Kelly O’Brien

Kelly O’Brien

Kelly O’Brien is the Senior Vice President of Risk & Compliance at Compass IT Compliance, bringing more than 20 years of experience in information technology and cybersecurity. She has built her career around helping organizations manage cyber risk, strengthen compliance programs, and align security initiatives with business strategy. Ms. O’Brien holds several distinguished certifications, including CISM, CRISC, CISA, CDPSE, CFE, and CMMC CCP. She is an active contributor to the professional community through organizations such as ISACA, Infragard, where she serves as a Board Member, and the Association of Certified Fraud Examiners. Her expertise spans a broad range of industries and encompasses key cybersecurity frameworks, regulatory standards, and specialized assessments, including CJIS. She has also authored articles for industry publications, delivered webinars for ISACA, and shared her expertise as a panelist and speaker at conferences on cybersecurity, risk management, and compliance. Beyond her professional work, Kelly volunteers with The Honor Foundation as a career coach, guiding transitioning U.S. Special Operations Forces personnel into private-sector careers. In this role, she focuses on helping veterans explore opportunities in Cyber Risk & Compliance, where her mentorship and practical insight make a meaningful impact.

Posts by Kelly O’Brien

HIPAA 2026 Security Rule Overhaul: Why the Stryker Attack Matters

HIPAA 2026 Security Rule Overhaul Why the Stryker Attack Matters

On March 11, 2026, the Iran-aligned hacktivist group Handala launched a devastating cyberattack on Stryker Corporation, one of the largest medical device companies in the United States, framing it as retaliation for U.S.-Israeli military strikes that killed civilians in Iran. The atta …

Read Story

HIPAA Updates 2026: What Healthcare Organizations Must Know

Critical HIPAA Updates for 2026 What Healthcare Organizations Need to Know

The healthcare industry is heading into one of its most significant regulatory shifts in over a decade. With proposed changes to both the HIPAA Security Rule and Privacy Rule expected to be finalized in 2026, organizations that handle electronic protected health information (ePHI) nee …

Read Story

How Often Should Internal Audits Be Conducted?

How Often Are Internal Audits Conducted?

Internal audits play a vital role in keeping an organization running smoothly. They help leadership confirm that processes are working as intended, risks are being managed, and regulatory obligations are being met. Despite their importance, one of the most common questions companies a …

Read Story

Securing Sea & Road: Cyber Threats in Maritime & Logistics

Cybersecurity on Sea & Road: Protecting Maritime & Logistics Operations

The shipping, trucking, and logistics sectors are increasingly in the crosshairs of cyber attackers. In the past few years, both major and minor incidents have shown that no size or mode of transport is immune. Whether it is a vessel navigating global trade routes or a fleet hauling f …

Read Story

Understanding AI: What It Is, How It Works, & Why It Needs Oversight

Understanding AI

Artificial Intelligence (AI) is no longer a futuristic concept; it is a reality. It’s already reshaping how we live, work, and interact with technology. From voice assistants and personalized ads to self-driving cars and automated customer support, AI is quietly becoming a core part o …

Read Story

CIS or NIST CSF? Choosing the Right Cybersecurity Framework (Or Both)

CIS vs NIST CSF

The Center for Internet Security (CIS) Critical Security Controls are a prioritized set of best practices designed to help organizations defend against common cyber threats. Version 8.0, released in 2021, introduced major changes to better reflect modern IT environments, including sup …

Read Story

Subscribe by email