SlideShare a Scribd company logo
1 of 26
Building cybersecurity
transparency with
clients using
compliance
automation tools Iurii Garasym
Chief Information Officer, ELEKS
AGENDA
01 02 03
About ELEKS New Elements in
Building Trust in
Value Delivery
Chain
ELEKS case of
building trust
using eCAP
Vision for
3rd party risk
management
04
01
About
ELEKS
The custom
software
development
and innovations
company
We are a technology partner
of choice for complex and
innovative software
development projects.
We have been delivering value
to our clients thanks to our
expertise and experience gained
from working as a software
innovation partner since 1991.
88%
Master’s
Degree
4%
PhDs &
MBAs
31 A Top 100 Global
Outsourcing
Company
years of
experience
We focus
on complex tasks
Long-term
partnerships
with clients
Deep
technical
expertise
Top
scientific
talent
Tallinn
Al Jubail
Ajman
Zürich
Berlin
Krakov
Rzeszów
Zagreb
Split
Toronto
Chicago
Las Vegas
Tokyo
Headquarters
Development Centre
International Office
Partner
Affiliate
Lviv
Kyiv
Ternopil
Ivano-Frankivsk
London
Global Presence
18 offices
2,300+
total global
headcount
1,800+
delivery
experts
Award-winning vendor More awards Featured in the media More publications
Our
clients
Milano
Copenhagen
Madrid
London Berlin
Birmingham Amsterdam
Munich
Kyiv
Stockholm
Paris
Amman
Dubai
Tokyo
San Francisco
Seattle
Kalispell Minneapolis
Detroit
Philadelphia
Raleigh
Washington
Chicago
New York
Boston
Tel-Aviv
Singapore
Geneva
Zurich
Basel
Brussels
Lyon
end-to-end solutions
delivered
700+
of clients do more than
one project with us
90%
years of cooperation
with our oldest clients
20+
active client
accounts
150+
We build long-term
partnerships with industry
leaders and technology
challengers to create truly
transformative results
``` ```
ISO 27001 ISO 9001
```
```
SOC2
HITRUST
```
GDPR
Certifications and frameworks
In progress with:​
```
CREST
* ISMS - Information Security Management System
QMS - Quality Management System
ELEKS is a company with well-
established quality management,
cybersecurity, data privacy and
business continuity processes in
line with international standards
There was not a single service
outage or security breach in our
history, including the period of
Russian invasion to Ukraine
In 2023 ELEKS successfully
passed annual re-certification
process for ISO9001, ISO27002,
SOC2 and is continuously
improving its compliance posture
with more certifications in pipeline
ELEKS – ISMS/QMS*
New Elements in
Building Trust in
Value Delivery Chain
02
Every organization exists in multiple
business ecosystems. These business
ecosystems are dynamic networks of
entities interacting with each other to
create and exchange sustainable value
for participants. The challenge is
deciding how your organization will
survive and thrive in its ecosystem.”
Andriy Krupa,
CEO ELEKS
“To deliver value to the end
customer, you need to play the
team game. You need to partner
both with your vendors and your
customers in order to create and
exchange sustainable value.
Your need trust, collaboration
and agility.”
Trust is necessary for
collaboration and
innovation.
To establish and maintain trust,
companies have to address
several components: Quality,
Security, Compliance, Privacy,
Transparency
Having the enabling
tools and technologies
to build this trust is
important.
Such technologies speed up
business interactions and build
trust across geographies, while
helping companies to deliver
value with lower operational costs.
1. Value continues to
migrate online:
Cloud, Big Data
2. Corporations are
expected to be more
‘open’ than ever before
3. Everything
is connected
4. Supply chains are
increasingly
interconnected.
Difficult to know what you even own,
difficult to analyze
Mobile, Social Networks, IoT, BYOx (bring
your own device / app …) are an easy point
of entry into corporate networks for malware
Everything is vulnerable
No perimeter any more. Companies are
encouraging vendors and customers
to join their networks
Trends in business
SECURITY VENDORS MAP
Tons of data + tons of
alerts. You can’t sit more
people to deal with it
Lack of budget, people,
skills, management
support… or decision
making
Security
technology
silos
Algorithms, machine learning,
AI are already on our side, but still
100+ days to discover a breach,
gaps in compliance obligations
03
ELEKS case
Building trust
using eCAP
The opportunity
Expensive
The cost of compliance is
growing while the
companies mostly fail to
improve their compliance
process assurance for
senior management
Manual
Personel account for 79%
of compliance costs
Complex
As the number of
regulations constantly
grows, the complexity of
compliance process also
exponentially increases
Inaccurate
The high rate of human
errors for repetitive high-
volume compliance tasks
puts companies at risk of
penalties
Inefficient
Companies struggle to
enforce all the
requirements and
continuously ensure they
work as intended
Today, most companies are
struggling to build proper
compliance workflow.
