How SoftComply and Eficode helped Cobham Satcom Build a Scalable Risk Management Framework in Jira

July 22, 2026

Implementing risk management in highly regulated industries isn’t just about passing audits – it’s about creating processes that scale across the business.

That was exactly the challenge facing Cobham Satcom, a leading provider of satellite communication solutions for the defence and aerospace industries.

Working together, SoftComply and Eficode combined product expertise with Atlassian consulting to deliver a practical, scalable risk management framework in Jira. Rather than building everything from scratch, the project combined the strengths of SoftComply Risk Manager Plus for Information Security Risk Management with a tailored Vendor Risk Assessment solution designed by Eficode.

The result? A framework that supports compliance today while providing a foundation for future governance initiatives.

Check out the interview between Mirjam from Eficode and Marion from SoftComply how Atlassian Solution and Marketplace Partners worked together to help implement the scalable risk management solution at Cobham Satcom:

 

The challenge: compliance is about business processes, not just a technical project

Like many organisations operating under ISO 27001, NIS2, GDPR and industry-specific defence requirements, Cobham Satcom needed more than another collection of Jira projects and custom fields.

They needed a way to:

  • manage information security risks consistently
  • assess vendor risks before onboarding suppliers
  • automate manual governance processes
  • create reusable workflows instead of disconnected solutions
  • build a foundation that could evolve as regulations and business requirements change


As Eficode consultant
Mirjam recalls, her first reaction to the project was refreshingly honest:

“First of all… breathe. Nothing is going to explode.”

It’s advice many Atlassian consultants can relate to when stepping into their first highly regulated environment.

Two risk management workflows, one shared vision

Rather than trying to solve every governance challenge with one solution, the project divided responsibilities where they made the most sense.

Information security risk management with SoftComply Risk Manager Plus

Cobham Satcom implemented SoftComply Risk Manager Plus to establish a structured Information Security Risk Management process directly inside Jira.

Instead of designing complex data models, workflows and reporting from the ground up, the organisation adopted an established framework aligned with compliance best practices embedded in the SoftComply Risk Manager Plus app in Jira Cloud.

This allowed the team to focus on configuring the information security risk management solution around Cobham’s own governance processes instead of reinventing core risk management capabilities.

Vendor risk assessment built in Jira Service Management

Alongside the information security programme, Mirjam designed an automated Vendor Risk Assessment process using Jira Service Management.

The workflow automatically:

  • initiates supplier onboarding requests
  • sends tailored questionnaires to vendors
  • separates legal, finance and security assessments into dedicated forms
  • routes responses to the appropriate internal reviewers
  • automatically calculates vendor risk scores based on predefined criteria
  • classifies vendors according to Cobham’s internal risk thresholds


The design significantly reduced manual work while ensuring every supplier followed the same governance process.

The biggest lesson: Understand the process before you build

Many Jira administrators instinctively start with workflows, automation rules and custom fields.

Highly regulated organisations require a different mindset.

Before a single automation was built, the project focused on understanding how risks moved through the organisation, who owned each decision, and how future processes would connect together.

As Mirjam explains, the goal wasn’t simply creating another Jira project – it was ensuring that today’s solution could support tomorrow’s governance initiatives without becoming another isolated system.

For Atlassian Solution Partners, this is one of the biggest shifts happening today: customers increasingly need business process consultants, not just Jira administrators.

Why building everything yourself isn’t always the best engineering decision

One of the interview’s recurring themes is something every technical consultant has experienced.

Engineers love building things.

But as Mirjam puts it:

“We as engineers want to build things… but we do not want to rebuild things that already exist.”

Risk management is a perfect example.

Building a complete governance framework from scratch means creating:

  • risk registers
  • assessment methodologies
  • relationships between risks and controls
  • reporting
  • permissions
  • auditability
  • compliance structures
  • maintenance processes


That’s an enormous amount of work before delivering any business value.

Instead, Cobham Satcom combined an established Information Security Risk Management solution (provided by SoftComply Risk Manager Plus) with targeted customisation where it truly mattered.

The result was faster implementation, lower long-term maintenance, and greater confidence that the solution reflected recognised compliance practices.

AI is exciting but reliability comes first

Like every technology conversation today, the project eventually turned to AI.

Mirjam experimented with using Atlassian Rovo to calculate vendor risk scores using natural language instructions.

The idea was promising.

The results weren’t.

Despite multiple attempts, the AI produced inconsistent risk scores for the same questionnaire responses – an unacceptable outcome in a regulated environment where every decision must be reliable, explainable and repeatable.

Her conclusion reflects a practical approach many organisations are taking:

Use AI where it creates value but never at the expense of reliable governance.

Advice for Atlassian Solution Partners

Perhaps the strongest takeaway from the project wasn’t technical at all.

It was about mindset.

Consultants working in governance, risk and compliance don’t need to know every regulation from day one.

They need curiosity.

They need to ask questions.

And they need to know when to rely on proven solutions instead of building everything themselves.

As Mirjam puts it:

“You’re not expected to know everything.”

Looking ahead

Cobham Satcom’s long-term vision is broader than managing individual risks.

It’s about creating a connected ecosystem where information security, vendor risk, operational risk and departmental risk registers all contribute to a shared view of organisational risk.

That vision is much easier to achieve when consultants, customers and technology vendors work together.

By combining SoftComply Risk Manager Plus with Eficode’s implementation expertise, Cobham Satcom established a scalable governance foundation that supports both today’s compliance requirements and tomorrow’s business growth.

For Atlassian Solution Partners, the message is simple:

Start by asking where the business is heading to before building a scalable risk management solution.

Table of Contents

Ready to get started?

Contact us to book a demo and learn how SoftComply can cover all your needs

Xray SoftComply Risk Based Testing Solution
Picture of Marion Lepmets

Marion Lepmets

CEO
July 7, 2026

Risk management is a critical part of product development and QA, especially in regulated industries where every feature must meet strict safety and compliance standards. Yet, as teams move faster in agile environments, managing the connection between risk and testing often becomes messy or manual. What if your risk management...

Frictionless CISO in Jira
Picture of Marion Lepmets

Marion Lepmets

CEO
July 2, 2026

What if your next ISO 27001 audit required almost no preparation? That’s exactly how Lemuel Valdez, CISO at Cobham Satcom, approaches security. Instead of scrambling to collect evidence before an audit, he builds systems where audit readiness is simply a byproduct of everyday work. “Controls, risk approvals, documents and evidence...

e-signature
Picture of Matteo Gubellini

Matteo Gubellini

Regulatory Affairs Manager
June 30, 2026

Not every Confluence e-signature app is designed for regulated industries. This guide explains how to evaluate Atlassian Marketplace apps against 21 CFR Part 11 and choose the right solution for MedTech, pharma, and biotech teams. Looking for an E-Signature App for Confluence? Open the Atlassian Marketplace and search for electronic...