SaaS
North America
Northbeam Analytics
Series-B observability platform with 180 employees, mostly remote engineers, processing customer telemetry in AWS.
Systems
- AWS multi-account
- Postgres (RDS)
- Internal auth via OIDC
- Customer-facing dashboard
Regulatory exposure
- SOC 2 (committed to enterprise deals)
- State breach notification laws (US)
Relevant frameworks
- SOC 2
- NIST CSF
Top risks
- Misconfigured S3 bucket
- Insider threat via admin console
- Vendor (datadog) concentration
- Oncall burnout
Control priorities
- IAM least privilege
- Centralized logging
- Vendor risk reviews
- Background checks
Audit concerns
- CC6.1 access reviews evidence
- CC7.2 monitoring completeness
- Vendor SOC 2 currency
Your task
You joined as the lead GRC analyst last month. Produce a 90-day plan that addresses the most material audit findings, stands up a vendor risk program, and gets the org to its first SOC 2 Type I readiness assessment.
Vendor risk
Concentration on Datadog and AWS; backup vendor not validated for cold-path failover.
BCP/DR
RPO 1 hour, RTO 4 hours declared but not tested in the past 9 months.