Insights for Secure, Compliant, and Scalable Growth
Practical guidance on cybersecurity, compliance, AI governance, and GRC—built to help your team manage risk with confidence.
On February 21, 2018, the SEC issued new guidance on cybersecurity disclosures for public companies. As an “interpretive release,” the new guidance in…
Quality Work Does Not Mean Quality Service "Managing the Professional Services Firm" by David Maister is considered to be "core canon" among consultin…
Overview of the SOC for Cybersecurity In 2017 the AICPA published guidance on a new cyber security risk management examination, System and Organizatio…
The NYDFS Cybersecurity regulation is relevant to all financial services, banking, and insurance organizations doing business in the state of New York…
Bottom Line Up Front Security Researchers have publicly disclosed the details of CPU design flaws that are the result of design decisions made industr…
This past week I completed the SANS SEC560 - Network Penetration Testing and Ethical Hacking course at the SANS Cyber Defense Initiative in Washington…
Organizations may benefit from greater understanding of the difference between and appropriate use of NIST 800-53 vs. NIST 800-171, especially when it…
Selecting the right partner to assist with SOC 2 compliance (or anything else) can be challenging. If you are trying to sort through the marketplace t…
If you are trying to determine if your company would benefit from obtaining a SOC report, here are a few questions and answers that may help make the …
This past week I sat for the (ISC)2 CISSP exam and passed on my first attempt! With the entire preparation and test taking experience still fresh on m…
The first thing I try to explain to new auditors (or clients going through an audit for the first time) is what techniques IT auditors use to audit. M…
This past December I took the ISACA CISA exam and I’m pleased to announce that last week, I got my confirmation letter stating that I passed in the to…
Tags
- Cyber Risk Management (59)
- IT Audit And Compliance (33)
- Penetration Testing (31)
- Cybersecurity (26)
- CISO Discussions (24)
- SOC Reporting (23)
- Security (22)
- News And Events (20)
- Christian Hyatt (19)
- ISO 27001 Compliance (19)
- Risk Management (19)
- ISO 27001 (18)
- SOC 2 (18)
- Compliance (17)
- Business (16)
- HITRUST (16)
- PCI DSS (13)
- Regulatory Compliance (12)
- Information Security (11)
- IT Audit (9)
- Webinars (9)
- CISO (8)
- Privacy (8)
- Penetration Test (7)
- Privacy Compliance (7)
- VCISO (7)
- Business Continuity (6)
- Cyber Risk (6)
- GRC Tool (6)
- ISO 42001 (6)
- Leadership (6)
- Compliance As A Service (5)
- Disaster Recovery (5)
- News (5)
- Risk Assessment (5)
- Training (5)
- BCAW (4)
- Cybersecurity Controls (4)
- GDPR (4)
- Network Security (4)
- Access Control (3)
- Artificial Intelligence (3)
- Attack Surface Management (3)
- Awareness Week (3)
- EU AI Act (3)
- Hacking (3)
- ISO (3)
- Passwords (3)
- Press Release (3)
- AWS (2)
- Attack Surface (2)
- Business Continuity Planning (2)
- Cyber Security Law (2)
- ISO 27701 (2)
- Internal Audit (2)
- NIST 800 Series (2)
- Report (2)
- SDLC (2)
- Vendor Management (2)
- Vulnerability Management (2)
- Amazon (1)
- Assessment (1)
- Attestation (1)
- Audit (1)
- BCMS (1)
- Backup And Recovery (1)
- Blackbasta (1)
- CI (1)
- CMMC (1)
- COVID (1)
- Caas (1)
- Certification (1)
- Cloud (1)
- Competitive (1)
- Engineers (1)
- Ethical Hacking (1)
- Exercises (1)
- Grit (1)
- Hashcat (1)
- ISO 22301 (1)
- ISO 27018 (1)
- ISO 42005 (1)
- IaaS (1)
- Kahoot (1)
- Management (1)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- PIA (1)
- Pentest Report (1)
- Phishing (1)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Security Advisory (1)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Vulnerability Scan (1)
- Wannacry (1)