Practical compliance guidance
No jargon, no fear-mongering—just what actually works for small businesses getting security-ready.
Security Insights
Compliance
Federal FY-Close: What You Can and Can't Ship Before Q4 Spend Closes
A FedRAMP Moderate authorization takes nine to twelve months on the fast path. Six weeks of FY26 remaining is not enough for the ATO — but it is enough for the SSP, gap assessment, vendor diligence, and continuous-monitoring instrumentation that make FY27 execution clean. What to sign for, and what not to.
Read the guide →Read by topic, not by date
Each series collects every piece we’ve written on a single topic. Start with the overview, then follow the threads that matter to you.
All posts
"We are FERPA-compliant" is the wrong answer to a district in Illinois or New York. The state-by-state map of the meaningfully-different student-privacy statutes stacking on top of FERPA, what is changing in 2027, and how the SDPC National Data Privacy Agreement short-circuits the per-state re-answer cycle.
DORA creates a new set of audit-adjacent revenue lines for cyber-attest practices with EU financial-entity clients — Register-of-Information audit, Article 30 contract review, incident-classification testing, resilience-testing-programme audit. TLPT is the higher-revenue, higher-capability opportunity. The build-versus-partner-versus-acquire decision on offensive-security capability, the DORA-vs-AICPA independence contrast, and where DORA fits in a multi-accreditation practice.
Q4 is the audit committee's sign-off quarter, and the year has to close on a number. Here is how to build a dollar figure that survives a skeptical director's follow-up questions, which parts of the standard security deck quietly get cut before the meeting, and the two slides that actually get read.
Most FERPA violations are not dramatic breaches. They are routine access-audit failures that never come up until an inspection or a records request. Ten cases (LAUSD/AllHere, Illuminate, Pearson, Chegg, Minneapolis, FCPS, plus four common failure patterns), what each vendor or district failed to prove, and what the 2027 posture will look for when AI-mediated classrooms are in scope.
AI in audit sampling is being actively adopted; the peer-review implications are being worked out. The Big 4 pattern (Helix, Clara, GL.ai, Argus) — AI does the mechanical work, the practitioner does the judgment. The specific AI capabilities that pass peer review vs the ones that fail, and the workpaper documentation requirements when AI is in the workflow.
Every vendor risk playbook assumes steady state. Then the fund closes a carve-out, or bolts on a competitor. What actually happens to the vendor register at close, which change-of-control triggers fire in week one, and the ninety-day playbook that separates the portcos the fund puts on the next platform strategy from the ones it quietly downgrades.
The AI industry aimed itself at the SOC — alert triage, log summarization, phishing detection. Meanwhile 71% of CISOs spend 10+ hours preparing each quarterly board report and boards give them 15 minutes on the agenda. The prompt at CISO altitude that has been walked past for two years: rank my security programs by loss reduced per dollar spent, given my current exposure and this budget. Why it's not a spreadsheet, four pitfalls in the order they bite, and how to acquire the capability — DIY in half a Saturday or productized in an hour.
The FTC unanimously finalized a substantial COPPA rule update on January 16, 2025 with full compliance required by April 22, 2026. Five specific tightenings, an expanded definition of personal information that now covers biometrics and government IDs, and the six adjustments EdTech vendors need to make before district DPAs get renegotiated for the 2027-28 filing window.
Realization, utilization, engagement margin — the three metrics move differently in cyber-attest than in financial audit, and the levers are different too. The 2026 pressure pattern that shows up in engagement margin first, before realization or utilization compress. The one-page monthly dashboard for the cyber-attest practice partner.
Carriers ask ~60 questions and take most of the answers on faith. They verify roughly a third — MFA depth, backup restore testing, EDR coverage. Line-by-line 2026 look at which questions carriers actually verify, which they still take on faith, and the four unverified questions where the buyer's evidence moves premium 10 to 24%.
The mid-tier assessor firm segment (Coalfire, Schellman, 38North, A-LIGN, MegaplanIT) runs 4-6 accreditations concurrently on the same practitioners. Each accreditation carries its own regulatory context, competency requirements, reporting templates, and quality oversight. The operational efficiency delta between framework-siloed tooling and cross-framework substrate is 200-400 hours per enterprise client per year.
