How WebEngage Improved Cloud Security and Built a Proactive Compliance Posture with Sprinto

WebEngage is a customer data platform and marketing automation suite that simplifies and improves user engagement and retention for consumer tech enterprises and SMBs. The platform helps brands drive revenue through personalized engagement campaigns across 10 communication channels.

webengage hero image
6 months Time to ISO 27001 & ISO 27701 certifications
6 years Duration without any major cybersecurity incident
4 frameworks Monitored continuously on Sprinto
sprinto-comparison-table-sprinto-logo
Before Sprinto
After Sprinto
After achieving ISO 27001 in April 2021 through a consultant-led approach with PwC and BSI, WebEngage found the model too slow and resource-intensive to sustain as compliance needs grew.
Using Sprinto’s pre-built policy templates and native integrations, WebEngage documented ISO 27701, mapped existing ISO 27001 policies to built-in controls, and automated policy acknowledgment campaigns.
Retrofitting PwC’s prescribed processes into WebEngage’s existing context took too long, and the process-centric, continuous-monitoring requirements of ISO 27701 made a platform-based approach necessary.
WebEngage automated 30 controls and unified access management, incident management, and change management on Sprinto, becoming ISO 27701-ready in just 6 months.
ISO 27001 documentation was tedious to maintain manually, and the team needed a tool with built-in capabilities to handle documentation and ongoing infosec housekeeping.
With real-time alerts and continuous monitoring across 4 frameworks, WebEngage now runs ISO 27001, ISO 27701, HIPAA, and SOC 2 on Sprinto.
“Agility is important to us. Organizations like PwC typically have a prescribed set of processes, and it was taking too long to fit these processes into what we already have in place at WebEngage.”


– Sanjay Mishra
Head of DevOps, WebEngage

“Sprinto was crucial in helping us identify gaps in our cloud setup and processes, which we were able to fill quickly with their guidance. The platform monitors our infra continuously and tells us what controls we need to check and fix, this has helped save a lot of time and effort for the security team.”

– Sanjay Mishra
Head of DevOps, WebEngage

Introduction

For Sanjay Mishra, Head of DevOps at WebEngage, the compliance journey began in 2020 when WebEngage onboarded PricewaterhouseCoopers (PwC) as compliance consultant and BSI as audit partner. WebEngage achieved ISO 27001 certification in April 2021, then conducted a gap analysis for ISO 27701. That analysis surfaced a clear problem: the consultant-based model was not built for the pace or continuous-monitoring demands that ISO 27701 required.

As Sanjay put it, “Agility is important to us. Organizations like PwC typically have a prescribed set of processes, and it was taking too long to fit these processes into what we already have in place at WebEngage.” WebEngage needed a different approach, one that could scale with its frameworks and fit the way the organization already operated.

The Problem

The consultant-led model that had carried WebEngage through ISO 27001 began to show its limits as the security team looked ahead to ISO 27701. The work was time- and resource-intensive, and retrofitting an external firm’s pre-set processes into WebEngage’s existing context created friction at every step. ISO 27701’s process-centric structure and requirement for continuous technical monitoring made offloading work to a platform, via integrations, a practical necessity rather than a preference.

Maintaining ISO 27001 documentation manually had also become tedious, and WebEngage needed a tool with built-in capabilities to handle documentation and ongoing infosec housekeeping.

The Solution

After evaluating multiple platforms, Sanjay chose Sprinto for its scalable automation and responsive integrations. “With Sprinto, the commitment was very straightforward. It was clear to us what we’d be able to do and what we’d need to change at our end to achieve compliance. Sprinto’s team also helped us understand our current posture and what processes we’d need to achieve the standards as well as we wanted. This went a long way in cementing Sprinto as our first choice.”

WebEngage pursued ISO 27701 first. The team used Sprinto’s pre-built policy templates to document ISO 27701, uploaded existing ISO 27001 policies, and mapped them to built-in controls. A policy acknowledgment campaign followed. “Earlier, we had to get someone from HR to follow up and track policy acknowledgments. On Sprinto, you can tell how many employees have completed pending tasks and nudge them directly. The platform also sends the infosec team reminders for when to start new training and policy campaigns.”

Using Sprinto’s risk register and pre-built controls framework, the team mapped risks to controls and automated management of 30 controls while retaining semi-manual workflows for approximately 15 administrative and physical safeguards. “Most of the controls we used for ISO 27001 and 27701 overlapped with Sprinto’s, making it easier for us to make the switch to platform-led management. Earlier, we had to manage compliances in three different places, but it’s all consolidated within Sprinto.”

Access management was enforced through Google Workspace and GitLab integrations with role-based access synced automatically. Incident management and change management via Jira were also unified on the platform. Throughout, Sprinto’s support team guided WebEngage in mapping controls to assets and processes according to key compliance requirements.

As a result, WebEngage was ISO 27701-ready in just 6 months.

Impact

As Sanjay noted, “Sprinto was crucial in helping us identify gaps in our cloud setup and processes, which we were able to fill quickly with their guidance. The platform monitors our infra continuously and tells us what controls we need to check and fix. This has helped save a lot of time and effort for the security team.”

With Sprinto’s real-time alerts and continuous monitoring, WebEngage’s cybersecurity posture shifted from reactive to proactive. The platform notifies the team of failing controls and incidents as they surface, helping close gaps before they become risks.

Beyond posture, Sprinto changed how WebEngage thinks about scaling compliance. “Today, if someone tells me to add a new framework, I know exactly what we’ll need to do and how long it will take. Earlier, these were things we had to figure out on our own, but Sprinto has made this so much easier.”

So far, WebEngage has operationalized ISO 27001, ISO 27701, HIPAA, and SOC 2 on Sprinto. As Sanjay put it, “We’re quite confident about our cloud security and compliance posture today, and this confidence translates to bigger clients and deals. Having multiple certifications under your belt helps push conversations forward, especially with MNCs and enterprise clients, and Sprinto has played a huge role in helping us achieve this confidence.”

Got questions? Talk to our experts!

Frameworks-logos-bg
Frameworks-logos-mob-bg
Industry Type

Customer data platform & marketing automation (martech SaaS)

Regions

India

Modules used
Continuous Monitoring Policy Management Risk Management Access Control
Frameworks used
sprinto-customer-template-iso-img.webp
sprinto-customer-template-aicpa-soc-img.webp
sprinto-customer-template-hipaaimg.webp