Compliance with customer
requirements, industry best
practices, regulations or
even their own requirements.
They characterize their
current processes as:
Cost-efficient
Compliance process in your
organization becomes
manageable along with a
50% decrease in cost
Scalable
You will be able to handle an
increase in transaction volume
without any negative impact on
operational expenses
Capable
You will establish a robust
onboarding process for new
regulatory requirements
Reliable
While algorithms will handle most
compliance cases, your experts will
have an opportunity to review the
exceptions carefully and achieve
near-zero error rates
What if there was a single tool that made
the compliance process a lot easier?
The solution
COMPLIANCE AUTOMATION PLATFORM GOALS
eCAP is an advanced
GRC (Governance, Risk and
Compliance) tool that helps to:
• Reduce costs by automation of
information security governance
activities (policies/controls design)
• Perform comprehensive security
and risk management monitoring
• Improve efficiency of internal
audits and success rate of
external certification audits
(ISO27002, SOC2, HITRUST)
More info is available on eCAP landing page: eleks.com
Generate
Information
Security policies
Generate Information
Security policies based on
applicable standards and
allow convenient
management of the
documents (review/approval
flow, version tracking,
retention in line with records
management requirements)
Compliance score
and security
controls reporting
Connect to various data
sources and obtain the
details on actual situation
with information security
controls. Both operational
and strategic level reporting
are available.
Enable Security
monitoring for
clients
Based on data collected
create easy to read
reporting for your clients
regarding security controls
on their projects. Multiple
clients can be handled at
the same time individually
defining the scope for
monitoring.
Reduce efforts
for certification
audits
All the data
created/collected in eCAP is
connected to original
requirements from
standards and allows to
instantly generate
evidences for auditors
Gather regulatory
and standards
related updates
Collect and auto-tag the
news to be up to date with
changes in regulatory
landscape
ELEKS COMPLIANCE AUTOMATION PLATFORM FEATURES
News Feed
Standards/
Policies/Controls Dashboards
Compliance
Score
Map and Gap
reporting
eCAP – Cybersecurity
Excellence Awards
Cybersecurity Excellence
Awards recognizes
companies, products and
professionals that
demonstrate excellence,
innovation and leadership
in information security.
More details available at:
cybersecurity-excellence-awards.com
The awards are produced by
Cybersecurity Insiders in partnership
with the Information Security
Community on LinkedIn, tapping into
the vast experience of over 400,000+
cybersecurity professionals to honor
the world’s best cybersecurity products,
professionals and organizations.
eCAP for ELEKS clients
ELEKS provides eCAP to clients in order
to introduce transparency and build trust.
Clients using eCAP have 24/7 access to
metrics calculated for their projects.
eCAP is aiming to become a single reporting window with our clients
Employees
General information for employees
working on the project, information
security trainings and monitoring
of obsolete accounts.
Endpoints
Metrics covering endpoints being
used by specialists on the projects
(OS updates, anti-malware, disk
encryption, etc.)
Additional metrics
There are additional metrics
present in our pipeline. They will
be introduced automatically on
the dashboards once released.
eCAP helps ELEKS clients to:
• Perform independent 24/7
monitoring of security metrics and
events on their projects
• Simplify the process of information
security audit of ELEKS as a vendor
ECAP: PROACTIVE APPROACH – CLIENT IS AUDITS
eCAP
(on-prem) eCAP SaaS
Client C
ELEKS
EU Data Center
Access to SaaS
Client A
ELEKS IS Solutions
(IAM, SIEM, Anti-Malware, Ticketing
System, HRMS, etc.)
Information
Security related
data feeds
Processing of data and generation
of security metricsc
eCAP SaaS
Client B
eCAP SaaS
Client A
EU/US
Microsoft Azure
Access to SaaS
Client B
Access to SaaS
Client C
Client Team
Client Team
Client Team
CASE STUDY
DELIVERED SOLUTION
eCAP as an advanced GRC
(Governance, Risk and
Compliance) tool helped to:
• Reduce costs by
automation of information
security activities and
certification audits
• Improve transparency by
allowing to monitor security
on their projects
• Support business growth by
enabling robust/predictable
certification process and
“distinctive” information
security capabilities
GOAL
Build a single pane of glass on
security compliance and introduce new
standard for risk management and
trust on software development market.
Improved efficiency
of compliance and risk
management
governance
ELEKS COMPLIANCE
AUTOMATION PLATFORM
CUSTOMER
Large IT company with delivery
centers in Europe and USA.
