Insights · Vol. I

Briefings for boards, security leaders, and general counsel.

Working papers from our attestation, certification and advisory practices. Written to inform a decision, not to fill a page.

Certification · 11 min read

ISO 27001 Certification Checklist for Fast-Growing Companies

The 11-stage checklist our advisory team uses to bring a Series B to Series D company through ISO 27001:2022 certification without stalling product velocity.

Read →

Regulation · 8 min read

HIPAA Compliance Requirements: What US Health-Tech Founders Miss

The Privacy, Security, and Breach Notification Rules translated into the specific controls, contracts, and evidence a modern digital-health company must maintain.

Read →

Regulation · 7 min read

GDPR Readiness for US Companies Serving European Customers

A concise operating framework covering lawful basis, data-transfer mechanics post-Schrems II, DPO thresholds, and the records US firms must produce on request.

Read →

Advisory · 6 min read

Virtual CISO vs Full-Time CISO: A Decision Framework

When a fractional security executive outperforms a full-time hire, and the three signals that indicate it is time to bring the role in-house.

Read →

Strategy · 7 min read

SOC 2 vs ISO 27001: Which Framework to Pursue First

The buyer, geographic, and operating factors that determine whether a security program should lead with SOC 2 Type II, ISO 27001:2022, or both in parallel.

Read →

Attestation · 10 min read

The SOC 2 Controls List, Written for Engineers

A pragmatic walk-through of the Trust Services Criteria control families — access, change, vendor, incident, monitoring — with the evidence auditors actually test.

Read →

Certification · 8 min read

ISO 27001 Cost: What Certification Actually Costs in 2026

A defensible ISO 27001 cost model covering readiness advisory, certification body fees, ISMS tooling, and internal effort — with the scoping levers that reduce the total.

Read →

Regulation · 9 min read

HIPAA Risk Analysis: The Template OCR Actually Accepts

The structure, scope, and evidence expectations for a HIPAA risk analysis that satisfies 45 CFR § 164.308(a)(1)(ii)(A) — with the pitfalls OCR enforcement actions cite.

Read →

Regulation · 7 min read

GDPR DPIA: When You Need One and How to Run It

A working guide to Data Protection Impact Assessments under GDPR Article 35 — triggers, methodology, consultation with supervisory authorities, and documentation.

Read →

Offensive Security · 6 min read

How to Scope a Penetration Test: A Buyer's Guide

Scope determines whether a penetration test finds exploitable risk or generates a scanner report. A guide to targets, rules of engagement, methodology, and reporting.

Read →

Advisory · 6 min read

vCISO Pricing Models: Fixed Retainer, Hours, or Outcomes

A breakdown of virtual CISO pricing models — fixed retainer, hourly, and outcome-based — with the engagement patterns that fit each.

Read →

Strategy · 7 min read

NIST CSF vs ISO 27001: Framework, Standard, or Both

NIST CSF is a framework. ISO 27001 is a standard. How to sequence, harmonize, and — where the buyer requires it — certify against both.

Read →

Regulation · 8 min read

PCI DSS 4.0: What Actually Changed and What to Do About It

The substantive PCI DSS 4.0 changes that affect your control estate — customized approach, targeted risk analysis, and the March 2025 compliance deadline.

Read →

Regulation · 9 min read

DORA Readiness: A Compliance Playbook for ICT Third-Party Risk

The Digital Operational Resilience Act became applicable in January 2025. What financial entities must have in place for ICT third-party risk, incident reporting, and testing.

Read →

Regulation · 8 min read

CMMC 2.0 for Defense Contractors: What Level You Need and When

The Cybersecurity Maturity Model Certification 2.0 is being phased into DoD contracts. A practical guide to Level 1, 2, and 3 obligations, assessments, and timelines.

Read →

Strategy · 9 min read

AI Governance: Building a Framework Before Regulators Force You To

How to stand up an AI governance program aligned to NIST AI RMF and ISO/IEC 42001 — model inventory, evaluation, red-teaming, and human oversight.

Read →

Architecture · 10 min read

Zero Trust Roadmap: A 12-Month Implementation Plan

A pragmatic zero trust roadmap aligned to NIST SP 800-207 — identity, device, network, application, and data pillars — sequenced for real organizations.

Read →