Old Policies, New Technology: Is Your Insurance Actually Ready for AI?
by Kelly O’Brien on August 4, 2026 at 12:00 PM
Most business owners have never read their commercial insurance policies front to back. They renew, file the paperwork, and trust that if something goes wrong, they're covered. For years, that quiet trust extended to artificial intelligence too, even though the word “AI” appeared nowh …
How to Read a SOC 2 Report: A Section-by-Section Guide
by Janelle Lewis on August 3, 2026 at 11:30 AM
A few months ago, at an ISACA event, a woman came up to me for help interpreting her organization's SOC 2 report. She had strong business acumen, but she'd been handed the vendor risk function with almost no background in how to actually read one. That conversation stuck with me, beca …
Mercedes-Benz Dealer ISO 27001 & TISAX Certification Deadline 2026
by Robbie Harriman on July 30, 2026 at 11:00 AM
If you lead IT, security, or compliance at a Mercedes-Benz dealership, you have probably already seen the note buried in your dealer communications: Mercedes-Benz now expects its dealer network to stand up a qualified information security program, backed by ISO 27001, TISAX Level 2 ce …
SAQ A, Requirements 6.4.3 & 11.6.1: What the Eligibility Change Means
by Kyle Daun on July 29, 2026 at 4:14 PM
A question has been coming up recently among people who work with e-commerce merchants, and it can be a real head-scratcher the first time you hit it. A small merchant qualifies for SAQ A and notices that Requirements 6.4.3 and 11.6.1 are simply gone from the form. A larger merchant w …
“We Don’t Use AI” Is a Claim, Not a Control
by Kelly O’Brien on July 24, 2026 at 1:53 PM
A question we hear often from clients sounds simple on its face: Our company says it doesn’t use AI, and our acceptable use policy says the same. How do we actually prove our employees aren’t using it? It is a fair question, and the honest answer is uncomfortable. A written policy sta …
How to Define Your Cardholder Data Environment (CDE) Under PCI DSS
by Patrick Hughes on June 28, 2026 at 1:30 PM
Before an organization can implement Payment Card Industry Data Security Standard (PCI DSS) controls, it must answer a foundational question: what is in scope? The answer lies in the definition of the Cardholder Data Environment (CDE). Get it wrong, and everything built on top of it i …
.webp?width=2169&height=526&name=Compass%20regular%20transparent%20website%20(1).webp)
-1.webp?width=2169&height=620&name=Compass%20regular%20transparent%20website%20smaller%20(1)-1.webp)





%20Under%20PCI%20DSS.jpg)