Moneycorp is a global payment and Foreign Exchange (FX) company that facilitates seamless cross-border currency payments for businesses and individuals. With a global footprint in 12 countries and 900 employees, the company trades in 120 different currencies to help businesses pay overseas employees, manage market volatility, and set up multicurrency accounts. It provides swift and reliable financial services for individuals as well, streamlining rental payments for expats living abroad and remittances to family members in other countries.
Head of IT Security Operations Stephen Coles leads a global team of 15 engineers responsible for the security operations center (SOC), vulnerability management, and security engineering. The team manages a complex international environment consisting mostly of Virtual servers with Microsoft Azure Virtual Desktop (AVD) ports, end-user laptops, and a small on-premises infrastructure. Stephen Coles also serves as the primary audit liaison for Moneycorp, maintaining a centralized evidence repository for internal and external reviews in the highly regulated financial services industry.
The Challenge
Before Stephen Coles joined the company, the vulnerability management team fell behind on patches due to an overload of responsibilities. After Stephen Coles was hired, he assembled a new vulnerability management team that embarked on a search for a tool to help them streamline and expedite remediation.
In addition to tracking vulnerabilities and remediation activities, the team needed a tool to support audit compliance across multiple jurisdictions. They needed a way to create clear, detailed reporting for external audits and monthly board meetings across multiple offices. Some of the frameworks that Moneycorp adheres to include Digital Operational Resilience Act (DORA), National Institute of Standards and Technology (NIST), and Center for Internet Security (CIS). Every year, the company also compiles a US multistate report and undergoes an Information Technology General Controls (ITGC) Audit which is a critical part of compliance with the Sarbanes-Oxley Act (SOX).
Continue reading to learn how Armis Centrix™ quickly proved its value by providing the team with end-to-end visibility into server vulnerabilities.
Challenges
-
Tracking vulnerabilities with accuracy -
Managing remediation activities -
Supporting audit compliance across multiple global jurisdictions -
Gaining visibility into assets in a complex distributed environment -
Reporting on security posture both internally and externally to meet compliance requirements
Results
-
Provided a clear, comprehensive view into assets and their vulnerabilities -
Saved time and effort in compiling reports -
Simplified supervision of vulnerability management team projects -
Caught missing patches that were not performed automatically as expected -
Produced easy-to-access lists of assets that required patching -
Delivered audit support across multiple jurisdictions