How Atomicwork embedded best practices and proved security with Sprinto

Atomicwork es un proveedor líder de gestión de servicios basada en agentes, que presta servicios a diversos sectores, incluidos los servicios financieros, la manufactura y el software como servicio (SaaS). La plataforma unificada de gestión de servicios de la compañía combina IA basada en agentes, un moderno servicio de asistencia técnica de TI y automatización inteligente de flujos de trabajo para optimizar las operaciones internas e impulsar el éxito.

2 meses Tiempo para completar la auditoría ISO 27001
15 minutos Tiempo dedicado diariamente al seguimiento del cumplimiento
200+ integraciones Integraciones nativas de la nube disponibles
Sprinto logo-blanco
Antes Sprinto
Después Sprinto
Era fundamental tener una visión clara de la infraestructura y los activos, y supervisar manualmente a los proveedores de la nube, los repositorios de código y los dispositivos de los empleados habría requerido un esfuerzo manual constante.
Atomicwork centralized its assets through Sprinto’s native AWS and Azure integrations for cloud security visibility and its GitLab integration for code vulnerability management, drawing on 200+ cloud-native integrations for comprehensive asset monitoring with minimal manual effort.
Era necesario automatizar la recopilación de pruebas y el seguimiento de las tareas omitidas, manteniendo informadas a las personas adecuadas para que la seguridad y el cumplimiento normativo nunca se vieran comprometidos.
Atomicwork defined security roles in Sprinto so contextual alerts reach the individuals tagged to a control when a check fails, and now spends a little more than 15 minutes a day managing compliance.
Los procesos que se desarrollaron de forma orgánica a medida que la empresa emergente crecía corrían el riesgo de seguir siendo improvisados, y Atomicwork necesitaba una ruta clara para escalar a través de ISO 27001, SOC 2 y una práctica HIPAA existente sin repetir el mismo trabajo.
Atomicwork used Sprinto’s common controls framework to run crosswalks between ISO 27001 and SOC 2, eliminating repetitive controls and tasks, migrated its existing HIPAA practice onto the platform, and cleared its ISO 27001 audit on the first cycle two months into the engagement.
“The ability to integrate with our cloud providers and subsequently automate evidence collection was critical. We wanted a solution that would keep us in the loop and notify missed tasks so security and compliance aren’t compromised. Another criterion was how well a platform supports multiple compliances, by making scaling efficient and providing clear direction about what we needed to do. Sprinto fulfilled these conditions handily!”


– Narasimha Murthy Pappu
CISO, Atomicwork

“El hecho de que hayamos podido obtener la certificación en la primera toma demuestra el impacto Sprinto had. I’ve known organizations that go through two or three rounds of audits before they get certified. So the fact that we were able to do it in one cycle is fantastic”


– Narasimha Murthy Pappu
CISO, Atomicwork

Introducción

Atomicwork, proveedor global de soluciones ITSM (Gestión de Servicios de TI) basadas en IA, considera que el cumplimiento normativo es el resultado de prácticas y procesos de seguridad fiables y verificables. «Para nosotros, el cumplimiento es una consecuencia. Implementar procesos seguros y fiables en los niveles adecuados es lo que garantiza el cumplimiento», afirma Narasimha Murthy Pappu, CISO de Atomicwork.

Esa perspectiva marcó la pauta de la empresa: basar las operaciones en las mejores prácticas de seguridad, eliminar los puntos ciegos de seguridad, demostrar la seguridad a los clientes y al mercado en general, y mantener un camino claro para la expansión en materia de cumplimiento normativo.

El problema

La visibilidad clara de la infraestructura y los activos era fundamental, lo que justificaba la inversión en una plataforma de monitoreo de cumplimiento con sólidas integraciones y automatización. Atomicwork necesitaba integraciones extensas, gestión basada en roles y recopilación automatizada de evidencia para optimizar la gestión del cumplimiento, acelerar las auditorías y escalar el cumplimiento sin interrupciones.

Having found the right solution in Sprinto, Atomicwork onboarded the platform to begin ISO 27001 certification and SOC 2 audit preparations.

“The ability to integrate with our cloud providers and subsequently automate evidence collection was critical. We wanted a solution that would keep us in the loop and notify missed tasks so security and compliance aren’t compromised. Another criterion was how well a platform supports multiple compliances, by making scaling efficient and providing clear direction about what we needed to do. Sprinto fulfilled these conditions handily!” says Narasimha Murthy.

