Kelly O’Brien

Kelly O’Brien

Kelly O’Brien is a Senior Cybersecurity Practitioner at Compass IT Compliance, bringing over 20 years of experience in information technology and cybersecurity. Throughout her career, Kelly has developed deep expertise across cyber risk, compliance, and strategic security initiatives. She holds multiple respected industry certifications and is an active member of several professional cybersecurity organizations, demonstrating her ongoing commitment to staying at the forefront of the field. In addition to her professional work, Kelly has volunteered with The Honor Foundation, where she serves as a career coach for transitioning U.S. Special Operations Forces personnel. In this role, she helps guide veterans into successful careers in the private sector, with a focus on Cyber Risk & Compliance—a field where her insight and mentorship make a meaningful impact.

Posts by Kelly O’Brien

Understanding AI: What It Is, How It Works, & Why It Needs Oversight

Understanding AI

Artificial Intelligence (AI) is no longer a futuristic concept; it is a reality. It’s already reshaping how we live, work, and interact with technology. From voice assistants and personalized ads to self-driving cars and automated customer support, AI is quietly becoming a core part o …

Read Story

CIS or NIST CSF? Choosing the Right Cybersecurity Framework (Or Both)

CIS vs NIST CSF

The Center for Internet Security (CIS) Critical Security Controls are a prioritized set of best practices designed to help organizations defend against common cyber threats. Version 8.0, released in 2021, introduced major changes to better reflect modern IT environments, including sup …

Read Story

HIPAA Compliance in 2025: What’s Changing & Why It Matters

HIPAA Compliance in 2025

Healthcare privacy is evolving rapidly, and 2025 is poised to be a year of significant developments. From how artificial intelligence is handled to increased scrutiny around reproductive health data, the boundaries of HIPAA compliance are expanding. This blog post highlights the most …

Read Story

Reporting Your DoD Self Assessment (SPRS) Score: What to Know

Reporting Your DoD Self Assessment (SPRS) Score

If you contract with the Department of Defense (DoD)—directly or indirectly—you’re likely required to report a cybersecurity self-assessment score to the Supplier Performance Risk System (SPRS). SPRS is a web-based system used by the DoD to track and assess contractor performance and …

Read Story

What Makes an Industry-Leading Cyber Insurance Policy Today?

Cyber Insurance Policy

Cyber insurance is no longer a niche product or an optional safeguard—it has become a critical pillar of enterprise risk management. As cyberattacks grow more sophisticated and regulatory pressures tighten, organizations of all sizes are reevaluating what they expect from their cyber …

Read Story

CJIS Security Policy v6.0 – Key Updates You Need to Know

Criminal Justice Information Services (CJIS) Security Policy v6.0

The Criminal Justice Information Services (CJIS) Security Policy v6.0, released on December 27, 2024, introduces significant modernization efforts aimed at enhancing security, compliance, and risk management in handling Criminal Justice Information (CJI). As technology and cyber threa …

Read Story

Subscribe by email