Penetration Testing Isn't About Finding Vulnerabilities—It's About Reducing Business Risk
Penetration Testing Isn’t About Finding Vulnerabilities—It’s About Reducing Business Risk The most valuable penetration ...
Customer Story
Evident.io was the leader in security and compliance automation for public clouds like AWS and Microsoft Azure. The Evident SaaS product enables organizations of all sizes to continuously monitor and manage cloud security and compliance risk — minimizing attack surface and improving overall security posture, all from a single dashboard. Evident.io was acquired by Palo Alto Networks in March 2018.
Evident.io (now part of Palo Alto Networks)
$5.5B annual revenue
Technology
SOC 2
The Challenge
Conduct third party audit to help position evident.io (now part of Palo Alto Networks) as an early adopter of 2017 SOC 2 criteria – before official guidance is available.
RKON and Evident.io leadership teamed up to build a cloud compliance program for the ESP that would satisfy an AICPA SOC 2 audit, positioning Evident.io as an early adopter of the 2017 SOC 2 criteria – before official guidance was available.
Our Solution
Conduct third party audit to help position evident.io (now part of Palo Alto Networks) as an early adopter of 2017 SOC 2 criteria – before official guidance is available.
RKON and Evident.io leadership teamed up to build a cloud compliance program for the ESP that would satisfy an AICPA SOC 2 audit, positioning Evident.io as an early adopter of the 2017 SOC 2 criteria – before official guidance was available.
"Repeatedly responding to hundreds of items in dozens of vendor questionnaires is horribly inefficient, and we knew self-certified assessments would not build the kind of customer trust and transparency we needed"
- Tim Prendergast, Founder & CEO of Evident.io
Penetration Testing Isn’t About Finding Vulnerabilities—It’s About Reducing Business Risk The most valuable penetration ...
Cyber Risk Is Continuously Evolving. Your Security Validation Strategy Should Keep Pace. Many organizations view penetra...
Why Validating Your Defenses Is Just as Important as Investing in Them Organizations continue to invest heavily in cyber...
The System Security Plan is dead. FedRAMP’s Consolidated Rules for 2026 (CR26), published June 24, retired the document ...