A practical HIPAA implementation plan in ten steps: risk analysis, policies, business associates, training and breach response, with realistic timings.
A practical GDPR implementation plan in ten steps: records of processing, lawful basis, DPIAs, data subject rights and breach response, with realistic timings.
Ask two companies how they prove supply chain security and you will get two unrelated answers. One will describe physical controls over goods in transit; the other will describe how
Teams adopting COBIT, ISO 31000 and the CIS Controls often assume they are choosing between them. They are not. Each occupies a different layer of the same problem, and an
Healthcare vendors get asked for HIPAA compliance constantly, and increasingly for HITRUST certification as well. The two are often spoken of as if they were alternatives, which they are not.
Sooner or later a prospect asks a cloud provider to prove its security, and the honest first answer is a question: prove it to whom? There is no single cloud
A NIST SP 800-30 risk assessment is how you work out which risks actually matter to your organisation. The NIST Cybersecurity Framework tells you what good security looks like. It
Every security team is asked the same question by its board sooner or later: are we getting safer? Answering it means reporting numbers — and that is where cybersecurity KRIs