Resources
  • All Resources

    Your central hub for security and compliance content.

  • Blog

    Stay informed with expert insights and practical advice on cybersecurity, privacy, and compliance challenges.

  • News

    Get the latest company updates, industry developments, and regulatory changes impacting the cybersecurity landscape.

  • Whitepapers

    Access in-depth research and strategic guidance on risk management, regulatory compliance, and cybersecurity best practices.

  • Case Studies

    See how organizations like yours solved complex cybersecurity and compliance challenges with TrustNet’s solutions.

Guides
  • All Guides

    Get practical step-by-step guides designed to help you navigate audits, improve security posture, and meet compliance requirements.

Edit Template
Lablynx Case Study

Annual Security Examination for a LIMS Vendor Serving State Government: LabLynx and TrustNet

TL;DR 

LabLynx provides its laboratory information management system to a U.S. state government agency. The state’s information security standard requires vendors who operate IT systems containing state data to undergo an independent security examination every year. 

LabLynx engaged TrustNet as its independent service auditor for that deployment. Each year, TrustNet plans and executes a NIST-aligned examination of the LIMS application, management’s review of the controls for its cloud hosting environment, and the organizational security controls behind it.

Background

LabLynx has built laboratory informatics software since 1997 and supports roughly 120 active deployments across analytical sciences, research, manufacturing, forensic sciences, and health and life sciences.

Among them is a LabLynx LIMS deployment for a state government agency, where the system supports sample tracking, test result management, chain-of-custody documentation, and regulatory reporting for the agency’s laboratory operations.

The Requirement

The state’s information security standard is grounded in the NIST Cybersecurity Framework and built on the NIST SP 800-53 control catalog, whose twenty control families set the baseline for everything from access control and audit logging to incident response and supply chain risk. For a vendor that services the state agency, the standard carries a specific obligation: an independent, third-party IT security examination, performed at least annually.

Why an independent service auditor matters

The state’s audit requirements demand that the auditing firm be genuinely independent of the entity that it evaluates.

TrustNet does not perform management functions, prohibited non-attest services, or other services for LabLynx, so the assessment the state receives is exactly what the requirement intends: an independent examination.

What the annual examination involves

TrustNet runs the engagement in five phases: planning and scoping, documentation review, technical testing, interviews and walkthroughs with LabLynx security and operations staff, and formal reporting.

The relationship. TrustNet has been LabLynx’s independent service auditor for this engagement since 2021.

In TrustNet's words

“LabLynx has been a great partner to work with since 2021. Their team treats security and compliance as a strategic priority rather than a checkbox, which makes our work together straightforward and effective. We appreciate the trust they have placed in TrustNet and the long-term relationship we have built.”

Trevor Horwitz, CISO, TrustNet 

The outcome

The state agency client receives the independent assurance its standard requires, on schedule, every year. The engagement covers this deployment specifically, and what it validates is not only the system but the organizational security controls behind it: the policies, training, incident response, and vulnerability management that LabLynx applies across its control environment.

LabLynx builds laboratory informatics solutions configured to each client’s lab and has done so since 1997. Labs that operate under independent security and compliance audits, like the one described here, are the kind of deployment it is built for. Learn more at www.lablynx.com.

Previous Post

Get Cybersecurity Consultation

For business teams improving security and compliance