A large Canadian City Government partnered with ReversingLabs to profoundly improve risk management in their software acquisition and management lifecycle by de-risking desktop and server software acquisition by a factor of 6300% and converting an unreliable, multi-day workflow into a 15-minute process, delivering actionable results and an accompanying audit trail.
Their Cybersecurity Leader described an overwhelming backlog of COTS (Commercial Off The Shelf) software approvals due to a manual, multi-day, interruption-prone risk assessment process for each request. Spectra Assure® allows the team to rapidly assess risks, including malware and vulnerable components, thus dramatically increasing team throughput while maintaining flat labor costs and achieving better risk insights.
The new process involves sharing SAFE reports with their vendors using Spectra Assure’s built-in sharing ability, which is met with appreciation and a commitment to address specific risks. This has materially improved the City’s risk posture. Capturing results in the SAFE report provides intuitive visual cues for non-technical users along with detailed information required for remediation. In this sense, a once detective control has become preventive as the COTS attack surface is reduced in cooperation with key vendors.
As with most city governments, many requests are “urgent”. The introduction of Spectra Assure empowers the team to stay ahead of emerging threats and expedite the resolution of routine end-user inquiries centered around the question, “Is this safe?”
Reducing Risks While Improving User Satisfaction
With an end-user population of roughly 18,000 and increasing geopolitical threats and privacy concerns, the City’s Security Operations team faces an ever-increasing influx of risks amidst an accelerating volume of requests from end users to download and deploy untested third-party commercial software. Furthermore, the City’s costs are meticulously reported, and team headcount increases are virtually impossible. The existing team is expected to maintain operational tempo despite increasing risks and legislated involvement with all RFPs and software requests, while their days are consumed developing controls around emerging capabilities such as AI.
Spectra Assure allows the team to optimize their approach to software requests, thus reducing risk while freeing up cycles for the team to remain nimble and responsive to an increasing volume of inquiries.
The City’s holistic approach to risk allows the Citizens to realize more value and better risk-avoidance from a cyber team that’s smaller than that of many comparable cities.