For HR solutions provider Sympa, which operates in several European countries, absolute data reliability, data protection and cyber security are business‑critical. As a SaaS company, Sympa’s cloud-based HR solution processes and stores customers’ employees’ personal data, making data security one of the cornerstones of Sympa’s operations. As a modern, cloud‑native growth company, Sympa has long invested in securing its public cloud environment.

“Sympa has always taken cyber security seriously. In addition to our ISO 9001 quality management system, we have held the ISO 27001 information security certification since 2014, and a cyber security partner has been monitoring our cloud services for a long time,” says Arttu Heikkilä, CTO of Sympa.

Sympa is the leading HR solutions provider in the Nordics. Its comprehensive offering covers the entire employee lifecycle, and its broad HR tools ecosystem brings all tools together into a single core system. Sympa also provides powerful HR tools designed to support HR professionals and business leaders in managing and developing their workforce.

As Sympa continued to grow both in the Nordic region and more broadly across Europe, the company reviewed its cyber security standards and public cloud development. How could cyber security and 24/7 public cloud services be further improved?

From a multi-vendor model to a single partnership

“We realized that our previous cyber security partner’s service offering no longer met all of our new needs, so we decided to tender the services among five different providers. Our goal was a cyber security service that offers breadth, continuity and scalability,” Heikkilä explains.

Previously, Sympa had distributed its IT environment, 24/7 public cloud services and 24/7 cyber security services across several vendors, which created challenges in coordination and incident troubleshooting. Seamless collaboration between cyber security, public cloud services and IT services was identified as essential for a SaaS company.

The solution was a broad partnership with Elisa, combining IT services, 24/7 monitored Azure public cloud services, and 24/7 cyber security services. This enables Sympa to provide even more comprehensive, higher-quality and more secure services for its customers and employees. Thanks to the unified solution, Sympa’s own experts have been able to focus more on developing the core business.

Today, Elisa’s cyber security and cloud professionals can resolve emerging issues directly with each other, without messages having to pass through Sympa.

Our workload has eased. We have many other priorities besides acting as an intermediary between different vendors. The service level of our cyber security and public cloud environment has improved, because if the worst were to happen, Elisa’s Cyber Security Center can itself shut down the necessary public cloud services – even in the middle of the night,” says Ari‑Pekka Puputti, Head of Cloud at Sympa.

A continuous improvement model that works

“In the tendering process, it was extremely important to us how we could ensure that the level of cyber security and services continues to evolve. Comprehensive security is never finished – it requires continuous development and readiness to respond as cyber threats change,” Heikkilä reflects.

The partnership with Elisa, which began in early 2024, has already proven to be the right choice.

“We have very productive meetings with Elisa, where we jointly review cyber security-related matters. For example, we have been able to tighten rules in our IT environment and proactively resolve issues before potential problems arise,” Heikkilä says.

Sympa invests heavily in product development and the services it provides to customers. Information security has naturally been at the core of Sympa’s operations throughout its 20-year history, and this development work will continue in the future.

“I appreciate that continuous service development is included in the pricing of Elisa’s core cyber security service. It enables good dialogue and ongoing, mutual improvement,” Heikkilä adds.

Continuous micro-training keeps employees alert

At the heart of Sympa’s cyber security approach are technical monitoring, protection and employee security awareness.

“As part of our partnership with Elisa, we introduced the Hoxhunt tool, which sends simulated phishing emails to our employees – posing, for example, as the CEO or HR Director. This helps raise awareness of new types of scams so everyone can recognize them and avoid falling victim. This kind of weekly micro-training is an excellent way to increase employee awareness,” Puputti explains.

Compliance with GDPR, NIS2 and ISO 27001 creates a competitive advantage

For many of Sympa’s customers, it is important that data is stored and protected within the EU.

“Compliance with the new NIS2 Directive is important for many of our customers, so we have invested in meeting its requirements. ISO 27001, ISO 9001 and GDPR are already familiar frameworks for our personnel,” Heikkilä says.

High standards of information security and data protection provide Sympa with a competitive advantage in the demanding HR software market.

“We can focus on developing our core product and provide our customers with peace of mind that their employee data is secure – around the clock. A high level of information security is a clear differentiator for us in the market,” Heikkilä summarizes.

Two decades of experience in human resources management have established Sympa as a leading player in the European HR technology market. Sympa employs approximately 150 people across four countries, and more than 1,000 organizations in over 100 countries already use the tools within Sympa’s HR solution.

Cyber security as part of all IT services

The partnership between Sympa and Elisa includes, in addition to Elisa’s 24/7 Cyber Security Center service, Azure 24/7 public cloud services and IT end-user services:

  • 24/7 Cyber Security Center (SOC): Through Elisa, Sympa receives real-time, around-the-clock monitoring and incident management. Potential attacks can be responded to immediately – even in the middle of the night – and, if necessary, compromised services can be shut down.
  • Centralized 24/7 cloud and security management: Sympa operates entirely in the Azure cloud, and Elisa is one of Microsoft’s strongest Nordic partners. This collaboration is reflected in up-to-date security patches, effective troubleshooting tools and rapid responses to new threats.
  • IT maintenance and 24/7 monitoring: Continuous monitoring and management of end-user device vulnerabilities prevents attack attempts originating from endpoints.
  • Development and continuous improvement: Elisa’s cyber security service pricing and operating model encourage continuous development. Sympa’s and Elisa’s cyber security professionals work closely together as a unified team.