Eliminating legacy infrastructure complexity
Many successful security breaches exploit legacy systems and configurations that organizations no longer need but have lost visibility into. This is another area where Bitsight has empowered the Datamark team to bring a more proactive approach to their security efforts. “As there is turnover in technology and security teams, it’s easy for many small things to go unchecked,” Padilla said. “We’ve done a lot of work over the last year in areas like reviewing certificates, cleaning out unnecessary DNS records, and adding web headers in places where they were missing.”
While many of these improvements may seem minor when viewed individually, they collectively add up to a significant improvement in Datamark’s overall security hygiene.
Reducing insurance and resource costs
In addition to reducing organizational risk, Datamark’s strategic use of Bitsight has also helped the company drive costs down in several key areas. One notable example is cybersecurity insurance premiums, where Datamark used its favorable Bitsight rating to support its negotiation. “We can roughly attribute a 10 percent premium decrease as a direct result of Bitsight,” Padilla said.
Additionally, approaching activities like vulnerability management, compliance audits, and customer risk assessments more systematically has also kept the team out of reactive mode and improved overall operational efficiency. “Bitsight easily saves us between 500 –1000 hours annually,” Padilla noted.
Strengthening companywide security awareness
The Bitsight Security Rating serves as an easy-to-understand reminder of the role that everyone across Datamark plays in keeping the company and its customers safe from cybersecurity threats. It’s used consistently at executive briefings, ongoing metrics and reporting, and companywide updates. “Bitsight has really helped us raise cybersecurity awareness across Datamark,” Padilla said. “It’s an easy way to see that we’re top-tier when it comes to security, and everyone, from the president to individual employees, takes an interest in the latest ratings updates.”