ESH Médias Group is a major local provider of print and digital news in French-speaking Switzerland. Over the past two decades, as the ESH Médias Group grew, the IT team addressed the increasing complexity of operations with a series of SaaS solutions from various service providers in the region.
IT leadership already understood that, with the benefits of enabling steady business growth, the multi-vendor SaaS approach also included gaps in visibility and security across the estate. With 12 different companies across 8 physical locations, all with their own technology history and culture, IT needed a more comprehensive map of applications and the links between them. That visibility would provide a new foundation for instituting a more comprehensive approach to security across the business.
The CTO of ESH Médias saw current risks as an opportunity to strategically improve both resiliency and security across the expanded business. He convinced the Board of Directors to invest in a risk assessment that would provide a prioritized view of existing IT vulnerabilities and clear recommendations for safeguarding the business with efficient operations and a simplified, more resilient IT environment.
Cybersecurity was a primary concern, with targeted cyberattacks against traditional IT and cloud infrastructures growing in both complexity and sophistication. The far-reaching effects of a successful attack can range from downtime and reputational damage to bankruptcy. As the cybersecurity skills gap continues to widen, it was critical to find a partner with deep cybersecurity expertise to help assess cyber risks and establish policies, controls, and compliance programs closely aligned to business objectives.
After reviewing proposals from many potential vendors, ESH Médias chose Kyndryl as the right partner to provide a complete analysis of both technology and and related business risks. ESH Médias partnered with Kyndryl for its deep global expertise assessing IT technical debt and familiarity with local markets and regulations.
Together, ESH Médias and Kyndryl set out to gain visibility into risks and current threats, and define a target state resulting from consistent application of security policies and controls.
Kyndryl worked side by side with ESH Médias application leaders to map the subscription and editorial business roles supported by systems across the company’s 12 distinct IT environments.
The team determined the recovery capabilities (RTC and RPC) of each application and defined recovery objectives (RTO and RPO) based on the application’s importance to the business. Providing visualization of this data helped the company assess the risks and expected recovery timelines and efforts.
Getting clarity on the business impact of technical gaps made the project a big success that we’re building on.