Download PDF
NAVEX > Case Studies > Major Telecom Company Accomplishes Security Compliance in 18 Months
NAVEX Logo

Major Telecom Company Accomplishes Security Compliance in 18 Months

Technology Category
  • Application Infrastructure & Middleware - Data Exchange & Integration
  • Cybersecurity & Privacy - Security Compliance
Applicable Industries
  • Telecommunications
Applicable Functions
  • Business Operation
Use Cases
  • Cybersecurity
  • Regulatory Compliance Monitoring
Services
  • System Integration
The Challenge
The telecom company was given a mandate by its board to create a broad-reaching governance, risk and compliance (GRC) program managing everything from audit and compliance to third-party risk and business continuity. The company faced a number of challenges, including a staffing shortage, customer demands, a dynamic regulatory environment and the off-the-grid nature of Alaska. They relied on spreadsheets, email and tribal knowledge for a patchwork compliance program, and lacked a comprehensive view of real risk areas. The Board requested the new GRC program to be up and running in 18 months.
About The Customer
The customer is a major telecom company based in Alaska. The company was facing a number of challenges including a staffing shortage, customer demands, a dynamic regulatory environment and the off-the-grid nature of Alaska. They relied on spreadsheets, email and tribal knowledge for a patchwork compliance program, and lacked a comprehensive view of real risk areas. The company was given a mandate by its board to create a broad-reaching governance, risk and compliance (GRC) program managing everything from audit and compliance to third-party risk and business continuity.
The Solution
To build a security compliance program, the telecom company hired a seasoned CISO with experience building similar programs. The company then formed a GRC team to integrate the entire GRC ecosystem at once. They chose NAVEX IRM, NAVEX ’s GRC platform, which is designed for integrated risk management. NAVEX IRM delivered on the company’s needs; namely, a collaborative tool with automation and functionality specific to the company’s use cases. Once data is in NAVEX IRM, it becomes actionable information that is then reported to business units to help them take action or make an informed decision. The GRC team was able to take a lifecycle approach to security compliance. It started with a controls framework design that lead to a current state assessment, followed by risk prioritization, remediation and reporting, with ongoing maintenance and, when necessary, updating the framework. NAVEX IRM supports every stage of this lifecycle.
Operational Impact
  • The telecom company’s GRC team created a custom control framework to comply with various regulations and standards, including HIPAA, PCI DSS, SOX, ISO 27001 and NIST 800-53.
  • They tracked progress within NAVEX IRM, reporting remediation efforts back to the business units to aid decision-making regarding security compliance.
  • The telecom company relied on NAVEX IRM not just for security compliance and documentation but also for audit, operational risk, business continuity, third-party risk and physical security.
Quantitative Benefit
  • Reduced costs related to audit findings management by 80%
  • Saved each department an average of 200 hours by preparing their BIAs in the system

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.