Skip to main content

Insights for Secure, Compliant, and Scalable Growth

Practical guidance on cybersecurity, compliance, AI governance, and GRC—built to help your team manage risk with confidence.

SEC Issues New Cybersecurity Guidance: What you need to know

On February 21, 2018, the SEC issued new guidance on cybersecurity disclosures for public companies. As an “interpretive release,” the new guidance in…

Read more

Quality Work Does Not Mean Quality Service

Quality Work Does Not Mean Quality Service "Managing the Professional Services Firm" by David Maister is considered to be "core canon" among consultin…

Read more

What is the difference between SOC 2 and SOC for Cybersecurity?

Overview of the SOC for Cybersecurity In 2017 the AICPA published guidance on a new cyber security risk management examination, System and Organizatio…

Read more

Key Due Dates and Deliverables for the NYDFS Cybersecurity Regulation

The NYDFS Cybersecurity regulation is relevant to all financial services, banking, and insurance organizations doing business in the state of New York…

Read more

Meltdown and Spectre - A Quick Overview

Bottom Line Up Front Security Researchers have publicly disclosed the details of CPU design flaws that are the result of design decisions made industr…

Read more

Takeaways from SANS SEC560- Ethical Hacking and Pen Testing

This past week I completed the SANS SEC560 - Network Penetration Testing and Ethical Hacking course at the SANS Cyber Defense Initiative in Washington…

Read more
ris-blog-fallback-featured-image

Vendor Due-Diligence: NIST 800-53 vs. NIST 800-171

Organizations may benefit from greater understanding of the difference between and appropriate use of NIST 800-53 vs. NIST 800-171, especially when it…

Read more

How to Choose a SOC 2 Audit Firm (with Vendor Scorecard Template)

Selecting the right partner to assist with SOC 2 compliance (or anything else) can be challenging. If you are trying to sort through the marketplace t…

Read more

Should I Get a SOC 2 Report? Examining the ROI of SOC 2 Compliance

If you are trying to determine if your company would benefit from obtaining a SOC report, here are a few questions and answers that may help make the …

Read more
CISSP

Advice for Studying and Passing the CISSP Exam

This past week I sat for the (ISC)2 CISSP exam and passed on my first attempt! With the entire preparation and test taking experience still fresh on m…

Read more
ris-blog-fallback-featured-image

IT Audit Techniques - Inquiry, Observation, Inspection

The first thing I try to explain to new auditors (or clients going through an audit for the first time) is what techniques IT auditors use to audit. M…

Read more
ris-blog-fallback-featured-image

Advice for Taking the CISA Exam

This past December I took the ISACA CISA exam and I’m pleased to announce that last week, I got my confirmation letter stating that I passed in the to…

Read more

Tags

See all