Building a Security Program for a High-Growth Financial Services Organization
Client OverviewA rapidly growing financial services organization managing millions of payment card records underwent a significant leadership transition. During this period, the company recognized that its security, compliance, and governance capabilities had not kept pace with its growth.
With increasing regulatory obligations, an upcoming PCI DSS assessment, and customer demands for independent assurance of security controls, leadership needed a clear path forward.
The Challenge
The organization faced several critical challenges:
- Limited cybersecurity governance and program structure
- Unclear ownership of security responsibilities
- Need to demonstrate compliance with PCI DSS requirements
- Requirement to obtain a SOC 2 Type II report to meet customer and business expectations
- Executive uncertainty regarding security strategy and investments
- Protection of a large environment containing millions of payment card records
Our Approach
Gilliam Security partnered with executive leadership to establish a practical and scalable security program aligned with business objectives.
Client Results
Security Program Development
We helped the organization build foundational cybersecurity capabilities by:
- Establishing governance and accountability structures
- Defining security policies and standards
- Implementing risk management processes
- Creating security metrics and executive reporting
- Developing a compliance-focused roadmap
PCI DSS Readiness and Audit Support
To prepare for the client's PCI assessment, we:SOC 2 Type II Program Support
- Conducted readiness reviews and gap assessments
- Validated existing controls and remediation activities
- Coordinated compliance efforts across technical and business teams
- Assisted leadership in understanding audit expectations
- Supported auditors throughout the assessment process
We guided the company through the design, implementation, and operationalization of controls required for a successful SOC 2 Type II examination.
Key activities included:
- Control design and documentation
- Evidence collection processes
- Risk and access management improvements
- Governance and compliance reporting enhancements
- Audit preparation and stakeholder coordination
The engagement delivered measurable business outcomes, to include:
PCI DSS Assessment SuccessBusiness Impact
The organization successfully completed its PCI DSS audit with no identified compliance gaps, providing confidence that cardholder data was being protected through an effective control environment.
SOC 2 Type II Achievement
The organization achieved a SOC 2 Type II report with no exceptions noted, demonstrating the effectiveness of its security controls over the audit period. Sustainable Security Function
Beyond compliance, the company emerged with:
- A formal cybersecurity governance program
- Improved executive visibility into risk
- Repeatable compliance processes
- Clear accountability for security operations
- A security roadmap aligned with business growth
By establishing a foundational security program and successfully navigating both PCI DSS and SOC 2 Type II requirements, the organization strengthened customer trust, reduced operational risk, and positioned itself for continued growth within the highly regulated financial services sector.