MasterControl Achieves FedRAMP Success with AWS Security Assistance
Tyler J. Cox, Chief Information Security Officer for MasterControl, shares how AWS Security Assistance Services helped them achieve their FedRAMP goals and improve their overall security posture.
About MasterControl
MasterControl is a unique SAAS company providing solutions that enable regulated companies in pharmaceuticals, life sciences, and medical device industries to get their products to market faster. They provide essential tools to navigate complex regulatory landscapes.
The FedRAMP Journey with AWS
According to Tyler, AWS is MasterControl's largest technology partner. He highlights the crucial role of AWS Security Assistance Services in their FedRAMP journey. These services provided a baseline and a roadmap, enabling MasterControl to aim for FedRAMP moderate ATO by the end of the year.
"They figured out where we were in that point in time and then they built a map to show us where we needed to go," explains Tyler. This roadmap allowed his teams to understand and follow the necessary steps. As a security leader, it provided clarity on resource allocation and investment.
Cost Savings and Efficiency Gains
The FedRAMP project in 2023 led to the consolidation of five security tools into three, resulting in a **net savings of $750,000 over three years.** MasterControl also increased their time to value, completing the project on time and within budget.
Improved Business Opportunities Through Enhanced Security
Investing in security has unlocked new business opportunities for MasterControl. Tyler emphasizes that it has positively impacted their topline revenue by **shortening the sales cycle and increasing customer confidence.**
People, Training, and Proactive Security
Tyler emphasizes the importance of people and proactive security measures. "I think it all starts with the people because we don't have infinite resources. We need to catch problems as soon as possible." AWS supports this by providing training for developers and platform teams, keeping them updated on the latest threats.
This training enables MasterControl to build gates and proactive security measures into their SDLC, giving them the best chance of staying ahead of threats and avoiding costly postrelease fixes.
Security as a Core Value
Ultimately, MasterControl wants its customers to understand that **security is part of the DNA of their product, not just an addon.** Their partnership with AWS is crucial in achieving this goal and delivering a secure and reliable solution.