NAVEX > Case Studies > Major Telecom Company Accomplishes Security Compliance in 18 Months

Major Telecom Company Accomplishes Security Compliance in 18 Months

NAVEX Logo
Company Size
1,000+
Region
  • America
Country
  • United States
Product
  • NAVEX IRM
Tech Stack
  • GRC Platform
Implementation Scale
  • Enterprise-wide Deployment
Impact Metrics
  • Cost Savings
  • Digital Expertise
  • Productivity Improvements
Technology Category
  • Application Infrastructure & Middleware - Data Exchange & Integration
  • Cybersecurity & Privacy - Security Compliance
Applicable Industries
  • Telecommunications
Applicable Functions
  • Business Operation
Use Cases
  • Cybersecurity
  • Regulatory Compliance Monitoring
Services
  • System Integration
About The Customer
The customer is a major telecom company based in Alaska. The company was facing a number of challenges including a staffing shortage, customer demands, a dynamic regulatory environment and the off-the-grid nature of Alaska. They relied on spreadsheets, email and tribal knowledge for a patchwork compliance program, and lacked a comprehensive view of real risk areas. The company was given a mandate by its board to create a broad-reaching governance, risk and compliance (GRC) program managing everything from audit and compliance to third-party risk and business continuity.
The Challenge
The telecom company was given a mandate by its board to create a broad-reaching governance, risk and compliance (GRC) program managing everything from audit and compliance to third-party risk and business continuity. The company faced a number of challenges, including a staffing shortage, customer demands, a dynamic regulatory environment and the off-the-grid nature of Alaska. They relied on spreadsheets, email and tribal knowledge for a patchwork compliance program, and lacked a comprehensive view of real risk areas. The Board requested the new GRC program to be up and running in 18 months.
The Solution
To build a security compliance program, the telecom company hired a seasoned CISO with experience building similar programs. The company then formed a GRC team to integrate the entire GRC ecosystem at once. They chose NAVEX IRM, NAVEX ’s GRC platform, which is designed for integrated risk management. NAVEX IRM delivered on the company’s needs; namely, a collaborative tool with automation and functionality specific to the company’s use cases. Once data is in NAVEX IRM, it becomes actionable information that is then reported to business units to help them take action or make an informed decision. The GRC team was able to take a lifecycle approach to security compliance. It started with a controls framework design that lead to a current state assessment, followed by risk prioritization, remediation and reporting, with ongoing maintenance and, when necessary, updating the framework. NAVEX IRM supports every stage of this lifecycle.
Operational Impact
  • The telecom company’s GRC team created a custom control framework to comply with various regulations and standards, including HIPAA, PCI DSS, SOX, ISO 27001 and NIST 800-53.
  • They tracked progress within NAVEX IRM, reporting remediation efforts back to the business units to aid decision-making regarding security compliance.
  • The telecom company relied on NAVEX IRM not just for security compliance and documentation but also for audit, operational risk, business continuity, third-party risk and physical security.
  • Using NAVEX IRM, the company reduced costs related to audit findings management by 80%.
  • Audits became so efficient that a single internal auditor was able to conduct several audits, offering more comprehensive results without adding headcount.
Quantitative Benefit
  • Reduced costs related to audit findings management by 80%
  • Saved each department an average of 200 hours by preparing their BIAs in the system

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.