Enterprise Security Readiness
When the security review goes deeper than the questionnaire.
Enterprise customers increasingly want evidence that security controls exist inside the underlying technology environment.
Fortera helps engineering and security teams close technical gaps uncovered during customer security reviews and vendor due diligence.
Context
Security due diligence becomes more demanding as customers become larger.
Early stage technology companies can often operate with relatively lightweight security processes.
As the organisation begins working with larger enterprises, regulated organisations, financial institutions, healthcare providers or global companies, the level of security scrutiny can increase substantially.
Fortera focuses on the technical cloud and infrastructure requirements within that process.
Areas a buyer may review
- Identity and privileged access
- Cloud architecture
- Encryption
- Network security
- Logging
- Monitoring
- Vulnerability management
- Change control
- CI/CD
- Infrastructure management
- Backup
- Disaster recovery
- Incident response
- Supplier risk
- Data handling
- Evidence of security controls
How it happens
From opportunity to ongoing control.
- 01Enterprise Opportunity
A technology company begins working with a larger or more security conscious customer.
- 02Security Due Diligence
The customer requests information about security controls and infrastructure practices.
- 03Evidence Request
The buyer may request policies, diagrams, screenshots, configurations, logs or evidence that controls operate in practice.
- 04Technical Gap
A requirement exposes an infrastructure weakness or control that needs improving.
- 05Remediation
Fortera works with the engineering or platform team to implement the required technical improvement.
- 06Validation
The organisation confirms the technical requirement has been addressed.
- 07Evidence
Updated evidence can be supplied to the appropriate assurance process.
- 08Ongoing Control
Where required, the control is standardised through infrastructure, automation or governance.
Examples
What can surface during an enterprise security review?
The customer asks how privileged cloud access is controlled.
Possible issue: Broad administrator permissions or weak separation of access.
Potential remediation areas
- Least privilege
- Role design
- Privileged access
- Access review
- Service identities
The customer asks whether administrative and security relevant events are logged.
Potential remediation areas
- Audit logging
- Centralised logs
- Retention
- Monitoring
- Alerting
The customer asks how sensitive information is encrypted.
Potential remediation areas
- Encryption at rest
- Encryption in transit
- Key management
- Secrets management
The customer asks how production infrastructure changes are controlled.
Potential remediation areas
- Infrastructure as Code
- Code review
- Deployment approval
- Pipeline permissions
- Environment controls
The customer asks how quickly a critical service can be recovered.
Potential remediation areas
- Backup
- Recovery testing
- Disaster recovery
- Environment rebuilding
- RTO / RPO validation
The customer asks how production environments are isolated and protected.
Potential remediation areas
- Network segmentation
- Private connectivity
- Security groups
- Environment separation
- Cloud architecture
Our role
We focus on the engineering behind the answer.
Fortera is not positioned as the organisation issuing certifications or acting as an external auditor. Fortera focuses on the technical implementation work that may be required once a security expectation has been identified.
Before the review
Identify obvious infrastructure gaps and strengthen technical controls before due diligence begins.
During the review
Support engineering teams where a customer requirement exposes a technical security weakness.
After the review
Remediate findings, standardise controls and support the creation of appropriate technical evidence.
Discuss an enterprise security requirement
If a customer review or vendor assessment has raised an infrastructure control requirement, we can help work out what implementing it actually involves.
Discuss an Enterprise Security Requirement