Compass IT Compliance Blog

Canvas Breach: What It Means for Schools & FERPA Compliance

Canvas Breach What It Means for Schools & FERPA Compliance

When the Canvas login page was replaced with a ransom note on the morning of May 7, 2026, it did not look like a typical edtech outage. Students at Harvard, the University of Michigan, Duke, the University of Maryland, and thousands of other institutions opened their laptops in the mi …

Read Story

How to Become a vCISO: The Skills That Set Great Ones Apart

How to Become a vCISO The Skills That Set Great Ones Apart

At Compass IT Compliance, we run one of the more established virtual CISO practices in the country. That vantage point has given us a clear view of the capabilities that consistently define the strongest vCISOs working in the field today. The skills are not always the ones aspiring vC …

Read Story

CMMC Assessments in Higher Education: What Campus Leaders Are Saying

CMMC Assessments in Higher Education What Campus Leaders Are Saying

I just got back from the EDUCAUSE Cybersecurity and Privacy Professionals Conference in Anaheim last week, and I came home with a notebook full of conversations that I think a lot of provosts, CIOs, and CISOs need to hear. The hallway talk between sessions, the candid moments over cof …

Read Story

PCI DSS Penetration Testing: A Practical Compliance Guide

PCI DSS Penetration Testing A Practical Compliance Guide

Here is a conversation we have more often than we would like to admit. We are on a call with an organization that processes payment cards, and we ask how they are tracking against PCI DSS. The response comes back fast and confident: "Oh, we are good. We have an ASV doing our quarterly …

Read Story

The SOC 3 Report: Your Most Underutilized Trust Asset

The SOC 3 Report Your Most Underutilized Trust Asset

In today's marketplace, trust is currency. Prospects evaluate vendors with increasing scrutiny, procurement teams demand proof of security controls before signing contracts, and buyers at every level want assurance that the organizations handling their data take that responsibility se …

Read Story

Shadow IT Is Now Shadow SaaS & Shadow AI: A Practical Cleanup Guide

Shadow IT Is Now Shadow SaaS & Shadow AI: A Practical Cleanup Guide

If you caught yourself searching "what is shadow IT" this week, you are not alone, and you have probably already lived through it. The term used to conjure rogue modems in a closet, a dusty Access database on somebody's C: drive, or a "just for the team" WiFi router plugged in under a …

Read Story

Subscribe by email