Kelly O’Brien

Kelly O’Brien

Kelly O’Brien is the Senior Vice President of Risk & Compliance at Compass IT Compliance, bringing more than 20 years of experience in information technology and cybersecurity. She has built her career around helping organizations manage cyber risk, strengthen compliance programs, and align security initiatives with business strategy. Ms. O’Brien holds several distinguished certifications, including CISM, CRISC, CISA, CDPSE, CFE, and CMMC CCP. She is an active contributor to the professional community through organizations such as ISACA, Infragard, where she serves as a Board Member, and the Association of Certified Fraud Examiners. Her expertise spans a broad range of industries and encompasses key cybersecurity frameworks, regulatory standards, and specialized assessments, including CJIS. She has also authored articles for industry publications, delivered webinars for ISACA, and shared her expertise as a panelist and speaker at conferences on cybersecurity, risk management, and compliance. Beyond her professional work, Kelly volunteers with The Honor Foundation as a career coach, guiding transitioning U.S. Special Operations Forces personnel into private-sector careers. In this role, she focuses on helping veterans explore opportunities in Cyber Risk & Compliance, where her mentorship and practical insight make a meaningful impact.

Posts by Kelly O’Brien

“We Don’t Use AI” Is a Claim, Not a Control

“We Don’t Use AI” Is a Claim, Not a Control

A question we hear often from clients sounds simple on its face: Our company says it doesn’t use AI, and our acceptable use policy says the same. How do we actually prove our employees aren’t using it? It is a fair question, and the honest answer is uncomfortable. A written policy sta …

Read Story

PCI DSS Compensating Controls: When & How to Use Them

PCI DSS Compensating Controls - When and How to Use Them

Every organization that stores, processes, or transmits payment card data eventually runs into the same wall. The Payment Card Industry Data Security Standard (PCI DSS) sets a clear bar, but a legacy system, a vendor limitation, or a business reality can make a specific requirement im …

Read Story

Maintaining Targeted Risk Analysis (TRAs) for PCI DSS Compliance

Maintaining Targeted Risk Analysis (TRAs) for PCI DSS Compliance

Every organization that processes, stores, or transmits cardholder data is required to protect it. That much is well understood. What is less understood, and where many organizations quietly fall short, is how they justify specific risk-based decisions inside their compliance program. …

Read Story

HIPAA 2026 Security Rule Overhaul: Why the Stryker Attack Matters

HIPAA 2026 Security Rule Overhaul Why the Stryker Attack Matters

On March 11, 2026, the Iran-aligned hacktivist group Handala launched a devastating cyberattack on Stryker Corporation, one of the largest medical device companies in the United States, framing it as retaliation for U.S.-Israeli military strikes that killed civilians in Iran. The atta …

Read Story

HIPAA Updates 2026: What Healthcare Organizations Must Know

Critical HIPAA Updates for 2026 What Healthcare Organizations Need to Know

The healthcare industry is heading into one of its most significant regulatory shifts in over a decade. With proposed changes to both the HIPAA Security Rule and Privacy Rule expected to be finalized in 2026, organizations that handle electronic protected health information (ePHI) nee …

Read Story

How Often Should Internal Audits Be Conducted?

How Often Are Internal Audits Conducted?

Internal audits play a vital role in keeping an organization running smoothly. They help leadership confirm that processes are working as intended, risks are being managed, and regulatory obligations are being met. Despite their importance, one of the most common questions companies a …

Read Story

Subscribe by email