Cybersecurity Blog
Category: Compliance
SOX Compliance Checklist for IT General Controls
Posted August 7, 2026 in Compliance, Cybersecurity
A SOX compliance checklist for IT general controls: scoping, access management, change management, operations, and...
Google Workspace HIPAA Compliance: Gmail, Chat, Drive, Meet
Posted August 6, 2026 in Compliance, Cybersecurity
Yes, Google Workspace HIPAA compliant email is possible. Learn which services the Google BAA covers, how to accept...
CMMC Level 2 Requirements: The Complete 2026 Guide
Posted August 6, 2026 in Compliance, Cybersecurity
CMMC Level 2 requirements for 2026: all 110 NIST 800-171 controls, SPRS scoring, POA&M rules, C3PAO vs...
CISA Issues Updated Guidance on Minimum Elements of an SBOM
Posted August 4, 2026 in Compliance, HIPAA, CMMC, Cybersecurity
The United States Cybersecurity and Infrastructure Security Agency recently published updated guidance establishing...
HIPAA Compliant Password Managers Guide
Posted August 4, 2026 in Cybersecurity, Compliance
What makes a HIPAA compliant password manager? BAA availability, Security Rule access controls, and the policies your...
How Much Does CMMC Certification Cost in 2026? A Straight Answer for Defense Contractors
Posted July 30, 2026 in CMMC, NIST, Compliance
What CMMC certification really costs in 2026: DoD published assessment estimates by level, the costs those numbers...
What DoD Instruction Implements the CUI Program? DoDI 5200.48, Explained for Defense Contractors
Posted July 30, 2026 in CMMC, NIST, Compliance, Cybersecurity
DoDI 5200.48 is the DoD instruction that implements the CUI program. What it requires, CUI marking rules, NIST SP...
GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical In
Posted July 28, 2026 in Compliance, HIPAA, Cybersecurity, CMMC, NIST
The U.S. government is accelerating its efforts to standardize cybersecurity incident reporting across critical...
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
Posted July 25, 2026 in Compliance, Ransomware, NIST, Cybersecurity
The recent disclosure regarding the DevMan ransomware-as-a-service portal marks a significant evolution in how threat...
Patient Data Exposed at Ohio Revenue Cycle Management Firm
Posted July 24, 2026 in Compliance, HIPAA, CMMC, Ransomware, Penetration Testing
Patient data exposure at an Ohio revenue cycle management company shows why healthcare vendors need HIPAA-aligned...
CMMC Level 3 Is the Quietest Land Grab in Defense Contracting
Posted July 24, 2026 in Ransomware, Cybersecurity, Compliance
CMMC Level 3 adds 24 NIST SP 800-172 requirements to Level 2. See the DoD cost estimates, why early movers win, and...
Clover Health Assessing Impact of Social Engineering Incident
Posted July 24, 2026 in Compliance, HIPAA, CMMC, NIST, Cybersecurity
Clover Health disclosed a social engineering cybersecurity incident to the SEC. See what happened and how healthcare...