25/09/2026
IT infrastructure: More than 12,000 assets
Number of employees: more than 5,000
Number of retail customers: 3 million
Number of branches: 70
Objectives
Automation of routine audit and compliance assessment activities.
Simplification reporting based on audit results.
Provision transparent monitoring of remediation activities and security controls.
Automation of cyber risk and operational risk management.
Challenge
For the financial sector, regular information security audits are an integral part of day-to-day operations. The Bank must demonstrate compliance with central bank regulations, applicable legislation, international and internal standards, including information security requirements, operational risk management requirements, personal data protection requirements, and internal information security policies.
To manage all these processes, the Bank required a single solution that would centralize compliance requirements and audit activities, support audit planning, and provide control over audit results.
The Bank had already established information security processes; however, the continued growth of its IT infrastructure and the regular introduction of new requirements increased the workload for the information security team. Employees had to conduct internal audits manually, collect data from business units, monitor the implementation of remediation activities, and consolidate the results into unified reports.
The main challenge was that the data required for audits was stored across multiple sources. This increased the time required to complete assessments and complicated subsequent monitoring of remediation activities.
Defensys SGRC was chosen as the platform for automating compliance management and information security risk management processes. The solution enabled the Bank to consolidate information on IT assets, regulatory requirements, internal standards, audit planning, and reporting within a single system.
Implementation
During the first stage of the project, the Bank implemented Defensys SGRC to automate audits and compliance assessments. The system was configured with requirement catalogs, audit workflows, participant roles, and report templates. All audit data and findings data became centrally available, simplifying report preparation and improving process transparency for all participants.
As the project evolved, the Bank expanded the use of the platform, making it an operational tool for the daily information security management tasks. A separate area of development focused on operational risk management and cyber risk assessment.
Results
Automation of more than 30 types of audits and compliance assessments.
Threefold reduction in the effort required to prepare reports.
Defensys SGRC enabled the Bank to centralize information security management processes and reduce the effort required to perform regular audits and compliance assessments.
A key outcome of the project was the improved transparency of information security processes. Specialists can now use a single system to monitor the current status of compliance requirements, audits, findings, responsible persons, and remediation activities. This reduces reliance on disparate files, accelerates audit preparation, and supports a more systematic approach to compliance management.
For the Bank, Defensys SGRC has become not only a tool for automating information security compliance, but also the foundation for the further development of information security management processes. Automation has enabled the Bank to move from isolated assessments and expert-based evaluations to a more systematic approach to compliance and cyber risk management.
“For a large bank, it’s important not only to successfully complete individual audits, but also to maintain continuous visibility into the actual state of its information security processes: which requirements are being fulfilled, where deviations exist, who is responsible for remediation activities, and how the status of assets and business units changes over time” – noted Andrey Chechetkin, Defensys CEO.
“Defensys SGRC has helped centralize these activities. It is particularly important for the Bank that the platform can continue to evolve, supporting not only compliance-related tasks but also cyber risk management.”