From nothing in place to a program the regulator passed
Regulator reviewed the program and passed it
- Trigger
- A state insurance cybersecurity regulation required a documented security program, evidence that it operated, and a commitment to ongoing assessment. They had none of the three, against a fixed compliance date.
- What we found
- No secure development process, no application security testing, and no view of the software supply chain. Tooling was deployed but not configured to cover what the regulation required, and nothing was written down behind any of it. The gap was not spend. Nothing was documented, owned, or verifiable.
- What changed
- We built the program from the ground up: secure development, application security and penetration testing, and software supply-chain coverage, along with the tooling to support them, reconfiguring what they already owned before specifying anything new. Policies, procedures, and named ownership followed, with internal assessment running before the deadline rather than after it. The regulator reviewed the program and passed it.