Tag

Compliance

Stay informed about cybersecurity compliance requirements, including regulations like HIPAA, GDPR, PCI DSS, and CMMC. Our compliance articles explain how to meet regulatory obligations, prepare for audits, and align security controls with industry standards.

posts

NIST Standards

NIST Standards: What Actually Matters for Your Security

The Framework Everyone References but Few Actually Implement In 2023, the MOVEit Transfer breach ripped through over 2,600 organizations worldwide. Many of those companies had compliance checklists. Many referenced NIST standards in their security policies. And yet, basic access controls and patch management — core tenets of NIST guidance — were

Carl B. Johnson May 13, 2026 6 min read
NIST Standards

NIST Standards: What Actually Matters for Your Security

800 Pages of Security Guidance — and Most Teams Read None of It In 2023, the MOVEit Transfer breach compromised data from over 2,600 organizations worldwide. Many of those organizations claimed compliance with major frameworks. The problem wasn't that NIST standards didn't cover the vulnerability class

Carl B. Johnson May 01, 2026 5 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: A 2025 Guide

In May 2023, T-Mobile agreed to a $350 million settlement after a data breach exposed the personal information of roughly 76 million people. A significant chunk of that cost wasn't the breach itself — it was the fallout from notification failures, regulatory scrutiny, and class-action lawsuits that followed. If

Carl B. Johnson Jun 15, 2025 8 min read
NIST Standards

NIST Standards: A Practical Guide for Real Security

In April 2021, the Colonial Pipeline hadn't yet made global headlines — but the SolarWinds breach was still fresh, and the Microsoft Exchange Server vulnerabilities had just rattled tens of thousands of organizations. Every one of those incidents had something in common: the affected organizations either ignored or incompletely

Carl B. Johnson May 15, 2021 7 min read
Shadow IT Risks

Shadow IT Risks: The Hidden Threat Draining Your Budget

Your Employees Already Built a Second IT Department A marketing manager signs up for an AI writing tool using her corporate email. A sales rep stores client contracts in a personal Dropbox. An engineering team spins up an AWS instance without telling anyone. None of these people are malicious. Every

Carl B. Johnson Oct 27, 2020 7 min read
NIST Standards

NIST Standards: A Practical Guide for Real-World Security

When Change Healthcare suffered its catastrophic ransomware attack in early 2024 — disrupting pharmacy operations across the United States for weeks — investigators found a familiar culprit: stolen credentials and no multi-factor authentication on a critical system. The company's parent, UnitedHealth Group, eventually disclosed the breach affected roughly 100 million

Carl B. Johnson Feb 02, 2019 7 min read