Anecdotes’ flexibility changed the game when it came to customer audits. Being able to redact data and scope what we want to show has taken our ability to build trust with customers to the next level.”
Ryan Swimm, Senior Manager, GRC Program, Bitsight
Challenge:
Resource-intensive Manual Processes: In managing compliance across multiple frameworks, the manual processes involved in evidence collection and mapping took way too much time.
Customer Audit Bottlenecks: When customer questions went beyond basic questionnaires, pulling evidence strained internal resources and created a potential bottleneck with customers.
Solution:
Automated Evidence Collection & Mapping: Anecdotes’ proprietary plugins helped Bitsight automate evidence collection and mapping across various controls.
Custom Framework Development: Bitsight tailored a framework for its SOC 2 Type 2 audits, which it is using “as a flexible foundation” for additional custom frameworks.
Improved Evidence Delivery Capabilities: The GRC team can use Anecdotes to manage and deliver evidence for customer audits independently—without burdening the engineering team. “Being able to act independently and pull that evidence for customers is a big time saver for our different organizations, especially engineering, who are already overloaded.” Ryan Swimm, Senior Manager, GRC Program, Bitsight
Results:
Smooth and Rapid Onboarding: Bitsight onboarded smoothly and confidently thanks to Anecdotes’ well-documented proprietary plugins.
Competitive Advantage: BitSight maintains a strong GRC posture by using Anecdotes frameworks to stay ahead of evolving regulations and build trust with customers.
Time Savings: Automated workflows and easily digestible data have freed up substantial time and resources, allowing Bitsight’s GRC team to focus more on strategic initiatives and reducing strain on other teams.
Client Bio
NYSE Ticker:
Industry:
Computer and Network Security
Employees:
749
HQ:
Boston, MA
BitSight, founded in 2011, is a global leader in cyber risk management, transforming how organizations manage exposure, performance, and risk for themselves and their third parties.