How Position2 won confidence by activating data security best practices

Position2 is a digital marketing firm that provides creative, demand generation, and AI-powered growth marketing services to B2B sectors worldwide, including cybersecurity, SaaS, healthcare, and more.

Key requirements

Position2 sought a trusted, user-friendly compliance automation platform with pre-built policies, tools, and integrations. The goal was to digitize compliance management, standardize processes, and embed data security best practices into daily operations.

Sprinto provided a comprehensive compliance automation platform featuring:

  • A unified compliance health dashboard for continuous monitoring and ongoing compliance
  • 200+ cloud-native integrations
  • Customizable policies
  • Pre-mapped controls and checks for standard security frameworks

ISO 27001:2022

SOC 2

SOC 2 Type 2

India

1.6x

More efficient vulnerability fixes

10 weeks

To achieve ISO 27001:2022 and SOC 2 Type 2 audit readiness

Ready to get started?

The Challenge: Ensuring data security with confidence

For Position2, achieving and maintaining confidence in their data security practices was the primary motivation for pursuing ISO 27001:2022 and SOC 2 Type 2 compliance.

Prabagaran Loganathan, Senior Manager of Information Systems, spearheaded the firm’s efforts to establish strong security controls and a privacy-first approach.

“Certification was necessary, but it wasn’t our main driver,” he explains. “We wanted robust security controls in place, ensuring confidence internally and when responding to security inquiries.”

Position2 initially partnered with a consultant in 2020 to achieve ISO 27001:2013 compliance. However, the initiative was put on hold due to the COVID-19 pandemic. When they resumed the project in 2022, they opted for a platform-driven approach to compliance and audits.

Previously, implementing the compliance framework was fragmented and disruptive. The security team had to manually enforce security training, policy acknowledgments, and best practices, making it challenging to align stakeholders. Additionally, consultants failed to unify compliance efforts, often diverting resources from critical business tasks.

Position2 recognized the need for a compliance platform that was simple to use, featured extensive integrations, and automated security housekeeping. After evaluating multiple solutions, Position2 selected Sprinto for its superior support and integrations, ensuring they could achieve ISO 27001:2022 and SOC 2 compliance within the required 60-90 day timeframe.

The Sprinto team was approachable and provided a clear understanding of the platform, expectations, scope of work, and how we could meet our compliance goals together. Most importantly, Sprinto gave us confidence to meet our deadlines.

The Solution: Automation-driven compliance for enhanced security

Upon onboarding Sprinto, Position2 focused on key risk areas, including vendors, personnel, devices, and cloud infrastructure. Sprinto’s pre-built policies, training modules, cloud integrations, risk registers, and Mobile Device Management (MDM) tools allowed Position2 to define SOC 2 Type 2 and ISO 27001:2022 compliance boundaries.

With compliance controls in place, Position2 launched near real-time monitoring for critical cloud tools used in email, project management, and marketing operations. They also implemented customized controls for multi-factor authentication (MFA), GitHub and AWS access restrictions, and admin privileges, ensuring their security practices met compliance standards.

Within two weeks, Position2 had achieved 60% readiness for ISO 27001:2022 and SOC 2 Type 2 audits. Over the following week, the team worked with Sprinto’s support to address control gaps and fine-tune their compliance processes, thoroughly preparing them for their audits.

Before Sprinto, Position2 used internal and offline processes to review data security regularly. However, there was no centralized visibility, and access rules were sometimes applied inconsistently. Sprinto provided a structured and transparent approach, ensuring access was need-based, and integrity was consistently upheld. Now, every security decision has a clear compliance rationale.

The Results: A strong security posture and compliance by default

Position2 successfully completed back-to-back ISO 27001:2022 and SOC 2 Type 2 audits within two months, achieving compliance with zero findings.

“Sprinto ensured we were audit-ready on time, which was crucial since delays would have been costly. It was our first compliance audit, yet we encountered no bottlenecks or surprises,” says Prabagaran.

Beyond compliance reporting, Position2 established a governance-aligned compliance culture. Over two years, they standardized onboarding and offboarding practices across two business units, reinforced data security protocols, and maintained clear visibility into data access controls, fostering organizational confidence in security.

“Previously, onboarding new employees meant weeks of IT follow-ups. Now, Sprinto centralizes policies, training, and monitoring, streamlining the process. Employees also understand how data security aligns with compliance, fostering responsible data handling.”

Sprinto also provided centralized visibility into the org’s cloud assets, including AWS, GCP, and GitHub repositories, allowing for immediate resolution of compliance gaps and solidifying data management practices.

One of the most significant improvements was in code vulnerability management. Sprinto’s monitoring capabilities surfaced risks in code repositories, helping Position2 instill a compliance-first approach to software development.

“Our developers now code with compliance in mind, proactively fixing vulnerabilities. This shift has significantly improved our security culture,” Prabagaran adds.

As a result, Position2 accelerated vulnerability fixes by 60-70%, reducing the time spent on triaging security issues. Weekly vulnerabilities dropped from 10-20 to single digits, sometimes appearing only once a month. Security compliance became second nature to the team.

With ISO 27001:2022 and SOC 2 Type 2 certifications secured, Position2 is now preparing to get compliant with HIPAA, further strengthening its presence in the healthcare sector. The security posture built with Sprinto has enabled Position2 to streamline internal processes while embedding best practices and confidence in data security.

With Sprinto, we’ve created a system where compliance is the default. There’s no ambiguity—everyone understands the importance of securing data, giving us internal and external confidence.