Upgrade to Pro — share decks privately, control downloads, hide ads and more …

About the Garland Group

Brad Garland
December 05, 2011

About the Garland Group

This is information about the Garland Group and why we love to do what we do.

Brad Garland

December 05, 2011
Tweet

More Decks by Brad Garland

Other Decks in Business

Transcript

  1. About Us Garland Group is a creative force in technology

    compliance and security testing solutions. The history of the company is steeped in technology as far back as the AS/400 and continues to help institutions deal with the overwhelming regulatory burden today. Henry and Brad Garland reinvented the company in 2003 in Dallas, TX to focus only on the financial services industry and that’s still what we do today. With our reputation in quality service, we have grown to have over 100 customers across the county - Garland Group is the company to beat.
  2. Services We pride ourselves on being a firm that only

    does a few things but does them really well. Garland Group has many competitors but if you look closely, what they provide in scope, service, and value pales in comparison. Continuous Compliance is a technology audit process that breaks away from the traditional one point in time annualized audit and establishing a ongoing, risk based review process. It has been a service that has been approved by examiners and is becoming the next generation of compliance for financial institutions. Security Testing isn’t only about testing the perimeter of your network and calling it a day. At Garland Group, we offer a Comprehensive Security Review that looks at your institution three ways. Outside your network, inside your network, and what is often your highest security threat, your people. Risk Assessments Technology Audits Continuous Compliance Reviews Social Engineering Vulnerability Assessment Pen. Testing
  3. Garland Group “The Competition” Continuous Compliance Methodology Once a year

    Scope: Covers all 13 handbooks of the FFIEC (includes ACH, Wires, Ops, ATMs, EBanking) IT Handbook Only Industry specific expertise & certification ? Ongoing Committee Meeting Updates Core System Vulnerability Review Includes RiskKey (Enterprise Compliance Mgmt Software) Penetration Testing Vulnerability Assessment Social Engineering In-Person Testing Dumpster Diving Phone & Email Tests Low Sample Rate Phone & Email Only
  4. Which service is right for you? Continuous Compliance Basic Continuous

    Compliance Standard Continuous Compliance Premium Ongoing Continuous Compliance Support Covers all 13 handbooks of the FFIEC Risk Assessment Review & Support On Demand Reporting Regulation Level Review (includes COBIT/SOX related regs) Core System Vulnerability Review Ongoing Committee Meeting Updates Quarterly Monthly Use of RiskKey Compliance Management Software Up to 10 projects Unlimited RiskKey Implementation Services (includes training & integration) 10 hours 40 hours Penetration Testing Vulnerability Assessment Social Engineering 5% 10% 15% In-Person Testing Dumpster Diving Phone & Email Tests In-Person Testing Dumpster Diving Phone & Email Tests In-Person Testing Dumpster Diving Phone & Email Tests
  5. What can our services provide you? With our proactive approach

    to protecting customer data and minimizing risk, we allow institutions the ability to infuse a culture of best practices and compliance into their organization. This increases ROI, dramatically reduces the workload, and transforms their IT security from a point-in-time check mark to Continuous Compliance. Executive Compliance Officer Technology Manager Increase ROI - Improve security and compliance initiatives, while minimizing the associated cost To protect customer data and be compliant with FFIEC, GLBA and other regulations Minimize the workload, time, and labor resources needed to efficiently govern, audit and protect customer data
  6. Our Beliefs If you’re going to choose to work with

    us, you need to know how we think about a few things. Here’s three key commandments of Garland Group: 1) Continuously Compliant - An audit done once a year is dying just as fast as paper checks in banking. Audit and compliance departments need to embrace a continuous compliance mindset to be a great financial institution today. That requires executive buy-in, proactive thinking, and the knowledge to look at compliance enterprise wide. 2) Compliant doesn’t mean secure - Lots of people want to only deal with getting through the examination but don’t care about improving and protecting their customers money. We want to work with clients that see the value in leveraging compliance projects as strategic value and ensuring security not only helps their network but ultimately their bottom line. 3) Low Risk for a Low Cost - Compliance is one of the highest expenses financial institutions deal with today. Utilizing someone like the Garland Group enables financial institutions to hire the people with the expertise, technology backgrounds while doing it at a lower cost. Garland Group can provide that.
  7. Low Risk for Low Cost Roles Cost CISA Auditor $65,000

    CISSP Security Consultant $90,000 Training, Systems, Admin $50,000 Total Cost $205,000 • Difficult to afford expert level resources • Hard to keep up with latest changes to regulations • Lack of insight from other institutions of various size and complexity • Only deal with one set of examiners Challenges
  8. Continuous Education, too! • Personal Continuous Compliance Updates • Monthly

    Webinars • Weekly posts from our experts • Free sample policy & procedures • Free Q&A phone calls • Ongoing feedback & support • If we can help, we will! Through our variety of different educational resources, you can ensure that you’re always kept up to date on the latest trends, risks, and new regulation requirements.
  9. “RiskKey has been a great tool for assisting our bank

    with the management and reporting of our Information Technology Assessments and Audits. We plan to make use of its abilities to serve as an overall enterprise risk management platform.” - Carlisle Mabrey - CTO, SVP of Citizens Security Bank "Deluxe selected the RiskKey as our partner for the compliance management component of our new regulatory program as they have a state of the art solution that is uniquely focused on the community bank segment." - Tom Morefield - President, Deluxe Financial Services "Garland Group's continuous compliance program has saved me hundreds of hours in audit preparation. Their findings and reports help provide our internal auditor, senior management and board of directors important recommendations for each audit. I encourage everyone to ask for a presentation on the continuous compliance program." - Jerry Bell, AVP/IT Project Manager for Lea County State Bank Our Credibility Nothing says that we’re doing this well better then hearing it from our customers. We have over 100 financial services companies that range from Denovo to $2B in assets. We also work with a number of financial vendors that hold the same financial regulatory requirements.