Derek Boczenowski

Derek Boczenowski

Derek Boczenowski, MBA, CISA, CISM, QSA, CMMC CCP, is a nationally recognized information security and compliance authority with over 20 years of experience across financial services, higher education, and government. As Chief Architect at Compass IT Compliance, he helps organizations identify security gaps and build practical, risk-based strategies to address them. Before joining Compass, Derek served as VP of Technology for a Massachusetts-based credit union with ~$700M in assets, giving him firsthand insight into the regulatory pressures financial institutions face daily. That perspective now informs his work with everyone from Fortune 500 companies to community banks. A sought-after speaker, Derek has presented at the Fiserv National Conference, the New York Bankers Association, and events nationwide. His expertise spans PCI DSS, SOC 2, CMMC, data privacy, and vendor risk management. He also writes extensively on emerging compliance issues and frequently presents through ISACA webinars.

Posts by Derek Boczenowski

Why Every Company Needs an Information Security Officer

Skyscrapers

In today's world, businesses of all sizes depend heavily on digital systems and data. While this digital transformation brings many benefits, it also exposes companies to a growing number of cyber threats. Data breaches, ransomware attacks, and other types of cybercrime have become al …

Read Story

Ransomware Alert: New Strain in the Wild

Ransomware Screenshot.jpg

Friends of Compass, There is a rash of ransomware attacks being reported that has affected as many as 74 countries. One of the largest reported sectors is hospitals within the United Kingdom, with at least 16 hospitals affected. Many hospitals report being disabled and unable to perfo …

Read Story

HIPAA Compliance: 5 HIPAA Mistakes to Avoid!

5 HIPAA Mistakes to Avoid Blog Graphic.png

Here at Compass, we have seen a huge upswing in the number of HIPAA / HITECH risk assessments we have been conducting over the last year. Covered entities (Doctors, Hospitals, Pharmacies) and health plans are obviously storing PHI (protected health information) and ePHI (electronic pr …

Read Story

Security Awareness Training is No Joke!

Without a doubt, almost every type of IT audit contains a section on security awareness training. And in many companies, it is a weakness that can be exploited easier than trying to hack a firewall or compromise a server. In many cases, it can be as easy as sending an email or making …

Read Story

Subscribe by email