Compass IT Compliance Blog

PCI Compliance for Small Business: A QSA's Field Guide to PCI DSS

PCI Compliance for Small Business: A QSA's Field Guide to PCI DSS

If you run a small business that accepts credit cards, the words "PCI compliance" probably land somewhere between mildly stressful and outright intimidating. I get it. I have spent years walking small merchants through the Payment Card Industry Data Security Standard (PCI DSS), and th …

Read Story

Canvas Breach: What It Means for Schools & FERPA Compliance

Canvas Breach What It Means for Schools & FERPA Compliance

When the Canvas login page was replaced with a ransom note on the morning of May 7, 2026, it did not look like a typical edtech outage. Students at Harvard, the University of Michigan, Duke, the University of Maryland, and thousands of other institutions opened their laptops in the mi …

Read Story

How to Become a vCISO: The Skills That Set Great Ones Apart

How to Become a vCISO The Skills That Set Great Ones Apart

At Compass IT Compliance, we run one of the more established virtual CISO practices in the country. That vantage point has given us a clear view of the capabilities that consistently define the strongest vCISOs working in the field today. The skills are not always the ones aspiring vC …

Read Story

CMMC Assessments in Higher Education: What Campus Leaders Are Saying

CMMC Assessments in Higher Education What Campus Leaders Are Saying

I just got back from the EDUCAUSE Cybersecurity and Privacy Professionals Conference in Anaheim last week, and I came home with a notebook full of conversations that I think a lot of provosts, CIOs, and CISOs need to hear. The hallway talk between sessions, the candid moments over cof …

Read Story

PCI DSS Penetration Testing: A Practical Compliance Guide

PCI DSS Penetration Testing A Practical Compliance Guide

Here is a conversation we have more often than we would like to admit. We are on a call with an organization that processes payment cards, and we ask how they are tracking against PCI DSS. The response comes back fast and confident: "Oh, we are good. We have an ASV doing our quarterly …

Read Story

The SOC 3 Report: Your Most Underutilized Trust Asset

The SOC 3 Report Your Most Underutilized Trust Asset

In today's marketplace, trust is currency. Prospects evaluate vendors with increasing scrutiny, procurement teams demand proof of security controls before signing contracts, and buyers at every level want assurance that the organizations handling their data take that responsibility se …

Read Story

Subscribe by email