
– Narasimha Murthy Pappu
CISO, Atomicwork
– Narasimha Murthy Pappu
CISO, Atomicwork
Introduction
Atomicwork, a global provider of AI-driven ITSM (IT Service Management) solutions, treats compliance as the result of security practices and processes that can be trusted and verified. “For us, compliance is an outcome. Bringing in secure, and trusted processes at the right levels is what gets you compliant,” says Narasimha Murthy Pappu, CISO at Atomicwork.
That outlook shaped the company’s agenda: anchor operations in security best practices, remove security blindspots, prove security to clients and the market at large, and hold a clear path to scale across compliances.
The Problem
Clear visibility into infrastructure and assets was mission-critical, which made a strong case for investing in a compliance monitoring platform with robust integrations and automation. Atomicwork needed extensive integrations, role-based management, and automated evidence collection to streamline compliance management, speed up audits, and scale compliance without disruptions.
Having found the right solution in Sprinto, Atomicwork onboarded the platform to begin ISO 27001 certification and SOC 2 audit preparations.
“The ability to integrate with our cloud providers and subsequently automate evidence collection was critical. We wanted a solution that would keep us in the loop and notify missed tasks so security and compliance aren’t compromised. Another criterion was how well a platform supports multiple compliances, by making scaling efficient and providing clear direction about what we needed to do. Sprinto fulfilled these conditions handily!” says Narasimha Murthy.
The Solution
To get started with ISO 27001 and SOC 2, Atomicwork worked with Sprinto’s expert support team on the baseline tasks: connecting various cloud services through integrations, implementing Sprinto’s ISO 25001-aligned ready-to-use risk register, starting from Sprinto’s built-in policy templates and writing and publishing its own policies on top of them, and putting in place built-in, pre-mapped controls along with pre-mapped checks to monitor compliance.
Native integrations with key cloud providers were crucial in centralizing Atomicwork’s assets. Atomicwork gained clear visibility into cloud security through its AWS and Azure integrations with Sprinto, while the GitLab integration simplified code vulnerability management, ensuring comprehensive asset monitoring with minimal manual effort.
Atomicwork then defined security roles on Sprinto so that contextual alerts go to the right individuals tagged to controls when checks fail, giving the company timely, actionable prompts for issue remediation and compliance maintenance, and keeping it on the fast track to audit readiness. “I’ve used other compliance tools, and this is one of the areas Sprinto shines,” says Narasimha Murthy.
With workflows and automated checks clearly tagged to assets, roles, and processes, Atomicwork made compliance part of its day-to-day operations, creating natural guardrails and boundaries for security. SSO for all applications, integration-enabled asset inventory, clearly classified cloud accounts, and employee device security through Sprinto’s built-in MDM all played a key role in standardizing and securing the key processes that mark Atomicwork.
Sprinto’s common controls framework was crucial in making compliance crosswalks efficient for Atomicwork and in helping the company migrate its existing HIPAA practice to the platform. By identifying overlaps between frameworks like ISO 27001 and SOC 2, Atomicwork eliminated repetitive controls and tasks.
With the requisite integrations securing cloud infrastructure, automated evidence collection handling housekeeping, and alerts keeping the team on top of compliance, Atomicwork was ready to face its first ISO audit. “Sprinto becomes that one place where you can not just monitor but also resolve a lot of the issues that come up. You don’t have to switch between apps and contexts to make sure things are sorted,” says Narasimha Murthy.
Impact
Atomicwork entered audits confidently, with the visibility of Sprinto’s consolidated dashboard and the efficiency of automated evidence collection behind it. Sprinto’s evidence dashboard was crucial in streamlining audit preparation, letting Atomicwork sample evidence and validate its accuracy directly within the platform. As a result, Atomicwork went into its ISO 27001 audit just two months into its engagement with Sprinto and cleared it with flying colors.
“The fact that we were able to get certified on the very first take goes to show the impact Sprinto had. I’ve known organizations that go through two or three rounds of audits before they get certified. So the fact that we were able to do it in one cycle is fantastic,” remarks Narasimha Murthy.
Alongside that two-month turnaround, Atomicwork standardized its processes and set guardrails at each level through Sprinto’s pre-mapped controls and automated checks, meeting industry security standards without compromising on flexibility. For an AI-driven ITSM platform like Atomicwork, that balance is key: AI agents can’t be afforded too much decision-making freedom, and they also shouldn’t be given too little access or too few permissions.
Atomicwork struck that balance by implementing the right access controls through Sprinto.
Today, Narasimha Murthy and the Atomicwork team spend a little more than 15 minutes managing compliances daily and are working towards gathering evidence for their SOC 2 audit and annual HIPAA review.
“For a growing start-up, one of the biggest challenges is that processes developed organically often end up being ad-hoc. With Sprinto, we are able to ensure clear rules and controls to streamline security operations. The wide range of integrations ensures everything is accurately mapped and tracked, helping embed best practices at Atomicwork,” says Narasimha Murthy.
Got questions? Talk to our experts!



Agentic service management / IT Service Management (ITSM)
India





