Home  /  What We Do  /  Compliance & Governance

Compliance and technology governance

Oh no — not the “C word”. It really isn’t that bad. But you do need to know how it affects your business.

Overview

Data compliance is less complex than its reputation

That reputation is the problem. With everything you read about identity theft and data breaches, compliance is not something you can ignore — and most business leaders are not comfortable with what the requirements actually demand, let alone how to manage the data behind them realistically.

As identity-related theft has climbed, businesses have had to take data security and archival seriously. In practice, data management is not that complex once you understand the tools and the concepts behind managing data stores.

Our team brings twenty years of data compliance experience from Fortune 100 financial environments, and we stay current with changing requirements and technology. We can help you identify what applies to you, safeguard it, and build a compliance action plan you can actually follow.

Who is affected

Virtually any organization that stores individually identifiable health or financial information. That includes healthcare and benefits records, individual financial information, self-insured employers — and equally the information systems vendors, service organizations and institutions that handle it on their behalf.

What compliance covers Compliance at the center, surrounded by eight facets: Requirements, Standards, Governance, Safeguards, Assessment, Reporting, Policies, Regulations. COMPLIANCE REQUIREMENTS STANDARDS GOVERNANCE SAFEGUARDS ASSESSMENT REPORTING POLICIES REGULATIONS
Standards

We have practical experience with

HIPAA

The Health Insurance Portability and Accountability Act sets the standard for protecting sensitive patient data. Any company handling protected health information must have the required physical, network and process safeguards in place — and actually follow them.

PCI DSS

The Payment Card Industry Data Security Standard governs any organization that accepts, processes, stores or transmits credit card information, and requires that they maintain a demonstrably secure environment.

Gramm-Leach-Bliley

GLBA requires financial organizations offering loans, financial or investment advice, tax or insurance to disclose their information-sharing practices to customers, and to implement security best practice around personally identifiable data.

SOC (formerly SAS 70)

Service Organization Controls are a series of standards for measuring and evaluating how well an organization controls its information and data — giving customers confidence when they partner with a third party.

How we help

Compliance assessment and risk assessment

We can help you work out where your strengths already lie, and identify the areas that need attention before someone else finds them for you.

We bring enterprise compliance expertise into your organization, so you have confidence not only that you meet your fiduciary compliance obligations, but — more importantly — that your mission-critical data is genuinely safe and secure.

Request an Assessment
Threat awareness

Let’s be honest: the highest risk to your business is your own people. Our Employee Education & Assessment Program educates your team and evaluates how they respond to real threats.

Learn More
Compliance & governance

Find out where you actually stand

Book an assessment and we’ll tell you what applies to you, what you already meet, and what needs work.