Derek Boczenowski

Derek Boczenowski

Derek Boczenowski, MBA, CISA, CISM, QSA, CMMC CCP, is a nationally recognized information security and compliance authority with over 20 years of experience across financial services, higher education, and government. As Chief Architect at Compass IT Compliance, he helps organizations identify security gaps and build practical, risk-based strategies to address them. Before joining Compass, Derek served as VP of Technology for a Massachusetts-based credit union with ~$700M in assets, giving him firsthand insight into the regulatory pressures financial institutions face daily. That perspective now informs his work with everyone from Fortune 500 companies to community banks. A sought-after speaker, Derek has presented at the Fiserv National Conference, the New York Bankers Association, and events nationwide. His expertise spans PCI DSS, SOC 2, CMMC, data privacy, and vendor risk management. He also writes extensively on emerging compliance issues and frequently presents through ISACA webinars.

Posts by Derek Boczenowski

NIST Cybersecurity Framework 2.0 – Key Takeaways

United States Department of Commerce

Last week, the National Institute of Standards and Technology (NIST) unveiled the second version of its Cybersecurity Framework (CSF), marking the first major new updates to NIST CSF since the framework's inception ten years ago. Initiated by Executive Order 13636, the development of …

Read Story

Understanding the Key Differences Between IT Governance & Compliance

Governance and Compliance

In the dynamic landscape of business expansion and evolution, distinguishing between IT governance and compliance becomes not just beneficial, but essential. While both are pillars in safeguarding organizations against a myriad of risks, they differ in their core objectives, methodolo …

Read Story

What is Protected Health Information (PHI)?

What is Protected Health Information (PHI)?

Protected Health Information (PHI) is a key element in healthcare, governed by stringent legal and ethical standards. This blog explores what PHI encompasses, its significance under HIPAA regulations, and the crucial distinction between PHI and electronic PHI (ePHI). The blog also del …

Read Story

Cell Phone Usage at Work & HIPAA Compliance: Uncovering the Risks

HIPAA Cell Phone Usage

The healthcare industry is increasingly embracing mobile technology, integrating smartphones, tablets, and other portable devices into everyday operations across hospitals, clinics, and other workplaces. This shift towards mobile integration, while offering substantial benefits, also …

Read Story

Not Using Multifactor Authentication? Your Days Are Limited!

MFA

Despite the fact the multifactor authentication (MFA) has been around for decades at this point, the majority of both business and personal logins only use it when absolutely necessary. The complaints are well known; it takes too long to login, if I forget my phone or token I can’t lo …

Read Story

PCI DSS v4.0 ROC Changes – Coming Now to an Organization Near You!

A person inserts their credit cared into a card reader

The Payment Card Industry Data Security Standard (PCI DSS) version 4.0 is here! It has been released, the documents are available publicly for anyone who would like to read them, and forms for both the 900-pound level 1 Report on Compliance (ROC) and the Self-Assessment Questionnaires …

Read Story

Subscribe by email