A Semiconductor Carve-Out Builds the Security Program Its Former Parent Used to Run

Get a Quote
The Project

Overview

A semiconductor company carved out of a larger parent engaged BD Emerson to build the security program the parent used to provide. The program runs five workstreams, and the company affirmed CMMC Level 1 about four months in.
Partnership

BD Emerson x 

Carve-Out Security Program for a Semiconductor Company

The client and the problem

When a semiconductor company with several thousand employees was carved out of its parent, its security belonged to the parent. Endpoint protection, monitoring, policies, and the compliance program its defense customers depended on all ran through the parent under a transition services agreement with an end date. The new company had two security staff. It needed a full program of its own, an infrastructure move out of the parent's environment, and continuous compliance for defense and export-controlled work through the transition.

What we built

The program runs five workstreams. CMMC covers the defense business. An ISO 27001 information security management system covers the company as a whole. Application security brings testing into the development pipeline. Cloud security covers the AWS environment the company is building to leave the parent's infrastructure, along with an assessment of its Oracle Cloud estate. A privacy program covers data inventory and data subject requests, including the employee privacy obligations that come with operations in Europe. Under all five, the team is replacing the parent's day-to-day security services with the company's own endpoint management and EDR, a SIEM, a policy set written for the new company, and a network review, with compliance tracked in Vanta.

How the work ran

A single program office coordinates all five workstreams with the company's technology leadership, and the delivery team has grown to 17 people as the scope expanded. CMMC moved first, and the company affirmed CMMC Level 1 about four months after the program started. The ISO 27001 management system is heading to its Stage 1 audit with an accredited certification body. BD Emerson prepares companies for these assessments and does not perform them: CMMC Level 2 certification comes from an independent C3PAO, and ISO 27001 certification comes from an accredited registrar.

The value delivered

Seven months in, the company has CMMC Level 1 affirmed for its defense business, completed security assessments of its applications and its Oracle Cloud estate, and an ISO 27001 management system heading into audit. The rest of the program, including the cloud build and the move off the parent's infrastructure, continues on the same plan, with each workstream reporting into one program office.

Why the client is not named

Client details in this case study are generalized, and in places combined across engagements, to protect confidentiality. The program combines our carve-out advisory and cybersecurity transformation work, and our guides to IT carve-outs and TSA exit planning cover the separation side. We are glad to walk through comparable work under NDA.

Industry
Semiconductors
Location
Global
Company size
Enterprise
Founded
Undisclosed
CONTACT

Separating from a parent company?

Get a Quote

We stand up the security program the parent used to run, workstream by workstream, on the timeline your transition services agreement sets. Book a working session.

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.