A Compliance Platform Determined to Elevate Resilience
Smarsh provides the archiving and communications compliance platform that roughly a quarter of the world’s financial services firms rely on to meet SEC and FINRA recordkeeping requirements. Headquartered in Portland, Oregon, with offices in Atlanta, New York, London, and India, the company is expanding into the federal government and FedRAMP space, work that raises the bar on its own operational resilience.
To strengthen governance and further elevate resilience across a primarily remote workforce, Smarsh turned to Mitratech Preparis for a governance-led continuity program.
"I think that's pretty spectacular, to be up and running in three weeks with a brand-new tool out of the box. From ink drying to the portal being created took about two hours, which is even more spectacular. It made me feel valued as a customer."
Josh Haravay
Business and Cyber Resilience Architect, Smarsh
挑战
When Josh Haravay joined Smarsh as its Business and Cyber Resilience Architect, he saw an opportunity to formalize and mature the company’s approach to business continuity and disaster recovery. “The frustration was that our documentation couldn’t keep pace with what we were actually delivering,” Josh says. “We needed a way to prove it, consistently, on demand.”
The stakes were rising, too. Smarsh’s move into FedRAMP-regulated federal contracts, combined with new obligations under the EU’s Digital Operational Resilience Act, meant resilience needed to operate as a fully governed, enterprise-wide program. It had to be documented, tested, and ready for scrutiny at any time.
Josh had solved a version of this problem twice before. Both times, he built a governance model instead of a delivery team. He sets the standard, and department leaders own their own plans. At Smarsh, with a majority of its user population working remotely, that governance model was the only one that could scale across every department.
“It makes no sense for me to own a human resources business continuity plan or a product disaster recovery plan,” Josh says. “I’m not the expert. Let the experts own it, and let me make sure what they’re doing meets Disaster Recovery Institute (DRI) best practices, ISO practices, and whatever compliance we need to do.”
"I've never worked with a company that has allowed me to be so involved in the enhancement process and the direction and roadmap of the tool."
Josh Haravay
Business and Cyber Resilience Architect, Smarsh
解决方案
Josh chose Mitratech Preparis Continuity Planning because its licensing model and platform structure were built for governance, not headcount. Department owners write and maintain their own business continuity plans directly in Mitratech Preparis. Josh reviews and governs the results, checking each plan against recognized DRI and ISO standards rather than authoring it himself.
Mitratech Preparis gives Smarsh a clear view into vendor and cloud dependencies across its products, mapping what each one relies on and what happens if a provider goes down, so disaster recovery planning stays actionable rather than theoretical.
Implementation moved quickly. The contract was signed, and the Mitratech Preparis portal was live within about two hours. Full rollout to users across the company took three weeks.
Josh recalls, “I think that’s pretty spectacular, to be up and running in three weeks with a brand-new tool out of the box. From ink drying to the portal being created took about two hours, which is even more spectacular. It made me feel valued as a customer.”
Bringing non-practitioners into a governance model took more hands-on work. Josh built his own documentation, breaking business continuity planning into six steps: risk assessment, business process validation, plan creation, call tree testing, a tabletop exercise, and ongoing review. That gave department owners who had never written a continuity plan a click-by-click path to follow.
Josh says the relationship with Mitratech’s team has shaped how Mitratech Preparis evolves, too, a level of involvement he calls unusual for a vendor relationship. “I’ve never worked with a company that has allowed me to be so involved in the enhancement process and the direction and roadmap of the tool,” Josh adds.
"We have call tree capabilities now that give us real visibility into who's impacted and who needs to know," Josh says. "That's the difference between a fast, coordinated response and a scramble."
Josh Haravay
Business and Cyber Resilience Architect, Smarsh
结果
The real test came from a string of AWS and Azure cloud outages recently. The first outage exposed exactly where plans were incomplete. Departments that hadn’t listed a dependency on Azure in their plans weren’t notified when it went down.
Josh used the gap as a training moment rather than a failure. By the second outage, the difference was measurable. “We probably took two to three hours to notify our impacted teams from the first outage,” Josh says. “When the next one happened, we were notifying teams within 10 to 15 minutes.”
These call tree capabilities mark a significant leap forward in the program’s maturity. “We have call tree capabilities now that give us real visibility into who’s impacted and who needs to know,” Josh says. “That’s the difference between a fast, coordinated response and a scramble.”
Audit readiness improved just as sharply. Smarsh has moved from static, periodically updated documentation to on-demand plan generation. Mitratech Preparis lets Josh generate a current plan on demand instead. “We’ve gone from flat files that could be up to 11 months old to generating plans on the fly,” Josh says. “If you ask for it tomorrow, I’ll generate a new plan for you tomorrow by clicking a button.”
Smarsh’s CISO and GRC and audit teams have noticed the shift from static documentation to on-demand plans. The same approach is now spreading into other parts of the compliance program, including generating policy language directly from control statements. Audit times, audit follow-up questions, and audit failures are all down since the change took hold.
展望未来
Josh sees the program’s next phase as building on that strong foundation: sharper testing, more realistic scenarios, and continued maturity as Smarsh continues growing. “I think our level of maturity can increase as far as things go,” he says. “We’re going to grow together.”
As an AI-first company, Smarsh is eager to bring the same discipline to the AI capabilities coming into the Mitratech Preparis platform. Josh’s first priority is using the AI engine to support governance of the plans being created, generating assessments that surface gaps more quickly and consistently than manual review.
Looking further ahead, he sees the greatest potential in reporting and predictive suggestions, extending the program’s governance model into forward-looking insight rather than point-in-time checks.
"Smarsh demonstrates what's possible when business continuity is treated as a governance discipline rather than a siloed IT function. By leveraging Mitratech Preparis, the company is able to scale audit-ready continuity planning across an entire organization, without owning a single department's plan. For companies navigating the dual pressures of federal compliance and operational resilience, that kind of lean, scalable governance model is efficient and a strategic advantage."
Henry Umney
Managing Director, GRC Strategy & Customer Success
常见问题
Mitratech Preparis is built for governance. A central function sets the standard while department leaders write and own their own plans directly in the platform. At Smarsh, one resiliency architect governs continuity plans across every department using Mitratech Preparis, checking each against DRI and ISO standards without owning any plan himself.
Yes. For organizations without owned data centers, Mitratech Preparis reframes disaster recovery around vendor dependencies rather than internal systems. Smarsh, an all-SaaS company, uses Mitratech Preparis to map which products depend on which cloud providers, so teams can act quickly when a vendor outage hits.
Preparis centralizes call trees, department contacts, and business impact data so response teams can identify who’s affected and notify them without searching across separate systems. After adopting Mitratech Preparis, Smarsh cut cross-team outage notification time from two to three hours down to 10 to 15 minutes following a cloud provider outage.
Mitratech Preparis generates a current plan on demand instead of relying on static files that go stale between review cycles. With Mitratech Preparis, Smarsh generates a fully current, audit-ready plan for any request within minutes.
How long does it take to implement Mitratech Preparis?
Implementation speed depends on program complexity, but Mitratech Preparis is built to get organizations live fast. Smarsh had a functioning Preparis portal within about two hours of signing its contract, and the platform was fully rolled out to users across the company within three weeks.