Virtual Compliance Officer Case Study
Requirement
Assist a large, privately-owned software company in Southern California with a multitude of security, privacy, and compliance challenges.
Issues
The client had experienced rapid growth in recent years, but also needed a flexible solution in terms of finding a compliance officer with both expertise and availability, as needed.
Additional issues for the client
Difficulty in Hiring a Compliance Officer: With a tight labor market, the client had immense challenges in finding an acceptable candidate for hire. As a result, their internal counsel was performing compliance duties, but was becoming overwhelmed with the workload.
Lack of Expertise: While internal counsel had legal and privacy expertise, this individual did not have the necessary InfoSec/cybersecurity and auditing expertise required for the organization’s growing list of compliance requirements.
Unclear Roadmap: With so many security and compliance issues to deal with, the client was unsure as to where to begin. There were different opinions and recommendations, all of which had a number of challenges.
Solution
Centris deployed a team of experts specializing in security, privacy, and compliance that successfully accomplished the following:
- Worked with client to define project scope and client participation, assigning roles, responsibilities - and hard deadlines and deliverables - to all personnel involved with the project.
- Designed, developed and implemented a comprehensive compliance program consisting of documented and highly formalized information security, cybersecurity, and data privacy policies, procedures, and processes.
- Along with developing much-needed compliance related policies and procedures, developed and implemented the following three (3) major programs: (1). Incident Response Plan, (2). Contingency Planning Program, (3). Data Privacy Program
Outcome
- Built and deployed an all-new compliance program from the ground up, while offering short-term virtual compliance services (5 hours to 7 hours a week) for handling their growing compliance needs.
- Created a true culture of compliance where employees now understand and value the importance of information security, cybersecurity, and data privacy.
- Implemented a continuous monitoring program for ensuring all compliance related programs are properly monitored long after the consultants are gone.