Governance, Risk and Compliance

GRC-as-a-Service from MSSP Velaspan Aims to Help Customers with Compliance, Security

A new Governance, Risk and Compliance-as-a-Service (GRCaaS) offering has been unveiled by Pennsylvania-based MSSP, Velaspan, which also focuses on wireless network design and consulting services.

Application-based or platform-based, in-house GRC is already used by businesses and organizations that want to protect their operations, customers, and reputations. But there are many businesses that do not have sizable and experienced IT staffs or budgets to tackle such tasks and responsibilities on their own, according to the company. That is where Velaspan’s managed, as-a-service GRC offering can be a better fit for customers that require such protections and controls to battle hostile cyber threats.

Velaspan’s managed GRCaaS services are designed to provide the operational structure, technical insights, and consulting services needed to help customers bring in these capabilities affordably as they meet their business strategy requirements, according to the vendor. The GRCaaS services also help customers maintain compliance with regulatory frameworks such as SOC 2, ISO 27001, and HIPAA.

Kerry Kulp, Velaspan’s co-founder and strategic lead for its GRC initiatives, told ChannelE2E that while many competitors use GRCaaS as a buzzword today to describe software or CISO consultancy services that Velaspan is taking an entirely different approach.

“We are delivering an actual GRC program as a managed service,” said Kulp. “Not just advice. Not just a tool. We give our clients the platform and the people to build and run a full governance, risk, and compliance operation. And because we come from real-world security and infrastructure, we are not just writing policies, we are helping clients implement the controls behind them. That is the gap that we are closing.”

Kulp said that the company has been slowly building up its cybersecurity practice for years.

“This is not a pivot for us,” he said. “It is a natural extension of where we have been headed. Velaspan’s roots are in enterprise mobility and network security. GRCaaS is just the latest piece.”

Velaspan got into this market because it is what some customers and partners were asking them to provide, he said. “The value here is speed, structure, and sustainability. We help clients get compliant faster, stay compliant longer, and actually improve security along the way. It is a business enabler, not just a checkbox exercise.”

How Velaspan’s GRCaaS Will Help MSPs

For MSPs, Velaspan’s GRCaaS offering will make it easier for them to offer these kinds of services to their clients, Kulp told ChannelE2E.

“Honestly, it seems like most MSPs do not want to touch GRC,” he said. “It is messy, it is nuanced, and it does not scale well without the right tooling. What we are offering gives MSPs a path to offer compliance and risk management without building a whole new business unit that requires a lot of upskilling. We take on the GRC heavy lifting. They just plug us in, and we become their GRC team in the background.”

And because the MSPs are likely already managing some or all of the IT and security ecosystem for their clients, Velaspan is feeding the remediation requirements to them for implementation and ensuring that their day-to-day operations align with business objectives and the GRC program, he said. “Their clients get better outcomes, and they get to stay focused on their core services. Everybody wins.”

To help MSPs access the technology more easily, Velaspan is bundling access to a compliance automation platform into the service, according to Kulp. “ So, no upfront licensing, no integrations to figure out, no configuration headaches. We onboard them, set it all up, map it all to the relevant frameworks and controls, and maintain it. It really lowers the hurdles for anyone who has tried to build their own GRC tech stack.”

To start a GRCaaS engagement with a customer, Velaspan experts begin by conducting discovery efforts, which include stakeholder interviews and analyzing policy and regulatory requirements. The Velaspan team then sets out goals and priorities, maps processes, and identifies risks. The Velaspan GRC software platform is then configured with this data, and the execution phase starts where policies are set and controls deployed. Velaspan provides continuous support to manage compliance activities, guide remediation efforts, and adapt the program as new risks and regulations emerge, according to the company.

“Our MSP partners needed help bridging the gap between technical security and business-level compliance,” said Kulp. “So, we built this offering to fill that gap.”

Other GRCaaS vendors in the marketplace include CyberSecOp, Zones, Exellor, and TruOps.

Todd R. Weiss

Todd R. Weiss is a contributing editor to ChannelE2E and MSSP Alert. He is an award-winning technology journalist and freelance writer who covers the full range of B2B IT topics. He served as managing editor at EnterpriseAI.news and was a staff writer for Computerworld and eWeek.com. He is a diehard Philadelphia Phillies, Eagles, Flyers and Sixers fan and says he is the world’s worst golfer.

You can skip this ad in 5 seconds