Our clients have worked through the daunting and challenging task of achieving compliance with global security standards like SOC 2 and ISO 27001.
The approaches we see across clients vary significantly. There's different ways to assign responsibilities, work through the requirements, manage the audit process, and integrate "compliance" as a function of the business - ideally all without creating operating burden and onerous activities that drain time from other business priorities.
Our clients have kindly shared their best tips and insights from their practical experience working through it.
livepro
livepro is a Customer Experience Knowledge Management system used by organisations as their single source of truth to deliver “answers” to customers, not long documents or PDFs. The SOC 2 report gave livepro (a smaller company) a level of security prestige within the market. It also helped tighten up the operations by providing clear guidelines on the best practices for managing a business. Their CEO, Brad Shaw, shared his tips for others undertaking similar projects:
Taking things in bite-sized chunks enables you to action things within
the business as you go, rather than having a big bang approach. It allowed me to continue to run the business while also using the SOC
2 process to identify best practice management processes. Lots was
achieved without the stress of deadlines.
- Brad Shaw, Founder & CEO, livepro
Vic.ai
Vic.ai is the AI (artificial intelligence) platform for accounting firms and enterprise finance departments. The goal of their SOC 2 project was to pursue new business opportunities whilst also leveraging the report and its findings to improve their cyber posture. Project Manager, Paul Lubik, shares their insight from achieving SOC 2 Type 1 and SOC 2 Type 2:
What may appear as a daunting process is like any project. Identify the components and execute one by one. Test and validate and move on to the next component. SOC 2 will change the thinking of the team so make sure you get real buy in from the management team if you want to succeed. It needs the commitment and drive to accept the findings and being willing to put the solutions into practice.
- Paul Lubik, Project Manager, Plan Build Run Solutions
FileInvite
FileInvite transforms the way information and documents are collected by enterprise – hassle free and on time. For FileInvite to grow as a company, they needed to know any gaps in the business and provide the confidence to get bigger enterprise customers onboard that trust FileInvite with their data. Catherine Fromont, Operations Manager, shares her top tip from the SOC 2 Type 1 and SOC 2 Type 2 projects:
Get a spreadsheet and break down all of the controls and assign owners, this makes it so much easier to know everyones responsibilities!
- Catherine Fromont, Operations Manager, FileInvite
JAVLN
JAVLN's cloud-based insurance software provides solutions for insurance companies, underwriting agencies and brokerages, delivering a true end-to-end policy administration system. JAVLN required an assurance report to streamline their clients due diligence process when evaluating JAVLN. Their Project Manager, Simon Gillson, shared his top tips for managing the SOC 2 Type 1 project:
- Simon Gillson, Project Manager, JAVLN
Communic8 Group
Communic8 offers the latest innovation in digital engagement that's providing organisations a better way to connect, inspire, analyse and align employees and customers. Communic8 services the communication needs of many of the world’s largest enterprise organisations. With that level of service, clients expect that their data is securely managed and require the assurance accordingly. Communic8's CEO, Bryon Westmoreland, shares their insights from achieving both SOC 2 Type 1 and SOC 2 Type 2 in a 9 month period!
- Bryon Westmoreland, CEO, Communic8 Group
Humanforce
Humanforce uses AI-powered technology for workforce engagement with easy onboarding, auto-rostering, smart time capture and more. Humanforce achieved both SOC 2 Type 1 and SOC 2 Type 2 in a 7 month period in order to appease their large business customers and support their enterprise sales. Jason Fischer, CTO, shared his top tips for others starting out with SOC 2.
Things to remember when planning to kick off SOC 2:
- Jason Fischer, CTO, Humanforce
There's some gems of practical insight in the feedback of these five clients. While they each talk about it as if it's easy following the methods they each applied, the reality was it took time and effort to reach that point. On most projects, there's a slow start and a few headaches to really understand the process and how to work through it. Our team at AssuranceLab are always on call to support that process, but it's important for each team to find what works best for them. We hope these practical insights will help you find yours!