SaaS
North America

Northbeam Analytics

Series-B observability platform with 180 employees, mostly remote engineers, processing customer telemetry in AWS.

Systems
  • AWS multi-account
  • Postgres (RDS)
  • Internal auth via OIDC
  • Customer-facing dashboard
Regulatory exposure
  • SOC 2 (committed to enterprise deals)
  • State breach notification laws (US)
Relevant frameworks
  • SOC 2
  • NIST CSF
Top risks
  • Misconfigured S3 bucket
  • Insider threat via admin console
  • Vendor (datadog) concentration
  • Oncall burnout
Control priorities
  • IAM least privilege
  • Centralized logging
  • Vendor risk reviews
  • Background checks
Audit concerns
  • CC6.1 access reviews evidence
  • CC7.2 monitoring completeness
  • Vendor SOC 2 currency
Your task
You joined as the lead GRC analyst last month. Produce a 90-day plan that addresses the most material audit findings, stands up a vendor risk program, and gets the org to its first SOC 2 Type I readiness assessment.
Vendor risk
Concentration on Datadog and AWS; backup vendor not validated for cold-path failover.
BCP/DR
RPO 1 hour, RTO 4 hours declared but not tested in the past 9 months.