Insights · Vol. I
Briefings for boards, security leaders,
and general counsel.
Working papers from our attestation, certification and advisory practices. Written to inform a decision, not to fill a page.
Certification · 11 min read
ISO 27001 Certification Checklist for Fast-Growing Companies
The 11-stage checklist our advisory team uses to bring a Series B to Series D company through ISO 27001:2022 certification without stalling product velocity.
Read →
Regulation · 8 min read
HIPAA Compliance Requirements: What US Health-Tech Founders Miss
The Privacy, Security, and Breach Notification Rules translated into the specific controls, contracts, and evidence a modern digital-health company must maintain.
Read →
Regulation · 7 min read
GDPR Readiness for US Companies Serving European Customers
A concise operating framework covering lawful basis, data-transfer mechanics post-Schrems II, DPO thresholds, and the records US firms must produce on request.
Read →
Advisory · 6 min read
Virtual CISO vs Full-Time CISO: A Decision Framework
When a fractional security executive outperforms a full-time hire, and the three signals that indicate it is time to bring the role in-house.
Read →
Strategy · 7 min read
SOC 2 vs ISO 27001: Which Framework to Pursue First
The buyer, geographic, and operating factors that determine whether a security program should lead with SOC 2 Type II, ISO 27001:2022, or both in parallel.
Read →
Attestation · 10 min read
The SOC 2 Controls List, Written for Engineers
A pragmatic walk-through of the Trust Services Criteria control families — access, change, vendor, incident, monitoring — with the evidence auditors actually test.
Read →
Certification · 8 min read
ISO 27001 Cost: What Certification Actually Costs in 2026
A defensible ISO 27001 cost model covering readiness advisory, certification body fees, ISMS tooling, and internal effort — with the scoping levers that reduce the total.
Read →
Regulation · 9 min read
HIPAA Risk Analysis: The Template OCR Actually Accepts
The structure, scope, and evidence expectations for a HIPAA risk analysis that satisfies 45 CFR § 164.308(a)(1)(ii)(A) — with the pitfalls OCR enforcement actions cite.
Read →
Regulation · 7 min read
GDPR DPIA: When You Need One and How to Run It
A working guide to Data Protection Impact Assessments under GDPR Article 35 — triggers, methodology, consultation with supervisory authorities, and documentation.
Read →
Offensive Security · 6 min read
How to Scope a Penetration Test: A Buyer's Guide
Scope determines whether a penetration test finds exploitable risk or generates a scanner report. A guide to targets, rules of engagement, methodology, and reporting.
Read →
Advisory · 6 min read
vCISO Pricing Models: Fixed Retainer, Hours, or Outcomes
A breakdown of virtual CISO pricing models — fixed retainer, hourly, and outcome-based — with the engagement patterns that fit each.
Read →
Strategy · 7 min read
NIST CSF vs ISO 27001: Framework, Standard, or Both
NIST CSF is a framework. ISO 27001 is a standard. How to sequence, harmonize, and — where the buyer requires it — certify against both.
Read →
Regulation · 8 min read
PCI DSS 4.0: What Actually Changed and What to Do About It
The substantive PCI DSS 4.0 changes that affect your control estate — customized approach, targeted risk analysis, and the March 2025 compliance deadline.
Read →
Regulation · 9 min read
DORA Readiness: A Compliance Playbook for ICT Third-Party Risk
The Digital Operational Resilience Act became applicable in January 2025. What financial entities must have in place for ICT third-party risk, incident reporting, and testing.
Read →
Regulation · 8 min read
CMMC 2.0 for Defense Contractors: What Level You Need and When
The Cybersecurity Maturity Model Certification 2.0 is being phased into DoD contracts. A practical guide to Level 1, 2, and 3 obligations, assessments, and timelines.
Read →
Strategy · 9 min read
AI Governance: Building a Framework Before Regulators Force You To
How to stand up an AI governance program aligned to NIST AI RMF and ISO/IEC 42001 — model inventory, evaluation, red-teaming, and human oversight.
Read →
Architecture · 10 min read
Zero Trust Roadmap: A 12-Month Implementation Plan
A pragmatic zero trust roadmap aligned to NIST SP 800-207 — identity, device, network, application, and data pillars — sequenced for real organizations.
Read →