
– Thomas Thomsen
Primary Security Architect, CellPoint Digital
– Frederic Lauret
Security Architect, CellPoint Digital
Introduction
CellPoint Digital’s payment orchestration platform enables intelligent routing and dynamic reports and analytics that help organizations transform payments, lowering costs, boosting revenue, and unlocking the true potential of payments to drive profitability.
Because CellPoint Digital handles sensitive payment data, PCI DSS is a crucial framework both for meeting security and privacy benchmarks and for demonstrating the company’s security posture to clients. CellPoint Digital needed a compliance solution that would fast-track PCI-DSS audit readiness while also sharpening visibility into infrastructure and compliance processes, automating infosec tasks, and making the compliance function more organized.
The Problem
Thomas Thomsen, the primary security architect who had been driving security compliance at CellPoint Digital, put the evidence gathering process under review after three years of leaning on an external auditor. “For the past three years we were using an auditor who was helping us with the evidence gathering. But I realized quickly that their methods were not meeting our standards,” observes Thomas.
One of the biggest challenges with PCI is grouping and tracking controls continuously so that compliance holds at all times. Streamlined tracking and evidence collection was a large part of the PCI agenda at CellPoint Digital, which led the organization toward automation-enabled compliance and to Control Case, a PCI-DSS compliance management partner. Even with Control Case’s agent deployed to integrate systems and collect evidence, Thomas shouldered the burden of uploading nearly 95% of it himself. “Data collection felt lacking, and the platform was difficult to navigate,” he added.
Being tied into inflexible legacy systems made the compliance process cumbersome and costly to change, which stood in the way of scaling coverage beyond PCI DSS, so Thomas and the CellPoint Digital team went looking for something more flexible. “When you tie into a system, there are some costs and it quickly becomes difficult to change. We started looking at compliance platforms that give you the freedom to go about audits the way you want,” reflects Thomas.
Three more criteria guided Thomas’s evaluation of compliance platforms: near real-time visibility into system configurations, security health, and day-to-day processes across a large and spread-out organization, enough to confirm that compliance guidelines were being followed as expected; automation; and scalability. On automation, Thomas says: “I’m always in favor of automating. Taking screenshots of this and that just seems like a waste of time, and once all this is done you have to start all over again for the next audit!” Scalability closed the list, since CellPoint Digital envisioned expanding compliance coverage to SOC 1 and 2, ISO 27001, and GDPR after completing PCI DSS. After evaluating Drata and Vanta, cost-effectiveness and platform integrity steered CellPoint Digital toward Sprinto.
The Solution
CellPoint Digital set out to stand up a PCI-DSS program quickly and then keep it running. Working through Sprinto’s expert-guided PCI-DSS program implementation, CellPoint Digital combined automation-led control testing and evidence collection, granular compliance tracking on a centralized compliance dashboard with real-time reporting, and a common control framework for mapping and scaling the program. Once CellPoint Digital had Sprinto up and running, the gaps in its security infrastructure surfaced immediately. “We identified weaknesses in device management, identity provisioning, and access controls almost right away,” says Thomas.
Joining Thomas on PCI-DSS audit prep, Frederic Lauret, security architect and decades-long PCI practitioner, saw structure come to compliance right off the bat, with better visibility and clearer alignment with PCI-DSS recommendations. That transparency let CellPoint Digital swiftly address security gaps and configure systems for sweeping PCI-DSS compliance. “I’ve been doing PCI certification for ten years and this is the first time I have something that groups all the information and also checks what should be done. I appreciate how the platform tells us what to do and where we’re sliding so that the certification process is always on track,” says Frederic.
CellPoint Digital tied systems, procedures, and policies to controls using Sprinto’s pre-built controls library, which surfaced compliance health as a daily control summary on the dashboard that Frederic worked through to close compliance gaps. “We have a control summary on the dashboard, and we just have to go through that to fix things a little bit every day,” he says.
With a wealth of experience operationalizing PCI-DSS, Frederic specifically wanted to hold a state of compliance beyond audit windows. “People tend to believe that PCI compliance is just for the time of the certification, but it’s not. It’s ongoing and you need to be compliant throughout the year, not once in the year,” he says. CellPoint Digital put Sprinto’s continuous compliance monitoring to work on that, running six to seven thousand daily checks across its various compliance controls, and that real-time vigilance kept the company from veering off compliance. “The metrics are reported at all times, and if something is sliding, we can see it. If you don’t have someone on board to do this manually, then this is where the tool can help, because you have a lot of things that you need to do over time: checking that your logs are okay, checking your users, and checking that all the components of your infrastructure are configured according to PCI requirements. All those things are automated on Sprinto”, Frederic explains.
CellPoint Digital went on to clear its PCI-DSS certification audit, with a 95% improvement in compliance reporting and a >65% improvement in audit processes.
Impact
CellPoint Digital used Sprinto’s automation to hold its PCI-DSS controls in place, strengthening its compliance posture and raising the precision of what it reports. Frederic says: “Previously, under PCI-DSS, I only reported on 5-10% of the infrastructure. Now with Sprinto, I can report everything, so our level of compliance is much more comprehensive and precise. It’s not just a daily check on a small subset, but everything, every day. It’s so much more satisfying.”
That coverage came with a reduced scope of work: with infosec housekeeping minimized on Sprinto, CellPoint Digital’s security team was free to pursue larger security goals. “We have more margin to operate now that everything’s under control. If we notice vulnerabilities in our processes or if we have to validate some crucial evidence, we have the opportunity to actually consider that matter,” says Frederic. Automated control testing and evidence collection also improved compliance throughput at large, adding integrity and trustworthiness to the program.
With PCI DSS running continuously, CellPoint Digital envisions expanding its compliance coverage to SOC 1 and 2, ISO 27001, and GDPR.
Got questions? Talk to our experts!



Payments / Payment orchestration
Denmark