25% 60% 40%
Certification
audits
Controls
execution
Client InfoSec
audits
Savings up to:
04
Vision for 3rd party
risk management
What’s next?
• External audits
• External scanning
• 3rd party reporting
Standardized data feeds
to assess 3rd party IS
posture assessment
Pre-requisites
Ongoing update of IS requirements
Outcome
Real time reporting and remediation
of the incidents (cut-off)
Cost-saving for 3rd party assessments
and incident management
Continuous assurance
VISION FOR 3rd PARTY RISK MANAGEMENT
Vendor A
(continuous monitoring – internal controls)
Independent assessment
(continuous monitoring – external scanning of Vendors A and B)
Compliance
management team
GRC solution
Vendor B
(continuous monitoring – internal controls)
Security auditor
Independent assessment
(periodical IS processes assurance of Vendors A and B)
(organization IS requirements as a feed from GRC)
Security vendor
Vendor A
Vendor B
Standardized
IS controls
reporting
Have a question? Write to
info@eleks.com
Find us at
eleks.com
Thank you
for your attention!
Iurii Garasym
Chief Information Officer, ELEKS
Questions
& Answers

More Related Content

Similar to Building cybersecurity transparency with clients using compliance automation tools

Blue Bricks Business Collateral
Blue Bricks Business CollateralBlue Bricks Business Collateral
Blue Bricks Business CollateralVikram Sareen
 
Towards Hybrid Strategies - 451 Research & Atos
Towards Hybrid Strategies - 451 Research & AtosTowards Hybrid Strategies - 451 Research & Atos
Towards Hybrid Strategies - 451 Research & AtosCsilla Zsigri
 
Fortify-Application_Security_Foundation_Training.pptx
Fortify-Application_Security_Foundation_Training.pptxFortify-Application_Security_Foundation_Training.pptx
Fortify-Application_Security_Foundation_Training.pptxYoisRoberthTapiadeLa
 
Fortify-Application_Security_Foundation_Training.pptx
Fortify-Application_Security_Foundation_Training.pptxFortify-Application_Security_Foundation_Training.pptx
Fortify-Application_Security_Foundation_Training.pptxVictoriaChavesta
 
Huwei Cyber Security Presentation
Huwei Cyber Security PresentationHuwei Cyber Security Presentation
Huwei Cyber Security PresentationPeter921148
 
Embracing secure, scalable BYOD with Sencha and Centrify
Embracing secure, scalable BYOD with Sencha and CentrifyEmbracing secure, scalable BYOD with Sencha and Centrify
Embracing secure, scalable BYOD with Sencha and CentrifySumana Mehta
 
The Journey to Digital Enterprise, presented by CSC
The Journey to Digital Enterprise, presented by CSCThe Journey to Digital Enterprise, presented by CSC
The Journey to Digital Enterprise, presented by CSCAmazon Web Services
 
Risk management for cloud computing hb final
Risk management for cloud computing hb finalRisk management for cloud computing hb final
Risk management for cloud computing hb finalChristophe Monnier
 
Presentación Dell, Omega Peripherals e Intel: El centro de datos eficiente (1...
Presentación Dell, Omega Peripherals e Intel: El centro de datos eficiente (1...Presentación Dell, Omega Peripherals e Intel: El centro de datos eficiente (1...
