The Challenge
Our client, a global bank headquartered in London, is a longstanding client of Wavestone. The Chief Security Office (CSO) required help to steer the remediation of a large number of cybersecurity issues following a review from the Internal Audit and asked Wavestone for support, due to our ongoing relationship within the cybersecurity functions.
The primary objectives of the project were:
- To secure the Cybersecurity Remediation Program (and ensure compliance with the Issue Management Standard).
- To detect weak signals for issues at risk of not being closed on time.
The Approach
The Results
Wavestone’s ability to translate the standard’s requirements into tangible risk indicators has provided our client with the necessary tools to govern their Remediation Program.
- 7 Automated Risk Indicators (covering the three main phases of the Issues lifecycle – Identification, Risk Assessment, Closure)
- Automated spreadsheet flagging issues at risk across a range of different controls: anticipated complexity of the remediation actions, anticipated complexity of the closure process
- Step-by-step process that outlines which checks need to be made at each stage in the Issue Management Process, depending on the nature of the Issue.
- New governance to secure the Remediation progress, arbitrate priorities, and share escalation needs.
- Weekly reports to the team highlighting the issues at risk, the issue coordinators to contact, the issues approaching closure.
Once implemented, these tools allowed our client to achieve its objective of having 3 consecutive months without any issue not closing on time.