Same compliance company. Ten industry playbooks.
vCISO Lite is a company, not a tool. Our compliance platform runs the continuous mechanics: evidence collection, framework attestation, quarterly delta reports. Our Other20 advisory team runs the human work: pre-bind calls, questionnaire completion, tabletops, incident response. Both know the specific playbook for your industry, because SOC 2 for a health-tech company reads different than SOC 2 for a marketing agency, and Coalition’s underwriting questions aren’t OCR’s.
Americans whose PHI was exposed in the Feb 2024 Change Healthcare breach, the largest HIPAA breach in US history and the moment every health-tech vendor’s BAA got re-read.
HHS Office for Civil Rights breach portal, 2024
NYC Local Law 144 enforcement began, mandating bias audits for automated hiring tools. Colorado AI Act followed May 2024 with enforcement in Feb 2026.
NYC DCWP; Colorado SB 24-205
SEC-mandated Form 8-K cyber-incident disclosure window since Dec 2023. The deadline that made every public issuer’s auditor, counsel, and carrier formalize incident-response programs.
SEC Final Rule 33-11216
DORA now fully applies across EU financial services and their critical ICT third parties (cloud, SaaS, MSPs). Named-vendor liability is real EU law, and every US carrier, auditor, or advisor touching an EU financial client is inside its scope.
DORA, EU Regulation 2022/2554
Pick your industry
What one program looks like when it’s tuned to your world.
Every industry we serve has a different auditor asking, a different buyer worrying, a different regulator writing rules. Here’s what the platform runs and where the vCISO shows up, for each.
Why one company fits many industries
The platform runs continuously. The advisory shows up when it matters.
Every industry we serve gets both, tuned to their regulator map.
The receipts, from our own program
We run the same program we sell.
Both tracks live against our own SOC 2 Type I evidence, not a slide. Here’s what each side has done for the company running this page.
- Evidence collectionContinuous, across the same 50+ integrations we sell.
- Framework attestationSOC 2 Type I in progress, tracked control by control.
- Sub-processor registerQuarterly review cadence, delta reports on demand.
- Signed evidence bundleExportable to auditors, carriers, or enterprise buyers.
- Tabletop exercisesSame cadence we run for clients. Not paperwork walk-throughs.
- Incident-response drillsReal scenarios against real playbooks, quarterly.
- Vendor risk reviewsEvery sub-processor onboarding, every renewal.
- Questionnaire responseBecause someone asks us the same things they ask you.
Both tracks, one accountability chain. See the full posture →
Your industry not listed? Both tracks still work.
Platform runs the compliance mechanics from day one. An Other20 vCISO can join your first hard conversation this week. Two ways in, one program.