Presentación Dell, Omega Peripherals e Intel: El centro de datos eficiente (1...Omega Peripherals
 
Success with APIs: A Checklist
Success with APIs: A ChecklistSuccess with APIs: A Checklist
Success with APIs: A ChecklistCA Technologies
 
CloudHealth Boston Presentation
CloudHealth Boston PresentationCloudHealth Boston Presentation
CloudHealth Boston PresentationAlert Logic
 
Cybersecurity | Meta Networks: Software defined perimeter platform
Cybersecurity | Meta Networks: Software defined perimeter platformCybersecurity | Meta Networks: Software defined perimeter platform
Cybersecurity | Meta Networks: Software defined perimeter platformVertex Holdings
 
Keynote: Future of IT - future of enterprise it Canada
Keynote: Future of IT - future of enterprise it CanadaKeynote: Future of IT - future of enterprise it Canada
Keynote: Future of IT - future of enterprise it CanadaAmazon Web Services
 
Bill_Haase_Resume Dec 2015
Bill_Haase_Resume Dec 2015Bill_Haase_Resume Dec 2015
Bill_Haase_Resume Dec 2015Bill Haase
 
Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]
Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]
Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]Tudor Damian
 
How Large Enterprises Use Platform Governance to Gain Agility
How Large Enterprises Use Platform Governance to Gain AgilityHow Large Enterprises Use Platform Governance to Gain Agility
How Large Enterprises Use Platform Governance to Gain AgilityOdaseva
 

Similar to Building cybersecurity transparency with clients using compliance automation tools (20)

Blue Bricks Business Collateral
Blue Bricks Business CollateralBlue Bricks Business Collateral
Blue Bricks Business Collateral
 
Towards Hybrid Strategies - 451 Research & Atos
Towards Hybrid Strategies - 451 Research & AtosTowards Hybrid Strategies - 451 Research & Atos
Towards Hybrid Strategies - 451 Research & Atos
 
Company_Profile_Updated_17032016
Company_Profile_Updated_17032016Company_Profile_Updated_17032016
Company_Profile_Updated_17032016
 
Fortify-Application_Security_Foundation_Training.pptx
Fortify-Application_Security_Foundation_Training.pptxFortify-Application_Security_Foundation_Training.pptx
Fortify-Application_Security_Foundation_Training.pptx
 
Fortify-Application_Security_Foundation_Training.pptx
Fortify-Application_Security_Foundation_Training.pptxFortify-Application_Security_Foundation_Training.pptx
Fortify-Application_Security_Foundation_Training.pptx
 
CCSK.pptx
CCSK.pptxCCSK.pptx
CCSK.pptx
 
Many products-no-security (1)
Many products-no-security (1)Many products-no-security (1)
Many products-no-security (1)
 
Huwei Cyber Security Presentation
Huwei Cyber Security PresentationHuwei Cyber Security Presentation
Huwei Cyber Security Presentation
 
Embracing secure, scalable BYOD with Sencha and Centrify
Embracing secure, scalable BYOD with Sencha and CentrifyEmbracing secure, scalable BYOD with Sencha and Centrify
Embracing secure, scalable BYOD with Sencha and Centrify
 
The Journey to Digital Enterprise, presented by CSC
The Journey to Digital Enterprise, presented by CSCThe Journey to Digital Enterprise, presented by CSC
The Journey to Digital Enterprise, presented by CSC
 
Risk management for cloud computing hb final
Risk management for cloud computing hb finalRisk management for cloud computing hb final
Risk management for cloud computing hb final
 
Presentación Dell, Omega Peripherals e Intel: El centro de datos eficiente (1...
Presentación Dell, Omega Peripherals e Intel: El centro de datos eficiente (1...Presentación Dell, Omega Peripherals e Intel: El centro de datos eficiente (1...
Presentación Dell, Omega Peripherals e Intel: El centro de datos eficiente (1...
 
Success with APIs: A Checklist
Success with APIs: A ChecklistSuccess with APIs: A Checklist
Success with APIs: A Checklist
 
CloudHealth Boston Presentation
CloudHealth Boston PresentationCloudHealth Boston Presentation
CloudHealth Boston Presentation
 
NG-Brochure
NG-BrochureNG-Brochure
NG-Brochure
 
Cybersecurity | Meta Networks: Software defined perimeter platform
Cybersecurity | Meta Networks: Software defined perimeter platformCybersecurity | Meta Networks: Software defined perimeter platform
Cybersecurity | Meta Networks: Software defined perimeter platform
 
Keynote: Future of IT - future of enterprise it Canada
Keynote: Future of IT - future of enterprise it CanadaKeynote: Future of IT - future of enterprise it Canada
Keynote: Future of IT - future of enterprise it Canada
 
Bill_Haase_Resume Dec 2015
Bill_Haase_Resume Dec 2015Bill_Haase_Resume Dec 2015
Bill_Haase_Resume Dec 2015
 
Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]
Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]
Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]
 
How Large Enterprises Use Platform Governance to Gain Agility
How Large Enterprises Use Platform Governance to Gain AgilityHow Large Enterprises Use Platform Governance to Gain Agility
How Large Enterprises Use Platform Governance to Gain Agility
 

More from ELEKS

Product Design Meetup in Copenhagen
Product Design Meetup in CopenhagenProduct Design Meetup in Copenhagen
Product Design Meetup in CopenhagenELEKS
 
The Perfect Blend: Combining Juicer Expertise with Digital Excellence at Joe ...
The Perfect Blend: Combining Juicer Expertise with Digital Excellence at Joe ...The Perfect Blend: Combining Juicer Expertise with Digital Excellence at Joe ...
The Perfect Blend: Combining Juicer Expertise with Digital Excellence at Joe ...ELEKS
 
Leading Innovation: How People-Centric Strategies Drive Sustainable Change in...
Leading Innovation: How People-Centric Strategies Drive Sustainable Change in...Leading Innovation: How People-Centric Strategies Drive Sustainable Change in...
