Compass IT Compliance Blog

A Key To Your Risk Management Strategy: Cybersecurity Insurance

A Key To Your Risk Management Strategy: Cybersecurity Insurance

I went to a conference back in October and the keynote speaker was a former NSA Director. He made a brilliant point during his presentation that was as follows: There are two types of companies, one that has been breached and the other is the one that has been breached but doesn’t kno …

Read Story

Security Awareness Training: The First Line of Defense

A group of business professionals debate at a meeting

Compass IT security auditors are often asked if there is a single “most important” factor involved in safeguarding a business’s data assets.

Read Story

Cybersecurity Insurance: Think You're Covered?

Cybersecurity Insurance: Think You're Covered?

IT security breaches have become so commonplace in recent years that they barely seem to raise an eyebrow anymore: Target, Bank of America, I.R.S., the list goes on. With that rise, the claims on Cybersecurity Insurance have risen as well.

Read Story

IT Auditing - Why It's a Smart Investment

A group of five business professionals celebrate

We have all heard the term "Audit" and most of the time it makes us cringe. The first thing that we think of is someone in a suit coming into our organization and poking holes in our Technology, People and Processes that we have built based on the needs of our company and business. Ho …

Read Story

Incident Response Management: What Is It and How to Implement It

Incident Response Management: What Is It and How to Implement It

An Incident Response Program is an aggregate of processes designed to minimize the impact of security incidents. The program is like a fire extinguisher case on the wall in a high school chemistry lab. It contains all of the components, including detailed instructions, for how to cont …

Read Story

Your PCI Risk Assessment: Security vs. Compliance

Your PCI Risk Assessment: Security vs. Compliance

Most people often think that security and compliance are the same thing, especially when looking at conducting a PCI Risk Assessment. Truth is, these are two very different topics yet are interchanged very frequently. A good place for us to start is to define these terms so that we kn …

Read Story

Subscribe by email