Back to Blog
Series · 7 pieces

The Cyber-Attest Practice

Running a modern cyber-attest practice — SOC 2, ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP, and DORA — in one console. Cross-framework control drift, IPE completeness at scale, evidence integrity, independence-by-design, and the engagement-margin math that decides which of your services survive AI pricing pressure.

  1. 2of 7
    Aug 13, 2026·12 min read

    Detecting Year-Over-Year Control Drift Across the SOC 2 Type II Cycle: A Practitioner's Method

    Control drift is the category of finding between 'operating effectively' and 'failed' — a directional change over time in population, frequency, disposition, or ownership. Most SOC 2 II examinations miss it because each cycle is tested in isolation. The four patterns worth detecting, the detection procedure that adds 2-4 hours at kickoff, and how to disclose drift responsibly in the report.

    Read
  2. 3of 7
    Aug 20, 2026·13 min read

    IPE Completeness and Accuracy at Scale: Testing Client-Produced Reports Across 40+ Concurrent SOC 2 Engagements

    IPE (Information Produced by the Entity) is the specific artifact type that produces more SOC 2 peer review findings than any other. Per-engagement heroics work at low volume; at 40+ concurrent engagements they eat the practice. The extraction-lineage approach that turns IPE testing from a scavenger hunt into a repeatable primitive — and what a defensible IPE workpaper actually contains.

    Read
  3. 4of 7
    Aug 27, 2026·12 min read

    Independence-by-Design: Why 'Read-Only' Should Be an Architecture, Not a Policy

    Policy independence is a peer-review vulnerability. Architectural independence — no write paths into the auditee's compliance state, one-way evidence flow, cryptographic integrity guarantees — resolves the appearance question a bundled auditor-and-platform vendor cannot. The five-question buyer's checklist, the three shapes of platform, and what peer reviewers actually look for.

    Read
  4. 5of 7
    Sep 3, 2026·13 min read

    CaseWare, Suralink, Fieldguide, Thoropass: How the Cyber-Attest Software Stack Actually Compares in 2026

    Five categories of cyber-attest platform, each with a distinct buyer profile. The category-by-category comparison — legacy workpaper (CaseWare, TeamMate+), PBC specialist (Suralink), AI-native workflow (Fieldguide), bundled auditor+platform (Thoropass, A-LIGN A-SCEND), and independent audit-firm substrate (vCISO Lite for Auditors) — plus the flat requirement-by-requirement table.

    Read
  5. 6of 7
    Sep 10, 2026·12 min read

    Hash-Chained, Timestamp-Anchored Workpapers: The Evidence Chain-of-Custody Standard the AICPA Hasn't Named Yet

    DMS-plus-log workpaper integrity is trivially forgeable in the modern threat model. Cryptographic evidence integrity — SHA-256 hash chains anchored to RFC 3161 timestamp authorities — is the mature, standards-based mechanism that resolves log-forgery, insider-elevation, and platform-migration failure modes. The five questions to ask any audit-tooling vendor.

    Read
  6. 7of 7
    Sep 17, 2026·12 min read

    From 3PAO to C3PAO to CCSFP to QSA: One Console for Firms That Hold Multiple Assessment Accreditations

    The mid-tier assessor firm segment (Coalfire, Schellman, 38North, A-LIGN, MegaplanIT) runs 4-6 accreditations concurrently on the same practitioners. Each accreditation carries its own regulatory context, competency requirements, reporting templates, and quality oversight. The operational efficiency delta between framework-siloed tooling and cross-framework substrate is 200-400 hours per enterprise client per year.

    Read

Ready to put this into practice?

See how vCISO Lite operationalizes the methodology behind this series.