Leading Innovation: How People-Centric Strategies Drive Sustainable Change in...ELEKS
 
Digital Transformation Overview
Digital Transformation OverviewDigital Transformation Overview
Digital Transformation OverviewELEKS
 
Cyber Security by Design in the AI Era
Cyber Security by Design in the AI EraCyber Security by Design in the AI Era
Cyber Security by Design in the AI EraELEKS
 
UX for AI-Powered Products: Balancing Magic and User Trust
UX for AI-Powered Products: Balancing Magic and User Trust UX for AI-Powered Products: Balancing Magic and User Trust
UX for AI-Powered Products: Balancing Magic and User Trust ELEKS
 
Securing the ChatGPT in your organization
Securing the ChatGPT in your organizationSecuring the ChatGPT in your organization
Securing the ChatGPT in your organizationELEKS
 
How to win the tech talent race and stay competitive
How to win the tech talent race and stay competitiveHow to win the tech talent race and stay competitive
How to win the tech talent race and stay competitiveELEKS
 
Putting sustainability at the heart of your company's development benefits an...
Putting sustainability at the heart of your company's development benefits an...Putting sustainability at the heart of your company's development benefits an...
Putting sustainability at the heart of your company's development benefits an...ELEKS
 
How product designer drive organizational transformation
How product designer drive organizational transformationHow product designer drive organizational transformation
How product designer drive organizational transformationELEKS
 
Design in startup / scale-up
Design in startup / scale-upDesign in startup / scale-up
Design in startup / scale-upELEKS
 
Building innovation pipeline with service design methods
Building innovation pipeline with service design methodsBuilding innovation pipeline with service design methods
Building innovation pipeline with service design methodsELEKS
 
How to succeed in building an international product team
How to succeed in building an international product teamHow to succeed in building an international product team
How to succeed in building an international product teamELEKS
 
Gitex 2021: Automation on Steroids: Robotics + AI
Gitex 2021: Automation on Steroids: Robotics + AI Gitex 2021: Automation on Steroids: Robotics + AI
Gitex 2021: Automation on Steroids: Robotics + AI ELEKS
 
ELEKS Switzerland office opening, Oct 2021
ELEKS Switzerland office opening, Oct 2021ELEKS Switzerland office opening, Oct 2021
ELEKS Switzerland office opening, Oct 2021ELEKS
 
Webinar: Effiziente Digitalisierungsstrategien für den Mittelstand
Webinar: Effiziente Digitalisierungsstrategien für den Mittelstand  Webinar: Effiziente Digitalisierungsstrategien für den Mittelstand
Webinar: Effiziente Digitalisierungsstrategien für den Mittelstand ELEKS
 
Design and Sustainability
Design and SustainabilityDesign and Sustainability
Design and SustainabilityELEKS
 
ELEKS Product Design Workshop: Creating Sustainable Value_Materials
ELEKS Product Design Workshop: Creating Sustainable Value_MaterialsELEKS Product Design Workshop: Creating Sustainable Value_Materials
ELEKS Product Design Workshop: Creating Sustainable Value_MaterialsELEKS
 
"Center Out" Business Architecture. Creating a Responsive Omnichannel Custome...
"Center Out" Business Architecture. Creating a Responsive Omnichannel Custome..."Center Out" Business Architecture. Creating a Responsive Omnichannel Custome...
"Center Out" Business Architecture. Creating a Responsive Omnichannel Custome...ELEKS
 
Digitization of Telecom and Smartphone Business: Post-COVID-19 Effects on the...
Digitization of Telecom and Smartphone Business: Post-COVID-19 Effects on the...Digitization of Telecom and Smartphone Business: Post-COVID-19 Effects on the...
Digitization of Telecom and Smartphone Business: Post-COVID-19 Effects on the...ELEKS
 

More from ELEKS (20)

Product Design Meetup in Copenhagen
Product Design Meetup in CopenhagenProduct Design Meetup in Copenhagen
Product Design Meetup in Copenhagen
 
The Perfect Blend: Combining Juicer Expertise with Digital Excellence at Joe ...
The Perfect Blend: Combining Juicer Expertise with Digital Excellence at Joe ...The Perfect Blend: Combining Juicer Expertise with Digital Excellence at Joe ...
The Perfect Blend: Combining Juicer Expertise with Digital Excellence at Joe ...
 
Leading Innovation: How People-Centric Strategies Drive Sustainable Change in...
Leading Innovation: How People-Centric Strategies Drive Sustainable Change in...Leading Innovation: How People-Centric Strategies Drive Sustainable Change in...
Leading Innovation: How People-Centric Strategies Drive Sustainable Change in...
