Thank you for Subscribing to CIO Applications Weekly Brief
Thank you for Subscribing to CIO Applications Weekly Brief
ProCircular has been recognized by CIO Applications Magazine as the exclusive recipient of “Top 10 GRC Technology Consulting/Service Companies - 2020,” based on our proprietary methodology, reflecting its position in the industry, and is also named among “,” reflecting its broader leadership. This profile has been developed by the CIO Applications research and editorial team based on insights from an interview with Ty Hollins, CISO.
Fulfilling this need in the marketplace is the Iowa-based cybersecurity company, ProCircular, that helps clients across the U.S. manage their risk, improve security readiness, and meet all regulatory and compliance requirements. “We offer scalable solutions with world-class expertise to clients extending from financial services to manufacturing, and also to the small to mid-size markets,” states Ty Hollins, the CISO of ProCircular.
In conversation with CIO Applications, Hollins mentions how the company is powered by industry experts with IT and security experience with a hands-on approach in providing insights and practical recommendations to keep businesses safe and secure.
Can you provide a brief overview of ProCircular?
From a GRC standpoint, our company partners with clients to improve their overall security posture and mitigate risks by applying various strategies. We are a cybersecurity and compliance firm that offers actionable guidance to address the ever-changing cyberthreat landscape while helping clients meet regulatory requirements. In most of our collaborations, we perform a risk assessment to identify risks within their IT infrastructure, support the management in understanding those, and how they can effectively mitigate such threats. We can also assist with revising their policies and procedures, implementing new technologies, including antivirus solutions or a SOC, and improving their risk mitigation program. Our company performs penetration testing, vulnerability management testing, and IT scans within clients’ organizations that can increase their security posture and educate everyone about the underlying issues. From an incident management standpoint, we can formulate incident response plans that will help clients’ employees know how they are supposed to interact and communicate with each other and outside the organization in the face of an unwanted incident. We offer a holistic assessment of their entire security posture, a complete network vulnerability assessment, and full-service monitoring and alerting programs to improve their overall security readiness.
What are some of the challenges your clients face with GRC implementation?
One of the most crucial roadblocks for all our clients is budgetary restraints from a capital and resources standpoint.
Please elaborate on the risk assessment and the compliance audit process that you have in place.
Our standard-based framework helps clients identify compliance gaps in their security programs and accordingly remediate them. We follow the set standards of CMMC, SOC2, ISO 27001, NIST, FERPA, HIPAA, and GDPR, depending on the type and size of organizations we work with. Even though every standard comes with multiple controls, we do not offer all these controls to our clients; instead, we tailor them according to their requirements. Once we have a customized framework for them, we conduct interviews with the key management personnel to understand their daily operations. This helps us identify individuals who are genuinely a good fit for the position they are responsible for. Following this discussion, we review their policies and procedures documentation, inform them of our findings, and provide constructive feedback. We also go offsite and perform a detailed risk and control assessment by testing their controls from a design and operations standpoint. Once the assessment is completed, we review all the findings and formulate concise recommendations that fit the clients’ objectives. We also draft a risk matrix that lists the findings and the risk score of whether the risks are high, critically high, medium, or low. Within two weeks, we conduct a readout of the report at the client’s organization and provide them the risk matrix to start inputting their management responses. Following this, the clients, too, state their management responses to our findings. We sign off our risk assessment contract and start working with them to gradually close all the gaps found within the organization.
Could you provide us with a customer success story?
We had collaborated with a client whose organization lacked a proper incident response plan but had a procedure and policy in place. After partnering with them, our first step was to carry out an extensive assessment of their overall policy and draft a plan and test it. We created several hypothetical scenarios within the organization and performed tabletop exercises with them. These tests helped reveal that the organization did not operate as indicated within their policies. For resolving this, we helped revise their procedures and provided them with an after-action report of our findings. About three months after implementing the incident response plan for this client, our personnel tested it and found limited gaps, showing that they were operating as expected. This is one of the many instances where we took a company from having no plan to having a well-executed plan to combat real-world incidents and mitigate all the associated risks.
What does the future roadmap look like for your company?
As a company, we are extremely passionate about cybersecurity and focus greatly on education, assessment, and analysis. With our industry expertise and best-of-breed tools, we enable clients to regularly monitor their systems and operation and identify compliance gaps in their security programs. With our compliance gap assessment and risk assessment, we aim at providing clients with the required visibility to avoid any financial and reputational costs of security non-compliance. We are heavily focused on adopting the leading trends within the marketplace, especially digitization through cloud computing, software advancements from AI and ML, increasing cybersecurity and data privacy needs, and ultimately improving our service offerings.
CIO Applications Weekly Brief
Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications
