Compass IT Compliance Blog

Shadow IT Is Now Shadow SaaS & Shadow AI: A Practical Cleanup Guide

Shadow IT Is Now Shadow SaaS & Shadow AI: A Practical Cleanup Guide

If you caught yourself searching "what is shadow IT" this week, you are not alone, and you have probably already lived through it. The term used to conjure rogue modems in a closet, a dusty Access database on somebody's C: drive, or a "just for the team" WiFi router plugged in under a …

Read Story

Your GRC Tool Has Limits: Why a CPA Must Be Behind Your SOC Report

Your GRC Tool Has Limits Why a CPA Must Be Behind Your SOC Report

There is a quiet misconception circulating in the compliance space, and it is worth addressing directly. As GRC automation platforms have grown in popularity, and as their marketing has increasingly emphasized “SOC 2 readiness,” “continuous compliance,” and “audit preparation” some or …

Read Story

The Hidden Cybersecurity Risk Nobody Talks About: Executive Turnover

The Hidden Cybersecurity Risk Nobody Talks About Executive Turnover

When security leaders talk about risk, the conversation usually gravitates toward ransomware, zero-day vulnerabilities, or third-party breaches. Those threats are real, and they deserve the attention they get. But there is another risk vector that quietly undermines cybersecurity prog …

Read Story

Why Most Cybersecurity Tabletop Exercises Fail (and How to Fix It)

Why Most Cybersecurity Tabletop Exercises Fail (and How to Fix It)

There is a question that comes up in every security community eventually: has anyone actually been in a tabletop exercise that felt worthwhile? The frustration behind that question is completely valid. Too many organizations have sat through exercises that were clearly theater, where …

Read Story

Security Awareness Training for SOC 2: What Your Auditor Expects

Security Awareness Training for SOC 2: What Your Auditor Expects

On March 15, 2026, the Chittenden Solid Waste District of Vermont lost $3 million to a single phishing attack. That was not a rounding error in someone’s budget; it was a significant portion of the district’s annual funding, gone in the span of a few fraudulent emails.

Read Story

Security Consulting Firms Offering Virtual CISO Services Stand Out

Security Consulting Firms Offering Virtual CISO Services Stand Out

The cybersecurity services market has become increasingly specialized. Some providers focus exclusively on technical testing, conducting penetration tests, vulnerability assessments, and red team exercises. Others concentrate entirely on governance, risk, and compliance (GRC), offerin …

Read Story

Subscribe by email