 
Digital Transformation Overview
Digital Transformation OverviewDigital Transformation Overview
Digital Transformation Overview
 
Cyber Security by Design in the AI Era
Cyber Security by Design in the AI EraCyber Security by Design in the AI Era
Cyber Security by Design in the AI Era
 
UX for AI-Powered Products: Balancing Magic and User Trust
UX for AI-Powered Products: Balancing Magic and User Trust UX for AI-Powered Products: Balancing Magic and User Trust
UX for AI-Powered Products: Balancing Magic and User Trust
 
Securing the ChatGPT in your organization
Securing the ChatGPT in your organizationSecuring the ChatGPT in your organization
Securing the ChatGPT in your organization
 
How to win the tech talent race and stay competitive
How to win the tech talent race and stay competitiveHow to win the tech talent race and stay competitive
How to win the tech talent race and stay competitive
 
Putting sustainability at the heart of your company's development benefits an...
Putting sustainability at the heart of your company's development benefits an...Putting sustainability at the heart of your company's development benefits an...
Putting sustainability at the heart of your company's development benefits an...
 
How product designer drive organizational transformation
How product designer drive organizational transformationHow product designer drive organizational transformation
How product designer drive organizational transformation
 
Design in startup / scale-up
Design in startup / scale-upDesign in startup / scale-up
Design in startup / scale-up
 
Building innovation pipeline with service design methods
Building innovation pipeline with service design methodsBuilding innovation pipeline with service design methods
Building innovation pipeline with service design methods
 
How to succeed in building an international product team
How to succeed in building an international product teamHow to succeed in building an international product team
How to succeed in building an international product team
 
Gitex 2021: Automation on Steroids: Robotics + AI
Gitex 2021: Automation on Steroids: Robotics + AI Gitex 2021: Automation on Steroids: Robotics + AI
Gitex 2021: Automation on Steroids: Robotics + AI
 
ELEKS Switzerland office opening, Oct 2021
ELEKS Switzerland office opening, Oct 2021ELEKS Switzerland office opening, Oct 2021
ELEKS Switzerland office opening, Oct 2021
 
Webinar: Effiziente Digitalisierungsstrategien für den Mittelstand
Webinar: Effiziente Digitalisierungsstrategien für den Mittelstand  Webinar: Effiziente Digitalisierungsstrategien für den Mittelstand
Webinar: Effiziente Digitalisierungsstrategien für den Mittelstand
 
Design and Sustainability
Design and SustainabilityDesign and Sustainability
Design and Sustainability
 
ELEKS Product Design Workshop: Creating Sustainable Value_Materials
ELEKS Product Design Workshop: Creating Sustainable Value_MaterialsELEKS Product Design Workshop: Creating Sustainable Value_Materials
ELEKS Product Design Workshop: Creating Sustainable Value_Materials
 
"Center Out" Business Architecture. Creating a Responsive Omnichannel Custome...
"Center Out" Business Architecture. Creating a Responsive Omnichannel Custome..."Center Out" Business Architecture. Creating a Responsive Omnichannel Custome...
"Center Out" Business Architecture. Creating a Responsive Omnichannel Custome...
 
Digitization of Telecom and Smartphone Business: Post-COVID-19 Effects on the...
Digitization of Telecom and Smartphone Business: Post-COVID-19 Effects on the...Digitization of Telecom and Smartphone Business: Post-COVID-19 Effects on the...
Digitization of Telecom and Smartphone Business: Post-COVID-19 Effects on the...
 

Recently uploaded

Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service DewasVip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewasmakika9823
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service PuneVIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service PuneCall girls in Ahmedabad High profile
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Roomdivyansh0kumar0
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechNewman George Leech
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsApsara Of India
 
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc.../:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...lizamodels9
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessAggregage
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Tina Ji
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...lizamodels9
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfmuskan1121w
 

Recently uploaded (20)

Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service DewasVip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service PuneVIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman Leech
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
 
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc.../:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
/:Call Girls In Jaypee Siddharth - 5 Star Hotel New Delhi ➥9990211544 Top Esc...
