Penetration Testing Isn't About Finding Vulnerabilities—It's About Reducing Business Risk
Penetration Testing Isn’t About Finding Vulnerabilities—It’s About Reducing Business Risk The most valuable penetration ...
Customer Story
Zoro is a wholesale maintenance, repair and operations (MRO) distributor that markets exclusively to small and medium-sized business customers. The company has a simple mission: make it easy for customers to find, buy, and get everything they need. Zoro sells over 12,000,000 product SKUs from thousands of trusted brands, including tools, industrial equipment, business supplies, and more. It is recognized for carrying the hard-to-find MRO products, tools, and equipment customers need to support their facility, warehouse, or any other type of business.
Zoro
Retail
NIST CSF Assessment & Roadmap
The Challenge
Zoro approached RKONfor assistance with its internal governance framework. They decided to use NIST Cybersecurity Framework (CSF) as their primary framework. This is a great framework for companies to start with as it is easily mapped back to other frameworks, such as NIST 800-53, PCI DSS, ISO 27001, and SOC 2. RKON has expertise with NIST CSF and worked with Zoro to help plan the implementation of controls to advance its CSF profile.
Our Solution
RKON reviewed the information security posture of their entire AWS deployment, including computing, networking, storage, identity, and disaster recovery. The posture was mapped to NIST CSF controls, and recommendations for improving each were documented.
AWS EC2: Hardening, Patching, and File Integrity Monitoring
AWS Marketplace: AMIs
AWS VPC: Security Groups and Access Controls
AWS IAM: SSO integration, Users and Roles
AWS RDS: Encryption and Disaster Recovery
AWS S3: Encryption and Access Control
Zoro has adopted the NIST CSF governance framework and is on a path to increase its current profile to a tier that meets its desired risk profile. Completing each recommendation will increase security risk mitigation as Zoro furthers its security-first approach to information technology.
"Our Zoro team absolutely loves working with RKON and considers them one of our favorite vendors. They continuously add value and understand our business.
RKON brought a solid team of cloud security and project management specialists. They involved us enough to keep us on schedule with security efforts and daily work. We always knew where we were in the process, what was needed from us to keep progressing, and our expectations of when each task would be completed. We have found a true and ongoing partnership in security and compliance with RKON."
- Donna Mains, Senior Director of Technology Operations, Zoro
Penetration Testing Isn’t About Finding Vulnerabilities—It’s About Reducing Business Risk The most valuable penetration ...
Cyber Risk Is Continuously Evolving. Your Security Validation Strategy Should Keep Pace. Many organizations view penetra...
Why Validating Your Defenses Is Just as Important as Investing in Them Organizations continue to invest heavily in cyber...
The System Security Plan is dead. FedRAMP’s Consolidated Rules for 2026 (CR26), published June 24, retired the document ...