Skip to main content

FAQ

Frequently asked questions.

Answers about cybersecurity governance, regulatory applicability, cyber insurance readiness, Fractional CISO engagements and how Infosec Check works.

What does Infosec Check do?

Infosec Check helps leadership identify potentially applicable cybersecurity obligations, clarify who owns each one, review available evidence, document unresolved questions, and prepare for regulatory, contractual, customer, vendor and cyber-insurance scrutiny. Work is delivered through governance and regulatory readiness, cyber-insurance readiness, and Fractional CISO engagements.

Who are Infosec Check services designed for?

Infosec Check services are designed for business owners and leadership teams that need to clarify cybersecurity responsibilities, potentially applicable requirements, available evidence, unresolved gaps, and cyber-insurance readiness. Applicability and engagement scope depend on the organization's activities, information, contracts, jurisdictions, and objectives.

Which frameworks and requirements come up most often?

The FTC Safeguards Rule, IRS taxpayer-data guidance, HIPAA, PCI DSS, the NIST Cybersecurity Framework, ISO 27001, state data-security and breach-notification requirements, customer security questionnaires and cyber-insurance control questions come up most often. Which of them applies depends on the organization's own facts.

Is Infosec Check a certifying body or auditor?

No. Infosec Check does not issue certifications, attestations or audit opinions, and does not act as an accredited certification body. Engagements prepare an organization for review and can coordinate with an auditor or assessor it selects.

Is Infosec Check an insurance broker or carrier?

No. Infosec Check does not act as an insurance carrier. Joseph Boyd is a licensed Virginia Insurance Consultant. Cybersecurity-governance and insurance-readiness engagements are separately scoped, and any insurance consulting is limited by applicable licensure, jurisdiction, engagement terms, and law.

How is a Fractional CISO engagement structured?

Fractional CISO work is delivered on a monthly retainer sized to an agreed level of committed time, and can be scaled during an audit, an incident, a renewal or a transaction. Scope, duration and terms are set in the engagement agreement.

Where is Infosec Check located?

Infosec Check operates from the United States and works with organizations across the United States. Insurance consulting activity is limited by applicable licensure and jurisdiction.

How do we start?

Call or text (855) 624-6262, or send a short note through the contact page. The first conversation is used to understand the situation and define a scoped next step.

Why do cyber insurance claims get denied?

Claims can be denied, reduced, or disputed based on the application, policy wording, exclusions, notice requirements, and the specific facts of the incident. No single factor determines the outcome, and organizations facing a denial or dispute should consult coverage counsel and licensed insurance professionals. Preparing accurate applications, organizing evidence, and understanding policy conditions before an incident can help reduce misunderstandings during claim review.

Does IRS Publication 4557 apply to my tax practice?

Publication 4557 outlines data safeguarding expectations for tax professionals and generally applies to firms that handle taxpayer data, though specific obligations depend on your practice's size, systems, and state requirements. It is commonly used alongside the FTC Safeguards Rule and state data-security laws to guide written information security plans and workforce training.

What cybersecurity requirements exist for tax preparers?

Tax preparers are generally expected to maintain a written information security plan under FTC Safeguards Rule and IRS guidance, though exact requirements depend on firm size, data handled, and state law. Additional obligations may include access controls, encryption, incident response planning, vendor oversight, and breach notification procedures where applicable.

Clarify Your Position

How certain are you that your organization could prove its cybersecurity answers today?

A brief conversation can help identify what may apply, what evidence should exist and what deserves a closer examination.

Call Infosec Check

(855) 624-6262
Prefer a return call?

Your information will be used only to respond to this inquiry. See our Privacy Policy.