
– Sanjay Mishra
Head of DevOps, WebEngage
– Sanjay Mishra
Head of DevOps, WebEngage
Introduction
WebEngage is a customer data platform and marketing automation suite that simplifies and improves user engagement and retention for consumer tech enterprises and SMBs.
The platform helps brands drive revenue through personalized engagement campaigns across 10 communication channels, designs intuitive user lifecycle journeys to convert existing users through data-backed omnichannel engagement campaigns, and offers in-depth product and marketing analytics to track growth metrics and campaign performance.
For Sanjay Mishra, Head of DevOps, and the members of the security team at WebEngage, the journey to compliance began in 2020, when they onboarded PricewaterhouseCoopers International Limited (PwC) and BSI as their compliance consultant and audit partner respectively.
The key requirement was a compliance solution that identifies and reports security gaps in cloud infrastructure, streamlines infosec housekeeping with robust control monitoring, and fulfills certification requirements using built-in tools and templates.
The Problem
Having completed their ISO 27001 certification in April 2021, WebEngage followed up with a gap analysis to determine readiness for ISO 27701. That exercise proved both time and resource intensive, and the difficulty of retrofitting PwC’s pre-set processes into WebEngage’s own context revealed several shortcomings in continuing with a consultant-based approach to compliance.
“Agility is important to us. Organizations like PwC typically have a prescribed set of processes, and it was taking too long to fit these processes into what we already have in place at WebEngage. Also, since we were pursuing ISO 27701, which is quite process-centric requiring continuous technical monitoring, we were looking to offload a lot of the work to a platform or a tool via integrations,” said Sanjay Mishra, Head of DevOps at WebEngage.
The ISO 27001 documentation process had also been tedious, so for ISO 27701 Sanjay and the security team were determined to offload much of the documentation and infosec housekeeping to a tool with built-in capabilities. After trying out 2-3 compliance platforms, Sanjay landed on Sprinto for a number of factors.
Scalable, automated compliance came first: Sprinto clarified the process and provided guidance on how to effectively organize and operationalize compliance to strengthen WebEngage’s cloud posture, while optimizing the automated approach for maximum efficiency. The process itself was straightforward, with Sprinto’s team clearly setting expectations as to what the platform could and couldn’t do, which let WebEngage evaluate it transparently against their specific needs.
Responsive integrations closed the case, as Sprinto’s extensive native integrations could centralize and monitor WebEngage’s entire cloud infrastructure with speed and precision, tracking controls without manual effort.
“With Sprinto, the commitment was very straightforward. It was clear to us what we’d be able to do and what we’d need to change at our end to achieve compliance. Sprinto’s team also helped us understand our current posture and what processes we’d need to achieve the standards as well as we wanted. This went a long way in cementing Sprinto as our first choice,” said Sanjay.
The Solution
WebEngage decided to use Sprinto to achieve ISO 27701 certification first, planning, based on the results, to pursue more frameworks such as HIPAA and SOC 2 and to move ISO 27001 compliance management onto the platform as well. To start off, WebEngage used Sprinto’s pre-built policy templates as the base and built out its ISO 27701 documentation from there.
WebEngage also uploaded its existing ISO 27001 policies to the platform and mapped them to built-in ISO controls, then ran a policy acknowledgment campaign on Sprinto. “Earlier, we had to get someone from HR to follow up and track policy acknowledgments. On Sprinto, you can tell how many employees have completed pending tasks and nudge them directly. The platform also sends the infosec team reminders for when to start new training and policy campaigns,” said Sanjay.
With policies acknowledged, WebEngage used Sprinto’s in-built risk register to align its risk practices with ISO 27001 standards, mapping risks to relevant controls using both its existing controls library and Sprinto’s pre-built controls framework for ISO 27701.
Having mapped these to built-in tests that validate controls, WebEngage successfully automated management of 30 controls, while retaining semi-manual workflows for ~15 controls related to administrative and physical safeguards.
“Most of the controls we used for ISO 27001 and 27701 overlapped with Sprinto’s, making it easier for us to make the switch to platform-led management. Earlier, we had to manage compliances in three different places, but it’s all consolidated within Sprinto,” said Sanjay.
Beyond overall risk management, ISO 27701 requires access and change management to be streamlined and secured. WebEngage enforced role-based access to its code repositories and supported a zero-trust model through Sprinto’s integrations with Google Workspace and GitLab, with roles added to Workspace automatically synced to Sprinto so that controls were triggered whenever access to critical systems like GitLab deviated from the assigned role.
WebEngage extended the same approach to incidents, connecting its incident and vulnerability management tools to Sprinto to record, update, and manage incident status on the platform and create a clear audit trail of incidents. Change management was streamlined the same way through Sprinto’s Jira integration, letting Sanjay and WebEngage capture tickets and resolution statuses on the platform and unify several aspects of compliance in one place.
Throughout the process, Sprinto’s support team guided WebEngage in mapping controls to assets and processes according to key compliance requirements, ensuring automated validation while workflows ensured compliance. With compliance automation and expert guidance in place, WebEngage was ISO 27701-ready in just 6 months.
Impact
WebEngage felt the effect of platform-led compliance at several levels, starting with a cybersecurity posture the security team could now run proactively. Real-time notifications on failing controls, incidents, and more keep the security team and management stakeholders on top of compliance, making compliance efforts visible and letting WebEngage put out fires at the first sign of smoke.
On that footing, WebEngage has not experienced any significant CyberSec incident in the last 6 years.
WebEngage also identified and closed control gaps intelligently using Sprinto’s responsive integrations with the cloud systems that make up its operating environment.
“Sprinto was crucial in helping us identify gaps in our cloud setup and processes, which we were able to fill quickly with their guidance. The platform monitors our infra continuously and tells us what controls we need to check and fix, this has helped save a lot of time and effort for the security team,” said Sanjay Mishra, Head of DevOps at WebEngage.
WebEngage now monitors 4 frameworks continuously on Sprinto, ISO 27001, ISO 27701, SOC 2, and HIPAA, with all compliance consolidated in one place.
“We’re quite confident about our cloud security and compliance posture today, and this confidence translates to bigger clients and deals. Having multiple certifications under your belt helps push conversations forward, especially with MNCs and enterprise clients, and Sprinto has played a huge role in helping us achieve this confidence,” says Sanjay Mishra, Head of DevOps at WebEngage.
Got questions? Talk to our experts!



Customer data platform and marketing automation
India





