Challenge
As Xactly scaled, its attack surface and security considerations evolved as well. To prioritize investments that support value creation and reduce drag on business performance, Matt Sharp (CISO, Xactly) and his team created a clear mapping of revenue streams to technical assets. Then they automated asset scoring, revealing a clear link between risk and business critical assets. At the same time, they applied Cyber Risk Quantification (CRQ) within a control framework, enabling risk to be modeled using annualized loss expectancy, and then prioritizing investments accordingly.
To execute on the important projects, alignment across Product, Engineering, DevOps, SRE, and IT teams required coordination. As stakeholder complexity increased, so did friction between risk insight and enterprise action.
Solution
Xactly implemented Continuous Threat Exposure Management (CTEM) powered by NEXA to transform exposure data into action-ready intelligence. The platform democratized access to risk intelligence, ensuring broader visibility into emerging threats while streamlining existing workflows.
Results
In less than three years, while continuing to scale its platform and innovation footprint, Xactly:
- Improved cybersecurity maturity by 92%
- Reduced quantified cyber risk (annualized loss expectancy) by 39%
- Achieved these milestones within the same overall budget envelope
CTEM + NEXA helped us compress feedback loops, democratize risk intelligence, and accelerate action across the enterprise. The result wasn’t theoretical improvement, it was measurable reduction in annualized loss expectancy within a disciplined capital framework. That’s how security supports enterprise growth.”
— Matt Sharp, CISO, Xactly