A non-compliant endpoint doesn't just get flagged — it gets fixed. Automatically. Before it becomes the entry point that takes down the network.

No One Person Holds All the Keys

XCAD enforces three-way separation of duties — not as a checkbox, but as an architectural principle:

· Security administrators write and approve policies. They can't touch operational systems.

· System administrators manage infrastructure. They can't change security policies.

· Audit administrators review every action. They can't modify policies or systems.

Every action is logged with who, what, when, and from where. When an auditor asks "show me who granted that privilege," the answer takes seconds, not days. When an incident occurs, traceability is instant. When compliance is tested, the paper trail is already complete.

The Result: From Three Problems to One Platform

XCAD didn't just replace Microsoft AD at the institute. It redefined how they think about identity, security, and compliance. The transformation shows up across three dimensions:

Endpoint Level: Finally, One Fleet That Actually Behaves Like One Fleet

Windows, UOS, Kylin, and Linux endpoints all report to the same console. The same password policy. The same port rules. The same vulnerability baseline. The same screen lock. The same audit trail. The excuse "oh, domestic terminals can't be managed" is gone. The problem of "new and old systems out of sync" is history. One standard. One enforcement. One view of the entire fleet.

Application Level: One Password to Rule Them All

The unified authentication gateway killed password sprawl. Users stopped writing credentials on sticky notes. IT stopped fielding "I forgot my password" tickets for the fifth app this week. The attack surface shrank because there were fewer credentials to steal, fewer accounts to compromise, fewer 3 AM pages for the security team. When every system trusts the same identity source, security becomes simpler — and simplicity is a security feature.

Compliance Level: From Checking Boxes to Building Muscle

The institute now satisfies the Cybersecurity Law, the Data Security Law, and SASAC's domestic IT substitution requirements — not as a one-time project, but as a continuous operating state. Weak password governance and operational audit logging directly address the Ministry of Public Security's "two highs and one weak" campaign. But compliance is just the floor. The real win is the shift from passive box-checking to active defense — detecting threats before they become incidents, containing risks before they become breaches.

The Bottom Line

Leagsoft XCAD didn't just help the institute retire an old system. It gave them something better: identity authentication they can trust, endpoint management that scales, and business operations that stay resilient even when regulators raise the bar again. And they will.

For an organization entrusted with China's nuclear future, that's not an upgrade. That's the difference between hoping you're secure and knowing you are.


Latest News

  • How Leagsoft XCAD Took a Nuclear Design Institute from Compliance Anxiety to Security Confidence

    2026-07-07 Read more
  • Leagsoft Powers a Power Industry Giant: Unified Domain Control for 250,000 Domestic Endpoints

    2026-07-07 Read more

Top recommendation

  • Leagsoft Empowers Saudi Jeraisy Group: Reinventing Security Service Capabilities with a Zero-Trust Architecture

    2025-09-15 Read more
  • Ecological Win-Win | LeagSoft and Huawei Jointly Build an Intelligent Endpoint Security Defense for Bank Rakyat Indonesia (BRI)

    2025-12-01 Read more