CIPA hasn't changed on paper. What changed is that districts now have both the FCC cybersecurity-pilot funding and the visibility to enforce it against AI-mediated classroom tools. The five artifacts vendors need to produce (content-safety alignment, turn-level monitoring, training-data attestation, sub-processor register, student-data incident response) before the 2027-28 filing window opens.
Tier 4 is the destination — the human sets the objective, the agent plans the work, the guardrails enforce the floor. It is not the right product to ship today, on any methodology shipping in 2026. The honest version of why, and what evidence would need to land before any vendor could responsibly cross the bar.
Most AI governance platforms in 2026 classify prompts. Which of IBM, ServiceNow, Credo AI, OneTrust, and Holistic AI actually prove what the agent did — and what the SMB integrity-plus-coherence alternative looks like.
DMS-plus-log workpaper integrity is trivially forgeable in the modern threat model. Cryptographic evidence integrity — SHA-256 hash chains anchored to RFC 3161 timestamp authorities — is the mature, standards-based mechanism that resolves log-forgery, insider-elevation, and platform-migration failure modes. The five questions to ask any audit-tooling vendor.
The FY25 operating plan I wrote in September 2024 landed with a $10.7M cyber org's CFO because of the frame, not the number. Two budgets, ABC work classification, an honest "What We're Not Doing" section, and a leading-indicator KPI per line item so the bet stays defensible through Q1. For 2027, three new AI line items belong on every plan — headcount leverage, sub-processor governance, and deepfake resistance co-owned with finance.
Three SEC rules — Item 1.05 8-K, Reg S-K Item 106, and Item 2.01 8-K — set the cyber disclosure duty around any M&A deal that touches a public acquirer or soon-to-be-public target. When the 4-business-day clock starts, what the diligence package must contain to support a defensible filing, and the three enforcement cases every deal team should know cold.
Five categories of cyber-attest platform, each with a distinct buyer profile. The category-by-category comparison — legacy workpaper (CaseWare, TeamMate+), PBC specialist (Suralink), AI-native workflow (Fieldguide), bundled auditor+platform (Thoropass, A-LIGN A-SCEND), and independent audit-firm substrate (vCISO Lite for Auditors) — plus the flat requirement-by-requirement table.
A two-person compliance team carrying SOC 2 plus state privacy, supporting enterprise sales, responding to 40-80 control events a week. At Tier 1 the queue is the bottleneck. At Tier 2 the bottleneck shifts. The working week, in detail — what changes, what does not, and why the headcount line is not the right line.
Kroll's 2026 PE cyber survey puts the average portco incident at $2.1M and ACA's 2026 benchmark finds half of PE portcos at elevated or high cyber risk. This is the three-slide quarterly packet that replaces the folder of heat maps and lets the fund answer the LP's aggregate-exposure question before an incident forces the answer.
Policy independence is a peer-review vulnerability. Architectural independence — no write paths into the auditee's compliance state, one-way evidence flow, cryptographic integrity guarantees — resolves the appearance question a bundled auditor-and-platform vendor cannot. The five-question buyer's checklist, the three shapes of platform, and what peer reviewers actually look for.
The 2026 renewal questionnaire moved a material chunk of controls from attestation into evidence-verified. What carriers now verify vs. take on faith, what a January renewer should do between August and December, and what does not move premium even though your broker may say it does.
Anyone can build a risk dashboard. The hard part is convincing an auditor that the numbers are correct. Most products skip this; we publish each indicator's Brier score against realized outcomes. The calibration discipline that distinguishes a real leading-indicator framework from prettier dashboards.
The six dimensions district compliance officers now ask about in AI-feature reviews — data flows, consent posture, training-data attestation, human decision authority, auditability, and incident response — and the framework answers that win the contract.
IPE (Information Produced by the Entity) is the specific artifact type that produces more SOC 2 peer review findings than any other. Per-engagement heroics work at low volume; at 40+ concurrent engagements they eat the practice. The extraction-lineage approach that turns IPE testing from a scavenger hunt into a repeatable primitive — and what a defensible IPE workpaper actually contains.
Ready to simplify security?
See how easy it can be.