How Officebeacon breezed through its ISO 27001 audit with Sprinto

Officebeacon is a US-based software solutions provider globally renowned for its virtual staffing solution, which is trusted by thousands of companies and leading institutions all over. With over 2000 employees and offices that span geographies, Officebeacon bears the capabilities to service businesses across markets and sectors.

officebeacon hero image
2 weeks Time to achieve ISO 27001 audit readiness
~1 month Time to complete ISO 27001 audit and receive certification
40 days From entering audit to receiving ISO 27001 Certification
Sprinto white-logo
Before Sprinto
After Sprinto
A pre-covid gap assessment by a Big 4 audit firm surfaced policy implementation shortcomings, and following the assessor’s recommendations would mean committing almost a year just to set up processes and implement policies, against a strict timeline.
Officebeacon closed those policy implementation gaps within its strict timeline, reaching ISO 27001 audit readiness in 2 weeks and receiving its certification within 40 days of entering the audit.
Tasks emphasized in Officebeacon’s policies, from device encryption and multifactor authentication to vulnerability management and vendor management, needed tooling that could enforce them at the entity level.
Officebeacon turned its policies into controls mapped to suitable checks, identified control owners, and enforced them at a granular level through time-bound compliance workflows and periodic triggers.
Compliance information sat in silos, and linking evidence to the controls being tested for an audit would have taken Excel, PowerBI and many man-hours.
Officebeacon consolidated everything into Sprinto’s interactive dashboard and shared evidence with its auditor through the auditor dashboard, with all relevant information in a single place.
“Following their recommendations would mean committing to almost a year of our time to just getting processes set up and policies implemented. We had a strict timeline to meet, and this approach was not feasible”


– Anil Varma
CISO, Officebeacon

“We could have accomplished all of this using Excel and PowerBI, but it would have required many man-hours. And more than 8 months. With a purpose-built tool like Sprinto, we can meet timelines and goals much faster.”


– Anil Varma
CISO, Officebeacon

Introduction

Planning a time-bound, strategic ramp-up of customer acquisition efforts across markets, Officebeacon needed ISO 27001 certification to prove both product security and operational maturity. For Anil Varma, CISO at Officebeacon, the certification was also the moment to apply technical rigor to how compliance itself was run, eliminating silos, enforcing policies, and monitoring controls against those policies. “Controls tell you how good your policy implementation is,” says Anil.

The Problem

A pre-covid gap assessment carried out by one of the Big 4 audit firms had revealed policy implementation shortcomings that needed to be addressed by way of a formal security compliance program.

“Following their recommendations would mean committing to almost a year of our time to just getting processes set up and policies implemented. We had a strict timeline to meet, and this approach was not feasible,” recalls Anil Varma, CISO at Officebeacon.

Anil adds, “An audit is not just about producing correct documents. You need to link evidence to the controls being tested to clearly show your policies are functioning as they are meant to do.” With compliance information sitting in silos, making those links for an audit would have meant working through Excel, PowerBI and many man-hours.

Effective implementation involves translating policies into specific control measures, mapping them to the right entities, assigning clear roles and responsibilities, and then monitoring their effectiveness to ensure they are working as intended.

The Solution

When Officebeacon began exploring vendors, they were looking for “specialists” who could identify and consolidate information in a single place, and Sprinto proved a good fit almost immediately. “No other tool gave us the confidence that Sprinto did,” notes Anil.

“Just by looking at the dashboard, I could tell that the platform is comprehensive. Unlike other platforms where you have to go through 2-3 pages to get information, Sprinto presents all relevant information in a single place. The platform is also more user-friendly compared to others,” he adds.

“Sprinto’s fundamentals are really remarkable!” Officebeacon decided to partner with Sprinto to address three things: improve the implementation of security policies; meet rigorous ISO 27001 compliance requirements and receive certification; and establish a technology-enabled practice for managing compliance. Officebeacon kicked off ISO 27001 implementation with policy documentation, starting from Sprinto’s policy templates and writing its own policy set on top of them.

“We spent almost 10 days on this,” notes Anil.

“Once the policies accurately reflected Officebeacon’s ethos and commitments, we published them in Sprinto and made them available to the entire organization,” he adds. Having integrated its employee email provider with Sprinto, Officebeacon could then trigger emails for security training and policy acknowledgment org-wide.

Turning policies into controls and mapping each control to suitable checks followed right after, with control owners identified and a monitoring and remediation exercise launched immediately to fill compliance gaps.

As part of the integrated risk assessment exercise, Officebeacon scoped out tasks ranging from device encryption and multifactor authentication to vulnerability management and vendor management practices.

“We realized that while many of these tasks were emphasized in our policies, they were not effectively implemented. Primarily because we lacked the tools to enforce them at the entity level as strictly as needed,” notes Anil. Progress against every one of those tasks stayed visible in a single dashboard view.

“Sprinto’s dashboard is very interactive. With a single click, you can see where you stand, and how many things are compliant and pending across different levels such as infrastructure, people, devices, and more,” says Anil. Technical factors aside, Anil notes that one of the biggest hurdles was getting an organization of over 2000 employees to come together at once to meet compliance requirements.

“It’s a mindset challenge, really,” he says.

“Coaching your teams on the importance of compliance helps. Senior leadership’s championship is key,” he adds. To enable prompt actions, Officebeacon leveraged Sprinto’s automation capabilities to the fullest, and with clear, time-bound compliance workflows and period triggers in place, moved steadily towards its goal of achieving ISO 27001 compliance.

Anil remarks, “We began operating at a granular level. Using Sprinto we configured checks in a detailed manner. Tagged to a workflow and a person, monitoring compliance progress became easy.”

Impact

Officebeacon was ISO 27001 audit ready in 2 weeks. “I went through each and every control and it was all mapped to exercises we did on-site,” says Anil. Using the Sprinto auditor dashboard, Officebeacon found it easy to share evidence with their auditor, and with accuracy being key, Sprinto assured Anil of the quality of the evidence, including snapshots.

“Because issues were fixed well in advance of the audit process, it was easy for us to complete audits quickly,” says Anil. Within 40 days of entering an audit, Officebeacon received its ISO 27001 Certification. Anil notes that automation played a crucial role in that audit success.

“We could have accomplished all of this using Excel and PowerBI, but it would have required many man-hours. And more than 8 months. With a purpose-built tool like Sprinto, we can meet timelines and goals much faster,” he says.

“Automation helps, in terms of linking all the pieces together. Along with APIs, Sprinto paints a clear picture of where you are and where you need to go,” he adds. Anil also emphasized the role Sprinto’s support team played in enabling him.

“Software vendors can be rigid but Sprinto was flexible and worked with us. They have a solution mindset and the team problem-solved with us every step of the way,” he notes. “Right from sales to support, the Sprinto team is always available,” he says.

With certification achieved and compliance monitoring consolidated in one platform, Anil notes, “Now that everything is lined up in one software, we are more relaxed.”

Got questions? Talk to our experts!

AI-CTA-bg
AI-CTA-bg
officebeacon logo
Industry Type

Software solutions / virtual staffing

Employees

2000+

Regions

USA

Modules used
Policy Management Continuous Monitoring Risk Assessment Security Training
Frameworks used
ISO 27001