What’s the Difference Between SOC for Cybersecurity and SOC 2?

by Sarah Harvey / June 14, 2023

Newest Addition to the SOC Suite The AICPA recently added a new offering to its SOC suite: SOC for Cybersecurity. The difference between SOC 1, SOC 2, and SOC 3 has always been fairly clear-cut based on factors like internal control over financial reporting, the Trust Services Criteria, and restricted report use. Now, we have a new player in the game. What’s the Difference Between SOC for Cybersecurity and SOC…

Data Center Physical Security Recommendations with Auditor Insights

by Mike Wise / June 15, 2023

Why is Data Center Physical Security Important? As we see more and more headlines of breaches, the focus on intruders accessing critical data has been heightened. What is the goal of those intruders? To access critical data stored by organizations. This brings data centers into focus because the ultimate nexus of that critical data is in the data center. One of the top responsibility areas for data centers falls into…

What Is SOC Cyber Security?

by Sarah Harvey / June 14, 2023

The Age of Cybersecurity & Risk Management In today’s world, information systems are incredibly interconnected, but this comes with a price. Because most organizations conduct some portion of their business in cyberspace, they open themselves up to a new level of risk. Who they are, what they do, and what information they possess can make businesses targets for malicious attackers. A malicious cybersecurity attack can result in: Reputational damage Disruption…

business people walking

Auditor Insights: Business Continuity and Disaster Recovery Plans for the Cloud

by Joseph Kirkpatrick / December 16, 2022

Most business owners understand the importance of Business Continuity and Disaster Recovery Plans. These documented sets of policies and procedures can be a lifeline to organizations following a disaster because they determine loss of operations, reputation, and revenue. But how does the cloud impact Business Continuity and Disaster Recovery Plans? Myths about Business Continuity and Disaster Recovery Plans for the Cloud When it comes to Business Continuity and Disaster Recovery…

[24]7.ai Cyber Incident: How Your Vendors Can Impact Your Security

by Sarah Harvey / December 16, 2022

Vendor Compliance Management: What Happened? On April 4th, [24]7.ai, a customer support software company, announced a cyber incident “potentially affecting the online customer payment information of a small number of our client companies,” that occurred between September 26 and October 12, 2017. This cyber incident specifically occurred in [24]7.ai’s chat tool. Never heard of [24]7.ai? We hadn’t either, but their well-known clients gave this breach national attention. Sears, Delta Air…