About Graco
Based in Minneapolis, Graco, Inc., is a world leader in fluid handling systems and components. Graco products move, measure, control, dispense, and apply a wide range of fluids and viscous materials used in vehicle lubrication, commercial, and industrial settings. Graco’s proprietary products, manufacturing processes, and high-quality customer communications are key components of the value that Graco provides.
For more information, visit graco.com.
NetSPI Solutions
Penetration Testing (PTaaS)
Industry
Manufacturing
Employee Count
1k-5k
Headquarters
Minnesota, United States
The manufacturing industry has changed significantly over the past decade. By shifting to overseas operations, especially in Asia, companies have been able to recognize significant cost savings. At the same time, there are risks involved. For example, manufacturers often have valuable intellectual property resulting from years of research and development efforts. That intellectual property is more vulnerable in manufacturing processes that span the globe.
As an organization that has developed both organically and through acquisitions, Graco has confronted a number of IS security, risk, and compliance challenges associated with that growth. At the same time, Graco also faces numerous challenges managing IS risks because of its manufacturing operations in the U.S., Europe, and Asia. As an industry leader, Graco has committed itself to ensuring the security of its intellectual property and the integrity of its operations. With these goals in mind, Graco’s Internal Audit team, IS group, and NetSPI have worked to ensure operational integrity, customer confidentiality, and regulatory compliance.
To achieve these three goals, NetSPI has partnered with Graco’s Internal Audit group and the IS staff, and become an important part of Graco’s Internal Audit process. NetSPI provides the critical information security, compliance, and industry best practices that help Graco understand, analyze, and mitigate risk. Since 2002, NetSPI has provided Graco’s Internal Audit with the following information technology and security risk management services:
- Internal Audit Partnership
- Security Program Development and Roadmap Creation
- Risk Analysis
- Quarterly Internet-Based Assessments
- Policy, Standards, and Architecture Review
- Network, Systems, and Wireless Assessment
Graco and NetSPI have entered into a three-year contract whereby NetSPI provides independent security evaluation. This large project includes comprehensive security program assessment, security program review, and regulatory compliance (with Sarbanes-Oxley as well as standards like ISO 17799, NIST, and NSA). This relationship has allowed Graco to focus on hiring employees for critical IS operations while satisfying Internal Audit requirements.
As a result of these efforts, Graco has realized considerable cost savings by having NetSPI execute security and compliance activities. At the same time, this relationship with NetSPI has also enabled Graco to reduce its operational risk and help ensure regulatory compliance.
Daniel Mathews, Internal Audit Manager at Graco, noted that: “NetSPI has done an excellent job understanding risk and compliance, and creating usable solutions at Graco. NetSPI has integrated with the Internal Audit group and provided significant value to Graco’s IS staff. The value of NetSPI is based on its strong technical insights, a comprehensive understanding of Internal Audit, and its realistic recommendations for remediation.”
Explore More Success Stories
Quantum Health: Redefining Benefits Navigation with Proactive Engagement and Cost Savings
Information Security Officer
By simulating real-world ransomware attacks, NetSPI Detective Controls Testing delivered 11x ROI and strengthened ransomware defenses for Quantum Health.
Everywhen Partners with NetSPI to Elevate TLPT Standards and Build Unparalleled Trust
CISO, Everywhen
“NetSPI Red Team consultant’s transparency, attention to detail, and commitment to building strong relationships make them feel like an integral part of your internal team, not just an external vendor.”
EAB Global improves attack surface security within 15 seconds using NetSPI Attack Surface Visibility Solutions
CISO, EAB Global
“NetSPI Attack Surface Visibility has saved EAB Global time, money, and helped us mature our program by helping answer questions faster and more accurately.”