Skip to main content

Case Studies

Engagements described without client identities.

Advisory work across regulatory applicability, vendor and data handling, and incident documentation.

Methodology and confidentiality note

These anonymized examples describe the problem presented, the scope of work, the approach taken, and categories of deliverables. Identifying details are withheld to protect confidentiality. They are illustrative narratives, not guarantees, statistics, testimonials, or predictions of results.

Client identities and identifying details have been withheld under confidentiality obligations. Descriptions are general in nature and do not include measured outcomes. Each engagement reflects the facts of that organization and should not be read as general industry evidence or as an indication of results in another organization.

Last updated

Engagements

Selected engagement narratives

Regulatory Advisory

FTC Safeguards Rule Advisory

Problem presented
A regulated business engaged Infosec Check to clarify what its obligations under the FTC Safeguards Rule might be.
Approach
Infosec Check conducted a regulatory applicability review and identified gaps in written information security program documentation.
Deliverable categories
Working with ownership, the engagement produced a written information security program and the supporting governance materials, together with a record of items that remained unresolved.
Healthcare-Adjacent Advisory

HIPAA-Adjacent Advisory

Problem presented
A business owner sought guidance after recognizing that HIPAA obligations were unclear within vendor and data-handling relationships.
Approach
Infosec Check reviewed data flows, vendor agreements, and administrative safeguards.
Deliverable categories
The engagement delivered a remediation roadmap scoped to the organization's size and resources, with open questions documented for leadership and counsel.
Incident Documentation

Incident Review and Documentation Engagement

Problem presented
Following indicators of unauthorized access, the client needed an independent review of how the exposure may have occurred and who was responsible for what.
Approach
Infosec Check reviewed authentication controls, endpoint safeguards, network segmentation, and vendor responsibilities using an investigative methodology.
Deliverable categories
The engagement produced executive-ready incident documentation and remediation tracking for leadership.

Clarify Your Position

How certain are you that your organization could prove its cybersecurity answers today?

A brief conversation can help identify what may apply, what evidence should exist and what deserves a closer examination.

Call Infosec Check

(855) 624-6262
Prefer a return call?

Your information will be used only to respond to this inquiry. See our Privacy Policy.