Derek Boczenowski

Derek Boczenowski

Derek Boczenowski, MBA, CISA, CISM, QSA, CMMC CCP, is a nationally recognized information security and compliance authority with over 20 years of experience across financial services, higher education, and government. As Chief Architect at Compass IT Compliance, he helps organizations identify security gaps and build practical, risk-based strategies to address them. Before joining Compass, Derek served as VP of Technology for a Massachusetts-based credit union with ~$700M in assets, giving him firsthand insight into the regulatory pressures financial institutions face daily. That perspective now informs his work with everyone from Fortune 500 companies to community banks. A sought-after speaker, Derek has presented at the Fiserv National Conference, the New York Bankers Association, and events nationwide. His expertise spans PCI DSS, SOC 2, CMMC, data privacy, and vendor risk management. He also writes extensively on emerging compliance issues and frequently presents through ISACA webinars.

Posts by Derek Boczenowski

Your CMMC SSP Is Not Just a Checkbox: How to Build One That Works

Your CMMC SSP Is Not Just a Checkbox How to Build One That Works

The System Security Plan (SSP) is the cornerstone document of any CMMC Level 2 compliance program. Yet it is also one of the most underdeveloped artifacts assessors encounter. Organizations preparing for a C3PAO assessment frequently arrive with an SSP that describes their environment …

Read Story

CMMC Scoping Guide: How to Define Your Level 2 Assessment Boundary

CMMC Scoping Guide How to Define Your Level 2 Assessment Boundary

One of the most consequential (and most misunderstood) steps in preparing for CMMC compliance is defining the scope of your assessment boundary. Scope too broadly and you’re burdening your organization with unnecessary controls and cost. Scope too narrowly and you risk leaving Control …

Read Story

Does SOC 2 Reduce Security Questionnaires, or Just Change Them?

Does SOC 2 Reduce Security Questionnaires, or Just Change Them?

Every B2B vendor chasing enterprise deals eventually asks the same thing. We are pouring real money and real calendar time into a SOC 2 Type 2 report, so will it actually reduce the security questionnaires we get buried under, or will buyers just keep sending them anyway?

Read Story

PCI Compliance for Small Business: A QSA's Field Guide to PCI DSS

PCI Compliance for Small Business: A QSA's Field Guide to PCI DSS

If you run a small business that accepts credit cards, the words "PCI compliance" probably land somewhere between mildly stressful and outright intimidating. I get it. I have spent years walking small merchants through the Payment Card Industry Data Security Standard (PCI DSS), and th …

Read Story

PCI DSS Penetration Testing: A Practical Compliance Guide

PCI DSS Penetration Testing A Practical Compliance Guide

Here is a conversation we have more often than we would like to admit. We are on a call with an organization that processes payment cards, and we ask how they are tracking against PCI DSS. The response comes back fast and confident: "Oh, we are good. We have an ASV doing our quarterly …

Read Story

When Vendors Get Hacked: Your Guide to Third-Party Data Breaches

When Vendors Get Hacked Your Guide to Third-Party Data Breaches

In today's interconnected business ecosystem, organizations rely heavily on third-party vendors for everything from payroll and marketing to cloud hosting, customer support, and specialized financial-services processing. While these partnerships unlock efficiency and innovation, they …

Read Story

Subscribe by email