Skip to main content

Insights

Field notes from the practice.

Notes on GRC, cyber insurance, and running security programs that hold up.

Regulatory Applicability

What Cybersecurity Regulations Apply to My Business?

A plain-language guide to how laws, contracts, vendors, and insurance create cybersecurity obligations, and how to find out which ones apply to you.

Read more
Insurance

Why Cyber Insurance Claims May Be Denied or Disputed

Ten application, policy, control, notice, consent, and evidence issues that may contribute to a cyber-insurance coverage dispute, depending on the policy, applicable law, and facts.

Read more
Tax and Accounting Cybersecurity

IRS Cybersecurity Requirements for Tax Preparers

A plain-language guide to the cybersecurity requirements affecting tax preparers, including the FTC Safeguards Rule, IRS WISP guidance, e-file standards and incident reporting.

Read more
Training Requirements

Cybersecurity Awareness Training Requirements, By Regulation

A table of employee cybersecurity awareness training requirements under HIPAA, the FTC Safeguards Rule, PCI DSS, New York DFS, Virginia insurance law, and the NAIC model law.

Read more

Free resource

Cyber insurance claim-readiness checklist

The evidence and documentation an adjuster asks for, before you need it.

Get the checklist

Ready to talk?

Book a 30-minute working session or send us a note. We'll come prepared.