Hubert Beaulat, COO, Nyaya
How Nyaya saved 100 hours on ISO 27001 certification
“Getting ISO 27001 certified was a critical step to demonstrate our commitment to the market that we manage data in the most efficient and secure way.”
Hubert Beaulat, COO, Nyaya
“Getting ISO 27001 certified was a critical step to demonstrate our commitment to the market that we manage data in the most efficient and secure way.”
Hubert Beaulat, Nyaya
Start-ups and SMBs can lack the expertise they need to stay on top of every business challenge. No surprise – they're often too busy disrupting new markets, scrapping for customers and trying to build a plane when it’s already in the air. It’s high-octane stuff.
But what happens when a business needs to focus on the less exciting (but equally as important) jobs? What do you do when customers start demanding information security and data privacy compliance? Where do you find the expertise you need when everyone else is so busy?
Questions that Nyaya – a company helping customers align sustainability beliefs with financial decisions – found themselves asking in 2023.
In this case, it was Nyaya COO Hubert Beaulat was asking the questions. Why? Because his potential customers were all telling him the same thing: Be ISO 27001 compliant or risk losing our business.
But like many small companies, Nyaya didn’t have dedicated people or expertise to manage the ISO certification process. So, the responsibility fell to Hubert.
“Information Security isn’t the most exciting part of my job, but it’s something I have to do at the moment because we don’t have the experience in our team,” confides Hubert. “So having someone from DataGuard who can guide me, provide explanations and help us do all the procedural heavy lifting was instrumental.”
And there can be a lot of heavy lifting. For example, part of the Nyaya certification process was building an Information Security Management System (ISMS). This requires a lot of documentation - a significant burden for a busy COO.
"We would have had to learn everything from scratch," says Hubert. "And with the sheer number of procedures we needed to do, it was impossible for me to learn everything. Being able to rely on DataGuard’s knowledge and experience was a total game changer."
Nyaya estimates that documenting 50 procedures for the ISMS project would typically have taken 3 hours per procedure. However, using existing templates in the DataGuard platform drastically improved that. Documents required less editing or rework— and only a handful of documents needed any adjustments at all.
The result? A reduction in time taken to 50 hours – a 66% saving.
There are many reasons to get ISO 27001 certified. But one of the key drivers for Hubert and his team was to demonstrate to potential customers that Nyaya held itself accountable to the very highest standards of data privacy and information security.
“We’re developing this innovative software for banks and financial institutions,” Hubert tells us. “It’s a sector where clients are particularly eager to ensure their data is fully protected. So, getting ISO 27001 certified was a critical step to demonstrate our commitment to the market that we manage data in the most efficient and secure way.”
But it wasn’t just a “one-and-done" effort to keep the flow of new deals open. Even at such an early stage in the development of the business, Hubert and his team wanted to focus on ongoing and continuous improvement.
“Getting ISO 27001 certified was a critical step to demonstrate our commitment to the market that we manage data in the most efficient and secure way.”Hubert Beaulat, COO, Nyaya
“We set up the company intending to build the right practices to enable us to engage with large institutions right away,” says Hubert. “And that’s really important to me. It helps establish a mindset. It's about making sure that the whole team understands what’s important and can put it into practice.”
And a great way to do that is to use the DataGuard Academy.
“We started using Dataguard Academy to make sure we have critical mandatory security training in place with the team and the platform works well. We've already chosen three compulsory training modules, and it's going great so far.”
But the DataGuard platform isn’t just a repository for critical knowledge. Admins can access analytics to understand how many users have completed training modules and assess completion rates. “I'm using the DataGuard to monitor that everybody has complied,” Hubert says. “It’s essential that we have visibility that people have completed mandatory training within the allocated time frame. The DataGuard platform gives us that.”
“We've already chosen three compulsory training modules from the DataGuard Academy, and it's going great so far.”Hubert Beaulat, COO, Nyaya
“The relationship we've built with our DataGuard expert Yazid means a lot to me,” Hubert says. “I know he’s there when I need him, and I know he’s always going to be providing guidance. Plus, we’ve still got a lot of work to do!”
So, it’s just the beginning for the ambitious start-up. While the ISO 27001 certification was a critical first step, Nyaya has ambitious plans for its ongoing compliance journey. Some of the first tasks will be to fully migrate to the DataGuard platform and plan for the transition to ISO 27001:2022.
We look forward to partnering with Hubert and his team in the future.
A company building software solutions that help customers align their sustainability beliefs with their financial decisions.
FinTech
12
London, UK & New York, USA
Infosec-as-a-service
We help your compliance run like clockwork with pragmatic, needs-based advice.
Get a quote
“Getting ISO 27001 certified was a critical step to demonstrate our commitment to the market that we manage data in the most efficient and secure way.”
“We increased our marketing database by 20% in just six months and are looking to double the opt-in rate by end of the year.”
“Without DataGuard, achieving our certifications so quickly would have been nearly impossible.”
“Working with consulting firms could have taken 50-80% more time to setup an ISMS. With DataGuard, we felt cared for and supported, even in challenging times.”
“Trying to find the right solution was a complete minefield. There was no understanding or empathy. We are dealing with sensitive data and needed extra help. Nobody took the time to really understand...
“When we started signing corporates and bigger companies, we realised data privacy plays a key role in our brand's perceived business ethics."
“Our schedule was less than 6 months, and it would have been impossible without DataGuard.”
“Caring about data privacy is just common courtesy. It shows that you care just as much about your customers themselves as you do about them spending money with your company. If we only cared about...
“Better safe than sorry. ISO 27001 and GDPR compliance were make or break for our business"
“E-commerce is all about people. We do more than just store personal data: we monetize it. This makes it critical for us to stay on the safe side of data protection law. DataGuard helps us do exactly...
“DataGuard's team of privacy experts is what makes the difference. They don't just tell us "do it like this", they also explain why it should be done in a specific way – which helps broaden my team's...
“Parconomy’s solution is aimed primarily at parking garage operators and mobility providers – both municipal and commercial. Data privacy is a top priority for these target groups – and that's a good...
"Strong data protection practices are a great argument in favour of a company. People really care about this. And if customers care about it, then businesses need to care about it, too. With the help...
"The requirements with regard to data privacy and information security recently increased massively with our automotive customers, similarly to our industrial customers from other industries."
"With DataGuard, there’s a certain amount of hours included in our package. It covers the amount of questions that I have and gives me peace of mind that I won’t get a huge invoice at the end of the...
“We were introduced to DataGuard and they were able to provide us with the perfect solution at the time we needed it. DataGuard gives us peace of mind and helps us sleep well at night. If you want to...
“We chose a professional solution that covers a spectrum which an individual internal data protection officer cannot provide – neither in terms of expertise nor in terms of time."
“As a non-profit, we often work with so much personal data – names, email addresses, phone numbers, and more. We have to be on the safe side when it comes to privacy.”
“DataGuard allows us to automate responses which saves time and money. And if we ever have a question, they have a team of experts standing by to help. It is like having a pain reliever."
“Previously, all data privacy queries ended up on my desk. Now, the platform is the linchpin. Colleagues can find all their necessary to-dos, templates, documentation, and training courses easily and...
Use our web-based platform was developed to be used by anyone, even privacy novices. Work on compliance at your own pace, with the support of our experts always just a click away.