La Solución

To get started with ISO 27001 and SOC 2, Atomicwork worked with Sprinto’s expert support team on the baseline tasks: connecting various cloud services through integrations, implementing Sprinto’s ISO 25001-aligned ready-to-use risk register, starting from Sprinto’s built-in policy templates and writing and publishing its own policies on top of them, and putting in place built-in, pre-mapped controls along with pre-mapped checks to monitor compliance.

Native integrations with key cloud providers were crucial in centralizing Atomicwork’s assets. Atomicwork gained clear visibility into cloud security through its AWS and Azure integrations with Sprinto, while the GitLab integration simplified code vulnerability management, ensuring comprehensive asset monitoring with minimal manual effort.

Atomicwork then defined security roles on Sprinto so that contextual alerts go to the right individuals tagged to controls when checks fail, giving the company timely, actionable prompts for issue remediation and compliance maintenance, and keeping it on the fast track to audit readiness. “I’ve used other compliance tools, and this is one of the areas Sprinto shines,” says Narasimha Murthy.

With workflows and automated checks clearly tagged to assets, roles, and processes, Atomicwork made compliance part of its day-to-day operations, creating natural guardrails and boundaries for security. SSO for all applications, integration-enabled asset inventory, clearly classified cloud accounts, and employee device security through Sprinto’s built-in MDM all played a key role in standardizing and securing the key processes that mark Atomicwork.

Sprinto’s common controls framework was crucial in making compliance crosswalks efficient for Atomicwork and in helping the company migrate its existing HIPAA practice to the platform. By identifying overlaps between frameworks like ISO 27001 and SOC 2, Atomicwork eliminated repetitive controls and tasks.

With the requisite integrations securing cloud infrastructure, automated evidence collection handling housekeeping, and alerts keeping the team on top of compliance, Atomicwork was ready to face its first ISO audit. “Sprinto becomes that one place where you can not just monitor but also resolve a lot of the issues that come up. You don’t have to switch between apps and contexts to make sure things are sorted,” says Narasimha Murthy.

Generar impacto

Atomicwork entered audits confidently, with the visibility of Sprinto’s consolidated dashboard and the efficiency of automated evidence collection behind it. Sprinto’s evidence dashboard was crucial in streamlining audit preparation, letting Atomicwork sample evidence and validate its accuracy directly within the platform. As a result, Atomicwork went into its ISO 27001 audit just two months into its engagement with Sprinto and cleared it with flying colors.

“El hecho de que hayamos podido obtener la certificación en la primera toma demuestra el impacto Sprinto had. I’ve known organizations that go through two or three rounds of audits before they get certified. So the fact that we were able to do it in one cycle is fantastic,” remarks Narasimha Murthy.

Alongside that two-month turnaround, Atomicwork standardized its processes and set guardrails at each level through Sprinto’s pre-mapped controls and automated checks, meeting industry security standards without compromising on flexibility. For an AI-driven ITSM platform like Atomicwork, that balance is key: AI agents can’t be afforded too much decision-making freedom, and they also shouldn’t be given too little access or too few permissions.

Atomicwork struck that balance by implementing the right access controls through Sprinto.

Actualmente, Narasimha Murthy y el equipo de Atomicwork dedican poco más de 15 minutos diarios a gestionar el cumplimiento normativo y trabajan para recopilar pruebas para su auditoría SOC 2 y su revisión anual de HIPAA.

“Para una empresa emergente en crecimiento, uno de los mayores desafíos es que los procesos desarrollados orgánicamente a menudo terminan siendo ad hoc. Con Sprinto, we are able to ensure clear rules and controls to streamline security operations. The wide range of integrations ensures everything is accurately mapped and tracked, helping embed best practices at Atomicwork,” says Narasimha Murthy.

¿Tienes preguntas? ¡Habla con nuestros expertos!

AI-CTA-bg
AI-CTA-bg
logotipo de atomicwork
Tipo de industria

Gestión de servicios basada en agentes / Gestión de servicios de TI (ITSM)

Empleados

51-200

Regiones

India

Módulos utilizados
ERP y SAP Registro de riesgo Gestión de políticas Monitoreo continuo / Controles automatizados
Marcos de trabajo utilizados
ISO 27001,
SOC 2 Tipo II
HIPAA