Infosec Check helps leadership identify potentially applicable cybersecurity obligations, clarify who owns each one, review available evidence, document unresolved questions, and prepare for regulatory, contractual, customer, vendor and cyber-insurance scrutiny. Work is delivered through governance and regulatory readiness, cyber-insurance readiness, and Fractional CISO engagements.
Infosec Check services are designed for business owners and leadership teams that need to clarify cybersecurity responsibilities, potentially applicable requirements, available evidence, unresolved gaps, and cyber-insurance readiness. Applicability and engagement scope depend on the organization's activities, information, contracts, jurisdictions, and objectives.
The FTC Safeguards Rule, IRS taxpayer-data guidance, HIPAA, PCI DSS, the NIST Cybersecurity Framework, ISO 27001, state data-security and breach-notification requirements, customer security questionnaires and cyber-insurance control questions come up most often. Which of them applies depends on the organization's own facts.
No. Infosec Check does not issue certifications, attestations or audit opinions, and does not act as an accredited certification body. Engagements prepare an organization for review and can coordinate with an auditor or assessor it selects.
No. Infosec Check does not act as an insurance carrier. Joseph Boyd is a licensed Virginia Insurance Consultant. Cybersecurity-governance and insurance-readiness engagements are separately scoped, and any insurance consulting is limited by applicable licensure, jurisdiction, engagement terms, and law.
Fractional CISO work is delivered on a monthly retainer sized to an agreed level of committed time, and can be scaled during an audit, an incident, a renewal or a transaction. Scope, duration and terms are set in the engagement agreement.
No. Website content is general educational and risk-management information. It is not a legal opinion, regulatory ruling, certification, attestation, audit opinion, coverage determination or guarantee. Requirements and outcomes depend on applicable law, contracts, insurance applications and policies, jurisdictions, and facts.
Infosec Check operates from the United States and works with organizations across the United States. Insurance consulting activity is limited by applicable licensure and jurisdiction.
Call or text (855) 624-6262, or send a short note through the contact page. The first conversation is used to understand the situation and define a scoped next step.
See the /.well-known/security.txt file on this domain or email security@infoseccheck.com.
Claims can be denied, reduced, or disputed based on the application, policy wording, exclusions, notice requirements, and the specific facts of the incident. No single factor determines the outcome, and organizations facing a denial or dispute should consult coverage counsel and licensed insurance professionals. Preparing accurate applications, organizing evidence, and understanding policy conditions before an incident can help reduce misunderstandings during claim review.
Publication 4557 outlines data safeguarding expectations for tax professionals and generally applies to firms that handle taxpayer data, though specific obligations depend on your practice's size, systems, and state requirements. It is commonly used alongside the FTC Safeguards Rule and state data-security laws to guide written information security plans and workforce training.
Tax preparers are generally expected to maintain a written information security plan under FTC Safeguards Rule and IRS guidance, though exact requirements depend on firm size, data handled, and state law. Additional obligations may include access controls, encryption, incident response planning, vendor oversight, and breach notification procedures where applicable.