Getting the GTIA Cybersecurity Trustmark (Part 4): How to Obtain Employee Buy-In

By Ashley Watters

Sep 26, 2025

Share this post

Group of professionals working together

Providing critical services to companies and supporting organizations with their technology needs is no easy lift and IT service providers (ITSPs) are the support services that keep companies operational. Consequently, ITSP employees often have their hands full keeping up with client demands and responsibilities, leaving little time to work on business-building projects such as the GTIA Cybersecurity Trustmark.

Make no mistake, the Cybersecurity Trustmark is definitely worth the work according to ITSPs—but you need employee buy-in. This is how you get it.

Adopt a Security-First Mindset

The Trustmark demonstrates your commitment to secure processes and policies. It shows your clients and industry partners that you have a security-first mindset and that you are a trusted provider. Before that can happen, it needs to be true and it needs to be true for all of your employees.

Your employees should be executing secure practices regularly as part of their everyday tasks. If they’re doing that with a security-first mindset, undertaking the Cybersecurity Trustmark process no longer seems like a separate endeavor because your employees will already be following best practice.

“My team was a little resistant as first. The initial lift is heavy, but once you are actually implementing all the safeguards, the load gets much lighter. Don’t ignore your security and it will be a much easier ongoing process,” said Jim Harryman, founder and CEO of Kinetic Technology Group.

Harryman found that implementing secure practices made the Trustmark process far easier on his employees.

Utilize User-Friendly tools to Gather Data

Gathering the data you need doesn’t have to be overwhelming when you’re using the right tools. Adopt tools that can help your team be efficient and effective. Josh Hohbein, information and security lead at CentrexIT, knew the importance of the Trustmark and he ensured his team made the time to complete the process. He did feel, however, that his team would have more efficient if they’d chosen to use better tools.

“We had bits and pieces put together already. With multi-departmental hands filling is out, it was challenging to get things done because we were passing around a large Excel spreadsheet that was hard to read and even harder to fill out,” he said.

Using a tool designed for capturing the data in a user-friendly format will simplify the process for your employees.

Make Everyone Accountable for Security

Being a secure organization can only truly be accomplished when it becomes a collective responsibility. When Carmine Corridore, president and founder of Underdog Cyber Defense, began the Cybersecurity Trustmark process, it became clear that her team would only succeed if everyone was accountable for their security.

“My team was mostly paranoid as far as security, but everyone needs to be on board. I realized I had to include everyone in this journey. We’re creating a whole team to handle incident response and know what to do so I can’t be the sole person undertaking the process,” she said.

Involving her team made the process far easier and ensured all employees at her ITSP were taking security seriously.

Free Up Employee Time to Pursue the Trustmark

The to-do list for employees can seem overwhelming at times. If you choose to add the Trustmark to that list, you’ll want to give your staff the time they need to complete their tasks. Otherwise, it’s unlikely to be a successful endeavor.

“Don’t boil the ocean. Do little steps at a time. But absolutely, dedicate time to this. Put it on the calendar. Don’t wing it. There has to be a process, and you have to follow a schedule,” said Michael Yudovin, senior engineer and CTO at Reliable Technology.

Yudovin and team found that dedicated time was the key to ensuring their success with the Cybersecurity Trustmark.

Use the Available Forum Resources

Your team will have questions as you undergo the process. Using the Trustmark forum resources can be a huge help and get those questions answered quickly. Additionally, those who have already undergone the Trustmark process can offer their perspectives and advice along the way.

“Trying to interpret what controls were being referenced was sometimes hard, but our GTIA resources were great, and the forums were a good resource to ask those questions,” Corridore said.

>> Read other tips and advice from industry leaders who have undergone the GTIA Cybersecurity Trustmark process.

Employee buy-in can make a big difference in the time and resources necessary to achieve the Trustmark.

“Do it. It really makes sure you’re doing the right things. This is the only [company-wide assurance] that is MSP-specific. Hop in, do things, get the credit. It really is a roadmap for best practices,” Hohbein said.

Learn more about the GTIA Cybersecurity Trustmark.
 

Related Posts:

By Ashley Watters / Jul 17, 2025

Getting the GTIA Cybersecurity Trustmark (Part 2): Lessons from the Trenches

Protecting your clients and your own business takes discipline, time and resources. Anyone who has put in the effort to perform at or above industry standards and reach Assured status for the GTIA Cybersecurity Trustmark will tell you that it takes a significant amount of elbow grease and a fair amount of digging around for documentation. But, the hard work doesn’t go unrewarded and those ITSPs who have been through the trenches and come out the other side report that the Trustmark is well worth the work.