California’s new cybersecurity audit rule: what CCPA-covered businesses need to know before 2027

by Mark Hinely / September 11, 2026

If your company sells or shares California residents' personal information, there's a new compliance deadline on your calendar, and it has nothing to do with cookie banners or opt-out links. Starting January 1, 2027, businesses that meet certain thresholds under the California Consumer Privacy Act need to complete an independent cybersecurity audit every year and certify the results to the state. It's a security requirement sitting inside a privacy law.…

Behind the Firewall ft. Suzette Corley

by Morgan Prost / August 25, 2026

Have you ever looked at a compliance project and thought, "Where do I even begin?" One client kept putting off their GDPR and privacy work. Not because they didn't care, but because the scope felt overwhelming. Every time the project came up, there seemed to be a reason to wait.Our Senior Privacy Auditor, Suzette Corley, didn't push harder. Instead, she acknowledged the challenge and reminded them that compliance gaps aren't…

Behind the Firewall ft. Wayne Clement

by Morgan Prost / August 12, 2026

Inactivity is the silent killer of any audit. Wayne Clement, an Information Security Auditor, has a name for the client behavior that quietly derails audits: the silent killer. Inactivity. It shows up in familiar forms like pushback on in-person meetings, evidence requests that sit untouched for days, or a "we'll get to it" that never receives attention. By the time anyone notices, the timeline is already slipping. Wayne's answer is relentless…

Behind the Firewall ft. Joseph Kirkpatrick

by Morgan Prost / July 28, 2026

What happens when no human remembers the environment? During a recent Team meeting, Joseph Kirkpatrick our Founder and President, made a point that stuck with everyone: automated tools are tempting, but what happens when no human remembers the environment? He'd just heard from a client about another vendor who assigns a different pen tester to every engagement. No continuity, no historical context — every test starts from zero. That’s what…

Behind the Firewall ft. Mark Dube

by Morgan Prost / July 1, 2026

As far as they were aware, they weren’t storing card data at all.  It started like any other assessment. Routine, methodical, and expected.  Then we brought in our Penetration Tester Mark Dube, and what he uncovered wasn’t just a few technical missteps — it was a wake-up call. While performing file share enumeration, Mark stumbled upon something alarming: 50,000 credit card numbers and 175,000 instances of first names, last names,…