Insights on cybersecurity leadership
Practical guidance on cybersecurity leadership, governance, risk and regulatory readiness, written to be useful whether you set the strategy, approve it or carry it out.
- Written for
- Anyone accountable for a security decision: executives, boards, counsel, compliance, IT and security teams.
- Subjects
- Governance, cyber risk, regulatory readiness and executive reporting.
- Every article
- Carries its author, its publication date and the date it was last substantively revised.
The archive
Every other article
- Cloud Security
- 1
- Compliance
- 6
- Compliance and Audit Readiness
- 1
- Compliance and Governance
- 1
- Governance
- 5
- Governance & Compliance
- 3
- Governance and Leadership
- 1
- Managed Security Services
- 1
- Regulatory Compliance
- 2
- Regulatory and Framework Readiness
- 6
- Risk Management
- 2
- Published
- 29
-
When SaaS Vendors Must Be Treated as Subservice Organizations Under SOC 2
SaaS companies undergoing SOC 2 audits face a critical question: when does a vendor's security become part of your own compliance obligation? This article explains the subservice organization concept, when vendors must be included in your SOC 2 scope, what evidence auditors require, and who inside your organization is accountable for the outcome. -
GLBA Safeguards Rule Changes: What Financial Institutions Must Do in 2024
The FTC amended the Gramm-Leach-Bliley Act Safeguards Rule in 2021 and 2023, with the most recent breach notification requirements taking effect in May 2024. Financial institutions subject to FTC jurisdiction must now maintain written information security programs meeting specific technical standards and report qualifying data breaches within 30 days. Leadership faces accountability for security outcomes without always having clear ownership or governance in place. -
What Security Documentation an Assessor Requests First and Why It Matters
Before a SOC 2, ISO 27001 or HITRUST assessment begins, an assessor requests specific documentation in a predictable sequence. Leadership must understand what gaps stop an assessment entirely, what can be addressed during fieldwork, and what delays certification. This article explains the documentation sequence, identifies who owns each category, and clarifies what adequate preparation looks like. -
When Privileged Access Management Becomes an Audit Requirement
SOC 2, PCI DSS and CMMC assessments increasingly test for privileged access controls, not as a checkbox but as evidence of governance. This article explains which frameworks mandate PAM, what constitutes compliance for audit purposes, and how leadership can establish accountability before the assessment begins. -
How FedRAMP Authorization Works and What It Requires Before You Apply
FedRAMP authorization allows cloud service providers to sell to federal agencies through a standardized security assessment process. Leadership must understand the timeline, evidence requirements and internal ownership structure before committing to an authorization effort that typically spans twelve to eighteen months and requires continuous executive oversight. -
What Changes When Your MSP Also Provides Security Monitoring
When a managed service provider takes on security monitoring, the lines of accountability blur unless leadership explicitly defines who decides risk tolerance, who speaks to regulators, and who owns the security program. This article explains what shifts, what stays internal, and how executive ownership closes the gap. -
What GDPR Requires of US Companies and When It Applies
The General Data Protection Regulation applies to US companies that process personal data of individuals in the European Union, regardless of where the company is located. This article explains the territorial scope, core obligations, leadership accountability and practical steps for compliance. -
What Sarbanes-Oxley IT General Controls Actually Require and How They Are Tested
Public company executives are accountable for IT general controls under Sarbanes-Oxley Section 404, yet many face audits without clarity on what is tested, what constitutes a deficiency, or who owns the outcome. This article explains what auditors examine, what delays sign-off, and how vCISO leadership provides the executive ownership needed to close this gap. -
When Log Retention Becomes a Legal Obligation and What That Means for Cloud Accounts
Organizations face legal and regulatory requirements to preserve specific system logs for defined periods, but cloud environments create complexity around who is responsible for which records. This article explains what log retention obligations exist, where the shared responsibility model leaves gaps, and how to establish clear ownership so the organization can meet its compliance duties without ambiguity. -
When Multi-Factor Authentication Is Legally Required and What Counts as Compliant
Federal regulations now mandate multi-factor authentication in specific contexts, but determining what qualifies as compliant and who owns implementation remains unclear in many organizations. This guide explains which regulations require MFA, what technical approaches satisfy those requirements, and how leadership should allocate accountability. -
What Counts as a Security Incident Under Your Cyber Insurance Policy
Cyber insurance policies require prompt notification of security incidents, but defining what qualifies is complicated. Many organizations lack clear decision protocols, creating delays that can invalidate claims. This article explains how incidents are defined, who should make the determination, and how to establish the governance needed to respond within policy timeframes. -
What HITRUST CSF r11 Requires That HIPAA Does Not
HITRUST CSF r11 is a contractual security certification increasingly required by health plans, business associates and investors. It builds on HIPAA's regulatory baseline with prescriptive technical controls, third-party validation and annual audits. Leadership must understand what the standard adds, who owns the work and how to demonstrate progress.