Derek Boczenowski

Derek Boczenowski

Derek Boczenowski, MBA, CISA, CISM, QSA, CMMC CCP, is a nationally recognized information security and compliance authority with over 20 years of experience across financial services, higher education, and government. As Chief Architect at Compass IT Compliance, he helps organizations identify security gaps and build practical, risk-based strategies to address them. Before joining Compass, Derek served as VP of Technology for a Massachusetts-based credit union with ~$700M in assets, giving him firsthand insight into the regulatory pressures financial institutions face daily. That perspective now informs his work with everyone from Fortune 500 companies to community banks. A sought-after speaker, Derek has presented at the Fiserv National Conference, the New York Bankers Association, and events nationwide. His expertise spans PCI DSS, SOC 2, CMMC, data privacy, and vendor risk management. He also writes extensively on emerging compliance issues and frequently presents through ISACA webinars.

Posts by Derek Boczenowski

It (Should) Be an MFA World, We Are Just Living in It

It (Should) Be an MFA World, We Are Just Living in It

Last week I was working in front of my laptop (happily, for any Compass staff reading) when I got an incoming text message. It was from Verizon. They had received my service request and were working on it. It was quickly followed by another text saying I could check the status of my r …

Read Story

CMMC 2.0 Transition: Navigating the Road to Compliance

CMMC 2.0 Transition: Navigating the Road to Compliance

Late last week, the Pentagon put out a memo that stuck a knife in the heart of CMMC 1.0, to replace it with the new and shiny CMMC 2.0! CMMC is dead, long live CMMC!

Read Story

The Difficulties of Remaining Compliant in the New COVID Landscape

The Difficulties of Remaining Compliant in the New COVID Landscape

If there is one thing that everyone can agree on in these interesting times, it is that COVID-19 has upset the apple cart in lots of different ways. Everything from school to work to social gatherings has been disrupted and changed over the last eight months, and some of these changes …

Read Story

Blackbaud Breach – Time to Review Your Vendors

Blackbaud Breach – Time to Review Your Vendors

It has recently been reported that Blackbaud, one of the world’s largest providers of education administration, fundraising, and financial management software for nonprofits suffered a ransomware attack back in May of 2020.

Read Story

CMMC – What Is It, and Why Does It Matter?

A rounded loop of a factory's assembly line

There has been a lot of discussion around the cybersecurity interwebs lately about something called CMMC. CMMC stands for Cybersecurity Maturity Model Certification, which sounds super fancy and important, but what does it really mean?

Read Story

Lessons Learned from a Part-Time Teleworker in Quarantine

Lessons Learned from a Part-Time Teleworker in Quarantine

If you read our blog on a regular basis, you have seen more than one excellent discussion on pandemic planning and how to set up remote workers with proper policies, process, hardware, and software to ensure secure and compliant ways to keep working from home.

Read Story

Subscribe by email