This doesn't seem at all realistic. Tight security and people are actually getting work done? Inconceivable!
The first thing I do with credentials is find out what they open. Seems like if you have the resources to follow up on access attempts, you have the resources to set ACLs correctly so you’re not scared of them.
The security of banks is certainly not in their IT departments.
I guess it's a place where "getting work done" doesn't involve downloading 1000 deps with npm and what have you from random sources on the internet.