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for Success
 
KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdf
 

Building cybersecurity transparency with clients using compliance automation tools

  • 1. Building cybersecurity transparency with clients using compliance automation tools Iurii Garasym Chief Information Officer, ELEKS
  • 2. AGENDA 01 02 03 About ELEKS New Elements in Building Trust in Value Delivery Chain ELEKS case of building trust using eCAP Vision for 3rd party risk management 04
  • 4. The custom software development and innovations company We are a technology partner of choice for complex and innovative software development projects. We have been delivering value to our clients thanks to our expertise and experience gained from working as a software innovation partner since 1991. 88% Master’s Degree 4% PhDs & MBAs 31 A Top 100 Global Outsourcing Company years of experience We focus on complex tasks Long-term partnerships with clients Deep technical expertise Top scientific talent
  • 5. Tallinn Al Jubail Ajman Zürich Berlin Krakov Rzeszów Zagreb Split Toronto Chicago Las Vegas Tokyo Headquarters Development Centre International Office Partner Affiliate Lviv Kyiv Ternopil Ivano-Frankivsk London Global Presence 18 offices 2,300+ total global headcount 1,800+ delivery experts Award-winning vendor More awards Featured in the media More publications
  • 6. Our clients Milano Copenhagen Madrid London Berlin Birmingham Amsterdam Munich Kyiv Stockholm Paris Amman Dubai Tokyo San Francisco Seattle Kalispell Minneapolis Detroit Philadelphia Raleigh Washington Chicago New York Boston Tel-Aviv Singapore Geneva Zurich Basel Brussels Lyon end-to-end solutions delivered 700+ of clients do more than one project with us 90% years of cooperation with our oldest clients 20+ active client accounts 150+ We build long-term partnerships with industry leaders and technology challengers to create truly transformative results
  • 7. ``` ``` ISO 27001 ISO 9001 ``` ``` SOC2 HITRUST ``` GDPR Certifications and frameworks In progress with:​ ``` CREST * ISMS - Information Security Management System QMS - Quality Management System ELEKS is a company with well- established quality management, cybersecurity, data privacy and business continuity processes in line with international standards There was not a single service outage or security breach in our history, including the period of Russian invasion to Ukraine In 2023 ELEKS successfully passed annual re-certification process for ISO9001, ISO27002, SOC2 and is continuously improving its compliance posture with more certifications in pipeline ELEKS – ISMS/QMS*
  • 8. New Elements in Building Trust in Value Delivery Chain 02
  • 9. Every organization exists in multiple business ecosystems. These business ecosystems are dynamic networks of entities interacting with each other to create and exchange sustainable value for participants. The challenge is deciding how your organization will survive and thrive in its ecosystem.” Andriy Krupa, CEO ELEKS “To deliver value to the end customer, you need to play the team game. You need to partner both with your vendors and your customers in order to create and exchange sustainable value. Your need trust, collaboration and agility.”
  • 10. Trust is necessary for collaboration and innovation. To establish and maintain trust, companies have to address several components: Quality, Security, Compliance, Privacy, Transparency Having the enabling tools and technologies to build this trust is important. Such technologies speed up business interactions and build trust across geographies, while helping companies to deliver value with lower operational costs.
  • 11. 1. Value continues to migrate online: Cloud, Big Data 2. Corporations are expected to be more ‘open’ than ever before 3. Everything is connected 4. Supply chains are increasingly interconnected. Difficult to know what you even own, difficult to analyze Mobile, Social Networks, IoT, BYOx (bring your own device / app …) are an easy point of entry into corporate networks for malware Everything is vulnerable No perimeter any more. Companies are encouraging vendors and customers to join their networks Trends in business
  • 12. SECURITY VENDORS MAP Tons of data + tons of alerts. You can’t sit more people to deal with it Lack of budget, people, skills, management support… or decision making Security technology silos Algorithms, machine learning, AI are already on our side, but still 100+ days to discover a breach, gaps in compliance obligations
  • 14. The opportunity Expensive The cost of compliance is growing while the companies mostly fail to improve their compliance process assurance for senior management Manual Personel account for 79% of compliance costs Complex As the number of regulations constantly grows, the complexity of compliance process also exponentially increases Inaccurate The high rate of human errors for repetitive high- volume compliance tasks puts companies at risk of penalties Inefficient Companies struggle to enforce all the requirements and continuously ensure they work as intended Today, most companies are struggling to build proper compliance workflow. Compliance with customer requirements, industry best practices, regulations or even their own requirements. They characterize their current processes as:
  • 15. Cost-efficient Compliance process in your organization becomes manageable along with a 50% decrease in cost Scalable You will be able to handle an increase in transaction volume without any negative impact on operational expenses Capable You will establish a robust onboarding process for new regulatory requirements Reliable While algorithms will handle most compliance cases, your experts will have an opportunity to review the exceptions carefully and achieve near-zero error rates What if there was a single tool that made the compliance process a lot easier? The solution
  • 16. COMPLIANCE AUTOMATION PLATFORM GOALS eCAP is an advanced GRC (Governance, Risk and Compliance) tool that helps to: • Reduce costs by automation of information security governance activities (policies/controls design) • Perform comprehensive security and risk management monitoring • Improve efficiency of internal audits and success rate of external certification audits (ISO27002, SOC2, HITRUST) More info is available on eCAP landing page: eleks.com
  • 17. Generate Information Security policies Generate Information Security policies based on applicable standards and allow convenient management of the documents (review/approval flow, version tracking, retention in line with records management requirements) Compliance score and security controls reporting Connect to various data sources and obtain the details on actual situation with information security controls. Both operational and strategic level reporting are available. Enable Security monitoring for clients Based on data collected create easy to read reporting for your clients regarding security controls on their projects. Multiple clients can be handled at the same time individually defining the scope for monitoring. Reduce efforts for certification audits All the data created/collected in eCAP is connected to original requirements from standards and allows to instantly generate evidences for auditors Gather regulatory and standards related updates Collect and auto-tag the news to be up to date with changes in regulatory landscape ELEKS COMPLIANCE AUTOMATION PLATFORM FEATURES News Feed Standards/ Policies/Controls Dashboards Compliance Score Map and Gap reporting
  • 18. eCAP – Cybersecurity Excellence Awards Cybersecurity Excellence Awards recognizes companies, products and professionals that demonstrate excellence, innovation and leadership in information security. More details available at: cybersecurity-excellence-awards.com The awards are produced by Cybersecurity Insiders in partnership with the Information Security Community on LinkedIn, tapping into the vast experience of over 400,000+ cybersecurity professionals to honor the world’s best cybersecurity products, professionals and organizations.
