Skip to main content

FAQ

Frequently asked questions.

Answers about cybersecurity governance, regulatory applicability, cyber insurance readiness, Fractional CISO engagements and how Infosec Check works.

What does Infosec Check do?

Infosec Check helps leadership identify potentially applicable cybersecurity obligations, clarify who owns each one, review available evidence, document unresolved questions, and prepare for regulatory, contractual, customer, vendor and cyber-insurance scrutiny. Work is delivered through governance and regulatory readiness, cyber-insurance readiness, and Fractional CISO engagements.

Who are Infosec Check services designed for?

Infosec Check services are designed for business owners and leadership teams that need to clarify cybersecurity responsibilities, potentially applicable requirements, available evidence, unresolved gaps, and cyber-insurance readiness. Applicability and engagement scope depend on the organization's activities, information, contracts, jurisdictions, and objectives.

Which frameworks and requirements come up most often?

The FTC Safeguards Rule, IRS taxpayer-data guidance, HIPAA, PCI DSS, the NIST Cybersecurity Framework, ISO 27001, state data-security and breach-notification requirements, customer security questionnaires and cyber-insurance control questions come up most often. Which of them applies depends on the organization's own facts.

Is Infosec Check a certifying body or auditor?

No. Infosec Check does not issue certifications, attestations or audit opinions, and does not act as an accredited certification body. Engagements prepare an organization for review and can coordinate with an auditor or assessor it selects.

Is Infosec Check an insurance broker or carrier?

No. Infosec Check does not act as an insurance carrier. Joseph Boyd is a licensed Virginia Insurance Consultant for Property and Casualty. Cybersecurity-governance and insurance-readiness engagements are separately scoped, and any insurance consulting is limited by applicable licensure, jurisdiction, engagement terms, and law.

How is a Fractional CISO engagement structured?

Fractional CISO work is delivered on a monthly retainer sized to an agreed level of committed time, and can be scaled during an audit, an incident, a renewal or a transaction. Scope, duration and terms are set in the engagement agreement.

Where is Infosec Check located?

Infosec Check operates from the United States and works with organizations across the United States. Insurance consulting activity is limited by applicable licensure and jurisdiction.

How do we start?

Call or text (855) 624-6262, or send a short note through the contact page. The first conversation is used to understand the situation and define a scoped next step.

Clarify Your Position

How certain are you that your organization could prove its cybersecurity answers today?

A brief conversation can help identify what may apply, what evidence should exist and what deserves a closer examination.

Call Infosec Check

(855) 624-6262
Prefer a return call?

Your information will be used only to respond to this inquiry. See our Privacy Policy.