Patrick Hughes

Patrick Hughes

Patrick Hughes is a seasoned Cybersecurity Practitioner at Compass IT Compliance with over ten years of comprehensive experience in the IT audit and compliance field. As a certified PCI Qualified Security Assessor (QSA), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), and Certified Data Privacy Solutions Engineer (CDPSE), Patrick brings extensive technical expertise to every client engagement. Throughout his decade-long career, he has partnered with organizations across diverse industries, guiding them through complex regulatory landscapes with specialized focus on PCI DSS assessments, HIPAA compliance, and business continuity planning. Patrick is passionate about building strong client relationships and thrives in the dynamic, multifaceted environment that IT audit provides, combining technical rigor with clear communication to help organizations strengthen their overall security posture while achieving their compliance objectives.

Posts by Patrick Hughes

The Anatomy of an IT Policy

The Anatomy of an IT Policy

What are policies and why do we need them? Every organization should have a set of policies in place. Policies are essentially the laws and regulations of an organization. They pertain to the health, safety, and accountability of employees and how the organization interacts with clien …

Read Story

Succession Planning and Testing – Who Will Step Up to the Plate?

Succession Planning and Testing – Who Will Step Up to the Plate?

Succession planning is so important to organizations, yet so often overlooked. Many folks are not really sure what it is. For those that get the idea of it, many are at a loss for where to start. In the next couple of minutes, I will take you through what succession planning is, how t …

Read Story

California Privacy Rights Act of 2020 – CCPA 2.0?

Tourists stand on a cliff in Santa Cruz

During last week’s election, the state of California voted to pass the new California Privacy Rights Act (CPRA). This legislation is intended to expand and strengthen the current California Consumer Privacy Act (CCPA). Last October I published a blog post outlining the implications of …

Read Story

Elements of Quality Security and Privacy Awareness Training

Markers fall onto a nightstand

As information technology professionals, we often hear the term security awareness training. Most organizations know they need to be conducting continuous security awareness training, whether the goal is to check a box for a framework/regulation they must adhere to, or they genuinely …

Read Story

Virtual Healthcare and HIPAA Compliance

Virtual Healthcare and HIPAA Compliance

COVID-19 has taken the world by storm, and society as we know it is changing rapidly. From how we interact with each other socially, to our ability to freely go shopping and eat at restaurants, changes are being initiated across the board. Industries all across the world have been aff …

Read Story

Pandemic Planning and Tabletop Testing

Pandemic Planning and Tabletop Testing

With the recent outbreak of the Coronavirus (COVID-19), the Centers for Disease Control and Prevention (CDC) has recommended that organizations assess their current pandemic response plans. If your organization doesn’t have a pandemic response plan in place, it is highly recommended t …

Read Story

Subscribe by email