Getting the GTIA Cybersecurity Trustmark (Part 2): Lessons from the Trenches

By Ashley Watters

Jul 17, 2025

Share this post

Protecting your clients and your own business takes discipline, time and resources. Anyone who has put in the effort to perform at or above industry standards and reach Assured status for the GTIA Cybersecurity Trustmark will tell you that it takes a significant amount of elbow grease and a fair amount of digging around for documentation. But, the hard work doesn’t go unrewarded and those ITSPs who have been through the trenches and come out the other side report that the Trustmark is well worth the work.

The GTIA Cybersecurity Trustmark includes safeguards for policies, system configurations, risk management protocols and staff training. And they’re all valuable and important to follow, according to executives from Trustmark-assured companies. Here are some lessons learned from ITSPs who have been through the process.

Read Part 1: Showcasing Your Company’s Security

Get Your Employees on Board

Employees are a big part of an ITSP reaching Assured status. Everyone needs to be on board if you truly want to make it through the process, not only to make sure you cover every aspect of your organization, but also because your employees will be expected to maintain an elevated level of security awareness moving forward.

Carmine Corridore, president and founder of Underdog Cyber Defense, encourages ITSPs to bring everyone into the conversation. “One thing I did realize is that I had to include my employees in this journey moving forward. I can’t be the sole person everyone comes to with questions about security. We’re creating a whole team to handle incident response, and they need to know what to do,” he says.

Schedule Time to Get it Done

One of the primary pieces of feedback ITSPs provide is the time it takes to achieve the Trustmark. Everything should be examined and accounted for with a fine-tooth comb. remarked on the time commitment, recommending that ITSPs should set aside time for the process just as you would any other project, according to Mark Kolk with Q-Cyber.

“It’s hard to implement something like this. Dedicate time. Don’t just do it in between work or it will never get done. Reserve the time and focus on the Trustmark,” he suggests.

Make Your Own Policies

Another key area that requires review is your organization’s policies. Your ITSP will need to demonstrate that they have solid cybersecurity policies in place to manage incidents. Kevin Mann, president of Resilient IT, noted that policy development is a pitfall for many companies.

“The biggest problem people make, doesn’t matter which vertical you’re in, if you want policy, you can’t just slap your name on it and sign off and say it’s good for your company if you haven’t actually read the policy. Many companies use a policy template, they think it looks good, but they don’t read the content and they’re not proper for their organization,” he says.

Mann recommends crafting your own policy so that it actually works for your organization. No two companies are the same and every company will require policies that fit their technology, their stack and their culture.

Get Ready for an In-Depth Data Discovery

Uncovering where all of your data lives and how it flows can be a challenge. Companies reported difficulty with identifying all of their data sources across departments. Josh Hohbein, information security lead at CentrexIT, found it challenging to really understand their full data structure across various departments.

“Data discovery is a big challenge. That’ s an undertaking. We had bits and pieces, but there were multi-departmental hands filling it out. Some of the more advanced data items were definitely challenging,” he says.

Be Prepared to Evaluate Your Physical Security Too

Security preparedness goes well beyond cybersecurity. You have to evaluate your physical security protocols also. This means taking a look around your locations and documenting your security for hardware and buildings.

For Michael Yudovin, senior engineer and CTO at Reliable Technology, this was a challenging aspect of the Trustmark process. Yudovin’s team was already well versed in cybersecurity and they’d already been through CIS, but he found that physical security hadn’t been assessed as thoroughly as their technology. “In retrospect, the hard things were physical security. Not only did we not lock down ports, but we didn’t unplug ports from the wall. We had to go through all of that” he says.

Don’t Expect Perfection

Perfection is the enemy of progress, as they say. And that certainly applies to the Trustmark. Many companies who pursue the Trustmark are already security-minded and have been through audits. They expect to breeze right through, but the truth is that every company has gaps and expecting perfection will limit your progress.

“Going through all this, there’s a lot of eye-openers. We felt we were doing things secure correctly, then we’d find a gap here, find a gap there. Even now we still find gaps. There’s no way you’ll never find nothing. We’re not perfect. We catch things. If you’re not finding anything, you’re not doing a good job. There’s always something,” says Yudovin.

Achieving Assured status for the Trustmark takes time and work, but going through the process is one of the best decisions an ITSP could make, said Mann. “It provides you with foundational knowledge and information to do things correctly to run your business. Until there’s a standard for MSPs or regulations, the Trustmark is about as close as you can get from an operational standpoint.”

Learn more about the GTIA Cybersecurity Trustmark.

Read part 4: How to Obtain Employee Buy-In

Related Posts:

Group of professionals working together
By Ashley Watters / Sep 26, 2025

Getting the GTIA Cybersecurity Trustmark (Part 4): How to Obtain Employee Buy-In

Providing critical services to companies and supporting organizations with their technology needs is no easy lift and IT service providers (ITSPs) are the support services that keep companies operational. Consequently, ITSP employees often have their hands full keeping up with client demands and responsibilities, leaving little time to work on business-building projects such as the GTIA Cybersecurity Trustmark.