The Results
By moving from manual spreadsheets to an integrated Cyber GRC platform, D’Youville realized significant efficiency gains and strengthened its overall security program.
Time Savings
- Kristin knows that the team was able to create more actionable policies to meet requirements then would be able to before FortifyData.
- D’Youville got through HIPAA compliance faster than they would have by being able to gather evidence a lot faster and provide it for the particular question or control and the end result was an institution wide policy.
- Board report preparation that previously consumed weeks could be compiled in a fraction of the time, freeing staff for operational priorities.
Improved Governance and Staff Buy-In
- Staff better understood the purpose of controls like MFA once they were tied to framework requirements.
- The University was able to develop an institution-wide HIPAA policy, not just specific to certain clinics on campus.
- Having a clear rubric gave the IT team a shared set of goals, improving collaboration and morale.
Simplified Vendor Risk Management
- Risk scores for third-party vendors provided actionable insights that influenced contracts and insurance renewals.
- The ability to proactively address compromised accounts (such as dark web findings) reduced reliance on reactive SOC alerts.
Support for Insurance Renewals
- FortifyData reports provided the proof and evidence insurance carriers demanded, helping with policy attainment and reducing the risk of denied claims.
Ease of Implementation
- Onboarding was seamless: a two- to three-week proof of concept transitioned directly into production, unlike the lengthy rollouts Kristin had experienced with other tools.
"We were able to gather evidence a lot faster and put it into the questionnaire for that particular framework… It probably reduced the adoption of that by like 30 or 40%. It also helped with user buy-in because if users can see what you’re doing and they understand why, they’re more likely to meet the requirements.”
Kristin Benoodt