---
title: DevOps Team Shifts to Preventive Security - Oshyn
description: Oshyn helps NEAMB shift from reactive patching to a fully documented, preventive security program, protecting the financial data of 3 million educators.
url: http://www.oshyn.com/work/devops-preventive-security
---
# DevOps Team Shifts Member Benefits Organization from Reactive Patching to Preventive Security

![DevOps engineer monitoring NEAMB's website](https://media2.oshyn.com/-/media/Oshyn/Case-Studies/NEAMB---DevOps/cs_hero_devops-preventive-security.jpg?rev=cfe06e0e44944f8aa1addf82fbf7d1bf&hash=830748C5A17D6B1AC5B7BCB293BF0A77)

The National Education Association Member Benefits (NEAMB), a subsidiary of the National Education Association (NEA), offers discounts and benefits on travel, insurance, finance, and more for teachers.

![NEAMB logo](https://media2.oshyn.com/-/media/Oshyn/Case-Studies/NEAMB---DevOps/cs_intro_devops-preventive-security.jpg?rev=80d3f12eddb24d118904583f23d7da41?h=564&w=476)


- Services
- DevOps for Sitecore

- Technologies
- Microsoft Update (WSUS)
- AWS Systems Manager Patch Manager
- Azure Update Management
- Infrastructure monitoring platform
- Configuration management tooling
- Jira
- Documentation & Reporting tools

#### Oshyn takes full ownership of NEAMB's recurring security update cycle, shifting the organization from reactive patching to a fully documented, preventive security operation.

## The Challenge

Three million educators trust NEAMB to safeguard their benefits, retirement accounts, and personal financial data. Every time a member logs in to check a balance or file a claim, that trust depends entirely on always-on infrastructure that must remain uncompromised and up to date against the security vulnerabilities disclosed every month by Microsoft, AWS, and Azure.

For an organization in this position, a security incident, whether a data breach or extended outage, threatens more than uptime. It puts the organization's reputation and regulatory standing on the line, along with real legal exposure if members' data is compromised.

NEAMB’s internal team wasn't idle, but it was stretched thin. Patches went out at inconsistent intervals, and cloud-provider advisories from AWS and Azure sometimes sat unread for weeks. Monitoring was fragmented enough that problems often surfaced only after they'd already caused impact, with no single view of infrastructure health to catch them earlier.

NEAMB didn't need another tool or policy document sitting on a shelf, so they turned to Oshyn to help them own the problem directly, maintain accountability for keeping patches on schedule, advisories reviewed, and infrastructure visible before any of it reached member-facing systems.

## The Solution

Oshyn was selected due to its extensive DevOps and security expertise. Since Oshyn’s DevOps team was already supporting NEAMB with other work, they absorbed full ownership of NEAMB's preventive security program, keeping patching, monitoring, and advisory management tightly coordinated with the existing release calendar.

Oshyn introduced a program built around four recurring disciplines. Each month, Oshyn reviews Microsoft's security bulletins and identifies every applicable patch for in-scope Windows systems. Those updates get staged in non-production environments first, then deployed during agreed maintenance windows and verified afterward. The same rigor applies to application-level updates, web servers, runtime environments, libraries, and middleware, where Oshyn monitors vendor channels and coordinates deployments around NEAMB's operational schedule.

Oshyn also tracks AWS and Azure security advisories directly, translating provider recommendations into concrete update actions aligned with the AWS Well-Architected Framework and Azure Security Benchmark. A separate monitoring layer continuously watches NEAMB's infrastructure for performance anomalies, configuration drift, and early signs of compromise, so issues are resolved before they worsen.

Every action taken is documented. Monthly reports give NEAMB's leadership a plain-language view of update status, system health, and open risk items, producing the kind of audit-ready evidence that makes compliance reviews significantly less painful.

![Laptop screen with NEAMB website](https://media2.oshyn.com/-/media/Oshyn/Case-Studies/NEAMB---DevOps/solutions-laptop_devops-preventive-security.png?rev=54edd5fb040b4c1e9b1f09211085a6e4?h=568&w=714)

![DevOps engineer monitoring NEAMB's website](https://media2.oshyn.com/-/media/Oshyn/Case-Studies/NEAMB---DevOps/cs_thumb_devops-preventive-security.jpg?rev=c7446debf6334b6ebdd144b90fd513a5)

![DevOps engineer monitoring NEAMB's website](https://media2.oshyn.com/-/media/Oshyn/Case-Studies/NEAMB---DevOps/cs_hp_thumb_devops-preventive-security.jpg?rev=30b7ace3331e46d2a4f384af3211c737)

DevOps Team Shifts Member Benefits Organization from Reactive Patching to Preventive Security

![agile](https://media2.oshyn.com/-/media/Oshyn/Case-Studies/NEAMB---Build/neamb-build_tablet.jpg?rev=13b2f80590c64cb7a771ab096e300a39)

DevOps Team Shifts Member Benefits Organization from Reactive Patching to Preventive Security

![NEA Member Benefits logo](https://media2.oshyn.com/-/media/Oshyn/TabbedCustomerCarousel/client-neamb-logo_wh.svg?rev=e2d2e06af54c4d70977d3048e61ef88b)

Oshyn helps NEAMB shift from reactive patching to a fully documented, preventive security program, protecting 3M educators' financial data.

![DevOps engineer monitoring NEAMB's website](https://media2.oshyn.com/-/media/Oshyn/Case-Studies/NEAMB---DevOps/cs_list_thumb_devops-preventive-security.jpg?rev=f37f7f8e6ab542598aac95b0a490e44e)

![NEA Member Benefits logo](https://media2.oshyn.com/-/media/Oshyn/TabbedCustomerCarousel/client-neamb-logo_wh.svg?rev=e2d2e06af54c4d70977d3048e61ef88b)

![NEA Member Benefits logo](https://media2.oshyn.com/-/media/Oshyn/TabbedCustomerCarousel/client-neamb-logo.svg?rev=dad462b233794b09aea90d31e7e9c540)


DevOps Team Shifts Member Benefits Organization from Reactive Patching to Preventive Security

## The Outcome

With Oshyn’s help, NEAMB now has a fully documented, consistent monthly security update cycle. Cloud advisories that once sat unreviewed for weeks are now assessed and acted on as part of a standing process, and critical and high-severity vulnerabilities are addressed within defined remediation windows, dramatically reducing the exposure window between disclosure and remediation.

Continuous monitoring has enabled Oshyn to find and solve infrastructure issues before they affect member-facing systems, protecting service availability for the 3 million educators who depend on it. NEAMB's leadership now has regular, clear visibility into their security posture, and a program built to catch risks when they're still small, before they turn into incidents.
