Cybersecurity Blog


Subscribe

Category: Compliance

SOX Compliance Checklist for IT General Controls

SOX Compliance Checklist for IT General Controls


Posted August 7, 2026 in Compliance, Cybersecurity

A SOX compliance checklist for IT general controls: scoping, access management, change management, operations, and...

Google Workspace HIPAA Compliance: Gmail, Chat, Drive, Meet

Google Workspace HIPAA Compliance: Gmail, Chat, Drive, Meet


Posted August 6, 2026 in Compliance, Cybersecurity

Yes, Google Workspace HIPAA compliant email is possible. Learn which services the Google BAA covers, how to accept...

CMMC Level 2 Requirements: The Complete 2026 Guide

CMMC Level 2 Requirements: The Complete 2026 Guide


Posted August 6, 2026 in Compliance, Cybersecurity

CMMC Level 2 requirements for 2026: all 110 NIST 800-171 controls, SPRS scoring, POA&M rules, C3PAO vs...

CISA Issues Updated Guidance on Minimum Elements of an SBOM

CISA Issues Updated Guidance on Minimum Elements of an SBOM


Posted August 4, 2026 in Compliance, HIPAA, CMMC, Cybersecurity

The United States Cybersecurity and Infrastructure Security Agency recently published updated guidance establishing...

HIPAA Compliant Password Managers Guide

HIPAA Compliant Password Managers Guide


Posted August 4, 2026 in Cybersecurity, Compliance

What makes a HIPAA compliant password manager? BAA availability, Security Rule access controls, and the policies your...

How Much Does CMMC Certification Cost in 2026? A Straight Answer for Defense Contractors

How Much Does CMMC Certification Cost in 2026? A Straight Answer for Defense Contractors


Posted July 30, 2026 in CMMC, NIST, Compliance

What CMMC certification really costs in 2026: DoD published assessment estimates by level, the costs those numbers...

What DoD Instruction Implements the CUI Program? DoDI 5200.48, Explained for Defense Contractors

What DoD Instruction Implements the CUI Program? DoDI 5200.48, Explained for Defense Contractors


Posted July 30, 2026 in CMMC, NIST, Compliance, Cybersecurity

DoDI 5200.48 is the DoD instruction that implements the CUI program. What it requires, CUI marking rules, NIST SP...

GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical In

GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical In


Posted July 28, 2026 in Compliance, HIPAA, Cybersecurity, CMMC, NIST

The U.S. government is accelerating its efforts to standardize cybersecurity incident reporting across critical...

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts


Posted July 25, 2026 in Compliance, Ransomware, NIST, Cybersecurity

The recent disclosure regarding the DevMan ransomware-as-a-service portal marks a significant evolution in how threat...

Patient Data Exposed at Ohio Revenue Cycle Management Firm

Patient Data Exposed at Ohio Revenue Cycle Management Firm


Posted July 24, 2026 in Compliance, HIPAA, CMMC, Ransomware, Penetration Testing

Patient data exposure at an Ohio revenue cycle management company shows why healthcare vendors need HIPAA-aligned...

CMMC Level 3 Is the Quietest Land Grab in Defense Contracting

CMMC Level 3 Is the Quietest Land Grab in Defense Contracting


Posted July 24, 2026 in Ransomware, Cybersecurity, Compliance

CMMC Level 3 adds 24 NIST SP 800-172 requirements to Level 2. See the DoD cost estimates, why early movers win, and...

Clover Health Assessing Impact of Social Engineering Incident

Clover Health Assessing Impact of Social Engineering Incident


Posted July 24, 2026 in Compliance, HIPAA, CMMC, NIST, Cybersecurity

Clover Health disclosed a social engineering cybersecurity incident to the SEC. See what happened and how healthcare...