Getting the GTIA Cybersecurity Trustmark (Part 3): Advice from Assured Members

By Ashley Watters

Aug 19, 2025

Share this post

Is the GTIA Cybersecurity Trustmark worth the investment in time, resources and money? Absolutely, according to IT service providers (ITSPs) who have achieved Assured status and elevated their cybersecurity policies and processes along the way.

The Trustmark can enhance your cybersecurity policies and procedures, your reputation with prospects and clients, and help you differentiate yourself in the market.

Greater Insights into Your Organization

For many ITSPs, the Trustmark helps to glean insights about their own organization, far beyond what they would uncover in traditional internal and third-party audits. And they gain with a greater understanding of why and how they should be doing security, according to Jim Harryman, founder and CEO at Kinetic Technology Group.

“I learned a lot of things. Sometimes, it confirmed that we were doing things right, but there was still room for improvement. SOC2 is great, but it’s generally not as prescriptive as what we got out of the Trustmark,” said Harryman.

For Michael Yudovin, senior engineer and CTO at Reliable Technology, the Trustmark helped him better understand how to implement security, but why it’s important—a message he can pass along to clients too.

“The reality is you learn to see how things are. The Trustmark was more about logically securing your organization, operating security in your organization, as opposed to achieving compliance. It makes more sense to how things are put together as a package. Trustmark will help your small business because it’s what makes sense for you and how to achieve it,” Yudovin said.

Improved Processes and Policies

Taking a hard look at your processes and policies is a foundational aspect of the GTIA Cybersecurity Trustmark. Eli Person, centralized services manager with Wolf Consulting, was forced to really dig in on existing processes. It’s easy to fall into a lull when you have a ton of processes, but that doesn’t necessarily mean they’re good ones and the Trustmark prompted Wolf and team to investigate whether their processes and policies were still working for the people who were expected to follow them.

“We did learn from a technical perspective. But we also needed to spend time formalizing policies and making sure we communicate those policies and that everyone understands what they are. We had a large security policies bible that was created previously. But if you hand it to someone who is non-technical, would they understand it? Technically, it met the needs, but we learned had to spend some time putting things in plain English,” Person said.

For Harryman, policies were also a challenge. His team found that while their policies and processes were sound, they didn’t always align.

“One thing I didn’t expect was for our policies and process to not line up. Before the Trustmark, we didn’t realize it. Yes, we had policy and processes, but we’d never spent the amount of time necessary to notice they didn’t go together,” he said.

Better Regulation

Many ITSPs seek out the Trustmark because it validates that they’re adhering to industry standards in a space where due to a lack of regulations anyone can say they’re a cybersecurity expert. That causes confusion and frustration in the market, according to Kevin Mann, president at Resilient IT.

“The main problem is an inherent one, up until now ITSPs have done their own thing. Until ITSPs are regulated in some way, we’re always going to have a problem,” said Mann. “We can continue educating, but there are so many people in this space that should not be in this space because they don’t do the work to do it properly. The Trustmark will change that.”

Mann cites regulatory compliance as the primary reason his company sought out the Trustmark, the ability to show his company operates according to security standards.

Increased Employee Buy-In

Many ITSPs reported that the Trustmark helped them gain greater employee buy-in for enhanced security. It’s easy to tell employees that they need greater security protocols, but often it’s difficult to get them to adhere to those standards in every aspect of their work. For many, the Trustmark process was the eye opener they needed to get their employees to fall into compliance.

“The Trustmark helps because you have checks and balances everywhere. We’re not perfect. We catch things. If you’re not finding anything, you’re not doing a good job," Yudovin said. "There’s always something and now our culture is different. People operate within guard rails. We still see lots of improvement we can do, but I don’t think we have a lot of resistance.”

Improved Trust

It’s really easy for an ITSP to proverbially point fingers at their clients and pick apart their approach to security. It’s entirely another thing to show them how it’s done. The Trustmark isn’t just a sticker, it shows you really understand security, and even more, you live by it.

“I do feel that when we talk to prospects, we’re not muddling our way through it. We know what we’re talking about. The Trustmark was a testament that we do things correctly. Someone checked and yeah, we are operating the right way according to a standard,” said Yudovin.

For Mann, he feels that the Trustmark was exactly what he needed to get his business in a secure place so that he can provide better security for his clients.

“The GTIA Cybersecurity Trustmark is definitely a lot of work, but going through the process is one of the best decisions you could make. It provides you with foundational knowledge and information to do things correctly to run your business,” Mann said.

Learn more about the GTIA Cybersecurity Trustmark.

Related Posts:

By GTIA / Jan 15, 2025

Cybersecurity Predictions and Trends to Watch in 2025

From large-scale ransomware attacks to IT outages to cybercriminal arrests, 2024 was a busy year in cybersecurity. And it’s not likely to slow down or get any easier in 2025. We asked a number of cybersecurity thought leaders for their predictions and trends to watch for the next 12 months. Here’s what they had to say.
Group of professionals working together
By Ashley Watters / Sep 26, 2025

Getting the GTIA Cybersecurity Trustmark (Part 4): How to Obtain Employee Buy-In

Providing critical services to companies and supporting organizations with their technology needs is no easy lift and IT service providers (ITSPs) are the support services that keep companies operational. Consequently, ITSP employees often have their hands full keeping up with client demands and responsibilities, leaving little time to work on business-building projects such as the GTIA Cybersecurity Trustmark.