  • 19. eCAP for ELEKS clients ELEKS provides eCAP to clients in order to introduce transparency and build trust. Clients using eCAP have 24/7 access to metrics calculated for their projects. eCAP is aiming to become a single reporting window with our clients Employees General information for employees working on the project, information security trainings and monitoring of obsolete accounts. Endpoints Metrics covering endpoints being used by specialists on the projects (OS updates, anti-malware, disk encryption, etc.) Additional metrics There are additional metrics present in our pipeline. They will be introduced automatically on the dashboards once released. eCAP helps ELEKS clients to: • Perform independent 24/7 monitoring of security metrics and events on their projects • Simplify the process of information security audit of ELEKS as a vendor
  • 20. ECAP: PROACTIVE APPROACH – CLIENT IS AUDITS eCAP (on-prem) eCAP SaaS Client C ELEKS EU Data Center Access to SaaS Client A ELEKS IS Solutions (IAM, SIEM, Anti-Malware, Ticketing System, HRMS, etc.) Information Security related data feeds Processing of data and generation of security metricsc eCAP SaaS Client B eCAP SaaS Client A EU/US Microsoft Azure Access to SaaS Client B Access to SaaS Client C Client Team Client Team Client Team
  • 21. CASE STUDY DELIVERED SOLUTION eCAP as an advanced GRC (Governance, Risk and Compliance) tool helped to: • Reduce costs by automation of information security activities and certification audits • Improve transparency by allowing to monitor security on their projects • Support business growth by enabling robust/predictable certification process and “distinctive” information security capabilities GOAL Build a single pane of glass on security compliance and introduce new standard for risk management and trust on software development market. Improved efficiency of compliance and risk management governance ELEKS COMPLIANCE AUTOMATION PLATFORM CUSTOMER Large IT company with delivery centers in Europe and USA. 25% 60% 40% Certification audits Controls execution Client InfoSec audits Savings up to:
  • 22. 04 Vision for 3rd party risk management
  • 23. What’s next? • External audits • External scanning • 3rd party reporting Standardized data feeds to assess 3rd party IS posture assessment Pre-requisites Ongoing update of IS requirements Outcome Real time reporting and remediation of the incidents (cut-off) Cost-saving for 3rd party assessments and incident management Continuous assurance
  • 24. VISION FOR 3rd PARTY RISK MANAGEMENT Vendor A (continuous monitoring – internal controls) Independent assessment (continuous monitoring – external scanning of Vendors A and B) Compliance management team GRC solution Vendor B (continuous monitoring – internal controls) Security auditor Independent assessment (periodical IS processes assurance of Vendors A and B) (organization IS requirements as a feed from GRC) Security vendor Vendor A Vendor B Standardized IS controls reporting
  • 25. Have a question? Write to info@eleks.com Find us at eleks.com Thank you for your attention!
  • 26. Iurii Garasym Chief Information Officer, ELEKS Questions & Answers

Editor's Notes

  1. worldwide presence, clients everywhere and we are close all the time
  2. https://eufordigital.eu/e-card/what-exactly-is-trust-and-security-in-the-digital-field-is-it-just-about-cybersecurity/
  3. https://eufordigital.eu/e-card/what-exactly-is-trust-and-security-in-the-digital-field-is-it-just-about-cybersecurity/ Cybersecurity is very important in this context, can differentiate one company among others.
  4. About Sprint 0, stabilization, etc