Skip to main content

Industries

Programs tuned to your regulatory reality.

We adapt to your sector's frameworks, regulators, and buyer expectations, not the other way around.

Tax & Accounting Firms

FTC Safeguards Rule and IRS Publication 4557

A written information security program is not optional for firms handling taxpayer data, and the IRS expects one to exist before an incident, not after. Preparers who cannot produce a current WISP have nothing to hand a regulator, an insurer, or a client who asks.

Where it bites: Seasonal preparers and contractors granted access to client records with no offboarding record.

Financial Services

GLBA, FFIEC CAT, PCI DSS 4.0, NY DFS Part 500

Examiners expect documented board oversight and a tested incident response plan, not a spreadsheet of intentions, and findings follow the institution from exam to exam.

Where it bites: Annual certification deadlines that arrive before third-party risk reviews are finished.

Healthcare

HIPAA Security Rule & HHS OCR enforcement

OCR opens with a request for your risk analysis, and an incomplete or stale one is the single most commonly cited failure in resolution agreements.

Where it bites: Business associate agreements signed years ago with vendors nobody has re-assessed since.

Insurance

Virginia Insurance Data Security Act

Insurance carriers and agencies operating in Virginia are subject to the Virginia Insurance Data Security Act. Licensees that determine a cybersecurity event has occurred must notify the Commissioner of Insurance as promptly as possible, and no later than three business days from that determination, when the licensee is a domestic insurance company or a Virginia-domiciled producer meeting applicable thresholds. Annual compliance certification applies to insurers domiciled in Virginia, not to every licensed agency. Exemptions can apply depending on employment status, affiliation, HIPAA compliance, or coverage under another licensee's information security program. Requirements, exemptions, and reporting deadlines vary by jurisdiction and by license type, and should be confirmed against the current Virginia SCC Bureau of Insurance guidance or with qualified counsel.

Where it bites: Producer and MGA networks holding policyholder data outside the carrier's control set.

Retail & eCommerce

PCI DSS 4.0 (SAQ A-EP / D) and FTC Safeguards

PCI DSS 4.0 added client-side script inventory and tamper detection for payment pages, which most storefronts running third-party tag managers cannot currently evidence.

Where it bites: Seasonal traffic spikes handled by contractors who quietly widen scope on the payment path.

Energy & Utilities

NERC CIP and NIST CSF 2.0

CIP audits test evidence retention and change management on cyber assets, and OT environments rarely produce the logs those standards assume exist.

Where it bites: Flat networks where a vendor laptop can reach both business systems and control systems.

Public Sector

FedRAMP Moderate, CMMC Level 2, StateRAMP

Contract eligibility depends on a scoped boundary and an accurate System Security Plan, and a self-assessment that overstates maturity now carries False Claims Act exposure.

Where it bites: CUI spreading into email, file shares, and personal drives outside the assessed enclave.

Non-Profit

State breach notification laws and PCI SAQ A for donations

Donor and beneficiary records carry the same notification duties as commercial data, but grant budgets rarely fund a security function to manage them.

Where it bites: Volunteer and board turnover leaving orphaned admin accounts in donor platforms.

Ready to talk?

Book a 30-minute working session or send us a note. We'll come prepared.