Client | Mejuri |
Industry | Retail, e-commerce, design and sell Gold Jewelry |
Service | Over 60 locations, 4 continents |
Technologies | Shopify, GCP, SaaS platforms |
Outcome | Mature cybersecurity across, IT, operations, and development. Optimized security licensing |
Engagement | Project and Managed Service |
Mejuri
Founded in 2015, Mejuri’s mission is to turn fine jewelry into an everyday occasion while working
towards making a positive impact in our communities, the industry, and the world.
The business is centered around sustainable practices by focusing on “trusted suppliers across the globe, using high-quality, responsibly sourced materials to create pieces meant to last a lifetime.” Operational expansion plans are expected to require additional operational maturity, security controls, and brand protection as enablers. While the organization has a e-commerce presence, a large amount of sales activity comes from brick and mortar retail operations, and more locations have been planned.
The Challenge
Revenue is heavily dependent upon the end of fiscal year holiday shopping season. The major expense is the purchasing of gold. With consumer confidence and gold prices both in flux, the primary focus is to continue growing revenue but finding ways to cut expense and maintain its margins.
Simultaneously retail expansion is heavily dependent upon renting retail space in areas where consumers will continue to recognize the brand as a luxury boutique product with sustainable practices. Rent in these markets is typically at above market rates. Fortunately the IT ops partner has been able to scale with operations but is primarily focused on availabilit of sites, creating a gap in security.
Security leadership has changed hands many times in recent years, creating fragmented governance structure, unified security technology purchases, and opportunities to standardize the application of standard security practices.
The Solution
Taking the approach of "what go you here, won't get you to the next level". Organizing against Annual Operational Planning cycles, in line with organizational objectives, revenue and expense metrics, and a risk and maturity level expressed by executive management.
Aligning with standard practices, like NIST CSF, and increasing security standardization appropriate for an organizational risk profile like Mejuri's. Knowing there are not many compliance drivers, most growth opportunities are in ensuring the availability of systems and resources as they are designed.
Apply industry standard safeguards across the technology footprint. Implement operational routines to measure security metrics in parallel with operational metrics. Scrutinize legacy practices and vendors for opportunities to optimize costs and support staff.
Results
Unified secure change management with operations and IT.
Market leading endpoint protection and response capability's at 30% reduced cost, previous covered with an over provisioned and under utilized license suite.
Visibility to cloud infrastructure vulnerability posture, that was not available due to operating an incapable tool.
Software development comment
Vendor risk comment
policy comment
IR readiness and training comment