Skip to main content

Case Studies

Real engagements, described without client identities.

Advisory work across regulatory applicability, vendor and data handling, and incident response.

Confidentiality note

The engagements below reflect real client work. Client identities and identifying details have been withheld under confidentiality obligations. Descriptions are general in nature to protect client confidentiality and do not include specific measured outcomes unless independently verifiable.

Engagements

Selected engagement narratives

Regulatory Advisory

FTC Safeguards Rule Advisory

Situation
A regulated business engaged Infosec Check to determine its obligations under the FTC Safeguards Rule.
Approach
Infosec Check conducted a regulatory applicability review and identified gaps in written information security program documentation.
Outcome
Working directly with ownership, Infosec Check built a defensible written information security program and the supporting governance materials.
Healthcare-Adjacent Advisory

HIPAA-Adjacent Advisory

Situation
A business owner sought guidance after recognizing that HIPAA obligations were unclear within vendor and data-handling relationships.
Approach
Infosec Check reviewed data flows, vendor agreements, and administrative safeguards.
Outcome
The engagement delivered a practical remediation roadmap aligned to the client's size and resources.
Incident Response

Incident Response and Investigative Engagement

Situation
Following indicators of unauthorized access, the client needed an independent assessment of how the exposure occurred and who was responsible for what.
Approach
Infosec Check assessed authentication controls, endpoint safeguards, network segmentation, and vendor responsibilities, drawing on investigative and forensic methodology.
Outcome
Infosec Check prepared executive ready incident documentation and remediation tracking for leadership.

Ready to talk?

Book a 30-minute working session or send us a note. We'll come prepared.