NAVEX > 实例探究 > Major Social Game Developer Embraces Integrated Risk Management and New Risk Culture

Major Social Game Developer Embraces Integrated Risk Management and New Risk Culture

NAVEX Logo
产品
  • NAVEX IRM
技术栈
  • Integrated Risk Management
实施规模
  • Enterprise-wide Deployment
影响指标
  • Cost Savings
  • Productivity Improvements
技术
  • 应用基础设施与中间件 - API 集成与管理
适用行业
  • Software
适用功能
  • 商业运营
用例
  • 网络安全
  • 监管合规监控
服务
  • 系统集成
关于客户
The customer is a high-profile social game developer that creates popular mobile games enjoyed by millions. The company was growing fast and leveling up, but it was not a skilled player at managing risk and complying with regulations. They were still using spreadsheets, word-processing, email, and an Intranet site for governance, risk management, and compliance. As a result, the company couldn’t see vulnerabilities and the risks posed by them. Asset inventory audits took months to reconcile. Onboarding new vendors took four weeks. Even convincing employees to acknowledge company policies, like acceptable use, was a Herculean effort.
挑战
The social game developer was facing challenges in managing cyber risk, compliance, and audits due to inadequate processes. They were using spreadsheets, word-processing, email, and an Intranet site for governance, risk management, and compliance. As a result, the company couldn’t see vulnerabilities and the risks posed by them. Asset inventory audits took months to reconcile. Onboarding new vendors took four weeks. Even convincing employees to acknowledge company policies, like acceptable use, was a Herculean effort. The company needed a senior analyst to lead its nascent program, as well as invest in a technology platform that could streamline cyber risk, compliance, and audit management activities while supporting game development.
解决方案
The social game developer selected NAVEX’s GRC platform, IRM to create a new IT and cyber risk program. The goals of the program were to get a bird’s-eye view of vulnerabilities, risks, audits, and policies, address employee challenges, like version control, understand and control the vendor lifecycle, make audits faster and less painful, and help employees understand their responsibilities as risk stakeholders. NAVEX IRM’s integrated risk management capabilities address eight business use cases: Compliance and policy management, Vendor risk management, IT risk management, Continuous monitoring, Business continuity management, Operational risk management, Audit management, Health and safety management.
运营影响
  • Automation: Shortened project timelines from two months to 48-72 hours by automatically importing and correlating vulnerabilities.
  • Single source of truth: Employees have access to only current policies and procedures.
  • Efficiency gains: Assessing new vendors went from two months to 2-3 days. The company launched a fast-track approval process for ongoing vendors.
  • Time savings: Audits that once took months to conduct now take, on average, 4 days.
  • Culture shift: Business owners appreciate their roles as risk owners and are faster to adopt new policies and respond to compliance requests.
数量效益
  • Shortened project timelines from two months to 48-72 hours.
  • Assessing new vendors went from two months to 2-3 days.
  • Audits that once took months to conduct now take, on average, 4 days.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

相关案例.

联系我们

欢迎与我们交流!
* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

感谢您的信息!
我们会很快与你取得联系。