Building a Security Program for a High-Growth Financial Services Organization

Client Overview
A rapidly growing financial services organization managing millions of payment card records underwent a significant leadership transition. During this period, the company recognized that its security, compliance, and governance capabilities had not kept pace with its growth.
With increasing regulatory obligations, an upcoming PCI DSS assessment, and customer demands for independent assurance of security controls, leadership needed a clear path forward.

The Challenge
The organization faced several critical challenges:
  • Limited cybersecurity governance and program structure
  • Unclear ownership of security responsibilities
  • Need to demonstrate compliance with PCI DSS requirements
  • Requirement to obtain a SOC 2 Type II report to meet customer and business expectations
  • Executive uncertainty regarding security strategy and investments
  • Protection of a large environment containing millions of payment card records
Leadership recognized that maintaining the status quo would increase operational, regulatory, and reputational risk.

Our Approach
Gilliam Security partnered with executive leadership to establish a practical and scalable security program aligned with business objectives.

Security Program Development

We helped the organization build foundational cybersecurity capabilities by:
  • Establishing governance and accountability structures
  • Defining security policies and standards
  • Implementing risk management processes
  • Creating security metrics and executive reporting
  • Developing a compliance-focused roadmap

PCI DSS Readiness and Audit Support

To prepare for the client's PCI assessment, we:
  • Conducted readiness reviews and gap assessments
  • Validated existing controls and remediation activities
  • Coordinated compliance efforts across technical and business teams
  • Assisted leadership in understanding audit expectations
  • Supported auditors throughout the assessment process
SOC 2 Type II Program Support

We guided the company through the design, implementation, and operationalization of controls required for a successful SOC 2 Type II examination.
Key activities included:
  • Control design and documentation
  • Evidence collection processes
  • Risk and access management improvements
  • Governance and compliance reporting enhancements
  • Audit preparation and stakeholder coordination
Client Results
The engagement delivered measurable business outcomes, to include:

PCI DSS Assessment Success

The organization successfully completed its PCI DSS audit with no identified compliance gaps, providing confidence that cardholder data was being protected through an effective control environment.

SOC 2 Type II Achievement

The organization achieved a SOC 2 Type II report with no exceptions noted, demonstrating the effectiveness of its security controls over the audit period. Sustainable Security Function

Beyond compliance, the company emerged with:
  • A formal cybersecurity governance program
  • Improved executive visibility into risk
  • Repeatable compliance processes
  • Clear accountability for security operations
  • A security roadmap aligned with business growth
Business Impact
By establishing a foundational security program and successfully navigating both PCI DSS and SOC 2 Type II requirements, the organization strengthened customer trust, reduced operational risk, and positioned itself for continued growth within the highly regulated financial services sector.