California’s new cybersecurity audit rule: what CCPA-covered businesses need to know before 2027

by Mark Hinely / September 11, 2026

If your company sells or shares California residents' personal information, there's a new compliance deadline on your calendar, and it has nothing to do with cookie banners or opt-out links. Starting January 1, 2027, businesses that meet certain thresholds under the California Consumer Privacy Act need to complete an independent cybersecurity audit every year and certify the results to the state. It's a security requirement sitting inside a privacy law.…

Notes from the Field: CIS Control 16 – Application Software Security 

by Greg Halpin / April 3, 2024

Recently, I’ve been working with a small Software as a Services (SaaS) company, and it quickly became clear they didn't have much in place by way of security. They didn't have a documented policy. They didn't do code reviews. New code releases were deployed on the fly. They didn't do secure scans of code or the web application. They didn't have a web application firewall (WAF). The application database was…

Notes from the Field: Center for Internet Security Control 10 – Malware Defenses 

by Greg Halpin / September 14, 2023

The client I was working with had a web application hosted on a Windows server with the anti-virus software disabled. When I asked the head of Information Technology about it, he said the company's web application didn't work when anti-virus was running, so they couldn't enable it. They weren't concerned about it as they had a firewall in place with malware protection. I strongly advised them to reconsider that decision.…